If system access and changes are not controlled, automated controls and system reports cannot be relied on. This checklist helps auditors review user access and basic IT general controls without needing a full specialist IT audit.
Use it when auditing key business systems or relying on system-generated evidence. Access lifecycle checks confirm requests specify business need and role, manager and system-owner approvals are obtained, roles follow least privilege, leaver access is disabled promptly, and mover access is adjusted rather than simply added to. Privileged access checks cover limited and separately identified admin accounts, logging and review of privileged activity, control of shared credentials, time-bound and retrospectively reviewed emergency access, and owners for service accounts. ITGC basics checks cover evidence-based periodic access reviews, approved, tested and segregated production changes, monitoring of critical jobs and interfaces, tested backup restoration, and tracking of security incidents and repeated access exceptions.
Mark each point Done, Review or N/A with evidence, use the risk prompts to look for conflicting access, and record your conclusion on the completion page. Escalate complex technical issues to IT audit specialists where needed.