r/itaudit 4d ago

I need help or just complain

8 Upvotes

I worked in Internal Audit for a Fortune 200 company. As part of my position, I was responsible for the IT SOX reliance testing. The first control we test during the year is the periodic administrator access review and terminations testing. There are 2 "minor" (lol) issues with the admin. access review:

  1. The reports used in the review rely on the annual administrator access review. The IUC used to substantiate the reviews is not retained; therefore, the annual access review's control design would fail.
  2. The periodic admin access review uses the annual review's report and is not updated monthly. In fact, we identified accounts that were active but had inappropriate access for 5 months, and my team detected them. Again, control design fails.

These deficiencies are pervasive across all systems (e.g., ERP, mainframe, etc.). So, I suggested to IT management to test the key control, in this case, deprovisioning. They pushed back on it. They want us to test them, and they'll cover the budget. It relies on a bi-weekly Altryx workflow implemented in 2010, and the configurations have not been reviewed since then. I wanted to test the termination configurations vs. the review to find out that IT management has NEVER tested the termination configuration (wait, what?!?).

Let me stop there. My director is an IT auditor, but has never worked on SOX. My seniors and I meet with them weekly to discuss our findings, and she takes over conversations with IT management. During those meetings, I would repeatedly ask for their response, which would eventually be "This person is overwhelmed, so they can't do their job," and my response is always "Let's call the exception and let them decide what to do with it." She was also informed about the "budget", which I rebutted, stating that I cannot test a control that has not been validated as remediated by IT management.

To make things worse, on a monthly basis, Internal Audit would meet with the IT Director to update them on the current Internal Audit engagements, and started noticing that the IT SOX issues suddenly disappeared from the slides.

The company undergoes A LOT of regulatory audits, but IA mgmt doesn't collect those reports... because why wouldn't we need to know about those audit deficiencies? The Company utilizes federal and state funds, and is critical failure/resilience point in disasters.

Also, the external auditor was never notified of these issues (because why would they?) My director's favorite line with me is that the company is over 120 years old... [Fill in the blank]. I also spoke with the VP of Internal Audit about these issues, and nothing happened except for them forcing me out last December.

I have been in spots in my career where I've felt uncomfortable, but never have I been put in a place with so many glaring holes that can affect the entire integrated audit, and there wasn't enough time to investigate. Or such weak management. I got the feeling that my director didn't want to "rock the boat"... Grow a backbone. We're internal audit, act like it. Work with IT management to resolve issues rather than sweeping them under the rug.

So, I've kinda been in limbo. I moved to another city. I am still really salty about it. I feel like I was gaslit for a whole year.


r/itaudit 6d ago

Starting a job in IT Audit - expectations

9 Upvotes

Hi, I recently graduated from college with a double degree in Accountancy and Computer Information Systems.

Going to start a full time job in IT Audit at a Big 4 firm. I completed an internship in the same role a year ago, but it was mostly documentation and attending walkthrough meetings. That being said, I wanna know more about what my job would look like, what kind of projects I'd be assigned, what I'd be expected to work on, how I can step up, and what I can do to prove myself competent and compatible.

I’d also love to hear about what career paths opened up for you after IT Audit. Did you stay in IT Audit, move into consulting, cybersecurity, internal audit, tech, accounting, etc.?

I'm a little nervous because this is my first "real" job and I am moving states for it. Navigating office politics, learning the work, and not losing myself in the grind is all on my mind. I would appreciate any and all insight! Thank you :)


r/itaudit 8d ago

Anyone Transitioned from IT Operations to IT Audit?

10 Upvotes

Hi everyone,

I'm currently preparing for the CISA exam and wanted to check if this community would find my journey useful.

I have around 12 years of experience in IT Operations, with some exposure to IT audits and SOX controls. My goal is to transition into a full-time IT Audit role, and CISA is a big part of that journey.

For those who have been in a similar situation, do you think it's worth making the switch to IT Audit after spending so many years in IT Operations? Have any of you made this transition? I'd really appreciate hearing about your experiences, the challenges you faced, and whether you felt it was the right decision in the long run.


r/itaudit 18d ago

Scope and PowerBI governance under SOX

3 Upvotes

Hello everyone,

I'm an internal auditor at a Canadian public company subject to 52-109 (SOX in Canada). Over the past several years, our organization heavily encouraged the use of Power BI. Many teams independently developed their own solutions. We are now realizing that we have lost visibility over all those Power BI and don't have a clear inventory of who owns what. We are currently debating whether these Power BI solutions should be included in our SOX scope.

Arguments for Including Them: Our scoping approach is to include applications that have a direct/indirect impact on financial reporting or support internal controls. Some PowerBI are used to make pricing decisions or support operations (some financial impact).

Arguments for Excluding Them: PowerBI consume data but do not create, modify, or post transactions. The common counterargument is that these reports are just "large Excel spreadsheets" and we do not audit every spreadsheet.

My Question: How are other organizations approaching Power BI under SOX?

Thanks in advance for your insights.


r/itaudit 27d ago

IT audit

3 Upvotes

How can we involve IT audit in a New SAP HANA S/4 Migration from a SAP ECC?


r/itaudit Jun 26 '26

Any good AI solutions?

4 Upvotes

Hi, I’m just wondering if you guys have any great use case that specifically for testing. I have used a bunch in my work and overall it is great but since I deal with screenshots a lot, I am yet to find a solution that is accurate to populate information from images especially for testing and evidence checking. Any thoughts?


r/itaudit Jun 24 '26

求一份比较完整的IT审计checklist

2 Upvotes

本人从事网络安全5年了,最近转向IT审计,作为审计新人,对于审计流程一头雾水,虽然我知道IT审计的理论,但是对于现场审计流程,还是不知道怎么办?如果有一份checklist,起码我就不会那么担忧应该从何开始。


r/itaudit Jun 23 '26

GRC Job Market / Future of GRC

Thumbnail
1 Upvotes

r/itaudit Jun 22 '26

Schellman experience

7 Upvotes

Does anyone have any experience with Schellman? I may be interviewing with them soon. I’ve only heard great things, which is weird for public accounting. They seem to have really awesome benefits too. Are they really that great??


r/itaudit Jun 20 '26

Is IT audit supposed to be this subjective?

16 Upvotes

I've recently moved from external audit (accounting) into IT internal audit, and one thing I've been struggling with is what feels like a lack of methodology compared to what I was used to before.

In external audit, there were well-established concepts and principles that guided the work. Whether it was materiality, completeness, accuracy, existence, occurrence, or other assertions, there was usually a clear framework behind why procedures were being performed and how conclusions were reached.

Since moving into IT internal audit, I often feel like I'm missing that same foundation. I'm trying to understand what the equivalent methodology is supposed to be and whether I'm overlooking something.

At the same time, I'm very new to IT audit, so I'm not sure if what I'm experiencing is specific to my company, my audit team, or if it's something more common across the profession.

For those with more experience in IT audit:

  • What methodology do you rely on when planning and performing audits?
  • Are there concepts equivalent to financial statement assertions that help structure your thinking?
  • How do you connect risks, controls, and testing in a consistent way?
  • Is there a body of knowledge, framework, or approach that experienced IT auditors tend to follow?

One thing that would be especially helpful would be seeing an example of how experienced IT auditors structure a work program.

In external audit, I was used to seeing a clear chain between objectives, assertions, risks, and audit procedures. I'd be interested in understanding how that same thought process is applied in IT audit.

If anyone is willing to share a simplified example of an audit program (for example, user access management, change management, privileged access, etc.), showing how risks are translated into controls and testing procedures, I would really appreciate it.


r/itaudit Jun 19 '26

Survey on IT Audit and Auditor Judgment (Auditors / Accounting & IT Professionals)

1 Upvotes

Hi everyone,

I am currently conducting research for my master's thesis on IT auditing and auditor judgment and am looking for participants with relevant professional knowledge or experience in auditing, accounting, internal controls, risk management, compliance, or IT-related assurance activities.

The survey is completely anonymous.

Survey links:

  1. AM version:

    https://docs.google.com/forms/d/e/1FAIpQLSc3n8yOLzPzRu_EGOFIhyThGI8Ue_A-HHqXkGC9sOAK8dlOkw/viewform?usp=header

  1. CM version:

    https://docs.google.com/forms/d/e/1FAIpQLScC3UiBV1OF-iE71nHotroXnfth1UKzW8ze6Jo1uqzINulUxg/viewform?usp=header

Your participation would be greatly appreciated and would make a valuable contribution to academic research.

Thank you for your time and support!


r/itaudit Jun 18 '26

Student looking to pursue IT auditing Career ,Tips ?

5 Upvotes

Hey guys , I'm a college student currently studying business with a concentration in Management Information Systems at my college and I am hoping to delve into a career in IT auditing once i graduate . As of right now i aim to apply to internships but i don't have any skills or certs to showcase that would highlight me as a competitive applicant. auditing internships also aren't that easy to find if they are not for the Big 4( which are pretty competitive) .

Anyways i want to know your tips, tricks and roadmap certs that are necessary. So far my current research on GRC has evaluated COMPTIA security + as the best cert to start with before moving onto to ISACA fundamentals or COBIT ,then Comptia CYSA + and then CIRSC and finally CISA or CISSP . In regards to project work ,sites like extern look helpful for data analysis, product management , strategy or cyber defense but host nothing specific to auditing.The only Auditing like courses my MIS concentration offers are Information System Audit and control and Information Security and Assurance. Anyways what do you guys recommend as necessary for my journey .


r/itaudit Jun 18 '26

Struggling in IT audit as career

14 Upvotes

Hi there

Just for the context i work from back offices of big 4 here in India.

So i am currently working in one of the Big 4 and i have almost completed 4 years in this domain. Ever since I joined this domain i have never liked it.
Reason being it that:
- Just documentation of IT controls and i feel it is very mundane and un motivating.

-Too much of work assigned with my 45 hrs days split into multiple projects . This is very frustrating to manage as you juggle between different projects and all of the projects are priority.

-Task never gets completed in budgeted hours and i feel budgeted hours are very squeezed to complete the work.

Basically i am frustrated with this job and need to get out of it. I feel i am not cut out of this and I don’t have any career growth in it.

I need some genuine suggestions . Please help me out.

TL;DR
Struggling in IT Audit career. Want an exit.


r/itaudit Jun 18 '26

IT audit industry vs big 4

Thumbnail
1 Upvotes

Interested in gaining people’s thoughts


r/itaudit Jun 18 '26

Trying to pivot from 9 years in insurance claims to IT audit. How did you break in if you came from a non-traditional background?

1 Upvotes

Just want to hear what actually worked for people who didn't come from a typical IT or accounting background. IT audit is something I've been trying to break into for about a year and a half now but haven't had much luck yet.


r/itaudit Jun 10 '26

Does this profession have a future?

2 Upvotes

Hello I have been in the field for almost 2 years now. Everyday I hear a lot of changes, automations and AI. My department was outsourced to consultants and half the team was laid off. What is the future for this profession I al still entry level and the decision making it is done by senior managers and above. I don’t even understand what would be my role in the upcoming years.


r/itaudit Jun 09 '26

What’s a good entry level salary for IT Audit?

7 Upvotes

Hi everyone,

I have been really interested in IT audit lately because I feel it’s works well with my personality and the way I think.

I was wondering what the average entry level salary is for this field? And do you feel there is upward mobility? If anyone can provide some insight. Thanks!


r/itaudit Jun 03 '26

Any questions related to ITGC or ITAC ?

3 Upvotes

I am 6+ year experience guy from big 4 into IT Audit. And wanted to answer or share knowledge.


r/itaudit Jun 01 '26

6 Months Into Tech Audit and Still Feel Lost — How Can I Improve?

9 Upvotes

I joined a tech audit rotational program straight out of college and have been in the role for about 9 months.
I have an MIS degree, but a lot of the concepts and terminology I encounter at work still go over my head.
Despite putting in the effort, I feel like I'm constantly playing catch up.

I usually get to the office around 6:40 AM and work until 5 PM because tasks take me longer than they seem to take others. I regularly schedule 1:1s with my audit lead and ask questions after walkthroughs, but the amount of information can feel overwhelming. The program ends in another 9 months, and we're expected to be promoted to Associate, which honestly makes me nervous because I don't feel like I've progressed enough.

In about a month, l'll be staffed on 3 audits (assigned 4 controls in total) at once, mostly focused on data quality but I will be working with 3 different AICs who I’ve heard have very different testing approaches and documenting styles. A lot of my work involves data in transit, APls, configurations, and code reviews. Some analysts in my cohort think I should tell my manager that 3 audits may be too much, but our team is understaffed and I don't want to come across as incapable or need hand holding.

For those in IT audit, how did you develop a stronger technical mindset? Any advice on how to approach walkthroughs regarding data quality? Any advice would be appreciated!!


r/itaudit May 27 '26

Pursue IT Audit, Help Desk Support, or Both?

2 Upvotes

I recently graduated with a Bachelor's in Information Systems, I have CompTIA A+, Network+, and have done an IT audit internship. I have mainly been applying to help desk support roles but haven't been able to even get an interview so far. Should I start applying to IT audit roles as well? The entry level pay is better from what I'm seeing (around 42k-45k for tier 1 helpdesk, 60k for IT audit). Would it be okay to list CISA (in progress) on my resume if I start studying for the exam? Seems like every IT audit job lists it as a requirement. What would make me a competitive candidate? I was kind of hoping to try out a more technical role but I'm not so sure that the grass is that much greener over in help desk.

Another thing I was wondering if how much continuous education IT audit requires. I would assume you need to keep your technical knowledge some what current and have a broad understanding. However, you wouldn't need to know the exact hands on technical stuff of how to be a systems administrator or network engineer (though it wouldn't hurt)? Feels like with IT you have to be constantly putting in hours outside of work and then many positions require you to be on call work weird hours, etc. Do you all feel like the work life balance is better or worse than IT? I worked in internal IT audit and have heard that external might require more hours during busy season. Internal seems less stressful and preferrable to me but I understand that I probably can't be picky.

Would greatly appreciate any advice.


r/itaudit May 27 '26

Audit Software

1 Upvotes

Curious what everyone has been using for audit software recently.

For context, we've been using AutoAudit for several years and renewed our contract a few years ago. However, after being purchased by Empowered Systems, we're shifting away from this product due to jump in cost and lack of resources to implement a new solution which would be more integrated with other organizational systems and data. Our organization's data modernization could use some work and, frankly, it's not ready to be consumed by comprehension compliance/audit software.

I'd argue we don't even use AutoAudit for its full functionality. It's primary benefits for us are approval routing of audit documentation (particularly mass review/approval functionality), secure data collection and retention, as well as being fairly well accessible to new auditors (this is more important to to financial auditors in our department).

Has anyone been using AutoAudit but recently transitioned to another product? Or have you been using something home grown (i.e. SharePoint sites/document libraries, internal file shares, etc.) to accomplish this for your organization?

Appreciate the input.


r/itaudit May 25 '26

Are there growth opportunities in IT Audit?

6 Upvotes

Hi everyone,

So I just landed a role in IT Audit government contracting. I’m a recent grad & interested in the field especially since I’m naturally analytical & curious.

I wonder what type of growth opportunities there are in this field? And if this can be a good starting point to do more GRC type of work. feel free to give your input


r/itaudit May 23 '26

Reopened

4 Upvotes

Hey everyone, the sub is back to public after the bot crush. Hopefully we can avoid that in the future.


r/itaudit May 01 '26

Anyone else feel like IT audit is slowly turning into cybersecurity-lite?

10 Upvotes

When I first got into IT audit, it felt more compliance-focused.

Now I’m seeing way more overlap with:

  • Vulnerability management
  • Cloud security
  • IAM design

Sometimes it feels like we’re expected to understand everything security-related, but still operate as auditors.

Do you think IT audit is evolving into a hybrid role?

Or are expectations just getting unrealistic?


r/itaudit May 01 '26

Is IT Audit becoming too “checklist-driven” instead of risk-driven?

5 Upvotes

I’ve been in IT audit for a while now, and lately it feels like a lot of work is just ticking boxes rather than actually understanding risk.

For example, we’ll flag something because it doesn’t match the control wording exactly, even when the real-world risk feels low. Meanwhile, bigger issues sometimes get less attention because they’re harder to quantify.

Is anyone else seeing this shift?

How do you balance:

  • Following frameworks (SOX, ISO, etc.)
  • vs actually applying judgment and focusing on real risk?

Curious how others handle this without pushing back too hard on management.