A
AcadiFi
CS
career_switch2026-05-21
cpaAUDAUD / ISC - Logical Access

What evidence should support a user access review?

44 upvotes
AcadiFi TeamVerified Expert
AcadiFi Certified Professional

A useful access review needs more than a sign-off. The auditor should look for the user listing reviewed, the review date, the reviewer, evidence of follow-up on exceptions, and support that the population was complete.

For example, if Lakeside Claims reviews access to its claims system, the evidence should show which users had access, which roles they held, whether terminated employees were removed, and whether incompatible duties were resolved. A checkbox without the user list and exception follow-up is weak evidence.

  • Related article: cpa-itgc-dependency-controls-map
  • Related QB item: qb-cpa-terminated-user-access-risk
📋

Master AUD with our CPA Course

86 lessons · 160+ hours· Expert instruction

#AUD / ISC - Logical Access