IT Governance Assessment
Most ICT audit findings do not originate in the server room. They originate in a governing body that accepted responsibility for technology on paper and never operationalised it. King IV Principle 12 makes technology and information governance a board responsibility, which means the structures, the reporting and the decision rights all have to exist and be evidenced. We assess whether they do.
1
Structures
Committees and mandates
2
Policies
Currency and approval
3
Planning
Strategy and budget
4
Reporting
What reaches the board
5
Report
Gaps and roadmap
How We Assess
01
Governance Structures and Mandates
We start with who is actually accountable. That means reviewing the committee structure, the terms of reference, the delegation of authority and whether the people named in those documents attend, decide and are minuted doing so.
- ICT steering or governance committee terms of reference
- Delegation of authority for ICT decisions and spend
- Attendance, quorum and minuted decision records
- Reporting line from ICT management to the board
02
Policy Framework Review
A policy suite is only governance if it is current, approved and known. We assess coverage against the risks the organisation actually carries, check approval dates and establish whether staff have ever been made aware of the documents.
- Policy coverage mapped against the ICT risk profile
- Approval authority and review dates
- Version control and accessibility to staff
- Awareness, acknowledgement and training records
03
ICT Strategic Planning
Technology spend that is not tied to a plan tends to be defended after the fact. We review whether an ICT strategic plan exists, whether it aligns to the organisational strategy, and whether the budget actually follows it.
- ICT strategic plan currency and board approval
- Alignment to the organisational strategy or IDP
- Budget alignment to planned initiatives
- Benefits tracking against approved business cases
04
Performance and Spend Oversight
Boards routinely approve ICT budgets and then receive nothing that tells them whether the money achieved anything. We assess what reporting reaches the governing body and whether it supports a decision.
- ICT performance reporting to the governing body
- Project portfolio status and escalation of failures
- Contract and vendor performance oversight
- Value delivered against approved spend
05
Risk and Assurance Integration
Technology risk that lives only in an ICT register is not governed. We check whether it reaches the organisational risk register, the audit committee and the combined assurance model.
- ICT risk on the organisational risk register
- Escalation thresholds and reporting frequency
- Coverage in the combined assurance model
- Tracking of prior audit findings to closure
What You Receive
- Governance structure and mandate assessment
- Policy framework gap analysis with currency status
- ICT strategic plan and budget alignment review
- Assessment of reporting reaching the governing body
- Prioritised governance improvement roadmap
- Board and audit committee summary
Indicative Timeline
A governance assessment normally runs two to four weeks. It is document and interview driven rather than test driven, so it moves faster than an ITGC review, but obtaining minutes and approval records is frequently the constraint.
- Document request and review: one week
- Interviews with management and committee members: one week
- Analysis and draft report: three to five days
- Management comment and final report: one week
What We Assess Against
Governance is measured against the codes and frameworks your board and auditors already answer to.
King IV Principle 12
The governing body governs technology and information in a way that supports the organisation setting and achieving its objectives.
COBIT 2019
Governance and management objectives, and the separation between the two that most structures blur.
MFMA and PFMA
Public sector requirements for planning, spend authorisation and reporting that ICT governance has to satisfy.
Treasury Regulations
Prescribed governance and reporting arrangements applying to public entities and municipalities.
ISO/IEC 38500
The international standard for corporate governance of information technology.
Combined Assurance
Whether technology risk is covered by somebody, and whether the board can see who.
Frequently Asked Questions
How is this different from an ITGC review?
An ITGC review tests whether controls operate. A governance assessment asks whether anybody is accountable for them, whether the right structures exist and whether the board receives enough to govern. Findings from the two are frequently linked, because a control failure often traces back to a governance gap.
What does King IV Principle 12 actually require?
That the governing body governs technology and information rather than delegating and forgetting. In practice that means an approved policy framework, defined decision rights, oversight of ICT spend and performance, and technology risk visible at board level.
We are a municipality. Does King IV apply to us?
King IV is a code rather than legislation, but it is widely applied in the public sector and the MFMA imposes parallel obligations for planning, authorisation and reporting. We assess against both so findings are actionable under whichever framework applies.
Do we need an ICT steering committee?
Not necessarily a separate one, but the function has to sit somewhere with a mandate and minutes. Many smaller organisations discharge it through an existing committee, which is acceptable provided the terms of reference say so.
Will this find the same issues as the external auditors?
Often, which is the point. Identifying a governance weakness before the external audit gives you a remediation window. Repeat findings damage an audit outcome considerably more than first time findings.
What happens after the assessment?
You receive a prioritised roadmap rather than a list of complaints. Where documents are missing we can draft them, and where structures need establishing we help write the terms of reference.
Related Services
This sits inside our ICT Audit practice. Related work: IT General Controls Reviews for the operating controls beneath the governance layer, and Business Advisory for wider King IV application at board level.
