Definition

What Is a User Access Review (UAR)?

A user access review (UAR) is the regular check that each person has only the access their job requires, and the removal of anything they should not have. It is also called access recertification or access attestation. For credit unions and community banks, regular UARs are a core control that NCUA and FDIC examiners expect, because they catch the excess and stale access that most internal breaches use.

What a good user access review includes

  • A full, current list of who has access to each system
  • The right reviewer assigned to each item
  • A clear approve or deny decision on every entry
  • Proof that anything denied was removed
  • A timestamped record of the whole process

Why do user access reviews matter?

Access spreads over time. People change roles, projects end, and vendors come and go, but access often stays behind. That leftover access is where many internal breaches begin, and it is one of the first things an examiner checks. A regular UAR keeps access aligned with roles, reduces risk, and produces the evidence your examination requires.

How often should you run a user access review?

Most financial institutions run a full UAR quarterly or twice a year, and run more frequent reviews for privileged, service, vendor, and administrative accounts. The right cadence depends on your risk profile and your examiners’ expectations.

User access review vs. entitlement review

A user access review confirms that a person should have access to a system at all. An entitlement review goes deeper and confirms that the specific permissions inside that system are appropriate for the person’s role. A strong program does both. See the glossary for related terms.

Why spreadsheets fall short

A spreadsheet review is out of date the moment you export it, cannot prove that a flagged item was actually fixed, and consumes days of staff time each cycle. See the full comparison in spreadsheets vs. Provision.

How Provision handles user access reviews

Provision runs scheduled, scoped reviews, routes each item to the right reviewer, and turns every approve or deny decision into a task that is closed with proof. Reporting runs on a complete data set, so your evidence is ready before the examiner asks. This is the core of the Insight tier, covered in depth on the user access reviews solution page.

Frequently asked

How often should UARs happen?
Usually quarterly or twice a year, and more often for privileged, service, and vendor accounts.
What is the difference between a UAR and an entitlement review?
A UAR confirms a person should have a system. An entitlement review confirms the specific permissions inside it are appropriate.
Who should perform the review?
The manager or system owner who understands what access each role needs, with the process coordinated centrally.

Run a review without the spreadsheet.

See how a UAR runs end to end in Provision, scoped, decided, and exported audit-ready.