Field notes

What inspectors ask first about access reviews

Security badge and access card on a wooden desk

When a fintech audit or inspection opens, privileged access is rarely left for later. Reviewers want to know who can move money, change customer status, or alter fee logic — and whether those rights were reviewed on a calendar someone can show.

Start with the list that matters

A complete directory dump is less useful than a curated list of roles that can approve payouts, override limits, or deploy payment code. Map each role to a named owner. If ownership sits with “the ops team,” rewrite it before anyone asks.

Evidence that survives questioning

Screenshots of a tick-box are fragile. Prefer exportable review logs with timestamps, reviewer identity, and the decision for each account. When someone left mid-quarter, show the offboarding ticket beside the access removal — inspectors notice when dates diverge.

Common stumble in Taiwan filings

Teams often review access for the customer-facing admin console but forget vendor consoles and shared cloud projects. During our Fintech Controls Audit engagements, those secondary surfaces produce a large share of medium-severity findings.

Keep the review calendar visible to compliance and engineering. An annual ritual that only one person remembers will not hold when that person is on leave during fieldwork week.