Regular user access reviews should be a shared responsibility between IT and HR, with security and business managers supporting the process. IT validates the technical access, HR confirms employment status and role changes, and managers verify whether the access still matches actual job needs. Shared ownership helps close the termination gap and improves SOX compliance.
Who should own regular user access reviews in finance?
Regular user access review should be shared between IT and HR, with security and business managers supporting the process. IT validates the technical access, HR confirms employment status and role changes, and managers verify whether the access still matches actual job needs. Shared ownership helps close the termination gap and improves SOX compliance.
How ownership should be split in a finance access review process
In practice, access review ownership works best as a three-part model. IT or IAM operations runs the review mechanics, extracts the entitlement data, and checks whether accounts, roles, and group memberships are technically valid. HR provides the employment and job-change source of truth, especially for joiner-mover-leaver events. Business managers make the judgement call on whether the access is still needed for the role.
This split matters because no single team can fully answer all three questions: who the person is, what access they have, and whether that access is still appropriate for the work they do. If one team owns the process alone, reviews often become either a paperwork exercise or a technical reconciliation with no business context. IAM and IGA Basics is useful background here because access review is one control inside a broader identity governance lifecycle.
Finance organisations usually also need a control owner who can enforce the cadence, evidence retention, and escalation path. That is often security, internal control, or a central IAM function, while the actual certification decisions remain distributed to the people who can verify them best.
Why finance needs shared ownership, not a single reviewer
Finance access reviews are high-stakes because they sit at the intersection of employment status, sensitive financial systems, and audit evidence. IT can confirm whether an account is active, but it cannot reliably determine whether a user still needs access for their job. Managers can judge business need, but they may not see dormant entitlements, role inheritance, or direct grants that are easy to miss in a large environment.
That is why access review is strongest when it combines technical validation with business attestation. The process should catch excess access before it becomes persistent privilege creep, and it should also catch people who have changed roles but retained old permissions. Joiner-Mover-Leaver (JML) Guide supports this model because leaver and mover events are where review failures often surface.
Shared ownership also improves auditability. When a reviewer removes access, there should be a clear record of who made the decision, what evidence they used, and when remediation happened. That makes the review defensible for SOX and easier to repeat at scale.
What goes wrong when access review ownership is unclear
Unclear ownership creates predictable failure modes. IT may generate the review but lack authority to decide business necessity. Managers may approve everything to avoid disruption. HR may know that someone has transferred or left, but the review may not reflect that change quickly enough. The result is stale access, delayed revocation, and inconsistent evidence for auditors.
In finance, that risk is not just administrative. Excess access can support fraud, inappropriate approvals, or unauthorized changes to sensitive records. The control also weakens if reviews focus only on named users while missing shared roles, inherited entitlements, and privileged exceptions. Segregation of Duties (SoD) Guide is relevant because access review should surface toxic access combinations, not just confirm that a person is employed.
Another common problem is reviewer fatigue. If managers receive long entitlement lists with little context, they approve by default. The review then becomes a compliance ritual instead of a meaningful control. The ownership model has to keep the decision close to the people who can actually validate necessity, while keeping the workflow simple enough to complete on time.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, CIS Controls v8 and OWASP ASVS set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Finance user access reviews are part of account lifecycle oversight and recertification. |
| AC-6 — Least Privilege | Access reviews should confirm that each user still has only the access needed for their role. | |
| AU-6 — Audit Record Review, Analysis, and Reporting | Access reviews in finance need traceable evidence and review outcomes for audit support. | |
| Recommendation — Review accounts regularly and remove or adjust access that no longer matches approved need. Revalidate entitlements against job need and remove excess privileges promptly. Retain review evidence and monitor remediation outcomes for auditability. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Regular access review is a core access-control governance activity under Annex A. |
| A.5.16 — Identity management | Access reviews depend on accurate identity and role records across joiners, movers, and leavers. | |
| A.5.18 — Access rights | This question is directly about reviewing and revalidating user access rights. | |
| Recommendation — Define and operate periodic access recertification with accountable reviewers. Keep identity and role records current before certifying access. Recertify access rights on a recurring schedule and revoke unjustified access. | ||
| CIS Controls v8 | CIS-5 — Account Management | CIS account management includes reviewing accounts and privileges to reduce excess access. |
| Recommendation — Periodically review accounts and privileges and remove those no longer justified. | ||
| OWASP ASVS | V8 — Authorization | Access reviews validate whether users still have authorized access to finance systems. |
| V16 — Security Logging and Error Handling | Reviews in regulated finance need evidence of decisions, approvers, and remediation. | |
| Recommendation — Verify access rights against business role and remove unauthorized entitlements. Log review decisions and retain evidence of access removals and exceptions. | ||
Practitioner Guidance
What to prioritise: Assign process ownership to IAM, security, or internal controls, but require manager attestation for business need and HR confirmation for employment changes. That division keeps the control both auditable and decisionable.
What to verify: Reviewers should see current role, manager, employment status, and entitlement context in one workflow. If those data points are not aligned, the review is too weak to trust.
Common mistake: Treating access review as an IT cleanup task. In finance, the technical list is only the starting point, the real control is the documented business decision to keep or remove access.
Practitioner takeaway: The best ownership model is not “who runs the report,” but “who can correctly decide and evidence removal,” with IT, HR, and managers each owning the part they can actually validate.
Related resources from NHI Mgmt Group
- How should security teams run access reviews for non-human identities?
- When do NHI access reviews create more value than a one-time cleanup?
- Who should own user access reviews when GRC, asset owners, and managers all have a role?
- How should security teams govern non-human identities that have persistent access?