Access reviews for SMEs: a quarterly process that stands up to an auditor
An access review is a periodic check that every account in a system still belongs to someone who still needs it. Done properly in a 50-person company it takes about two hours a quarter. Done as an annual panic it takes two days and convinces nobody.
Written by Apexward Assure editorial team
Reviewed by Apexward Assure product team
Last reviewed: 30 August 2026
Why reviews exist: joiners, movers and leavers
Access reviews are a control that compensates for another control being imperfect. In theory, your joiners, movers and leavers process grants the right access on day one, adjusts it when someone changes role, and removes it on their last day. In practice it leaks, and the review is how you find the leaks before an assessor or an attacker does.
Leavers are the failure everyone thinks about and the one most companies handle reasonably well, because someone leaving is a visible event with a date attached. The accounts that get missed are the peripheral ones: the shared vendor portal, the analytics tool nobody administers, the account in the system a contractor set up two years ago.
Movers are the real problem, and the one almost nobody catches. When someone moves from support to finance, they get finance access. Nothing removes their support access, because no event triggers it: there is no last day, no exit checklist, no handover. Three role changes later you have someone with a genuinely surprising combination of permissions, entirely by accretion. This is how a small company ends up with a single person who can raise a purchase order, approve it, and change the bank details on the supplier record. Nobody decided that. It accumulated.
A movers-aware review asks a different question from a leavers-aware one. Not “does this person still work here?” but “does this person still need this, for the job they do now?”
Scope: not all systems, and not all at once
The instinct is to review every system, which is why so many first attempts collapse. A 30-person company might have sixty SaaS tools. Reviewing sixty systems quarterly is not going to happen, and a review that does not happen is worth less than a smaller one that does.
Review quarterly the systems where wrong access is genuinely consequential:
- Your identity provider itself, which is the master key
- Systems holding customer data or personal data
- Finance and payroll, especially anything that can move money or change bank details
- Production infrastructure and code repositories, including administrative roles
- Anything with a public-facing administrative interface
For a typical small supplier that is four to eight systems. Everything else gets reviewed annually, or on change. Write down which systems are in quarterly scope and why, because an assessor will ask about the ones that are not, and “we scoped on data sensitivity and privilege, here is the list and the rationale” is a complete answer. Scoping is defensible. Forgetting is not.
If you have never done this, do not start with all eight. Start with the identity provider and the finance system in the first quarter and add one or two systems per quarter. A programme that grows gets run. A programme that starts at full size gets abandoned by quarter two.
Who reviews
The reviewer should be the person who knows what the access is for, which is almost never IT. IT knows that Sarah has editor rights in the finance system. Only the finance manager knows whether Sarah should. Sending the whole list to whoever administers the systems produces a review where every line is approved, because the administrator has no basis to say no.
So: the system owner or the relevant department head reviews their own people. IT or whoever runs the platform pulls the account lists, distributes them, and carries out the removals. The reviewer decides, and their name goes on the decision. That separation is also what makes the record credible: the person who can change access is not the person who signed off that it was correct.
Two categories need a named owner in advance, because they are the ones that drift: service accounts and shared or generic accounts. Each needs a human owner who can say what it is for. An unowned service account with administrative rights is the single most common finding in a first review.
What the attestation record needs
An assessor is not asking whether you looked. They are asking you to demonstrate it. A record that satisfies that has five elements:
- The reviewer’s name, as a person rather than a team or a mailbox
- The date the review was completed, not the date it was assigned
- The system reviewed, and the point in time the account list was taken from
- A decision per account: retain, reduce or remove. Per account, not an overall sign-off on a spreadsheet, because a single signature at the bottom of a list of ninety names does not show that ninety decisions were made
- Evidence that removals actually happened, with a date. This is the part most often missing. A review that identified four accounts for removal and cannot show they were removed has documented a failure rather than a control
Record exceptions explicitly. If an account with more access than it needs is retained for a business reason, write the reason and the review date. An assessor is comfortable with a documented exception. They are not comfortable with an inconsistency you did not notice.
Keeping it under two hours
The time goes on gathering, chasing and formatting, not on deciding. Four habits keep it small.
Export on a fixed day. Pull every account list on the same date each quarter, say the first working day. Consistency makes the lists comparable and removes the negotiation about when the review starts.
Review the delta first. Most accounts did not change. Put new accounts, changed permissions and anyone whose role or department changed at the top of the list. Those are where the findings are. The unchanged remainder is a faster read once you know the interesting rows have already had attention.
Give reviewers a decision, not a spreadsheet. A reviewer facing an unformatted CSV export will approve everything. A reviewer facing a name, what that person can do, when they last signed in, and three buttons will not.
Close the loop in the same fortnight. Removals identified in the review get actioned and evidenced before the review is marked complete. Reviews that stay open until the next one starts are how a quarterly control quietly becomes an annual one.
Realistically, a first review takes longer, because the first one finds the accumulated debt: the leavers nobody removed, the unowned service accounts, the contractor from 2024. That is the review doing its job. Quarters two onwards are the two-hour version.
Where Apexward Assure fits
The organisation module holds people, their roles and their access, and keeps access review attestations with a date and a name against each decision, so the record exists as a by-product of doing the review rather than as a separate write-up afterwards. Reviews link to the controls they satisfy in your compliance programme, and an assessor can be given a scoped role that reads evidence and raises questions without being able to change the programme they are assessing. The platform is free, so trying it costs nothing beyond running one quarter’s review in it and seeing whether the record it leaves behind is the one your assessor asks for.