Back to Explore
🛡️

IT & Cyber Audit

Access-Control Review

Excess and dormant access is the most common path to unauthorised transactions and undetected fraud in financial systems.

📖 6 min read🎯 Intermediate✍️ Updated 2026

Why Access Review Matters

The principle of least privilege requires that users hold only the access their role demands, and periodic access review is the control that keeps reality aligned with that principle as people move, leave and change roles. Dormant accounts and accumulated privileges are repeatedly cited by the AGSA and under ISSAI 5300 as access-control weaknesses that enable fraud and error. AuditPro Core reviews user rights, dormant accounts and privilege creep across systems so access stays appropriate rather than quietly expanding.

The Numbers

AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.

Accounts reviewed

4,210

Dormant accounts

186

no login 90+ days

Excess privileges

94

Recertification rate

88%

▲ 5 pts

Access issues by system

Privileged account exposure

SystemAdminsDormantShared
Financial ledger921
Payroll612
HR730
Email / directory1251
Billing821

Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.

Least privilege

Every user should have the minimum access needed for their job and nothing more. Access granted for a past role but never removed is the residue that least-privilege reviews exist to catch.

Dormant accounts

Accounts that are no longer used — leavers, contractors, generic logins — are prime vectors for unauthorised access. Dormant privileged accounts are especially dangerous and should be disabled promptly.

Privilege creep

As employees change roles, access tends to accumulate rather than reset. Over time this erodes segregation of duties and concentrates risky capability in long-tenured staff.

How AuditPro Core Bridges the Gap

  • Access reconciliation: current rights are matched against role baselines to expose excess and orphaned access.
  • Dormancy detection: accounts with no recent activity are flagged for disablement.
  • Exception workflow: inappropriate access routes to system and data owners for revocation and sign-off.
  • Audit-ready export: the access-review register and attestations export as evidence for the ITGC access domain.

Key Takeaways

  • Least privilege only holds if access is reviewed when roles change, not just at onboarding.
  • Dormant and orphaned accounts are leading unauthorised-access vectors.
  • Privilege creep silently erodes segregation of duties over an employee's tenure.
  • Owner attestation, not just a report, is what makes a review defensible.

See This on Your Own Data

AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.