IT & Cyber Audit
System Change Management
Unauthorised or untested system changes are a direct route to data corruption, control bypass and unreliable financial information.
Why Change Management Matters
Change management is the ITGC domain that ensures system changes are authorised, tested and traceable, preventing a developer or vendor from altering logic or data outside proper control. The AGSA and ISSAI 5300 scrutinise emergency and unauthorised changes closely, because they are where reliance on system-generated information most often breaks down. AuditPro Core governs the change lifecycle — approvals, emergency changes and unauthorised deployments — so every alteration to a key system is accountable.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
Changes deployed
612
Unauthorised
14
no approval
Emergency changes
47
8% of total
Approval rate
94%
▲ 3 pts
Changes by type
Unauthorised changes by system
| System | Count | Tested | Status |
|---|---|---|---|
| Financial ledger | 5 | 2 | Investigate |
| Billing | 4 | 1 | Investigate |
| Payroll | 2 | 2 | Regularised |
| HR | 2 | 0 | Investigate |
| Website | 1 | 1 | Regularised |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
Authorised change lifecycle
A controlled change is requested, approved, tested and deployed by separated parties with a record at each step. Missing any step weakens assurance that the change was legitimate and safe.
Emergency changes
Emergencies sometimes require expedited changes, but these must be retrospectively approved and reviewed. Emergency status cannot become a routine bypass of the normal approval path.
Unauthorised deployments
A change in production with no corresponding approved request is the most serious change-control failure. It means the controlled lifecycle was circumvented entirely and the system state can no longer be trusted.
How AuditPro Core Bridges the Gap
- Lifecycle traceability: every production change is matched to its approval, test and deployment record.
- Exception workflow: unauthorised and unreviewed emergency changes escalate for investigation and sign-off.
- Continuous monitoring: deployments without a matching approved request are flagged as they occur.
- Audit-ready export: the change register exports as evidence for the ITGC change-management domain.
Key Takeaways
- Authorise, test and separate duties across the change lifecycle, every time.
- Emergency changes need retrospective approval; they cannot become the default path.
- An unmatched production change is the most serious change-control finding.
- Reliable financial data depends on a controlled, traceable change process.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.
