Simpra
All articles
The Complete Guide to Quarterly Access Reviews
Access Management 3 min read ·

The Complete Guide to Quarterly Access Reviews

The access review is the single most-tested control in SOC 2 audits. Here's how to run one in under two hours, and what auditors specifically look for in the evidence.

Nothing generates more audit findings than access reviews. The control is simple — confirm that who has access to what is still appropriate — but the execution is where teams get tripped up. Here's how to do it well.

What auditors actually look for

When a SOC 2 auditor samples an access review, they check:

What to include in your review

At minimum, every quarter:

Low-risk systems (design tools, internal wikis) can move to annual reviews. Prioritize anything that can touch customer data or production.

How to run one in under two hours

Assuming you have the right tooling:

  1. Export user lists from each system. Most compliance platforms do this automatically.
  2. Send each system owner their list, with simple instructions: "For each user, reply confirm, modify, or revoke."
  3. Collect the responses, typically within a week.
  4. Implement the decisions: revocations happen within the SLA your policy specifies.
  5. Archive the evidence: original list, system owner's response, confirmation that revocations were implemented.

The whole thing should take 90–120 minutes of real work across a quarter. Longer than that means your tooling is wrong.

Common findings to pre-empt

The calendar trick

Set up four recurring calendar events — one for each quarter's review — with the required system owners invited and a checklist in the description. Let the calendar drive the cadence, not your willpower.

Simpra platform

Stop managing compliance in spreadsheets.

Simpra is the AI-native platform that turns policies, controls, evidence, and risk into one live system of record.

← Previous
Third-Party Risk: Managing Your Sub-Processor List
Next →
Why AI-Native Compliance is Actually Different