Workiva advert Ideagen advert TeamMate

IT auditing and cyber security

IT is a broad term that is concerned with managing and processing information. It affects an organisation's strategy, structure, marketing and operations. Areas encompassed by IT that relate to internal audit include:

  • IT governance
  • information security
  • system development and implementation
  • business continuity
  • networking and telecommunications

Internal auditors are increasingly being expected to provide assurance that their organisation is managing the risks new technologies present. Our series of guidance examines the key issues. 


Artificial intelligence

New: Artificial intelligence – considerations for the profession of internal auditing

Organisations are investing in artificial intelligence research and applications to automate, augment, or replace human intelligence. Internal audit is well-suited to be a key contributor to an organisation’s artificial intelligence related activities. Whether lending advice on implementation or providing assurance on reliability, internal audit can positively influence the adoption of artificial intelligence.

This report on artificial intelligence is part one of a three-part series from IIA Global and outlines five critical and distinct internal audit activities related to artificial intelligence.

Published: October 2017


Cloud computing

The main concern about cloud computing is the fear that it might be insecure. Sensitive data may be open to change, loss and theft.

Read more about cloud computing


Cyber security

Cyber security is concerned with minimising any risk of financial loss, disruption or damage to the reputation of an organisation that arises from the failure of its information technology systems.

Read our guidance on how to audit cyber risk and our short board briefing. IIA Global have also published a paper on what board directors need to ask about cyber security.


Data analytics, data mining and big data

If you work in an environment that uses big data, you'll need knowledge of data analytics, statistical modelling and IT security in order to provide assurance in this area. This guide explains the key concepts and provides questions for internal audit to consider.

Read more about big data

Good practices for (smaller) internal audit functions

This analytics report from IIA Netherlands seeks to provide practical applications of analytics, particularly smaller internal audit functions by assessing experiences, needs and leading analytical practices.

Published: August 2017


General Data Protection Regulation (GDPR)

With GDPR coming into force on 25 May 2018, organisation need to take action now. Internal audit should be involved at all levels, to help management better understand and mitigate the related risks.

Read our guide and handy self-assessment table


GTAGs: guides on technology risks and controls

IIA Global's Global Technology Audit Guides cover technology-related risks and recommended practices. Each GTAG covers a specific risk and describes the type of controls that can be implemented and tested.


Impact of digitisation on the internal audit function

As businesses transform, internal audit needs to keep pace with developments. This will impact not only the type of internal audits undertaken and the way assurance is provided, but the skills required and the audit methodology itself. 

Read our guide and be ready


Want to become an expert in IT auditing?

We offer a few services that will help you specialise in this area:

  1. Develop your expertise in IT by taking our IT Auditing Certificate, which is designed for qualified internal auditors.

  2. Take one or both of our courses on information systems auditing. We offer an introduction course and an advanced course on this subject.
  3. Join the Information Security Special Interest Group which supports practitioners working in areas of computer audit and information security.

External resources

There's an array of online resources that can help organisations develop, manage and secure IT, some of which are focused upon the identification and assessment of risk.

International Standards Organisation
A range of standards relating to IT governance and business continuity. Perhaps the most well known of these is the ISO27000 series that provides a process approach to establish a risk based information security management systems (ISMS).

Information Systems Audit and Control Association
ISACA has designed an IT governance model known as Control Objectives for Information and related Technology or CoBiT. Its website includes both information and computer assisted audit techniques, some of which can be downloaded for free.

UK Department for Business Innovation and Skills
Advice on policy to embed good information security practice within the UK business community.

Content reviewed: 1 November 2017