Client contracts in IT services are written around SLAs, and SLAs are written around clocks. Clocks can be paused — 'waiting for user', 'awaiting third party' — and tickets can be closed in bulk before a reporting date. Each is legitimate in the right circumstances. Patterns of them, without the customer contact that should accompany a pause, are not.
What sample audits miss
- Tickets paused for a customer response when no message was sent
- Closures concentrated in the days before month-end reporting
- Production changes deployed without change-advisory-board approval
- Accounts that stay active after the employee has left
A quarterly audit that samples a few dozen tickets will rarely see these patterns. Testing every ticket, change and account will — and the evidence is already in the ITSM, change and HR records.
An investigation, not an alert
The five-step SLA-integrity investigation
From the platforms we have built
| Step | What it establishes |
|---|---|
| Detection | Which tickets and patterns look suspicious |
| Root cause | How the pattern arises, at three levels of analysis |
| Business impact | Hidden pause hours and the true SLA breaches behind the reported figure |
| Responsibility | Who owns the process and where to escalate |
| Remediation | Immediate and longer-term actions with owners |
Source: SCIKIQ, “GCC & IT services accelerators: ITSM, audit and agent platforms we have built” (2026)
From finding to fix
Continuous IT general control tests — change management, user access — run alongside the SLA analysis, and every observation, test and action is kept in a control diary. The result is evidence a client, a parent's SOX team or an ISO 27001 auditor can follow.
Test the controls on all the data, and show the reasoning behind every finding. That is what turns an audit observation into a fix.