Finding · F-IAQ2-CHG-02

Emergency changes without retrospective CAB approval

ClosedCHG-02 · Emergency changes are retrospectively approvedChange ManagementQ2 2026 Unified Program Review
Fraud indicator
Rating
No
High
Medium
Low

Requirement to validation

Observation
Raised 2026-06-20 in the Q2 2026 internal audit baseline. 4 of 11 emergency changes in April-June had no retrospective CAB approval recorded.
Applications: GitHub Enterprise Cloud, ServiceNow ITSM.
Potential risk
The control may not operate consistently, weakening reliance by auditors and the regulator.
Root cause
Emergency label in GitHub was not linked to the ServiceNow CAB record.
Agreed action plan

Remediate: emergency changes without retrospective cab approval.

Management response: Management agreed and committed to remediate before the Q3 review.

Owner (FPR)
Aditya Singh
Target date
31 Jul 2026
Priority
Medium
Status
Closed

Evidence for this control (7)

Open list →
EvidenceTitleControlSource systemCollectedStatus
ITGC-REQ-024ServiceNow: Emergency CRs closed with PIRCHG-025 Oct 2026Rejected
Q2-EV-018GitHub Enterprise Cloud · screenshot (Q2)CHG-02GitHub Enterprise Cloud21 Jun 2026Rejected
Q2-EV-019ServiceNow ITSM · system export (Q2)CHG-02ServiceNow ITSM26 Jun 2026Rejected
RBI-REQ-016GitHub: Bypass merges have retrospective approvalCHG-028 Oct 2026Under review
RBI-REQ-017ServiceNow: Emergency CRs closed with PIRCHG-027 Oct 2026Rejected
SOC2-REQ-022GitHub: Bypass merges have retrospective approvalCHG-028 Oct 2026Accepted
SOC2-REQ-023ServiceNow: Emergency CRs closed with PIRCHG-027 Oct 2026Accepted

Tests of this control (2)

Open list →
TestControlCycleTestedByResultConfidence
TST-SOC2-CHG-02CHG-02 · Emergency changes are retrospectively approvedQ3 2026 Unified Program Review3 Oct 2026Laura Bennett · Kestrel Assurance LLPFailHigh
TST-Q2-CHG-02CHG-02 · Emergency changes are retrospectively approvedQ2 2026 Unified Program Review18 Jun 2026Farah Khan, Vikram Mehta · Meridian Internal AuditFailHigh