Audit is not an interrogation. It is an independent, evidence-based examination of whether what is written in a policy actually matches what is happening in operational reality.
An IT audit is a systematic, independent examination of an organization's IT controls, processes, and systems to determine whether they are designed and operating effectively to achieve their intended objectives. Auditors collect and evaluate evidence — they do not fix problems (that is management's job).
| Dimension | Internal Audit | External Audit |
|---|---|---|
| Independence | Functionally independent; reports to audit committee | Fully independent; separate organization |
| Purpose | Improve operations and risk management | Provide assurance to external stakeholders |
| Audience | Board, senior management | Regulators, shareholders, customers |
| Scope | Broad — any organizational activity | Scoped by engagement contract |
| Standards | IIA IPPF (International Standards for Professional Practice of Internal Auditing) | AICPA, PCAOB, ISAE 3402 |
Plan: Define scope, objectives, and approach based on risk assessment. Execute: Perform fieldwork — request evidence, interview personnel, test controls. Report: Document findings, root causes, and recommendations. Follow-Up: Verify management has implemented agreed remediation actions. This cycle repeats continuously in a mature internal audit function.
A control is effectively designed if it is capable of preventing or detecting the relevant risk — the control makes sense in theory. A control is operating effectively if it is actually being performed consistently as designed — the control works in practice. A beautiful policy that no one follows has good design but poor operating effectiveness.
The Institute of Internal Auditors (IIA) publishes the IPPF — the global framework governing internal audit practice. The 2024 IPPF Global Internal Audit Standards define:
To enhance and protect organizational value by providing risk-based, objective assurance, advice, and insight. Internal audit is an assurance AND advisory function — not just a compliance checker.
Demonstrates integrity; demonstrates competence; maintains objectivity; aligns with the strategies and objectives of the organization; is appropriately positioned; demonstrates quality; communicates effectively; provides risk-based assurance; is insightful, proactive, and future-focused; promotes organizational improvement.
The CAE (Chief Audit Executive) must report functionally to the audit committee of the board — never to the same executive whose activities are being audited. Objectivity means auditors form unbiased judgments based on evidence alone.
Audit plans are derived from the organization's risk assessment — not arbitrary rotations. High-risk areas receive more audit attention. The plan is approved by the audit committee annually.
Audit evidence must be sufficient (enough of it), reliable (trustworthy source), relevant (related to the assertion), and useful (supports the conclusion). Five types of evidence, ranked from most to least reliable:
Direct observation and inspection by the auditor. Example: auditor physically observes a data center badge reader working, or witnesses a backup tape being vaulted. Cannot be fabricated for the auditor in the moment.
Written records — logs, invoices, screenshots, configuration files, signed policies. Reliability depends on source: externally generated documents (bank statements) are more reliable than internally generated ones.
Derived from analysis of data — comparing current period to prior period, benchmarking against industry norms, trend analysis. Used to identify anomalies that warrant deeper investigation.
Statements from management and employees — interviews, representations, confirmations. Least reliable type alone — must be corroborated with documentary or physical evidence for significant findings.
System-generated reports, audit logs, access review exports. Reliability depends on system integrity — auditors must verify the completeness and accuracy of the system generating the evidence.
Auditors use five primary testing techniques. The choice depends on the control type, risk level, and available evidence:
Ask people how a control works. Fastest method. Never sufficient alone — must be corroborated. Used for initial understanding and scoping.
Watch the control in action. More reliable than inquiry alone. Limitation: behavior may change when observed (Hawthorne Effect). Effective for physical controls and procedures.
Review documents, records, and reports. The most common audit technique. Auditor reviews access provisioning records, change management tickets, patch reports.
Auditor independently performs the control and compares to management's execution. Strongest form of evidence — confirms the control works as claimed.
Statistical and data analysis to identify anomalies. Example: running a duplicate payment analysis in accounts payable, or mapping access levels against job descriptions.
Testing a subset of a population to draw conclusions about the whole. Statistical sampling allows probability-based confidence levels. Judgmental sampling uses auditor expertise to select items.
A well-written audit finding is the primary output of an audit. High-quality findings follow the PCCA structure:
What was tested, and what was observed. Be specific — state the exact deviation found. "Of 25 access reviews sampled, 8 (32%) had no documented approval." Not "some access reviews were missing."
The standard, policy, or requirement that was not met. "Per the Access Management Policy v2.3, all access reviews must be approved by the resource owner within 30 days."
Why the deviation occurred. Root cause analysis — not just symptoms. "The access review workflow was not automated, relying on manual email reminders that were not consistently sent."
What could happen because of the deviation. "Without timely access reviews, terminated employees or role-changed employees may retain inappropriate access, increasing the risk of unauthorized data access or insider threat."
The most common audit report weakness is describing what was found without explaining why it matters. The Effect section is what motivates management to remediate.
ISACA publishes two foundational frameworks used globally in IT audit:
A comprehensive framework for IT governance and management. COBIT 2019 defines 40 governance/management objectives across 5 domains: Evaluate, Direct & Monitor (EDM); Align, Plan & Organize (APO); Build, Acquire & Implement (BAI); Deliver, Service & Support (DSS); Monitor, Evaluate & Assess (MEA).
ISACA's professional practices framework for IT audit. Defines standards, guidelines, and tools for IT audit professionals. Used by CISA-certified auditors globally.
You are an IS auditor performing a spot-check audit of a Google Workspace account. Complete each audit test step exactly as you would in a real audit — checking control design, gathering evidence, and noting exceptions.