Day 15 of 22ITGC · SOC 1 / SOC 2· ~60 min

Design an access review checklist (SOX-aligned)

Scenario

KaizenMotors (auto-parts, mid-size, ₹300 cr revenue, US-listed parent) requires quarterly access reviews for all financial-system users under SOX ITGC. There are 4 systems in scope: 1. Oracle EBS (ERP + Finance) — 340 users 2. Blackline (reconciliation) — 80 users 3. Kyriba (treasury) — 25 users 4. Corporate GitHub org — 60 users (some devs have prod-DB read access)

Your role

You are the ITGC Lead.

Your task

Design the access review process: 1. Access review checklist (what data to pull, from where) 2. Reviewer assignment (who reviews whose access) 3. Review criteria (what does 'appropriate access' mean per system) 4. Segregation-of-duties (SoD) conflict rules — 3 examples 5. Exception approval workflow (when access is retained despite review) 6. Evidence retention for auditor

Deliverable format: Process document ~700-1000 words + checklist table

Toolkit

  • SOX ITGC access requirements: quarterly review, business owner sign-off, evidence retained 7 years
  • SoD examples: cannot post + approve a journal, cannot create + pay a vendor, cannot request + approve access
  • Business owner ≠ IT admin — separation matters for defensibility
  • Rule of thumb: reviewer needs to actually understand what the access allows

Success criteria (what the AI grades against)

  • SoD conflicts are specific transactions, not vague roles
  • Reviewer assignment excludes self-review
  • Exception approval requires ranking above reviewer's role
  • Evidence retention meets 7-year rule
  • Blackline + Kyriba likely have higher scrutiny (financial-close impact)
  • GitHub prod-DB access flagged as SoD risk (dev + prod)

Log in to submit your deliverable for AI review.

Log in / Register