Knowella

System Access Review Template

Most access reviews find the same two things: a leaver whose account was never disabled, and an administrator right nobody can explain. The review exists to catch both, but it only catches what it looks at. An account created outside the standard provisioning route is invisible to a review built on the assumption that provisioning was followed in the first place.

KnowComplyReviewCMP-03648 fields across 6 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ISO 27001 cl.9.2
Workspace
KnowComply
Form type
Review
Review cadence
Every six months, plus after any trigger event
Completed by
IT with system owners confirming their own lists

The short version

  • This is a singleton register: one live access review maintained and updated at each cycle, not a fresh record per event, and other templates refer back to it by ID.
  • Leaver accounts that are still active and administrator rights nobody remembers appointing are the two findings almost every cycle produces, and they are named explicitly in the form.
  • The scored metric is unjustified access, where low is good; the process fields underneath it score Yes as good, which is a different question answered correctly rather than a contradiction.
  • It sits inside the Data Protection and Information Security programme and links forward into offboarding and access control, so a weak review degrades the templates that depend on it.

What this is

What is a system access review?

What is a system access review?

A periodic check of who has access to which systems and at what privilege level, run against a list each system owner confirms. It covers standard, privileged, shared, service and contractor accounts, and it is the control ISO 27001 relies on to show that access is granted and removed deliberately, not by accident of history.

Who actually has to confirm the access list?

The system owner, not IT alone. IT can produce the account list, but only the person who understands what each role needs can say whether a privilege level is still justified. A review where IT confirms its own output is not independent of the thing it checks.

What counts as an account still active after someone leaves?

Any credential, standard or privileged, that authenticates after the person's last working day, including one shared with a colleague or provisioned outside the normal joiner process. The finding is the same whether or not it was actually used after departure.

Scope

When is a system access review required?

This review is one step in a larger programme. Using it for work that belongs to a neighbouring template produces records that are hard to report on later.

Use this template when

  • The scheduled six-month interval has arrived, or a trigger event (acquisition, system change, security incident) has brought it forward
  • A new system is being added to the register and needs its first access baseline set
  • You are running the Data Protection and Information Security programme and this is one of its steps
  • A linked record needs this one to exist: offboarding, access control
  • An auditor or customer security questionnaire asks for evidence of periodic access review

Do not use it for

  • Information Security Risk Assessment, which assesses threats to systems, data and operational technology, including plant control systems.
  • Cyber Incident Record, which records a cyber event affecting systems, data or plant operation, with containment, recovery and notification.
  • Backup and Recovery Test Record, which records a test that backups can actually be restored, not merely that they ran.
  • The offboarding workflow itself, which removes access on a leaver's last day; this review only checks that it worked
  • Anything outside KnowComply, which belongs in the workspace that owns that process

Compliance mapping

Which ISO 27001 cl.9.2 requirements does this satisfy?

Access review is a named control in the management system, not a general good-practice suggestion, and the 2013-to-2022 Annex A renumbering moved where it lives without changing what it requires.

ClauseRequirementWhere it lands
ISO 27001:2013 Annex A.9.2.5Asset and system owners review user access rights at regular intervalsProcess
ISO 27001:2013 Annex A.9.2.1 / A.9.2.2Formal user registration and de-registration process so every account is attributable to a personProcess
ISO 27001:2013 Annex A.9.2.6Access rights removed on termination of employment or contract, and adjusted on role changeFindings
ISO 27001:2013 Annex A.9.2.3Allocation and use of privileged access rights is restricted and controlledFindings
ISO 27001:2022 Annex A.8.5Secure authentication, including multi-factor authentication for privileged accountsAction
ISO 27001:2013 Annex A.9.4.2Management of secret authentication information, including password policyFindings
ISO 27001 cl.9.1Monitoring, measurement, analysis and evaluation of the ISMS at planned intervalsOutcome

What it does not cover

  • Information Security Risk Assessment, which assesses threats to systems, data and operational technology, including plant control systems.
  • Cyber Incident Record, which records a cyber event with containment, recovery and notification, not routine access hygiene.
  • Backup and Recovery Test Record, which proves backups restore, not who can reach the systems that hold them.
  • The offboarding process itself, which is the HR and IT workflow that removes access on a leaver's last day; this review only checks that it worked.
  • CCTV and Monitoring Review, which covers physical and camera monitoring rather than logical system access.

Global

System Access Review requirements by country

ISO 27001 sets the control itself. Two other regimes make the review consequential in practice: a US customer due-diligence framework that tests it directly, and UK data protection law that treats a stale account as a security failure.

International

ISO/IEC 27001 Annex A.9.2 (2013) / A.5.18, A.8.2 (2022)

The certifiable control most customer security questionnaires ask for by name

A documented, evidenced review is frequently the one artefact a prospective customer's security team asks to see before signing, and it must show an actual review, not a policy that describes one.

US

SOC 2 Trust Services Criteria CC6.1–CC6.3

Access review as a named control sampled in every SOC 2 Type II audit cycle

Auditors pull the underlying evidence for a sample of periods, not the policy; a review on the calendar but not actually run for a sampled cycle fails the test, regardless of how good the other cycles were.

UK

UK GDPR Article 5(1)(f) (integrity and confidentiality) and the ICO's expectations of access control

Stale access as a security-of-processing failure, not just an IT housekeeping gap

Where a leaver's account can still reach personal data after departure, the ICO treats the omission as a security failure that can sit inside a reportable incident, not a separate administrative matter.

How to complete it

How to complete a system access review, step by step

The form records that a review happened. Whether the record is defensible turns on four judgement calls that the fields alone don't settle.

Confirmation has to mean the owner actually looked

"System Owners Confirmed Their Lists" is easy to answer Yes without opening the list. Treat a blanket yes with zero exceptions as a signal to check, not a clean result — a system with real turnover producing no exceptions more likely means an unread list than a well-managed one.

Unexplained admin rights get removed, not merely noted

"Privileged Access Justified" recorded as No or Partly is not itself the fix. The judgement call is whether the review closes the loop that cycle — remove the right or get a documented justification — rather than carrying the same unexplained administrator forward as a known issue.

Shared and service accounts need an owner, not just a label

"Shared Accounts Identified" and "Service Accounts Reviewed" scored Yes tells you they were counted, not that anyone is accountable for them. A shared login with no named owner is a control gap wearing the look of a completed review.

A leaver finding should trigger the offboarding review, not just the removal

Removing one active leaver account fixes that account. "Offboarding Process Reviewed" is where the judgement actually lives: if the same failure mode produced the finding last cycle too, the process is broken, not just this instance of it.

What auditors find

Most common system access review findings

The findings below are what a review of this kind actually turns up, not a hypothetical list.

FindingClauseWhat fixes it
A leaver's account is still active months after their last working day.ISO 27001:2013 Annex A.9.2.6Remove the account immediately, then trace why the offboarding trigger didn't fire for it.
Administrator rights granted for a project that finished over a year ago are still live.ISO 27001:2013 Annex A.9.2.3Remove the right or record a current business justification; do not carry it forward unexamined.
A shared login is used by several people under one account with no individual attribution.ISO 27001:2013 Annex A.9.2.1 / A.9.2.2Replace with individual accounts, or move to a managed credential vault that logs who checked it out.
The system owner marked the review complete with no exceptions on a list they never opened.ISO 27001:2013 Annex A.9.2.5Require the owner to name at least the accounts they checked, not a single blanket confirmation.
Multi-factor authentication is not enforced on a privileged account.ISO 27001:2022 Annex A.8.5Mandate MFA as a condition of keeping the privileged right, not an optional hardening step.
A password policy failure is recorded but no corrective action is raised against it.ISO 27001:2013 Annex A.9.4.2Link every No or Partly answer to a CAPA reference; a noted gap with no owner does not get fixed.

Case in point

Case in point: the account the review couldn't see

An IT contractor was given domain administrator rights for a three-month migration. The engagement ended, the offboarding ticket was closed, and the contractor's standard user account was disabled on schedule. The administrator account was not, because it had been created as a local privileged account outside the normal joiner-mover-leaver process, and the offboarding checklist only ever looked at accounts that process had created.

The next review, four months later, listed it as active and asked the system owner to confirm it. The owner didn't recognise the name and marked it justified anyway, assuming IT would know. It took a second cycle before anyone traced it to a contract that had ended two review periods earlier, and nobody could say whether it had been used meanwhile. The finding that mattered wasn't the dormant account; it was that a review built on the assumption provisioning followed the standard process cannot see the accounts that didn't.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

48fields
6 sections
Reference
CMP-036
Archetype
Review
Record ID
SAR2-2026-000
Scoring
Unjustified access
Direction
Low is good
Singleton
Yes
Basis
ISO 27001 cl.9.2
Links
Links Offboarding, Access control
Tags
Security, Information
Sections
6
Fields
48
Follow up fields
3
Repeating sections
0
Links out
3
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

10 fields
Text

Review ID*

Generated on save

Auto sequence. Format SAR2-2026-000.

The record's own ID. Other templates point at this value.

Single Choice

Status*

Scored

Drives who this goes to next.

  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Date & Time

Date and Time*

Users

Completed By*

Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Format SITE-000.

Links to FDN-001 Site ID

Text

Period Reviewed*

Users

Reviewed By*

Numeric Answer

Systems In Scope*

Scored
Info

Administrators Nobody Remembers Appointing

Every access review finds leavers who still have accounts and administrator rights granted for a project that ended years ago.

Process

6 fields
Single Choice

System Owners Confirmed Their Lists*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Every Account Attributed To A Person*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Shared Accounts Identified*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Privileged Accounts Identified*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Service Accounts Reviewed*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Contractor Accounts Reviewed*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts

Findings

6 fields
Single Choice

Leaver Accounts Still Active*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Access Beyond Current Role*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Dormant Accounts Identified*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Privileged Access Justified*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Segregation Of Duties Maintained*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Password Policy Enforced*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts

Action

6 fields
Single Choice

Unjustified Access Removed*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Privileged Access Reduced*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Offboarding Process Reviewed*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Joiners And Movers Process Reviewed*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Multi Factor Applied To Privileged Accounts*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Findings Tracked To Closure*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts

Related records

1 field
Text

Security Assessment ID

OptionalLinked

The risk assessment that set the access requirements.

Links to CMP-035 Assessment ID

Outcome

19 fields
Numeric Answer

Accounts Reviewed*

Scored
Numeric Answer

Accounts Removed*

Scored
Single Choice

Process Effective*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Offboarding Working*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Feeds Management Review*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Date & Time

Next Review Due*

Numeric Answer

Items Assessed*

Excludes anything marked N/A.

Numeric Answer

Items Failed*

Numeric Answer

Score Percent*

Scored

Calculated on submission. High is good. N/A items leave the denominator.

Single Choice

Result Band*

Scored
  • Pass3 pts
  • Caution1 pt
  • Fail0 pts
Numeric Answer

Completeness Percent*

How much of the template was actually answered. A high score on a half completed form is not a high score.

Single Choice

Action Required*

Scored

Raise the action record, then enter its reference here.

  • No2 pts
  • Yes0 pts
Single Choice

Priority

OptionalScoredShows if Action Required equals Yes
  • High0 pts
  • Medium1 pt
  • Low3 pts
Text

CAPA ID

OptionalLinkedShows if Action Required equals Yes

Format CAPA-2026-00000.

Links to FDN-014 CAPA ID

Users

Action Owner

OptionalShows if Action Required equals Yes
Users

IT*

Signature

Signature*

Users

Compliance Lead*

Signature

Second Signature*

CMP-036 · record IDs look like SAR2-2026-000 · Links Offboarding, Access control

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

The form is the easy part. Chasing a real confirmation from system owners, tracing an account back to a contract that ended two cycles ago, and closing the loop into offboarding is the work that actually slips.

KnowComply

Holds the access review register against your systems list, routes each record to its system owner, and keeps the leaver and privileged-access evidence together.

KnowContractor

Tracks contractor engagement dates and access grants, closing the gap where a project-scoped administrator account outlives the contract that justified it.

KnowOps

Feeds joiner, mover and leaver events from daily operations into the review, so the account list reflects who currently works there, not last cycle's snapshot.

Ella
Ella

Chases system owners for an actual confirmation rather than a blanket yes, flags accounts unresolved across two cycles, and holds every write for your approval before it touches a record.

This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.

Meet KnowComply→

Glossary

System Access Review definitions and key terms

Privileged access
An account with elevated rights beyond standard use, such as administrator, root or configuration access, which most reviews treat as a separate and higher-scrutiny category.
Dormant account
An account that still authenticates but has not been used for an extended period, which a review should surface even where no one has left.
Segregation of duties
Splitting a sensitive process across two or more people or roles so that no single account can complete it unchecked.
Service account
A non-human account used by an application or automated process to authenticate to a system, frequently overlooked because it has no leaving date to trigger a review.
Leaver account
An account belonging to someone who has left the organisation or ended a contract; the review's most common and most consequential finding is one still active.

FAQ

Frequently asked questions about system access review

What is the system access review template based on?+

It is built against ISO 27001 Annex A.9.2, user access management, which requires formal registration, periodic review by system owners and prompt removal on leaving. The 2022 revision moved the same requirements into A.5.18 and A.8.2 without changing their substance.

What sections does the system access review contain?+

Six: header, process, findings, action, related records, outcome. Together they hold 48 fields, 43 required, covering leaver, privileged, shared, service and contractor accounts.

How many system access review records should we have?+

This is a singleton: one live record per workspace, updated at each cycle rather than created fresh per event, with the linked security assessment ID carried forward from the risk assessment that set the access requirements.

Which programme does the system access review belong to?+

It is part of Data Protection and Information Security, alongside the processing register, impact assessments, breach response and backup testing. Monitoring was introduced with consultation, and backups are proven by restoring them.

How is a system access review scored?+

The headline metric is unjustified access, where low is good. The underlying process fields score Yes as good because they measure whether the review was done properly, which is a different, correctly-scored question.

Can the system access review template be changed?+

Yes. Every field, option, score and conditional rule is editable, and links to other templates come with it. Most teams install it as it is, run it for a cycle, then adjust the cadence or account categories to match what they actually run.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • ISO/IEC 27001:2013 Annex A.9.2 — User access management
  • ISO/IEC 27001:2022 Annex A.5.18 and A.8.2 — Access rights and privileged access rights
  • SOC 2 Trust Services Criteria CC6.1–CC6.3 — Logical access controls
  • UK GDPR Article 5(1)(f) — Integrity and confidentiality (security)

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.