Closing the Access Gap: A 3-Phase User Access Review Framework
Internal Audit Collective
0:00 / 0:00
Closing the Access Gap: A 3-Phase User Access Review Framework
2 просмотра · 7 дн. назад
Internal Audit Collective
10 подписчиков
2 просмотра · 7 дн. назад
Most user access reviews are a rubber stamp — an email with a spreadsheet attached and "looks good" typed back. Brian Ellis, IT Controls Manager at B. Riley Financial, inherited multiple material weaknesses built on exactly that pattern. Eighteen months later, the process is being copied by sister companies and getting zero UAR-related audit findings. This session is the live walkthrough of how he rebuilt it.
You'll learn Brian's three-phase framework — preparation, execution, remediation — including how to define system scope, build an ownership matrix, require line-item review decisions instead of blanket approvals, and document remediation so it actually counts as evidence.
Real examples throughout include a live demo of his team's JIRA-based review workflow, how they document segregation of duties for complex systems like NetSuite, how they handle dormant accounts and privileged access exceptions, and where to draw the responsibility line for terminated users versus current employees with inappropriate access.
Whether your UAR process is failing audit or you're just looking to tighten up documentation, this framework gives you a repeatable structure to work from.
👉 Join the Internal Audit Collective, the community where 1300+ Internal Audit and SOX practitioners connect in real time: internalauditcollective.com
Subscribe for more practical, no-fluff internal audit and SOX content.
#internalaudit #SOXcompliance #ITGC #useraccessreview #riskmanagement #cybersecurity
0:00 Introduction
3:37 The Transformation Story: From Material Weakness to Clean Process
9:29 The Three-Phase UAR Framework
14:25 Preparation: System Inventory, Risk Tiers & Data Flow
20:33 Live Demo: Active Employee Listing & Reconciliation
27:47 Live Demo: Walking Through a JIRA Review Ticket
39:15 Live Demo: Documenting Segregation of Duties
47:55 Execution Best Practices: Sizing Reviews & Avoiding Fatigue
49:30 Remediation: Immediate Action Protocols & Exceptions
52:42 Advanced Strategies, Tech Enablers & Common Pitfalls
56:00 Recap & Closing