Attempt to transition a change request to 'Approved' state without completing any impact assessment entries. Confirm the system blocks the transition with a clear error. This is the single most important change control test — all downstream control depends on the impact assessment being enforced.
Attempt to complete an implementation task on a change request that is still in 'In Review' state (not yet approved). Confirm the system blocks task completion or flags it as a pre-approval implementation requiring documented justification. This negative test is the only way to confirm sequential enforcement exists — positive-path testing will not reveal a parallel execution gap.
Flag a validated system in the impact assessment. Attempt to close the change request without a linked, completed revalidation assessment. Confirm the system blocks closure. Complete and link the revalidation assessment and confirm closure is now available. If your Vault configuration does not enforce this at the system level, document this explicitly as a procedural control gap.
Confirm the PIV task cannot be assigned to and completed by the same user who is the primary implementer, if your SOP requires independence. Test by attempting self-assignment of the PIV task with the implementer's account — confirm the system blocks this or requires a second approver to accept the self-verification. Confirm PIV completion is required before closure.
Complete an approval action and confirm the e-signature captures the individual user's credentials (not a shared or role account), the password re-authentication is required, the meaning statement is specific to the approval action, and the signature event is retrievable in the audit trail with user name, timestamp, and meaning text.
Attempt to invoke the emergency change lifecycle path using a standard user role without emergency authorisation. Confirm this requires elevated authorisation. Invoke a legitimate emergency change and confirm: implementation is documented immediately, the retroactive formal approval is required within the configured timeframe, and the record is distinguishable from standard changes in reporting and periodic review.