Skip to main content
Category: Access and Identity Management

User Lifecycle Management

Also known as: ULM, Identity Lifecycle Management, ILM, Joiner-Mover-Leaver process, JML
Simply put

User Lifecycle Management is the process of managing a user's access to systems from the moment they join an organization through any role changes until they leave. It covers setting up new accounts with the right permissions, updating those permissions when a person's role changes, and removing access when they depart. Many organizations use automation to handle these steps consistently across the tools employees use.

Formal definition

User Lifecycle Management (ULM), also referred to as Identity Lifecycle Management (ILM), is the framework for provisioning, modifying, and deprovisioning digital identities and their associated entitlements across the Joiner, Mover, and Leaver (JML) stages. It typically encompasses account creation and initial privilege assignment at onboarding, access recertification and entitlement adjustment upon role or department changes, and timely revocation of access at offboarding. In many enterprise environments these processes are automated through IAM tooling to enforce consistent access control and reduce residual or excessive privileges. In a compliance context, ULM controls commonly support access-related objectives; for example, they can provide evidence relevant to the SOC 2 Security (Common Criteria) logical access requirements and to ISO/IEC 27001 access control objectives, though the specific controls in scope depend on the engagement, applicable criteria, and defined ISMS scope.

Why it matters

User Lifecycle Management addresses one of the most persistent sources of access-related risk: the gap between what access a person needs and what access they actually hold. When accounts are created without disciplined privilege assignment, when entitlements accumulate as people move between roles, or when access lingers after someone departs, organizations are left with residual or excessive privileges that expand the potential attack surface. Timely deprovisioning at offboarding is a particularly common weak point, since a departed employee or contractor whose access is not revoked can represent an unmonitored pathway into systems.

Who it's relevant to

Compliance and GRC Managers
ULM controls commonly support access-related objectives that appear in both SOC 2 and ISO 27001 engagements. GRC professionals rely on documented Joiner-Mover-Leaver processes to demonstrate that access is granted, modified, and revoked in a controlled way, while recognizing that the specific controls in scope depend on the applicable criteria and defined scope.
Auditors and Assessors
For a SOC 2 examination, ULM processes can provide evidence relevant to the Security (Common Criteria) logical access requirements, and for ISO/IEC 27001 they can support access control objectives. In a SOC 2 Type II engagement, auditors typically examine operating effectiveness over the defined review period, which makes consistent, repeatable ULM evidence particularly valuable.
Security Engineers and IAM Administrators
Those who implement and maintain IAM tooling handle the provisioning, modification, and deprovisioning of identities and entitlements across the JML stages. Automation helps them apply access decisions consistently across the tools employees use and reduce residual or excessive privileges.
IT Operations and Help Desk Teams
These teams often execute onboarding and offboarding tasks and coordinate access changes when people move roles. Clear ULM processes reduce the inconsistency that can arise from manual handling and support the timely revocation of access at departure.

Inside ULM

Provisioning (Joiner)
The process of creating user identities and granting initial access rights when an individual joins the organization or takes on a new role. Access is typically granted based on role, job function, or documented approval, and often aligns with the principle of least privilege depending on scope.
Access Modification (Mover)
The adjustment of a user's access entitlements when their role, department, or responsibilities change. This typically involves removing access that is no longer needed and granting new access appropriate to the changed role, helping to prevent privilege accumulation over time.
Deprovisioning (Leaver)
The timely removal or disabling of user access when an individual leaves the organization or no longer requires access. In most engagements, auditors examine the timeliness of termination-related access removal as evidence of control operating effectiveness.
Access Reviews / Recertification
Periodic reviews in which access rights are re-evaluated by appropriate personnel to confirm they remain appropriate. The frequency and scope of these reviews are typically set by organizational policy and risk considerations rather than a single fixed rule.
Authentication and Credential Management
The controls governing how user credentials are issued, maintained, and retired, including password requirements and multi-factor authentication where applicable. The specific mechanisms depend on scope, applicable criteria, and risk assessment.
Role and Entitlement Definition
The definition of roles, groups, or entitlements that determine what access is appropriate for a given function. This underpins consistent provisioning and modification decisions across the lifecycle.

Common questions

Answers to the questions practitioners most commonly ask about ULM.

Does implementing user lifecycle management mean my organization automatically satisfies both SOC 2 and ISO 27001 access control requirements?
No. User lifecycle management supports access-related criteria in both frameworks, but satisfying one framework does not automatically satisfy the other. In a SOC 2 examination, user provisioning, review, and deprovisioning practices are evaluated as controls mapped to the Security (Common Criteria) category, while in ISO 27001 they typically relate to Annex A reference controls selected via the Statement of Applicability and to the ISMS requirements in clauses 4 through 10. Mapping between the two is possible but partial, and each engagement or certification assesses these controls on its own terms, based on the auditor, certification body, and defined scope.
If a SOC 2 report shows our user lifecycle controls are in place, does that guarantee no unauthorized access occurred?
No. A SOC 2 report attests only to the controls and the period covered by the examination. A Type I report addresses the suitability of design of user lifecycle controls at a point in time, while a Type II report addresses both design and operating effectiveness over a defined review period whose length is set by scoping decisions. Neither report guarantees freedom from unauthorized access or breaches; it provides assurance about the controls examined, not an absolute assurance of security outcomes.
How should user lifecycle management be scoped for a SOC 2 examination?
Scoping is determined in consultation with the CPA firm performing the examination and depends on which Trust Services Criteria categories are in scope. Security is always included as the Common Criteria, so access provisioning and deprovisioning practices are typically relevant in most engagements. If categories such as Confidentiality or Privacy are selected, lifecycle controls governing access to the relevant data may also come into scope. The systems, applications, and personnel populations covered should be defined clearly, since the report attests only to what is within the stated boundaries.
What documentation typically supports user lifecycle management during an audit or certification assessment?
Auditors and certification bodies commonly look for evidence such as provisioning and deprovisioning records, access request approvals, periodic access reviews, and records tied to joiner-mover-leaver events. In an ISO 27001 context, the treatment of these controls is typically documented through the Statement of Applicability and informed by the organization's risk assessment. The specific evidence expected varies by the auditor, certification body, scope, and applicable criteria rather than following a single fixed checklist.
How frequently should access reviews within user lifecycle management be performed?
There is no universally mandated frequency; review cadence depends on the organization's risk assessment, scope, and the expectations agreed with the auditor or certification body. In most engagements organizations define a periodic review schedule and demonstrate that reviews were performed consistently across the review period, which for a SOC 2 Type II examination is a defined period set by scoping decisions. Documenting a defined cadence and showing it was followed is typically more important than any specific interval.
How does user lifecycle management differ between the SOC 2 and ISO 27001 frameworks in practice?
The underlying activities, granting, modifying, and removing access as personnel and roles change, are similar, but the frameworks evaluate them differently. Under SOC 2, these controls are assessed as part of an attestation examination against the Trust Services Criteria, with the Security category always applicable. Under ISO 27001, they are addressed within the ISMS requirements and through Annex A reference controls selected via the Statement of Applicability, with control selection informed by risk. Because the frameworks structure and reference these controls distinctly, organizations pursuing both typically map their lifecycle processes to each framework's requirements separately rather than assuming direct equivalence.

Common misconceptions

A SOC 2 report or an ISO 27001 certificate proves that user lifecycle controls have never failed or that no unauthorized access has ever occurred.
A SOC 2 report attests only to the controls and the review period covered and does not guarantee freedom from control exceptions or breaches. Similarly, an ISO 27001 certificate covers only the defined scope of the ISMS. Evidence of a control operating effectively over a period is not a guarantee of perfection.
Meeting user lifecycle requirements for one framework automatically satisfies the other.
Mapping between SOC 2 (Trust Services Criteria, with the Security/Common Criteria being the only required category) and ISO 27001 (ISMS requirements in clauses 4 through 10, with reference controls selected via the Statement of Applicability) is possible but partial. Satisfying access management expectations under one framework does not automatically satisfy the other, as the criteria, scope, and evidence expectations differ.
There is a single mandatory frequency or method for access reviews and deprovisioning that applies to every organization.
Compliance outcomes depend on the auditor or certification body, the defined scope, risk assessment, and applicable criteria. In most engagements, review frequency and deprovisioning timeliness are set by organizational policy informed by risk rather than by a universal fixed standard.

Best practices

Document formal joiner, mover, and leaver procedures with defined approval steps, and retain evidence of approvals so that control design and operation can be examined during a SOC 2 Type II period or an ISO 27001 audit.
Grant access based on role and least privilege where feasible, and remove access that is no longer needed during role changes to limit privilege accumulation.
Establish timely deprovisioning triggered by termination or role change, and retain records demonstrating the timeliness of access removal, since this is commonly examined by auditors.
Conduct periodic access reviews or recertifications at a frequency informed by your risk assessment and organizational policy, and document the outcomes and any remediation.
Align user lifecycle controls to your defined scope and applicable criteria, and where you pursue both SOC 2 and ISO 27001, maintain a mapping while recognizing it is only partial.
Retain sufficient evidence throughout the review period rather than assembling it at audit time, so that both suitability of design and operating effectiveness can be demonstrated.