IT Audits & Controls Assessments

IT Audits and Controls Assessments

We test whether the IT controls your organization relies on are designed sensibly and actually operating the way your policies claim. Scope is agreed in writing before we begin, and every conclusion is supported by evidence we can show you.

Engagements cover access lifecycle, privileged access, change management, IT operations, backup and restore, vendor oversight and the application controls that matter to your reporting or regulatory obligations.

When this helps

Situations we are usually called into

  • An external auditor, lender or customer has asked for evidence that your IT controls work.
  • You inherited an environment and need an independent view of access, change and backup discipline.
  • Access reviews, joiner-mover-leaver steps or approvals happen informally and are hard to evidence.
  • You are preparing for a first assurance engagement and want to find control gaps before someone else does.
  • A prior audit raised IT findings and you need a structured plan to close them.

Scope & deliverables

What the engagement covers

Access and privileged access

How accounts are requested, approved, provisioned, reviewed and removed, and how administrative rights are controlled.

  • Joiner, mover and leaver steps and their evidence
  • Periodic user and privileged access reviews
  • Administrator, break-glass and service account handling
  • Authentication settings, including multi-factor coverage

Change management and development

Whether changes to systems and applications are authorized, tested and traceable.

  • Change request, approval and testing records
  • Separation between development and production
  • Emergency change handling
  • Release and rollback evidence

IT operations, backup and restore

The day-to-day disciplines that keep systems available and recoverable.

  • Job monitoring, incident and problem handling
  • Patch and vulnerability remediation records
  • Backup configuration and restore testing
  • Logging and monitoring coverage

Vendor and application controls

Third parties and in-scope applications that affect your data or reporting.

  • Vendor inventory, contracts and assurance reports on file
  • Review of third-party reports such as SOC 2 reports you receive
  • Application input, processing and interface controls in scope
  • Segregation of duties within key applications

What you receive

  • Written scope, control list and testing approach agreed before fieldwork
  • Workpapers recording the population, sample, test performed and result
  • Findings rated by risk with the evidence behind each conclusion
  • Remediation plan with recommended owners, sequence and effort
  • Management summary suitable for leadership or a board committee
  • Optional retest of remediated controls in a later period

Design effectiveness versus operating effectiveness

Testing design asks whether a control, if performed as described, would address the risk. Testing operating effectiveness asks whether it was actually performed throughout an agreed period. Operating-effectiveness conclusions depend on the period, the population available and the sample tested, so a clean result applies to that scope and period, not to your environment forever. Where records do not exist for a period, we report that limitation rather than infer a pass.

How we work

A five-step engagement

  1. Step 01

    Scope and plan

    Agree objectives, in-scope systems, the control list, the period under review and who provides evidence.

  2. Step 02

    Walkthroughs

    Interview control owners, document how each control is performed and confirm the design against your policies.

  3. Step 03

    Testing

    Request populations, select samples, inspect evidence and record every test in a workpaper.

  4. Step 04

    Findings and validation

    Share draft findings with owners, confirm facts, remove misunderstandings and rate the remaining issues by risk.

  5. Step 05

    Report and remediation

    Deliver the report and remediation plan, then walk leadership through priorities and optional retest timing.

Working together

What we need from you, and how we handle your data

Your responsibilities

  • Name a coordinator who can reach control owners and system administrators.
  • Provide read-only or evidence-level access for the systems in scope, or extract evidence for us.
  • Supply complete populations for sampling, such as user lists, change logs and ticket exports.
  • Confirm the review period and any known gaps up front so testing is not built on incomplete data.

Data handling

  • We request the minimum evidence needed for the agreed tests and prefer redacted extracts where they are sufficient.
  • Evidence is exchanged through a channel we agree in writing before the engagement starts.
  • Workpapers are retained for a defined period stated in the engagement letter and then deleted on request.
  • Findings are shared only with the recipients you name.

How we use enquiry information is set out in our privacy policy.

FAQ

IT Audits & Controls Assessments: common questions

Is this the same as a financial statement audit?

No. We are not a CPA firm and do not issue audit opinions on financial statements. We perform IT controls assessments that management, or your financial auditors, can use as input. Where your external auditor tests IT general controls, our work helps you prepare and remediate rather than replace their testing.

How long does an IT audit take?

Most engagements run between two and six weeks of elapsed time. The main drivers are the number of in-scope systems, how quickly complete populations arrive and whether control owners are available for walkthroughs.

Do you need administrative access to our systems?

Usually not. Read-only or evidence-level access is enough for most testing, and in many engagements your team exports the evidence instead. We agree the access model in writing before fieldwork.

What happens if you cannot test a control?

We report it as a scope limitation with the reason, for example that logs were not retained for the period. We do not record an untested control as effective.

Can you help fix the findings you raise?

Yes, as a separate remediation engagement. When we have performed the assessment we will state that clearly so you can decide whether independence matters for your purposes, for example when a third party relies on the report.

Will you retest after we remediate?

Retesting is available once the control has operated long enough to produce evidence. We agree the retest period and scope separately.

Discuss an IT audit

Tell us which systems and period you need covered and we will come back with a scope, timeline and evidence list.

Stay Updated. Stay Ahead.

Subscribe to receive the latest business insights, technology updates, company news, and useful ideas delivered to your inbox.

We respect your privacy. Unsubscribe at any time.