I've been using a shared login with a colleague for minor development tasks at a large consulting firm in India. I'm officially allocated and billed to another project, and my project manager knew I was using the shared account. During a recent meeting, an internal audit senior manager heard me mention it and told me to obtain a separate login immediately. I have a follow-up meeting with him next week, but my program manager says a separate login may not be available. I've stopped to reconsider the situation and want to understand what risks I face and how best to address it. The auditor is an internal employee, not someone auditing a client.
4 Answers
Stop using the shared account immediately and be completely factual in the meeting. Explain when and why it was used, who knew about it, and what work was performed. Ask your program manager to attend so responsibility and the access issue are discussed openly. The appropriate solution is an individually assigned account, or a formally documented exception with compensating controls—not an informal shared password.
Invite the program manager, or at least tell the auditor beforehand that management was aware of the arrangement. You can acknowledge that using someone else’s credentials was a mistake without speculating about penalties. The fact that the auditor warned you now gives you a chance to correct it, but continuing after being told to stop would make the situation much worse.
Your manager’s statement that a separate login isn’t available doesn’t make password sharing compliant. Raise the issue through the normal security or access-management process and request written guidance. In the meeting, focus on remediation: disable the shared access, identify the affected systems and dates, review the logs, and obtain proper permissions or an approved alternative.
This can be treated as a serious access-control violation because activity under a shared login cannot be reliably attributed to one person. Consequences depend on company policy, the systems involved, and whether any sensitive data or unauthorized actions were accessed. Don’t delete logs, alter records, or try to coordinate a story; preserve the facts and cooperate with the review.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures