An access review answers a simple question: can anyone still see, change or move money when they no longer need that power? The review should cover the bank, accounting software, payroll, payment gateways and the email accounts used to approve financial work.
Build one inventory across all systems that touch money
Start with the business bank, then add accounting software, payroll, expense-card platforms, merchant accounts, payment processors and finance email accounts. List the user's name, role, last known need for access and the highest-risk action they can perform. Do not review each system in isolation because excessive access often hides in the gaps between them.
A former finance assistant may have lost bank access but still retain administrator rights in an accounting platform that stores supplier details. An external accountant may still have broad access after the engagement ended. A director may have an old backup login on a phone nobody uses. The inventory makes these residual privileges visible.
Apply least privilege to the job the person performs today
The NCSC recommends the principle of least privilege: users should have only the access and functionality required for their role. Review whether each permission is genuinely needed. A staff member who uploads invoices may not need beneficiary-management rights. A bookkeeper may need statement exports without payment authority.
Where systems support role-based access, use roles rather than granting bespoke full access repeatedly. Keep administration separate from ordinary work where possible. The point is to reduce the damage one compromised account can cause without making normal finance work unnecessarily difficult.
Treat payment approvers and finance administrators as privileged users
NCSC guidance explicitly gives approving financial payments as an example of privileged access. These users deserve stronger control because compromise can create loss beyond their immediate job role. Identify who can release high-value payments, add users, change limits, amend beneficiaries or alter payment controls.
Privileged access should be strongly authenticated and used only when necessary. If a director needs full administrative rights once a month but only needs view access on ordinary days, consider whether the platform supports separate roles or a safer operating method. The most powerful account should not be the default account used for every routine task.
Remove access when people leave or their responsibilities change
The NCSC advises regular review of unnecessary privileges and prompt revocation when access is no longer required. Build finance access into the leaver checklist. Bank users, accounting accounts, expense cards, email groups, saved devices and shared folders should all be reviewed, not just the employee's main company login.
Role changes matter too. A salesperson promoted away from purchasing may still have an old company card and procurement-platform access. An accountant who moves from bookkeeping to annual accounts may no longer need day-to-day bank visibility. Access should follow the current job rather than accumulating over time.
Review MFA, device access and account-recovery paths
The NCSC recommends MFA and stronger authentication for privileged accounts. Check that finance users are enrolled correctly, old devices are removed and recovery methods do not point to personal email addresses or former staff phone numbers. Recovery is part of access control because an attacker who can reset the account can bypass strong login settings.
Also check shared credentials. Generic logins such as finance@company with one shared password make attribution harder and increase the number of people who know the secret. Prefer named users wherever the provider supports them. If a legacy system forces shared access, document the risk and compensate with stronger surrounding controls.
Record the review and repeat it on a sensible trigger
Keep a simple review record: system, user, role, permissions, reviewer, date and action. This gives management evidence that access was deliberately checked rather than assumed. For the highest-risk systems, sample logs or recent activity where available to confirm privileged actions are being performed by the expected users.
Run a scheduled review and also trigger one after key events: staff departures, acquisitions, banking changes, accounting-platform migrations or fraud incidents. The NCSC's Cyber Assessment Framework treats a failure to review privileged users within the last 12 months as a warning sign for essential systems. Many businesses should review high-risk finance access more frequently than that.
Editorial Verdict
A finance access review is valuable because permissions tend to accumulate silently. Start with the people who can move money or change controls, then work outward to accounting, payroll, merchant and email systems.
Use named accounts, least privilege, strong authentication and prompt removal of obsolete access. The review should leave a short evidence trail and a list of actions, not just a spreadsheet marked "checked". If nobody can explain why a user still has a permission, remove or reduce it until a real business need is shown.
Sources
- NCSC, Introduction to identity and access management: https://www.ncsc.gov.uk/guidance/introduction-identity-and-access-management
- NCSC, 10 Steps to Cyber Security, identity and access management: https://www.ncsc.gov.uk/collection/10-steps/identity-and-access-management
- NCSC, Cyber Assessment Framework, identity and access control: https://www.ncsc.gov.uk/collection/cyber-assessment-framework/caf-objective-b/principle-b2-identity-and-access-control