Access Review (Access Certification)

Access Review is the regular, documented review of existing access rights by responsible persons. It confirms or revokes whether users, groups and technical identities still need the permissions assigned to them. Internationally, the term access certification is also used; in German-speaking countries, the term recertification is common.

Access reviews usually run as campaigns, for example quarterly per application, role or organizational unit, or event-driven after role changes and project closures. The reviewers are usually line managers as well as application or data owners. A well-known problem is blanket confirmation without a real check (rubber stamping) when too many rights are presented at once. Risk-based prioritization, usage data and clear decision templates counteract this.

The regular review of access rights is anchored, among other things, in ISO/IEC 27001 (Annex A 5.18); regulatory frameworks such as NIS2 and DORA also require regulated access controls. Tools for Identity Governance and Administration (IGA) automate campaigns, reminders and audit evidence. Access reviews enforce the Least Privilege principle organizationally and are a governance building block of Identity Security.