I work at a large consulting firm in India and have been using a shared login with a colleague for minor development tasks. I'm officially billed to another project, and my project manager knew this arrangement was happening. During a meeting, an internal audit senior manager heard me mention it and told me to obtain a separate login immediately. I have a follow-up meeting with him next week, but my program manager says a separate account may not be available. What should I do, and what consequences could there be? I want to clarify that this is an internal audit matter, not a client audit, and the auditor said separate credentials were needed to protect me.
3 Answers
Shared credentials are a serious security and audit issue because activity can’t be reliably attributed to one person. Possible consequences range from having access removed and receiving a warning to a formal investigation or disciplinary action, depending on company policy and what was accessed. The fact that management knew about it may be relevant, but it doesn’t make the practice compliant.
Stop using the shared login unless security explicitly authorizes it. Preserve any relevant facts and records, but don’t alter logs or delete anything. Before the meeting, contact IT security or the access-management team through the normal process and ask for a compliant solution. Keep the discussion factual and focus on correcting the access problem rather than assigning blame.
Be transparent and bring your program manager into the meeting. Explain exactly what access was used, why the shared login was necessary, who knew about it, and when it happened. Don’t minimize it or try to coordinate a story. Ask security or IT for an approved individual account, documented exception, or alternative access method.

If your program manager already said an individual account isn’t possible, ask them to explain that directly to the auditor and request written guidance on the approved workaround.