Nowadays, almost everything is moving online — from banking to HR, from CRM to Teams. The question of who has access to what becomes one of the most important and most ignored issues within companies.
That’s where user access review procedures come in: a simple, repeatable, and auditable process to ensure that only the right people have the right permissions for the right amount of time.
Conducting an effective user access review is essential to identify and mitigate risks such as privilege creep, misuse, and unauthorised access, with periodic access reviews recognised as a best practice.
Would your company survive unauthorised access?
A professional services company thought it was okay. MFA active, antivirus installed, backups up to date. The problem arose months later when a former employee still had access to customer folders in Microsoft 365.
This highlights the importance of regularly reviewing user access rights and promptly revoking access for former employees or third parties to maintain security and compliance. Implementing a user access review (UAR) procedure — a formal, periodic process for reviewing and updating user permissions — ensures that only authorised users retain access.
Many data breaches trace back to access that was never revoked or reviewed; user access reviews help identify discrepancies and revoke access that is no longer needed, minimising the attack surface that could be exploited by malicious actors.
A single valid login was enough to copy sensitive information, trigger an internal investigation, involve lawyers, and consume weeks of operational time. Many incidents do not start with something dramatic. They start with forgotten permissions, old accounts, accumulated groups, and flawed leaver processes.
Why access reviews matter so much in the UK
The British landscape remains hostile and very noisy. In the UK government’s Cyber Security Breaches Survey 2025, 43% of companies reported having identified an attack or breach in the last 12 months. Among companies that have suffered incidents, phishing remains the most common type.
Successful phishing often becomes legitimate access through stolen credentials. If your environment tolerates broad permissions, unowned accounts, and scattered admin rights, attackers don’t need to break in — they just log in.
That’s why regular user access reviews are essential: they reduce privilege creep, limit insider risk (including disgruntled former employees), and support compliance requirements such as PCI DSS.
What is a user access review procedure?
It is not a nice document to keep in a drawer. It is an operational cycle that allows you to answer, at any time:
-
Who has access to this data/system?
-
Is this access justified and proportionate?
-
Who approved it, and when was the last review?
In operation, the user access review process typically combines a user access audit or access surveys (by system and by data), validation with those responsible, remediation (removal/adjustment), and recording of evidence for auditing and continuous improvement.
Using a user access review template can help standardise and streamline the process, ensuring all necessary steps are covered. Automation tools for user access reviews can generate regular reports, send reminders, and flag unusual access patterns to enhance efficiency and security.
An access control matrix is often used to map users against the resources they can access, specifying the type of access each user has. Documenting each step of the user access review process is crucial for compliance and for identifying bottlenecks in the review process.
Key stakeholders in access reviews
Effective access reviews rely on the involvement of key stakeholders across the organisation. IT teams generate user access reports, manage access controls, and implement any required changes.
Department managers and business owners review permissions for their teams, confirming that only authorised personnel have the access needed for their roles. HR provides up-to-date employee status information — such as new starters, role changes, and leavers — which is essential for keeping access accurate.
Compliance and security teams oversee governance, ensuring the review meets regulatory requirements and internal policies. In some cases, external auditors may also be involved to independently validate the effectiveness of the review. With these stakeholders engaged, access reviews are more likely to be thorough, accurate, and aligned with both business needs and regulatory expectations.
More than a password: Access is identity, function, and evidence
Password management is important, but it does not solve the essential issue of access governance. A good user access review procedure is a structured, multi-step process that involves auditing and managing user permissions and user access rights to ensure compliance and security.
It should also include the definition and enforcement of access control policies to govern user permissions and access rights across the organisation. Involving data owners or managers, as well as multiple stakeholders such as IT teams and department managers, is crucial to ensure accurate assessments and prevent ‘rubber stamping’.
Documenting each step of the user access review process is essential for compliance and for identifying bottlenecks or areas for improvement. With that in mind, focus on:
Identity: active accounts, service accounts, third-party accounts, orphan accounts.
Function: permissions aligned with job role (RBAC), temporary access when necessary.
Evidence: audit trail (who reviewed, when, what was removed, and why).
This directly addresses what the NCSC reinforces in basic controls such as separation of administrative accounts and MFA, especially for sensitive access and cloud services.
User access data and audit: what to track and why it matters
Tracking user access data is fundamental to strong access controls and effective risk management. Organisations should keep detailed records of who can access which systems, applications, and sensitive data, along with the permissions assigned to each account.
It’s also important to log changes to those permissions — additions, removals, and modifications — so inappropriate or unnecessary access can be spotted early, before it contributes to a breach or insider misuse.
Regular audits help confirm that access remains aligned with job needs and support compliance with requirements such as GDPR and HIPAA by evidencing that protected information is restricted to authorised users. With consistent monitoring and auditing, organisations can detect and remediate risks quickly, keeping access appropriate and up to date.
Role-based access control (RBAC) for small businesses
Role-based access control (RBAC) is a practical, efficient way for small businesses to manage access and reduce security risk. Permissions are assigned by job function, so employees receive only what they need to do their work. This simplifies day-to-day administration — supporting onboarding, role changes, and timely access removal when someone leaves.
RBAC also helps prevent privilege creep, where users gradually accumulate excessive permissions, and reduces the likelihood of unauthorised access to sensitive data. Automated tools can streamline implementation and ongoing maintenance, helping small businesses strengthen controls and support compliance requirements without adding unnecessary complexity.
Best practices for user access reviews
To maintain strong access controls and protect sensitive data, organisations should follow best practices for user access reviews. Begin with a clear cadence: run reviews quarterly or six-monthly for critical systems, and at least annually for others. Involve key stakeholders — IT, department managers, HR, and compliance — to ensure decisions reflect both operational needs and policy requirements.
Use automation where possible to streamline the process and reduce manual errors. Apply role-based access control (RBAC) and the principle of least privilege, granting only the access required for each role.
Document the review thoroughly, including changes made and the rationale for granting or revoking permissions; this is essential for audit readiness and for investigating security incidents. Done consistently, access reviews reduce security risk, help prevent breaches caused by unnecessary permissions, and support compliance with regulations such as GDPR, HIPAA, and PCI DSS.
Be aware of three silent villains
Excessive access (privilege creep)
People change roles, join projects, get exceptions… and rarely lose what they no longer need. As user access rights evolve over time, it is crucial to track and document access changes to maintain transparency and security. The result is an environment where many people can do anything.
Automating user access reviews helps prevent privilege creep, reduces manual errors, and ensures compliance with security standards. Best practices for user access reviews include enforcing role-based access control (RBAC), implementing a regular risk-based review schedule, and leveraging automation to maintain accuracy and compliance.
Orphan accounts and forgotten access
Old email accounts, former employees’ logins, supplier accounts, and service accounts with no clear owner are examples of user accounts that can become orphaned. Regularly reviewing user accounts and revoking access for ex-employees is essential to minimising security risks. In an audit, this becomes a risk; in an incident, it becomes a door.
It is also important to document who performed the review, what changes were made to user accounts, and the business justification for any retained access.
Shared access
When the entire team uses the same login, you lose traceability and increase the chance of intentional or accidental abuse. To maintain security and accountability, access should be restricted to only authorised individuals, ensuring that each user’s actions can be traced and sensitive information is protected.
People make mistakes, and the process needs to anticipate this
Even with excellent technology, human error remains inevitable. Someone approves access for today only and forgets; someone adds a user to the wrong group; someone maintains permissions for fear of breaking something. A recurring review process, with data owners and system owners, reduces this risk without relying on memory or goodwill.
And what about the UK GDPR in all this?
The UK GDPR requires you to apply appropriate technical and organisational measures, and on a day-to-day basis, this translates into reducing access to what is necessary and setting more restrictive default standards (data protection by default). The logic is simple: if access is not necessary, it should not exist.
In addition to the UK GDPR, the General Data Protection Regulation (GDPR) sets out strict requirements for organisations operating in the European Union to protect data privacy and security. To support compliance, organisations should implement regular user access reviews, alongside data auditing and robust security measures.
Furthermore, the Health Insurance Portability and Accountability Act (HIPAA) requires organisations to periodically review and modify user access rights, ensuring that access policies are established, documented, and updated as necessary.
Why choose Immervox?
At Immervox, we help small businesses implement practical, repeatable user access review procedures that reduce risk without adding unnecessary complexity.
We design and manage secure Microsoft 365, cloud and network environments with clear access controls, role-based permissions and documented review processes. We support joiner, mover and leaver workflows, remove orphan accounts and help you evidence reviews for audits, insurers and compliance requirements such as UK GDPR and Cyber Essentials.
Our UK-based team provides ongoing managed IT support, proactive monitoring and clear reporting, so access governance is not a one-off exercise but part of a structured security approach.
If your permissions are unclear, inconsistent or undocumented, we can help you regain control and build a process that stands up to scrutiny.
Frequently asked questions
What is a user access review (UAR)?
A user access review (UAR) involves periodically reviewing access and permissions for systems and data, ensuring alignment with function, need, and risk, with evidence and approvals recorded.
How often should I conduct a review?
It depends on the level of risk and the type of data involved (for example, financial, health, or personal data). Many organisations adopt a quarterly or six-monthly cadence for critical systems and an annual review for lower-risk areas, with additional reviews triggered by joiner/mover/leaver events (entry, role change, or exit).
Periodic access reviews are a common expectation across major security and compliance frameworks. Under PCI DSS v4.0, all user accounts and related access privileges must be reviewed at least once every six months, and application and system account access must be reviewed at a frequency defined by the organisation’s targeted risk analysis.
NIST’s Cybersecurity Framework also recommends reviewing access privileges periodically and whenever someone changes roles or leaves. ISO/IEC 27001 similarly expects access rights to be provisioned, reviewed, modified, and removed in line with policy and business need.
Regular reviews help ensure access remains aligned with current responsibilities and reduce the risk of unauthorised access.
Is this only for large companies?
No. In small companies, the risk can be even greater because permissions tend to be broader and processes more informal. The procedure only changes in scale. It is important to review access to all company resources, regardless of company size, to ensure that only authorised users have the appropriate level of access and to maintain security and proper resource management.
Is access review the same as MFA?
No. MFA reduces the risk of stolen credentials being used; access review reduces the damage if someone manages to get in because it limits privileges and removes unauthorised access. The user access review process is a structured way to regularly assess and adjust access privileges, ensuring that users only have the permissions they need and complementing the protection provided by MFA.
Does this help with Cyber Essentials?
It helps a lot. Cyber Essentials places strong emphasis on user access control — account management, separation of administrative privileges, and MFA for relevant access. A formal, documented user access review process makes it easier to regularly assess and update user permissions, ensuring they remain appropriate to each role and are removed promptly when no longer needed.
Where to start if everything is a mess today?
Start with critical systems and data (Microsoft 365, finance, CRM, storage), deal with joiners, movers, and leavers, eliminate orphan accounts, and create a simple review cycle with clear responsibilities and minimal evidence. As part of the initial review cycle, review user access and document all access changes to maintain transparency and accountability. Use a user access review checklist to ensure nothing is missed during the process.



