DocsControls

IT audit and control testing

All documentation pages

Test the full population of controls every month

  • Domain: Audit & Compliance
  • Moment: Before you sign
  • Customer: A national capital markets institution

Test every item in scope with the same approved rules.

The situation

An internal audit function has to give an opinion on IT general controls: who has access to what, whether that access was approved, whether changes to production followed the process, whether privileged accounts are justified, whether someone who left in March still has a login in September.

The population is tens of thousands of entitlements across dozens of systems. The team is small. So the team samples, tests forty items well, and extrapolates. Everyone in the room knows what that means and nobody says it out loud.

What breaks today

The sample limits the opinion. Testing forty items from forty thousand gives a conclusion about the selected items and leaves the rest untested.

The evidence arrives as exports, in different shapes, from systems that were never designed to be compared. The identity store lists accounts. HR lists people. The approval workflow lists tickets. Nothing joins cleanly, and the joining is done by hand in a spreadsheet that is rebuilt every audit cycle.

Findings arrive after the damage. An access review run in November tells you about a leaver from June. The control failed for five months and the report is the first anyone hears of it.

The same finding comes back every year. The sampled items may be fixed while the same issue remains elsewhere in the population.

Nobody can rebuild the test. Twelve months later, when a regulator asks how a conclusion was reached, the working papers describe the method but the intermediate data is gone. The number was right. The path to it cannot be walked again.

What Manuel does

Assembles the evidence, in whatever form it arrives. Identity and access exports, HR joiner and leaver records, the approved role matrix, change tickets, deployment logs, privileged account registers, vendor access lists. Files, database extracts, API pulls, or a screen where there is no other route in.

Resolves identity across sources. Account names, employee numbers, email addresses, and contractor references may all describe one person. Manuel stores the matching rules and fallbacks for reuse in each cycle.

Runs the test against the full population. Every entitlement is checked against the role matrix. Every active account is checked against current employment. Production changes and privileged accounts are checked for the required approvals and review dates.

Names each exception. For example: this account has production write access, the role matrix allows read access only, the entitlement was added on 14 March, and the referenced ticket covers another system.

Runs as evidence changes. A former employee with live access can surface within days of the data arriving.

Creates the working paper during the run. Every test retains what was checked, the rule version, result, reviewer, and time. The test can be repeated months later on the data as it stood.

What the customer gets

Coverage expands from the sample to the full population. The audit team receives exceptions with supporting records, and findings can surface while they are still easier to fix. Each run also creates the working paper needed to repeat the test.

Discovery measures how much of the population can be tested and how quickly a failed control appears. Both measures use the client's own data and become the acceptance criteria.

What stays with your existing systems

The identity store, ticketing system, HR system, and GRC platform stay in place. Manuel reads from them, tests the approved audit rules, and produces the exception list and evidence pack. Remediation and access changes remain with the existing systems and authorised teams. Most audit deployments stay read-only.

What a first scope looks like

Start with one control area, usually user access review, for a historical period the team has already audited. We test the full population and compare the result with the completed sample review.

The comparison shows the added coverage before the control enters a live cycle.


Related: Sustainability and compliance disclosure / Continuous audit / Enterprise data intake