User Access Review Checklist
Review Scoping and Data Pull
List the systems covered this cycle: Entra ID / AD, Okta, M365, Salesforce, GitHub, AWS / Azure, ERP, plus any HIPAA-covered or SOX-significant apps. Tag each with its applicable framework (SOX ITGC, SOC 2 CC6, HIPAA 164.308(a)(4)) so the evidence matches what the auditor will ask for.
Pull the source-of-truth roster from Workday / BambooHR / ADP, including department, manager, status (active / LOA / terminated), and termination date. The HRIS roster is the reconciliation baseline — every system's user list gets compared back to it.
Export user + group + role membership from Entra ID (Get-MgUser / Access Reviews), Okta (System Log + group rules), AWS IAM (credential report + IAM Access Analyzer), and each in-scope SaaS app. Snapshot the date — auditors will ask what point-in-time the data represents.
Diff the entitlement exports against the HRIS roster. Flag three buckets: terminated users still active, active users with no HRIS record (likely contractor / service accounts), and accounts last-logon > 90 days. The ghost-account count is a number the audit will ask for.
Account Verification
For each terminated user still active in any system: disable in Entra ID, revoke sessions, and document the disable timestamp vs. the HRIS termination date. SOX and SOC 2 both look at the gap — anything beyond the documented SLA (typically 24 hours) is a finding.
List every non-human account: service accounts, shared mailboxes, break-glass accounts, application identities. Each needs a named human owner, a documented purpose, and a last-rotation date. Orphaned service accounts running as Domain Admin are a recurring audit finding.
Any account with no interactive logon in 90+ days gets flagged for manager confirmation. Stale accounts are the easiest path for an attacker — they're unmonitored and often retain prior entitlements. Default action is disable; manager must justify retention in writing.
Run the Entra ID MFA registration report and the Okta factor enrollment report. Verify conditional access blocks legacy basic-auth (IMAP / POP / SMTP) — MFA enabled with legacy auth still allowed is a bypass auditors specifically test for.
Entitlement and Role Review
Send each people manager their direct reports' entitlements per system. Use Entra ID Access Reviews, SailPoint, or a tracked spreadsheet — whichever your auditor has accepted before. Set a 10-business-day response SLA and copy the manager's VP on the request.
Walk Domain Admins, Enterprise Admins, Global Administrators, AWS root / OrgAdmin, and Tier 0 groups line by line with the security lead. Privileged group membership gets the most auditor scrutiny — every member needs a documented business justification, not just a manager's nod.
For SOX-significant systems (ERP, financial close apps), run the SoD matrix: no single user can both create and approve a vendor, post and approve a journal entry, or change pay rates and approve payroll. Document mitigating controls for any unavoidable conflict.
Tally returned attestations: approved as-is, modify entitlement, or revoke access. Non-responses default to revoke after escalation to the VP. The completeness percentage is a number the audit asks for — anything below 100% needs a documented exception.
Execute the revoke list in each source system (Entra ID, Okta groups, AWS IAM, app-level roles). Capture before / after screenshots or API confirmations as evidence. Revocations must trace back to the named manager who requested them.
Approval Process Audit
Pull a 25-ticket sample from ServiceNow / Jira Service Management / Freshservice covering new hires, transfers, and ad-hoc access requests. The sample size is what your SOC 2 auditor agreed to; document the population and selection method.
For each sampled ticket, confirm the requester, approver (manager + system owner where required), approval timestamp, and that the granted access matches what was approved. Verbal approvals or self-approvals are findings.
For each bypass: identify the user, the access granted without approval, the system owner notified, and the corrective action (revoke + re-request, or retroactive approval with justification). File the remediation plan with the security lead before the cycle closes.
Reporting and Sign-Off
Bundle the entitlement snapshots, attestation responses, revocation evidence, and approval-sample workpapers into a single dated package. Index it the way your auditor's PBC list expects — workpapers without an index get re-requested.
SOX and SOC 2 expect access reviews on a regular cadence — quarterly is the most common. Put the next cycle on the calendar with the data-pull date locked, so the population is reproducible.
Final sign-off captures the review outcome, exceptions accepted, and the next review date. The CISO or Director of IT signs as control owner; for SOX-significant systems, the application owner co-signs.
Use this template in Manifestly
- Cloud Migration Checklist
- Cloud Security Checklist
- Data Recovery Checklist
- Containerization Rollout Checklist
- Database Backup Checklist
- Password Management Checklist
- Backup and Restore Checklist
- Network Upgrade Checklist
- Server Backup Checklist
- Business Continuity Plan Checklist
- Problem Management Checklist
- Server Decommissioning Checklist
- Cloud Monitoring Checklist
- Hardware Inventory Checklist
- IT Regulatory Compliance Review
- Release Management Checklist
- Server Maintenance Checklist
- Rollback Plan Checklist
- Customer Support Ticket Workflow
- Software Upgrade Checklist
- Quarterly Compliance Reporting Checklist
- Patch Management Checklist
- Hardware Maintenance Checklist
- Server Security Checklist
- IT Emergency Response Checklist
- Incident Management Checklist
- Disaster Recovery Plan Checklist
- User Role Management Checklist
- Software Installation Checklist
- Compliance Audit Checklist
- Access Control Checklist
- Cloud Cost Management Checklist
- IT Staff Performance Review
- Change Management Checklist
- Firewall Configuration Checklist
- Security Audit Checklist
- Quarterly Network Security Review
- Database Migration Checklist
- Employee Onboarding Checklist
- Capacity Planning Checklist
- IT Budgeting Checklist
- Network Monitoring Checklist
- Cloud Deployment Checklist
- Database Installation Checklist
- IT Service Request Checklist
- Database Security Checklist
- System Monitoring Checklist
- Hardware Troubleshooting Checklist
- IT Strategy Checklist
- Patch Deployment Checklist
- Hardware Upgrade Checklist
- Performance Tuning Checklist
- Application Performance Monitoring Checklist
- Employee Training Checklist
- User Onboarding Checklist
- IT Vendor Management Checklist
- Server Build and Hardening Checklist
- IT Policy Review Checklist
- Help Desk Ticket Handling Checklist
- Infrastructure as Code Checklist
- Hardware Disposal Checklist
- IT Resource Allocation Checklist
- Incident Response Checklist
- Network Troubleshooting Checklist
- User Offboarding Checklist
- Risk Management Checklist
- Regulatory Compliance Checklist
- Quarterly Internal Control Review Checklist
- Sales Tax Reporting Checklist
- Legal Entity Management Checklist
- Employee File Audit Checklist
- Anti-Money Laundering Compliance Checklist
- SOX Compliance Checklist
- GDPR Compliance Review Checklist
- IT Security Audit Checklist
- HR Compliance Checklist
- Payroll Processing Checklist
- Building Code Compliance Checklist
- Employee Records Management Checklist
- Legal Document Storage Checklist
- Security Audit Checklist
- Property Risk Assessment Checklist
- Property Safety Inspection Checklist
- Cybersecurity Protocol Checklist
- Fair Housing Compliance Checklist
- Legal Compliance Checklist for New Properties
- Lease Agreement Checklist
- Software Licensing Compliance Checklist
- PCI DSS Compliance Checklist
- Real Estate Legal Compliance Checklist
- HIPAA Compliance Checklist
- MLS Listing Review Checklist
- Real Estate License Renewal Checklist
- GDPR Compliance Checklist
- Real Estate Contract Review Checklist
- Fair Housing Compliance Audit
- Listing Agreement Intake Checklist
- ISO/IEC 27001 Compliance Checklist
- HR Compliance Checklist
- Real Estate Ethics & Compliance Review
- Brokerage Trust Account Management Checklist
- Real Estate Professional Development Checklist
- Brokerage Technology Inventory Audit
- Real Estate Website Audit Checklist
- Continuing Education Checklist
- Employee Termination Checklist
- Employee Records File Audit
- Regulatory Compliance Checklist
- Brokerage HR Policy Compliance Checklist
- Employee Handbook Annual Review
- Employee Termination Checklist
- Data Privacy Compliance Checklist
- Risk Management Checklist
- Insurance Compliance Checklist
- Complaint Resolution Checklist
- Financial Audit Checklist
- Data Security Checklist
- Risk Mitigation Checklist
- Claims Auditing Checklist
- Quarterly Industry Standards Compliance Review
- Insurance Training and Development Checklist
- Anti-Money Laundering Checklist
- Training Evaluation Checklist
- Manufacturing Regulatory Compliance Checklist
- Training Needs Assessment Checklist
- Skills Development Checklist
- Audit Preparation Checklist
- Network Security Checklist
- Employee Offboarding Checklist
- IT Asset Inventory Management Checklist
- Regulatory Reporting Checklist
- Compliance Audit Checklist
- Insurance Program Initiation Checklist
- Insurance Program Launch Project Monitoring Checklist
- Training Materials Checklist
- Quarterly Risk Monitoring Checklist
- System Backup Checklist
- Employee Benefits Checklist
- Insurance Program Launch Execution Checklist
- Insurance Marketing Campaign Checklist
- Email Compliance Checklist
- Law Firm Compliance Checklist
- Anti-Money Laundering Compliance Checklist
- Law Firm Compliance Checklist
- Professional Responsibility Compliance Review
- Data Privacy Compliance Checklist
- Law Firm Risk Management Checklist
- HR Audit Checklist
- HR Compliance Checklist
- Email Deliverability Checklist
- Law Firm Ethics Compliance Review
- Document Retention Policy Checklist
- Employee File Audit Checklist
- Law Firm Risk Management Checklist
- Cloud Security Checklist
- IT Regulatory Compliance Review
- Compliance Audit Checklist
- Security Audit Checklist
- Business Continuity Checklist
- Employee Termination Checklist
- Quarterly Operations and Compliance QA Review
- Expense Management Checklist
- Advisor and Employee Onboarding Checklist
- Client Satisfaction Survey Checklist
- Operational Risk Checklist
- Know Your Customer (KYC) Checklist
- Litigation Preparation Checklist
- Contract Review Checklist
- New Hire Onboarding Checklist
- Client Onboarding Checklist
- Contract Review Checklist
- Regulatory Compliance Checklist
- Monthly Financial Reporting Checklist
- Regulatory Reporting Checklist
- Intellectual Property Management Checklist
- Internal Audit Checklist
- Lead Generation Checklist
- Annual Financial Reporting Checklist
- Annual Compliance Program Review
- Annual Risk Assessment Checklist
- Data Security Review Checklist
- Quarterly Performance Measurement Checklist
- Financial Services Project Initiation Checklist
- IT Policy Review Checklist
- Data Protection Checklist
- E-commerce Sales Tax Reporting Checklist
- Project Execution Checklist
- Project Planning Checklist
- Project Monitoring Checklist
- Financial Statement Review Checklist
- Quarterly Compliance Monitoring Checklist
- Cybersecurity Risk Assessment Checklist
- Project Closure Checklist
- Financial Services IT Security Audit Checklist
- PCI DSS Compliance Checklist
- Advisor and Staff Onboarding Checklist
- Cybersecurity Incident Response Checklist
- E-commerce Risk Management Checklist
- CRM Data Entry Checklist
- Business Continuity Plan Checklist
- E-commerce Legal Compliance Checklist
- Vendor Contract Review Checklist
- Annual Risk Management Review Checklist
- Risk Assessment Checklist
- Agency Compliance and Risk Management Checklist
- Annual School Compliance Audit
- School First Aid and Emergency Medication Audit
- Motor Carrier TSA Security Compliance Checklist
- Internal Controls Checklist
- Client Communication Checklist
- Restaurant Permit and Licensing Renewal Checklist
- New Hire Paperwork Checklist
- Restaurant Policy Update Checklist
- Restaurant New Hire Checklist
- Annual Attorney Professional Conduct Review
- International Fuel Tax Agreement (IFTA) Quarterly Filing Checklist
- Restaurant Licensing Renewal Checklist
- Marketing Strategy Checklist
- Department of Transportation (DOT) Audit Checklist
- Retail Policy Update and Compliance Checklist
Ready to take control of your recurring tasks?
Start Free 14-Day TrialUse Slack? Sign up with one click
