What this is
What is a system access review?
What is a system access review?
A periodic check of who has access to which systems and at what privilege level, run against a list each system owner confirms. It covers standard, privileged, shared, service and contractor accounts, and it is the control ISO 27001 relies on to show that access is granted and removed deliberately, not by accident of history.
Who actually has to confirm the access list?
The system owner, not IT alone. IT can produce the account list, but only the person who understands what each role needs can say whether a privilege level is still justified. A review where IT confirms its own output is not independent of the thing it checks.
What counts as an account still active after someone leaves?
Any credential, standard or privileged, that authenticates after the person's last working day, including one shared with a colleague or provisioned outside the normal joiner process. The finding is the same whether or not it was actually used after departure.
Scope
When is a system access review required?
This review is one step in a larger programme. Using it for work that belongs to a neighbouring template produces records that are hard to report on later.
Use this template when
- The scheduled six-month interval has arrived, or a trigger event (acquisition, system change, security incident) has brought it forward
- A new system is being added to the register and needs its first access baseline set
- You are running the Data Protection and Information Security programme and this is one of its steps
- A linked record needs this one to exist: offboarding, access control
- An auditor or customer security questionnaire asks for evidence of periodic access review
Do not use it for
- Information Security Risk Assessment, which assesses threats to systems, data and operational technology, including plant control systems.
- Cyber Incident Record, which records a cyber event affecting systems, data or plant operation, with containment, recovery and notification.
- Backup and Recovery Test Record, which records a test that backups can actually be restored, not merely that they ran.
- The offboarding workflow itself, which removes access on a leaver's last day; this review only checks that it worked
- Anything outside KnowComply, which belongs in the workspace that owns that process
Compliance mapping
Which ISO 27001 cl.9.2 requirements does this satisfy?
Access review is a named control in the management system, not a general good-practice suggestion, and the 2013-to-2022 Annex A renumbering moved where it lives without changing what it requires.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 27001:2013 Annex A.9.2.5 | Asset and system owners review user access rights at regular intervals | Process |
| ISO 27001:2013 Annex A.9.2.1 / A.9.2.2 | Formal user registration and de-registration process so every account is attributable to a person | Process |
| ISO 27001:2013 Annex A.9.2.6 | Access rights removed on termination of employment or contract, and adjusted on role change | Findings |
| ISO 27001:2013 Annex A.9.2.3 | Allocation and use of privileged access rights is restricted and controlled | Findings |
| ISO 27001:2022 Annex A.8.5 | Secure authentication, including multi-factor authentication for privileged accounts | Action |
| ISO 27001:2013 Annex A.9.4.2 | Management of secret authentication information, including password policy | Findings |
| ISO 27001 cl.9.1 | Monitoring, measurement, analysis and evaluation of the ISMS at planned intervals | Outcome |
What it does not cover
- Information Security Risk Assessment, which assesses threats to systems, data and operational technology, including plant control systems.
- Cyber Incident Record, which records a cyber event with containment, recovery and notification, not routine access hygiene.
- Backup and Recovery Test Record, which proves backups restore, not who can reach the systems that hold them.
- The offboarding process itself, which is the HR and IT workflow that removes access on a leaver's last day; this review only checks that it worked.
- CCTV and Monitoring Review, which covers physical and camera monitoring rather than logical system access.
Global
System Access Review requirements by country
ISO 27001 sets the control itself. Two other regimes make the review consequential in practice: a US customer due-diligence framework that tests it directly, and UK data protection law that treats a stale account as a security failure.
ISO/IEC 27001 Annex A.9.2 (2013) / A.5.18, A.8.2 (2022)
The certifiable control most customer security questionnaires ask for by name
A documented, evidenced review is frequently the one artefact a prospective customer's security team asks to see before signing, and it must show an actual review, not a policy that describes one.
SOC 2 Trust Services Criteria CC6.1–CC6.3
Access review as a named control sampled in every SOC 2 Type II audit cycle
Auditors pull the underlying evidence for a sample of periods, not the policy; a review on the calendar but not actually run for a sampled cycle fails the test, regardless of how good the other cycles were.
UK GDPR Article 5(1)(f) (integrity and confidentiality) and the ICO's expectations of access control
Stale access as a security-of-processing failure, not just an IT housekeeping gap
Where a leaver's account can still reach personal data after departure, the ICO treats the omission as a security failure that can sit inside a reportable incident, not a separate administrative matter.
How to complete it
How to complete a system access review, step by step
The form records that a review happened. Whether the record is defensible turns on four judgement calls that the fields alone don't settle.
"System Owners Confirmed Their Lists" is easy to answer Yes without opening the list. Treat a blanket yes with zero exceptions as a signal to check, not a clean result — a system with real turnover producing no exceptions more likely means an unread list than a well-managed one.
"Privileged Access Justified" recorded as No or Partly is not itself the fix. The judgement call is whether the review closes the loop that cycle — remove the right or get a documented justification — rather than carrying the same unexplained administrator forward as a known issue.
"Shared Accounts Identified" and "Service Accounts Reviewed" scored Yes tells you they were counted, not that anyone is accountable for them. A shared login with no named owner is a control gap wearing the look of a completed review.
Removing one active leaver account fixes that account. "Offboarding Process Reviewed" is where the judgement actually lives: if the same failure mode produced the finding last cycle too, the process is broken, not just this instance of it.
What auditors find
Most common system access review findings
The findings below are what a review of this kind actually turns up, not a hypothetical list.
| Finding | Clause | What fixes it |
|---|---|---|
| A leaver's account is still active months after their last working day. | ISO 27001:2013 Annex A.9.2.6 | Remove the account immediately, then trace why the offboarding trigger didn't fire for it. |
| Administrator rights granted for a project that finished over a year ago are still live. | ISO 27001:2013 Annex A.9.2.3 | Remove the right or record a current business justification; do not carry it forward unexamined. |
| A shared login is used by several people under one account with no individual attribution. | ISO 27001:2013 Annex A.9.2.1 / A.9.2.2 | Replace with individual accounts, or move to a managed credential vault that logs who checked it out. |
| The system owner marked the review complete with no exceptions on a list they never opened. | ISO 27001:2013 Annex A.9.2.5 | Require the owner to name at least the accounts they checked, not a single blanket confirmation. |
| Multi-factor authentication is not enforced on a privileged account. | ISO 27001:2022 Annex A.8.5 | Mandate MFA as a condition of keeping the privileged right, not an optional hardening step. |
| A password policy failure is recorded but no corrective action is raised against it. | ISO 27001:2013 Annex A.9.4.2 | Link every No or Partly answer to a CAPA reference; a noted gap with no owner does not get fixed. |
Case in point
Case in point: the account the review couldn't see
An IT contractor was given domain administrator rights for a three-month migration. The engagement ended, the offboarding ticket was closed, and the contractor's standard user account was disabled on schedule. The administrator account was not, because it had been created as a local privileged account outside the normal joiner-mover-leaver process, and the offboarding checklist only ever looked at accounts that process had created.
The next review, four months later, listed it as active and asked the system owner to confirm it. The owner didn't recognise the name and marked it justified anyway, assuming IT would know. It took a second cycle before anyone traced it to a contract that had ended two review periods earlier, and nobody could say whether it had been used meanwhile. The finding that mattered wasn't the dormant account; it was that a review built on the assumption provisioning followed the standard process cannot see the accounts that didn't.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
6 sections
- Reference
- CMP-036
- Archetype
- Review
- Record ID
- SAR2-2026-000
- Scoring
- Unjustified access
- Direction
- Low is good
- Singleton
- Yes
- Basis
- ISO 27001 cl.9.2
- Links
- Links Offboarding, Access control
- Tags
- Security, Information
- Sections
- 6
- Fields
- 48
- Follow up fields
- 3
- Repeating sections
- 0
- Links out
- 3
Header
10 fieldsReview ID*
Auto sequence. Format SAR2-2026-000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Date and Time*
Completed By*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Period Reviewed*
Reviewed By*
Systems In Scope*
Administrators Nobody Remembers Appointing
Every access review finds leavers who still have accounts and administrator rights granted for a project that ended years ago.
Process
6 fieldsSystem Owners Confirmed Their Lists*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Every Account Attributed To A Person*
- Yes3 pts
- Partly1 pt
- No0 pts
Shared Accounts Identified*
- Yes3 pts
- Partly1 pt
- No0 pts
Privileged Accounts Identified*
- Yes3 pts
- Partly1 pt
- No0 pts
Service Accounts Reviewed*
- Yes3 pts
- Partly1 pt
- No0 pts
Contractor Accounts Reviewed*
- Yes3 pts
- Partly1 pt
- No0 pts
Findings
6 fieldsLeaver Accounts Still Active*
- Yes3 pts
- Partly1 pt
- No0 pts
Access Beyond Current Role*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Dormant Accounts Identified*
- Yes3 pts
- Partly1 pt
- No0 pts
Privileged Access Justified*
- Yes3 pts
- Partly1 pt
- No0 pts
Segregation Of Duties Maintained*
- Yes3 pts
- Partly1 pt
- No0 pts
Password Policy Enforced*
- Yes3 pts
- Partly1 pt
- No0 pts
Action
6 fieldsUnjustified Access Removed*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Privileged Access Reduced*
- Yes3 pts
- Partly1 pt
- No0 pts
Offboarding Process Reviewed*
- Yes3 pts
- Partly1 pt
- No0 pts
Joiners And Movers Process Reviewed*
- Yes3 pts
- Partly1 pt
- No0 pts
Multi Factor Applied To Privileged Accounts*
- Yes3 pts
- Partly1 pt
- No0 pts
Findings Tracked To Closure*
- Yes3 pts
- Partly1 pt
- No0 pts
Related records
1 fieldSecurity Assessment ID
The risk assessment that set the access requirements.
Links to CMP-035 Assessment ID
Outcome
19 fieldsAccounts Reviewed*
Accounts Removed*
Process Effective*
- Yes3 pts
- Partly1 pt
- No0 pts
Offboarding Working*
- Yes3 pts
- Partly1 pt
- No0 pts
Feeds Management Review*
- Yes3 pts
- Partly1 pt
- No0 pts
Next Review Due*
Items Assessed*
Excludes anything marked N/A.
Items Failed*
Score Percent*
Calculated on submission. High is good. N/A items leave the denominator.
Result Band*
- Pass3 pts
- Caution1 pt
- Fail0 pts
Completeness Percent*
How much of the template was actually answered. A high score on a half completed form is not a high score.
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
IT*
Signature*
Compliance Lead*
Second Signature*
CMP-036 · record IDs look like SAR2-2026-000 · Links Offboarding, Access control
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The form is the easy part. Chasing a real confirmation from system owners, tracing an account back to a contract that ended two cycles ago, and closing the loop into offboarding is the work that actually slips.
Holds the access review register against your systems list, routes each record to its system owner, and keeps the leaver and privileged-access evidence together.
Tracks contractor engagement dates and access grants, closing the gap where a project-scoped administrator account outlives the contract that justified it.
Feeds joiner, mover and leaver events from daily operations into the review, so the account list reflects who currently works there, not last cycle's snapshot.

Chases system owners for an actual confirmation rather than a blanket yes, flags accounts unresolved across two cycles, and holds every write for your approval before it touches a record.
This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.
Meet KnowComply→Glossary
System Access Review definitions and key terms
- Privileged access
- An account with elevated rights beyond standard use, such as administrator, root or configuration access, which most reviews treat as a separate and higher-scrutiny category.
- Dormant account
- An account that still authenticates but has not been used for an extended period, which a review should surface even where no one has left.
- Segregation of duties
- Splitting a sensitive process across two or more people or roles so that no single account can complete it unchecked.
- Service account
- A non-human account used by an application or automated process to authenticate to a system, frequently overlooked because it has no leaving date to trigger a review.
- Leaver account
- An account belonging to someone who has left the organisation or ended a contract; the review's most common and most consequential finding is one still active.
FAQ
Frequently asked questions about system access review
What is the system access review template based on?+
It is built against ISO 27001 Annex A.9.2, user access management, which requires formal registration, periodic review by system owners and prompt removal on leaving. The 2022 revision moved the same requirements into A.5.18 and A.8.2 without changing their substance.
What sections does the system access review contain?+
Six: header, process, findings, action, related records, outcome. Together they hold 48 fields, 43 required, covering leaver, privileged, shared, service and contractor accounts.
How many system access review records should we have?+
This is a singleton: one live record per workspace, updated at each cycle rather than created fresh per event, with the linked security assessment ID carried forward from the risk assessment that set the access requirements.
Which programme does the system access review belong to?+
It is part of Data Protection and Information Security, alongside the processing register, impact assessments, breach response and backup testing. Monitoring was introduced with consultation, and backups are proven by restoring them.
How is a system access review scored?+
The headline metric is unjustified access, where low is good. The underlying process fields score Yes as good because they measure whether the review was done properly, which is a different, correctly-scored question.
Can the system access review template be changed?+
Yes. Every field, option, score and conditional rule is editable, and links to other templates come with it. Most teams install it as it is, run it for a cycle, then adjust the cadence or account categories to match what they actually run.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Data Protection and Information Security
Personal Data Processing Record
Records what personal data the organisation holds, why, on what basis and for how long
Data Protection Impact Assessment
Assesses the privacy impact of a new system or monitoring activity before it is introduced
Data Breach Record
Records loss, exposure or unauthorised access to personal data, with the assessment of harm and notification decision
Subject Access Request Record
Records a request from an individual for the data held about them, and how it was answered within the deadline
Information Security Risk Assessment
Assesses threats to systems, data and operational technology, including plant control systems
Cyber Incident Record
Records a cyber event affecting systems, data or plant operation, with containment, recovery and notification
More in Information Security
Information Security Risk Assessment
Assesses threats to systems, data and operational technology, including plant control systems
Cyber Incident Record
Records a cyber event affecting systems, data or plant operation, with containment, recovery and notification
Backup and Recovery Test Record
Records a test that backups can actually be restored, not merely that they ran

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO/IEC 27001:2013 Annex A.9.2 — User access management
- ISO/IEC 27001:2022 Annex A.5.18 and A.8.2 — Access rights and privileged access rights
- SOC 2 Trust Services Criteria CC6.1–CC6.3 — Logical access controls
- UK GDPR Article 5(1)(f) — Integrity and confidentiality (security)
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.