GTAG11-coverGTAG 11: Developing the IT Audit Plan
Download (members only): PDF, 2.9MB
Purchase from The IIA Research Foundation Bookstore
Rate this guide

Results from several IIA external quality assessment reviews reveal that developing an appropriate IT audit plan is one of the weakest links in internal audit activities. Many times, internal auditors simply review what they know or outsource to other companies, letting them decide what to audit.

To this end, Developing the IT Audit Plan can help CAEs and internal auditors:

  • Understand the organization and how IT supports it.
  • Define and understand the IT environment.
  • Identify the role of risk assessments in determining the IT audit universe.
  • Formalize the annual IT audit plan.

This GTAG also provides an example of a hypothetical organization to show how to execute the steps necessary to define the IT audit universe.

TABLE OF CONTENTS
1. Executive Summary
2. Introduction

spacer2.1 IT Audit Plan Development Process
3. Understanding the Business
spacer3.1 Organizational Uniqueness
spacer3.2 Understanding the Operating Environment
spacer3.3 IT Environment Factors

4. Defining the IT Audit Universe
spacer4.1 Examining the Business Model
spacer4.2 Role of Supporting Technologies
spacer4.3 Annual Business Plans
spacer4.4 Centralized and Decentralized IT Functions
spacer4.5. IT Support Processes
spacer4.6. Regulatory Compliance
spacer4.7. Define Audit Subject Areas
spacer4.8. Business Applications
spacer4.9. Assessing Risk

5. Performing a Risk Assessment
spacer5.1 Risk Assessment Process
spacerspacer
5.1.1 Identify and Understand Business Objectives
spacerspacer5.1.2 Identify and Understand IT Strategy
spacerspacer5.1.3 IT Universe
spacer5.2 Ranking Risk
spacer5.3 Leading IT Governance Frameworks

6. Formalizing the IT Audit Plan
spacer6.1 Audit Plan Context
spacer6.2 Assurance and Consulting Services Requests
spacer6.3 Audit Frequency
spacer6.4 Audit Plan Principles
spacer6.5 The IT Audit Plan Content
spacer6.6 Integration of the IT Audit Plan
spacer6.7 Validating the Audit Plan
spacer6.8 The Dynamic Nature of the IT Audit Plan
spacer6.9 Communicating, Gaining Executive Support, and Obtaining Plan Approval
Appendix: Hypothetical Company Example

Authors
 

Kirk Rehage, Chevron Corp.

Steve Hunt, Crowe Horwath LLP
Fernando Nikitin, Inter-American Development Bank

 

Questions for the authors about this guide? E-mail technology@theiia.org.

 

 
© 2010 The Institute of Internal Auditors / 247 Maitland Avenue Altamonte Springs, FL. 32701-4201 USA / +1-407-937-1100 / FAX +1-407-937-1101 • www.theiia.org