Summary
The IT Audit and Information Systems Auditing Training Course is a professional corporate training programme designed to strengthen organisational capabilities in technology assurance, information systems governance, internal controls and technology risk management. As organisations increasingly depend on enterprise applications, cloud environments, digital platforms and interconnected information systems, effective IT audit practices have become essential for maintaining operational resilience, regulatory compliance, information security and business continuity.
This course focuses on practical approaches to IT audit and information systems auditing within complex corporate environments. It addresses the processes required to assess technology controls, evaluate information system risks, review user access, examine application controls and determine whether IT processes are operating effectively. The programme provides a structured approach to understanding how technology-related risks can affect financial reporting, operational performance, data protection and organisational governance.
The training incorporates important areas such as ITGC testing, systems access review and application control audits. These areas are particularly relevant for organisations seeking stronger assurance over general technology controls and business-critical applications. Participants gain an integrated understanding of how IT auditors assess control design, test control effectiveness, identify weaknesses and communicate findings to management and relevant stakeholders.
The Geneva Institute of Business Management delivers this training with a strong focus on corporate requirements and business-oriented audit practices. The programme is suitable for organisations that need professionals capable of evaluating technology environments, supporting internal audit functions and contributing to effective risk and control frameworks.
Modern IT audit requires more than checking technical configurations. It requires an understanding of business processes, governance responsibilities, risk exposure, access management, application functionality, change management and evidence-based assurance. This course therefore connects information systems auditing with broader organisational objectives, enabling professionals to approach technology assurance from a business and risk perspective.
The course forms part of the Review and Audit Training Courses category and provides a structured professional framework for reviewing IT environments, information systems and technology-enabled business processes.
Objectives
The primary objective of the IT Audit and Information Systems Auditing Training Course is to develop a practical and commercially focused approach to technology assurance and information systems control evaluation.
Strengthen IT Audit Capabilities
The programme develops a structured approach to planning, conducting and documenting IT audits. Participants examine how audit objectives can be aligned with organisational risks, business processes and technology dependencies.
The training supports professionals in developing audit procedures that provide meaningful assurance rather than simply reviewing technical configurations. It covers the relationship between audit scope, risk assessment, control objectives, testing procedures, evidence collection and reporting.
Develop IT Risk Assessment Practices
Effective information systems auditing begins with understanding the risks associated with technology and business operations. The course examines approaches for identifying technology risks across infrastructure, applications, users, data and processes.
Participants explore how risks can be assessed according to their potential impact on confidentiality, integrity, availability, compliance and business continuity. This supports better prioritisation of audit resources and more focused control testing.
Apply ITGC Testing Techniques
ITGC testing is a central component of many corporate IT audit programmes. The course addresses the assessment of general technology controls covering areas such as access management, change management, IT operations, backup procedures and system administration.
Participants develop an understanding of how ITGC testing can be structured, documented and evaluated. The emphasis is placed on determining whether controls are appropriately designed and consistently operating.
Improve Systems Access Review
Unauthorised or excessive system access can expose organisations to significant security, operational and compliance risks. The course therefore provides practical insight into systems access review processes.
Participants examine user provisioning, access modification, termination procedures, privileged access, role-based permissions and periodic access certification. The programme also considers how access controls can be assessed against business responsibilities and segregation of duties requirements.
Strengthen Application Control Audits
Business applications frequently support financial, operational, customer and regulatory processes. Application control audits help determine whether automated controls within these systems are appropriately designed and functioning as intended.
The course examines application-level controls, data validation, transaction processing, authorisation, automated calculations, exception handling and interface controls. This enables professionals to assess whether applications provide reliable and controlled processing of business information.
Enhance Audit Evidence and Documentation
Reliable audit conclusions depend on appropriate evidence. The programme addresses methods for collecting, evaluating and documenting audit evidence in technology environments.
Participants examine how audit documentation can clearly demonstrate the procedures performed, evidence reviewed, control conditions identified and conclusions reached. Strong documentation supports transparency, management review and subsequent audit activities.
Improve Audit Reporting
Technology audit findings must be communicated in a way that enables management to understand risk exposure and take appropriate action. The course develops approaches for presenting findings based on risk, impact, root cause and recommended corrective action.
Participants learn how to distinguish between control weaknesses, process deficiencies and significant technology risks while developing clear and commercially relevant audit reports.
Target Audience
The IT Audit and Information Systems Auditing Training Course is designed for professionals involved in technology governance, internal audit, information security, risk management, compliance and business control functions.
IT Auditors
IT auditors can use the programme to strengthen audit planning, control testing, evidence evaluation and reporting capabilities. The training supports professionals responsible for reviewing technology processes across enterprise environments.
Internal Auditors
Internal audit professionals can benefit from a stronger understanding of information systems risks and technology controls. The course supports internal auditors who increasingly need to incorporate IT considerations into broader operational, financial and compliance audits.
Information Security Professionals
Information security specialists can use the training to develop a more structured understanding of audit requirements, control assurance and evidence-based evaluation of security-related processes.
Risk and Compliance Professionals
Risk and compliance teams can benefit from understanding how technology controls contribute to organisational risk management and regulatory requirements. The programme provides insight into control weaknesses that may create operational, security or compliance exposure.
IT Managers and Technology Leaders
IT managers can use the course to strengthen their understanding of audit expectations and control requirements. It helps technology leaders establish better cooperation with internal audit, external audit, risk and compliance functions.
Systems and Application Managers
Professionals responsible for enterprise applications can benefit from understanding how application controls, access management and change processes are evaluated during information systems audits.
Governance Professionals
Corporate governance professionals can use the training to understand the relationship between technology governance, risk management, internal controls and organisational assurance.
Professionals Responsible for Technology Controls
The course is also suitable for professionals responsible for IT operations, access administration, change management, system controls, technology compliance and business continuity.
Modules
Module 1: Foundations of IT Audit and Information Systems Auditing
This module establishes the corporate framework for IT audit and information systems auditing. It examines the purpose of technology assurance and its relationship with organisational governance, risk management and internal control.
Key areas include:
- Role and scope of IT audit
- Information systems audit objectives
- Technology risk and business risk relationships
- Audit independence and professional responsibilities
- Audit planning and scoping
- Technology control environments
- Audit criteria and control objectives
- Risk-based IT auditing
- Audit documentation and working papers
Module 2: IT Audit Planning and Risk Assessment
This module focuses on establishing an effective audit strategy based on organisational priorities and technology risks.
Key areas include:
- Understanding business processes and technology dependencies
- IT risk identification
- Risk assessment methodologies
- Audit universe development
- Risk-based audit planning
- Defining audit scope and objectives
- Identifying critical systems
- Determining audit priorities
- Developing audit procedures
- Preparing audit work programmes
Module 3: IT General Controls and ITGC Testing
This module examines the structure and evaluation of general technology controls. ITGC testing is addressed as a core process for assessing whether foundational technology controls are appropriately designed and operating effectively.
Key areas include:
- IT general control frameworks
- Access management controls
- Change management controls
- IT operations controls
- Backup and recovery controls
- Incident management
- System administration controls
- Job scheduling and monitoring
- ITGC testing approaches
- Control evidence requirements
- Control exceptions and deficiencies
- Evaluating operating effectiveness
Module 4: Systems Access Review and Identity Controls
This module focuses on access-related risks across enterprise information systems. Systems access review is examined from both security and audit perspectives.
Key areas include:
- User account management
- User provisioning and deprovisioning
- Access authorisation
- Role-based access
- Privileged user access
- Segregation of duties
- Periodic access reviews
- Terminated user access
- Dormant accounts
- Access recertification
- Password and authentication controls
- Access-related audit evidence
Module 5: Application Control Audits
This module examines controls embedded within business applications and their role in ensuring reliable transaction processing.
Key areas include:
- Application control objectives
- Input controls
- Processing controls
- Output controls
- Automated calculations
- Validation controls
- Authorisation controls
- Exception reporting
- Interface controls
- Data integrity controls
- Transaction completeness
- Transaction accuracy
- Application control audits
Module 6: Change Management and Systems Development Controls
Technology changes can introduce significant operational and control risks. This module addresses the audit of system development and change management processes.
Key areas include:
- Change request procedures
- Change approval
- Testing and quality assurance
- Development and production separation
- Emergency changes
- Version control
- Release management
- System implementation controls
- User acceptance processes
- Change-related audit evidence
Module 7: IT Operations and Business Continuity Controls
This module evaluates operational controls that support system availability, resilience and continuity.
Key areas include:
- IT operations management
- Backup controls
- Recovery procedures
- Business continuity
- Disaster recovery
- System monitoring
- Incident management
- Availability controls
- Capacity management
- Operational documentation
- Recovery testing
- Technology resilience
Module 8: Data Governance and Information Security Controls
This module considers the relationship between information systems auditing, data governance and information security.
Key areas include:
- Data governance controls
- Information classification
- Data integrity
- Data confidentiality
- Data availability
- Security monitoring
- Security control assessment
- Data access management
- Information handling
- Technology-related compliance risks
Module 9: Audit Testing, Evidence and Analytical Techniques
This module develops practical approaches for testing technology controls and evaluating audit evidence.
Key areas include:
- Audit sampling
- Control testing
- Evidence collection
- Evidence evaluation
- Test procedures
- Exception identification
- Data analysis
- Audit trail examination
- Documentation standards
- Working paper quality
- Root cause analysis
- Control effectiveness assessment
Module 10: IT Audit Findings and Reporting
This module focuses on communicating technology audit results to management and relevant stakeholders.
Key areas include:
- Audit finding development
- Risk-based classification
- Root cause identification
- Business impact assessment
- Corrective action recommendations
- Management responses
- Audit report structure
- Executive-level communication
- Follow-up procedures
- Remediation monitoring
Module 11: Governance, Risk and Compliance Integration
This module connects IT auditing with broader corporate governance, risk and compliance activities.
Key areas include:
- Technology governance
- IT risk management
- Internal control frameworks
- Compliance monitoring
- Risk ownership
- Control accountability
- Audit committee reporting
- Assurance coordination
- Regulatory expectations
- Continuous control improvement
Module 12: Integrated IT Audit Review
The final module brings together the major components of information systems auditing into an integrated corporate audit approach.
Participants review the relationship between IT risk assessment, ITGC testing, systems access review, application control audits, evidence evaluation and management reporting.
The module focuses on developing a complete audit perspective that considers technology, business processes, controls, risks and organisational objectives together. It supports professionals in applying consistent audit methodologies across different information systems and corporate environments.
FAQs
What is covered in the IT Audit and Information Systems Auditing Training Course?
The course covers IT audit planning, technology risk assessment, IT general controls, ITGC testing, systems access review, application control audits, change management, IT operations, data governance, audit evidence and technology audit reporting.
Who should attend this IT audit training course?
The programme is suitable for IT auditors, internal auditors, information security professionals, risk and compliance specialists, IT managers, systems managers, governance professionals and individuals responsible for technology controls.
Why is ITGC testing important in corporate IT auditing?
ITGC testing helps organisations assess foundational controls surrounding areas such as access management, change management and IT operations. Effective testing provides assurance that key technology controls are appropriately designed and operating consistently.
What is the purpose of systems access review?
A systems access review helps organisations determine whether users have appropriate access according to their responsibilities. It can identify excessive privileges, inappropriate access, inactive accounts and potential segregation of duties concerns.
How do application control audits support business assurance?
Application control audits assess automated and system-based controls that influence transaction processing, data accuracy, authorisation and completeness. They help organisations identify weaknesses within business-critical applications and strengthen the reliability of information systems.
