Key information:
Periodic reviews of employee accounts and access rights to systems, applications and data are an important element of risk management within an organisation.
One of the fundamental stages of any meaningful access review should be an analysis of segregation of duties (SoD) conflicts.
In some cases, identified irregularities cannot be eliminated and additional control mechanisms must be implemented to mitigate the risk.
In many organisations, access reviews are carried out solely because they are required by internal procedures, group control standards or auditors. As a result, the process is often reduced to approving a system-generated list of users, which becomes a routine exercise performed without deeper analysis of the actual risks associated with granted permissions. Unfortunately, this approach gives rise to numerous threats. What exactly are these risks, and why should they not be ignored?
First and foremost, it should be emphasised that a properly conducted access review can constitute one of the key elements of the internal control environment. It enables organisations to verify whether system users possess only those permissions that are necessary to perform their duties, while also identifying areas that may adversely affect:
- information security,
- data integrity,
- the reliability of financial reporting.
Access reviews become particularly important in systems supporting key business processes, such as ERP systems. Excessive permissions, uncontrolled privileged access or unresolved segregation of duties conflicts may lead not only to operational errors but may also weaken the control mechanisms on which the financial reporting process relies. Access reviews should therefore be viewed not as a recurring formality, but as a tool supporting effective risk management within an organisation.
Find out how we can support your business
Which systems should be prioritised when analysing risks related to employee access rights?
Not all systems used within an organisation generate the same level of risk. When conducting an internal audit aimed at mitigating deficiencies, attention should first be focused on applications supporting key business processes and systems whose operation may directly or indirectly affect financial reporting.
Depending on the organisation’s specific circumstances, the systems most exposed to risks arising from inadequate access management may include:
- ERP systems and finance and accounting applications,
- warehouse management systems,
- production systems,
- sales systems,
- applications and solutions used for identity and access management.
How can you assess whether an employee genuinely requires all assigned permissions?
Many organisations conducting periodic access reviews as part of their control processes focus solely on validating the list of active users and overlook an analysis of the scope of permissions assigned to them. Yet excessive access rights are among the most common risks affecting data security and information confidentiality in business systems.
Changes in job position, participation in an unusual project or temporary cover arrangements may result in additional permissions being granted, which are not always subsequently removed by the access administrator.
For this reason, every review should answer two key questions:
- Who has access?
- Is the level of access still justified from a business perspective?
Analysis of privileged access rights
It is worth remembering that internal auditors should pay particular attention during regular access reviews to users holding privileged access rights, including administrative privileges.
Users with privileged access often have the ability to manage user accounts, modify and configure systems, or perform activities unavailable to standard users. Consequently, organisations that aim to manage access effectively should periodically verify the appropriateness of such roles and ensure that they have been assigned exclusively to individuals who genuinely require them to perform their duties.
This enhanced analysis should cover all user accounts frequently used for system integrations, automated processes or application operations. This means that organisations reviewing privileged access should place particular emphasis on monitoring:
- administrator accounts,
- technical accounts,
- service accounts.
Due to their broad scope of permissions – and the limited ability to identify the individual responsible for their use – such accounts should have an assigned business or technical owner and be subject to regular review.
Risks associated with overlooking segregation of duties (SoD) conflicts
It should be stressed that a review of system access rights should not be limited to assessing individual user permissions. Account reviews should be carried out from a broad and holistic perspective. This means understanding not only which processes a given individual can perform within the system, but also determining whether the assigned permissions allow that person to perform activities that should act as controls over one another.
Examples of such conflicting activities include:
- the ability to create suppliers, enter payment instructions and approve payments simultaneously,
- the ability to enter and post accounting documents,
- the ability to assign permissions to other users.
Such segregation of duties conflicts are among the most frequently identified audit findings and may significantly weaken the control mechanisms operating within an organisation.
For this reason, SoD analysis should form one of the fundamental elements of every meaningful review of access rights assigned within an organisation.
Former employee accounts and inactive access rights – a risk not worth ignoring
One of the primary objectives of regular reviews of access to data and applications is to confirm that system access is granted only to individuals who genuinely require it. Nevertheless, during audits and assurance engagements aimed at confirming the quality of organisational processes, statutory auditors regularly identify active accounts belonging to former employees or users who have not accessed the system for an extended period.
The existence of such dormant accounts increases the risk of unauthorised account use and makes it more difficult to manage the control environment effectively. For this reason, every review of access to organisational resources should include an analysis of unused accounts and a rigorous assessment of whether they remain justified. It is also worth noting that this issue does not affect only personal accounts. Similar risks may arise in connection with privileged access management and may involve unused technical, service or temporary accounts left within systems following project completion or organisational changes.
The regular identification of such accounts helps reduce risk and increases the transparency of the control environment.
How should the results of an access rights review be documented?
Importantly, a review of access rights does not end once irregularities have been identified. Proper documentation of the review’s findings is equally important. Such documentation should indicate:
- who conducted the review,
- the scope of the review,
- the risks identified during the review,
- the decisions taken in relation to particular users or permissions.
It is equally important to identify the individual responsible for approving the review results. In practice, this role is most commonly performed by the business process owner, the system owner or the manager of the organisational unit with the best understanding of the system’s use and associated risks. This individual should perform an independent verification of the review results, reducing the risk that irregularities may be overlooked.
Organisations should also implement processes that facilitate effective future access control management and document remediation activities, including the persons responsible for implementing them and the planned completion dates. This approach enables organisations to monitor progress and confirm that identified deficiencies have been effectively addressed. Properly prepared documentation also serves as important evidence of the operation of controls for auditors, management and individuals responsible for overseeing the internal control system.
Documentation and monitoring of exceptions
The purpose of reviewing access to applications and systems used within an organisation is not merely to identify irregularities but also to make informed decisions regarding the treatment of identified risks.
In certain cases, removing a segregation of duties conflict, restricting privileged access rights or revoking specific access may not be possible without adversely affecting the organisation’s operations. This particularly applies to smaller entities, organisations undergoing transformation, restructuring or conversion, as well as areas where limited staffing resources prevent the full implementation of an ideal control environment.
In such situations, any exception identified during an access review should be formally approved by the process owner, system owner or the individual responsible for managing the relevant risk. The documentation prepared by auditors should clearly define the reason for the exception, the level of associated risk, the anticipated duration of the exception and the additional controls implemented to reduce the risk to an acceptable level.
Examples of measures that may reduce the risks associated with such exceptions include:
- periodic review of reports,
- additional approval of performed operations,
- independent review of activities carried out by users possessing elevated permissions.
Regular reassessment of approved exceptions is equally important. Risks that were business-justified several months earlier may no longer remain valid following changes in the organisational structure, implementation of a new system or growth in workforce levels. For this reason, every organisation should establish a frequency for reviewing exceptions and designate individuals responsible for monitoring their ongoing justification.
This approach transforms exceptions from informal departures from established rules into elements of a conscious risk management process. It helps maintain a balance between control requirements and business needs while improving the transparency and effectiveness of the entire access review process.
What should be remembered when reviewing access to systems that affect financial reporting?
To summarise, effective access management requires a clear understanding that a review of access to applications and systems should not be reduced to the periodic approval of system-generated user lists. Its primary objective is to confirm that access to critical applications is granted only to individuals who genuinely require it to perform their duties and that the scope of permissions remains appropriate for their role.
It is also worth remembering that the greatest value is delivered by risk-based reviews focused on:
- analysing systems supporting key business processes,
- verifying privileged access rights,
- identifying segregation of duties conflicts,
- regularly monitoring inactive user accounts.
Equally important are the proper documentation of review outcomes and the informed management of exceptions that cannot be eliminated for business or organisational reasons.
A well-executed access review not only reduces the risk of unauthorised access to data and system functionalities, but also strengthens the internal control environment and enhances the reliability of information used in the financial reporting process. As a result, it becomes a genuine control mechanism supporting organisational risk management rather than merely a formality performed for audit or regulatory compliance purposes.