How the IT Audit Process Works
The IT audit process follows the same broad path, whether it is an internal review or an external certification. Knowing the stages helps leaders set expectations and helps teams see where their effort goes.
The IT Audit Process in Five Stages
- Scope. Agree on the systems, locations, time period and standard the audit covers.
- Assess risk. Rank systems and processes by how much damage a failure could cause, so testing goes where it matters.
- Test controls. Review design documents, interview owners, sample records and check live settings to see whether each control works.
- Report. Write up findings with their severity, the evidence behind them and a recommended fix.
- Remediate and follow up. Owners fix the gaps by agreed dates, and the auditor checks that each fix holds.
This is the high-level view. Our guide to running a holistic IT audit walks through how auditors scope and run each stage in detail.
What Auditors Check: IT General Controls (ITGC)
IT general controls are the base controls that every application and system relies on. If they fail, no single system can be trusted, however well it is built. That is why ITGC testing sits at the heart of most compliance audits, SOX audits in particular. Auditors usually group them into four areas.
Access Control and Identity Management
Who can log in, what can they do, and who approved it? Auditors check how accounts are created, reviewed and removed, how privileged access is limited and whether multi-factor authentication covers sensitive systems. Access control is often the area with the most findings.
Change Management
Good change management means every change to a production system is requested, approved, tested and recorded. Auditors sample changes and trace each one back to its ticket and approval. They also look for changes that skipped the process. Building security testing into the software development lifecycle makes this control much easier to pass.
Backup and Disaster Recovery
Auditors confirm that critical data is backed up on schedule, that copies are protected from tampering and that restores are tested. They compare recovery test results with the recovery times the business has agreed. Strong IT infrastructure management practices make this evidence routine.
IT Operations and Security Monitoring
This area covers how systems are watched and how problems are handled. For security monitoring, auditors check that logs are collected and reviewed. They also confirm that alerts reach someone who acts on them and that incidents are recorded and closed. A security operations center often provides much of this evidence.
After the Audit: Findings and Remediation
The report is where the real work starts. Each audit finding needs an owner, a fix and a date. Serious findings go to leadership. The auditor then tests the fixes at follow-up. Repeated findings are a warning sign, because they suggest the root cause was never addressed.
For the findings auditors raise most often and how to close them, see our guide to common IT audit findings.