Control: Change Advisory Board (CAB) approval
Classify: Timing? Execution? Key? Level?
Context: ERP Migration
Memory hook: “CAB = Committee Approves Before” → Preventive/Manual
Control: UAT evidence standards / sign-off requirements Classify: Timing? Execution? Key? Level?
Context: ERP Migration
Memory hook: “No signature = No go-live” → Preventive gate
Control: Data migration validation
Classify: Timing? Execution? Key? Level?
Context: ERP Migration.
Memory hook: “Validation” = checking AFTER the fact → Detective
Control: Parallel payroll run
Classify: Timing? Execution? Key? Level?
Context: ERP Migration.
Memory hook: “Parallel” = run both, compare AFTER → Detective
Control: SoD matrix for new system
Classify: Timing? Execution? Key? Level?
Context: ERP Migration.
Memory hook: System says “ACCESS DENIED” automatically → Preventive/Automated/Application
Control: Internal control ownership framework
Classify: Timing? Execution? Key? Level?
Context: Stakeholder Alignment.
Memory hook: “Framework” = org-wide governance → Entity-level
Control: Process documentation requirements
Classify: Timing? Execution? Key? Level?
Context: Stakeholder Alignment.
Memory hook: Documentation supports but doesn’t directly touch money → Non-key
Control: Risk quantification/reporting
Classify: Timing? Execution? Key? Level?
Context: Stakeholder Alignment.
Memory hook: “Reporting” = telling someone what you found → Detective
Control: API authentication/authorization
Classify: Timing? Execution? Key? Level?
Context: Zendesk-Smartsheet Integration.
Memory hook: “Authentication” = gatekeeper that blocks → Preventive/Automated
Control: Audit trail logging
Classify: Timing? Execution? Key? Level?
Context: Zendesk-Smartsheet Integration.
Memory hook: “Logging” = recording what already happened → Detective
Control: Duplicate ticket detection
Classify: Timing? Execution? Key? Level?
Context: Zendesk-Smartsheet Integration.
Memory hook: “Detection” = finding something that exists → Detective
Control: Pipeline error monitoring/alerting
Classify: Timing? Execution? Key? Level?
Context: Zendesk-Smartsheet Integration.
Memory hook: “Monitoring” = watching for problems → Detective
Control: Access provisioning runbook
Classify: Timing? Execution? Key? Level?
Context: SAP Support Transformation.
Memory hook: “Provisioning” = granting access = must control it tightly → Key
Control: Configuration change runbook
Classify: Timing? Execution? Key? Level?
Context: SAP Support Transformation.
Memory hook: “Configuration change” in financial system = high risk → Key
Control: Incident escalation procedures
Classify: Timing? Execution? Key? Level?
Context: SAP Support Transformation.
Memory hook: “Escalation” = reacting to something that happened → Detective
Control: Knowledge transfer validation
Classify: Timing? Execution? Key? Level?
Context: SAP Support Transformation.
Memory hook: Training validation is important but doesn’t touch money directly → Non-key
Control: Lease data entry/abstract validation
Classify: Timing? Execution? Key? Level?
Context: Yardi Revenue Cycle.
Memory hook: “Validation before entry” → Preventive
Control: Automated billing generation
Classify: Timing? Execution? Key? Level?
Context: Yardi Revenue Cycle.
Memory hook: “Automated” + “generation” = system does it → Automated/Application
Control: Rent escalation accuracy review
Classify: Timing? Execution? Key? Level?
Context: Yardi Revenue Cycle.
Memory hook: “Review” = looking at what the system produced → Detective/IT-Dep Manual
Control: Cash receipts application and matching
Classify: Timing? Execution? Key? Level?
Context: Yardi Revenue Cycle.
Memory hook: “Matching” = comparing two things that already exist → Detective
Control: AR aging review and collection follow-up
Classify: Timing? Execution? Key? Level?
Context: Yardi Revenue Cycle.
Memory hook: “Aging review” = looking at what’s old → Detective
Control: Tenant account reconciliation
Classify: Timing? Execution? Key? Level?
Context: Yardi Revenue Cycle.
Memory hook: “Reconciliation” always = Detective (comparing two sources)
Control: Revenue recognition / straight-line rent calculation
Classify: Timing? Execution? Key? Level?
Context: Yardi Revenue Cycle.
Memory hook: System “enforces” = Preventive/Automated
Control: Billing exception report review
Classify: Timing? Execution? Key? Level?
Context: Yardi Revenue Cycle.
Memory hook: “Exception report review” = system produces, human reviews → IT-Dep Manual/Detective