Before sign-off

IT audit and control testing

Compare every account and access right with employment, approvals, and the role matrix.

Where to start
The control flowSource records / rules / result

What arrives

  • Accounts and entitlements
  • HR and role matrix
  • Tickets and change logs
Manuel

Test access and changes

  • Active employment and approved role
  • Privileged-access review
  • Production-change approval
Checks pass

Tested record retained

Needs review

Access or approval finding

Every result keeps its source records, rule version, and decision history.

The problem

Identity exports, HR records, and tickets use different identifiers. A leaver's access or an unapproved change can stay hidden between reviews.

What your team gets

Findings with the affected account, failed rule, source records, and working paper needed to repeat the test.

Access changes remain with authorised IT teams. Manuel reads and tests the evidence.

A first project

Start with work you have already completed.

One control area, usually access review, for a period already audited.

How we check the result

Compare full-population results with the completed sample review. This engagement has been delivered.

Discuss this processRead the detailed notes