I’ve been involved in a number of debates lately regarding whether auditors should have READ access to IT systems and data. Surprisingly, I’ve found that there appears to be very little middle ground – auditors either get READ access to whatever they request or get no access at all.