GTAG11-coverGTAG 11: Developing the IT Audit Plan
Results from several IIA external quality assessment reviews reveal that developing an appropriate IT audit plan is one of the weakest links in internal audit activities. Many times, internal auditors simply review what they know or outsource to other companies, letting them decide what to audit.

To this end, Developing the IT Audit Plan can help CAEs and internal auditors:

  • Understand the organization and how IT supports it.
  • Define and understand the IT environment.
  • Identify the role of risk assessments in determining the IT audit universe.
  • Formalize the annual IT audit plan.

This GTAG also provides an example of a hypothetical organization to show how to execute the steps necessary to define the IT audit universe.

TABLE OF CONTENTS
1. Executive Summary
2. Introduction
spacer2.1 IT Audit Plan Development Process
3. Understanding the Business
spacer3.1 Organizational Uniqueness
spacer3.2 Understanding the Operating Environment
spacer3.3 IT Environment Factors
4. Defining the IT Audit Universe
spacer4.1 Examining the Business Model
spacer4.2 Role of Supporting Technologies
spacer4.3 Annual Business Plans
spacer4.4 Centralized and Decentralized IT Functions
spacer4.5. IT Support Processes
spacer4.6. Regulatory Compliance
spacer4.7. Define Audit Subject Areas
spacer4.8. Business Applications
spacer4.9. Assessing Risk
5. Performing a Risk Assessment
spacer5.1 Risk Assessment Process
spacerspacer5.1.1 Identify and Understand Business Objectives
spacerspacer5.1.2 Identify and Understand IT Strategy
spacerspacer5.1.3 IT Universe
spacer5.2 Ranking Risk
spacer5.3 Leading IT Governance Frameworks
6. Formalizing the IT Audit Plan
spacer6.1 Audit Plan Context
spacer6.2 Assurance and Consulting Services Requests
spacer6.3 Audit Frequency
spacer6.4 Audit Plan Principles
spacer6.5 The IT Audit Plan Content
spacer6.6 Integration of the IT Audit Plan
spacer6.7 Validating the Audit Plan
spacer6.8 The Dynamic Nature of the IT Audit Plan
spacer6.9 Communicating, Gaining Executive Support, and Obtaining Plan Approval
Appendix: Hypothetical Company Example

Authors
Kirk Rehage, Chevron Corp. : : Steve Hunt, Crowe Chizek and Co. LLC
Fernando Nikitin, Inter-American Development Bank

Download a free copy of this GTAG (PDF, 1MB).
Purchase a printed version.
Download form for permission to translate to another language(PDF, 20KB).

The Institute of Internal Auditors • 247 Maitland Avenue • Altamonte Springs, Florida 32701-4201 USA
+1-407-937-1100 • Fax +1-407-937-1101 • www.theiia.org • Copyright 2008