ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Contractor Access Review Checklist

Contractor Access Review Checklist

1. Purpose

The Contractor Access Review Checklist is used to periodically verify that contractors, consultants, freelancers, temporary workers, and other external personnel continue to have only the access required for their current business engagement.

The review helps confirm that contractor access is:

  • Authorized
  • Business-justified
  • Current
  • Appropriate for the contractor’s role
  • Limited to the required systems and information
  • Appropriately authenticated and protected
  • Time-bound where practical
  • Consistent with contractual requirements
  • Removed when the engagement or business need ends

Core Principle

Identify → Validate → Review → Correct → Verify → Record


2. Review Information

FieldDetails
Review ID
Review Period
Review Date
Business Unit
Contractor Population
Reviewer
Security/ISMS Reviewer
Contractor Manager/Sponsor
Review Owner
Previous Review
Evidence Repository
Review StatusOpen / In Progress / Completed

3. Contractor Information

FieldDetails
Contractor Name
Contractor ID
Organization/Vendor
Contractor TypeConsultant / Freelancer / Temporary / Vendor
Internal Sponsor
Manager
Department
Project
Role
Contract/SOW
Contract Start Date
Contract End Date
Review Date
Engagement StatusActive / Ending / Ended

4. Review Scope

Review all systems and information to which the contractor has access.

Systems

☐ Corporate Email
☐ Identity Provider/SSO
☐ SaaS Applications
☐ AWS/Azure/GCP
☐ Production Environment
☐ Development Environment
☐ Test Environment
☐ Databases
☐ Source-Code Repository
☐ CI/CD Platform
☐ VPN/Remote Access
☐ Customer Systems
☐ Security Platforms
☐ File-Sharing Platforms
☐ Collaboration Tools
☐ Other Critical Systems


5. Contract and Engagement Review

Confirm:

☐ Contractor engagement is still active
☐ Contract/SOW is valid
☐ Contract end date is recorded
☐ Contractor’s role remains unchanged
☐ Internal sponsor remains responsible
☐ Business purpose remains valid
☐ Security requirements are included where applicable
☐ Confidentiality/NDA requirements remain applicable
☐ Data protection requirements are addressed where applicable
☐ Customer contractual requirements are considered
☐ Subcontractor involvement is known and authorized

Contractual Issues Identified


6. Business Need Review

Confirm that the contractor still requires access.

Review QuestionResult
Is the contractor still working for the organization?Yes / No
Is the project still active?Yes / No
Is the original business purpose still valid?Yes / No
Is the access still required?Yes / No
Could access be reduced?Yes / No
Could access be removed?Yes / No
Is the contractor’s role unchanged?Yes / No

Business Justification


7. Contractor Identity Verification

Verify:

☐ Contractor identity is known
☐ Contractor organization is known
☐ Internal sponsor is identified
☐ Account belongs to the correct individual
☐ Shared contractor account is not being used without approved justification
☐ Identity is recorded in the Identity Register
☐ Contractor account is associated with the correct engagement


8. Access Rights Review

Compare the contractor’s actual access against approved access.

SystemActual AccessApproved AccessAppropriateAction
Yes / No
Yes / No

Check:

☐ Access is approved
☐ Access is still required
☐ Access matches contractor role
☐ Access matches business purpose
☐ Unnecessary permissions are absent
☐ Actual access matches the Access Rights Register
☐ Old project access has been removed


9. Least Privilege Review

Assess whether the contractor has more access than required.

☐ Only required systems are accessible
☐ Only required resources are accessible
☐ Only required information is accessible
☐ Read-only access is used where sufficient
☐ Administrative access is restricted
☐ Production access is separately justified
☐ Temporary permissions are appropriately limited
☐ Old permissions have been removed

Excess Access Identified

Required Action


10. Contractor Privileged Access Review

Identify contractors with elevated access.

Examples:

  • Cloud administrator
  • Database administrator
  • Security administrator
  • Network administrator
  • Repository administrator
  • CI/CD administrator
  • Production administrator
  • SaaS administrator
ContractorSystemPrivileged RoleBusiness NeedApprovalMFADecision

Check:

☐ Privileged access is explicitly approved
☐ Business justification exists
☐ Privilege remains necessary
☐ Least privilege is applied
☐ MFA is enabled where required
☐ Activity is appropriately monitored
☐ Privileged access is recorded
☐ Access expiry is defined where appropriate


11. Production Access Review

Production access should receive additional scrutiny.

☐ Production access is required
☐ Business justification exists
☐ System owner approval exists
☐ Access is limited to required systems
☐ Access is limited to required resources
☐ Privileged access is separately approved
☐ MFA/strong authentication is applied where required
☐ Activity is appropriately logged
☐ Temporary access is removed when no longer required

Production Access Justification


12. AWS / Cloud Access Review

For contractors with AWS, Azure, or GCP access, review:

☐ Cloud account/subscription/project
☐ Identity/role
☐ Permissions
☐ Environment
☐ Production access
☐ Development access
☐ Database access
☐ Storage access
☐ Security administration
☐ Cross-account access
☐ MFA
☐ Access expiry
☐ Activity logging

AWS Example

A contractor supporting a SaaS application may have:

Corporate SSO → MFA → AWS Role → Development Account → Required Resources

The contractor should not automatically receive production administrator access merely because they require development access.


13. Source-Code Access Review

Review access to GitHub, GitLab, Bitbucket, or equivalent.

Check:

☐ Contractor is still assigned to the project
☐ Repository access remains required
☐ Repository scope is appropriate
☐ Organization-level access is justified
☐ Administrator permissions are justified
☐ External collaborator status is appropriate
☐ MFA is enabled where required
☐ Personal/shared accounts are appropriately controlled
☐ Deploy keys/tokens are reviewed where applicable
☐ Old repositories are removed


14. SaaS Application Access Review

Review critical SaaS applications used by contractors.

Examples:

  • Microsoft 365
  • Jira
  • Slack/Teams
  • Salesforce
  • Customer support platforms
  • HR platforms
  • Security platforms
  • Project-management systems

Check:

☐ Account active
☐ Business need valid
☐ Correct role
☐ Correct groups
☐ Administrator access justified
☐ External sharing reviewed
☐ Customer data access appropriate
☐ Contractor expiry recorded


15. Database Access Review

For contractor database access:

☐ Database identified
☐ Environment identified
☐ Access level documented
☐ Business purpose documented
☐ Production access separately approved
☐ Read/write access justified
☐ DBA privileges justified
☐ MFA/strong authentication applied where supported
☐ Activity logging appropriate
☐ Access remains necessary


16. Customer-System Access Review

If contractors access customer systems:

☐ Customer authorization exists where required
☐ Contract/SOW permits access
☐ Customer data access is necessary
☐ Access scope is defined
☐ Named individual account used
☐ MFA enabled where required
☐ Access is monitored where appropriate
☐ Customer-specific requirements are followed
☐ Access expiry is defined
☐ Access will be removed when engagement ends


17. Authentication Review

Verify:

☐ Contractor uses an individual identity
☐ MFA enabled where required
☐ Strong authentication configured
☐ SSO used where appropriate
☐ Password requirements followed
☐ Shared credentials avoided
☐ API keys/tokens appropriately controlled
☐ SSH keys appropriately managed
☐ Authentication information is not stored in the review record

Actual passwords, API keys, MFA secrets, private keys, or recovery codes must never be recorded in this checklist.


18. Temporary Access Review

Identify temporary contractor permissions.

SystemAccessStart DateExpiry DateStill RequiredAction
Yes / No

Check:

☐ Expiry date exists
☐ Expiry has not passed
☐ Extension is approved if required
☐ Temporary access has not become permanent without review
☐ Expired access is removed


19. Contractor Role Change Review

Identify contractors whose responsibilities have changed.

Check:

☐ Role change identified
☐ Existing access reviewed
☐ Old access removed
☐ New access approved
☐ New access provisioned
☐ Privileged access reassessed
☐ Access Register updated
☐ Verification completed

Important

A role change should not simply result in additional access.

The organization should first review and remove access that is no longer required.


20. Contractor Offboarding Check

For contractors whose engagement has ended:

☐ Engagement end confirmed
☐ Internal sponsor notified
☐ All accounts identified
☐ Corporate account disabled
☐ SSO access removed
☐ Email access removed
☐ SaaS access removed
☐ AWS/cloud access removed
☐ Source-code access removed
☐ Database access removed
☐ VPN access removed
☐ Customer-system access removed
☐ Privileged access removed
☐ API tokens reviewed/revoked
☐ SSH keys reviewed/revoked
☐ Physical access removed
☐ Company assets returned
☐ Organizational information returned/deleted where required
☐ Subcontractor access reviewed
☐ Access revocation verified
☐ Registers updated


21. Contractor Access Revocation Verification

Do not rely only on an email or ticket stating that access was removed.

Verify actual system status.

SystemRevocation RequestedActual StatusVerified ByDate

Examples of evidence:

  • Account disabled
  • Group membership removed
  • Cloud role removed
  • Repository access removed
  • VPN access removed
  • SaaS account disabled
  • Database permissions removed
  • API token revoked
  • SSH key removed

22. Dormant Contractor Accounts

Identify contractor accounts with:

  • No recent activity
  • No current project
  • Expired contract
  • No active sponsor
  • No documented business purpose

Action

Identify → Investigate → Confirm Need → Disable/Remove → Verify → Record

AccountSystemLast ActivitySponsorFindingAction

23. Orphaned Contractor Accounts

An orphaned contractor account is one where the organization cannot establish:

  • Who the individual is
  • Which organization they represent
  • Who their sponsor is
  • Why the account exists
  • Which project they support
  • Whether the engagement is still active

Required Response

☐ Investigate
☐ Identify Owner
☐ Confirm Business Need
☐ Restrict Access
☐ Revoke if Unauthorized/Unnecessary
☐ Verify
☐ Record


24. Segregation of Duties Review

Consider whether contractor access creates conflicts such as:

  • Developer + production approval
  • Access administrator + access approval
  • Change implementer + change approver
  • Security administrator + independent security review

Result

☐ No conflict
☐ Potential conflict
☐ Confirmed conflict
☐ Compensating control required
☐ Escalation required

Comments


25. Contractor Information Access Review

Assess what information the contractor can access.

InformationClassificationAccess RequiredAppropriate
Public / Internal / Confidential / RestrictedYes / No

Pay particular attention to:

  • Customer data
  • Personal data
  • Financial information
  • Source code
  • Security information
  • Production information
  • Credentials/secrets
  • Confidential contracts
  • Audit evidence

26. Third-Party / Subcontractor Review

Determine whether the contractor uses subcontractors or other personnel.

Check:

☐ Subcontractor involvement known
☐ Organization has approved subcontractor use
☐ Individual identities are known
☐ Access is separately authorized
☐ Contractual requirements apply
☐ Confidentiality requirements apply
☐ Data protection requirements are addressed where applicable
☐ Downstream access is reviewed
☐ Access is revoked when no longer required


27. Contractor Access Findings

Finding IDContractorSystemFindingRiskActionOwnerDue DateStatus

Possible findings include:

  • Excessive access
  • Missing approval
  • Expired contract
  • Expired access
  • Unnecessary production access
  • Unapproved privileged access
  • Dormant account
  • Orphaned account
  • Missing MFA
  • Incorrect role
  • Missing access expiry
  • Uncontrolled third-party access

28. Finding Classification

The organization may classify findings as:

Conforming

Access is appropriate and adequately controlled.

Observation

A condition has been identified for monitoring or consideration.

Improvement Opportunity

A process or control could be strengthened.

Nonconformity

A defined requirement or control has not been adequately met.

Formal classifications should follow the organization’s audit methodology.


29. Corrective Action Register

Action IDFindingRequired ActionOwnerDue DateStatusVerified

Possible actions:

  • Revoke access
  • Reduce permissions
  • Remove production access
  • Disable account
  • Enable MFA
  • Add expiry date
  • Update sponsor
  • Update Access Rights Register
  • Update Identity Register
  • Rotate/revoke credentials
  • Investigate access
  • Implement compensating control

30. Remediation Verification

After corrective action:

☐ Actual access checked
☐ Permission change confirmed
☐ Account status confirmed
☐ Contractor record updated
☐ Access Rights Register updated
☐ Privileged Access Register updated where applicable
☐ Identity Register updated
☐ Evidence retained
☐ Reviewer confirmed closure

Verified By: ____________________

Date: ____________________


31. Contractor Access Review Summary

MetricResult
Contractors Reviewed
Active Contractors
Contractors Ending Engagement
Systems Reviewed
Privileged Contractors
Production Access
Third-Party Access
Dormant Accounts
Orphaned Accounts
Excess Access Identified
Access Revoked
Access Modified
MFA Issues
Open Findings
Closed Findings

32. Review Conclusion

Overall Result

☐ Contractor access remains appropriate
☐ Corrections required
☐ Significant remediation required
☐ Further investigation required

Summary

Key Findings

Key Actions


33. Exceptions

Exception IDContractorAccessReasonRiskCompensating ControlApproverExpiry

Exceptions should be documented, approved, risk-assessed, and reviewed periodically.


34. Review Approval

Reviewer

Name: ____________________
Role: ____________________
Approval: ____________________
Date: ____________________

Contractor Manager/Sponsor

Name: ____________________
Approval: ____________________
Date: ____________________

System Owner

Name: ____________________
Approval: ____________________
Date: ____________________

Security/ISMS

Name: ____________________
Approval: ____________________
Date: ____________________


35. Evidence to Retain

Evidence may include:

  • Contractor register
  • Contract/SOW
  • NDA/confidentiality agreement
  • Access request
  • Approval records
  • Access Rights Register
  • Privileged Access Register
  • Identity Register
  • SSO/IAM reports
  • AWS/cloud access reports
  • SaaS access reports
  • Repository access reports
  • Database access reports
  • Access-review records
  • Access-revocation evidence
  • Change tickets
  • Offboarding records
  • Corrective-action records
  • Exception approvals

Do not retain actual passwords, API keys, tokens, private keys, MFA secrets, or other authentication secrets in the review evidence.


36. Recommended Review Frequency

The organization should establish the frequency based on risk and business requirements.

Example:

Contractor TypeExample Review
Standard ContractorPeriodic
Privileged ContractorMore frequent
Production AccessMore frequent
Customer-System AccessRisk-based
High-Risk Data AccessMore frequent
Temporary ContractorAt/near expiry
Third-Party SupportPeriodic
Contractor Ending EngagementImmediate offboarding review

These are examples rather than universal ISO 27001-prescribed frequencies.


37. Startup-Friendly Contractor Access Review

A startup can perform this review using a spreadsheet and system exports.

Step 1 — Obtain Contractor Population

Start with:

HR/Contractor Register → Contractor Accounts → SSO → AWS → GitHub → SaaS → Databases

Step 2 — Compare Actual Access

Compare actual permissions against:

  • Contractor Account Register
  • Access Rights Register
  • Privileged Access Register
  • Approved access requests

Step 3 — Check Contract Status

Identify:

  • Active contractors
  • Expired contracts
  • Upcoming contract expirations
  • Changed roles
  • Completed projects

Step 4 — Identify Exceptions

Focus on:

  • Former contractors
  • Excessive access
  • Production access
  • Privileged access
  • Dormant accounts
  • Unknown accounts
  • Missing expiry dates

Step 5 — Correct

Remove or reduce unnecessary access.

Step 6 — Verify

Check actual system permissions.

Step 7 — Update

Update registers and retain evidence.


38. AWS SaaS Startup Example

A SaaS company uses external developers for application support.

A contractor has:

  • Corporate SSO
  • MFA
  • GitHub repository access
  • AWS development role
  • Jira access
  • No production administrator access

During the quarterly review, the reviewer discovers that the contractor completed the original development project but still has access to an additional repository.

Action

  1. Confirm current business need.
  2. Confirm contractor’s current project.
  3. Identify unnecessary repository access.
  4. Remove the repository permission.
  5. Verify the actual GitHub permission.
  6. Update the Access Rights Register.
  7. Record the corrective action.

Audit Trail

Contractor → Actual Access → Approved Access → Finding → Removal → Verification → Register Update


39. Common Contractor Access Review Mistakes

Avoid:

  • Reviewing only employee access.
  • Assuming contractors automatically need broad access.
  • Failing to check contract expiry.
  • Failing to check project completion.
  • Ignoring contractor role changes.
  • Ignoring privileged contractor access.
  • Ignoring production access.
  • Ignoring customer-system access.
  • Ignoring subcontractor access.
  • Failing to check actual system permissions.
  • Allowing access without an internal sponsor.
  • Failing to define expiry dates.
  • Failing to remove old project access.
  • Disabling email but leaving cloud/repository access active.
  • Failing to verify access revocation.
  • Storing actual credentials in review records.

40. Relationship With Other ISMS Documents

DocumentRelationship
Contractor Account ProcedureDefines contractor account lifecycle
Third-Party Access ProcedureDefines external access controls
Contractor Offboarding ChecklistHandles engagement termination
Privileged Access Review TemplateReviews elevated contractor access
Access Rights RegisterRecords contractor permissions
Identity RegisterRecords contractor identities
Privileged Access RegisterRecords contractor privileged access
User Access Request FormProvides access approval
User Access Management ProcedureDefines access lifecycle
JML ProcedureHandles role and lifecycle changes
Access Revocation ChecklistVerifies access removal
Information Classification PolicyDetermines information protection
Data Handling ProcedureDefines data handling requirements
Third-Party Information Sharing AgreementDefines external information-sharing requirements
Risk RegisterRecords significant contractor-access risks
Incident ManagementHandles unauthorized contractor access

41. Contractor Access Review — Quick Audit Checklist

Contractor

☐ Identity verified
☐ Organization identified
☐ Sponsor identified
☐ Contract valid
☐ Project/role current

Access

☐ Access approved
☐ Business need valid
☐ Actual access reconciled
☐ Least privilege applied
☐ Old access removed
☐ Temporary access reviewed

Privileged

☐ Privileged access identified
☐ Business justification exists
☐ Production access reviewed
☐ MFA/strong authentication assessed
☐ Privileged access monitored appropriately

Information

☐ Customer data reviewed
☐ Personal data reviewed
☐ Confidential information reviewed
☐ Restricted information reviewed
☐ Access appropriate to classification

Third Party

☐ Subcontractors reviewed
☐ Contract requirements checked
☐ Confidentiality requirements checked
☐ Downstream access reviewed

Offboarding

☐ Contract end date monitored
☐ Accounts revoked when required
☐ Cloud access revoked
☐ Repository access revoked
☐ SaaS access revoked
☐ Customer-system access revoked
☐ Privileged access revoked
☐ Assets returned
☐ Information returned/deleted where required
☐ Revocation verified

Evidence

☐ Findings documented
☐ Actions assigned
☐ Remediation verified
☐ Registers updated
☐ Exceptions documented
☐ Review approved


42. ISO 27001 Connection

Contractor access review supports the organization’s implementation of information-security controls relating to:

  • Identity management
  • Authentication information
  • Access rights
  • Privileged access
  • Access restriction
  • Segregation of duties
  • Supplier relationships
  • Information transfer
  • Information classification
  • Logging and monitoring
  • Personnel responsibilities
  • Offboarding and access revocation

The exact controls applicable to the organization should be determined through the organization’s risk assessment and Statement of Applicability (SoA).


43. Final Audit Trail

For each contractor review, the organization should be able to demonstrate:

Who is the contractor?
Which organization do they represent?
Who is their internal sponsor?
Is the contract still valid?
What systems can they access?
Why do they need the access?
Who approved it?
Does actual access match approved access?
Is privileged or production access justified?
Has unnecessary access been removed?
What happened when the engagement ended?
Was access revocation verified?
Were the relevant registers updated?

Final Principle

Contractor access should exist only for a legitimate business purpose, be limited to the required systems and information, be appropriately protected and periodically reviewed, and be completely revoked when the engagement or business need ends — with evidence supporting the entire lifecycle.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *