Scrutineer · Platform
User access review software and tools to automate SOC 2, SOX and PCI access reviews
The user access review is the control auditors test hardest, and the one most teams still run in a spreadsheet.
Scrutineer pulls entitlements from the systems you already use, routes each review to the owner who can judge it, and keeps the decisions and revocations as evidence.
Control-mapped findings · linked evidence · you decide what to remediate
›
Illustrative sample · not an audit attestation
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with access reviews
Entitlements pulled, not requested
Read-only connections to your identity provider, cloud accounts and business systems build the review population directly from live entitlement data. Nobody exports a CSV, and nobody reviews a list that was already out of date when it was pasted into the sheet.
Routed to the owner who can judge it
A review is only worth the judgment behind it. Scrutineer sends each account to the system or data owner who knows what the access is for, chases the ones nobody answered, and records who decided what and when.
Revocation closed, not just recommended
Auditors do not test the decision, they test the follow-through. Every remove decision stays open until the access is actually gone, and the closure timestamp sits alongside the original review as one piece of evidence.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Builds the review population from live entitlement data, not exported spreadsheets
- Routes each account to the system owner and chases the reviews nobody completed
- Tracks every revocation through to closure, with the timestamp an auditor asks for
- Maps one review to SOC 2, ISO 27001, PCI DSS, SOX ITGC and HIPAA at the same time
- Flags dormant accounts, orphaned accounts and privilege that outgrew the role
- Keeps a dated history so the second review is a comparison rather than a restart
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
Requirement reference
What each framework requires of a user access review
One review can satisfy every row below, which is the whole argument for running it against a mapped control set. Note how few frameworks actually name a frequency: most test you against the cadence you wrote in your own policy.
| Framework | Where the requirement sits | Stated frequency | What gets tested |
|---|---|---|---|
| SOC 2 | The CC6 logical access common criteria. Access reviews are the control teams normally map to CC6.3, alongside provisioning and deprovisioning under CC6.1 and CC6.2. | None stated. The Trust Services Criteria do not name an interval, so you are tested against your own policy. Auditors report treating annual-only reviews on in-scope systems as thin. | That the population was complete, the reviewer was appropriate, and every removal decision was carried out. |
| ISO 27001:2022 | Annex A 5.18, access rights: access is provisioned, reviewed, modified and removed in line with the access control policy. | None stated. Regular review at intervals you define, with asset owners involved. | That asset owners, not just IT, made the decisions, and that role changes were caught as well as leavers. |
| PCI DSS v4.0 | Requirement 7.2.4 for user accounts. Application and system accounts sit separately under 7.2.5. | At least once every six months for user accounts, including third-party and vendor accounts. Application and system account frequency comes from a targeted risk analysis. | That access still matches the role, that inappropriate access was addressed, and that management acknowledged the result. |
| SOX ITGC | The access to programs and data control family, tested by the external auditor over systems in scope for financial reporting. | Not set by statute. Quarterly is the common practice for in-scope financial systems. | Whether the auditor can rely on the system. A failed review pushes the audit toward substantive testing, which costs far more. |
| HIPAA Security Rule | Information access management at 45 CFR 164.308(a)(4), with the information system activity review at 164.308(a)(1)(ii)(D). | None stated. The rule requires the process, not an interval. | That access to protected health information is granted by role and that the authorization is documented and current. |
| NIST SP 800-53 and CMMC | Account management under AC-2, which carries into NIST SP 800-171 and CMMC Level 2 for defense contractors. | An organization-defined frequency. FedRAMP baselines set that parameter for cloud service providers. | Account inventory accuracy, and whether accounts were disabled when they were no longer required. |
| Running it once for all six | A single mapped control set, reviewed on the shortest applicable cadence, evidenced once. | Set by the strictest framework in your scope. This is where Scrutineer sits. | Nothing extra. That is the point: the same population, decisions and revocation records answer every row above. |
Clause references are to SOC 2 Trust Services Criteria CC6, ISO/IEC 27001:2022 Annex A 5.18, PCI DSS v4.0 requirements 7.2.4 and 7.2.5, and 45 CFR 164.308. Frequencies described as common practice are what auditors and practitioners report expecting rather than published requirements, and only PCI DSS states an interval in the standard itself. Confirm scope and cadence with your own auditor. Scrutineer prepares and maintains access review evidence; it does not provision or revoke access, and an accredited auditor issues any attestation.
Good questions
Questions about access reviews
Keep reading
Guides that go deeper on access controls and the audits that test them
All 93 ISO 27001 Annex A controls
Where 5.18 access rights sits in the 2022 control set, and the other controls your access review evidence already answers.
Read the guideThe SOC 2 audit checklist
The CC6 logical access work in sequence, and what an auditor asks for when they sample your access reviews.
Read the guideThe PCI DSS compliance checklist
The only framework here that names a review frequency outright, plus the SAQ that decides how much of requirement 7 applies to you.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification