NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new
Access reviews

The review is easy. Knowing what to review is the hard part.

Most access review programmes certify a spreadsheet export rather than the actual estate, which is how a confident sign-off ends up covering the wrong data. Venvera holds a register of every entitlement, including the service accounts and third-party access that never reach your joiners process, scores each one on a published model, and turns the whole thing into a review cycle with a decision trail.

Access Reviews is included on every plan, from EUR 399 per month. Several platforms in this category sell it as a separate module or reserve it for an enterprise tier.
ISO 27001 A.5.15SOC 2 CC6NIS2 Art. 21(i)DORA Art. 9PCI DSS Req. 7

A review of an incomplete list is worse than no review.

Export users from three systems, paste into a workbook, send it round, collect approvals. What just got certified is the export, not the estate. The systems nobody remembered are not in the file, so they were not reviewed, and you now hold a signed document asserting a state you never checked. Venvera fixes the order of operations: build the register first, score it so attention lands on the entitlements that matter, then review.

 app.venvera.com
/ ACCESS REVIEWS - the register, scored and sorted by risk
/ ACCESS REVIEWS - the register, scored and sorted by risk
0-11
Published risk score, computed in the database
4
Account types including service and third party
Auto
Review status derived from the last review date
Free
Included on every plan
The register

Every entitlement, including the ones with no manager to ask.

One row per identity, system and access level, covering employees, contractors, ICT third-party providers and service accounts. The categories that fall out of a spreadsheet review are the ones that carry the most risk, so they are first-class account types here rather than a footnote.

  • Employees, contractors, third-party providers and service accounts
  • Each entitlement linked to the ICT asset it grants access over
  • Approval date, ticket reference and approver recorded per entry
  • CSV import so existing exports load rather than get retyped
  • Active, suspended and revoked states, with revocation dates
 app.venvera.com
/ 27 entitlements, sorted by risk, with review status derived
/ 27 entitlements, sorted by risk, with review status derived
Risk scoring

A score you can recompute by hand, and argue with.

A red badge with no published model fails the first question an auditor asks. Venvera scores each entitlement from 0 to 11 using weights we publish: account type, criticality, data classification, access level, privileged and remote access add; multi-factor authentication, activity logging and a strong password policy subtract.

  • Deterministic, so two people scoring the same entitlement agree
  • Computed in the database, never written by the application
  • Compensating controls subtract, rewarding a real fix over another review
  • Live preview of the score while you record the attributes
  • Filter the register by minimum score to find the tail that matters
 app.venvera.com
/ Filtered to score 6 and above: service accounts and third parties first
/ Filtered to score 6 and above: service accounts and third parties first
Review cycles

Scope a cycle, decide per item, keep the reasoning.

A cycle over everything is a cycle nobody finishes. Scope by risk score, system or status, assign reviewers who can actually revoke, and require a justification on every decision, including the approvals. The risk score is stamped onto each decision at the moment it is made.

  • Scope by score, system or review status
  • Approve, modify or revoke, per item
  • Justification required on every decision
  • Risk score recorded at the point of decision, not just today
  • Export the cycle as an evidence pack for the auditor
 app.venvera.com
/ Cycles turn a static register into a repeatable event
/ Cycles turn a static register into a repeatable event
Evidence

One cycle, evidenced against every framework that asks.

The review satisfies overlapping requirements in ISO 27001, SOC 2, NIS2, DORA and PCI DSS. Rather than filing the same artefact five times, the evidence maps to each control, so a single annual cycle answers all of them and stays current in one place.

  • Mapped to ISO 27001 Annex A access control
  • Mapped to the SOC 2 logical access common criteria
  • Mapped to NIS2 Article 21(i) and DORA Article 9
  • Mapped to PCI DSS Requirement 7
  • Evidence entered once, counted by every framework you run
 app.venvera.com
/ Attributes in, score out, evidence mapped
/ Attributes in, score out, evidence mapped

Access reviews, answered.

Related: User access review software: a guide, ISO 27001, NIS2, DORA

See your access risk before your auditor does.

Build your register with us in 30 minutes. Bring your systems list and leave with a scored register and a scoped first cycle.

Every paid plan: audit-ready in 90 days, or your money back*

10 minutes · no email to start · no credit card · yours to keep