Scrutineer.ai

Scrutineer · Platform

User access review software and tools to automate SOC 2, SOX and PCI access reviews

The user access review is the control auditors test hardest, and the one most teams still run in a spreadsheet.

Scrutineer pulls entitlements from the systems you already use, routes each review to the owner who can judge it, and keeps the decisions and revocations as evidence.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Illustrative sample · not an audit attestation

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with access reviews

Entitlements pulled, not requested

Read-only connections to your identity provider, cloud accounts and business systems build the review population directly from live entitlement data. Nobody exports a CSV, and nobody reviews a list that was already out of date when it was pasted into the sheet.

Routed to the owner who can judge it

A review is only worth the judgment behind it. Scrutineer sends each account to the system or data owner who knows what the access is for, chases the ones nobody answered, and records who decided what and when.

Revocation closed, not just recommended

Auditors do not test the decision, they test the follow-through. Every remove decision stays open until the access is actually gone, and the closure timestamp sits alongside the original review as one piece of evidence.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Builds the review population from live entitlement data, not exported spreadsheets
  • Routes each account to the system owner and chases the reviews nobody completed
  • Tracks every revocation through to closure, with the timestamp an auditor asks for
  • Maps one review to SOC 2, ISO 27001, PCI DSS, SOX ITGC and HIPAA at the same time
  • Flags dormant accounts, orphaned accounts and privilege that outgrew the role
  • Keeps a dated history so the second review is a comparison rather than a restart
ACCESS REVIEWS readiness_report
READINESS · 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Example report layout, not customer data

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

Requirement reference

What each framework requires of a user access review

One review can satisfy every row below, which is the whole argument for running it against a mapped control set. Note how few frameworks actually name a frequency: most test you against the cadence you wrote in your own policy.

Framework Where the requirement sits Stated frequency What gets tested
SOC 2 The CC6 logical access common criteria. Access reviews are the control teams normally map to CC6.3, alongside provisioning and deprovisioning under CC6.1 and CC6.2. None stated. The Trust Services Criteria do not name an interval, so you are tested against your own policy. Auditors report treating annual-only reviews on in-scope systems as thin. That the population was complete, the reviewer was appropriate, and every removal decision was carried out.
ISO 27001:2022 Annex A 5.18, access rights: access is provisioned, reviewed, modified and removed in line with the access control policy. None stated. Regular review at intervals you define, with asset owners involved. That asset owners, not just IT, made the decisions, and that role changes were caught as well as leavers.
PCI DSS v4.0 Requirement 7.2.4 for user accounts. Application and system accounts sit separately under 7.2.5. At least once every six months for user accounts, including third-party and vendor accounts. Application and system account frequency comes from a targeted risk analysis. That access still matches the role, that inappropriate access was addressed, and that management acknowledged the result.
SOX ITGC The access to programs and data control family, tested by the external auditor over systems in scope for financial reporting. Not set by statute. Quarterly is the common practice for in-scope financial systems. Whether the auditor can rely on the system. A failed review pushes the audit toward substantive testing, which costs far more.
HIPAA Security Rule Information access management at 45 CFR 164.308(a)(4), with the information system activity review at 164.308(a)(1)(ii)(D). None stated. The rule requires the process, not an interval. That access to protected health information is granted by role and that the authorization is documented and current.
NIST SP 800-53 and CMMC Account management under AC-2, which carries into NIST SP 800-171 and CMMC Level 2 for defense contractors. An organization-defined frequency. FedRAMP baselines set that parameter for cloud service providers. Account inventory accuracy, and whether accounts were disabled when they were no longer required.
Running it once for all six A single mapped control set, reviewed on the shortest applicable cadence, evidenced once. Set by the strictest framework in your scope. This is where Scrutineer sits. Nothing extra. That is the point: the same population, decisions and revocation records answer every row above.

Clause references are to SOC 2 Trust Services Criteria CC6, ISO/IEC 27001:2022 Annex A 5.18, PCI DSS v4.0 requirements 7.2.4 and 7.2.5, and 45 CFR 164.308. Frequencies described as common practice are what auditors and practitioners report expecting rather than published requirements, and only PCI DSS states an interval in the standard itself. Confirm scope and cadence with your own auditor. Scrutineer prepares and maintains access review evidence; it does not provision or revoke access, and an accredited auditor issues any attestation.

Good questions

Questions about access reviews

A user access review is a periodic check that every account in a system still belongs to someone who needs it, at the privilege level their current job requires. An owner looks at each account and decides to keep, modify or remove the access, and the decisions plus the resulting revocations are retained as evidence. It is also called a user entitlement review or an access certification.
An application user access review is the same exercise scoped to a single business application rather than to the identity provider. It matters because application-level entitlements, roles inside an ERP or permission sets inside a CRM, are usually invisible from your single sign-on directory. Someone can be correctly provisioned into an application and still hold a role inside it that nobody ever approved.
It is a detective control. The access already exists by the time anyone reviews it, so the review finds problems rather than stopping them. Provisioning approval and automated deprovisioning are the preventive controls. Auditors care about the pairing: a strong review that keeps finding the same leaver accounts is evidence that the preventive control is not working.
Both, and for several others. SOC 2 tests access reviews under the CC6 logical access criteria, ISO 27001 under Annex A 5.18 access rights, PCI DSS under requirement 7.2.4, and SOX through the IT general controls the external auditor tests. The underlying evidence is the same, which is why running the review once against a mapped control set is far cheaper than running it separately per framework.
Quarterly is the working standard for in-scope systems, and it is what most auditors expect to see. PCI DSS is the only major framework that names a frequency outright: requirement 7.2.4 sets at least once every six months for user accounts. SOC 2, ISO 27001 and HIPAA leave the interval to you, so you set it in your policy and are then tested against your own stated cadence.
PCI DSS v4.0 requirement 7.2.4 requires that all user accounts and related access privileges, including third-party and vendor accounts, are reviewed at least once every six months, with management confirming that the access remains appropriate. Application and system accounts are handled separately under 7.2.5, where the review frequency is set by a targeted risk analysis rather than fixed at six months.
Four things, and the fourth is where reviews fail. The complete population of accounts and how you proved it was complete. The reviewer, and evidence they were the right person to decide. The decision for each account, dated. And proof that every remove decision was actually carried out, with the revocation timestamp. A signed spreadsheet with no revocation evidence is the most common exception in this area.
In IT general controls, the user access review is one of the access-to-programs-and-data controls the external auditor tests as part of a financial statement audit. If it fails, the auditor cannot rely on the automated controls or the reports coming out of that system, so the failure spreads into the substantive audit work. That knock-on effect is why access review exceptions get escalated faster than most control failures.
Connect to the systems that hold the entitlements so the population builds itself, map each system to the owner who reviews it, schedule the campaign, and let the tool chase incomplete reviews and track revocations to closure. The part worth automating is not the sign-off click. It is the population build and the revocation follow-through, which is where the manual process actually breaks.
Identity governance platforms provision and enforce access: they can grant, change and revoke entitlements directly. Access review software collects entitlements, runs the review and produces the evidence, then hands the revocation to whoever owns the system. Buyers who need an audit finding closed usually need the second and get sold the first, which costs several times more and takes months to deploy.
A privileged access review is the same process narrowed to accounts that can change security settings, access production data or grant access to others: administrators, break-glass accounts, service accounts with elevated rights. Most policies review these more often than standard accounts, monthly or quarterly, because a single stale privileged account is worth more to an attacker than a hundred stale read-only ones.
No. Scrutineer connects to your identity provider and your business systems read-only, and it does not grant or revoke access itself. It builds the review population, routes the decisions, tracks each revocation to closure and keeps the evidence mapped to the frameworks you report against. Provisioning stays where it is.

Keep reading

Guides that go deeper on access controls and the audits that test them

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification