Internal Audit Report

Identity & access governance audit report

This mock internal audit report demonstrates how a formal audit outcome can be presented in the same dynamic dashboard language as the other projects in my portfolio. The audit focuses on access governance, privileged control discipline, and evidence quality across an expanding platform environment. This page keeps the formal structure of an audit report while presenting it in the same dashboard-led visual style as the internal audit and ratio monitoring examples.

Please note that this is a mock report and does not reflect any actual audit outcome.

Report Metadata

Report Date

7 July 2026

Author

Internal Audit, Digital Risk & Assurance

Engagement

Q2 2026 Internal Audit Cycle

Audit findings5
Process improvements2
High-severity items2
Overall ratingNeeds Improvement

Management Summary

Control themes, severity mix, and management response

The audit identified a functioning but uneven control environment. Core governance mechanisms exist, but several important controls are not operating consistently enough for a scaled platform organization. Two high-severity findings require near-term remediation, supported by management commitments and named ownership. Medium- and low-severity findings indicate process maturity gaps that should be addressed through structured remediation planning and improved control evidence discipline.

Overall Rating

Needs Improvement

2

Control design and operation are broadly adequate, but important weaknesses exist that require management attention and structured remediation.

Severity Mix

Findings by severity

High2
Medium2
Low1

Finding Summaries

Management Response

Accepted with phased remediation

Management accepted all findings. Executive sponsors requested accelerated closure of the high-severity items, monthly progress review for medium-severity items, and incorporation of low-severity actions into the next governance improvement cycle.

Audit Findings

Detailed observations and linked management actions

Each finding uses the standard audit flow: condition, criteria, cause, effect or risk, evidence, recommendation, and management action plan. Recommendations scale in urgency to the severity assigned.

IA-01

Privileged Access Reviews Are Not Performed Consistently

High
Condition

Quarterly recertification of administrator-level access was incomplete in three of the last four review periods. Several privileged groups contained members whose current business need could not be evidenced during testing.

Criteria

Privileged access should be reviewed on a defined cadence, approved by accountable system owners, and supported by retained evidence for each certification decision.

Cause

The recertification process is distributed across multiple teams without a single operational owner, and reminder-based execution has not scaled with organizational growth.

Effect / Risk

Excess or stale privileged access increases the risk of unauthorized changes, inappropriate data access, and weaker containment if an account is compromised.

Evidence / Examples

Testing identified two transferred engineering managers who retained production administrator access beyond 60 days, plus one shared escalation group that contained four members without recorded reapproval.

Internal Audit Recommendation

Implement an enforced privileged access recertification workflow within 30 days, including automatic escalation for overdue approvals. Because this is high severity, remediation should be treated as urgent and tracked weekly to closure.

Management ownerSecurity Engineering
Target date15 August 2026
Management Action Plan

Security Engineering will centralize recertification in the identity platform, assign owners for each privileged group, and complete a full catch-up review cycle.

IA-02

Emergency Break-Glass Accounts Lack Sufficient Oversight

High
Condition

Break-glass accounts existed for production continuity, but real-time alerting, post-use review steps, and evidence of monthly readiness checks were not consistently available.

Criteria

Emergency access accounts should be tightly controlled, continuously monitored, and subject to documented post-use validation following every activation.

Cause

The control relies on manual checklists, and ownership between incident response and identity administration has not been clearly operationalized.

Effect / Risk

Improperly governed emergency accounts can enable privileged activity to occur without timely detection during high-pressure incidents.

Evidence / Examples

One break-glass account had no documented readiness test for the previous two months, while another routed alerts to a deprecated incident channel.

Internal Audit Recommendation

Automate break-glass alerting within 14 days and require documented post-use review within one business day of every activation. High-severity remediation should be completed on an urgent basis and validated by control testing before closure.

Management ownerPlatform Operations
Target date31 July 2026
Management Action Plan

Platform Operations and Corporate Security will reconfigure account monitoring, reroute alerts, and introduce a standard post-incident evidence template.

IA-03

Joiner, Mover, Leaver Workflows Contain Delays for Internal Transfers

Medium
Condition

Access updates for employees changing teams were not consistently completed within the expected turnaround. Sampled users retained prior access for several days after approved role changes.

Criteria

Access provisioning and deprovisioning should align promptly with approved organizational changes so users retain only the access required for current duties.

Cause

The HR change workflow functions correctly, but downstream access tasks span several systems and still depend on manual reconciliation.

Effect / Risk

Delayed entitlement updates can create conflicting access, increase segregation-of-duties concerns, and slow onboarding into the new role.

Evidence / Examples

Four of twelve sampled internal transfers showed lingering access for between three and six days, most frequently in support tooling and deployment consoles.

Internal Audit Recommendation

Introduce a unified transfer checklist and automated exception reporting within 60 days. Medium-severity findings should be remediated in the near term with monthly management visibility until the control operates consistently.

Management ownerIT Operations
Target date30 September 2026
Management Action Plan

IT Operations will pilot transfer exception reporting and work with HR Systems to automate reconciliation for high-volume moves.

IA-04

Service Account Ownership Records Are Incomplete

Medium
Condition

A subset of non-human accounts used for integrations and scheduled jobs did not have a clearly recorded business owner or technical custodian in the central register.

Criteria

All service accounts should have named ownership, documented purpose, and periodic review to confirm necessity and privilege appropriateness.

Cause

Service account creation has historically been embedded in project delivery workflows, while the central ownership inventory was introduced later and is still partially adopted.

Effect / Risk

Unowned service accounts can persist longer than required, complicate incident response, and weaken accountability over privileged automation paths.

Evidence / Examples

Nine of forty-one sampled service accounts lacked an owner field, and three had descriptions too generic to identify the underlying integration or business process.

Internal Audit Recommendation

Complete the service account inventory and ownership attestation within 90 days, beginning with production-connected integrations first. Medium-severity remediation should follow a scheduled plan with milestones and periodic oversight.

Management ownerInfrastructure Engineering
Target date15 October 2026
Management Action Plan

Infrastructure Engineering will reconcile the account inventory against active integrations and obtain owner attestations through the quarterly control forum.

IA-05

Access Review Evidence Is Stored Inconsistently Across Teams

Low
Condition

Standard access reviews were generally performed, but evidence was retained in different formats and locations, making independent validation slower than necessary.

Criteria

Control evidence should be stored in a consistent, accessible format so control operation can be demonstrated efficiently and repeatedly.

Cause

Teams have been allowed discretion over how they retain support for their reviews, and no single evidence template has been mandated.

Effect / Risk

The issue does not immediately weaken access controls, but it increases audit effort and reduces the speed of future management attestations.

Evidence / Examples

Evidence was spread across chat exports, spreadsheets, ticket comments, and screenshots without a single indexed record for final approvals.

Internal Audit Recommendation

Adopt a standard evidence template and common repository model during the next review cycle. Low-severity items can be addressed through routine process improvement alongside adjacent governance enhancements.

Management ownerGovernance Team
Target date1 October 2026
Management Action Plan

The Governance team will publish an evidence standard and establish a shared filing convention ahead of the next quarterly access review window.

Process Improvements

Advisory actions to improve the audit lifecycle

These are lower-intensity improvement opportunities and intentionally do not carry a formal management response.

PI-01

Create a Reusable Audit Request Pack

Evidence collection required repeated clarification because control owners submitted similar materials in different formats. A reusable request pack would reduce friction for both audit and management.

BenefitImproves consistency, reduces prep time, and shortens the first-round evidence cycle.

PI-02

Introduce a Live Remediation Dashboard

Management actions are currently monitored through static updates and steering meetings. A live dashboard would make remediation status, dependencies, and validation points easier to monitor between forums.

BenefitIncreases transparency, supports earlier escalation, and gives executives a cleaner view of progress.

Appendix

Severity and overall rating guides

Severity reflects the combination of control weakness, business impact, and urgency of remediation. The overall rating explains the final audit opinion scale used across the report.

Low Severity

What this means

Low

Low-severity findings indicate a limited weakness or process maturity gap. They should still be addressed, but they can usually be incorporated into normal improvement cycles.

Medium Severity

What this means

Medium

Medium-severity findings indicate a meaningful control gap that could become more serious if left unresolved. These items should be remediated in the near term through an owned plan with milestones and oversight.

High Severity

What this means

High

High-severity findings indicate material control weakness or elevated business risk. These items should be remediated urgently and monitored frequently by senior management until validated as closed.

Appendix

Overall rating system

The overall rating translates the full control assessment into a four-point opinion scale.

Rating 1

Satisfactory

1

Controls are generally well designed and operating effectively. Only minor issues were identified, and any improvement opportunities are limited in impact and can usually be addressed through routine management action without heightened oversight.

Rating 2

Needs Improvement

2

Control design and/or operation is broadly adequate, but some weaknesses exist that require management attention. The control environment remains workable overall, although remediation is needed to prevent these gaps from becoming more significant over time.

Rating 3

Unsatisfactory

3

Significant control weaknesses exist. The control environment is not consistently effective and exposes the business to material risk, meaning management should prioritize corrective action and maintain active oversight until improvements are embedded.

Rating 4

Critical / Inadequate

4

Severe or pervasive control failures exist. Immediate management attention is required due to high risk exposure, regulatory impact, financial impact, or potential operational disruption, and urgent intervention is expected to stabilize the control environment.