PCI DSS User Access Review Checklist
Complete this checklist to ensure user access aligns with PCI DSS requirements. Review all relevant user accounts and access controls as part of your periodic compliance process.
Full Name of Reviewer
*
First Name
Last Name
Date of Review
*
 -
Month
 -
Day
Year
2 digit month, 2 digit day, 4 digit year
Date
Are all user accounts current, active, and authorized?
*
Yes
No
N/A
Have all dormant, inactive, or terminated user accounts been disabled or removed?
*
Yes
No
N/A
Does each user have only the minimum necessary access (least privilege)?
*
Yes
No
N/A
Are all privileged or administrative accounts reviewed and justified?
*
Yes
No
N/A
Has access been reviewed for all third-party or vendor accounts?
*
Yes
No
N/A
Are access approval and change records documented for all users?
*
Yes
No
N/A
Is periodic user access review performed as per PCI DSS policy?
*
Yes
No
N/A
Have all exceptions or issues identified during this review been remediated?
*
Yes
No
N/A
Additional comments or notes (optional)
Submit Review
Should be Empty: