Day 16 of 22ITGC · SOC 1 / SOC 2· ~60 min

Change management control test for a SaaS platform

Scenario

KaizenMotors runs a customer-facing SaaS (parts-catalogue). Auditor wants to test change management for the last quarter — 47 production changes were deployed. He'll sample 15 and ask you to prove each: (a) had approval, (b) was tested, (c) had rollback plan, (d) was deployed by an authorised person.

Your role

You are the IT auditor doing the walkthrough + test.

Your task

Design the change management test: 1. Sample selection method (random / risk-based / hybrid — justify) 2. Evidence checklist per sampled change (5-7 items) 3. Test procedures (steps you'd walk through with the SME) 4. Deficiency categorisation (what makes a finding 'significant' vs 'minor') 5. How you'd handle emergency changes (fast-track) in the sample

Deliverable format: Test document ~600-900 words + evidence checklist

Toolkit

  • Sample: 15/47 is ~32% — good for a first year, statistically reasonable
  • Standard evidence: change ticket, approvals list, test results, deployment record, post-deploy verification
  • Emergency changes: pre-approved playbook + post-hoc board notification within 5 days
  • Deficiencies: material weakness (multi-transaction misstatement risk), significant, minor, observation

Success criteria (what the AI grades against)

  • Sample selection method reasoned (not just 'random')
  • Evidence checklist covers ALL 4 requirements (approval + test + rollback + deployer)
  • Emergency changes have their own path (audit doesn't ignore them)
  • Deficiency categorisation is defensible
  • Test procedures name specific ticketing systems (Jira, ServiceNow)

Log in to submit your deliverable for AI review.

Log in / Register