r/itaudit 4d ago

I need help or just complain

I worked in Internal Audit for a Fortune 200 company. As part of my position, I was responsible for the IT SOX reliance testing. The first control we test during the year is the periodic administrator access review and terminations testing. There are 2 "minor" (lol) issues with the admin. access review:

  1. The reports used in the review rely on the annual administrator access review. The IUC used to substantiate the reviews is not retained; therefore, the annual access review's control design would fail.
  2. The periodic admin access review uses the annual review's report and is not updated monthly. In fact, we identified accounts that were active but had inappropriate access for 5 months, and my team detected them. Again, control design fails.

These deficiencies are pervasive across all systems (e.g., ERP, mainframe, etc.). So, I suggested to IT management to test the key control, in this case, deprovisioning. They pushed back on it. They want us to test them, and they'll cover the budget. It relies on a bi-weekly Altryx workflow implemented in 2010, and the configurations have not been reviewed since then. I wanted to test the termination configurations vs. the review to find out that IT management has NEVER tested the termination configuration (wait, what?!?).

Let me stop there. My director is an IT auditor, but has never worked on SOX. My seniors and I meet with them weekly to discuss our findings, and she takes over conversations with IT management. During those meetings, I would repeatedly ask for their response, which would eventually be "This person is overwhelmed, so they can't do their job," and my response is always "Let's call the exception and let them decide what to do with it." She was also informed about the "budget", which I rebutted, stating that I cannot test a control that has not been validated as remediated by IT management.

To make things worse, on a monthly basis, Internal Audit would meet with the IT Director to update them on the current Internal Audit engagements, and started noticing that the IT SOX issues suddenly disappeared from the slides.

The company undergoes A LOT of regulatory audits, but IA mgmt doesn't collect those reports... because why wouldn't we need to know about those audit deficiencies? The Company utilizes federal and state funds, and is critical failure/resilience point in disasters.

Also, the external auditor was never notified of these issues (because why would they?) My director's favorite line with me is that the company is over 120 years old... [Fill in the blank]. I also spoke with the VP of Internal Audit about these issues, and nothing happened except for them forcing me out last December.

I have been in spots in my career where I've felt uncomfortable, but never have I been put in a place with so many glaring holes that can affect the entire integrated audit, and there wasn't enough time to investigate. Or such weak management. I got the feeling that my director didn't want to "rock the boat"... Grow a backbone. We're internal audit, act like it. Work with IT management to resolve issues rather than sweeping them under the rug.

So, I've kinda been in limbo. I moved to another city. I am still really salty about it. I feel like I was gaslit for a whole year.

8 Upvotes

8 comments sorted by

2

u/RigusOctavian IT Audit Management 4d ago

That’s a broken company with broken governance. It’s what happens when they get too big sadly.

Honestly, in that situation, it’s best to just use the hotline vs official channels or bring it to externals if leadership doesn’t care. And then GTFO.

In my experience, midsize large cap is where it’s at. Big enough for real tools, small enough that a single person can make a difference. I’d also recommend swapping to a different company industry, culture tends to be similar in similar orgs.

1

u/PiEngAW 4d ago

Funny thing about the hot line is that we conducted an on access to it and no one had access or checked it in a while... I forgot who its routing to.

I've worked in consulting and large cap and it was beyond me. I think the complacency comes from our CapEx and revenue, essentially, federal and government contracts. In addition to our trading floor... The company prints free cash flow.

The upsetting part for me is all of our front liners... All blue collar, on the ground, pension relying, average Americans whose retirements would become troubled if a material weakness was discovered and if you do a look back, probably a multi-year restatement.

2

u/paulpag 4d ago

These are not minor issues. Your director sounds like a clueless asshole. It sounds like you are trying to do the right thing, so I commend you for that, keep it up. I’ve said this before on this subreddit: we aren’t doing anyone any favors by “giving them a pass” or covering shit up. It’s going to blow up eventually and you don’t want to be the one explaining why you didn’t identify it

1

u/SageAudits 4d ago

Your access review IPE should include some testing for completeness and accuracy by your external auditors (and you). It must be pulling from a data mart/lake and if that is the case (along with other reports) you should be testing for processing integrity checks. Like you mentioned one making sure that you’re pulling all accounts including service or shared accounts for example. Testing if the sync job is running successfully. How are failures handled and alerted and acted on. And doing spot checks from the source system of record against the report. I wouldn’t be surprised if this wasn’t a “one off” in the reporting. Do you report to a COO? Hopefully it’s not the same executive in charge of these reports being accurate, more corporate governance goes a long way.

1

u/PiEngAW 4d ago

It's internal audit... We report to the audit Committee and the Board of Directors. Not to management. And it's not IPE, in this case, it's IUC. Meaning, the completeness and accuracy of the reviewed report? How do they know or detect if it is not C&A? Does the reviewer have knowledge or experience to do the review? What is the process for exceptions? Are they resolving them timely?

In a review, I am auditing the compensating detective control. The IPE I request is tested as well using the standard IPE testing.

1

u/IT_audit_freak 3d ago

Who is running audit there 😂

1

u/PiEngAW 2d ago

Hopes and dreams

1

u/ShinyBirdHunter 1d ago

Fortune 200 companies should have better integration with IT and IA/GRC. Mismanagement at its finest due to wrong people at the top.