Vendor Data Access Reviews
The Review Was Completed. Every Account Was Approved. Half of Them Should Not Exist.
9 min read · 1 July 2026 · Privacy
A cloud services vendor completed their quarterly access review on schedule. The review covered all user accounts with access to customer data environments , seventy-three accounts reviewed, seventy-three accounts approved. The review was submitted to their compliance team as complete. Four months later, a security audit found that fourteen of the seventy-three approved accounts belonged to former employees who had left the organization over the previous eighteen months. Three belonged to contractors whose engagements had ended. Four belonged to accounts created for specific customer projects that had concluded. The accounts were active, the credentials were valid, and in at least two cases had been accessed in the months following the access review. The review had been conducted using a spreadsheet listing account names. The reviewers , department managers , had been asked to confirm whether each account should have access. They had confirmed yes for accounts they recognized and yes for accounts they did not recognize, because the path of least resistance when reviewing an unfamiliar account name is to assume it belongs to someone who should have it.
What is the Access Review Quality Problem, Really?
Access reviews , the periodic process of verifying that all accounts with access to sensitive systems and data should still have that access , are a fundamental identity governance control, required by PCI-DSS, SOC 2, ISO 27001, and most regulatory frameworks that address information security. The intent is to identify accounts that should no longer have access: former employees, contractors whose engagements have ended, service accounts whose purpose has changed, and users whose roles have evolved beyond their current access scope. Executed well, access reviews reduce the attack surface available to credential compromise, limit insider threat opportunities, and ensure that the principle of least privilege is maintained over time as roles and relationships change.
The quality problem arises from the gap between the process of conducting an access review and the outcome of conducting it well. An access review that produces a list of accounts, sends it to managers for approval, and processes all approvals as confirmations of legitimate access has met the procedural requirement for an access review. It has not necessarily produced an accurate assessment of which accounts should have access. The accuracy of the review depends on the quality of the account data presented , whether it includes information reviewers need to make informed decisions , the context available to reviewers , whether they know who each account belongs to and what their current role is , and the cultural accountability for the review outcome , whether approving an account that should not have access has consequences.
The orphaned account problem is the most common and most significant consequence of low-quality access reviews. Orphaned accounts , accounts that belong to individuals who no longer have a legitimate need for the access, typically former employees, former contractors, and users whose roles have changed , accumulate in any organization where the joiner-mover-leaver process for access provisioning and deprovisioning has gaps. Regular access reviews are designed to catch what the provisioning process missed. When reviews rubber-stamp the existing access list rather than challenging it, the orphaned accounts persist indefinitely, providing a population of valid credentials that can be used by the former holders, by attackers who compromise those credentials, or by anyone else who gains access to them.
Access review quality failures cluster around five specific patterns in vendor environments:
- Rubber-stamp approval by uninformed reviewers , managers approving access lists containing accounts they do not recognize because the review process provides no context and the path of least resistance is approval
- Account data quality insufficient for review , access lists that contain account names or usernames without sufficient context , last login date, role, account purpose, current employment status , to enable informed review
- No consequence for approval of illegitimate accounts , review processes where approving an account that should not have access produces no accountability or remediation obligation for the approver
- Review scope limited to primary systems , access reviews that cover the main application databases and miss analytics platforms, reporting tools, collaboration access, and administrative interfaces
- No independent validation of review outcomes , reviews accepted as complete based on manager sign-off without independent verification that approved accounts correspond to legitimate current access needs
Why this matters
Access review quality matters for TPRM because it is the control that governs whether the access granted to a vendor's employees remains proportionate to their current roles over time. Initial access provisioning at onboarding creates the access baseline. The access review is supposed to maintain that baseline as roles change , ensuring that an employee who moved to a different function three years ago is not still carrying access that was appropriate for their previous role, and that a contractor who finished their engagement six months ago is not still holding credentials that were never deprovisioned.
The former employee access risk is where vendor access review failures create the most immediately consequential exposure. A former employee who retains access to a vendor's customer data environments is a credential that exists outside the vendor's employment relationship, outside the vendor's security monitoring scope, and potentially in use by someone who no longer has a business reason to hold it. The fourteen former employees who passed the vendor's quarterly access review were not accessing the systems in most cases , but in at least two cases, access had occurred after the review confirmed the accounts were legitimate. Former employees with active credentials in vendor environments are not a theoretical risk.
For TPRM practitioners, the access review quality assessment requires going beyond cadence confirmation , quarterly is good, monthly is better , to the quality of the review process itself. A quarterly access review that rubber-stamps an access list produces less actual security value than an annual review that genuinely challenges every account and removes orphaned accounts that reviewers cannot justify. Cadence is the frequency of the opportunity. Quality is whether the opportunity is used.
Where most teams get this wrong
The most consistent failure is treating review frequency as a proxy for review quality. Quarterly access reviews sound rigorous. An access review conducted quarterly but executed as a rubber-stamp approval of an unchallenged list provides the compliance documentation of a quarterly review without the security value. The cadence question , how often do you conduct access reviews , is a governance frequency question. The quality question , what happens in the review that ensures illegitimate accounts are identified and removed , is the governance effectiveness question.
The second failure is not asking about what information is presented to reviewers. An access review presented as a list of usernames with no context requires reviewers to have independent knowledge of every account to make informed decisions , knowledge they may not have. An access review that presents last login date, account creation date, account purpose, current employment verification, and role mapping gives reviewers the information needed to identify accounts that should not exist. The information quality determines the review quality.
- Treating review frequency as equivalent to review quality , quarterly rubber-stamps provide less security value than annual genuine reviews
- Insufficient account context for informed review , lists of usernames without last login, employment status, or account purpose
- No accountability for approving illegitimate accounts , reviewers who approve orphaned accounts face no consequence
- Review scope limited to primary systems , analytics, reporting, and collaboration access not included
- No independent validation , manager sign-off accepted without verification of approval accuracy
What good looks like
Mature access review programs present reviewers with context-rich account data that enables informed decisions, require justification for each approval rather than accepting approval as the default, and include independent validation mechanisms that catch approvals that should have been rejections.
- Context-rich access review data , every account presented with username, full name, current employment status, last login date, account creation date, and account purpose
- Justification required for approval , reviewers required to provide a brief justification for continuing each account's access, not simply mark approved
- Automated employment verification , access review tool integrated with HR system to flag accounts belonging to former employees before the review begins
- No-response equals revocation , accounts not responded to within the review window automatically flagged for revocation rather than defaulting to continued access
- Post-review independent validation , sample of approved accounts independently verified to confirm they correspond to legitimate current users
- Review scope covering all access types , analytics platforms, reporting tools, administrative interfaces, and collaboration access reviewed alongside primary database access
Tooling
Effective access review requires identity governance tooling that automates context collection, enforces review completion, and provides independent validation capability.
Identity Governance and Administration , SailPoint, Saviynt, Omada
IGA platforms automate the access review process , collecting account data across systems, enriching it with HR context, routing reviews to appropriate managers with deadlines, and automatically revoking access that is not certified within the review window. SailPoint IdentityNow integrates with HR systems to provide employment status alongside access data, enabling reviewers to see immediately which accounts belong to former employees. For TPRM practitioners, asking whether the vendor uses an IGA platform for access reviews , rather than spreadsheet-based manual processes , surfaces the difference between systematically supported review and manually managed review.
Privileged Access Management , CyberArk, BeyondTrust, Delinea
PAM platforms specifically govern privileged account access reviews , providing enhanced oversight for the accounts with the highest-risk access. For TPRM practitioners, asking whether privileged account reviews are conducted through a PAM platform with separate, enhanced review workflows surfaces whether the highest-risk access is subject to proportionate review rigor.
Directory Services and SCIM , Azure AD, Okta, SCIM protocols
Identity directory integration with automated provisioning and deprovisioning provides the first line of orphaned account prevention , automatically disabling accounts when HR systems record a departure. When automated deprovisioning works correctly, access reviews catch fewer orphaned accounts because most have already been removed. For TPRM practitioners, asking whether the vendor has automated deprovisioning integrated with HR systems provides a control that reduces the remediation burden on the access review.
Governance challenges
The governance challenge with access review quality is the scale and attention problem. An organization with a thousand user accounts conducts an access review that asks managers to review hundreds of accounts each. Under time pressure, reviewers apply the least-effort heuristic: approve what is familiar, approve what is not recognized on the assumption that it must be legitimate. The review process produces a compliance artifact while the actual security value depends on reviewer attention that the scale of the review makes impractical.
For TPRM programs, the practical governance approach is to ask vendors about access review quality indicators rather than just cadence , specifically, what percentage of accounts are revoked or modified at each review cycle. A quarterly access review that modifies zero accounts is almost certainly a rubber-stamp process. A quarterly review that consistently revokes five to fifteen percent of accounts is demonstrating genuine challenge activity. The revocation rate is the quality indicator that review cadence cannot provide.
- Ask about access review revocation rates , percentage of accounts revoked or modified at each cycle as a quality proxy
- Ask about account context provided to reviewers , employment status, last login, and account purpose in review data
- Ask about automated deprovisioning , whether HR system integration prevents orphaned accounts before they reach the review
- Require independent validation evidence , post-review sample verification of approved accounts
- Ask about review scope , all access types including analytics and collaboration platforms
If you are a small team
Ask your highest-risk vendors one quality question alongside their standard access review confirmation: in your most recent access review, what percentage of accounts were revoked or modified as a result of the review? A number close to zero means the review is confirming the existing access list rather than challenging it. A meaningful revocation rate , five percent or more , means the review is finding and removing accounts that should not exist. That single number tells you more about access review quality than the cadence answer ever will.
- Ask for the revocation rate from the most recent access review , the quality proxy cadence cannot provide
- Ask what account context is provided to reviewers during the review
- Ask whether automated HR deprovisioning prevents orphaned accounts before the review
- Ask whether analytics and collaboration access is included in review scope
What to require
Ask directly:
"In your most recent access review, what percentage of accounts were revoked or had their access modified as a result of the review , and does that percentage reflect genuine challenge activity or confirmation of an existing access list?"
"What context is provided to reviewers for each account , specifically, does each account entry show current employment status, last login date, account creation date, and account purpose?"
"Do you have automated deprovisioning integrated with your HR system that removes access when employees depart , and if so, what percentage of access removals are handled automatically versus through the access review cycle?"
Expect as evidence
- Access review revocation rate from most recent cycle
- Access review data format showing account context provided to reviewers
- Automated deprovisioning confirmation and HR integration description
- Review scope confirmation including analytics and collaboration platforms
A vendor who responds to the revocation rate question with 'our access reviews are thorough and quarterly' has described the frequency again. Ask for the specific number , what percentage of accounts were revoked in the last review. If the answer is zero or close to it, the review is confirming the list, not challenging it.
How to evidence it
Access reviews are required by PCI-DSS Requirement 7 and 8, SOC 2 Trust Services Criteria for logical access, ISO 27001 A.9 controls, and HIPAA's access management implementation specifications. Demonstrating due diligence requires evidence that review quality was assessed alongside review frequency.
- Vendor assessment records documenting review quality questions , revocation rate, account context, scope
- Access review revocation rate evidence from recent cycles
- Automated deprovisioning integration confirmation
- Review scope confirmation covering analytics and collaboration access
Key Takeaway
The access review that approves every account produces a compliance artifact without a security outcome. The review is complete. The former employees are still active. The contractors whose engagements ended months ago still have credentials. The accounts whose purposes changed two years ago still carry the access they were granted for a role that no longer exists. Access review quality is measured by what it finds and removes, not by how often it is conducted. A quarterly review with a zero percent revocation rate is a quarterly rubber stamp. An annual review that removes fifteen percent of accounts is an annual genuine assessment. Ask for the revocation rate. It is the number that review frequency cannot provide.
Speak to It™
The term you nodded along to, explained in ninety seconds, so you can speak to it professionally. It is how most readers find these articles.
Join the Association