IT Auditor
The IT Auditor determines audit objectives and activities by examining changes to the technological landscape, regulations and the organization's IT assets and technologies to identify potential risks to IT assets. He/She assists in the development of an IT audit plan which includes outlining all workflows and audit activities. He conducts audit activities as per audit plan and analyses IT business controls and processes against organizational and industry standards to identify areas of non-compliance and potential risks. He assists with investigation and the preparation of documentation of work performed and develops reports. He also identifies potential recommendations to enhance compliance and address risks identified. He works in a dynamic environment due to rapid changes in the IT landscape. He is knowledgeable of relevant regulatory requirements and internal auditing standards, particularly in the area of technology risk management. The IT Auditor has a natural ability to process diverse sets of information and see relevant interdependencies and linkages. He is inquisitive and observant when analyzing issues and is able to effectively articulate concepts and ideas.
Skills and Competencies
Technical Skills & Competencies
Generic Skills & Competencies
Critical Work Functions and Key Tasks
• Conduct research on technological landscape and regulations to analyse its impact on the organisation’s IT audit plans
• Identify potential risks to IT assets
• Analyse changes to the organisation's IT assets to develop IT audit requirements
• Identify required IT audit workflows and activities
• Assist in the development of an IT audit plan
• Conduct audit activities in accordance with the IT audit plan and requirements
• Analyse IT controls and processes against organisational and industry IT standards
• Identify areas of non-compliance to IT standards and potential IT risk
• Gather evidence to identify root causes of areas of non-compliance
• Document evidence and IT audit conclusions
• Provide recommendations to enhance compliance to IT standards and address IT risks identified
• Develop communication and presentation materials to share IT audit findings and recommendations
• Drive awareness of IT controls across organisation
• Promote best practices and raise organisational awareness on matters relating to governance, risk and compliance
• Monitor resolution of identified non-compliance and risks