-
Selecting an Audit Management System: A Vendor-Neutral RFP Method
How to choose an audit management system without a vendor ranking: whether you need one at all, requirements weighted by the size of the function, an RFP requirements…
Updated
·
21–32 minutes -
CISA for Internal Auditors: When It Is Worth It, What It Tests and How to Pass
Is the CISA worth it for an internal auditor? Five career profiles, the 2024 job practice translated into audit work, ISACA requirements, fees and waivers, a twelve-week study…
Updated
·
21–31 minutes -
How to Audit AWS: A Practical Program for the Dominant Cloud
An AWS-specific audit program for IT auditors: the estate structure, Organizations guardrails and account vending, root user controls including the 2024 to 2025 MFA requirements and centralized root…
Updated
·
19–29 minutes -
How to Audit Cloud Security: A Control-by-Control Program
A provider-agnostic cloud security audit program: the shared-responsibility test map by service model, criteria (CSA CCM v4, ISO/IEC 27017 and 27018, NIST SP 800-210, CIS Foundations Benchmarks, DORA),…
Updated
·
19–28 minutes -
Auditing Cyber Resilience: Can the Organization Actually Recover?
Recovery-side cyber assurance, distinct from prevention-focused audits: resilience versus security, the frameworks that describe recovery (NIST SP 800-160 Vol. 2, CSF 2.0 Recover, DORA Articles 11 and 12,…
Updated
·
19–29 minutes -
DORA for Internal Auditors: ICT Risk, Incident Reporting, and Resilience Testing
The EU Digital Operational Resilience Act as an evergreen structure for internal auditors: scope and proportionality, the five pillars with their articles and delegated regulations, the ICT risk…
Updated
·
19–28 minutes -
How to Audit End-User Computing: Spreadsheet Risk and the EUC Inventory
The end-user computing audit program: why spreadsheets and other user-built tools keep producing wrong numbers, what counts as an EUC, discovery and inventory from six sources when asking…
Updated
·
19–29 minutes -
Manual, Automated, and IT-Dependent Manual Controls: Testing Implications of Each
The three control natures defined by what can fail, their testing implications side by side (design test, operating test, sample sizes, ITGC reliance, evidence, roll-forward), a five-question classification…
Updated
·
20–30 minutes -
How to Audit the SDLC and DevOps Pipeline
How to audit a modern software delivery pipeline: the five change control objectives mapped from traditional ITGCs to pipeline mechanisms, the standards (NIST SSDF, SLSA, ISO/IEC 27001:2022 A.8.25…
Updated
·
21–31 minutes -
Assessing Cybersecurity With NIST CSF 2.0: An Internal Audit Method
An internal audit method for using NIST CSF 2.0 as assessment criteria: how to scope a first-time assessment by depth, turn the 106 subcategories into agreed criteria, apply…
Updated
·
19–29 minutes -
The Cybersecurity Topical Requirement: A Conformance Workbook
The IIA Cybersecurity Topical Requirement turned into a working checklist: the three domains and seventeen requirements with what to assess, example evidence and the common gap for each,…
Updated
·
22–33 minutes -
How to Audit Active Directory and Entra ID: The Identity Backbone
The directory is the control plane of every other control. The method for auditing Active Directory and Entra ID: why it is in scope of everything, the privileged…
Updated
·
20–30 minutes -
How to Audit Data Privacy Compliance: A GDPR-Anchored Program
Privacy programs have excellent policies and unknown practice. The method for auditing one, anchored on the GDPR and portable to the UK GDPR, the CPRA and the twenty…
Updated
·
20–29 minutes -
How to Audit Patch and Vulnerability Management
You cannot patch what you cannot see. The method for auditing vulnerability and patch management as a program: the frameworks from NIST SP 800-40 Rev. 4 to the…
Updated
·
19–29 minutes -
How to Review a SOC 2 Report: Trust Services Criteria for User Entities
The user entity’s method for a SOC 2 report under the AICPA Trust Services Criteria: what the report is and is not, which of the five categories your…
Updated
·
20–29 minutes -
How to Audit Incident Response: Detection to Post-Mortem
The method for auditing incident response as a program rather than a plan: the eight components and their controls under NIST SP 800-61 Rev. 3 and the IIA’s…
Updated
·
20–30 minutes -
Building the IT Audit Plan: From Risk Assessment to Coverage Map
The technology layer of the audit plan, built in six steps: an IT universe reconciled from sources that already exist, a ten-factor risk assessment with evidence behind every…
Updated
·
20–30 minutes -
Testing Automated Controls and System Configurations: A Non-IT Auditor’s Method
How to test the controls a system performs without anyone watching: the seven types of automated control and where their logic lives, why one well-designed test can cover…
Updated
·
21–31 minutes -
How to Review a SOC 1 Report: A User Entity’s Working Method
The user entity’s method for a SOC 1 report under SSAE 18: what the report is and is not, the five sections and what to read in each,…
Updated
·
21–31 minutes -
How to Audit Backups and Recovery: The Restore Test Is the Only Test
Backups are a job that runs; recovery is an outcome that has been proven or has not. The nine controls with their NIST, ISO, CISA and DORA references,…
Updated
·
23–35 minutes -
How to Audit IT Change Management: From Ticket to Production
The working method for auditing IT change management: the ten controls and their COBIT, ITIL, NIST and COSO references, why the population must come from the production system…
Updated
·
26–38 minutes -
The P2P Fraud Analytics Catalog: Cross-Stage Tests That Catch Collusion
The collusion-sensitive layer beyond single-table AP tests: twenty cross-stage procure-to-pay analytics that join requisitions, orders, receipts, invoices, payments, the vendor master, bids, and the employee master, each with…
Updated
·
18–27 minutes -
The Auditor’s Prompt Library: Reusable Prompts for Audit Work (With Guardrails)
Twelve reusable prompts for planning, fieldwork, reporting, and function management, written in full with structure notes and verification steps, opening with the eight guardrails that keep model output…
Updated
·
21–32 minutes -
The Journal Entry Analytics Catalog: Risk-Scoring the General Ledger
Twenty-five journal entry analytics tests in four families, each with logic, data, threshold, what a hit means and its false positives, anchored to the entry characteristics in PCAOB…
Updated
·
19–29 minutes -
The Payroll Analytics Catalog: 30 Tests for Ghost Employees and Beyond
Thirty payroll analytics tests in five families, each with its logic, data, threshold, what a hit usually means and what produces false positives; the five datasets and the…
Updated
·
19–29 minutes -
The Accounts Payable Analytics Catalog: 40 Tests With Logic
Forty accounts payable analytics tests in six families, each with its logic, the data and threshold it needs, what a hit usually means and what produces false positives;…
Updated
·
20–29 minutes -
How to Run an ERP Segregation of Duties Analysis (Any Platform)
Vendor rulesets flag thousands of conflicts; a few dozen matter. The platform-agnostic method for an ERP segregation of duties analysis: a conflict matrix built from your own risks…
Updated
·
21–31 minutes -
How to Perform a User Access Review That Actually Works
Most user access reviews are signatures, not reviews. How to build one that removes access: scoping by tier with the right reviewers, population completeness reconciled to the system…
Updated
·
19–29 minutes -
SOX ITGC Scoping: Which Systems Are In, and Why
Which systems belong in SOX ITGC scope, and which do not: the six-step chain from significant accounts to applications, layers and third parties, the layer decision defended by…
Updated
·
19–28 minutes -
How to Audit Privileged Access: Admin Rights, Break-Glass, and Vaulting
Privileged access decides how bad everything else can get. The method for auditing it: privilege defined by capability across every layer from the directory to the database and…
Updated
·
19–28 minutes