
IT auditor
Examines IT processes and controls against agreed criteria, gathers evidence, assesses identified exceptions and produces supported findings and recommendations for improvement.
On this profession page, you will learn:
Who is IT auditor
Are departing employees’ permissions removed, changes approved and backup recovery tested? The IT auditor investigates such questions through documents, record samples, interviews and technical evidence. A written procedure is distinguished from evidence that it actually operated during the period examined.Deliverables include audit working papers, supported findings and agreed corrective actions. Facts are discussed with process owners while maintaining independent judgment. The auditor checks follow through on recommendations but does not replace daily administration or management’s responsibility for operating controls.
AI impact on IT auditor
Medium riskAI replacement risk
50%
AI may help organise evidence and draft reports. Evidence sufficiency, conclusion limits and independent judgment remain the auditor’s responsibility.
Tasks at risk of automation
- Initial evidence grouping
- Draft observation descriptions
Tasks that will remain human
- Assessing evidence sufficiency
- Forming an independent conclusion
Key skills of IT auditor
Work schedule and conditions
Audit teams combine evidence analysis with interviews and discussion of findings. The work requires confidentiality, attention to sampling limits and calm explanation of uncomfortable facts during report discussions.
What a IT auditor does
- Define audit scope, risks and evaluation criteria
- Gather evidence and test samples of control operation
- Link identified exceptions to risk and supported facts
- Report findings and verify agreed remediation
Benefits of the IT auditor profession
Evidence led work
Findings can be built on checked records and facts, helping an organisation distinguish declared procedures from controls that actually operate.
Broad IT understanding
Reviewing different processes develops understanding of access, change, recovery and vendor management, revealing connections between technical and organisational decisions.
Disadvantages of the IT auditor profession
Difficult discussions
Process owners may disagree with findings, requiring patient explanation of evidence, separation of facts from assumptions and careful refinement of wording.
Limited evidence
Incomplete logs and small samples can limit conclusions, while a missing record does not always establish why a procedure failed.
How to become a IT auditor
Combine IT process knowledge with audit methods.
1. Study
Study internal controls, risk assessment, sampling, access, change management and system recovery.
2. Practice
Use fictional change tickets to test approvals and write a finding with evidence, limitations and a recommended action.
Begin real reviews with clearly defined scope and professional supervision.
Vocational training
Information Systems Auditing, Controls and Assurance
4 weeks of study, 2 hours/week
Coursera