Practical IT Audit Bootcamp
Registrations for this batch are now closed.
Next batch coming soon!
We are
now! Registrations
open until 11 Am.
IT audit requires more than knowing control names. Professionals need to understand how controls work in real business systems, how to test them, how to evaluate evidence, and how to write findings that can stand up to review.
This practical workshop helps junior auditors, GRC professionals, risk analysts, and audit professionals build real-world IT audit skills across ITGCs, IT application controls, walkthrough documentation, evidence validation, issue writing, and executive reporting. The focus is deliberately limited to ITGC, ITAC, and audit reporting so participants can go deep enough to start applying the concepts on real audit engagements.
C.K Kulkarni
C.K Kulkarni is an AVP-level Cyber Audit professional at a leading global investment bank with Big Four technology audit experience across ITGC, ITAC, SOX, SOC, scoping, stakeholder communication, and executive reporting. He simplifies complex audit concepts into practical learning, helping auditors understand what to test, how to document, and why audit judgment matters in real engagements.
- IT General Controls and IT Application Controls
- SOX and SOC audit engagements
- Audit scoping and risk-based planning
- Control walkthroughs and documentation
- Evidence review and control testing
- Audit issue writing and risk articulation
- Stakeholder communication and control owner discussions
- Executive reporting and audit conclusions
- Technology audit and cyber audit
- Practical audit judgment for real engagements
Special Offer! Limited Time Only
MODULE 1: Orientation: IT Audit in the GRC Ecosystem
- What is IT Audit?
- Why technology matters in financial audits
- Types of audit: External, Internal, Tech Risk
- Role of IT in ICFR / SOX
- Where IT audit fits in Three Lines of Defense
- Audit vs compliance vs risk vs security: who does what
MODULE 2: Understanding Audit Lifecycle
- What is an audit lifecycle?
- Phases of an audit lifecycle – pre-planning, planning, fieldwork, socialization, reporting
- What can go wrong in each phase?
MODULE 3: Pre-planning and Planning
- Understanding audit universe
- Risk Assessment and audit universe for audit plan
- Understanding business processes under audit in detail
- Where does IT come into each process?
- Identifying applications and system dependencies
- Practical: Process flow mapping
- Purpose & outcomes; how risk informs audit scope
- Practical: Define scope: processes, systems, data
- Write clear risk statements: asset–threat–vulnerability–impact
- Practical: Draft 5–7 risk statements for ITGCs and ITACs
MODULE 4: Introduction Into Fieldwork
- What is “testing” a control?
- Understanding Phases of Testing – Design vs Operation
- Understanding types of controls to test – Manual vs Automated vs IT Dependent Manual Controls
- Sample size, test design, exceptions, root cause analysis
- What is a walkthrough and why it matters
- What is good vs bad documentation
- How to structure walkthrough notes: who, what, why, how
- Practical: Sample walkthrough note for Change Management
- Practical: Review exercise: Poor walkthrough notes vs improved version
- Practical: Creating flowchart from walkthrough
- Practical: Follow-up tracker and documentation hygiene
MODULE 5: Introduction Into IT General Controls
- What are ITGCs?
- Types: Access Control, Change Management, IT Operations
- Practical: Real-world examples of each control
- Practical: Mapping ITGCs to Business Processes
- Practical: Sample walkthrough: Access Management
MODULE 6: Access Management Controls
- What is access management?
- Risks: Unauthorized access, privilege access, SOD violation
- Examples: New user provisioning, termination, reviews
- Common applications: SAP, Workday, Active Directory
- Practical: Designing walkthrough questions for Access controls
- Practical: Sample evidence: Review of terminated user removal in Workday
- Practical: Writing test procedures: Provisioning and Termination
- Regulatory & framework overlays: SOX 404, ISO 27001 A.5/A.6/A.8, PCI DSS Req. 7
MODULE 7: Change Management Controls
- What is change management in IT audit?
- Risk: Unauthorized/untested changes impacting financial processing
- Change types: Normal, Standard, Emergency
- Attributes of a well-controlled change process
- Who performs what: Requestor, Approver, Implementer
- Practical: Sample walkthrough script for Change Management
- Practical: Writing design attributes: What to look for
- Framework overlays: ISO 27001 A.8.32/A.8.33, COBIT BAI06
MODULE 8: IT Operations: Jobs, Backups, Resilience
- What is the control? Job monitoring, backup/restore, HA/DR
- Risk: failed jobs, data loss, untested restores, RPO/RTO misses
- Practical: Design attributes: job alerts, exception handling, backup frequency/retention, restore tests
- Practical: Things to look for: success/failure logs, aging of exceptions, dual control on restores
- Practical: How to test: job failure trail; backup job logs; evidence of periodic restore tests
- Overlays: ISO 27001 A.5/A.8.13/A.8.14, ISO 22301
MODULE 9: IT Application Controls: ITAC
- What are ITACs?
- 6 Types of ITACs
- Risks: System misposting, wrong GL impact, user override
- Example: JE posting only to open periods
- Practical: Walkthrough documentation for ITAC
- Practical: Designing test steps for ITACs
MODULE 10: Writing Audit Issues
- What qualifies as a real issue vs. a non-issue: the “so what” test — risk and impact
- Components of an issue statement: Condition, Criteria, Cause, Effect/Risk Exposure, Recommendation
- Impact assessment — financial, operational, regulatory
- Probability/likelihood assessment — frequency of the underlying process, role of compensating controls
- Practical: Writing issue language — neutral, factual, defensible without you in the room
- Practical: Common mistakes in issue language — blame, absolutes, vague wording
- Negotiating and agreeing issues with control owners — handling pushback, separating fact disputes from severity disputes
MODULE 11: Audit Report Writing & Executive Reporting
- Purpose of the report — who actually reads it, and what decision it needs to enable
- Components of an audit report: Executive Summary, Scope, Objective, Overall Conclusion, Detailed Findings, Management Response, Overall Risk Rating
- Sequencing findings — by severity, not by order discovered
- Practical: Executive Summary language — writing for a reader who won’t read the detail
- Report language principles
- Overall audit conclusion — how it’s derived from individual findings, and how one finding can or cannot outweigh others
- Rating the report/engagement overall — connecting individual issue impact to an overall opinion
- Timeline management — draft report, management response window, final report issuance, follow-up scheduling
- Practical: Common report-writing mistakes — burying the real risk, overly technical language, inconsistent severity ratings across findings
*Note: Participants will have access to session recordings for a period of 60 days.
Special Offer! Limited Time Only
Interested in Joining the
Our advisor will contact you with event details, and exclusive offers!