ICT Audit
Information technology controls sit underneath almost every financial assertion, which is why ICT findings feature so heavily in public sector audit outcomes. We test the controls themselves rather than reading a policy document and calling it assurance. Our team runs these engagements at municipal level, where the findings end up in front of the Auditor General.
Four domains carry most of the risk: who can get into the system, how changes reach production, how the environment is run day to day, and whether data can be recovered. We test each one against evidence rather than against what the policy says should happen.
- User access management and privileged accounts
- Change management and segregation of duties
- IT operations, backups and job scheduling
- Physical and environmental controls
King IV makes the governing body responsible for technology and information, and most ICT findings trace back to that responsibility never being operationalised. We assess the governance structures, the policies meant to support them, and whether ICT spending and delivery are reported upward at all.
- King IV Principle 12 alignment review
- ICT governance framework and committee structures
- Policy suite currency and approval trail
- ICT strategic plan and budget oversight
General controls protect the environment, but the business logic sits inside the applications. We test input validation, calculation accuracy, interface completeness and the reconciliations that are supposed to catch whatever slips through.
- Input, processing and output control testing
- Interface completeness and accuracy
- System generated report reliability
- Master data and standing data controls
Almost every organisation has a continuity plan. Far fewer have tested one. We review the plan against the recovery objectives the business actually needs, check whether the backups restore, and report the distance between the documented position and the real one.
- Backup configuration and restore testing
- Recovery time and recovery point objectives
- Continuity plan review and gap analysis
- Disaster recovery test observation
POPIA compliance is usually handled as a legal exercise and then never reflected in the systems. We look at where personal information actually lives, who can reach it, how long it is kept, and whether the operator agreements match what the systems permit.
- Personal information inventory and flow mapping
- Access rights over personal information
- Retention, archiving and deletion controls
- Operator agreements and third party access
A repeat ICT finding damages an audit outcome more than a first time finding does. We take the management report, work out the control weakness underneath each finding rather than the symptom described, and help you build remediation that survives the following audit.
- Root cause analysis of prior year findings
- Remediation action plans with owners
- Control design and implementation support
- Pre audit readiness testing
