IS Audit

What a first IS audit actually covers

July 2026 · 6 min read

01

Article

An information systems audit sounds broader than it is. In practice, a first audit walks a defined path: understand the environment, identify the systems that matter to the business, and test the controls those systems depend on. Here is that path, in the order an auditor walks it.

1. Scoping — which systems actually matter

The audit starts by mapping business processes to the applications and infrastructure behind them. A core banking system, an ERP, a billing platform — the systems whose failure or compromise would hurt. Everything else is noted but not tested in depth. A good scope is short; a scope that lists every server usually means nobody made a decision.

2. IT general controls — the recurring core

Most of a first audit is spent on ITGC, in three families. Access: who can get into each system, how joiners and leavers are handled, whether privileged accounts are controlled and reviewed. Change: how code and configuration changes are approved, tested and moved to production, and who can push directly. Operations: backups and whether restores are actually tested, job scheduling and failure handling, and incident logging.

3. Evidence, not assurances

For each control the auditor asks for proof it operated during the period: user access review sign-offs, change tickets with approvals, restore-test records. "We always do that" is not evidence; a dated record is. This is the step that surprises first-time auditees most, and it is where preparation pays off.

4. Findings and ratings

Gaps get written up with a severity rating, the risk they create, and a recommended fix with an owner and a date. A first audit almost always has findings — that is the point of doing it. What matters to the board, and to any regulator reading the report, is whether the findings close on schedule.

What to prepare before the auditors arrive

Four things shorten every first audit: a current inventory of systems and their owners, a list of who has admin access to each, your change and access-management procedures as actually practised, and the last few months of tickets and review records. If any of those don't exist yet, creating them is the real first step — the audit just makes it official.

02

Next

Working through this in your own organisation?