Generate an Excel/PDF workbook for user access, privileged access, SoD, change management, backups, interfaces, jobs, audit logs, report reliability and monitoring exceptions.
| Area | Risk | Control | Test | Evidence | Cadence |
|---|---|---|---|---|---|
| User access lifecycle | Users are created, modified or retained without approved business need, role mapping or timely leaver removal. | Access request approval, role-based provisioning, joiner-mover-leaver workflow and periodic access review. | Match active user list to HR active/leaver list, sample new users, test role mapping and inspect review sign-off. | User list, HR employee/leaver list, access tickets, role matrix, access review file and exception tracker. | Monthly / Quarterly |
| Privileged access | Admin or superuser rights allow unauthorised master changes, transaction overrides or audit-log suppression. | Privileged access approval, separate admin IDs, activity logging and periodic admin review. | List privileged users, inspect approval, review admin activity logs and test emergency access closure. | Admin user list, privileged access approval, activity log, emergency access register and reviewer conclusion. | Monthly |
| Segregation of duties | One user can initiate and conceal transactions, such as vendor creation plus payment release. | SoD rule matrix, role-combination review, conflict approval and compensating control validation. | Run role-conflict report, identify create/approve/post/release conflicts and review unresolved exceptions. | SoD matrix, role export, conflict report, compensating control evidence and owner sign-off. | Quarterly |
| Change management | Application, configuration, workflow or report changes move to production without approval, testing or rollback evidence. | Change request approval, UAT sign-off, production migration approval, emergency-change review and developer access restriction. | Sample production changes, trace approval/UAT/deployment, review emergency changes and check production developer access. | Change tickets, UAT evidence, deployment log, release note, emergency-change register and production access list. | Monthly / Release based |
| Backup recovery and DR | Critical finance data cannot be restored because backups fail, are overwritten or have never been restoration-tested. | Scheduled backups, backup-failure alerts, offsite/off-network retention, restoration testing and RTO/RPO mapping. | Inspect backup logs, verify restoration test, review failure tickets and compare RTO/RPO to business requirement. | Backup logs, restoration report, DR drill evidence, RTO/RPO matrix, incident tickets and storage policy. | Monthly / Quarterly |
| Interfaces and batch jobs | Data moving between ERP, payroll, bank, GST, inventory, WMS or reporting systems is incomplete, duplicated or stale. | Interface control totals, failed-job alerts, exception queue review and manual reprocessing approval. | Review failed jobs, compare source/target counts and values, age exception queues and test reprocessing approvals. | Interface logs, batch totals, exception queue, reconciliation file, job scheduler report and reprocessing approval. | Weekly / Monthly |
| Audit logs and master changes | Critical configuration, vendor, customer, bank, payroll or inventory changes cannot be traced to user, timestamp and approval. | Audit trail enabled, log retention, master-data change approval and high-risk change review. | Verify logs for critical tables, sample master changes, compare old/new values and inspect approval evidence. | Audit-log settings, master change report, old/new value extract, approval ticket, retention policy and review sign-off. | Monthly |
| Report reliability and IPE | Auditors rely on ERP reports or exported spreadsheets that are incomplete, modified or generated with wrong parameters. | Report owner approval, parameter retention, source reconciliation and protected export storage. | Reperform report extraction for samples, compare report totals to GL/subledger and inspect parameter evidence. | Report catalogue, report parameters, export file, GL/subledger tie-out, owner sign-off and version history. | Per audit / Monthly |
| Third-party and cloud systems | Hosted ERP, payroll, POS, bank, SaaS or outsourced systems lack access, change, backup or incident evidence. | Vendor responsibility matrix, SOC/assurance report review, SLA monitoring, incident reporting and exit plan. | Review vendor controls, SOC exceptions, SLA breaches, incident logs and user access responsibilities. | Vendor contract, responsibility matrix, SOC report, SLA dashboard, incident register and exit/BCP plan. | Annual / Quarterly |
| ITGC monitoring and follow-up | Access, SoD, failed-job, backup or master-change exceptions repeat without ownership, due dates or closure evidence. | Exception rules, owner assignment, management response, due-date tracking and closure evidence review. | Review open exceptions, test ageing, inspect closure evidence and identify repeat exceptions by control owner. | Exception report, ATR tracker, management response, closure evidence, ageing report and repeat-finding analysis. | Monthly |
Use this with the ITGC internal audit checklist, the audit trail Rule 11(g) guide and the monitoring rules repository.
ITGC audit should focus on the systems and reports that finance and operational controls rely on. The workbook connects access, SoD, changes, operations, logs, report reliability and third-party/cloud controls to the process controls affected by those systems.
The Excel export gives auditors separate sheets for engagement scope, RCM rows, user access, privileged access/SoD, changes, backup/DR, interfaces/jobs, logs/master changes, report reliability and monitoring exceptions.
A CA firm is reviewing ERP reliance for a company using SAP, payroll software, bank portals and a reporting dashboard for P2P, payroll, inventory and R2R internal audit.