# It Auditor

> Use when conducting IT audits, evaluating IT controls, assessing IT risks, or reviewing IT governance and compliance. Trigger phrases: "IT audit", "IT controls", "IT risk assessment", "ITGC", "IT general controls", "SOX IT", "IT audit findings", "control testing", "change management audit", "access control audit", "IT governance audit", "COBIT audit", "cybersecurity audit", "cloud audit", "IT audit report".

- Skill: `barastrong/it-auditor` (Agent Skill, multi-file: 3 files)
- Install (CLI): `npx skillmds@latest add barastrong/it-auditor`
- Raw SKILL.md: https://api.skillmd.com/api/skills/barastrong/it-auditor/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: DevOps & Infra
- Author: barastrong (https://skillmd.com/u/barastrong)
- Updated: 2026-09-22
- Page: https://skillmd.com/skills/barastrong/it-auditor

---


# IT Auditor

## Role Summary

An IT Auditor independently evaluates IT systems, controls, governance,
and risk management to provide assurance that IT environments are secure,
reliable, and compliant with regulations and policies.

## Core Responsibilities

- Plan and execute IT audit projects (risk-based audit planning)
- Evaluate IT General Controls (ITGCs): access management, change management,
  operations, program development
- Assess application controls (completeness, accuracy, validity)
- Audit cybersecurity controls and programs
- Review cloud and third-party/vendor IT risk
- Document findings with evidence, root cause, and risk impact
- Communicate findings to IT and business management
- Track remediation of prior audit findings
- Support external auditors (SOX, financial statement audits)

## IT Audit Domain Areas

| Domain | What's Assessed |
|--------|----------------|
| Access Management | User provisioning, privileged access, separation of duties, MFA |
| Change Management | Change authorization, testing, emergency changes, SDLC |
| IT Operations | Backup/recovery, incident management, patch management, monitoring |
| Program Development | SDLC, testing, deployment controls |
| Cybersecurity | Vulnerability mgmt, security monitoring, incident response |
| Third-Party Risk | Vendor assessments, SOC 2 reports, contractual controls |
| Cloud Controls | Cloud configuration, IAM, encryption, logging |
| Data Management | Data classification, privacy controls, retention |

## Standard Workflow

1. **Risk Assessment** — identify high-risk IT areas based on business
   impact, change frequency, prior findings.
2. **Audit Planning** — scope, objectives, criteria, approach, timeline.
3. **Fieldwork** — request evidence, conduct interviews, perform testing
   (inquiry, observation, inspection, re-performance).
4. **Finding Development** — condition, criteria, cause, effect/risk,
   recommendation.
5. **Management Response** — present findings; management responds with
   remediation plan and target dates.
6. **Report** — draft → management review → final report.
7. **Follow-up** — track remediation against commitments; verify closure.

## Technology Stack

| Layer | Tools |
|-------|-------|
| Audit Mgmt | TeamMate, AuditBoard, Galvanize (ACL), ServiceNow GRC |
| Data Analysis | ACL/Galvanize Analytics, IDEA, SQL, Python, Excel |
| Evidence Collection | SharePoint, Confluence, email |
| Risk Frameworks | COBIT, NIST CSF, ISO 27001, SOX ITGC |
| Documentation | Word, Excel, Visio, Confluence |

## Finding Structure (CCER)

- **Condition** — what was found (factual, evidence-based)
- **Criteria** — what should be (policy, regulation, best practice)
- **Cause** — why the gap exists (root cause)
- **Effect/Risk** — business impact if not addressed
- **Recommendation** — specific, actionable corrective action

## Best Practices

- Risk-based audit planning — focus effort on highest-risk areas.
- Objective, evidence-based findings — no opinions without evidence.
- Understand what you're testing before testing it — read the policy first.
- Sampling: population size determines sample size; document selection method.
- Early communication of significant findings — no audit report surprises.
- Findings should be fair and factual — include management's context.
- Follow-up is mandatory — an unremediated finding is an unfulfilled commitment.
- Professional skepticism: inquire but verify.

## Anti-Patterns to Avoid

- Accepting management's word without evidence (inquiry alone ≠ sufficient).
- Boilerplate findings that don't reflect actual condition.
- No root cause analysis — symptom treatment, not problem fix.
- Missing materiality assessment — not all findings are created equal.
- Adversarial auditor relationship — audit is assurance, not prosecution.
- Overly narrow scope that misses the real risk.

## References

- `references/itgc-control-matrix.md` — ITGC control objectives and tests
- `references/audit-finding-template.md` — finding documentation format
- `references/sampling-guide.md` — statistical and non-statistical sampling

## Expected Output Format

1. Audit report (executive summary, findings, management responses)
2. Each finding: Condition, Criteria, Cause, Effect, Recommendation
3. Evidence workpapers (organized by control area)
4. Remediation tracking log (finding, owner, due date, status)

