User Access Review Checklist

Purpose

Use this checklist to periodically confirm that employees, contractors, vendors, service accounts, and administrators still have appropriate access.

The objective is to remove access that is no longer needed, reduce excessive permissions, identify forgotten accounts, and confirm that high-risk access remains justified.

Review Information

System or service:


Business owner:


Technical owner:


Review date:


Reviewer:


Previous review date:


Next review date:


User and Account Review

For each account, confirm:

☐ The account belongs to a current employee, contractor, vendor, or approved service.

☐ The account still has a valid business purpose.

☐ The user's current role still requires access.

☐ The access level matches current responsibilities.

☐ No unnecessary permissions have accumulated.

☐ Former employee accounts are disabled or removed.

☐ Former contractor or vendor accounts are disabled or removed.

☐ Duplicate accounts are investigated.

☐ Dormant or unused accounts are reviewed.

☐ Unknown accounts are investigated.

High-Risk Access Review

Confirm:

☐ Administrator access is limited to people who need it.

☐ Finance and payment access is appropriate.

☐ Payroll and HR access is appropriate.

☐ Sensitive customer data access is appropriate.

☐ Cloud and SaaS administrator access is appropriate.

☐ Backup administrator access is appropriate.

☐ Security tool access is appropriate.

☐ Vendor and MSP privileged access is still required.

☐ Temporary high-risk access has expired or been removed.

Authentication Review

Confirm:

☐ MFA is enabled where required.

☐ High-risk accounts use appropriate MFA.

☐ Shared credentials are avoided where possible.

☐ Shared accounts have an owner where they remain necessary.

☐ Service accounts have an owner.

☐ Service account credentials or secrets are appropriately protected.

☐ Emergency accounts remain controlled.

Role Change Review

Check whether any users have:

☐ Changed departments.

☐ Changed responsibilities.

☐ Been promoted.

☐ Moved onto or off a temporary project.

☐ Taken extended leave.

☐ Changed contractor or vendor status.

For these users, confirm that old access was removed rather than only adding new access.

Vendor and Contractor Review

Confirm:

☐ Vendor accounts have internal owners.

☐ Vendor access is limited to required systems.

☐ MFA is used where practical.

☐ Expired projects no longer have active access.

☐ Remote support access remains justified.

☐ Vendor administrative access is reviewed.

Shared and Service Account Review

Confirm:

☐ Shared accounts are still necessary.

☐ Shared account membership is current.

☐ Shared passwords have been rotated where necessary.

☐ Service accounts are still used.

☐ Service accounts have only required permissions.

☐ Unused service accounts are disabled.

Findings

Record any access that should be:

  • Removed
  • Reduced
  • Changed
  • Investigated
  • Temporarily suspended
  • Escalated

Finding:


User or account:


Action required:


Owner:


Due date:


Priority:


Review Completion

Number of accounts reviewed:


Accounts requiring removal:


Accounts requiring modification:


Unknown accounts found:


High-risk issues found:


Review completed by:


Business owner approval:


Completion date:


Evidence location:


Privileged and high-risk access:

Quarterly where practical.

Vendor and MSP access:

Quarterly and whenever the relationship changes.

General user access:

At least annually, with more frequent reviews for sensitive systems.

Access should also be reviewed after major staffing changes, reorganizations, incidents, or system changes.