BG Beter Geregeld ICT
Access reviews · 2 min leestijd · 18 November 2025 · ★ Pillar-gids

Periodic access reviews: process, frequency, and audit evidence

An access review is an audit requirement that nearly every SMB struggles with. Once you set it up properly the first time, the second round won't cost you a whole week.

Access reviews — periodically checking who has access to what and why — are not optional under ISO 27001 Annex A.9. Even without audit pressure, they're the only reliable way to keep your access matrix up to date.

\n\n

Frequency: quarterly or twice a year

\n

The SMB standard: quarterly. Fewer than 20 people and low staff turnover? Every six months is also acceptable. Annual reviews are not sufficient for ISO purposes. See also ISO 27001 Annex A.9.

\n\n

The six steps

\n
    \n
  1. Snapshot. Freeze a copy of the current matrix.
  2. \n
  3. Define scope. See defining your scope.
  4. \n
  5. Decide row by row. Keep, revoke, or change. Involve line managers — see involving managers.
  6. \n
  7. Bulk decisions for clear-cut cases. 80% will be "keep". See bulk decisions.
  8. \n
  9. Follow-up actions. Every "revoke" and "change" becomes a concrete task for IT.
  10. \n
  11. Retain evidence. See audit evidence.
  12. \n
\n\n

Common pitfalls

\n
    \n
  • "There's never enough time." Block it in Outlook — otherwise it simply won't happen.
  • \n
  • Review done by a single person. The risk: most of their own access gets rubber-stamped without scrutiny.
  • \n
  • Decisions that never get actioned. A revoke on paper is worthless.
  • \n
\n\n

Automation

\n

Our AccessGuard tool generates a review snapshot in a single click. The demo walks through a live review cycle.

\n\n

See also: quarterly cadence, AI in access reviews, sample-based vs. full review.

Onderwerpen

#governance #access-review #audit #iso-27001

Volledige gids: Revisiones de acceso periódicas: proceso, frecuencia y evidencia

Dit artikel is onderdeel van onze uitgebreide Access reviews-gids. Lees de pillar voor het complete plaatje.

Lees de pillar →