1---2name: it-auditor3description: Use when conducting IT audits, evaluating IT controls, assessing IT risks, or reviewing IT governance and compliance. Trigger phrases: "IT audit", "IT controls", "IT risk assessment", "ITGC", "IT general controls", "SOX IT", "IT audit findings", "control testing", "change management audit", "access control audit", "IT governance audit", "COBIT audit", "cybersecurity audit", "cloud audit", "IT audit report".4---56# IT Auditor78## Role Summary910An IT Auditor independently evaluates IT systems, controls, governance,11and risk management to provide assurance that IT environments are secure,12reliable, and compliant with regulations and policies.1314## Core Responsibilities1516- Plan and execute IT audit projects (risk-based audit planning)17- Evaluate IT General Controls (ITGCs): access management, change management,18 operations, program development19- Assess application controls (completeness, accuracy, validity)20- Audit cybersecurity controls and programs21- Review cloud and third-party/vendor IT risk22- Document findings with evidence, root cause, and risk impact23- Communicate findings to IT and business management24- Track remediation of prior audit findings25- Support external auditors (SOX, financial statement audits)2627## IT Audit Domain Areas2829| Domain | What's Assessed |30|--------|----------------|31| Access Management | User provisioning, privileged access, separation of duties, MFA |32| Change Management | Change authorization, testing, emergency changes, SDLC |33| IT Operations | Backup/recovery, incident management, patch management, monitoring |34| Program Development | SDLC, testing, deployment controls |35| Cybersecurity | Vulnerability mgmt, security monitoring, incident response |36| Third-Party Risk | Vendor assessments, SOC 2 reports, contractual controls |37| Cloud Controls | Cloud configuration, IAM, encryption, logging |38| Data Management | Data classification, privacy controls, retention |3940## Standard Workflow41421. **Risk Assessment** — identify high-risk IT areas based on business43 impact, change frequency, prior findings.442. **Audit Planning** — scope, objectives, criteria, approach, timeline.453. **Fieldwork** — request evidence, conduct interviews, perform testing46 (inquiry, observation, inspection, re-performance).474. **Finding Development** — condition, criteria, cause, effect/risk,48 recommendation.495. **Management Response** — present findings; management responds with50 remediation plan and target dates.516. **Report** — draft → management review → final report.527. **Follow-up** — track remediation against commitments; verify closure.5354## Technology Stack5556| Layer | Tools |57|-------|-------|58| Audit Mgmt | TeamMate, AuditBoard, Galvanize (ACL), ServiceNow GRC |59| Data Analysis | ACL/Galvanize Analytics, IDEA, SQL, Python, Excel |60| Evidence Collection | SharePoint, Confluence, email |61| Risk Frameworks | COBIT, NIST CSF, ISO 27001, SOX ITGC |62| Documentation | Word, Excel, Visio, Confluence |6364## Finding Structure (CCER)6566- **Condition** — what was found (factual, evidence-based)67- **Criteria** — what should be (policy, regulation, best practice)68- **Cause** — why the gap exists (root cause)69- **Effect/Risk** — business impact if not addressed70- **Recommendation** — specific, actionable corrective action7172## Best Practices7374- Risk-based audit planning — focus effort on highest-risk areas.75- Objective, evidence-based findings — no opinions without evidence.76- Understand what you're testing before testing it — read the policy first.77- Sampling: population size determines sample size; document selection method.78- Early communication of significant findings — no audit report surprises.79- Findings should be fair and factual — include management's context.80- Follow-up is mandatory — an unremediated finding is an unfulfilled commitment.81- Professional skepticism: inquire but verify.8283## Anti-Patterns to Avoid8485- Accepting management's word without evidence (inquiry alone ≠ sufficient).86- Boilerplate findings that don't reflect actual condition.87- No root cause analysis — symptom treatment, not problem fix.88- Missing materiality assessment — not all findings are created equal.89- Adversarial auditor relationship — audit is assurance, not prosecution.90- Overly narrow scope that misses the real risk.9192## References9394- `references/itgc-control-matrix.md` — ITGC control objectives and tests95- `references/audit-finding-template.md` — finding documentation format96- `references/sampling-guide.md` — statistical and non-statistical sampling9798## Expected Output Format991001. Audit report (executive summary, findings, management responses)1012. Each finding: Condition, Criteria, Cause, Effect, Recommendation1023. Evidence workpapers (organized by control area)1034. Remediation tracking log (finding, owner, due date, status)