Question for Internal Audit professionals using American Express corporate card programs:
How does your audit team obtain access to Amex reporting data for audit testing and analytics?
• Does Internal Audit have direct access to the platform?
• Does Amex offer a role that allows users to view, run, and download reports without administrative or transactional capabilities?
• If so, what role name or permission set is used?
• If not, how does your team obtain the data needed for testing?
I'm looking to understand whether Amex supports a reporting-only access model for Internal Audit and how other organizations have implemented it.
Any insights are much appreciated 🙂