What Is IT Auditing? Types, Frameworks, and Legal Requirements

IT auditing is an independent review of an organization’s technology systems, security controls, and data-handling practices to determine whether those systems work as intended and comply with the laws that apply to them. Auditors look at server configurations, firewall rules, access permissions, backup routines, and disaster recovery plans, among other things. The review serves two purposes at once: catching vulnerabilities before an attacker or a regulator does, and satisfying external requirements imposed by statutes such as the Sarbanes-Oxley Act and HIPAA.

The point of the exercise is not the report itself. It is the assurance that what the organization says it does with its data actually matches what happens on the wires.

What Auditors Examine

An IT audit works through the technology environment in layers. Weaknesses in one layer can compromise the others, so auditors rarely stop at a single component.

Hardware and Physical Assets

Servers, workstations, laptops, and mobile devices form the base layer. Auditors check how these assets are inventoried, physically secured, and tracked when they leave the premises. Storage media get particular attention, because a single unencrypted hard drive in the wrong hands can expose thousands of records.

Software and Applications

Enterprise applications like ERP systems and databases, along with the operating systems they run on, are evaluated for correct configuration and proper access restrictions. The audit tests whether these applications process data accurately and whether their security settings actually match the organization’s written policies. Outdated or unpatched software is one of the most common findings here.

Network Infrastructure

Routers, switches, firewalls, and wireless access points connect everything. Auditors inspect traffic filtering rules, intrusion detection systems, and network segmentation to confirm sensitive systems are isolated from general traffic. A misconfigured firewall rule can quietly expose an entire network segment for months before anyone notices.

Data Management

Database structures, backup routines, and recovery mechanisms are all fair game. Auditors verify that backups actually complete, that recovery procedures have been tested, and that information flowing between systems follows documented protocols. Backup failures that go undetected until a real disaster strikes are a recurring theme in audit findings.

Cloud and SaaS Environments

When workloads move to the cloud, auditing responsibility splits between the customer and the provider under what is known as the shared responsibility model. The provider typically handles security of the underlying infrastructure: physical data centers, host servers, and network hardware. The customer remains responsible for its own data, user accounts and access controls, application configuration, and the devices employees use to connect.1Microsoft Learn. Shared Responsibility in the Cloud

Auditors review the customer’s controls and also verify that the provider can demonstrate adequate security on its end, usually through SOC reports or equivalent certifications. Assuming the provider handles everything without reviewing those reports is one of the fastest ways to fail a cloud-related audit.

Types of IT Audits

Not every IT audit covers the same ground. Most engagements fall into one of several recognized categories, and the scope depends on what the organization needs to evaluate.

Systems and Applications Audits

These evaluate the internal controls governing specific software programs and the data they process. Auditors verify that automated controls prevent errors during data entry, that outputs are accurate, and that privacy protections work as designed. If a payroll system can be manipulated to create phantom employees, this is the audit that would catch it.

Information Processing Facility Audits

Facility audits focus on the physical and environmental controls in data centers and server rooms. Climate control, fire suppression, backup power, and physical access restrictions are all tested. The people managing the environment are part of the evaluation too, since the best environmental controls mean nothing if an operator props open the server room door.

Systems Development Audits

When an organization builds or implements new technology, auditors review the project lifecycle to confirm the new system meets business requirements and includes appropriate security controls before going live. Catching design flaws during development costs a fraction of what it costs to fix them after deployment.

Management and Governance Audits

These reviews examine IT leadership, strategic planning, and resource allocation. Auditors assess whether technology investments align with organizational goals and whether executives have adequate visibility into IT risks. A company spending heavily on perimeter security while ignoring insider threat controls, for instance, has a governance problem.

AI and Machine Learning Systems

As organizations deploy AI in decision-making, auditors increasingly evaluate these systems for bias, security, and transparency. The National Institute of Standards and Technology published the AI Risk Management Framework to help organizations assess trustworthiness in AI products and services. The framework’s core functions include governing AI policies, measuring risks, and managing identified issues throughout the system’s lifecycle.2National Institute of Standards and Technology. AI Risk Management Framework NIST released a companion profile for generative AI in 2024, addressing the risks posed by large language models and similar tools.

Frameworks Auditors Use

IT auditors do not invent their criteria from scratch. They work from established frameworks that provide structured benchmarks for evaluating controls, measuring maturity, and documenting findings.

COBIT 2019

The Control Objectives for Information and Related Technologies, known as COBIT, is one of the most widely used IT governance frameworks. Published by ISACA, COBIT 2019 provides guidelines for managing digital governance and risk, and serves as a benchmark for measuring how mature an organization’s internal controls are.3ISACA. COBIT – Control Objectives for Information Technologies Auditors frequently use COBIT because it maps to business objectives rather than focusing purely on technical details.

ISO/IEC 27001

Published jointly by the International Organization for Standardization and the International Electrotechnical Commission, ISO/IEC 27001 sets requirements for establishing and maintaining an information security management system. Organizations pursuing certification must meet the requirements in each of the standard’s ten clauses, covering risk assessment through operational controls. Recent updates added specific controls for cloud security and data privacy.4NSF. ISO/IEC 27001 Information Security Management System

NIST Cybersecurity Framework 2.0

The NIST Cybersecurity Framework, updated to version 2.0, organizes cybersecurity risk management around six core functions: Govern, Identify, Protect, Detect, Respond, and Recover.5National Institute of Standards and Technology. NIST Cybersecurity Framework 2.0 – Resource and Overview Guide The framework is voluntary but has become a de facto standard because it gives executives, auditors, and regulators a common vocabulary. The Govern function, added in version 2.0, treats cybersecurity risk management as something that should be embedded in organizational culture and monitored continuously, much like financial risk.

When the Law Requires an IT Audit

Beyond voluntary frameworks, certain industries face mandatory IT audit and control requirements imposed by federal law. Failing to meet these standards exposes organizations to significant financial penalties and regulatory action.

Sarbanes-Oxley Act

The Sarbanes-Oxley Act requires every publicly traded company to include an internal control report in its annual filing with the SEC. That report must affirm that management is responsible for maintaining effective controls over financial reporting and must include an assessment of those controls as of the fiscal year end.6Office of the Law Revision Counsel. 15 USC 7262 – Management Assessment of Internal Controls Because financial reporting depends heavily on IT systems, SOX compliance means rigorous testing of application controls, database integrity, access restrictions, and change management within the technology environment.

For larger public companies, an independent accounting firm must also attest to management’s assessment.6Office of the Law Revision Counsel. 15 USC 7262 – Management Assessment of Internal Controls Smaller issuers that do not qualify as accelerated filers are exempt from the external attestation requirement, though they still must perform the internal assessment.

HIPAA

Organizations that handle electronic protected health information must comply with the HIPAA Security Rule, which requires administrative, physical, and technical safeguards. The rule specifically mandates a thorough risk analysis to identify vulnerabilities to the confidentiality, integrity, and availability of patient data.7U.S. Department of Health and Human Services. Summary of the HIPAA Security Rule The requirements apply to health plans, healthcare clearinghouses, providers who transmit health information electronically, and their business associates.

HIPAA penalties follow a four-tier structure based on the level of negligence. Unknowing violations start at $137 per incident, while willful neglect that goes uncorrected can reach roughly $69,000 per violation, with an annual cap exceeding $2 million per violation category. These figures are adjusted for inflation periodically.

Gramm-Leach-Bliley Act

Financial institutions have an ongoing obligation under the Gramm-Leach-Bliley Act to protect the security and confidentiality of customer records and to guard against anticipated threats to that information.8Office of the Law Revision Counsel. 15 US Code 6801 – Protection of Nonpublic Personal Information The FTC’s Safeguards Rule, which implements these requirements, calls for regular security assessments including vulnerability scans, penetration testing, and security audits. A designated qualified individual must report audit results to the organization’s governing body at least annually.

PCI DSS

Any organization that stores, processes, or transmits payment card data must comply with the Payment Card Industry Data Security Standard. PCI DSS provides technical and operational requirements designed to protect payment account data.9PCI Security Standards Council. Data Security Standard – PCI DSS PCI DSS is enforced by the payment card brands rather than a government agency, but the financial consequences of noncompliance, including fines and loss of the ability to process card transactions, can be just as severe.

SOC Reports for Service Providers

Organizations that rely on third-party technology vendors also encounter Service Organization Control reports as part of their own audit process. A SOC 2 examination evaluates controls relevant to the five Trust Services Criteria established by the AICPA: security, availability, processing integrity, confidentiality, and privacy.10AICPA & CIMA. SOC 2 – SOC for Service Organizations – Trust Services Criteria The service organization chooses which criteria are relevant based on the services it provides.11AICPA & CIMA. 2017 Trust Services Criteria With Revised Points of Focus 2022 A Type II report, which tests whether controls operated effectively over six to twelve months, carries more weight than a Type I, which evaluates control design at a single point in time.

How the Audit Process Runs

A typical IT audit takes roughly three months from kickoff to final report, though the timeline varies with scope and organizational complexity. The work breaks into distinct phases.

Planning

The planning phase usually takes about four weeks. Auditors define the scope, identify the systems and controls to be tested, assess preliminary risks, and build a detailed work plan. This is also when they request documentation: system architecture diagrams, security policies, user access logs, disaster recovery plans, and software license agreements. Skimping on planning almost always means a longer, more disruptive fieldwork phase.

Fieldwork and Testing

Fieldwork occupies another four weeks or so and runs on two parallel tracks. Auditors interview technical staff and department managers to understand how policies are applied day to day. These conversations frequently reveal gaps between written procedures and actual practice. At the same time, auditors perform hands-on technical testing: reviewing configuration settings, attempting to bypass access controls, testing password complexity requirements, verifying that multi-factor authentication works as expected, and examining change management logs.

This is where most material findings surface. An organization might have a perfectly written access control policy, but if the auditor finds 40 dormant accounts with administrative privileges, the policy is not the problem.

Reporting

Compiling the audit report takes approximately four weeks. The final document catalogs every finding, rates each one by severity, and provides specific remediation recommendations. Findings are typically classified as high, medium, or low risk, and the report distinguishes between control design weaknesses (the control was never going to work) and operating effectiveness failures (the control was designed correctly but not followed consistently). The report goes to the board of directors or executive management, and for regulated organizations, it often feeds directly into compliance filings.

Remediation

The report is not the finish line. Organizations are expected to develop remediation plans that address each finding, with timelines proportional to severity. High-risk findings typically demand resolution within 30 to 90 days, while lower-risk items may get a longer runway. When the same finding appears across multiple audit cycles, regulators scrutinize whether the latest remediation effort reflects meaningful change from previous unsuccessful attempts.12PCAOB. Staff Guidance Concerning the Remediation Process

How Often IT Audits Should Happen

Most organizations conduct at least one comprehensive IT audit per year. Several factors push that frequency higher: regulated industries often require specific assessments at defined intervals, major system implementations warrant audits before and after go-live, and organizations that have experienced security incidents typically increase audit frequency afterward.

The GLBA Safeguards Rule requires financial institutions to conduct risk assessments at least annually and to perform regular vulnerability scans and penetration tests throughout the year. HIPAA’s Security Rule mandates ongoing risk analysis without specifying a fixed cadence, though annual assessments have become the accepted baseline.7U.S. Department of Health and Human Services. Summary of the HIPAA Security Rule Organizations pursuing ISO 27001 certification face annual surveillance audits and a full recertification audit every three years.

Treating the annual audit as a once-a-year event rather than a continuous process is where many organizations get into trouble. The companies with the strongest outcomes monitor controls throughout the year and treat the formal audit as confirmation of what they already know.

Who Performs IT Audits

Two credentials dominate the IT audit and security management field, both administered by ISACA.

The Certified Information Systems Auditor (CISA) designation focuses on audit, control, and assurance. It qualifies the holder to evaluate whether systems, data, and processes are reliable, compliant, and aligned with business objectives. Earning the CISA requires passing an examination and completing at least five years of professional experience in information systems auditing, control, or security. That experience must be gained within the ten years preceding the application, and candidates have five years after passing the exam to apply for certification. Maintaining the credential requires 120 hours of continuing professional development every three years, with a minimum of 20 hours per year.13ISACA. How to Get CISA Certified

The Certified Information Security Manager (CISM) credential focuses on security management rather than auditing. CISM holders lead and oversee enterprise-level security programs rather than evaluate them from the outside.14ISACA. CISA, CISM and CISSP – Why They Are More Complementary Than Competing In practice, you will encounter CISA holders performing the audit and CISM holders on the other side of the table, managing the security program being assessed. The credentials are complementary, and many professionals hold both.