ISO 27001 User Access Review: What Annex A 5.18 Actually Requires

ISO 27001:2022 doesn't just recommend reviewing who has access to what — Annex A 5.18 makes it a control auditors will test directly. This article breaks down what the standard requires, what auditors actually check during certification, and why a growing number of ISO 27001-certified companies are moving user access review off spreadsheets and onto purpose-built platforms like Squarum.
IOS27001 User Access Revieew

If you’re preparing for an ISO 27001 audit, you’ve probably already found the clause everyone quotes and few people fully implement: Annex A 5.18, Access Rights. It sounds simple — review who has access, remove what they don’t need. In practice, it’s one of the most commonly flagged nonconformities during certification and surveillance audits, because “we review access” and “we can prove we reviewed access, on a schedule, with sign-off” are two very different things.

What Annex A 5.18 says

In the 2022 revision of ISO 27001, Annex A 5.18 consolidated what used to be several separate controls under the 2013 standard — user registration and de-registration, management of privileged access rights, and the review of user access rights (formerly 9.2.1, 9.2.2, and 9.2.5). The consolidated control requires that access rights be provisioned, reviewed, modified, and removed in line with the organization’s own access control policy, throughout the full lifecycle of a user account — from onboarding to role change to offboarding.

The intent behind the control is straightforward: access should only exist because someone with the authority to grant it decided it was necessary, and that decision should be revisited at planned intervals rather than left to persist indefinitely. Left unchecked, access accumulates — a phenomenon commonly called privilege creep — and it becomes one of the more exploitable gaps in an otherwise well-designed ISMS.

What auditors actually want to see

A certification auditor testing 5.18 isn’t looking for a policy document alone. They typically want evidence of:

What the auditor checks Why it matters
A defined review cadence (e.g. quarterly) Shows access review is planned, not ad hoc
Named reviewers, tied to specific systems or roles Confirms accountability rests with the asset owner, not IT alone
Documented outcomes per review cycle Proves the review actually happened and had a result
Evidence that flagged access was actually removed Closes the loop between “reviewed” and “remediated”
Tighter scrutiny of privileged and admin accounts Higher-risk access warrants more frequent review

Where spreadsheet-based reviews break down

Most organizations start their access review process in Excel, and for a first certification cycle, that’s often enough to pass. The problems tend to surface later — at surveillance audit, or after headcount grows past a hundred people. A spreadsheet can’t natively answer “who approved this,” it doesn’t lock a record once it’s reviewed, and it’s trivially easy to overwrite a prior cycle’s evidence without anyone noticing. When an auditor asks for last quarter’s sign-off trail and the only version that exists is the one currently open on someone’s laptop, that’s a nonconformity waiting to happen.

This is precisely the gap Squarum’s ISO 27001 user access review page addresses directly: how the standard’s wording maps onto an actual, auditable workflow, and what a review record needs to contain to hold up under audit scrutiny rather than just internal habit.

Squarum for ISO 27001
Squarum turns Annex A 5.18 into a recurring, evidence-generating workflow — role-based access matrices, timestamped reviewer sign-off, and an immutable audit trail your certification body can actually rely on. See how it maps to your ISMS on the ISO 27001 user access review page.

Frequently asked questions

How often does ISO 27001 require user access reviews?

The standard itself doesn’t state a fixed number of days or months — it requires reviews “at planned intervals,” meaning the organization defines its own cadence in its access control policy and then follows it consistently. Most certified organizations settle on quarterly reviews for standard access and more frequent cycles (often monthly) for privileged or admin-level accounts, since the earlier 2013 wording explicitly called out higher-risk accounts for closer attention.

Who is responsible for conducting the access review under Annex A 5.18?

Responsibility sits with the asset owner — the person or role accountable for the system or data in question — not with IT by default. IT typically provisions and de-provisions access, but the decision about whether access is still appropriate belongs to whoever owns the underlying business risk. Auditors will often ask you to name that person by system, which is where undocumented or informal review processes tend to fall apart.

Can we still use a spreadsheet for ISO 27001 access reviews?

You can, and many organizations pass their initial certification that way. The risk isn’t in day one — it’s in proving a consistent, unbroken audit trail across every review cycle since, without a single overwritten cell or missing sign-off. As user counts and system counts grow, that becomes harder to guarantee manually, which is why more ISO 27001-certified teams are shifting to dedicated tools that generate the evidence automatically.