IT Governance Assessment

Most ICT audit findings do not originate in the server room. They originate in a governing body that accepted responsibility for technology on paper and never operationalised it. King IV Principle 12 makes technology and information governance a board responsibility, which means the structures, the reporting and the decision rights all have to exist and be evidenced. We assess whether they do.

1

Structures

Committees and mandates

2

Policies

Currency and approval

3

Planning

Strategy and budget

4

Reporting

What reaches the board

5

Report

Gaps and roadmap

How We Assess

01

Governance Structures and Mandates

We start with who is actually accountable. That means reviewing the committee structure, the terms of reference, the delegation of authority and whether the people named in those documents attend, decide and are minuted doing so.

02

Policy Framework Review

A policy suite is only governance if it is current, approved and known. We assess coverage against the risks the organisation actually carries, check approval dates and establish whether staff have ever been made aware of the documents.

03

ICT Strategic Planning

Technology spend that is not tied to a plan tends to be defended after the fact. We review whether an ICT strategic plan exists, whether it aligns to the organisational strategy, and whether the budget actually follows it.

04

Performance and Spend Oversight

Boards routinely approve ICT budgets and then receive nothing that tells them whether the money achieved anything. We assess what reporting reaches the governing body and whether it supports a decision.

05

Risk and Assurance Integration

Technology risk that lives only in an ICT register is not governed. We check whether it reaches the organisational risk register, the audit committee and the combined assurance model.

What You Receive

Indicative Timeline

A governance assessment normally runs two to four weeks. It is document and interview driven rather than test driven, so it moves faster than an ITGC review, but obtaining minutes and approval records is frequently the constraint.

What We Assess Against

Governance is measured against the codes and frameworks your board and auditors already answer to.

King IV Principle 12

The governing body governs technology and information in a way that supports the organisation setting and achieving its objectives.

COBIT 2019

Governance and management objectives, and the separation between the two that most structures blur.

MFMA and PFMA

Public sector requirements for planning, spend authorisation and reporting that ICT governance has to satisfy.

Treasury Regulations

Prescribed governance and reporting arrangements applying to public entities and municipalities.

ISO/IEC 38500

The international standard for corporate governance of information technology.

Combined Assurance

Whether technology risk is covered by somebody, and whether the board can see who.

Frequently Asked Questions

An ITGC review tests whether controls operate. A governance assessment asks whether anybody is accountable for them, whether the right structures exist and whether the board receives enough to govern. Findings from the two are frequently linked, because a control failure often traces back to a governance gap.

That the governing body governs technology and information rather than delegating and forgetting. In practice that means an approved policy framework, defined decision rights, oversight of ICT spend and performance, and technology risk visible at board level.

King IV is a code rather than legislation, but it is widely applied in the public sector and the MFMA imposes parallel obligations for planning, authorisation and reporting. We assess against both so findings are actionable under whichever framework applies.

Not necessarily a separate one, but the function has to sit somewhere with a mandate and minutes. Many smaller organisations discharge it through an existing committee, which is acceptable provided the terms of reference say so.

Often, which is the point. Identifying a governance weakness before the external audit gives you a remediation window. Repeat findings damage an audit outcome considerably more than first time findings.

You receive a prioritised roadmap rather than a list of complaints. Where documents are missing we can draft them, and where structures need establishing we help write the terms of reference.

Related Services

This sits inside our ICT Audit practice. Related work: IT General Controls Reviews for the operating controls beneath the governance layer, and Business Advisory for wider King IV application at board level.

Discuss an IT governance assessment