Skip to content

Audit & Assurance

Information Systems Audit

A broader engagement than ITGC. An IS audit examines whether your technology estate as a whole is governed, controlled and operated in a way that supports the business and satisfies whoever is asking the question.

Scope

IS audit is deliberately wide. Where ITGC answers "can we rely on this system", IS audit answers "is technology in this organisation being run properly". The domains below are the standard universe; a given engagement will take a risk-weighted subset agreed at planning.

  • IT governance and organisation — strategy alignment, steering structures, IT budget and value delivery, reporting to the board.
  • IT risk management — risk identification, the risk register, treatment decisions and residual risk acceptance.
  • Infrastructure and network — architecture, segmentation, hardening baselines, patch and vulnerability management, endpoint controls.
  • Application controls — input validation, processing integrity, interface and reconciliation controls, audit trails.
  • Data management — classification, retention, integrity, database security, backup and archival.
  • Third-party and outsourcing — due diligence, contractual control requirements, right to audit, ongoing monitoring, concentration risk.
  • Business continuity and disaster recovery — plans, RTO and RPO definition, and evidence of live testing.
  • Information security — the security programme, incident management, monitoring and logging, awareness.

How we keep it independent

We do not implement the systems we audit, and we do not sell the products we recommend. The finding you receive is not a lead-generation exercise for another part of the firm. Where a remediation clearly needs a vendor, we tell you the control requirement and let you run your own procurement.

How an IS audit runs

1 Plan 2 Walkthrough 3 Design 4 Operating 5 Validate 6 Report Every exception is validated with the control owner before it becomes a finding
Risk-weighted coverage, evidenced testing, findings reported with root cause.

How the engagement runs

  1. 1

    Engagement setup

    Agree objectives, scope boundaries, reporting lines and the audit universe with the audit committee or sponsor.

  2. 2

    Risk assessment

    Score auditable areas by inherent risk and control maturity so effort lands where it matters, rather than being spread evenly.

  3. 3

    Programme design

    Build the control objectives and test procedures for the selected areas, referenced to ITAF and the relevant framework.

  4. 4

    Fieldwork

    Interviews, walkthroughs, configuration review, sample testing and, where in scope, technical validation.

  5. 5

    Analysis

    Aggregate exceptions into themes with root cause, so the report drives systemic fixes rather than a list of one-offs.

  6. 6

    Reporting

    Draft, clear with management, finalise, and present to the audit committee.

What you receive

Risk-assessed audit universe with rationale for what was and was not covered
Detailed audit programme aligned to ISACA ITAF
Complete working paper file suitable for external auditor or regulator inspection
Findings rated by significance with root cause and business impact stated
Prioritised remediation roadmap with realistic sequencing
Board and audit committee presentation

Frequently asked questions

A penetration test asks whether a specific system can be broken into at a point in time. An IS audit asks whether the organisation has the governance, processes and controls to keep systems secure and reliable over time. They answer different questions and most regulated organisations need both. We often run a targeted penetration test as a technical work stream inside a wider IS audit.

Usually read-only access to configuration and logs, plus the ability to observe an administrator performing an action. We work under an agreed access protocol, use named accounts issued to us, and hand them back at closing. Where read-only access cannot be granted, we test through supervised screen-share walkthroughs instead.

Yes, and it is a common arrangement. Your internal audit team owns the plan and the relationship with the audit committee; we provide the IT specialist capability for the technology portion. Your Chief Audit Executive retains the opinion.

Related services

Related regulatory frameworks

Need an independent view?

Tell us the scope, the regulator and the deadline. We will come back with an approach, a team and a fee estimate.

Request a proposal
Top