Policies & Approvals

Reviewing Access to Expense and Card Systems

Conduct a role-focused access review of expense and card records, verify business need, and document removals, conflicts, and unresolved access exceptions.

By Remizen Editorial · · 3 min read

Access reviews should answer a practical question: does each person still need the actions and data their account permits, especially actions that can change, approve, pay, or reconcile expenses? This guide covers a periodic review of expense and card-system access by the organization that owns the process. It does not assume a particular vendor feature or security configuration. The GAO 2025 Green Book is a framework for U.S. federal agencies; private organizations may adapt its practices, but it is not a mandate for all employers.

Build a review population and permission map

Request a dated list of active accounts and roles from each system owner, plus employee status and manager for validation. Include privileged or service accounts that can affect expense information, and ask the technical owner what each can do. Translate role names into actions: submit, view, edit, approve, administer users, change payment details, export, or reconcile. Green Book Principle 11.02 defines information security as protecting information and technology from unauthorized actions or disruption; Principle 11.07 says general controls support application and user controls. These principles inform scope, not a vendor-specific checklist.

Compare access with current responsibilities, approval authority, and your duty map. Look for former personnel, role changes, duplicate accounts, broad access without a current need, and combinations that allow a person to alter a transaction and approve or certify the same activity. Do not infer that an account is unused merely because it has no recent transactions; confirm with its owner and your access policy. Record the reviewer and review date, source listing date, access decision, rationale for retained elevated access, and ticket or administrator evidence for requested changes.

Resolve mismatches and verify changes

Send each item to a manager or business owner who can validate current duties; an administrator executes technical changes. Separate the access decision from implementation where practical. For removal or reduction, record account, role, reason, administrator, and target date. Obtain confirmation or a fresh listing showing the new state; a request alone does not prove a change. For temporary access, record rationale, approver, review date, and any compensating monitoring. Green Book Principle 12.04 describes corrective follow-up in procedures; do not leave exceptions without an owner.

Worked example: employee changes roles

A travel coordinator moves into a non-finance role but still appears in the card system with transaction editing and cardholder-administration rights. The manager confirms that the person still needs read-only access to historical travel records for a defined handover period, but no longer needs editing or administration. The system owner records the reduced role, administrator, effective date, and limited purpose. A reviewer then checks a current account listing to verify the old permissions are gone. If the system cannot provide only the narrow read-only role, the owner documents the limitation and alternative access restriction rather than asserting a control the system does not provide.

Handle uncertain or urgent cases

If a manager cannot identify an account owner, mark it unresolved and route it to the system owner under existing access policy. Do not blindly delete a service account or block a user if that could interrupt operations; ask the technical owner to establish its purpose and safe next step. For suspected inappropriate access, follow established incident procedures and preserve evidence. Set follow-up dates and record closure. GAO Principle 16 describes ongoing monitoring and separate evaluations with scope informed by risk and change; use this as a timing framework, not a universal interval.

  • Retain a dated account-and-role population from each system owner.
  • Translate role labels into transaction and administration capabilities.
  • Record manager decisions, removal requests, and reasoned exceptions.
  • Verify completed changes and assign owners and dates to unresolved access.

Sources and further reading

  • Corporate Card Controls

    Corporate card controls combine preventive rules, transaction visibility, review, and follow-up to reduce avoidable spending problems. Learn to layer controls around the risks and purchasing realities of your organization without relying on restrictions alone.

  • Corporate Card Policies

    A corporate card policy explains who may use company cards, which purchases are allowed, what documentation is required, and how exceptions are handled. This guide outlines the decisions and communication practices behind an enforceable, usable policy.

  • Expense Management Controls

    Understand how preventive, review, and reconciliation controls support reliable expense management. Learn to assign control owners and investigate exceptions without treating alerts as proof of wrongdoing.

  • Financial Controls for Employee Spending

    Learn how practical controls can prevent, detect, and resolve issues in employee spending while keeping legitimate purchases workable. The guide covers authority, documentation, review, access, and ongoing monitoring.