IT controls
IT Access Control Deficiencies
Findings on user access management, segregation of duties and privileged access across financial systems.
Why access controls matter
Financial systems are only as trustworthy as the controls governing who can access them and what they can do, which makes IT access control a foundation of the entire control environment. Weak user management, broken segregation of duties and unchecked privileged access undermine every downstream financial assertion and create direct fraud and POPIA exposure. AuditPro Core consolidates access-control findings across financial systems so general IT control weaknesses are addressed before they corrupt the financial records they protect.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
Access findings
289
▲ 14
SoD violations
146
Dormant accounts active
1 920
Privileged users unreviewed
68%
Access findings by system
Top access deficiencies
| Deficiency | Entities | Severity |
|---|---|---|
| Generic / shared accounts | 94 | High |
| No user access review | 121 | High |
| Terminated users active | 78 | Medium |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
User access management
Access must be granted on a least-privilege basis, reviewed regularly and revoked promptly when staff leave or change roles. Stale and orphaned accounts are a primary attack surface.
Segregation of duties in systems
No single user should be able to initiate, approve and record the same transaction. Where system roles allow this, the control breaks down regardless of paper policy.
Privileged and super-user access
Administrator and super-user accounts can bypass application controls and alter data directly. Their use must be tightly restricted, logged and independently reviewed.
Link to POPIA and data integrity
Uncontrolled access also exposes personal information, engaging POPIA obligations. Access logs are the evidence base for both financial assurance and data-protection accountability.
How AuditPro Core Bridges the Gap
- Access reconciliation: system user lists are reconciled to active HR records to surface orphaned and stale accounts.
- Exception workflow: segregation-of-duties conflicts and excessive privileges are flagged for remediation.
- Traceability to source: each finding links to the user, role and system affected, with supporting access logs.
- Continuous monitoring: access rights are re-tested each cycle so privilege creep is caught early.
Key Takeaways
- Access control is the foundation beneath every financial system assertion.
- Least privilege and prompt revocation prevent orphaned-account risk.
- Privileged accounts can bypass controls and must be logged and reviewed.
- Uncontrolled access is simultaneously a financial and a POPIA exposure.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.
