Access Review
An access review is the periodic, recorded check that every user’s access to your systems still matches their role — quarterly for most SOC 2 programs. It’s among the first controls auditors sample and among the most common sources of report exceptions, because it requires sustained discipline rather than one-time configuration.
What a defensible review looks like
Pull the actual user lists from each in-scope system (not from memory); have someone with context review each entry — typically the system owner; record the decision per user: appropriate, modify, or revoke; execute the revocations within a defined window; and keep the artifact — reviewer, date, decisions, and completed changes. The record is the control. A review that happened but wasn’t recorded, didn’t happen.
Why teams fail it
Quarter one is easy. Quarter three lands mid-crunch, the review slips six weeks, and the observation window now contains a gap that becomes a report exception. The failure isn’t knowledge — everyone knows what an access review is — it’s cadence ownership, which is why automation that generates the review and chases the reviewers (people management) or an operator who owns the calendar (outsourced compliance) is what separates clean reports from qualified ones.
Continuous Monitoring — Continuous monitoring is the automated, ongoing testing of security controls — replacing point-in-time evidence scrambles with always-current audit readiness.
SOC 2 Type I vs Type II — Type I attests your controls are designed properly at a point in time. Type II attests they operated over a period. Here's which one customers accept.