Skip to content

Internal and Forensic Audit · Internal Audit of Specific Functions

Internal Audit of IT and Information Systems

Updated 11 October 2026 · Fact-checked

Internal audit of IT checks whether information systems are secure, reliable and support business goals. You test IT general controls (access, change management, backup, operations, continuity) and application controls (input, processing, output) using a risk-based plan, then report gaps with fixes and follow-up.

Understand Internal Audit of IT and Information Systems

Almost every business process now runs on software. If the system fails or is misused, the numbers, the operations and the compliance all suffer. Internal audit of IT gives management and the audit committee assurance that the technology is controlled.

The audit covers two layers of controls. IT general controls (ITGCs) apply to the whole IT environment. They cover access security, change management, data backup and recovery, IT operations and business continuity. Application controls sit inside a specific system, such as payroll or billing. They make sure data is input completely and accurately, processed correctly and output reliably.

The link between them matters. Application controls work only if general controls are sound. If anyone can change a program without approval, a perfectly designed validation check can be removed. So weak ITGCs reduce your reliance on application controls.

The audit starts with risk. You understand the IT landscape, identify critical systems, and judge risks such as unauthorised access, data loss, unapproved changes, system downtime and cyber attacks. Your testing then focuses on the high-risk areas. Techniques include inquiry, inspection of logs and approvals, observation, re-performance and, where useful, CAATs.

The internal auditor does not run IT. The role is independent assurance and recommendations. Findings go to management and the audit committee, with follow-up on agreed actions.

Key rules to remember

Two layers of IT controls
IT controls = General controls (environment) + Application controls (each system)
General controls support all applications; application controls are specific to one process.
Application control categories
Input controls → Processing controls → Output controls
Examples: validation checks, batch totals, reconciliation of outputs, exception reports.
ITGC areas to remember
Access security + Change management + Backup and recovery + IT operations + Business continuity
Use this as a checklist for any ITGC question.
Access principle
Least privilege + Segregation of duties + Periodic access review
Users get only the access their role needs, and no one controls a whole transaction cycle.
Recovery measures
RTO = maximum acceptable downtime; RPO = maximum acceptable data loss (measured in time)
They guide backup frequency and the design of the recovery plan.

How to solve Internal Audit of IT and Information Systems questions

Use this method for any question on auditing IT, whether it asks for a checklist, a comparison or a case analysis.

  1. 1Identify what the question asks: general controls, application controls, one area (such as backup) or the whole audit approach.
  2. 2Understand the system and risk: name the critical system, the data it holds and the main risks.
  3. 3List the relevant controls under a clear heading: access, change management, backup, operations, continuity, or input, processing, output.
  4. 4State the audit procedure for each control: what you inspect, ask, observe or re-perform, and what evidence you collect.
  5. 5Link to the facts given: apply the points to the case, such as a shared password or an unapproved patch.
  6. 6Conclude with the finding, its risk and impact, and a recommendation.
  7. 7Close with reporting and follow-up to management and the audit committee.

Quickest way: Layer, area, test, report

When to use it: Use when time is short, especially for a checklist or short-note question.

  1. Write the two layers: general and application controls, with one line on how they relate.
  2. Pick the areas asked for and write one control and one audit test for each.
  3. Add one practical example from the case, with a rupee or business impact if given.
  4. End with a recommendation and the reporting line to the audit committee.

Common mistakes in Internal Audit of IT and Information Systems

  • Mixing up general and application controls.

    Both are called IT controls and examples overlap in memory.

    Fix: Ask: does this control cover the whole IT environment or one process? Environment means general; one process means application.

  • Listing controls without audit procedures.

    Students recall control names but forget the auditor's role is to test them.

    Fix: For each control add what you inspect, ask, observe or re-perform, and the evidence you keep.

  • Saying a backup exists, so recovery is assured.

    Backup is treated as the end of the matter.

    Fix: Check that backups are tested by restoration, stored offsite or securely, and match the recovery objectives.

  • Ignoring segregation of duties in access and change management.

    Focus stays on passwords alone.

    Fix: Check that the person who develops a change is not the one who approves or moves it to production.

  • Writing about the auditor fixing or managing IT.

    Confusing assurance with management responsibility.

    Fix: Frame answers as evaluate, test, report and recommend. Management owns the controls.

  • Answering generically without using the case facts.

    Pre-learned lists are written out in full.

    Fix: Tie each point to the facts given, then conclude in the provision, analysis, conclusion pattern.

Worked examples

Example 1

Distinguish between IT general controls and application controls, with two examples of each.

Show the solution
  1. Define general controls: they apply across the IT environment and support the reliable working of all applications.
  2. Examples of general controls: restricting system access by user role, and approving and testing program changes before moving them to production.
  3. Define application controls: they operate within a specific application to ensure complete and accurate input, processing and output.
  4. Examples of application controls: a validation check rejecting an invoice with an invalid vendor code, and a batch total reconciliation of processed records.
  5. State the link: weak general controls reduce reliance on application controls, so the auditor tests general controls first.

Answer: General controls cover the whole IT environment (for example, access security and change management). Application controls work inside one system (for example, input validation and batch totals). Reliable application controls depend on sound general controls.

Example 2

Arjun Textiles Ltd's internal auditor finds that developers can move program changes directly to the live payroll system, and that backups are taken daily but never test-restored. Evaluate the issues and recommend actions.

Show the solution
  1. Issue 1 is change management. Developers moving changes to production with no independent approval breaks segregation of duties. Unauthorised or faulty changes could alter payroll calculations without detection.
  2. Audit test: take a sample of changes from the change log and check for request, approval, testing and an independent person moving it live.
  3. Issue 2 is backup and recovery. Daily backups give some protection, but without test restoration there is no assurance the data can be recovered.
  4. Audit test: review restoration test records and the storage location of the backups, and compare recovery time with the business need.
  5. Impact: payroll errors, fraud risk, statutory deduction mistakes and extended downtime after failure.
  6. Recommend: a formal change approval process with separate roles, a periodic restore test with documented results, and recovery objectives set by management.
  7. Report the findings to management and the audit committee and follow up on the agreed actions.

Answer: Both are significant general control weaknesses. Recommend segregating development and production roles with approved, tested changes, and regular documented restoration tests of backups. Report to the audit committee and follow up.

Exam tips

  • Always begin with the two-layer structure of general and application controls. It earns marks in almost every question on this topic.
  • Use headings for access, change management, backup, operations and continuity so the answer reads as a checklist.
  • For case questions, name the control weakness, the risk it creates and a recommendation. Stay in the auditor's assurance role.
  • Mention CAATs briefly when asked about testing large volumes of data, and connect to the related CAATs topic.
  • Keep answers practical, with examples such as payroll, billing or ERP systems.

Practice questions from Internal Audit of Specific Functions

Internal Audit of IT and Information Systems in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Internal Audit of IT and Information Systems: frequently asked questions

What is the difference between general controls and application controls?

General controls apply to the entire IT environment, such as access, change management and backup. Application controls work inside a specific system and cover input, processing and output. General controls must be sound for application controls to be relied on.

What should an internal auditor check in access security?

Check how user IDs are created, approved and removed, whether access matches job roles, and whether duties are segregated. Also review password rules, privileged access and periodic access reviews.

Why is business continuity part of the IT audit?

A system failure or disaster can stop operations and lose data. The auditor checks that a continuity and recovery plan exists, is approved, is tested and covers critical systems.

How do I write an IT audit answer in the exam?

State the control layer, list the controls for the area asked, give the audit test for each, apply the case facts, and end with a recommendation and reporting. Use short headings and bullets.