User Access & ITGC Checklist free PDF cover
Checklist

User Access & ITGC Checklist

Verify access and core IT general controls: approved least-privilege access, prompt leaver removal, controlled privileged and service accounts, evidence-based access reviews, approved changes and tested backups.

What you'll find inside

  • Access lifecycle checks: business need, manager and system-owner approval, least privilege, prompt leaver removal and adjusted mover access
  • Privileged access checks: limited admin accounts, logged activity, shared credentials, time-bound emergency access and owned service accounts
  • ITGC basics checks: access reviews, approved and tested production changes, job and interface monitoring, backup restoration and incident tracking
  • Risk prompts on control bypass, one-person control of an outcome and exceptions that have become normal practice
  • An “evidence to retain” list for your workpapers, plus a Done / Review / N/A status key, with space for auditor notes and testing exceptions
  • A completion page with six closing checks and a final conclusion, owner and follow-up date

Best for

  • IT Auditors
  • Internal Auditors
  • Senior Internal Auditors
  • Compliance Professionals

Resource information

Format:
PDF
Pages:
6
Price:
Free
Registration:
Not required

About This Resource

If system access and changes are not controlled, automated controls and system reports cannot be relied on. This checklist helps auditors review user access and basic IT general controls without needing a full specialist IT audit.

Use it when auditing key business systems or relying on system-generated evidence. Access lifecycle checks confirm requests specify business need and role, manager and system-owner approvals are obtained, roles follow least privilege, leaver access is disabled promptly, and mover access is adjusted rather than simply added to. Privileged access checks cover limited and separately identified admin accounts, logging and review of privileged activity, control of shared credentials, time-bound and retrospectively reviewed emergency access, and owners for service accounts. ITGC basics checks cover evidence-based periodic access reviews, approved, tested and segregated production changes, monitoring of critical jobs and interfaces, tested backup restoration, and tracking of security incidents and repeated access exceptions.

Mark each point Done, Review or N/A with evidence, use the risk prompts to look for conflicting access, and record your conclusion on the completion page. Escalate complex technical issues to IT audit specialists where needed.

© Salih Ahmed Islam

Related Internal Audit Resources

Segregation of Duties Review Checklist free PDF cover
ChecklistInternal Controls

Segregation of Duties Review Checklist

Review segregation of duties end to end — risk-based conflict definitions, privileged and emergency access, users matched to current roles, tested compensating controls and remediation prioritized by business impact.

PDF • 6 Pages • Free

Risk & Control Matrix Template free PDF cover
TemplateInternal Controls

Risk & Control Matrix Template

Build a practical risk and control matrix that links each business objective and risk to its control, owner, frequency and evidence, then records the planned test and conclusion.

PDF • 6 Pages • Free