Point of viewGoverning AI

Green SLAs, real risk: auditing service performance on all the data

A dashboard can be green while the service is not. Pauses without customer contact, closures bunched before reporting dates, changes that skip the CAB and leavers who keep access are rarely found by sample-based audits. Testing every record changes that.

6 min read By · Point of view
5
steps in the AI-narrated SLA-integrity investigation, from detection to remediation1

Key takeaways

  • SLA figures depend on how clocks are paused and tickets closed — and both can be gamed.
  • Continuous testing of IT general controls on all the data finds what samples miss.
  • Explainable findings, with the reasoning chain shown, are what make audit and HR teams willing to act.

Client contracts in IT services are written around SLAs, and SLAs are written around clocks. Clocks can be paused — 'waiting for user', 'awaiting third party' — and tickets can be closed in bulk before a reporting date. Each is legitimate in the right circumstances. Patterns of them, without the customer contact that should accompany a pause, are not.

What sample audits miss

  • Tickets paused for a customer response when no message was sent
  • Closures concentrated in the days before month-end reporting
  • Production changes deployed without change-advisory-board approval
  • Accounts that stay active after the employee has left

A quarterly audit that samples a few dozen tickets will rarely see these patterns. Testing every ticket, change and account will — and the evidence is already in the ITSM, change and HR records.

An investigation, not an alert

Exhibit 1

The five-step SLA-integrity investigation

From the platforms we have built

StepWhat it establishes
DetectionWhich tickets and patterns look suspicious
Root causeHow the pattern arises, at three levels of analysis
Business impactHidden pause hours and the true SLA breaches behind the reported figure
ResponsibilityWho owns the process and where to escalate
RemediationImmediate and longer-term actions with owners

Source: SCIKIQ, “GCC & IT services accelerators: ITSM, audit and agent platforms we have built” (2026)

From finding to fix

Continuous IT general control tests — change management, user access — run alongside the SLA analysis, and every observation, test and action is kept in a control diary. The result is evidence a client, a parent's SOX team or an ISO 27001 auditor can follow.

Test the controls on all the data, and show the reasoning behind every finding. That is what turns an audit observation into a fix.
For executives

What this means for your bank

  1. Recalculate SLA attainment without unexplained pauses and compare it with what is reported.
  2. Test change and access controls continuously, not quarterly.
  3. Keep a control diary that links findings to owners and remediation dates.
Put it to work

How SCIKIQ can help

Set up continuous control testing in our Data Governance, Privacy & IT Controls service.

Learn more

Strengthen access and change controls in our Security, Access & IT Controls service.

Learn more

See the investigation among our accelerators.

Learn more

Sources

  1. 1

Figures are drawn from the cited public sources. Opinions labelled “SCIKIQ point of view” are our own.

Stay informed

Get new GCCs and IT services insights in your inbox

New perspectives on AI, data and transformation in GCCs and IT services — a few times a month. Browse all insights.

Subscribe to SCIKIQ Insights Questions about this insight? Talk to the practice