Audit & Assurance
Information Systems Audit
A broader engagement than ITGC. An IS audit examines whether your technology estate as a whole is governed, controlled and operated in a way that supports the business and satisfies whoever is asking the question.
Scope
IS audit is deliberately wide. Where ITGC answers "can we rely on this system", IS audit answers "is technology in this organisation being run properly". The domains below are the standard universe; a given engagement will take a risk-weighted subset agreed at planning.
- IT governance and organisation — strategy alignment, steering structures, IT budget and value delivery, reporting to the board.
- IT risk management — risk identification, the risk register, treatment decisions and residual risk acceptance.
- Infrastructure and network — architecture, segmentation, hardening baselines, patch and vulnerability management, endpoint controls.
- Application controls — input validation, processing integrity, interface and reconciliation controls, audit trails.
- Data management — classification, retention, integrity, database security, backup and archival.
- Third-party and outsourcing — due diligence, contractual control requirements, right to audit, ongoing monitoring, concentration risk.
- Business continuity and disaster recovery — plans, RTO and RPO definition, and evidence of live testing.
- Information security — the security programme, incident management, monitoring and logging, awareness.
How we keep it independent
We do not implement the systems we audit, and we do not sell the products we recommend. The finding you receive is not a lead-generation exercise for another part of the firm. Where a remediation clearly needs a vendor, we tell you the control requirement and let you run your own procurement.
How an IS audit runs
How the engagement runs
-
1
Engagement setup
Agree objectives, scope boundaries, reporting lines and the audit universe with the audit committee or sponsor.
-
2
Risk assessment
Score auditable areas by inherent risk and control maturity so effort lands where it matters, rather than being spread evenly.
-
3
Programme design
Build the control objectives and test procedures for the selected areas, referenced to ITAF and the relevant framework.
-
4
Fieldwork
Interviews, walkthroughs, configuration review, sample testing and, where in scope, technical validation.
-
5
Analysis
Aggregate exceptions into themes with root cause, so the report drives systemic fixes rather than a list of one-offs.
-
6
Reporting
Draft, clear with management, finalise, and present to the audit committee.
What you receive
Frequently asked questions
Related services
Related regulatory frameworks
Need an independent view?
Tell us the scope, the regulator and the deadline. We will come back with an approach, a team and a fee estimate.
Request a proposal