Watch DemoRead About It
Browse ServicesService Provider InfoSign In / Up
Audit & AssuranceAll statesComing soon

IT / Technology Audit

Service description

An information systems audit, also known as an IT audit, is a systematic examination of an organization's information technology infrastructure, policies, and procedures. It evaluates the effectiveness of IT controls in safeguarding assets, maintaining data integrity, and ensuring the overall alignment of IT with organizational goals. Essentially, it's a way to assess the security, reliability, and compliance of an organization's IT systems.

Common industries

Any business running its own IT systems, especially one also undergoing a financial audit.

ROI

Surfaces control gaps before they become findings or incidents, and satisfies auditors and customers who ask about your IT controls.

Benefit

An independent assessment of your IT general controls and systems — access, change management, operations — often needed alongside a financial audit.

Why get it

A financial audit tests financial controls, not IT general controls; a business whose financial systems depend on IT, or that needs to show a customer or auditor its systems are controlled, needs the IT controls tested on their own.

When you benefit

Often annual, timed alongside a financial statement audit that relies on the same systems, or after a significant system change, migration, or new application goes live.

What it costs

Usually a fixed fee, scoped to the number of systems and applications in scope.

When you pay

Commonly billed as one fee once fieldwork is complete, or in stages tied to planning, testing and reporting for a broader engagement.

Other costs

Fixing a control gap the audit finds — new access controls, change-management processes, or system configuration — is separate from the audit fee.

Risks to know

An audit only covers the systems and controls actually in scope, so leaving one out creates a blind spot a later audit or incident can expose. A gap identified but left unaddressed carries the same exposure a real incident would find.

When risks arise

Findings are most useful acted on right after the report, while the context is fresh; a gap left open past the next system change or audit cycle is easy to lose track of.

The process

The auditor scopes the systems and control framework to be tested, reviews configurations, access controls and change-management processes, and tests operating effectiveness. It documents any gaps and reviews findings with the business before issuing its report.

Your commitment

The business gives the auditor a list of systems and applications in scope, access to review configurations and controls, and a technical point of contact who can answer questions about how systems are set up.

Documents to gather

Helpful reading

Further research

Suggest an edit to this page →

Not open yet

IT / Technology Audit isn’t taking requests yet. Join the waitlist. It is listed in your requests tray.