Insights Article: The Identity Risk Series – A Failed Security Audit

SOX compliance and audit risk graphic highlighting privileged access security gaps and executive accountability for internal controls.

For Business Owners, CIOs & CSOs [5-minute read]

A Failed Security Audit

The Security Gaps Your Auditors Will Find First

“You certify your internal controls. Your auditors test your privileged accounts. If they don’t agree, it’s your signature on the line.”

Four times a year, the CEO and CFO of every public company sign a document that most of their IT teams have never read. It is not a press release. It is not a strategic forecast. It is a federal certification, filed with the SEC, that legally attests the company’s internal controls over financial reporting are designed effectively and operating as intended.

It is called a SOX 302 certification. And if it turns out to be wrong, the consequences are not reputational. They are criminal.

The uncomfortable reality is that the most common reason a SOX 302 certification becomes inaccurate is not accounting fraud or financial manipulation. It is something far more mundane: inadequate controls over who has access to your systems, specifically which accounts have privileged access to the financial and operational infrastructure your auditors are assessing.

What You Are Actually Certifying

SOX Section 302 requires your CEO and CFO to certify, in every quarterly and annual SEC filing, that they have personally evaluated the company’s internal controls within the preceding 90 days and that those controls are effective. That certification covers not just financial processes but the entire information technology infrastructure that supports them.

What the CEO and CFO certify every quarter

  • The signing officers are responsible for establishing and maintaining disclosure controls and procedures and have designed such controls to ensure that material information is made known to them.
  • The signing officers have disclosed to the company’s auditors and audit committee any significant deficiencies or material weaknesses in the design or operation of internal controls which could adversely affect the company’s ability to record, process, summarize, and report financial data.
  • The signing officers have indicated whether or not there were significant changes in internal controls that could significantly affect internal controls subsequent to the date of their evaluation.

SOX Section 906 layers criminal enforcement on top of this. An executive who knowingly certifies a false report faces up to $1 million in fines and ten years in prison. An executive who willfully certifies a false report faces up to $5 million in fines and twenty years in prison.

These are not theoretical penalties held in reserve for spectacular fraud cases. The SEC enforces them. And the fastest path to a false certification is signing off on controls that your auditors from Deloitte, PwC, EY, or KPMG, have already flagged as deficient.

What Auditors Are Actually Looking At

When the Big 4 audit your organization, they are not just verifying the numbers in your financial statements. Under SOX Section 404, they are required to assess and attest to the effectiveness of your internal controls over financial reporting. A significant portion of that work focuses on IT General Controls (ITGC), the foundational technology controls that determine whether your financial systems can be trusted to produce accurate, tamper-resistant data.

ITGC’s are not abstract. They are specific, testable, and directly tied to the accounts in your environment that have elevated access to financial systems, databases, ERP platforms, and the infrastructure that supports them.

What Auditors Test Under IT General Controls

Privileged Access Management

Key Question

Can every privileged account be justified?

Auditor Tests
  • Who has administrator-level access to financial systems, ERP platforms, and databases?
  • How is privileged access approved, reviewed, and revoked?
  • Are there privileged accounts with no active owner or business purpose?

User Access Lifecycle

Key Question

Are access rights removed when they should be?

Auditor Tests
  • Are accounts disabled immediately when employees leave?
  • Are contractor and vendor accounts removed at the end of engagements?
  • Are orphaned accounts identified and eliminated?

Periodic Access Reviews

Key Question

Does management regularly certify who has access?

Auditor Tests
  • Are formal access reviews conducted for critical systems?
  • Is there documented evidence the reviews occurred?
  • Can every privileged account still be justified?

Segregation of Duties (SoD)

Key Question

Can one person do too much?

Auditor Tests
  • Can the same user initiate and approve payments?
  • Can developers deploy code directly into production?
  • Are privileged users able to bypass approval controls?

Change Management Controls

Key Question

Are changes properly governed?

Auditor Tests
  • Are system changes tested and approved before deployment?
  • Are all production changes logged?
  • Are developers prevented from approving or deploying their own changes?

Auditor Red Flags

These are among the most common ITGC deficiencies identified during Big 4 audits.

  • Orphaned privileged accounts
  • Excessive administrator rights
  • Missing access reviews
  • Segregation of duties conflicts
  • Weak change management controls

These are not edge cases in an audit. They are the core of every ITGC assessment. And they map almost perfectly to the domains where most organizations have the most exposure: unmanaged privileged accounts, stale access that was never revoked, and service accounts operating with administrator rights that no one is actively monitoring.

When the Auditor Finds What You Missed

Audit findings related to access controls come in two grades, and the distinction between them is critical. A significant deficiency is a control weakness serious enough to merit the attention of those responsible for oversight, it must be disclosed to the audit committee. A material weakness is worse: it represents a reasonable possibility that a material misstatement in the financial statements would not be prevented or detected. A material weakness requires public disclosure in the annual 10-K report, triggers a qualified audit opinion, and remains on the public record until it is remediated and independently verified.

A material weakness disclosure drops stock price by an average of 19% over the following 12 months and increases audit fees by more than 60%.

It also resets the relationship with your auditors, triggers heightened SEC scrutiny, and stays on the public record until remediation is independently verified, a process that can take years.

$1M +10yrs

Knowingly certifying a financial report that does not comply with the requirements of the Securities Exchange Act. This standard applies even when the executive did not intend to deceive — knowing the certification was false is sufficient.

$5M +20yrs

Willfully certifying a false financial report. The SEC can also bar the individual from serving as an officer or director of any public company permanently.

The bridge between these penalties and your IT infrastructure is shorter than most executives realize. A CEO who signs a SOX 302 certification asserting effective internal controls while the company has undiscovered material weaknesses in privileged access governance has signed a document that may not reflect reality. If the auditors find it first, the consequence is a public disclosure. If a breach exposes it, the consequence may be significantly worse.

The auditors are not looking for problems in the abstract. They are testing specific controls. Privileged access governance is one of the first things they test, and one of the most common places they find deficiencies.

The Auditor’s View of Privileged Access

From an auditor’s perspective, privileged accounts represent concentrated risk. A single administrator account can read, modify, or delete financial data, potentially without leaving a detectable trace if logging is inadequate. An account that can both initiate and approve transactions is a segregation of duties failure. A former employee’s account that was never deprovisioned remains an open door into systems the company has certified as properly controlled.

These are not theoretical risks. Auditors test them directly. They review user access lists, compare them to HR records, identify accounts with unjustified elevated privileges, and verify that access reviews have been completed and documented. When they find gaps, the path from an audit finding to a material weakness disclosure and ultimately a public 10-K filing can be remarkably short.

Every privileged account that cannot be justified, every access right that was never revoked, every service account with administrator privileges that no one is monitoring, these are the findings that become disclosures, that become stock price events, that become the reason the CEO and CFO are explaining to the audit committee why their certification was premature.

The organizations that navigate audit cycles cleanly are not those with perfect environments. They are those with clear visibility into their privileged access landscape, including who has what, why they have it, when it was last reviewed, and what controls govern its use. That visibility is precisely what auditors are looking for. And it is precisely what the gap analysis was designed to surface.

Do You Know Your Blast Radius?

The auditors will find what you haven’t looked for, the question is whether you find it first. Take our Ransomware & Data Breach Gap Analysis below, a structured assessment that identifies the privileged access exposures in your environment most likely to be exploited, and shows you exactly how much risk you are carrying right now.

Security Assessment

How Exposed Is
Your Company?

Uncover hidden risks across privileged accounts, credentials, vendor access, MFA, session monitoring, and compliance controls. Take our 5 minute Gap Assessment to see where your biggest security gaps may be hiding.

Start Free Assessment →

5 MinutesQuick & Easy
14 Critical AreasComprehensive Coverage
Instant ResultsKnow Your Risks
Stronger SecurityBetter Protection