Back to Explore
🛡️

IT controls

IT Access Control Deficiencies

Findings on user access management, segregation of duties and privileged access across financial systems.

📖 6 min read🎯 Intermediate✍️ Updated 2026

Why access controls matter

Financial systems are only as trustworthy as the controls governing who can access them and what they can do, which makes IT access control a foundation of the entire control environment. Weak user management, broken segregation of duties and unchecked privileged access undermine every downstream financial assertion and create direct fraud and POPIA exposure. AuditPro Core consolidates access-control findings across financial systems so general IT control weaknesses are addressed before they corrupt the financial records they protect.

The Numbers

AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.

Access findings

289

▲ 14

SoD violations

146

Dormant accounts active

1 920

Privileged users unreviewed

68%

Access findings by system

Top access deficiencies

DeficiencyEntitiesSeverity
Generic / shared accounts94High
No user access review121High
Terminated users active78Medium

Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.

User access management

Access must be granted on a least-privilege basis, reviewed regularly and revoked promptly when staff leave or change roles. Stale and orphaned accounts are a primary attack surface.

Segregation of duties in systems

No single user should be able to initiate, approve and record the same transaction. Where system roles allow this, the control breaks down regardless of paper policy.

Privileged and super-user access

Administrator and super-user accounts can bypass application controls and alter data directly. Their use must be tightly restricted, logged and independently reviewed.

Link to POPIA and data integrity

Uncontrolled access also exposes personal information, engaging POPIA obligations. Access logs are the evidence base for both financial assurance and data-protection accountability.

How AuditPro Core Bridges the Gap

  • Access reconciliation: system user lists are reconciled to active HR records to surface orphaned and stale accounts.
  • Exception workflow: segregation-of-duties conflicts and excessive privileges are flagged for remediation.
  • Traceability to source: each finding links to the user, role and system affected, with supporting access logs.
  • Continuous monitoring: access rights are re-tested each cycle so privilege creep is caught early.

Key Takeaways

  • Access control is the foundation beneath every financial system assertion.
  • Least privilege and prompt revocation prevent orphaned-account risk.
  • Privileged accounts can bypass controls and must be logged and reviewed.
  • Uncontrolled access is simultaneously a financial and a POPIA exposure.

See This on Your Own Data

AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.