Back to Explore
🛡️

IT & Cyber Audit

System Change Management

Unauthorised or untested system changes are a direct route to data corruption, control bypass and unreliable financial information.

📖 6 min read🎯 Intermediate✍️ Updated 2026

Why Change Management Matters

Change management is the ITGC domain that ensures system changes are authorised, tested and traceable, preventing a developer or vendor from altering logic or data outside proper control. The AGSA and ISSAI 5300 scrutinise emergency and unauthorised changes closely, because they are where reliance on system-generated information most often breaks down. AuditPro Core governs the change lifecycle — approvals, emergency changes and unauthorised deployments — so every alteration to a key system is accountable.

The Numbers

AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.

Changes deployed

612

Unauthorised

14

no approval

Emergency changes

47

8% of total

Approval rate

94%

▲ 3 pts

Changes by type

Unauthorised changes by system

SystemCountTestedStatus
Financial ledger52Investigate
Billing41Investigate
Payroll22Regularised
HR20Investigate
Website11Regularised

Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.

Authorised change lifecycle

A controlled change is requested, approved, tested and deployed by separated parties with a record at each step. Missing any step weakens assurance that the change was legitimate and safe.

Emergency changes

Emergencies sometimes require expedited changes, but these must be retrospectively approved and reviewed. Emergency status cannot become a routine bypass of the normal approval path.

Unauthorised deployments

A change in production with no corresponding approved request is the most serious change-control failure. It means the controlled lifecycle was circumvented entirely and the system state can no longer be trusted.

How AuditPro Core Bridges the Gap

  • Lifecycle traceability: every production change is matched to its approval, test and deployment record.
  • Exception workflow: unauthorised and unreviewed emergency changes escalate for investigation and sign-off.
  • Continuous monitoring: deployments without a matching approved request are flagged as they occur.
  • Audit-ready export: the change register exports as evidence for the ITGC change-management domain.

Key Takeaways

  • Authorise, test and separate duties across the change lifecycle, every time.
  • Emergency changes need retrospective approval; they cannot become the default path.
  • An unmatched production change is the most serious change-control finding.
  • Reliable financial data depends on a controlled, traceable change process.

See This on Your Own Data

AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.