Control · ACC-04
Quarterly user access review of in-scope applications
Access ControlSOC 2 · ISO 27001 · ITGC · RBIRisk High
Requirement to validation
Requirement
ISO-A.5.18 · ITGC-AM-03 · RBI-ITGRCA-2023-7.1 · SOC2-CC6.2 · SOC2-CC6.3
mapped
Policy
Access Control Policy
pol-access
Control
ACC-04
Quarterly user access review of in-scope applications
Application
Microsoft Entra ID · Salesforce (Sales + Financial Services Cloud) · SAP S/4HANA
mapped
Evidence · Q3
5 items
0 approved · 5 pending · 0 rejected
Test · Q3
Not tested
Finding
F-IAQ2-ACC-04 · Medium
Closed
Action
Ananya Rao
REM-F-IAQ2-ACC-04 · Closed
Validation
Pending
as recorded
What should be true
Application owners review all user and privileged access to SAP, Salesforce, AWS, GitHub and the Customer Portal admin console quarterly (privileged monthly); removals are completed within 10 business days.
- Requirements
- ISO-A.5.18 A.5.18 · Access rightsITGC-AM-03 ITGC-AM-03 · Periodic user access review of financially significant applicationsRBI-ITGRCA-2023-7.1 RBI-ITGRCA-2023 §7.1 · Access control — least privilege, privileged access management, periodic review (RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices, 2023)SOC2-CC6.2 CC6.2 · User registration and authorization prior to issuing credentialsSOC2-CC6.3 CC6.3 · Role-based access, least privilege and segregation of duties; access modification and removal
- Third parties
- Northstar BPO Services Ltd.
- Testing procedure
- Entra ID Access Reviews for SSO apps; SAP and Salesforce review via Prismet form evidence. Tests: SAP S/4HANA: Q3 SAP access review signed off; Salesforce (Sales + Financial Services Cloud): Q3 Salesforce access review signed off; Microsoft Entra ID: Entra access review campaign status. Frequency quarterly.
Findings (1)
| Finding | Observation | Control | Applications | Severity | Status | Owner | Action | Validation |
|---|---|---|---|---|---|---|---|---|
| F-IAQ2-ACC-04 | Salesforce user access review not completed | ACC-04 | Microsoft Entra ID, Salesforce (Sales + Financial Services Cloud), SAP S/4HANA | Medium | Closed | Ananya Rao | REM-F-IAQ2-ACC-04 · Closed | Pending |
Evidence (7)
| Evidence | Title | Control | Source system | Collected | Status |
|---|---|---|---|---|---|
| ITGC-REQ-007 | SAP S/4HANA: Q3 SAP access review signed off | ACC-04 | SAP S/4HANA | 7 Oct 2026 | Under review |
| ITGC-REQ-008 | Salesforce: Q3 Salesforce access review signed off | ACC-04 | 6 Oct 2026 | Under review | |
| ITGC-REQ-009 | Microsoft Entra ID: Entra access review campaign status | ACC-04 | Microsoft Entra ID | 5 Oct 2026 | Under review |
| Q2-EV-007 | SAP S/4HANA · policy document (Q2) | ACC-04 | SAP S/4HANA | 14 Jun 2026 | Rejected |
| Q2-EV-008 | Salesforce (Sales + Financial Services Cloud) · screenshot (Q2) | ACC-04 | Salesforce (Sales + Financial Services Cloud) | 19 Jun 2026 | Rejected |
| SOC2-REQ-010 | SAP S/4HANA: Q3 SAP access review signed off | ACC-04 | SAP S/4HANA | 6 Oct 2026 | Under review |
| SOC2-REQ-011 | Salesforce: Q3 Salesforce access review signed off | ACC-04 | 5 Oct 2026 | Under review |
Tests (1)
| Test | Control | Cycle | Tested | By | Result | Confidence |
|---|---|---|---|---|---|---|
| TST-Q2-ACC-04 | ACC-04 · Quarterly user access review of in-scope applications | Q2 2026 Unified Program Review | 18 Jun 2026 | Farah Khan, Vikram Mehta · Meridian Internal Audit | Fail | Medium |