PeopleSoft IT Audit Software Consulting
PeopleSoft IT audit software is the tooling used to test the information technology general controls (ITGCs) that support a PeopleSoft Financials or HCM environment — access provisioning and deprovisioning, change management for PeopleTools objects and Component Interfaces, batch job scheduling and monitoring, and database-level security around the underlying Oracle or SQL Server tables PeopleSoft runs on. IT audit in a PeopleSoft context sits one layer below the SOX-specific SoD and application-control testing internal audit performs on business processes; it is testing whether the platform itself, and the infrastructure and change process around it, is controlled well enough for the application controls above it to be relied upon. PeopleSoft's age and typical customization depth make ITGC testing here materially different from testing a recently implemented cloud ERP.
Access provisioning and deprovisioning at the platform layer
IT audit's access-related ITGC testing in PeopleSoft covers two distinct populations: PeopleSoft application user profiles (the layer internal audit typically tests for SoD) and the PeopleTools administrative accounts that can modify security definitions, permission lists, and roles themselves. A PeopleTools administrator account with broad access to Security Administration effectively sits above the SoD controls internal audit tests, because it can create, modify, or delete the permission lists and roles that enforce those controls. IT audit testing needs to confirm that PeopleTools administrator access is itself restricted to a small, individually accountable group, and that changes made through that access are logged and reviewable.
Deprovisioning testing in PeopleSoft has a specific failure mode worth naming directly: because user profiles can be deactivated without necessarily removing their role assignments, a terminated employee's profile can remain inactive-but-configured for an extended period, and if the account is ever reactivated (a common scenario in rehire situations or contractor renewals) it can silently retain access from a prior role that was never formally reviewed. IT audit test procedures should confirm the deprovisioning process actually removes or nulls role assignments on termination, not just flags the user profile as inactive.
Change management for PeopleTools objects and Component Interfaces
PeopleSoft change management ITGC testing covers changes to delivered and custom PeopleTools objects — pages, components, Application Engine programs, and Component Interfaces — as they move from development through test to production, typically via PeopleSoft's Application Designer and a change-migration process (STAT, Rapid Start, or a custom migration tool many long-running shops still use). IT audit's core test is whether every production change to a financially relevant object has a corresponding change ticket, an independent reviewer distinct from the developer, and a migration log entry that ties the two together. In practice, this is one of the areas most likely to have gaps in older PeopleSoft shops, where migration tooling was built years ago and informally maintained rather than governed by a current change-management policy.
Component Interfaces deserve specific IT audit attention because they are frequently built for integrations and batch loads outside the standard change-migration discipline applied to user-facing pages — a CI built quickly to support a one-off data load can persist in production for years, running under a service account with access scoped far more broadly than the integration currently needs. IT audit testing should include a current CI inventory reconciled against active integrations, confirming that CIs no longer supporting a live integration are deactivated and that active CI service accounts are scoped to only the data the integration requires.
Batch processing, Process Scheduler, and database-layer controls
Process Scheduler ITGC testing focuses on who can define, modify, and execute run controls for financially relevant batch jobs — GL journal generation, AP payment posting, payroll calculation — and whether the Process Monitor log provides enough detail to independently verify a batch job ran as scheduled, by an authorized requestor, without unauthorized modification to the run control parameters. A frequent finding is a Process Scheduler operator ID shared across an IT operations team rather than assigned to individuals, which breaks the individual accountability IT audit needs to sample against and functions as a control gap even when the batch jobs themselves ran correctly.
Database-layer testing is often the most technically distinct piece of PeopleSoft IT audit work, because PeopleSoft's application-level security does not prevent someone with direct database access (a DBA account, a reporting user with a database login rather than a PeopleSoft user profile) from reading or modifying financially relevant tables outside any PeopleSoft-enforced workflow. IT audit needs visibility into who holds direct database credentials to the PeopleSoft database instance, how that access is different from and reviewed separately from PeopleSoft application access, and whether database-level changes to financial tables are logged independently of the PeopleSoft application audit trail.
What actually differentiates the options
- ·Coverage of PeopleTools administrator access as a distinct, higher-privilege population from PeopleSoft application user profiles, since it can override SoD controls configured at the application layer.
- ·Test procedures for deprovisioning that confirm role assignments are actually removed on termination, not just that the user profile is flagged inactive.
- ·A current Component Interface inventory reconciled against active integrations, with service account access scoped to each integration's actual data need.
- ·Process Scheduler operator ID mapping to individuals for all financially relevant batch processes, with Process Monitor logs sufficient to independently verify authorized execution.
- ·Visibility into direct database-layer access to the PeopleSoft instance, reviewed separately from and in addition to PeopleSoft application-level access controls.
Requirement, control, evidence
| Requirement | Control | Evidence |
|---|---|---|
| ITGC — logical access security over the application platform | PeopleTools administrator access restricted to a small, individually accountable group, separate from and more tightly controlled than standard PeopleSoft application user access. | Administrator access listing reviewed against an approved role roster, with any changes to Security Administration access logged and independently reviewed. |
| ITGC — access provisioning and deprovisioning | Termination process that removes or nulls role assignments from a user profile, not merely deactivating the profile, preventing silent access retention on reactivation. | Sample of terminated employee user profiles showing role assignments cleared at or near termination date, cross-referenced to HR termination records. |
| ITGC — change management for financially relevant configuration and integrations | Every production migration of a PeopleTools object or Component Interface supporting an in-scope financial process requires a change ticket, independent review, and a migration log entry. | Sample of production migrations tied to change tickets showing requester, independent reviewer, and migration timestamp from the migration tool log. |
| ITGC — database and infrastructure-layer access controls | Direct database access to the PeopleSoft instance restricted to a defined DBA population and reviewed independently of PeopleSoft application-level access recertification. | Database access listing for the PeopleSoft instance, reconciled against an approved DBA roster, with database-layer changes to financial tables logged separately from the application audit trail. |
What this actually costs
| Cost driver | Low | High | What moves it |
|---|---|---|---|
| ITGC scoping and PeopleTools/Component Interface change-process assessment | $45,000 | $160,000 | Higher end reflects instances relying on informally maintained, homegrown migration tooling rather than a current, governed change-management platform. |
| Remediation: administrator access restriction, deprovisioning process fix, CI inventory and re-scoping | $70,000 | $280,000 | Scales with number of active Component Interfaces and integrations requiring service-account rescoping, and depth of deprovisioning process changes needed. |
| Ongoing ITGC testing and database-layer access review | $40,000/yr | $150,000/yr | Depends on accelerated-filer status, batch job volume in scope, and whether database-layer access review is newly established or already mature. |
- · Ranges assume a single primary PeopleSoft instance with one associated production database; multi-instance environments trend toward or beyond the high end.
- · Figures are illustrative estimates based on typical PeopleSoft ITGC engagements, not a quote for a specific organization.
- · External audit fees for ITGC reliance testing under 404(b) are excluded — this reflects internal and advisory remediation labor only.
A representative scenario
A hypothetical logistics company running PeopleSoft Financials on-prem for over a decade undergoes its first formal ITGC assessment after growing past the threshold requiring more rigorous internal controls testing. The assessment finds that PeopleTools administrator access — the ability to modify Security Administration definitions — was granted to nine members of the IT team over the years, several of whom no longer work on PeopleSoft day to day, with no periodic review of that population separate from standard application access recertification. A parallel review of terminated employees finds that deprovisioning deactivates the user profile but does not remove role assignments, and two reactivated contractor accounts are found to have retained access from roles assigned during a prior engagement two years earlier. A Component Interface inventory, built for the first time as part of the assessment, surfaces several CIs supporting integrations that were decommissioned years ago but never deactivated, still running under service accounts with broad component access. Remediation narrows PeopleTools administrator access to three individuals with quarterly review, rebuilds the deprovisioning process to clear role assignments at termination, and deactivates or rescopes the stale Component Interfaces. This pattern — administrative access sprawl and incomplete deprovisioning surfacing together on a first rigorous ITGC review — is common enough in long-running on-prem PeopleSoft environments that it is described here as illustrative, not as a specific client outcome.
Common questions
IT audit tests the platform and infrastructure controls that make application-level controls trustworthy — access provisioning, change management, batch processing, and database security — while internal SOX audit tests the business-process controls those platform controls support, such as segregation of duties and workflow approvals. A PeopleSoft environment can have well-designed SoD controls at the application layer that are still undermined by weak ITGCs, such as unrestricted PeopleTools administrator access that can bypass those controls entirely.
Book an assessment
Get a scoping call on peoplesoft it audit software for your organisation's platform and entity structure.
Book an Assessment →