Module 5 · Beginner · ⏱ 40 min · 🏆 +170 XP

IT Audit Fundamentals

Audit is not an interrogation. It is an independent, evidence-based examination of whether what is written in a policy actually matches what is happening in operational reality.

IIA StandardsAudit Lifecycle ISACAAudit Evidence Test of ControlsInternal vs External

Learning Objectives

  • Define the purpose and scope of an IT audit and how it differs from a security assessment.
  • Distinguish between internal and external audit functions.
  • Describe the full audit lifecycle: Plan → Execute → Report → Follow-Up.
  • Identify the five types of audit evidence and the characteristics of high-quality evidence.
  • Apply IIA Standards principles to an audit scenario.
  • Explain the difference between design effectiveness and operating effectiveness.

Lecture

1 · What is an IT Audit?

An IT audit is a systematic, independent examination of an organization's IT controls, processes, and systems to determine whether they are designed and operating effectively to achieve their intended objectives. Auditors collect and evaluate evidence — they do not fix problems (that is management's job).

2 · Internal vs External Audit

DimensionInternal AuditExternal Audit
IndependenceFunctionally independent; reports to audit committeeFully independent; separate organization
PurposeImprove operations and risk managementProvide assurance to external stakeholders
AudienceBoard, senior managementRegulators, shareholders, customers
ScopeBroad — any organizational activityScoped by engagement contract
StandardsIIA IPPF (International Standards for Professional Practice of Internal Auditing)AICPA, PCAOB, ISAE 3402

3 · The Audit Lifecycle

Plan: Define scope, objectives, and approach based on risk assessment. Execute: Perform fieldwork — request evidence, interview personnel, test controls. Report: Document findings, root causes, and recommendations. Follow-Up: Verify management has implemented agreed remediation actions. This cycle repeats continuously in a mature internal audit function.

4 · Design vs Operating Effectiveness

A control is effectively designed if it is capable of preventing or detecting the relevant risk — the control makes sense in theory. A control is operating effectively if it is actually being performed consistently as designed — the control works in practice. A beautiful policy that no one follows has good design but poor operating effectiveness.

Auditor's mantra: "Show me the evidence." Assertions without evidence are opinions, not audit findings.

Theory Deep Dive — Audit Frameworks and Methods

📜 IIA International Professional Practices Framework (IPPF)

The Institute of Internal Auditors (IIA) publishes the IPPF — the global framework governing internal audit practice. The 2024 IPPF Global Internal Audit Standards define:

Purpose of Internal Audit

To enhance and protect organizational value by providing risk-based, objective assurance, advice, and insight. Internal audit is an assurance AND advisory function — not just a compliance checker.

Core Principles (10 Total)

Demonstrates integrity; demonstrates competence; maintains objectivity; aligns with the strategies and objectives of the organization; is appropriately positioned; demonstrates quality; communicates effectively; provides risk-based assurance; is insightful, proactive, and future-focused; promotes organizational improvement.

Independence & Objectivity

The CAE (Chief Audit Executive) must report functionally to the audit committee of the board — never to the same executive whose activities are being audited. Objectivity means auditors form unbiased judgments based on evidence alone.

Risk-Based Audit Planning

Audit plans are derived from the organization's risk assessment — not arbitrary rotations. High-risk areas receive more audit attention. The plan is approved by the audit committee annually.

🔍 Audit Evidence — Quality and Types

Audit evidence must be sufficient (enough of it), reliable (trustworthy source), relevant (related to the assertion), and useful (supports the conclusion). Five types of evidence, ranked from most to least reliable:

1
Physical Evidence (Most Reliable)

Direct observation and inspection by the auditor. Example: auditor physically observes a data center badge reader working, or witnesses a backup tape being vaulted. Cannot be fabricated for the auditor in the moment.

2
Documentary Evidence

Written records — logs, invoices, screenshots, configuration files, signed policies. Reliability depends on source: externally generated documents (bank statements) are more reliable than internally generated ones.

3
Analytical Evidence

Derived from analysis of data — comparing current period to prior period, benchmarking against industry norms, trend analysis. Used to identify anomalies that warrant deeper investigation.

4
Testimonial Evidence

Statements from management and employees — interviews, representations, confirmations. Least reliable type alone — must be corroborated with documentary or physical evidence for significant findings.

5
Computer-Generated Evidence

System-generated reports, audit logs, access review exports. Reliability depends on system integrity — auditors must verify the completeness and accuracy of the system generating the evidence.

🧪 Testing Methods — How Auditors Test Controls

Auditors use five primary testing techniques. The choice depends on the control type, risk level, and available evidence:

Inquiry

Ask people how a control works. Fastest method. Never sufficient alone — must be corroborated. Used for initial understanding and scoping.

Observation

Watch the control in action. More reliable than inquiry alone. Limitation: behavior may change when observed (Hawthorne Effect). Effective for physical controls and procedures.

Inspection (Re-performance)

Review documents, records, and reports. The most common audit technique. Auditor reviews access provisioning records, change management tickets, patch reports.

Re-performance

Auditor independently performs the control and compares to management's execution. Strongest form of evidence — confirms the control works as claimed.

Analytical Procedures

Statistical and data analysis to identify anomalies. Example: running a duplicate payment analysis in accounts payable, or mapping access levels against job descriptions.

Sampling

Testing a subset of a population to draw conclusions about the whole. Statistical sampling allows probability-based confidence levels. Judgmental sampling uses auditor expertise to select items.

📋 Audit Findings — Structure and Quality

A well-written audit finding is the primary output of an audit. High-quality findings follow the PCCA structure:

P
Population / Condition

What was tested, and what was observed. Be specific — state the exact deviation found. "Of 25 access reviews sampled, 8 (32%) had no documented approval." Not "some access reviews were missing."

C
Criteria

The standard, policy, or requirement that was not met. "Per the Access Management Policy v2.3, all access reviews must be approved by the resource owner within 30 days."

C
Cause

Why the deviation occurred. Root cause analysis — not just symptoms. "The access review workflow was not automated, relying on manual email reminders that were not consistently sent."

A
Effect / Risk

What could happen because of the deviation. "Without timely access reviews, terminated employees or role-changed employees may retain inappropriate access, increasing the risk of unauthorized data access or insider threat."

The most common audit report weakness is describing what was found without explaining why it matters. The Effect section is what motivates management to remediate.

🏢 ISACA and COBIT — Audit Standards for IT

ISACA publishes two foundational frameworks used globally in IT audit:

COBIT (Control Objectives for IT)

A comprehensive framework for IT governance and management. COBIT 2019 defines 40 governance/management objectives across 5 domains: Evaluate, Direct & Monitor (EDM); Align, Plan & Organize (APO); Build, Acquire & Implement (BAI); Deliver, Service & Support (DSS); Monitor, Evaluate & Assess (MEA).

ITAF (IT Assurance Framework)

ISACA's professional practices framework for IT audit. Defines standards, guidelines, and tools for IT audit professionals. Used by CISA-certified auditors globally.

🧪 Lab — IT Audit Walkthrough: Gmail Account

You are an IS auditor performing a spot-check audit of a Google Workspace account. Complete each audit test step exactly as you would in a real audit — checking control design, gathering evidence, and noting exceptions.

Scenario — Shared Admin Accounts Discovered

Mission Quiz

Mission Complete

← Module 4 Next: Module 6 →