Test · TST-RBI-ACC-01
ACC-01 · MFA and SSO enforced for workforce access
PassQ3 2026 Unified Program ReviewTested 3 Oct 2026 by Vikram Mehta, Farah Khan · Meridian Internal Audit (IS Audit cell)
Requirement to validation
Requirement
ISO-A.5.17 · ISO-A.8.5 · ITGC-AM-04 · RBI-ITGRCA-2023-7.1 · SOC2-CC6.1
mapped
Policy
Access Control Policy
pol-access
Control
ACC-01
MFA and SSO enforced for workforce access
Application
Amazon Web Services (ap-south-1) · Microsoft Entra ID · GitHub Enterprise Cloud
mapped
Evidence · Q3
6 items
6 approved · 0 pending · 0 rejected
Test · Q3
Pass
TST-RBI-ACC-01 · High confidence
Finding
None
Action
None
Validation
Not planned
Procedure and result
- Procedure
- Entra conditional access + federation of AWS and GitHub to Entra. Tests: Microsoft Entra ID: Conditional access requires MFA for all users; Amazon Web Services (ap-south-1): AWS IAM Identity Center federated to Entra; GitHub Enterprise Cloud: GitHub org enforces SAML SSO. Frequency continuous.
- Sample
- 2 items sampled (reperformance)
- Expected
- All workforce access to corporate and production systems is authenticated through Microsoft Entra ID SSO with phishing-resistant MFA enforced by conditional access.
- Observed
- Operating effectiveness confirmed for Microsoft Entra ID, AWS, GitHub; no exceptions in 2 sample(s).
- Confidence
- High