Change management control test for a SaaS platform
Scenario
KaizenMotors runs a customer-facing SaaS (parts-catalogue). Auditor wants to test change management for the last quarter — 47 production changes were deployed. He'll sample 15 and ask you to prove each: (a) had approval, (b) was tested, (c) had rollback plan, (d) was deployed by an authorised person.
Your role
You are the IT auditor doing the walkthrough + test.
Your task
Design the change management test: 1. Sample selection method (random / risk-based / hybrid — justify) 2. Evidence checklist per sampled change (5-7 items) 3. Test procedures (steps you'd walk through with the SME) 4. Deficiency categorisation (what makes a finding 'significant' vs 'minor') 5. How you'd handle emergency changes (fast-track) in the sample
Deliverable format: Test document ~600-900 words + evidence checklist
Toolkit
- Sample: 15/47 is ~32% — good for a first year, statistically reasonable
- Standard evidence: change ticket, approvals list, test results, deployment record, post-deploy verification
- Emergency changes: pre-approved playbook + post-hoc board notification within 5 days
- Deficiencies: material weakness (multi-transaction misstatement risk), significant, minor, observation
Success criteria (what the AI grades against)
- Sample selection method reasoned (not just 'random')
- Evidence checklist covers ALL 4 requirements (approval + test + rollback + deployer)
- Emergency changes have their own path (audit doesn't ignore them)
- Deficiency categorisation is defensible
- Test procedures name specific ticketing systems (Jira, ServiceNow)
Log in to submit your deliverable for AI review.
Log in / Register