IT & Cyber Audit
Access-Control Review
Excess and dormant access is the most common path to unauthorised transactions and undetected fraud in financial systems.
Why Access Review Matters
The principle of least privilege requires that users hold only the access their role demands, and periodic access review is the control that keeps reality aligned with that principle as people move, leave and change roles. Dormant accounts and accumulated privileges are repeatedly cited by the AGSA and under ISSAI 5300 as access-control weaknesses that enable fraud and error. AuditPro Core reviews user rights, dormant accounts and privilege creep across systems so access stays appropriate rather than quietly expanding.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
Accounts reviewed
4,210
Dormant accounts
186
no login 90+ days
Excess privileges
94
Recertification rate
88%
▲ 5 pts
Access issues by system
Privileged account exposure
| System | Admins | Dormant | Shared |
|---|---|---|---|
| Financial ledger | 9 | 2 | 1 |
| Payroll | 6 | 1 | 2 |
| HR | 7 | 3 | 0 |
| Email / directory | 12 | 5 | 1 |
| Billing | 8 | 2 | 1 |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
Least privilege
Every user should have the minimum access needed for their job and nothing more. Access granted for a past role but never removed is the residue that least-privilege reviews exist to catch.
Dormant accounts
Accounts that are no longer used — leavers, contractors, generic logins — are prime vectors for unauthorised access. Dormant privileged accounts are especially dangerous and should be disabled promptly.
Privilege creep
As employees change roles, access tends to accumulate rather than reset. Over time this erodes segregation of duties and concentrates risky capability in long-tenured staff.
How AuditPro Core Bridges the Gap
- Access reconciliation: current rights are matched against role baselines to expose excess and orphaned access.
- Dormancy detection: accounts with no recent activity are flagged for disablement.
- Exception workflow: inappropriate access routes to system and data owners for revocation and sign-off.
- Audit-ready export: the access-review register and attestations export as evidence for the ITGC access domain.
Key Takeaways
- Least privilege only holds if access is reviewed when roles change, not just at onboarding.
- Dormant and orphaned accounts are leading unauthorised-access vectors.
- Privilege creep silently erodes segregation of duties over an employee's tenure.
- Owner attestation, not just a report, is what makes a review defensible.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.
