Skip to main content
Category: Identity & Access Management

Access Review

Also known as: Access Certification, Access Recertification, User Access Review, Entitlement Review
Simply put

An access review is a process in which an organization examines who has access to its systems, data, and applications to confirm that each person still needs that access. It helps reduce the risk of unauthorized access by identifying and removing permissions that are outdated, excessive, or no longer appropriate. Reviews are often performed periodically and can support broader governance and compliance goals.

Formal definition

An access review is a structured security and governance process for monitoring, assessing, and validating user access privileges and entitlements across systems, groups, and applications. Reviewers, often resource owners, managers, or governance stakeholders, certify or revoke access to enforce least-privilege and to control group membership and application access. In platforms such as Microsoft Entra ID Governance, access reviews can be configured to review group members, application assignments, and guest user access, with reviewers certifying whether continued access is warranted. As a governance and risk-management control, access reviews support but do not by themselves guarantee compliance; their effectiveness depends on review scope, cadence, reviewer diligence, and the quality of underlying identity data. In a virtual CISO engagement, the vCISO typically advises on and helps design access review programs and policies, while operational execution and accountability for access decisions generally remain with the client organization and its resource owners.

Why it matters

Over time, the access rights granted to employees, contractors, and guest users tend to accumulate faster than they are removed. People change roles, projects end, and third-party relationships wind down, yet the permissions granted for those situations often persist. Access reviews exist to counter this drift by periodically confirming that every entitlement still corresponds to a legitimate business need. Without this discipline, organizations gradually build up excessive and outdated access that widens the attack surface and increases the impact of a compromised account.

Access reviews are a core control for enforcing least-privilege and for controlling group membership and application access. As Microsoft's guidance on Entra ID Governance notes, reviews can be used to certify guest user access to groups and to control group membership and application access in support of governance, risk management, and compliance goals. This matters both for internal risk reduction and for demonstrating to auditors and stakeholders that access is being actively governed rather than left to chance. However, an access review is a supporting control, not a guarantee: its value depends on the scope reviewed, the cadence, the diligence of the reviewers, and the quality of the underlying identity data.

It is worth emphasizing what access reviews do not do on their own. They do not prevent breaches by themselves, and a completed review does not certify that an organization is compliant with any given regulation or standard. A review that is rubber-stamped without genuine scrutiny, or that omits critical systems, can create a false sense of assurance. The control is only as strong as the accountability and follow-through behind it, and accountability for access decisions remains with the organization and its resource owners.

Who it's relevant to

Security and Governance Leaders
CISOs, virtual CISOs, and identity governance leads use access reviews as a central control for enforcing least-privilege and controlling group membership and application access. In a virtual CISO engagement, the vCISO typically advises on and helps design the access review program, policy, scope, and cadence, while operational execution and accountability for the actual access decisions remain with the client organization and its resource owners.
Resource Owners and Managers
Because reviewers are often resource owners or managers, these individuals carry much of the practical weight of an access review. They are the ones certifying or revoking access based on whether continued access is warranted, so their diligence directly determines whether the review meaningfully reduces unauthorized-access risk or merely produces a paper trail.
Compliance, Audit, and Risk Functions
Teams responsible for governance, risk management, and compliance rely on access reviews to demonstrate that access is being actively validated. These stakeholders should understand that reviews support compliance and audit objectives but do not by themselves guarantee compliance with any specific framework or regulation; the outcome depends on scope, cadence, reviewer diligence, and the quality of the underlying identity data.
IT and Identity Administrators
Administrators who operate platforms such as Microsoft Entra ID Governance configure access reviews to cover group members, application assignments, and guest user access, and then implement the certify-or-revoke decisions returned by reviewers. Their work maintaining accurate identity data is what makes reviews trustworthy in the first place.

Inside Access Review

Entitlement Inventory
A compiled list of who holds access to which systems, applications, data stores, and privileged accounts. An access review depends on this inventory being reasonably complete and current; gaps in the inventory directly limit the review's reliability.
Reviewer Assignment
The designation of who is responsible for validating each access grant, typically the resource owner, data owner, or line manager. A virtual CISO often advises on this governance structure but generally does not perform the line-by-line certification personally unless explicitly contracted.
Certification or Attestation
The documented act of a reviewer confirming that a given access grant remains appropriate, or flagging it for revocation. This produces the evidence trail relied upon during audits for frameworks such as SOC 2 and ISO 27001.
Remediation Workflow
The process for acting on review outcomes, including removing or adjusting access that is no longer justified. A review without follow-through on flagged items provides limited assurance value.
Review Cadence and Trigger Events
The schedule (for example, periodic reviews) and the event-based triggers (such as role changes, transfers, or terminations) that prompt a review. Cadence often varies by provider, engagement scope, and the sensitivity of the systems involved.
Scope Definition
The explicit boundary of which systems, user populations, and access types are in scope for a given review cycle. Clear scope is essential because a vCISO typically directs and governs the review rather than administering the underlying tools.

Common questions

Answers to the questions practitioners most commonly ask about Access Review.

Does a virtual CISO perform the access review themselves?
Typically no. A virtual CISO generally defines the policy, governance framework, and cadence for access reviews and advises on how they should be conducted, but the hands-on execution, pulling access lists, validating entitlements, and administering identity tools, is usually an operational task owned by internal IT, identity, or security operations teams. In many engagements this hands-on work falls outside a vCISO's scope unless it is explicitly contracted. Treating a vCISO as the person who clicks through user accounts often reflects a misunderstanding of the role as governance and oversight rather than operational execution.
If a vCISO oversees access reviews, are they accountable when inappropriate access leads to a problem?
Not usually. A virtual CISO advises on and can direct the access review process, but legal and organizational accountability for access decisions typically remains with the client organization and its officers. The vCISO helps ensure reviews happen, are documented, and align with policy, yet the responsibility for granting, approving, and revoking access, and the accountability for the outcomes, generally stays with the accountable data or system owners and management. This distinction should be clarified in the engagement contract, since a vCISO does not assume regulatory or legal liability unless a contract specifies it.
How often should access reviews be performed?
The cadence often varies by organization, system sensitivity, and applicable requirements, so a fixed universal frequency is not appropriate. In many engagements a virtual CISO helps the organization define a risk-based schedule, for example, more frequent reviews for high-privilege or sensitive-data access and less frequent reviews for lower-risk systems. The right cadence also depends on organizational maturity, the availability of accurate access data, and stakeholder cooperation, all of which affect how practical a given schedule is.
What frameworks or requirements typically shape how access reviews are structured?
Access reviews are commonly informed by frameworks and standards such as NIST CSF, ISO 27001, SOC 2, and requirements associated with HIPAA, PCI DSS, or similar regimes, which address access control and periodic review of entitlements. A virtual CISO can help map an organization's access review process to the relevant control expectations to support readiness. It is important to note that aligning reviews to these frameworks supports compliance and audit readiness but does not by itself guarantee certification or a compliant outcome, which depends on broader controls and evidence.
Who should be involved in an access review, and what does the vCISO coordinate?
Effective access reviews typically involve system or data owners who can validate whether access is still appropriate, IT or identity administrators who provide the access data and implement changes, and sometimes HR to confirm role changes or departures. A virtual CISO often coordinates this process by defining roles, ensuring reviewers understand what they are attesting to, and confirming that decisions are documented. The value of this coordination depends heavily on stakeholder cooperation and the vCISO's access to the right people and data.
What documentation should come out of an access review?
In many engagements the review should produce evidence of who reviewed access, what was reviewed, what decisions were made, and what remediation actions followed, such as removing or adjusting entitlements. A virtual CISO can advise on maintaining this documentation so it supports audit and compliance readiness. The quality of this evidence often depends on the accuracy of the underlying access data and the discipline of the reviewers, which is why a vCISO frequently emphasizes reliable data sources and clear approval trails.

Common misconceptions

A virtual CISO personally performs the access review by examining every entitlement in each system.
Access review is generally a governance and program function for a vCISO. In many engagements the vCISO designs the review process, defines cadence, and oversees outcomes, while resource owners and operational staff perform the hands-on certification and revocation. Direct tool administration is typically out of scope unless the contract specifies it.
Completing an access review guarantees compliance or certification under frameworks like SOC 2, ISO 27001, or HIPAA.
An access review can support readiness and provide evidence relevant to these frameworks, but it does not by itself assert or guarantee certification. Certification depends on the full control environment, auditor assessment, and factors beyond any single control. A vCISO supports readiness rather than warranting a compliance outcome.
Once an access review is complete, the organization has assurance until the next scheduled cycle.
Access drifts continuously as roles change and people join or leave. Periodic reviews provide point-in-time assurance and are often supplemented by trigger-based reviews. The value of any review also depends on organizational maturity, client cooperation, and the accuracy of the underlying entitlement inventory.

Best practices

Define and document the scope of each review cycle explicitly, stating which systems, user populations, and access types are included and which are deliberately excluded.
Assign certification responsibility to the appropriate resource, data, or business owners rather than centralizing it, so those best positioned to judge appropriateness make the call.
Pair periodic reviews with trigger-based reviews for role changes, transfers, and terminations to reduce access drift between scheduled cycles.
Ensure a remediation workflow is in place so that flagged access is actually revoked or adjusted, and track closure of those items as part of the evidence trail.
Verify and improve the completeness of the underlying entitlement inventory before relying on review results, since gaps in the inventory undermine the assurance the review provides.
Clarify in the engagement scope whether the vCISO is governing the review process or performing hands-on certification, and confirm that legal and organizational accountability for access decisions remains with the client organization and its officers unless the contract states otherwise.