This is a dumb question but when can I opine on a user listing and say it’s generated completely and accurately? Like for privileged access. Or can I only say the listing is complete?

like
Posting as :
works at
You are currently posting as works at

I would recommend you ask your senior or any superior on the engagement instead of here. There are ways to say it’s both complete and accurate depending on how the listing is pulled, whether from a DB or an export from the application

like

Why do people use “listing” instead of “list” or “population”?

likefunny

You should be able to say there is reasonable assurance that a population is complete and accurate. By inquiring of the evidence owner regarding how the population was generated, understanding what the population is and how it is generated, seeing screenshots of the process for creating the population if there isn’t necessarily a way to see the underlying code used to create the population (often happens with OTS software), and fully understanding what types of filters were applied to help ensure that the population has not omitted relevant items. These will widely vary depending on the data source, but if you can get a good grasp on how the population was generated, you should be able to say there is reasonable assurance that the population is complete and accurate. We do not opine that a population is 100% complete and accurate without a doubt because there is always a chance something could have been omitted, something may have been withheld, etc., we only say there is reasonable assurance that it is complete and accurate.

like

As a part of administrator testing, yes you would do this. With the system admins having the highest level of access, you want to make sure 1) they are an active employee, and 2) they are authorized to have that access. I have seen people in the past check the employee HR data provided by a client to see if each employee associated with an admin account has a job title that is commensurate with needing admin access, but at the end of the day the system owner is the one who determines who is authorized to have that access. Once I confirm they are all active employees (or authorized service accounts), I then check with the system owner so that I have explicit confirmation that the listed users are authorized for access. We as external auditors can’t judge the “appropriateness” of the access, only that it is authorized and not accessible by terminated/unauthorized users.

Probably should have observed management generating it

I have a generation/parameter screenshot

How was it generated? Query? Export button? Does screenshot include line item total? Can you tie back listing to screenshot?

Answer those and you are good

like

Related Posts

Going to Jamaica for a bachelor party Memorial Day Weekend...da hell do I wear?

How common is it for a firm to contribute to an HSA on an employee’s behalf, and what is the largest contribution you’ve seen that an employer gives?

like

I see some tweets started stating #GreatResignation will lead to #GreatLayoff. I am aware that skill plays a vital role and up skilling saves. Still what would be the worse impact these trend can cause in near future. Would like to get some views from Fishes.

like

Hi folks, anyone interested in creating a healthy sleep/wake schedule? I’m targeting to achieve and maintain a 10pm/5am sleep/wake schedule on the weekdays. I wonder if we can get this started, and check in to support and make it happen!

like

What’s an Engagement Manager?

like

Buying a new construction single fam house in PA suburbs. Already Signed the contract and Looking for a lender with lower interest rate. Anyone come across comparable lower IR lenders? Any insight is appreciated! :)

like

Trying to do some initial research on laptops for business school and trying to determine if a new Mac book pro could be used at Wharton (or honestly any school!) for finance (not quant finance major though!)

like

Hi fishes, I have a few questions about employment with Nokia for the role of Senior data analyst.
1. How is the company in terms of growth and learnings, for data analysts?
2. How much shall I expect in terms of salary and benefits?
3. How about work culture and wlb?

I have 12 YOE

like

Hi , Can anyone explain about level 4 in A& E and the kind of responsibilities , future growth?

like

Anybody have experience with giving their notice couple of weeks before annual bonus payout? Should you wait to give notice until the day you receive pay?

like

McKinsey & Company I am a senior graduating soon with a technical masters (accelerated program) from an Ivy League. I have an offer for Facebook TPM and McKinsey & Company BA. McK first year TC is 75k less. Will McK increase the offer? If so, how much?

Any thoughts on FB vs McK?

like

Hello All

How's job security, work life balance, work pressure, work environment & Salesforce testing projects at Brillio?

like

Hi,
I have a couple of questions -
1. What is the average bonus pay for WM division ? I asked HR and he did not quote any range.
2. How long it takes to promote to 602 given an average to above average performer.
Thanks

like

Why do people burn out those who are willing to work hard for them

like

Hi BCG fish! I just signed my offer letter to join starting next year in Brazil. Any tips on how to prepare? And who makes staffing decisions? I want to start networking with people globally to help me get staffed on projects related to my industries of interest.

like

Does citi accept counter offer after releasing the offer letter?

like

State bar fees while you’re clerking? Please tell it doesn’t just come out of your own pocket during the two years? 😭

like

So BLKJ have weak knees and sold out to Havas....Always knew that an agency could be bought to provide them with an excuse to be mediocre. It hardly ends well.....

like

Hi Fishes,
What should be the salary for Manager / Sr Manager having 14+ yoe in project/product service operations? I am at 32 lpa which I think is quite low having worked with top consulting firms for close to 12 years.

like

The prices on apts right now is crazy - any tips for good finds?? Need to move to NYC in 2 months

like

Additional Posts in Risk Assurance

Has an tested roles for SAP through productive test simulation within production? Is there any risk doing this as the test is in production?

like

Are the exit opportunities better in Internal Audit/Business Process than IT Audit? All I hear is how awful IT Audit is but don’t hear as much complaining from the business side

like

If anyone is looking for a referral as an experienced hire to the PwC DAT (Digital Assurance & Transparency - formerly Risk Assurance) practice let me know and would be happy to refer you. We are actively looking to hire.

like

Currently in Risk Assurance but have the opportunity to transfer into Deals & Strategy. Which one is better for a career long term?

like

Does business Process Internal Audit or IT Internal Audit make more?

like

What aspects would you look at when interviewing a person for a Manager position?

like

Anyone hiring for entry level risk compliance roles?

like

Im looking at new job opportunities out side of PA but struggle to confidently answer how much I’m looking to be paid. I’m so worried of over asking or leaving money in the table.
I’m in a SoCal HCOL and have been asking for 100k for Senior Internal Audit Roles (2 years) and working on my CiSa.
Is that too optimistic?

like

Does Deloitte and PWC has a dedicated app sec pen-test team? What percent of the time do you travel? Do you guys work from home or need relocation to any place in US?

like

I have an interview coming up for internal audit manager. Currently in external audit. When asked about my experience in ERM - what would you say Is transferable skills that I can leverage in my answer?

like

Any strong performing seniors looking for a pay increase and potential fast track to manager? Reach out to me. Expanding the team and would love to bring in some new talent.

like

Should I take this offer in a second line role with similar bad WLB as public? Current salary: 155k base, 8k annual bonus (7YOE):

Offer:
170 base
17k sign on
25,500 (15% annual bonus)
28k annual RSUs (vest quarterly)

like

Mid year promotions, I found out you need to make your own case for it rather than the firm coming to you. If you think you’re ready make sure you speak up!

I'm a Tech Risk SC, but have an accounting/finance background. I'm doing the FRM now for broader cert experience, is it worth doing CA long term in my area?

Does anyone still have an active Becker account that I could borrow for 2 months to study for my REG exam? Please! Thanks!

like

What’s it mean if your boss tells you to start looking for a new job? What would be your first step?

like

How does IT SOX audit in industry usually do during recessions?

likehelpful

Tried to jump to a big 4 as a senior 2 in risk assurance . SF market - offered 93k base and 15k bonus. Is this worth?

London, Dublin, Luxembourg, Munich. Choose a place to move to from NYC. Fuck H1B.

New to Fishbowl?

Download the Fishbowl app to
unlock all discussions on Fishbowl.
That was just a preview…
Sign Up to see all discussions
  • Discover what it’s like to work at companies from real professionals
  • Get candid advice from people in your field in a safe space
  • Chat and network with other professionals in your field
Sign up in seconds to unlock all discussions on Fishbowl.

Already a user?
Login here

Share

Embed this post

Copy and paste embed code on your site

Preview

Download the
Fishbowl app

See what’s happening in your industry
from the palm of your hand.

A phone with Fishbowl app

Scan your QR code to download
Fishbowl app on your mobile

Download app

Sign up for free to view this conversation on Fishbowl

By continuing you agree to Terms of Use and Privacy Policy

Already have an account? Log in

Sign up for free to continue using Fishbowl

By continuing you agree to Terms of Use(New) and Privacy Policy(New)
Messaging rates may apply

Already have an account? Log in

For account settings, visit Fishbowl on Desktop Browser or

General

Legal