Access reviews that pass an ISO 27001 audit
By Sam Rivera, Founder, SentinelPanda · June 17, 2026 · 2 min read · ISO 27001
Access creep is the most common audit finding there is. A repeatable review closes it — and one record satisfies four frameworks.
Why access reviews fail audits
People change roles and accumulate access; offboarding misses a system; a contractor’s account outlives the contract. The result is access creep — privileges that no longer match need. ISO 27001 Annex A 5.18 (access rights) and 8.2 (privileged access) exist precisely to catch it, as do PCI Requirement 7 and SOC 2 CC6. The control is not "grant access correctly once"; it is "review it on a schedule."
What a review must cover
- Every system in scope, mapped to an owner who can judge whether access is still appropriate.
- Joiners, movers, and leavers since the last review — especially role changes.
- Privileged / admin accounts, reviewed more frequently than standard ones.
- Service and machine accounts, which are routinely forgotten.
- Dormant accounts flagged for disablement.
Make the evidence fall out of the process
Auditors want to see who performed the review, what they looked at, what they changed, and when — signed off. If the review happens in a spreadsheet emailed around, that evidence is fragile. Run it as a tracked task with the reviewer, date, scope, and outcomes recorded, and the audit artifact is a by-product of doing the work.
One review, four frameworks
A single quarterly access review, properly recorded, is creditable evidence for ISO 27001, PCI DSS, SOC 2, and HIPAA simultaneously. Collect it once and map it across — the second framework should cost almost nothing.