Audit access to critical systems — joiner, mover and leaver workflows, timely removal, privileged and dormant accounts, access recertification, and the change and logging controls behind them.
Verify access and core IT general controls: approved least-privilege access, prompt leaver removal, controlled privileged and service accounts, evidence-based access reviews, approved changes and tested backups.
Review segregation of duties end to end — risk-based conflict definitions, privileged and emergency access, users matched to current roles, tested compensating controls and remediation prioritized by business impact.
Identify combinations that let one person initiate and complete a risky transaction, test them against actual user access, and judge whether compensating controls really work.