IT Governance, Risk, and Compliance

Feb 17 2012   8:50PM GMT

Auditing IT Governance – Part III

Robert Davis Robert Davis Profile: Robert Davis

To prevent expectation misinterpretation, the IT governance engagement ‘terms of reference’ should minimally address engagement ambit, reporting lines, and IT audit authority. Specifically, IT governance functional areas and issues definitions; identified ‘highest-organization-level’ issues reporting; as well as auditor information access rights should be clearly documented in the audit charter and/or engagement letter.

IT governance can be an individual audit area examination or an auditable unit examination for every IT function audit undertaken. During the IT audit planning process, all or segments of an entity’s deployed governance related frameworks may be selected as auditable units. Furthermore, IT governance audits may cross divisional, functional, or departmental demarcations.

View Part I of the Auditing IT Governance series here

 Comment on this Post

There was an error processing your information. Please try again later.
Thanks. We'll let you know when a new response is added.
Send me notifications when other members comment.

Forgot Password

No problem! Submit your e-mail address below. We'll send you an e-mail containing your password.

Your password has been sent to:

Share this item with your network: