Orphaned accounts, and why auditors ask
An orphaned account is an account whose owner has left or was never named: a service account set up by someone who moved on, an API key nobody remembers asking for, a leaver's login still enabled, a shared login owned by "the team". It still works, and nobody is asked about it at the access review.
Why auditors ask about them first
An orphaned account is access with nobody to answer for it. The auditor samples leavers against enabled accounts, asks who owns each service account and API key, and asks for the last review of each. SOC 2 CC6.2 expects credentials removed once access is no longer authorised; ISO/IEC 27001 A.5.16 expects identities managed through their whole life cycle; PCI DSS 8.2.5 expects a terminated user's access revoked immediately; CIS Controls 5.1 and 5.5 expect an inventory of accounts and service accounts with an owner. A US issuer's external auditor also samples leavers, shared logins and privileged accounts in the financial systems when testing IT general controls under Sarbanes-Oxley section 404 (named, not quoted), a broad obligation rather than a rule for each account.
The four ways an account becomes orphaned
- A leaver's own account is still enabled: the person has gone, the login has not.
- The owner has left: a service account, key or bot whose named owner is in the staff list as a leaver.
- No owner, or a team for an owner: nobody, or nobody in particular.
- An AI agent credential with no owner or no review: the newest kind, acting through a credential someone has to own.
The clauses behind them
SOC 2 CC6.2Registering and authorising users before issuing credentialsBefore system credentials are issued and access is granted, internal and external users whose access the organisation administers are registered and authorised; their credentials are removed once their access is no longer authorised. Points of focus: credentials to protected assets are created only on authorisation from the asset owner or an authorised custodian; access is removed when a person no longer needs it; and credentials are reviewed periodically for people who should not hold them.
ISO/IEC 27001 A.5.16Identity managementIdentities are to be managed throughout their whole life cycle. Purpose (stated in ISO/IEC 27002:2022): enables unique identification of people and systems accessing organizational assets and appropriate assignment of access rights. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.16.
PCI DSS 8.2.5Terminated users' access revoked immediatelyAccess for users who have been terminated must be revoked immediately. The testing procedures check both local and remote access lists for terminated IDs and confirm that any physical authentication factor, for example a token or smart card, has been deactivated or handed back. The guidance explains that a former employee or third party who keeps a working account, or an attacker who takes over an abandoned one, could reach cardholder data. Objective under the customized approach: accounts belonging to terminated users cannot be used.
CIS Controls 5.5Establish and Maintain an Inventory of Service AccountsKeep a register of service accounts that records, at a minimum, the owning department, the date of review and the purpose. Review service accounts on a regular cycle of at least once a quarter to confirm that every active one is authorised.
See the specimen: 40 accounts, 11 nobody ownsThe review template