TRUST-IT · Published
DECISION BRIEF
What this assessment should establish
- Map authority and recovery across people, entities and providers.
- Validate important controls with authorised tests and dated evidence.
- Leave with assigned actions, measurable acceptance checks and a confidential handover.
Define the boundary around people and authority
Begin with the principal’s priorities: preventing payment fraud, preserving privacy, maintaining access during travel or establishing reliable oversight of outsourced IT. List the legal entities, residences, office systems and advisers included in the assessment. A single-family office and a multi-family office need different separation and disclosure arrangements; client-by-client boundaries should be explicit.
Record who owns each account, who administers it and who can recover it. These roles often sit with different people. Separate personal accounts, corporate accounts and systems controlled by banks, custodians or advisers. Obtain authorisation from the relevant owner before technical testing. An engagement with the office does not automatically authorise access to a family member’s private device or a third party’s platform.
Trace privileged access and account recovery
Inventory primary email, password management, domain registration, cloud administration and mobile-number recovery dependencies. Review active sessions, delegated mailboxes, forwarding rules, application grants and administrator roles using scoped, read-only exports where possible. Record the population reviewed and the collection time; a screenshot of one protected account does not establish office-wide coverage.
Test agreed recovery paths with designated test accounts or supervised procedures. Determine whether a lost phone can be replaced without falling back to an uncontrolled mailbox or an assistant’s personal number. Examine spare authentication keys, emergency access ownership and revocation after staff changes. A successful recovery test should show that an authorised person regained access and that obsolete access was removed.
From confidential scope to verified improvement
- ScopePeople, entities, systems and consent
- MapAccess, authority and recovery
- ValidateEvidence and controlled exercises
- PrioritiseImpact, uncertainty and ownership
- RetestConfirm the agreed acceptance checks
Examine payments as a chain of decisions
Map the journey from a supplier’s instruction to beneficiary creation, approval and bank execution. Ask where a compromised inbox, a changed telephone number or an urgent voice message could influence the decision. Check that beneficiary changes are verified through a previously trusted channel, with appropriate separation between preparation and authorisation.
A tabletop exercise can use a fictitious change request without sending a real payment. Record whether staff identify the change, use the approved callback source and escalate a mismatch. Preserve only the evidence needed to demonstrate the control. Do not place live account numbers, payment credentials or family financial records in a general assessment report.
Review devices, advisers and sensitive information
Reconcile the device inventory against management and protection coverage, including executive travel devices and approved personal-device access. Sample encryption, updates, screen locking, local privileges and loss-response procedures. Review file-sharing links, adviser access and retention of sensitive documents. An external adviser’s assurance report should be assessed against the actual service and access they provide.
Record exceptions rather than forcing a uniform corporate configuration onto every household activity. Where a private device cannot be assessed, explain what remains unknown and which compensating measures are feasible. Test the removal of a former adviser’s access across groups, shared folders, delegated mail and active sessions within the authorised scope.
An audit matrix that connects controls to evidence
| Area | Evidence to request | Acceptance check |
|---|---|---|
| Identity and recovery | Account and administrator inventory; recovery dependencies; dated access exports. | Sample recovery and revocation with authorised accounts; disclose exclusions. |
| Payments | Approval map; beneficiary-change procedure; redacted exercise records. | A simulated change cannot proceed without the agreed independent verification. |
| Adviser access | Provider access list, shared resources, contract scope and offboarding record. | Selected departed or expired access is removed and checked across relevant systems. |
| Devices and continuity | Coverage reconciliation; exception log; supervised restore or lost-device exercise. | Selected records can be used after restoration; recovery ownership and gaps are clear. |

Prove recovery without disrupting the office
Choose a controlled scenario, such as losing the principal’s travel phone while the usual assistant is unavailable. Identify the communication channel, alternate approver, identity check, emergency-access custodian and recovery sequence. Use test data and an agreed stop condition. Record elapsed time as an observation of this exercise, not a promise for every future incident.
For business records, a useful restore check validates readability, permissions and the ability to continue the selected process. A backup job reporting success is only one piece of evidence. Record dependencies that were not tested, such as the availability of a bank or telecom provider, and assign the next verification step.
Turn findings into a decision and a retest
Prioritise findings by credible harm, exposure, confidence in the evidence and operational dependency. A recovery route controlled by a departed employee may deserve action before a low-impact configuration issue. Distinguish confirmed weaknesses, untested assumptions and improvements that reduce inconvenience rather than material risk.
The handover should include an executive briefing, a restricted technical annex, an ownership map and a remediation register. Each action needs an accountable owner, target date, acceptance criterion and retest method. Agree secure transfer, retention and deletion of working evidence. Start a confidential scoping discussion with a description of the concern and the systems involved; share sensitive records only through an agreed channel.
Illustrative audit scenario: the hidden recovery dependency
An illustrative office uses strong authentication for the principal’s mailbox, but an old external administrator still controls the domain registrar and recovery email. The assessment would trace and verify that dependency, agree a controlled transfer of ownership, remove obsolete sessions and test recovery with the new custodian. This is an example of a method, not a claim about a TRUST-IT client or a completed result.
Common questions
Is this the same as a penetration test?
No. The audit considers authority, operating procedures, configuration and recovery as well as technical exposure. A separately scoped penetration test may validate selected risks, but it does not replace the wider review.
Can our existing IT provider participate?
Yes. Agree evidence requests and responsibilities together. Separate the provider’s assertions from independent observations, and record any systems or checks outside the agreed scope.
Will you need private family records?
The starting point is a minimal inventory and the business concern. Redacted samples and supervised checks can often reduce disclosure. Any additional access, collection and retention must be agreed before work begins.
Further reading
Put the guidance to work
Strengthen access controls, secure communications, and digital protection for organisations and executives.
Identity & executive security