ICT Audit

Information technology controls sit underneath almost every financial assertion, which is why ICT findings feature so heavily in public sector audit outcomes. We test the controls themselves rather than reading a policy document and calling it assurance. Our team runs these engagements at municipal level, where the findings end up in front of the Auditor General.

IT General Controls Reviews

Four domains carry most of the risk: who can get into the system, how changes reach production, how the environment is run day to day, and whether data can be recovered. We test each one against evidence rather than against what the policy says should happen.

IT Governance Assessment

King IV makes the governing body responsible for technology and information, and most ICT findings trace back to that responsibility never being operationalised. We assess the governance structures, the policies meant to support them, and whether ICT spending and delivery are reported upward at all.

Application and Data Integrity Controls

General controls protect the environment, but the business logic sits inside the applications. We test input validation, calculation accuracy, interface completeness and the reconciliations that are supposed to catch whatever slips through.

Disaster Recovery and Continuity

Almost every organisation has a continuity plan. Far fewer have tested one. We review the plan against the recovery objectives the business actually needs, check whether the backups restore, and report the distance between the documented position and the real one.

POPIA and Data Protection Readiness

POPIA compliance is usually handled as a legal exercise and then never reflected in the systems. We look at where personal information actually lives, who can reach it, how long it is kept, and whether the operator agreements match what the systems permit.

Audit Finding Remediation

A repeat ICT finding damages an audit outcome more than a first time finding does. We take the management report, work out the control weakness underneath each finding rather than the symptom described, and help you build remediation that survives the following audit.

Discuss an ICT audit