How to Answer Periodic Access Review Questions
Your customer asked: “Do you conduct periodic user access reviews?”
The short answer
A periodic access review is a deliberate check that existing access is still appropriate. Routine account administration is not automatically a periodic review. Answer based on whether your company actually performs a recurring review and can describe its scope and frequency.
Educational guidance only. This page does not determine what is true about your company and does not create a security, compliance, testing, or certification claim.
What the customer is really asking
Understand the question before you answer it.
The customer is asking whether access that was once appropriate is reassessed later. They may want to know who reviews it, which systems are covered, how often the review occurs, and what happens when access is no longer needed.
How to answer accurately
Start with the version that matches reality.
If reviews occur on a schedule
State the actual cadence and scope, then describe who reviews access and how changes are handled.
If reviews happen only when roles change
Do not call that periodic unless there is also a recurring review. Describe the event-driven process you actually use.
If you have never performed a formal review
A truthful “not currently” is better than relabeling normal user administration as a periodic control.
A useful answer structure
Status → scope → current practice → supporting information. Start with the direct answer, narrow it to what you can verify, explain how the practice works, and reference evidence only when that evidence actually exists.
Evidence that may help
These are examples, not requirements and not proof that your company has the practice. Use only evidence that really exists and is appropriate to share.
- Dated access-review record
- Reviewer sign-off
- User and privilege export used for the review
- Tickets or notes showing access changes from the review
What not to say
- That access is reviewed quarterly because someone occasionally checks accounts.
- That automated account sync is the same as human or rules-based access review.
- That a policy requiring reviews proves reviews occurred.
How Oredra handles this
Answer it once. Keep the truth behind the answer.
Oredra can distinguish “we intend to review access” from “a review was performed and evidence exists,” which keeps questionnaire language precise.
Inside Oredra, a written policy, stated company practice, implemented control, available evidence, tested control, and independent certification remain distinct. Oredra uses approved information to draft future answers and flags questions that the approved profile cannot support.
Authoritative references
Oredra uses primary guidance where a technical or assurance concept benefits from verification. These references do not determine your company's answer.
Related questionnaire questions
Do you require multi-factor authentication (MFA)?
The reviewer is usually asking whether access requires more than a password and, just as importantly, where that requirement applies. Do not answer “yes” simply because your software supports MFA. Confirm that your company actually requires it for the users and systems in scope.
How do you provision user access?
Explain how a person receives access, who approves it, and how the access level is chosen. A written procedure is useful, but do not claim a formal approval workflow if access is actually granted informally.
How do you remove access when an employee or contractor leaves?
Describe who triggers access removal, who performs it, which account types are covered, and any timing you can actually support. Avoid promising immediate or same-day removal unless that is a verified company practice.