Advisory · 02/07
IT Audit
An independent assessment of your IT systems and processes: do your controls protect assets, keep data accurate and meet the regulations that apply to you?
- Typical duration
- 3 to 8 weeks
- Team
- Audit manager (CISA), IT auditors, subject specialists as needed
01Overview
An IT audit gives management, the audit committee and regulators an objective view of how well IT is controlled. Done well, it is also the fastest way to find out where your real risks are.
Our auditors hold CISA and related certifications and work to ISACA’s IT Audit Framework. We perform internal audit co-sourcing, pre-certification audits and targeted reviews, and we write findings that operational teams can act on.
02What we do
- 01
General IT controls review
Access management, change management, backup and recovery, IT operations and physical security.
- 02
Application controls testing
Input, processing and output controls in core systems such as ERP, core banking and billing.
- 03
Data reliability assessment
Whether the data your reports depend on is complete, accurate and protected from unauthorized change.
- 04
Regulatory compliance audit
Testing against sector rules, data protection law and the standards you have committed to.
- 05
Pre-certification audit
A readiness check before ISO/IEC 27001, ISO 22301 or PCI DSS certification audits.
- 06
Internal audit co-sourcing
Specialist IT auditors who join your internal audit team for planned engagements.
03What you get
- An objective view of IT control effectiveness
- Findings ranked by business risk, not by checklist
- Evidence ready for external auditors and regulators
- A practical remediation plan with owners and dates
Typical deliverables
- 01Audit plan and scope
- 02Detailed findings report
- 03Executive summary for the audit committee
- 04Management action plan
- 05Follow-up review
04How the engagement runs
- 01
Planning
Risk-based scope, audit program and evidence request agreed with you.
- 02
Fieldwork
Walkthroughs, control testing, sampling and technical checks.
- 03
Reporting
Findings discussed with owners before the report is issued. No surprises.
- 04
Follow-up
We verify that agreed actions have been implemented and close findings.
05Technologies & partners
06Questions clients ask
Frequently asked questions
01Can you audit systems you also helped implement?
No. To protect independence, we do not audit work we delivered. We will tell you upfront if a conflict exists and recommend another approach.
02How much of our team’s time does an audit take?
We send a single evidence request at the start and group interviews into a few days. Most teams spend two to four hours each over the engagement.
03Do you use automated tools?
Yes, for configuration review and vulnerability data, for example Titania Nipper and Tenable. Tools speed up testing; auditors interpret the results.
07Related services
IT Governance
Strategy, risk and control frameworks that tie IT spend to business goals.
Learn more 03Policies & Compliance
Policy sets and evidence trails that stand up to regulators and auditors.
Learn more 04Cybersecurity
Risk assessment, testing and protection against malware, phishing and ransomware.
Learn moreStart a conversation
Tell us where things stand. We will tell you honestly what it takes.
A 30-minute call with a senior consultant, no sales script. You leave with a clear next step, whether or not we work together.

