Technology
Change Management Controls
Discipline of IT change approvals, emergency changes and unauthorised changes across production systems.
Why undisciplined change threatens system integrity
Uncontrolled changes to production systems are a leading cause of outages, data corruption and undetected fraud, and they undermine the reliability of every automated control that the AGSA might otherwise rely upon. Disciplined change management, with proper approvals and tight handling of emergency and unauthorised changes, is a core IT general control. AuditPro Core measures change-approval discipline and the incidence of emergency and unauthorised changes across production.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
Changes deployed
428
Properly approved
94%
▲ 2%
Emergency changes
31
7% of total
Unauthorised
6
▼ 3
Change approval compliance by month
Change discipline by system
| System | Changes | Approved % | Unauthorised |
|---|---|---|---|
| Financial (BAS) | 132 | 96 | 1 |
| Payroll (PERSAL) | 74 | 93 | 2 |
| Billing system | 118 | 92 | 2 |
| Web portal | 104 | 95 | 1 |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
Authorised change
A controlled change is requested, assessed, approved and tested before deployment. The approval step is what separates a managed change from an uncontrolled one.
Emergency changes
Emergency changes bypass the normal queue to fix urgent problems and are sometimes unavoidable. They become a risk when their volume is high or retrospective approval is skipped.
Unauthorised changes
An unauthorised change reaches production without any approval. Each one is a control breakdown and a potential vector for error or malicious activity.
Segregation in deployment
The person who writes a change should not be the one who approves and deploys it unchecked. Segregation across the change lifecycle limits both error and abuse.
How AuditPro Core Bridges the Gap
- Approval tracking: changes are monitored for evidence of proper authorisation before deployment.
- Emergency oversight: the platform tracks emergency-change volume and retrospective approval compliance.
- Exception workflow: detected unauthorised changes raise an immediate investigation action.
- Traceability to source: every production change links to its request, approver and testing evidence.
Key Takeaways
- Uncontrolled change undermines the reliability of automated controls.
- Emergency changes are acceptable only with retrospective approval and low volume.
- Every unauthorised change is a control breakdown requiring investigation.
- Segregate who builds, approves and deploys changes to limit abuse.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.
