Feedback Is a Gift – Even When It Comes from an External IT Auditor
Engaging external auditors is a strategic decision. These professionals have seen a wide range of organisational setups and understand how things can go wrong—such as when overly broad access rights are exploited, leading to financial or operational losses. Ensure that employees working with auditors recognise that gathering evidence and explaining decisions is a proactive way to prevent future issues.
1. Investigate Auditor Observations Thoroughly
If an auditor flags something suspicious, don’t dismiss it as irrelevant. Instead, dig deeper to uncover the root cause. Could it be due to overlapping access from multiple roles assigned to the same user? Or remnants from past projects or system upgrades? Understanding the origin of the issue is key to resolving it effectively.
2. Define Your Organisation’s Risk Appetite
Once you understand why an issue has been flagged, determine your company’s tolerance for access-related risks. Auditors are not enforcers—they’re advisors. If you acknowledge the risks and accept them, auditors will typically respect that stance.
Where strong compensating controls exist, it may be acceptable for certain individuals to retain elevated access privileges.
3. Take Action on Audit Findings
Start by cleaning up: remove unnecessary critical access. Be careful not to hinder essential business operations or development work—establish and communicate safer alternative processes. Separate system accounts for emergency access are a good example.
Ensure that all users follow clear, detailed instructions. High-level process flows rarely provide sufficient guidance for daily operations. Each organisation should maintain documentation that outlines which actions are permitted and who must approve them. These can take the form of e.g. working instructions, standard operating procedures, or maintenance and operating guides.
4. Trust but Verify
Monitor critical access within your SAP systems throughout the year—not just during annual audits. The goal is to catch small issues before they escalate. Both preventive controls (e.g. access approvals) and detective controls (e.g. regular reviews of access against current responsibilities and processes) are essential for maintaining secure system access.
5. Use the Audit Report as a Strategic Tool
The audit report can be a powerful tool to highlight issues and resource needs to senior management. Avoid downplaying findings by claiming wide access is “as expected.” Instead, welcome the visibility these audit findings bring—they can help justify additional resources for remediation.
Also, request that context be included in the report. While observations are neutral, their interpretation and wording can vary. Ensure auditors acknowledge improvements made during the audit period and avoid portraying isolated issues as systemic failures.
Auditors Are Allies
In conclusion, external auditors are partners—not judges. Collaborate with them, learn from their insights, and take steps to reduce access risks year over year. A proactive approach today leads to fewer findings tomorrow.