Back to Explore
📋

IT & Cyber Audit

Password Policy & MFA Coverage

Coverage of multi-factor authentication and password-policy enforcement across critical systems and users.

📖 6 min read🎯 Intermediate✍️ Updated 2026

Why MFA coverage is now a baseline expectation

Multi-factor authentication and enforced password policy are the most effective defences against credential compromise, and their absence on financial and privileged systems is increasingly cited in AGSA IT control findings and POPIA security-safeguard assessments. Coverage gaps, even on a few critical accounts, undermine the whole control. AuditPro Core measures MFA and password-policy enforcement across critical systems and users so blind spots are visible.

The Numbers

AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.

MFA coverage

82%

▲ 14 pts vs prior

Policy-compliant pwd

76%

Privileged without MFA

26

critical exposure

Systems assessed

18

MFA coverage by system

Authentication gaps

SystemMFA %Weak pwd usersPriority
Legacy billing5284Critical
Payroll7141High
Financial (mSCOA)7833High
Email9118Medium

Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.

Coverage is only as strong as its weakest gap

MFA protects the institution only where it is actually enforced; a handful of exempted privileged accounts can negate the benefit. Measuring coverage against the full critical-user population is what matters.

Policy enforcement differs from policy existence

A documented password policy means nothing if systems do not technically enforce complexity, rotation and lockout. Assurance comes from confirming enforcement, not from the policy document.

Privileged users are the priority

MFA on administrator and finance-system accounts yields the greatest risk reduction. Prioritising coverage there before general users reflects the actual threat model.

How AuditPro Core Bridges the Gap

  • Coverage measurement: AuditPro Core reports MFA and policy enforcement against the defined critical-user and system population.
  • Gap identification: uncovered accounts and non-enforcing systems are flagged specifically rather than reported as an average.
  • Remediation tracking: closing gaps is assigned and monitored to completion.
  • Traceability: coverage evidence supports both the IT controls file and POPIA safeguards assessment.

Key Takeaways

  • A few uncovered privileged accounts can negate MFA's benefit.
  • Confirm technical enforcement, not just a written policy.
  • Prioritise MFA on privileged and finance-system accounts.
  • Coverage evidence serves both AGSA and POPIA requirements.

See This on Your Own Data

AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.