š GRC education: If you're pursuing SOC 2 Type II, access reviews are a required periodic control ā and most auditors expect them quarterly.
Here's what auditors look for:
ā
Evidence that you reviewed who has access to each in-scope system
ā
Documentation of your review decisions (approve, revoke, escalate)
ā
Timely revocation of access for anyone flagged during the review
ā
Consistent cadence ā not just a one-time review right before the audit
Common gaps we see:
ā Reviews run once a year instead of quarterly
ā No documentation of decisions ā just informal Slack threads
ā Terminated employees missed because they had direct app logins outside SSO
The good news: when access reviews are run in Vanta, the evidence is captured automatically ā no manual screenshots required.
How frequently is your team running access reviews? š