You can check this step using either way:
- In the IIS configuration - application pool, identity settings.
- In CA you can look up what account is used for the web application through Service accounts.
Then you should ensure that this account is included in the farm administrators group. And if not - you should add it there, and reload SharePoint services and IIS.