← All Cheat Sheets

IS Audit Process Checklist

Step-by-step audit process from planning through follow-up.

IS Audit Process Checklist

A step-by-step reference covering the five phases of an IS audit. Use this as a checklist when planning, executing, or reviewing audit engagements.

Phase 1: Audit Planning

  • Define the audit objective and scope
  • Perform a risk assessment to prioritize audit areas
  • Review prior audit findings and management responses
  • Identify applicable standards, regulations, and frameworks
  • Develop the audit program (procedures, timeline, resources)
  • Send the engagement letter to auditee management

Phase 2: Fieldwork Preparation

  • Gather preliminary information (org charts, policies, network diagrams)
  • Identify key personnel and schedule interviews
  • Select sampling methodology (statistical or judgmental)
  • Prepare CAATs (Computer-Assisted Audit Techniques) if needed
  • Confirm resource allocation and audit team assignments

Phase 3: Fieldwork Execution

  • Conduct walkthroughs of key processes
  • Test controls: preventive, detective, and corrective
  • Collect evidence (documents, logs, screenshots, interview notes)
  • Evaluate evidence for sufficiency and reliability
  • Document findings using the format: Condition, Criteria, Cause, Effect
  • Perform substantive testing where control weaknesses exist

Phase 4: Reporting

  • Draft the audit report with findings and recommendations
  • Rate findings by severity (high, medium, low)
  • Include management responses and agreed remediation dates
  • Present the report to appropriate management level
  • Obtain sign-off from the audit committee or senior management

Phase 5: Follow-Up

  • Track remediation progress against agreed timelines
  • Verify that corrective actions have been implemented
  • If management accepts the risk, document the acceptance formally
  • Update the risk register based on audit outcomes
  • Feed results into the next audit planning cycle

Key Reminders

Principle What It Means
IndependenceAuditor must be free from conflicts of interest
Professional SkepticismQuestion assumptions; verify, do not assume
MaterialityFocus on items that could influence decisions
Due Professional CareApply skill and diligence expected of a competent auditor

Ready to test your knowledge?

Put this cheat sheet to work with scenario-based CISA practice questions.

Start Free