Related Posts
Anyone knows how to open a non-profit company?
Additional Posts in Risk Assurance
What makes more money IT Audit or IT GRC?
New to Fishbowl?
Download the Fishbowl app to
unlock all discussions on Fishbowl.
unlock all discussions on Fishbowl.




Both - Or if theres no org chart, validate against job title + inquiry w control owner
This^ and I’d say regardless of what the control owner says, still look at job title and independently think about it that title/role makes sense to have access to that control
We usually see access reviewed by management in an itgc
Mentor
We validate against the most recent HR roster and only go to BPOs with weird access. E.g. if the inventory manager has access to update inventory I'm not gonna ask the director of inventory to validate.
Create excel sheet -> send excel sheet for your contact to fill out -> charge 6 hours