09 May 2026 · 5 min

Reconciling SaaS access logs with written policy

Policy says quarterly access reviews. Logs show orphaned admin seats from a contractor who left in February. Auditors will find both.

Person working on a laptop in a study setting

Fintech stacks lean on SaaS for CRM, support, data warehouses, and deploy tooling. Each tool has its own export format. Written policy rarely lists them all, which is how “complete coverage” claims unravel.

Inventory tools that can move money or customer data

Start with blast radius, not with the IT asset list. If a role can change payouts, view KYC documents, or push production code, it belongs in the access control story even if the license sits under a marketing budget.

Pair each policy statement with an extract recipe

For every claim — joiner provisioning within 24 hours, leaver removal within 48 — store the exact admin path or API call used to evidence it. When the vendor UI changes, update the recipe the same week.

Run a monthly micro-reconcile

Do not wait for the quarterly ceremony. A short monthly compare of privileged roles versus HR status catches drift early. Document exceptions with ticket IDs; that trail becomes your sample-ready population later.

Say when automation is incomplete

If one legacy admin console still needs a manual checklist, write it as a compensating control with an owner. Pretending automation is universal is a faster path to findings than admitting a narrow manual step.

The Access & Change Control short course walks through this loop with critique. See the catalog or contact the desk.