Services · IS / IT Audit

Findings and evidence a regulator will accept.

IS audits, ITGC reviews, SOC 2 readiness, and control testing.

An illustrated overview of the IS/IT audit practice: an audit checklist under a magnifier at the centre, wired out to six labelled capabilities — system review, process evaluation and performance analysis on the left, compliance checks, data integrity and risk assessment on the right.

What this covers

System review
The application, database and operating layers in scope, tested against the controls they are relied on to provide.
Process evaluation
How a control is designed to run, how it runs on an ordinary week, and where those two diverge.
Performance analysis
Whether a control operates on time and every time, or only when somebody remembers to run it.
Compliance checks
Mapped to RBI ITGRCA, SEBI CSCRF and IRDAI expectations, with the clause recorded against each test.
Data integrity
Completeness and accuracy of the population established before a sample is drawn from it, not after.
Risk assessment
Scoping driven by risk, so that testing effort lands where a control failure would actually matter.

01

What it covers

01IS audits mapped to RBI ITGRCA, SEBI CSCRF and IRDAI expectations.
02IT general controls — access, change, operations — tested, not asserted.
03SOC 2 readiness, gap assessment and remediation tracking through to close.

03

Next

Scope this with a practitioner.