Test · TST-ITGC-CHG-03

CHG-03 · Developers have no standing production access; deployments via pipeline only

PassQ3 2026 Unified Program ReviewTested 3 Oct 2026 by Vikram Mehta, Farah Khan · Meridian Internal Audit

Requirement to validation

Procedure and result

Procedure
GitHub environments + OIDC deploy role; IAM permission set design. Tests: GitHub Enterprise Cloud: Production environment requires reviewers; Amazon Web Services (ap-south-1): No developer roles with prod write. Frequency continuous.
Sample
2 items sampled (reperformance)
Expected
Production deployments to AWS run only through the GitHub Actions pipeline with protected environments; developers have no standing write access to production accounts.
Observed
Operating effectiveness confirmed for GitHub, AWS; no exceptions in 2 sample(s).
Confidence
High