← All Cheat Sheets
IS Audit Process Checklist
Step-by-step audit process from planning through follow-up.
IS Audit Process Checklist
A step-by-step reference covering the five phases of an IS audit. Use this as a checklist when planning, executing, or reviewing audit engagements.
Phase 1: Audit Planning
- Define the audit objective and scope
- Perform a risk assessment to prioritize audit areas
- Review prior audit findings and management responses
- Identify applicable standards, regulations, and frameworks
- Develop the audit program (procedures, timeline, resources)
- Send the engagement letter to auditee management
Phase 2: Fieldwork Preparation
- Gather preliminary information (org charts, policies, network diagrams)
- Identify key personnel and schedule interviews
- Select sampling methodology (statistical or judgmental)
- Prepare CAATs (Computer-Assisted Audit Techniques) if needed
- Confirm resource allocation and audit team assignments
Phase 3: Fieldwork Execution
- Conduct walkthroughs of key processes
- Test controls: preventive, detective, and corrective
- Collect evidence (documents, logs, screenshots, interview notes)
- Evaluate evidence for sufficiency and reliability
- Document findings using the format: Condition, Criteria, Cause, Effect
- Perform substantive testing where control weaknesses exist
Phase 4: Reporting
- Draft the audit report with findings and recommendations
- Rate findings by severity (high, medium, low)
- Include management responses and agreed remediation dates
- Present the report to appropriate management level
- Obtain sign-off from the audit committee or senior management
Phase 5: Follow-Up
- Track remediation progress against agreed timelines
- Verify that corrective actions have been implemented
- If management accepts the risk, document the acceptance formally
- Update the risk register based on audit outcomes
- Feed results into the next audit planning cycle
Key Reminders
| Principle | What It Means |
|---|---|
| Independence | Auditor must be free from conflicts of interest |
| Professional Skepticism | Question assumptions; verify, do not assume |
| Materiality | Focus on items that could influence decisions |
| Due Professional Care | Apply skill and diligence expected of a competent auditor |
Ready to test your knowledge?
Put this cheat sheet to work with scenario-based CISA practice questions.
Start Free