ISO 27001
Access reviews under ISO 27001:2022
ISO 27001 asks you to manage access to information and systems deliberately — granting it by policy, keeping it appropriate, and removing it when it’s no longer needed. In the 2022 revision, the relevant Annex A controls sit in the A.5.15–A.5.18 range (access control, identity, authentication, and access rights). A periodic review of access rights is a common way to show these controls work in practice. This guide covers what those controls ask for and how to produce evidence an ISO auditor accepts.
Where access review fits in ISO 27001:2022
The 2022 controls in the A.5.15–A.5.18 range cover access control policy, identity management, authentication, and — most relevant here — the management and review of access rights (A.5.18). ISO 27001 doesn’t prescribe a fixed review interval or a mandated procedure; it expects you to define access control based on business and security requirements and to keep access rights appropriate over time. A periodic review of who has access, aligned to your access control policy, is a common control used to demonstrate that. The certification auditor checks that the control is defined, operating, and evidenced — not that you followed a specific cadence they imposed.
Reviewing access rights (A.5.18)
A.5.18 deals with granting, reviewing, modifying, and removing access rights. In practice that means access is provisioned per your policy, reviewed periodically by someone accountable, adjusted when roles change, and removed on exit. A review over your in-scope systems is where “access rights are kept appropriate” stops being an assertion in a policy document and becomes something you can show line by line.

Tying reviews back to your ISMS
ISO 27001 is a management-system standard, so auditors care that the review connects to the rest of your ISMS: it should follow the cadence your access control policy defines, feed risk treatment when it surfaces inappropriate access, and leave records that support your Statement of Applicability. A review that runs on a defined schedule, records decisions, and produces exportable evidence is far easier to point to during certification than an ad-hoc spreadsheet nobody can date.
- A defined cadence in your access control policy — and reviews that actually ran on it.
- A decision per access right by an accountable reviewer, dated and attributable.
- Removal of access that’s no longer appropriate, with proof it happened.
- Records you can retrieve at audit time without reconstructing them.
Evidence that survives to the audit
The recurring problem is evidence that can’t be trusted because it may have changed after the fact. Useboards snapshots access at review-start so the record reflects exactly what the reviewer saw, and writes every grant, change, and revocation to an append-only, tenant-isolated audit log the application can’t edit. When the certification or surveillance audit comes, you export a CSV evidence pack — reviewer, decision, timestamp, and justification per line — instead of trying to prove a live spreadsheet wasn’t touched.

Running it in Useboards
Hold your systems in the catalog with owners and access levels, route access through approval flows so grants follow policy, and run periodic reviews over the in-scope systems. Reviewers work each access right keep or revoke; revokes become tracked deprovisioning, and onboarding/offboarding handle the joiner and leaver ends of A.5.18. The result is access control you can evidence against ISO 27001 without an enterprise IGA deployment.
Frequently asked questions
Does ISO 27001 require access reviews at a set frequency?
No fixed interval is prescribed. ISO 27001:2022 expects access control based on business and security requirements and that access rights are managed and reviewed (A.5.18); the cadence comes from your own access control policy. The auditor checks the control is defined, operating, and evidenced — not that you met a frequency they imposed.
Which ISO 27001 controls relate to access reviews?
In the 2022 revision, the relevant Annex A controls sit in the A.5.15–A.5.18 range — access control, identity management, authentication, and the management and review of access rights. A.5.18 (access rights) is the most directly tied to periodic reviews.
What evidence does an ISO 27001 auditor want from a review?
That the review ran on the cadence your policy defines, that an accountable reviewer decided each access right with a date, and that inappropriate access was removed with proof. Snapshot-based, timestamped records are far easier to defend than a spreadsheet whose history can’t be verified.
How does this connect to our ISMS?
The review should follow your access control policy, feed risk treatment when it finds inappropriate access, and leave records supporting your Statement of Applicability. Useboards runs the review on a defined cadence and exports auditor-ready evidence, so the control links cleanly back into the management system.
Related
Evidence A.5.18 without an IGA rollout
Snapshot-based reviews, approval flows, and a tamper-evident audit log.