Signify Insights
DiscoverSignify PlaygroundSignify FieldworkSignify LabsSignify KidsSpotlightsAboutSignify SolutionSignify HiveSignify Impact
Signify Playground
A publishing & interactive-learning property · Philadelphia · est. 2019
Signify PlaygroundDrillInternal Audit · Issue rating7 minLevel 3
DrillIssue rating · Internal Audit

Rate the Issue

Fifteen findings to rate by exposure rather than by irritation. Four of them cannot be rated at all on what you are given — and a number invented to fill the column is what stops anyone believing the rest.

~7 min · Scored · Per-item recap · No sign-up

1. A shared administrator account on the payments platform is used by four people. Its password has not changed in two years and two of the four have left.

2. The disaster recovery plan names a recovery point objective of four hours. Backups run nightly. This has never been tested.

3. A control procedure document has not been reviewed since 2023. The control operates correctly and the procedure still describes it accurately.

4. Three of twenty-five purchase orders sampled were approved by someone outside the delegation matrix. All three were under £1,000.

5. The vendor onboarding form does not capture ultimate beneficial ownership.

6. An internal application stores personal data. The team could not tell us which fields or how many records.

7. User access reviews for the HR system were not performed for two of the four quarters. The system holds payroll data for 4,000 staff.

8. A batch job failure alert routes to a mailbox nobody monitors. The job has not failed in eighteen months.

9. Segregation of duties is not enforced in the finance system: the same role can create and approve a payment. Compensating detective review exists and was evidenced as operating.

10. The IT change policy has no rollback requirement. Changes are deployed weekly; the team could not say how many were rolled back last year.

11. Two former contractors retain active VPN accounts. Both accounts show no authentication attempts since their end dates fourteen months ago.

12. Petty cash counts are performed monthly by the person who holds the float.

13. The organisation has no formal risk appetite statement.

14. A firewall rule permits inbound traffic from any source to a test server. The test server sits on the same flat network as production.

15. Quarterly access recertification completed nine days after the deadline.

0%

Educational. Rating scales differ by function; what transfers is rating against exposure you can evidence, and being willing to record that a finding cannot be sized yet rather than defaulting to the middle.