Q3 2026
As of 9 Oct 2026
As of 9 Oct 2026
Control exceptions
8
▼ -38% (-5) vs Q2 2026
Failed control tests fell from 13 in Q2 2026 to 8 in Q3 2026.
Investigate →Control exceptions by control
failed tests · Q3 2026
ACC-03 · Privileged access is just-in-time and reviewed1(1)P2P-01 · Purchase orders follow approval thresholds; no self-approval1(1)SOD-01 · Segregation of incompatible duties in SAP1(1)VEN-01 · Critical third parties are risk-assessed before onboarding and annually1(1)CHG-02 · Emergency changes are retrospectively approved1(1)JML-02 · Mover access is recertified on role change1(0)KYC-01 · Customer accounts are activated only with complete KYC1(0)VEN-03 · Supplier security incidents are assessed for impact and tracked1(0)ACC-02 · User access provisioning is approved before grant0(1)ACC-04 · Quarterly user access review of in-scope applications0(1)CHG-01 · Production code changes are peer-reviewed and approved0(1)CHG-03 · Developers have no standing production access; deployments via pipeline only0(1)LOG-01 · Security events are centrally logged and monitored 24x70(1)OPS-01 · Backups are performed daily and monitored0(1)PAY-01 · Payment APIs secured with mTLS, signing and customer 2FA0(1)VUL-01 · Vulnerabilities are scanned and remediated within SLA0(1)
- ACC-03 · Privileged access is just-in-time and reviewed 1 13%
- P2P-01 · Purchase orders follow approval thresholds; no self-approval 1 13%
- SOD-01 · Segregation of incompatible duties in SAP 1 13%
- VEN-01 · Critical third parties are risk-assessed before onboarding and annually 1 13%
- CHG-02 · Emergency changes are retrospectively approved 1 13%
- Other (11) 3 38%
Control risk level by test result
Fail
Pass with observation
Pass
High risk
Medium risk
Low risk
Click a cell to list its controls. Risk level is the control's recorded rating; result is the current-period test.