Ga naar inhoud

ISO 27001 ·

Identity lifecycle: HR to offboarding without orphaned accounts

July 2026. Orphaned accounts and slow offboarding remain top ISO 27001 findings. Auditors follow one departure: HR event → IdP disable → SaaS revoke within agreed SLA.

Joiner-mover-leaver (JML)

  • HR system as source of truth for start/end/role change;
  • automation to IdP where possible — manual for exceptions;
  • checklist per SaaS without SSO;
  • periodic reconcile: active accounts vs HR list.

Metrics

Average offboarding time, orphaned accounts found in reconcile — report in management review. Target: critical apps within 24 hours, rest within 72 hours.

More: ISO 27001 SaaS, access reviews, ISMS. Service accounts: named owner + quarterly review.

Externals and freelancers: expiring access and line sponsor — no permanent guest accounts.

Reconcile and exception management

Monthly reconcile HR vs IdP vs critical SaaS — differences resolved or justified within 48 hours. Keep reconcile reports as audit evidence.

Exceptions (shared accounts, legacy apps): named owner, review date, compensating controls in risk register.

Mover events: role change triggers access review within 5 business days — do not wait for quarterly batch.

Next steps in your ISMS

Turn this article into one concrete action in your risk register or improvement plan: owner, deadline, expected evidence. Discuss progress in the next management review — auditors and chain partners want decisions, not policy intent alone. Link where possible to existing ISO 27001, NIS2 or GDPR documentation so you do not maintain parallel folders.

Questions on scope, certification or chain requirements? Use our readiness overview and knowledge base for deeper guidance. This article does not replace legal or audit advice for your situation.

Share relevant findings briefly with line management and procurement — compliance becomes workable when the whole organisation recognises the same priorities. Repeat the chosen action quarterly in team meetings and update evidence locations in your SoA or control plan so surveillance samples are easy to answer.

What to do this week

Pick one concrete action from this article, assign an owner and add it to your risk or improvement register with a deadline. Share briefly in team meetings so compliance is something the line recognises. Repeat quarterly in management review so leadership sees progress, not only intent.

Note: this article is educational and does not replace legal, privacy or audit advice for your specific situation.

Evidence and governance

Record who owns the measures in this article and how you prove operation in the sample period — logs, tickets, approved changes or exercise reports. Certification bodies and chain partners do not accept intent without samples. Link evidence locations to your SoA or control plan so internal and external audit use the same sources.

Chain and contracts

Many 2026 requirements come via customers, not only formal law scope. Align contract SLAs with your ISMS: incident notification, audit rights, patch timelines and exit. Document where contract is stricter than internal policy — management review must explicitly accept that gap or plan investment.

Continual improvement

Plan a short quarterly review: what worked, which near-miss stood out, which control needs extra attention? Record three improvement actions with owners — that is what ISO 27001, NIS2 and GDPR supervision want to see: PDCA in practice, not paper only.

Knowledge base and readiness

For deeper guidance see our knowledge base on ISMS, ISO 27001, NIS2 and GDPR. Use the readiness overview to compare priorities with your current maturity. This article is educational; engage specialists for legal or audit decisions.

Evidence and governance

Record who owns the measures in this article and how you prove operation in the sample period — logs, tickets, approved changes or exercise reports. Certification bodies and chain partners do not accept intent without samples. Link evidence locations to your SoA or control plan so internal and external audit use the same sources.

Chain and contracts

Many 2026 requirements come via customers, not only formal law scope. Align contract SLAs with your ISMS: incident notification, audit rights, patch timelines and exit. Document where contract is stricter than internal policy — management review must explicitly accept that gap or plan investment.

Continual improvement

Plan a short quarterly review: what worked, which near-miss stood out, which control needs extra attention? Record three improvement actions with owners — that is what ISO 27001, NIS2 and GDPR supervision want to see: PDCA in practice, not paper only.

Deep dive in the knowledge base

Run the ISO 27001 readiness scan

See where you stand before investing in documents or consultants.

Start the readiness scan

← Back to overview