Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What do auditors expect from access reviews under…
Governance, Ownership & Risk

What do auditors expect from access reviews under ISO 27001 or SOC 2?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Governance, Ownership & Risk

Auditors want to see that permissions were reviewed, exceptions were handled, and removals were traceable. They also expect the review process to match the organisation’s stated control objective, whether that is risk-based ISMS discipline or evidence of sustained control operation over a reporting period.

What auditors look for in an access review

Auditors are usually checking that the review was real, complete, and tied to a defined control objective. That means the organisation can show who was reviewed, what was approved or challenged, what was removed, and when it happened. They also want evidence that the review was performed on a sensible cadence and covered the population the control claims to govern.

For iso 27001, the emphasis is on whether the review supports the stated ISMS control objective and whether the process is operating as a managed control, not a one-off cleanup. For SOC 2, the same review needs to demonstrate consistent operation over the reporting period, with enough evidence to support the auditor’s test of design and operating effectiveness.

Good review evidence is usually more than a spreadsheet. Auditors expect traceability from review decision to remediation action, so the record should show exceptions, approvers, timestamps, and follow-up on removals or compensating actions. A review that only proves someone opened a file is weak; a review that proves decisions were made and acted on is what matters.

What makes the evidence acceptable under ISO 27001 or SOC 2?

The evidence needs to line up with the assurance model. Under ISO 27001, the reviewer should be able to show that access rights are periodically reviewed against policy, that exceptions are justified, and that the process fits the organisation’s risk treatment and control ownership model. A control that exists in procedure but is not followed in practice will be treated as a gap.

Under SOC 2, auditors are more likely to probe whether the access review operated consistently for the entire audit window and whether exceptions were tracked to closure. They are not just looking for policy language, they are testing whether the control left an evidentiary trail that supports the trust service criteria the report is based on, especially security and confidentiality.

In practice, the strongest reviews have a clear scope, a named reviewer, a defined review period, explicit disposition for each entitlement, and documented remediation for removals or retained access. If access is retained, the rationale should be visible, because unexplained exceptions weaken both the control and the audit trail.

How to make an access review audit-ready

Audit-ready access reviews are built around identity governance basics, not ad hoc clean-up. The review should be anchored to an entitlement inventory, a current owner or manager, and a defined approval rule so that auditors can see the control is repeatable rather than improvised.

Remediation must also be visible. Access reviews and certification work best when removals, exceptions, and re-certifications are closed in the same workflow instead of being tracked in a separate email trail. That makes it easier to prove that the review changed access, not just opinions about access.

Where roles, segregation-of-duties conflicts, or elevated entitlements are in scope, the review should show that those higher-risk items were examined with more scrutiny than ordinary access. Segregation of duties concerns are often where auditors focus because they expose whether the review is actually preventing conflicted access from persisting.

Risk and Threat Considerations

Access reviews fail when they become administrative theatre: broad lists, rubber-stamped approvals, and no enforced follow-through on removals. That creates lingering excess privilege, weakens accountability, and leaves the organisation unable to prove that access drift was corrected rather than merely observed.

Failure mechanism: Incomplete scope, stale entitlement data, or unmanaged exceptions allow inappropriate access to survive the review cycle, especially when reviewers do not have enough context to challenge questionable entitlements.

Impact: The control may still look present on paper, but auditors can treat it as ineffective if access remains unjustified, removals are not traceable, or the review cannot demonstrate sustained operation.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

ISO/IEC 27001:2022 and SOC 2 (AICPA) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
ISO/IEC 27001:2022A.5.15 — Access ControlAccess reviews demonstrate periodic access control governance under the ISMS.
A.5.18 — Access rightsAuditors expect review and removal of access rights to be governed and evidenced.
Recommendation — Verify that entitlements are reviewed, exceptions are justified, and removals are traceable. Recertify access rights on a defined cadence and retain remediation evidence.
SOC 2 (AICPA)CC6.1 — Logical and Physical Access ControlsAccess reviews are core evidence for operating logical access controls during the report period.
CC6.2 — System Access ControlReviewing, approving, and removing access supports system access control effectiveness.
CC7.2 — Change ManagementAccess removals and exception remediation need traceable changes to evidence control operation.
Recommendation — Document periodic review of access and show the control operated consistently. Enforce approval and removal workflows for access changes and exceptions. Track access removals as controlled changes with clear evidence of completion.

Practitioner Guidance

What to verify: Confirm that every review sample can be traced from entitlement list to reviewer decision to remediation outcome. If the evidence cannot show who approved retention, who removed access, and when the change was completed, the review is too weak for audit reliance.

What good looks like: The review population matches the control objective, exceptions are explicitly recorded, and closures are time-bound. For higher-risk access, auditors usually expect more than manager sign-off, they expect a control owner to be able to explain why the exception existed and why it was acceptable.

Practitioner takeaway: Treat the access review as a control execution problem, not a documentation exercise, because auditors are looking for proof that review decisions actually changed access and that the change can be evidenced end to end.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org