
How to Review Segregation of Duties
Identify combinations that let one person initiate and complete a risky transaction, test them against actual user access, and judge whether compensating controls really work.
PDF • 6 Pages • Free
Almost every business process now runs through systems. If access to those systems is not controlled, or if changes are made without approval, even well-designed business controls cannot be relied on. That is why every internal auditor — not only IT specialists — needs a working understanding of IT general controls.
IT audit work at this level typically reviews user access provisioning and removal, periodic access reviews, privileged and generic accounts, segregation of duties within systems, and change management for key applications. Auditors also consider the reliability of system reports used as audit evidence.
Common risks include former employees with active accounts, users with conflicting access such as creating vendors and releasing payments, unmonitored administrator accounts, access reviews that are rubber-stamped, and system changes moved to production without testing or approval.
The resources below are designed for operational and financial auditors who need practical IT assurance. Use the user access and ITGC guide and checklist to test the basics, and the segregation of duties resources to identify conflicting access. Escalate complex technical issues to specialist IT auditors where needed.
4 free resources · No registration

Identify combinations that let one person initiate and complete a risky transaction, test them against actual user access, and judge whether compensating controls really work.
PDF • 6 Pages • Free

Audit access to critical systems — joiner, mover and leaver workflows, timely removal, privileged and dormant accounts, access recertification, and the change and logging controls behind them.
PDF • 6 Pages • Free

Review segregation of duties end to end — risk-based conflict definitions, privileged and emergency access, users matched to current roles, tested compensating controls and remediation prioritized by business impact.
PDF • 6 Pages • Free

Verify access and core IT general controls: approved least-privilege access, prompt leaver removal, controlled privileged and service accounts, evidence-based access reviews, approved changes and tested backups.
PDF • 6 Pages • Free