The steps of a user access review
- Define the scope: which applications, roles or privileged groups, and the population as of a set date.
- Send each reviewer (usually the manager or application owner) the list of access to certify.
- Reviewers keep or revoke each item, with a reason for anything unusual.
- IAM removes the revoked access and records when it was done.
- Follow up on items nobody reviewed. Unreviewed access is a finding, not a pass.
- Keep the evidence: the population, the decisions, who made them and the removal tickets.
What auditors check
Auditors test completeness (was the full population reviewed), accuracy (was the list pulled from the real system), timeliness (were revocations done) and independence (nobody certifies their own access).
Rubber-stamping, where a reviewer approves everything without looking, is the most common weakness. Look for reviews completed in seconds or with no revocations at all.
Practise both sides
In Rolevara, access reviews show up as tickets on the IAM side, and as an access-review completeness test (UAR-01) on the GRC side. Working both shows you how a small shortcut in the review becomes an audit finding.
Practise it on a realistic job
Run access reviews and audit them on a realistic company, free.
Start practisingQuestions
How often should user access reviews run?
Commonly every quarter for privileged and financially significant access, and every six or twelve months for everything else. Follow the policy and framework that apply.
What is the difference between an access review and an access audit?
The review is the control the business runs. The audit tests whether that review was complete, accurate and acted on.
Is a user access review the same as recertification?
Yes. Access review, access certification and recertification are used for the same control.

