Design an access review checklist (SOX-aligned)
Scenario
KaizenMotors (auto-parts, mid-size, ₹300 cr revenue, US-listed parent) requires quarterly access reviews for all financial-system users under SOX ITGC. There are 4 systems in scope: 1. Oracle EBS (ERP + Finance) — 340 users 2. Blackline (reconciliation) — 80 users 3. Kyriba (treasury) — 25 users 4. Corporate GitHub org — 60 users (some devs have prod-DB read access)
Your role
You are the ITGC Lead.
Your task
Design the access review process: 1. Access review checklist (what data to pull, from where) 2. Reviewer assignment (who reviews whose access) 3. Review criteria (what does 'appropriate access' mean per system) 4. Segregation-of-duties (SoD) conflict rules — 3 examples 5. Exception approval workflow (when access is retained despite review) 6. Evidence retention for auditor
Deliverable format: Process document ~700-1000 words + checklist table
Toolkit
- SOX ITGC access requirements: quarterly review, business owner sign-off, evidence retained 7 years
- SoD examples: cannot post + approve a journal, cannot create + pay a vendor, cannot request + approve access
- Business owner ≠ IT admin — separation matters for defensibility
- Rule of thumb: reviewer needs to actually understand what the access allows
Success criteria (what the AI grades against)
- SoD conflicts are specific transactions, not vague roles
- Reviewer assignment excludes self-review
- Exception approval requires ranking above reviewer's role
- Evidence retention meets 7-year rule
- Blackline + Kyriba likely have higher scrutiny (financial-close impact)
- GitHub prod-DB access flagged as SoD risk (dev + prod)
Log in to submit your deliverable for AI review.
Log in / Register