“Who has access to sensitive financial data in our organization?”
Assuming you have a definition of what “sensitive financial data” means for your organization, can you easily answer this question? If you needed to perform an audit to verify only the appropriate people have access, what actions would you take? Whether it be users who have switched teams and still have access that shouldn’t, or shadow IT systems where access isn’t audited, several scenarios relating to process complexity, silos, and inefficient processes can lead to increased risk to your organization.