Technology
Access Rights Recertification
Status of periodic user access reviews and the volume of excessive or stale entitlements found.
Why stale access is a standing control failure
Excessive and stale user entitlements are among the most common IT control weaknesses the AGSA reports, and they directly undermine segregation of duties and POPIA obligations to limit data access. Periodic recertification, where owners confirm that each user still needs their access, is the control that keeps entitlement creep in check. AuditPro Core tracks recertification status and the volume of excessive or stale rights uncovered.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
Reviews due
62
Completed
48
77%
Excess entitlements
214
to revoke
Dormant accounts
89
▲ 22
Flagged entitlements by system
Recertification by system
| System | Users | Reviewed % | Revoked |
|---|---|---|---|
| Financial (BAS) | 420 | 82 | 41 |
| Payroll (PERSAL) | 96 | 71 | 28 |
| SCM portal | 188 | 79 | 22 |
| HR system | 145 | 68 | 17 |
| Active Directory | 610 | 74 | 33 |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
Access recertification
Recertification is a periodic review where the appropriate owner confirms or revokes each user's access. It counters the natural drift of accumulating rights over time.
Excessive entitlements
An excessive entitlement is access beyond what a role requires, often breaking segregation of duties. It widens both the fraud surface and the data-breach surface.
Stale access
Stale access belongs to leavers, movers or dormant accounts that retain rights they no longer need. It is a frequent route for unauthorised or untraceable activity.
Review completeness
A recertification campaign is only as good as its completion rate. Unreviewed populations leave blind spots that defeat the purpose of the control.
How AuditPro Core Bridges the Gap
- Campaign tracking: recertification status is monitored per system and per reviewer to completion.
- Exception flagging: excessive and stale entitlements are surfaced for revocation through a workflow.
- Continuous monitoring: the platform watches for entitlement drift between formal review cycles.
- Audit-ready export: completed recertifications and revocations export as evidence for IT general control audits.
Key Takeaways
- Entitlement creep erodes segregation of duties and POPIA data limits.
- Stale leaver and dormant accounts are a common unauthorised-access route.
- Recertification only works at high completion; unreviewed populations are blind spots.
- Track both review status and the volume of rights actually revoked.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.
