1. Purpose
The Contractor Access Review Checklist is used to periodically verify that contractors, consultants, freelancers, temporary workers, and other external personnel continue to have only the access required for their current business engagement.
The review helps confirm that contractor access is:
- Authorized
- Business-justified
- Current
- Appropriate for the contractor’s role
- Limited to the required systems and information
- Appropriately authenticated and protected
- Time-bound where practical
- Consistent with contractual requirements
- Removed when the engagement or business need ends
Core Principle
Identify → Validate → Review → Correct → Verify → Record
2. Review Information
| Field | Details |
|---|---|
| Review ID | |
| Review Period | |
| Review Date | |
| Business Unit | |
| Contractor Population | |
| Reviewer | |
| Security/ISMS Reviewer | |
| Contractor Manager/Sponsor | |
| Review Owner | |
| Previous Review | |
| Evidence Repository | |
| Review Status | Open / In Progress / Completed |
3. Contractor Information
| Field | Details |
|---|---|
| Contractor Name | |
| Contractor ID | |
| Organization/Vendor | |
| Contractor Type | Consultant / Freelancer / Temporary / Vendor |
| Internal Sponsor | |
| Manager | |
| Department | |
| Project | |
| Role | |
| Contract/SOW | |
| Contract Start Date | |
| Contract End Date | |
| Review Date | |
| Engagement Status | Active / Ending / Ended |
4. Review Scope
Review all systems and information to which the contractor has access.
Systems
☐ Corporate Email
☐ Identity Provider/SSO
☐ SaaS Applications
☐ AWS/Azure/GCP
☐ Production Environment
☐ Development Environment
☐ Test Environment
☐ Databases
☐ Source-Code Repository
☐ CI/CD Platform
☐ VPN/Remote Access
☐ Customer Systems
☐ Security Platforms
☐ File-Sharing Platforms
☐ Collaboration Tools
☐ Other Critical Systems
5. Contract and Engagement Review
Confirm:
☐ Contractor engagement is still active
☐ Contract/SOW is valid
☐ Contract end date is recorded
☐ Contractor’s role remains unchanged
☐ Internal sponsor remains responsible
☐ Business purpose remains valid
☐ Security requirements are included where applicable
☐ Confidentiality/NDA requirements remain applicable
☐ Data protection requirements are addressed where applicable
☐ Customer contractual requirements are considered
☐ Subcontractor involvement is known and authorized
Contractual Issues Identified
6. Business Need Review
Confirm that the contractor still requires access.
| Review Question | Result |
|---|---|
| Is the contractor still working for the organization? | Yes / No |
| Is the project still active? | Yes / No |
| Is the original business purpose still valid? | Yes / No |
| Is the access still required? | Yes / No |
| Could access be reduced? | Yes / No |
| Could access be removed? | Yes / No |
| Is the contractor’s role unchanged? | Yes / No |
Business Justification
7. Contractor Identity Verification
Verify:
☐ Contractor identity is known
☐ Contractor organization is known
☐ Internal sponsor is identified
☐ Account belongs to the correct individual
☐ Shared contractor account is not being used without approved justification
☐ Identity is recorded in the Identity Register
☐ Contractor account is associated with the correct engagement
8. Access Rights Review
Compare the contractor’s actual access against approved access.
| System | Actual Access | Approved Access | Appropriate | Action |
|---|---|---|---|---|
| Yes / No | ||||
| Yes / No |
Check:
☐ Access is approved
☐ Access is still required
☐ Access matches contractor role
☐ Access matches business purpose
☐ Unnecessary permissions are absent
☐ Actual access matches the Access Rights Register
☐ Old project access has been removed
9. Least Privilege Review
Assess whether the contractor has more access than required.
☐ Only required systems are accessible
☐ Only required resources are accessible
☐ Only required information is accessible
☐ Read-only access is used where sufficient
☐ Administrative access is restricted
☐ Production access is separately justified
☐ Temporary permissions are appropriately limited
☐ Old permissions have been removed
Excess Access Identified
Required Action
10. Contractor Privileged Access Review
Identify contractors with elevated access.
Examples:
- Cloud administrator
- Database administrator
- Security administrator
- Network administrator
- Repository administrator
- CI/CD administrator
- Production administrator
- SaaS administrator
| Contractor | System | Privileged Role | Business Need | Approval | MFA | Decision |
|---|---|---|---|---|---|---|
Check:
☐ Privileged access is explicitly approved
☐ Business justification exists
☐ Privilege remains necessary
☐ Least privilege is applied
☐ MFA is enabled where required
☐ Activity is appropriately monitored
☐ Privileged access is recorded
☐ Access expiry is defined where appropriate
11. Production Access Review
Production access should receive additional scrutiny.
☐ Production access is required
☐ Business justification exists
☐ System owner approval exists
☐ Access is limited to required systems
☐ Access is limited to required resources
☐ Privileged access is separately approved
☐ MFA/strong authentication is applied where required
☐ Activity is appropriately logged
☐ Temporary access is removed when no longer required
Production Access Justification
12. AWS / Cloud Access Review
For contractors with AWS, Azure, or GCP access, review:
☐ Cloud account/subscription/project
☐ Identity/role
☐ Permissions
☐ Environment
☐ Production access
☐ Development access
☐ Database access
☐ Storage access
☐ Security administration
☐ Cross-account access
☐ MFA
☐ Access expiry
☐ Activity logging
AWS Example
A contractor supporting a SaaS application may have:
Corporate SSO → MFA → AWS Role → Development Account → Required Resources
The contractor should not automatically receive production administrator access merely because they require development access.
13. Source-Code Access Review
Review access to GitHub, GitLab, Bitbucket, or equivalent.
Check:
☐ Contractor is still assigned to the project
☐ Repository access remains required
☐ Repository scope is appropriate
☐ Organization-level access is justified
☐ Administrator permissions are justified
☐ External collaborator status is appropriate
☐ MFA is enabled where required
☐ Personal/shared accounts are appropriately controlled
☐ Deploy keys/tokens are reviewed where applicable
☐ Old repositories are removed
14. SaaS Application Access Review
Review critical SaaS applications used by contractors.
Examples:
- Microsoft 365
- Jira
- Slack/Teams
- Salesforce
- Customer support platforms
- HR platforms
- Security platforms
- Project-management systems
Check:
☐ Account active
☐ Business need valid
☐ Correct role
☐ Correct groups
☐ Administrator access justified
☐ External sharing reviewed
☐ Customer data access appropriate
☐ Contractor expiry recorded
15. Database Access Review
For contractor database access:
☐ Database identified
☐ Environment identified
☐ Access level documented
☐ Business purpose documented
☐ Production access separately approved
☐ Read/write access justified
☐ DBA privileges justified
☐ MFA/strong authentication applied where supported
☐ Activity logging appropriate
☐ Access remains necessary
16. Customer-System Access Review
If contractors access customer systems:
☐ Customer authorization exists where required
☐ Contract/SOW permits access
☐ Customer data access is necessary
☐ Access scope is defined
☐ Named individual account used
☐ MFA enabled where required
☐ Access is monitored where appropriate
☐ Customer-specific requirements are followed
☐ Access expiry is defined
☐ Access will be removed when engagement ends
17. Authentication Review
Verify:
☐ Contractor uses an individual identity
☐ MFA enabled where required
☐ Strong authentication configured
☐ SSO used where appropriate
☐ Password requirements followed
☐ Shared credentials avoided
☐ API keys/tokens appropriately controlled
☐ SSH keys appropriately managed
☐ Authentication information is not stored in the review record
Actual passwords, API keys, MFA secrets, private keys, or recovery codes must never be recorded in this checklist.
18. Temporary Access Review
Identify temporary contractor permissions.
| System | Access | Start Date | Expiry Date | Still Required | Action |
|---|---|---|---|---|---|
| Yes / No |
Check:
☐ Expiry date exists
☐ Expiry has not passed
☐ Extension is approved if required
☐ Temporary access has not become permanent without review
☐ Expired access is removed
19. Contractor Role Change Review
Identify contractors whose responsibilities have changed.
Check:
☐ Role change identified
☐ Existing access reviewed
☐ Old access removed
☐ New access approved
☐ New access provisioned
☐ Privileged access reassessed
☐ Access Register updated
☐ Verification completed
Important
A role change should not simply result in additional access.
The organization should first review and remove access that is no longer required.
20. Contractor Offboarding Check
For contractors whose engagement has ended:
☐ Engagement end confirmed
☐ Internal sponsor notified
☐ All accounts identified
☐ Corporate account disabled
☐ SSO access removed
☐ Email access removed
☐ SaaS access removed
☐ AWS/cloud access removed
☐ Source-code access removed
☐ Database access removed
☐ VPN access removed
☐ Customer-system access removed
☐ Privileged access removed
☐ API tokens reviewed/revoked
☐ SSH keys reviewed/revoked
☐ Physical access removed
☐ Company assets returned
☐ Organizational information returned/deleted where required
☐ Subcontractor access reviewed
☐ Access revocation verified
☐ Registers updated
21. Contractor Access Revocation Verification
Do not rely only on an email or ticket stating that access was removed.
Verify actual system status.
| System | Revocation Requested | Actual Status | Verified By | Date |
|---|---|---|---|---|
Examples of evidence:
- Account disabled
- Group membership removed
- Cloud role removed
- Repository access removed
- VPN access removed
- SaaS account disabled
- Database permissions removed
- API token revoked
- SSH key removed
22. Dormant Contractor Accounts
Identify contractor accounts with:
- No recent activity
- No current project
- Expired contract
- No active sponsor
- No documented business purpose
Action
Identify → Investigate → Confirm Need → Disable/Remove → Verify → Record
| Account | System | Last Activity | Sponsor | Finding | Action |
|---|---|---|---|---|---|
23. Orphaned Contractor Accounts
An orphaned contractor account is one where the organization cannot establish:
- Who the individual is
- Which organization they represent
- Who their sponsor is
- Why the account exists
- Which project they support
- Whether the engagement is still active
Required Response
☐ Investigate
☐ Identify Owner
☐ Confirm Business Need
☐ Restrict Access
☐ Revoke if Unauthorized/Unnecessary
☐ Verify
☐ Record
24. Segregation of Duties Review
Consider whether contractor access creates conflicts such as:
- Developer + production approval
- Access administrator + access approval
- Change implementer + change approver
- Security administrator + independent security review
Result
☐ No conflict
☐ Potential conflict
☐ Confirmed conflict
☐ Compensating control required
☐ Escalation required
Comments
25. Contractor Information Access Review
Assess what information the contractor can access.
| Information | Classification | Access Required | Appropriate |
|---|---|---|---|
| Public / Internal / Confidential / Restricted | Yes / No |
Pay particular attention to:
- Customer data
- Personal data
- Financial information
- Source code
- Security information
- Production information
- Credentials/secrets
- Confidential contracts
- Audit evidence
26. Third-Party / Subcontractor Review
Determine whether the contractor uses subcontractors or other personnel.
Check:
☐ Subcontractor involvement known
☐ Organization has approved subcontractor use
☐ Individual identities are known
☐ Access is separately authorized
☐ Contractual requirements apply
☐ Confidentiality requirements apply
☐ Data protection requirements are addressed where applicable
☐ Downstream access is reviewed
☐ Access is revoked when no longer required
27. Contractor Access Findings
| Finding ID | Contractor | System | Finding | Risk | Action | Owner | Due Date | Status |
|---|---|---|---|---|---|---|---|---|
Possible findings include:
- Excessive access
- Missing approval
- Expired contract
- Expired access
- Unnecessary production access
- Unapproved privileged access
- Dormant account
- Orphaned account
- Missing MFA
- Incorrect role
- Missing access expiry
- Uncontrolled third-party access
28. Finding Classification
The organization may classify findings as:
Conforming
Access is appropriate and adequately controlled.
Observation
A condition has been identified for monitoring or consideration.
Improvement Opportunity
A process or control could be strengthened.
Nonconformity
A defined requirement or control has not been adequately met.
Formal classifications should follow the organization’s audit methodology.
29. Corrective Action Register
| Action ID | Finding | Required Action | Owner | Due Date | Status | Verified |
|---|---|---|---|---|---|---|
Possible actions:
- Revoke access
- Reduce permissions
- Remove production access
- Disable account
- Enable MFA
- Add expiry date
- Update sponsor
- Update Access Rights Register
- Update Identity Register
- Rotate/revoke credentials
- Investigate access
- Implement compensating control
30. Remediation Verification
After corrective action:
☐ Actual access checked
☐ Permission change confirmed
☐ Account status confirmed
☐ Contractor record updated
☐ Access Rights Register updated
☐ Privileged Access Register updated where applicable
☐ Identity Register updated
☐ Evidence retained
☐ Reviewer confirmed closure
Verified By: ____________________
Date: ____________________
31. Contractor Access Review Summary
| Metric | Result |
|---|---|
| Contractors Reviewed | |
| Active Contractors | |
| Contractors Ending Engagement | |
| Systems Reviewed | |
| Privileged Contractors | |
| Production Access | |
| Third-Party Access | |
| Dormant Accounts | |
| Orphaned Accounts | |
| Excess Access Identified | |
| Access Revoked | |
| Access Modified | |
| MFA Issues | |
| Open Findings | |
| Closed Findings |
32. Review Conclusion
Overall Result
☐ Contractor access remains appropriate
☐ Corrections required
☐ Significant remediation required
☐ Further investigation required
Summary
Key Findings
Key Actions
33. Exceptions
| Exception ID | Contractor | Access | Reason | Risk | Compensating Control | Approver | Expiry |
|---|---|---|---|---|---|---|---|
Exceptions should be documented, approved, risk-assessed, and reviewed periodically.
34. Review Approval
Reviewer
Name: ____________________
Role: ____________________
Approval: ____________________
Date: ____________________
Contractor Manager/Sponsor
Name: ____________________
Approval: ____________________
Date: ____________________
System Owner
Name: ____________________
Approval: ____________________
Date: ____________________
Security/ISMS
Name: ____________________
Approval: ____________________
Date: ____________________
35. Evidence to Retain
Evidence may include:
- Contractor register
- Contract/SOW
- NDA/confidentiality agreement
- Access request
- Approval records
- Access Rights Register
- Privileged Access Register
- Identity Register
- SSO/IAM reports
- AWS/cloud access reports
- SaaS access reports
- Repository access reports
- Database access reports
- Access-review records
- Access-revocation evidence
- Change tickets
- Offboarding records
- Corrective-action records
- Exception approvals
Do not retain actual passwords, API keys, tokens, private keys, MFA secrets, or other authentication secrets in the review evidence.
36. Recommended Review Frequency
The organization should establish the frequency based on risk and business requirements.
Example:
| Contractor Type | Example Review |
|---|---|
| Standard Contractor | Periodic |
| Privileged Contractor | More frequent |
| Production Access | More frequent |
| Customer-System Access | Risk-based |
| High-Risk Data Access | More frequent |
| Temporary Contractor | At/near expiry |
| Third-Party Support | Periodic |
| Contractor Ending Engagement | Immediate offboarding review |
These are examples rather than universal ISO 27001-prescribed frequencies.
37. Startup-Friendly Contractor Access Review
A startup can perform this review using a spreadsheet and system exports.
Step 1 — Obtain Contractor Population
Start with:
HR/Contractor Register → Contractor Accounts → SSO → AWS → GitHub → SaaS → Databases
Step 2 — Compare Actual Access
Compare actual permissions against:
- Contractor Account Register
- Access Rights Register
- Privileged Access Register
- Approved access requests
Step 3 — Check Contract Status
Identify:
- Active contractors
- Expired contracts
- Upcoming contract expirations
- Changed roles
- Completed projects
Step 4 — Identify Exceptions
Focus on:
- Former contractors
- Excessive access
- Production access
- Privileged access
- Dormant accounts
- Unknown accounts
- Missing expiry dates
Step 5 — Correct
Remove or reduce unnecessary access.
Step 6 — Verify
Check actual system permissions.
Step 7 — Update
Update registers and retain evidence.
38. AWS SaaS Startup Example
A SaaS company uses external developers for application support.
A contractor has:
- Corporate SSO
- MFA
- GitHub repository access
- AWS development role
- Jira access
- No production administrator access
During the quarterly review, the reviewer discovers that the contractor completed the original development project but still has access to an additional repository.
Action
- Confirm current business need.
- Confirm contractor’s current project.
- Identify unnecessary repository access.
- Remove the repository permission.
- Verify the actual GitHub permission.
- Update the Access Rights Register.
- Record the corrective action.
Audit Trail
Contractor → Actual Access → Approved Access → Finding → Removal → Verification → Register Update
39. Common Contractor Access Review Mistakes
Avoid:
- Reviewing only employee access.
- Assuming contractors automatically need broad access.
- Failing to check contract expiry.
- Failing to check project completion.
- Ignoring contractor role changes.
- Ignoring privileged contractor access.
- Ignoring production access.
- Ignoring customer-system access.
- Ignoring subcontractor access.
- Failing to check actual system permissions.
- Allowing access without an internal sponsor.
- Failing to define expiry dates.
- Failing to remove old project access.
- Disabling email but leaving cloud/repository access active.
- Failing to verify access revocation.
- Storing actual credentials in review records.
40. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Contractor Account Procedure | Defines contractor account lifecycle |
| Third-Party Access Procedure | Defines external access controls |
| Contractor Offboarding Checklist | Handles engagement termination |
| Privileged Access Review Template | Reviews elevated contractor access |
| Access Rights Register | Records contractor permissions |
| Identity Register | Records contractor identities |
| Privileged Access Register | Records contractor privileged access |
| User Access Request Form | Provides access approval |
| User Access Management Procedure | Defines access lifecycle |
| JML Procedure | Handles role and lifecycle changes |
| Access Revocation Checklist | Verifies access removal |
| Information Classification Policy | Determines information protection |
| Data Handling Procedure | Defines data handling requirements |
| Third-Party Information Sharing Agreement | Defines external information-sharing requirements |
| Risk Register | Records significant contractor-access risks |
| Incident Management | Handles unauthorized contractor access |
41. Contractor Access Review — Quick Audit Checklist
Contractor
☐ Identity verified
☐ Organization identified
☐ Sponsor identified
☐ Contract valid
☐ Project/role current
Access
☐ Access approved
☐ Business need valid
☐ Actual access reconciled
☐ Least privilege applied
☐ Old access removed
☐ Temporary access reviewed
Privileged
☐ Privileged access identified
☐ Business justification exists
☐ Production access reviewed
☐ MFA/strong authentication assessed
☐ Privileged access monitored appropriately
Information
☐ Customer data reviewed
☐ Personal data reviewed
☐ Confidential information reviewed
☐ Restricted information reviewed
☐ Access appropriate to classification
Third Party
☐ Subcontractors reviewed
☐ Contract requirements checked
☐ Confidentiality requirements checked
☐ Downstream access reviewed
Offboarding
☐ Contract end date monitored
☐ Accounts revoked when required
☐ Cloud access revoked
☐ Repository access revoked
☐ SaaS access revoked
☐ Customer-system access revoked
☐ Privileged access revoked
☐ Assets returned
☐ Information returned/deleted where required
☐ Revocation verified
Evidence
☐ Findings documented
☐ Actions assigned
☐ Remediation verified
☐ Registers updated
☐ Exceptions documented
☐ Review approved
42. ISO 27001 Connection
Contractor access review supports the organization’s implementation of information-security controls relating to:
- Identity management
- Authentication information
- Access rights
- Privileged access
- Access restriction
- Segregation of duties
- Supplier relationships
- Information transfer
- Information classification
- Logging and monitoring
- Personnel responsibilities
- Offboarding and access revocation
The exact controls applicable to the organization should be determined through the organization’s risk assessment and Statement of Applicability (SoA).
43. Final Audit Trail
For each contractor review, the organization should be able to demonstrate:
Who is the contractor?
Which organization do they represent?
Who is their internal sponsor?
Is the contract still valid?
What systems can they access?
Why do they need the access?
Who approved it?
Does actual access match approved access?
Is privileged or production access justified?
Has unnecessary access been removed?
What happened when the engagement ended?
Was access revocation verified?
Were the relevant registers updated?
Final Principle
Contractor access should exist only for a legitimate business purpose, be limited to the required systems and information, be appropriately protected and periodically reviewed, and be completely revoked when the engagement or business need ends — with evidence supporting the entire lifecycle.
