IT Audit
An independent review of how your IT is governed, operated and controlled, measured against the frameworks your auditors, regulators and customers expect.
Request a proposalWhat it is
An IT audit checks whether the controls that protect your systems and data are designed well and work in practice. We review evidence, interview the people who run the controls, and test samples to see whether what is written down matches what actually happens.
Typical engagements include IT general controls (ITGC) reviews, ISO/IEC 27001 readiness assessments, and reviews of information security policies, standards and procedures.
-
IT general controls (ITGC)
Access management, change management, IT operations, backup and recovery, and program development.
-
ISO/IEC 27001 readiness
Gap assessment of your information security management system (ISMS) and Annex A controls before certification.
-
Policy and controls review
Review of policies, standards and procedures for completeness, clarity and alignment with practice.
Who needs it
IT audit is usually the right starting point if you:
- Are preparing for an external financial audit and need confidence in your IT general controls
- Plan to pursue ISO/IEC 27001 certification and want to know how far you are from it
- Must show regulators, customers or partners that your controls are working
- Have grown quickly and are unsure whether policies still match how the business operates
- Want an independent view before a merger, acquisition or major system change
Our approach
-
Plan and scope
Agree objectives, the framework to audit against, in-scope systems and processes, and an evidence request list.
-
Understand the environment
Walkthroughs and interviews with system owners to understand how each control is meant to work.
-
Test the controls
Assess design, then test operating effectiveness by sampling evidence such as access reviews, change tickets and backup logs.
-
Rate and report
Rate each gap by risk and likelihood, agree factual accuracy with your team, and issue the final report.
-
Support remediation
Help prioritise fixes and, if requested, review updated evidence to confirm gaps are closed.
Deliverables
-
Executive summary
Overall control maturity, the most significant risks, and recommended priorities in business language.
-
Detailed findings
Each gap with the control reference, evidence observed, risk rating and a specific recommendation.
-
Control matrix
A worksheet mapping every in-scope control to its test result, for tracking and for your auditors.
-
Remediation roadmap
A prioritised, time-phased plan showing what to fix first and who should own it.
Frequently asked questions
Is this the same as an ISO/IEC 27001 certification audit?
No. Certification can only be issued by an accredited certification body. Our readiness assessment tells you how prepared you are and what to fix before you book that audit.
How long does an IT audit take?
It depends on scope. A focused ITGC review of a few key systems is usually much shorter than a full ISO/IEC 27001 readiness assessment. We give you a timeline with the proposal once scope is agreed.
What do you need from us?
A named point of contact, access to the people who operate the controls, and the evidence on our request list. We keep the list focused to limit disruption.
Can you also write our policies?
Yes. After a review we can help draft or update policies and procedures. Where independence matters, we will tell you if doing both could create a conflict.
Ready to find out where you stand?
Tell us about your environment and goals. We will reply with a suggested scope and next steps.