Report Date
7 July 2026
Internal Audit Report
This mock internal audit report demonstrates how a formal audit outcome can be presented in the same dynamic dashboard language as the other projects in my portfolio. The audit focuses on access governance, privileged control discipline, and evidence quality across an expanding platform environment. This page keeps the formal structure of an audit report while presenting it in the same dashboard-led visual style as the internal audit and ratio monitoring examples.
Please note that this is a mock report and does not reflect any actual audit outcome.
7 July 2026
Internal Audit, Digital Risk & Assurance
Q2 2026 Internal Audit Cycle
Management Summary
The audit identified a functioning but uneven control environment. Core governance mechanisms exist, but several important controls are not operating consistently enough for a scaled platform organization. Two high-severity findings require near-term remediation, supported by management commitments and named ownership. Medium- and low-severity findings indicate process maturity gaps that should be addressed through structured remediation planning and improved control evidence discipline.
Overall Rating
Control design and operation are broadly adequate, but important weaknesses exist that require management attention and structured remediation.
Severity Mix
Finding Summaries
Quarterly recertification of administrator-level access was incomplete in three of the last four review periods. Several privileged groups contained members whose current business need could not be evidenced during testing.
Break-glass accounts existed for production continuity, but real-time alerting, post-use review steps, and evidence of monthly readiness checks were not consistently available.
Access updates for employees changing teams were not consistently completed within the expected turnaround. Sampled users retained prior access for several days after approved role changes.
A subset of non-human accounts used for integrations and scheduled jobs did not have a clearly recorded business owner or technical custodian in the central register.
Standard access reviews were generally performed, but evidence was retained in different formats and locations, making independent validation slower than necessary.
Management Response
Management accepted all findings. Executive sponsors requested accelerated closure of the high-severity items, monthly progress review for medium-severity items, and incorporation of low-severity actions into the next governance improvement cycle.
Audit Findings
Each finding uses the standard audit flow: condition, criteria, cause, effect or risk, evidence, recommendation, and management action plan. Recommendations scale in urgency to the severity assigned.
Quarterly recertification of administrator-level access was incomplete in three of the last four review periods. Several privileged groups contained members whose current business need could not be evidenced during testing.
Privileged access should be reviewed on a defined cadence, approved by accountable system owners, and supported by retained evidence for each certification decision.
The recertification process is distributed across multiple teams without a single operational owner, and reminder-based execution has not scaled with organizational growth.
Excess or stale privileged access increases the risk of unauthorized changes, inappropriate data access, and weaker containment if an account is compromised.
Testing identified two transferred engineering managers who retained production administrator access beyond 60 days, plus one shared escalation group that contained four members without recorded reapproval.
Implement an enforced privileged access recertification workflow within 30 days, including automatic escalation for overdue approvals. Because this is high severity, remediation should be treated as urgent and tracked weekly to closure.
Security Engineering will centralize recertification in the identity platform, assign owners for each privileged group, and complete a full catch-up review cycle.
Break-glass accounts existed for production continuity, but real-time alerting, post-use review steps, and evidence of monthly readiness checks were not consistently available.
Emergency access accounts should be tightly controlled, continuously monitored, and subject to documented post-use validation following every activation.
The control relies on manual checklists, and ownership between incident response and identity administration has not been clearly operationalized.
Improperly governed emergency accounts can enable privileged activity to occur without timely detection during high-pressure incidents.
One break-glass account had no documented readiness test for the previous two months, while another routed alerts to a deprecated incident channel.
Automate break-glass alerting within 14 days and require documented post-use review within one business day of every activation. High-severity remediation should be completed on an urgent basis and validated by control testing before closure.
Platform Operations and Corporate Security will reconfigure account monitoring, reroute alerts, and introduce a standard post-incident evidence template.
Access updates for employees changing teams were not consistently completed within the expected turnaround. Sampled users retained prior access for several days after approved role changes.
Access provisioning and deprovisioning should align promptly with approved organizational changes so users retain only the access required for current duties.
The HR change workflow functions correctly, but downstream access tasks span several systems and still depend on manual reconciliation.
Delayed entitlement updates can create conflicting access, increase segregation-of-duties concerns, and slow onboarding into the new role.
Four of twelve sampled internal transfers showed lingering access for between three and six days, most frequently in support tooling and deployment consoles.
Introduce a unified transfer checklist and automated exception reporting within 60 days. Medium-severity findings should be remediated in the near term with monthly management visibility until the control operates consistently.
IT Operations will pilot transfer exception reporting and work with HR Systems to automate reconciliation for high-volume moves.
A subset of non-human accounts used for integrations and scheduled jobs did not have a clearly recorded business owner or technical custodian in the central register.
All service accounts should have named ownership, documented purpose, and periodic review to confirm necessity and privilege appropriateness.
Service account creation has historically been embedded in project delivery workflows, while the central ownership inventory was introduced later and is still partially adopted.
Unowned service accounts can persist longer than required, complicate incident response, and weaken accountability over privileged automation paths.
Nine of forty-one sampled service accounts lacked an owner field, and three had descriptions too generic to identify the underlying integration or business process.
Complete the service account inventory and ownership attestation within 90 days, beginning with production-connected integrations first. Medium-severity remediation should follow a scheduled plan with milestones and periodic oversight.
Infrastructure Engineering will reconcile the account inventory against active integrations and obtain owner attestations through the quarterly control forum.
Standard access reviews were generally performed, but evidence was retained in different formats and locations, making independent validation slower than necessary.
Control evidence should be stored in a consistent, accessible format so control operation can be demonstrated efficiently and repeatedly.
Teams have been allowed discretion over how they retain support for their reviews, and no single evidence template has been mandated.
The issue does not immediately weaken access controls, but it increases audit effort and reduces the speed of future management attestations.
Evidence was spread across chat exports, spreadsheets, ticket comments, and screenshots without a single indexed record for final approvals.
Adopt a standard evidence template and common repository model during the next review cycle. Low-severity items can be addressed through routine process improvement alongside adjacent governance enhancements.
The Governance team will publish an evidence standard and establish a shared filing convention ahead of the next quarterly access review window.
Process Improvements
These are lower-intensity improvement opportunities and intentionally do not carry a formal management response.
PI-01
Evidence collection required repeated clarification because control owners submitted similar materials in different formats. A reusable request pack would reduce friction for both audit and management.
PI-02
Management actions are currently monitored through static updates and steering meetings. A live dashboard would make remediation status, dependencies, and validation points easier to monitor between forums.
Appendix
Severity reflects the combination of control weakness, business impact, and urgency of remediation. The overall rating explains the final audit opinion scale used across the report.
Low Severity
Low-severity findings indicate a limited weakness or process maturity gap. They should still be addressed, but they can usually be incorporated into normal improvement cycles.
Medium Severity
Medium-severity findings indicate a meaningful control gap that could become more serious if left unresolved. These items should be remediated in the near term through an owned plan with milestones and oversight.
High Severity
High-severity findings indicate material control weakness or elevated business risk. These items should be remediated urgently and monitored frequently by senior management until validated as closed.
Appendix
The overall rating translates the full control assessment into a four-point opinion scale.