SOC 2 Wants Proof.
Not a Spreadsheet.
Most access reviews are a formality. Managers approve without context, shadow IT goes unreviewed, and evidence is thin. Here is what SOC 2 and ISO 27001 actually require, and what closing the gap looks like.
Your access review works on paper
Every quarter, someone on the security team sends a spreadsheet to 40 managers. The managers are busy, uncertain about what their reports actually use, and unclear on what "review" really means. They click approved on most rows and send it back. Someone collects the responses. The audit evidence folder gets another attachment.
This is how most companies do access reviews today. It satisfies the letter of the requirement. It increasingly doesn't satisfy auditors, and it definitely doesn't satisfy the spirit of what SOC 2 and ISO 27001 are asking for.
What the standards actually require
Both SOC 2 and ISO 27001 care about the same fundamental question: can you prove that access is controlled, appropriate, and cleaned up when it shouldn't be there anymore?
The key distinction for SOC 2 is between Type I and Type II. Type I says: "we have controls designed to achieve these criteria." Type II says: "those controls operated effectively over the audit period." For access reviews, Type II means demonstrating that reviews happened, were complete, and resulted in removals, consistently over 6–12 months.
"We have a policy" is a Type I answer to a Type II question.
Three ways access reviews fail in practice
What good evidence looks like
What auditors want to see is a closed loop: discovery → review → decision → remediation → evidence. Each step traceable, timestamped, and attributable to a named reviewer.
Here's what a structured review campaign looks like when the data is actually there to support it:
The "last active" column is what makes the difference between a real review and a rubber stamp. Without it, a manager reviewing Tom's access has no basis for a decision. With it, "94 days ago" on a Salesforce admin account is an obvious flag.
For audit purposes, the export from this review needs to show:
The frequency question
SOC 2 doesn't prescribe a specific review cadence, but most auditors expect quarterly reviews for privileged access and at least annual for standard users. ISO 27001 says "at regular intervals", typically interpreted as quarterly or semi-annual depending on your risk profile.
The more useful question is: why is frequency the constraint?
The quarterly cadence is an artifact of the manual process. Collecting access data, building spreadsheets, chasing manager responses, reconciling removals. It takes long enough that doing it more often isn't realistic. But the underlying risk is continuous. Someone changes roles on a Tuesday in February. The next review isn't until April. For two months, they have access they shouldn't.
When access data is live and review campaigns are automated, reviews can be triggered by events: a role change, a project closing, 60 days of inactivity, rather than just the calendar. The quarterly review becomes a compliance artifact that confirms what continuous monitoring already caught, rather than a first line of discovery.
That's the difference between access review as a compliance exercise and access review as an actual control.