The principle of separation of duties should also be considered when conducting user access reviews.
Access should be reviewed when users resign, are terminated, change roles, and/or no longer need the authorization to carry out duties for any other reason.
Review and revalidate user access for least privilege and separation of duties with a frequency that is commensurate with organizational risk tolerance.