Skip to main content
Category: Access and Identity Management

Access Rights Review

Also known as: UAR, User Access Review, Access Review, User Access Review Verification, Access Rights Verification
Simply put

An access rights review is a periodic check of who has access to an organization's systems and data, confirming that each person's permissions are still appropriate for their role. It helps ensure that only authorized individuals can reach key systems and that access no longer needed is removed. Organizations typically use it to support governance, risk management, and compliance efforts.

Formal definition

An access rights review (commonly called a user access review, or UAR) is a formal, periodic process in which user permissions across systems, applications, and data are evaluated to confirm they are appropriate, necessary, and aligned with each user's current role and the principle of least privilege. In practice, reviewers validate group membership and application access, identify and remediate excessive, stale, or orphaned entitlements, and document the review as evidence. In compliance engagements, such reviews are frequently relied upon to demonstrate logical access controls, for example, supporting the SOC 2 Security (Common Criteria) category or ISO/IEC 27001 access control objectives selected via the Statement of Applicability, though the specific frequency, scope, and evidentiary expectations vary by auditor, certification body, and defined scope.

Why it matters

Access rights tend to accumulate over time. As people change roles, join new projects, or leave the organization, the permissions they were granted often persist longer than the business need that justified them. Without a periodic check, this leads to excessive, stale, or orphaned entitlements, access that no longer maps to any legitimate role. An access rights review is the control that surfaces and corrects these drift conditions, helping ensure that only authorized individuals can reach an organization's key systems and data.

Beyond day-to-day hygiene, access rights reviews are a common focus of compliance engagements. In a SOC 2 examination, they frequently serve as evidence supporting the Security (Common Criteria) category's logical access controls, while under ISO/IEC 27001 they can support access control objectives selected through the Statement of Applicability. Because these are attestation and certification frameworks respectively, reviewers typically expect not just that access is appropriate but that the review itself is documented and repeatable. The specific frequency, scope, and evidentiary expectations vary by auditor, certification body, and defined scope.

It is worth noting the limits of the control. An access rights review confirms that permissions align with roles at the point the review is performed; it does not by itself prevent misuse of legitimately held access, nor does it guarantee freedom from breaches. Its value lies in reducing the standing attack surface and demonstrating governance, and it is most effective when combined with least-privilege provisioning and timely deprovisioning rather than treated as a standalone safeguard.

Who it's relevant to

Compliance and GRC managers
Access rights reviews are a recurring control that GRC teams rely on to demonstrate logical access governance. Depending on scope, the same review activity can support the SOC 2 Security (Common Criteria) category and ISO/IEC 27001 access control objectives selected via the Statement of Applicability, though satisfying one framework does not automatically satisfy the other and the evidentiary expectations differ.
Auditors and assessors
For a CPA firm performing a SOC 2 examination or a certification body assessing an ISMS, documented access reviews are a common source of evidence for logical access controls. Assessors typically evaluate whether reviews were performed at an appropriate cadence, covered the intended systems, and resulted in remediation of inappropriate access, recognizing that expectations vary by engagement and defined scope.
Security engineers and IT administrators
Those who provision and manage identities are often responsible for producing the entitlement data reviewed and for executing remediation, such as removing orphaned or excessive access. Where identity governance tooling is available, they may automate parts of the review, but the underlying goal remains enforcing least privilege across systems and applications.
System and data owners
Business owners are frequently asked to attest that the access to their systems or datasets remains appropriate for each user's current role. Their role-level knowledge is central to distinguishing legitimate access from access that should be revoked, making them key participants in most review cycles.

Inside UAR

Periodic Review of User Entitlements
A recurring examination of which users hold which access rights across in-scope systems, applications, and data stores, comparing granted permissions against current job responsibilities to identify entitlements that are no longer appropriate.
Reviewer and Approver Assignment
Designation of the individuals responsible for evaluating access, typically system owners, data owners, or line managers who have sufficient context to judge whether an entitlement remains justified. The specific roles and approval hierarchy vary by organization and scope.
Privileged and Administrative Access Coverage
Particular attention to elevated or administrative accounts, which generally warrant closer scrutiny because of the greater impact of inappropriate access. The extent of coverage depends on scoping decisions.
Evidence and Documentation
Records demonstrating that the review occurred, who performed it, what was examined, the outcome, and any remediation actions taken. Such artifacts support both SOC 2 examinations and ISO 27001 certification assessments as evidence of operating effectiveness.
Remediation Workflow
The process for acting on findings, such as revoking or modifying access that is no longer warranted, and tracking those changes through to completion. Timeliness expectations depend on organizational policy and the assessor's judgment.
Framework Mapping
In a SOC 2 examination, access rights review typically supports controls addressed under the Security category (the Common Criteria). Under ISO/IEC 27001, it relates to Annex A reference controls concerning access, which are selected via the Statement of Applicability and informed by risk assessment. The specific control references depend on the applicable criteria and the Annex A version in effect.

Common questions

Answers to the questions practitioners most commonly ask about UAR.

Does passing a SOC 2 examination that includes access rights review certify that our access controls are compliant?
No. SOC 2 is an attestation examination performed by a licensed CPA firm under the AICPA SSAE 18 standard, resulting in a report rather than a certification. A SOC 2 report attests only to the controls and the period covered, so it reflects the auditor's opinion on the access rights review controls in scope but does not issue a certificate or guarantee that access is free from misuse or breach.
Is access rights review a specific mandatory control found identically in both SOC 2 and ISO 27001?
Not in an identical form. Access rights review relates to the Security category (the Common Criteria) under the SOC 2 Trust Services Criteria and to Annex A reference controls under ISO/IEC 27001, but these are distinct structures and should not be conflated. Under ISO 27001, Annex A controls are reference controls selected via the Statement of Applicability and informed by risk assessment, while the certifiable requirements sit in clauses 4 through 10. Mapping between the two frameworks is possible but partial, and addressing access review under one does not automatically satisfy the other.
How often should access rights reviews be performed?
The frequency typically depends on scope, risk assessment, and the expectations of the auditor or certification body rather than a single fixed interval. In most engagements, organizations define a review cadence in their own policies and demonstrate that they follow it consistently. Because the appropriate frequency varies with the sensitivity of the systems and data involved, it is best set through scoping and risk decisions rather than assumed to be universal.
What evidence is typically expected to demonstrate that access rights reviews occurred?
Evidence expectations vary by auditor, certification body, and scope, but organizations commonly retain records showing that reviews were performed, who performed them, what was examined, and what remediation followed. In a SOC 2 Type II examination, which assesses both design and operating effectiveness over a defined review period, evidence typically needs to show the control operated consistently across that period, whereas a Type I assesses the suitability of design at a point in time.
Who should perform and approve access rights reviews?
Responsibility is typically defined within the organization's own policies and depends on scope. In most engagements, reviews involve individuals with sufficient knowledge of the systems and appropriate authority to confirm or revoke access, such as system owners or managers, with independence from the access being reviewed where practical. Because requirements depend on the auditor, certification body, and applicable criteria, the specific roles should be established through scoping rather than assumed.
How does access rights review relate to the boundaries of a SOC 2 report or an ISO 27001 certificate?
A SOC 2 report attests only to the controls and period covered, so access rights review is relevant only insofar as it falls within the defined scope and applicable Trust Services Criteria. Similarly, an ISO 27001 certificate covers only the defined scope of the ISMS, so access review controls are addressed to the extent the Statement of Applicability and risk assessment bring them into scope. Neither outcome extends assurance to systems, populations, or periods outside those defined boundaries.

Common misconceptions

Completing access rights reviews means the same evidence automatically satisfies both SOC 2 and ISO 27001.
Mapping between the two frameworks is possible but partial. A SOC 2 report is an attestation examination performed by a licensed CPA firm under SSAE 18, while ISO/IEC 27001 is a certification issued by an accredited certification body against a management system standard. The same review activity may support both, but satisfying one framework does not automatically satisfy the other, and each assessor evaluates evidence against its own criteria.
There is a single mandatory frequency for access rights reviews.
Neither framework prescribes one universal interval that applies to every organization. Review frequency typically depends on scope, risk assessment, organizational policy, and the assessor's or certification body's expectations, and often varies by system sensitivity, with privileged access commonly reviewed more often.
A clean access rights review guarantees that no unauthorized access has occurred.
A review attests only to the controls and, for a SOC 2 Type II, the period examined. It does not guarantee freedom from breaches or misuse outside what was assessed. It provides assurance about the design and, where applicable, operating effectiveness of the reviewed controls, not an absolute assurance of security.

Best practices

Define and document a review cadence driven by risk assessment, reviewing privileged and administrative accounts more frequently than standard user accounts where warranted by scope.
Assign reviews to owners with sufficient context, typically system, data, or line managers, so that access decisions are made by those able to judge whether an entitlement remains justified.
Retain clear evidence for each review cycle, including who reviewed, what was examined, the outcome, and remediation taken, so the activity can support both SOC 2 examination and ISO 27001 certification assessment.
Establish a tracked remediation workflow to revoke or adjust inappropriate access and confirm completion, rather than treating identification of an issue as the end of the process.
Reconcile granted entitlements against current job responsibilities and promptly address access left over from role changes, transfers, or departures.
Confirm how the review maps to the applicable criteria, the SOC 2 Common Criteria for Security and the relevant ISO 27001 Annex A reference controls in the version in effect, recognizing the mapping is partial and framework-specific.