Who can do what
Access, segregation of duties, and privileged users
A structured review of roles, conflicting entitlements, shared IDs, and the privileged accounts that can bypass maker-checker in the TMS.
Typically 2–3 weeks · Information security, internal audit, and treasury heads
Treasury applications concentrate the ability to move cash. Role names inherited from the vendor rarely match the way a Malaysian corporate treasury actually works — especially where a small team covers front, middle, and back office. We map real tasks to real logins and show where one person can create, approve, and release.
Privileged accounts, vendor support IDs, and ‘break-glass’ roles are reviewed with the same seriousness as day-to-day operators. We sample joiners, movers, and leavers to see whether access followed the person or stayed behind on a shared mailbox.
You leave with a conflict register, a recommended role model that fits the size of your team, and a short list of accounts to disable or re-own before the next recertification.
What the work usually includes
- Role-to-task mapping against your SOD matrix
- Identification of conflicting entitlements and compensating controls
- Privileged, generic, and vendor-access review
- Joiner-mover-leaver sample for the last twelve months