Audit Evidence Review

Difficulty: Advanced · Track: GRC

Test a control against real evidence, decide pass or fail, and assign a finding severity.

Context

You're running a mock internal audit of the access-revocation control from the Policy Gap Analysis challenge. You've been handed an offboarding log for one terminated employee. This is what auditors actually do: test a control against evidence, not just read the policy.

Task

  1. Read the offboarding log and severity rubric below (static, safe example).
  2. Decide whether the control passed or failed against the 5-day policy requirement.
  3. Calculate how late the revocation was, and assign the correct finding severity.

Audit Evidence

Answers are directly copy-pasteable or calculable from this block.

Note: Educational example — employee name and dates are fictional.

Capture the Flags

Copy or calculate each answer from the evidence above. Case-insensitive.

0/3 flags captured

Flag 1 — Does this control pass or fail?

Question: Compare the dates against the 5-business-day requirement.

Flag 2 — Approximately how many calendar days elapsed before access was revoked?

Question: Count from the last working day (2026-03-10) to the ticket close date (2026-04-24).

Flag 3 — What severity should this finding be assigned?

Question: Apply the rubric to how many days late the revocation was (well beyond the 5-day requirement).

Back to Challenges