ISO 27001 A.5.18 evidence for Microsoft 365 access reviews

Control A.5.18 of ISO/IEC 27001:2022 says access rights must be provisioned, reviewed, modified and removed according to your access control policy. The review part is where most audits find gaps, because the evidence is a spreadsheet from last year.

What control A.5.18 requires

A.5.18 "Access rights" reads: access rights to information and other associated assets shall be provisioned, reviewed, modified and removed in accordance with the organization’s topic-specific policy on and rules for access control. It sits next to A.5.15 (access control), A.5.16 (identity management) and A.8.2 (privileged access rights).

The implementation guidance in ISO/IEC 27002:2022 adds that access rights should be reviewed regularly and after changes such as a role change or termination, and that privileged access deserves closer review.

What auditors ask to see

For Microsoft 365, the hard part is the objects that do not belong to one person: shared mailboxes, Teams, SharePoint sites and service principals. Nobody is obviously responsible for reviewing them, so they are often left out.

How Ownership Registry covers it

Audit questionWhere the answer comes from
What is in scope?The scheduled Graph scan inventory, including service principals and custom object types
Who is responsible?The named primary and backup owner of each object
Was it reviewed, by whom, when?The attestation record: one click by the owner, timestamped
What happened when nobody answered?Two reminders a week apart, then an escalation email to your service desk
Can the record be trusted?Append-only audit log, enforced by a database trigger
How are leavers handled?Owners are re-validated against Entra ID on every scan, and the backup owner takes over automatically

The review cadence is set per object (monthly, six-monthly or yearly), so the frequency written in your policy is the frequency the registry runs. The same trail answers SOC 2 and NIS2 questions about access review.

ISO 27001 questions

Does ISO 27001 say how often access must be reviewed?

No. A.5.18 requires reviews in line with your own access control policy, and the auditor checks that you follow what the policy says. Choose a risk-based cadence, write it down, and make sure the evidence shows it being met.

Do we still need the 2013 control numbers?

No. The transition period for ISO/IEC 27001:2013 certificates ended on 31 October 2025, so certificates now refer to the 2022 Annex A, where access rights are control A.5.18 (formerly A.9.2.5 among others).

Does it cover access inside our business applications?

No. It covers Microsoft 365 objects and service accounts, plus anything you register as a custom object type. Access inside an ERP or CRM needs that application’s own review.

Bring evidence, not a spreadsheet

See the audit trail on your own tenant in a 30-minute read-only demo. Security details are on the security page. Book a demo