Finding · F-IAQ2-ACC-04

Salesforce user access review not completed

ClosedACC-04 · Quarterly user access review of in-scope applicationsAccess ControlQ2 2026 Unified Program Review
Fraud indicator
Rating
No
High
Medium
Low

Requirement to validation

Observation
Raised 2026-06-20 in the Q2 2026 internal audit baseline. The Q1 user access review for Salesforce, including Northstar BPO accounts, was not signed off by the application owner.
Applications: Microsoft Entra ID, Salesforce (Sales + Financial Services Cloud), SAP S/4HANA.
Potential risk
The control may not operate consistently, weakening reliance by auditors and the regulator.
Root cause
Review ownership unclear after the Operations reorganisation.
Agreed action plan

Remediate: salesforce user access review not completed.

Management response: Management agreed and committed to remediate before the Q3 review.

Owner (FPR)
Ananya Rao
Target date
31 Jul 2026
Priority
Medium
Status
Closed

Evidence for this control (7)

Open list →
EvidenceTitleControlSource systemCollectedStatus
ITGC-REQ-007SAP S/4HANA: Q3 SAP access review signed offACC-04SAP S/4HANA7 Oct 2026Under review
ITGC-REQ-008Salesforce: Q3 Salesforce access review signed offACC-046 Oct 2026Under review
ITGC-REQ-009Microsoft Entra ID: Entra access review campaign statusACC-04Microsoft Entra ID5 Oct 2026Under review
Q2-EV-007SAP S/4HANA · policy document (Q2)ACC-04SAP S/4HANA14 Jun 2026Rejected
Q2-EV-008Salesforce (Sales + Financial Services Cloud) · screenshot (Q2)ACC-04Salesforce (Sales + Financial Services Cloud)19 Jun 2026Rejected
SOC2-REQ-010SAP S/4HANA: Q3 SAP access review signed offACC-04SAP S/4HANA6 Oct 2026Under review
SOC2-REQ-011Salesforce: Q3 Salesforce access review signed offACC-045 Oct 2026Under review

Tests of this control (1)

Open list →
TestControlCycleTestedByResultConfidence
TST-Q2-ACC-04ACC-04 · Quarterly user access review of in-scope applicationsQ2 2026 Unified Program Review18 Jun 2026Farah Khan, Vikram Mehta · Meridian Internal AuditFailMedium