ITGC – User Access Review Testing

ITGC – User Access Review Testing


πŸ‘οΈUser Access Review

🧭 Planning:
Quarterly access reviews assessed across high-risk systems (finance, HR).

🎯 Objectives:

  • Ensure periodic user access validation

  • Validate manager sign-offs and exception handling

πŸ“Œ Procedures:

  • Reviewed Q1/Q2 access review logs

  • Verified reviewer identity and sign-off

  • Sampled 10 users per system for appropriateness

πŸ“‘ Working Papers:

  • WP-ITGC-AR001: Access recertification control

  • Access review calendars, approval logs

πŸ“Š Findings:

  • ❗ Missed sign-offs in 2 of 4 departments

  • ❗ Reviews conducted without system owner input

  • ⚠️ Limited audit trail of post-review remediation

🧰 Tools Used:
Excel, email approvals, manager review sheets

βœ… Recommendations:

  • Enforce system owner accountability

  • Use automated certification platforms

  • Establish escalation path for late reviews

Leave a Reply