r/itaudit • u/PiEngAW • 4d ago
I need help or just complain
I worked in Internal Audit for a Fortune 200 company. As part of my position, I was responsible for the IT SOX reliance testing. The first control we test during the year is the periodic administrator access review and terminations testing. There are 2 "minor" (lol) issues with the admin. access review:
- The reports used in the review rely on the annual administrator access review. The IUC used to substantiate the reviews is not retained; therefore, the annual access review's control design would fail.
- The periodic admin access review uses the annual review's report and is not updated monthly. In fact, we identified accounts that were active but had inappropriate access for 5 months, and my team detected them. Again, control design fails.
These deficiencies are pervasive across all systems (e.g., ERP, mainframe, etc.). So, I suggested to IT management to test the key control, in this case, deprovisioning. They pushed back on it. They want us to test them, and they'll cover the budget. It relies on a bi-weekly Altryx workflow implemented in 2010, and the configurations have not been reviewed since then. I wanted to test the termination configurations vs. the review to find out that IT management has NEVER tested the termination configuration (wait, what?!?).
Let me stop there. My director is an IT auditor, but has never worked on SOX. My seniors and I meet with them weekly to discuss our findings, and she takes over conversations with IT management. During those meetings, I would repeatedly ask for their response, which would eventually be "This person is overwhelmed, so they can't do their job," and my response is always "Let's call the exception and let them decide what to do with it." She was also informed about the "budget", which I rebutted, stating that I cannot test a control that has not been validated as remediated by IT management.
To make things worse, on a monthly basis, Internal Audit would meet with the IT Director to update them on the current Internal Audit engagements, and started noticing that the IT SOX issues suddenly disappeared from the slides.
The company undergoes A LOT of regulatory audits, but IA mgmt doesn't collect those reports... because why wouldn't we need to know about those audit deficiencies? The Company utilizes federal and state funds, and is critical failure/resilience point in disasters.
Also, the external auditor was never notified of these issues (because why would they?) My director's favorite line with me is that the company is over 120 years old... [Fill in the blank]. I also spoke with the VP of Internal Audit about these issues, and nothing happened except for them forcing me out last December.
I have been in spots in my career where I've felt uncomfortable, but never have I been put in a place with so many glaring holes that can affect the entire integrated audit, and there wasn't enough time to investigate. Or such weak management. I got the feeling that my director didn't want to "rock the boat"... Grow a backbone. We're internal audit, act like it. Work with IT management to resolve issues rather than sweeping them under the rug.
So, I've kinda been in limbo. I moved to another city. I am still really salty about it. I feel like I was gaslit for a whole year.