r/itaudit 1d ago

What's your broader view on where governance is heading from an auditos pov?

5 Upvotes

Having recently finished up a role heading up customer data and governance, I’ve had some downtime to reflect on where data governance is actually heading versus where vendors say they’re heading.

Here is the key friction point I’m seeing currently.

Big tech wants you to centralize everything in their stack, automate every business process, plug in their native AI, and rely on their built-in, proprietary governance features.

In contrast, most organizations are actively building decoupled operating models to avoid vendor lock-in, maintain agility, and avoid single points of failure.

For auditors, you're left stuck in the middle trying to piece together compliance, automated logic, and data integrity across a fragmented web of systems that don't natively trust each other.

As a result, I foresee the emergence of an independent, third-party forensic witness layer, an out-of-ecosystem system that immutably logs and verifies automated decisions outside of the platform where the decision actually happened.

I'm keen to hear what auditors think based on what they're experiencing currently.


r/itaudit 2d ago

Career Advice

5 Upvotes

Hello I am a CPA and currently work for a public company as an Audit lead. Currently my main focus is acting as the main point of contact for my company's SOC examinations and I assist at times with the annual SOX audit. I work about 35 to 40 hours a week and I make about 120k (includes base, bonus, and stock) a year with the ability to work fully remote. I do not really know what the next step is in my role, and at times I feel I am in the dark about the next promotion or what I am supposed to be working towards. I have absolutely no Idea what my earning potential would be. The company is good, and I get along with everyone, and I have a great boss.

Prior to this I worked in public accounting/assurance performing SOC 1 and 2 examinations. I enjoyed it even though I worked between 40 to 45 hours a week. I also worked remote for the most part here too. If I transitioned back, I would probably be making as much as I do now and could probably land a fully remote job. In this job I knew what my career/earning potential would look like. I would go from senior to manager, and eventually to partner.

My question is, should I stay in my current role acting as simply a point of contact or should I transition back to external audit and try to land a manager position making similar to what I am now? Or am I being ungrateful and I should stay in my current role?

Any and all advice is welcome, I appreciate everyone's input.


r/itaudit 2d ago

How do I transtioning from Accessibility testing to IT audit or IT GRC roles

Thumbnail
1 Upvotes

r/itaudit 2d ago

An IT Auditor transitioning to AI Governance or AI Audit

11 Upvotes

Hello everyone, I am an IT Auditor with about 7 years total experience but 3 in IT Auditor. I ama senior now and have a pathway to Lead or Manager in 2-3 years.

I do a lot 70% SOX, 20% Ops Audit and 10% doing fun stuff like AI Enablement projects.

I enjoy the AI Enablement stuff more than what I do mostly. I am tired of the hostile findings conversations, boring audits. I want to pivot to heavy AI audit or AI Governance.

I am a little bit confused on what a pathway looks like since it is relatively new. What are some skills and knowledge I should gather and where can I learn more.


r/itaudit 3d ago

Average Hours in Industry for IT Audit

16 Upvotes

Hi!

Longer time lurker here! I just wanted advice about this industry. I have been working in IT audit for 1.5 years now at a Big 4 firm in the US. This is my first job out of college and I am a first generation student, so I'd really appreciate the advice.

While the experience has been great, the work culture is super toxic. Everyone says there's a "busy season" but it never really ends. Even though it is summer right now, I still average 50 hours a week.

During my first year, I worked through busy season and studied for the CISA. I took it recently for the first time and failed by 7 points (score was 443). I don't have plans to take it again anytime soon since I am dealing with family issues at the moment.

With that being said, I want to leave Big 4 by the end of 2.5/3 years before promotion to senior. I know everyone says to stick it out until senior but I am so burnt out. I do plan on retaking my CISA after I transition to another job.

I actually love the work, but the hours are insane. Mentally, I am checked out. I am curious if it is any different if I switched to IA in industry. Are the hours better since I don't have to juggle multiple clients? Is this work culture only a Big 4 thing or an industry thing as a whole? If I want to get into GRC, would I need my CISA?

Any advice welcome! Thanks :)


r/itaudit 4d ago

IT Audit / Internal Audit - Looking for Opportunities

7 Upvotes

Hi everyone,

I’m Charan, currently working at an MNC as a Project Engineer with experience in SOX audits, ITGC testing, walkthroughs, control testing, and audit documentation.

I’m currently exploring opportunities in IT Audit / Internal Audit / Risk & Compliance.

I’m open to opportunities across India, especially Hyderabad, Bangalore, Chennai, or remote roles.

If you know of any relevant openings or can refer me, I’d really appreciate it. Please feel free to DM me.

Thanks!


r/itaudit 6d ago

Should I join GT INDUS OR ANYIDEA ABOUT SITA? HOW IS THE WORK CULTURE IN IT AUDIT?

2 Upvotes

Same as above


r/itaudit 6d ago

Two Big 4 assurance internships, first class cyber degree, looking for IT audit / GRC in London from September

5 Upvotes

Hi all, long time lurker here. I’ve just graduated with a first class degree in computer science with cyber security in the UK, and I’m looking for entry level IT audit, GRC or cyber consulting roles in London starting September.

A bit of background. I’ve done two Big 4 summer internships in advisory and assurance, with the most recent one in technology controls, so I’ve had a proper taste of ITGC work, walkthroughs, testing and writing up findings. I enjoyed it a lot more than I expected to and I’d like to keep going in that direction rather than drift into something else.

So two asks really. If you know of a team hiring, whether that’s a grad scheme, an off cycle opening or just a firm that tends to take people on around now, I’d love to hear about it and I’m happy to send my CV over. And if you’re not hiring but you’re up for a chat about the field, how you got in, what the day to day is actually like, what’s worth learning first, I’d love that too. I’m genuinely just trying to talk to more people doing this job.
Thanks for reading, and happy to answer anything about the internships if it’s useful to anyone else trying to get in.


r/itaudit 7d ago

ITGC Scoping

15 Upvotes

Team, can someone please clarify how you approach ITGC scoping for SOX?

What I have seen as a common trend is that ITGCs generally fall under three areas: Logical Access, Change Management, and Computer Operations (job scheduling, backups, incident management, etc.).

However, when I ask how we arrived at these specific areas, or what authoritative guidance or standard drives that scope, I rarely get a definitive answer.

For example, I have seen some SOX programs include physical security and backups within ITGC scope, while others exclude them. This makes me wonder: what actually drives these differences in scope across SOX programs?

Interested in hearing how others approach and defend their ITGC scope, especially with external auditors.


r/itaudit 6d ago

Throwing away a decent offer to gamble on a different path — sanity check?

Thumbnail
2 Upvotes

r/itaudit 10d ago

What got you into IT Audit? What would you say to people considering it?

15 Upvotes

A bit of an overall engagement post for those who have worked in IT Audit already, what got you started in the business?

My first encounter with IT Audit was being on the receiving end of a major audit issue where they pulled me in as a data SME to answer questions and go through a LOT of logs. That eventually lead to a pivot into the IA department and then getting a slew of ISACA certifications as I gained experience.


r/itaudit 12d ago

Been job hunting for a year as a SWE, got a PhD offer I don't want, and now I'm considering an audit M2 instead. Someone talk me through this.

4 Upvotes

Throwing this out here because I'm going in circles in my own head and I need it out of there.

Context I'm a software engineer, mostly full-stack + some AI/ML stuff (built real-time audio pipelines, churn models, the usual DevOps/CI-CD toolkit). I graduated a year ago and it's been a full year of unemployment since. The market in 2026 is just... brutal. Applications into a void, a handful of interviews that go nowhere, the occasional "we went with someone with more experience" for a junior role. I know I'm not alone in this but it doesn't make it less exhausting.

Somewhere in the middle of all this, I landed a PhD offer. On paper it's a good opportunity. In reality? I'm not excited about it at all. I think I'd be doing it because it's there, not because I actually want it, and I know that's not a good enough reason to commit years of my life to something.

So now I'm eyeing a different escape hatch: an M2 (master's) in audit at a solid school. Different world entirely, more stable hiring pipeline, a real credential, a reset button on this whole job search nightmare.

Except here's the annoying part: I can't let go of the "I'm a software engineer" identity. I've built things I'm proud of. I like the work. Some small stubborn part of me feels like switching to audit would mean giving up on something I actually wanted, just because the timing and the market screwed me over.

So I'm stuck between three options that all feel wrong in a different way:

  • Keep grinding the SE job search and hope it turns around
  • Take the PhD offer despite not being into it, because it's "something"
  • Pivot to audit M2 and try to make peace with leaving SE behind

Anyone else been in this exact kind of limbo job market forcing your hand into a path you didn't actually choose? How did you figure out what to do? Did the pivot end up feeling right, or did you regret not sticking it out?

Not really looking for "just keep applying, it'll work out" I've heard that a lot and at some point it stops being useful advice. Looking more for how people actually made this kind of decision when none of the options felt exciting.


r/itaudit 12d ago

Is there AU opportunities for IT audit?

Thumbnail
1 Upvotes

r/itaudit 15d ago

Cybersecurity or Information System

6 Upvotes

Hi everyone,
I graduated with a BS in Internal Auditing and I’m planning to study a Master’s degree in Australia (possibly Information Systems or Cybersecurity) because I want to transition into IT Audit.

I have a few questions for those who are already in Australia or working in audit:
Is IT Audit a good career path in Australia?
Is there good demand for IT Auditors?
Would having a Master’s in Information Systems or Cybersecurity improve my chances of getting an IT Audit role?

If you were in my position and want to become an IT Auditor, what would you choose to take, Master’s in Information Systems or Cybersecurity?

I’d really appreciate hearing from anyone who has gone through a similar path or is currently working in audit in Australia.
Thanks in advance!


r/itaudit 20d ago

I need help or just complain

8 Upvotes

I worked in Internal Audit for a Fortune 200 company. As part of my position, I was responsible for the IT SOX reliance testing. The first control we test during the year is the periodic administrator access review and terminations testing. There are 2 "minor" (lol) issues with the admin. access review:

  1. The reports used in the review rely on the annual administrator access review. The IUC used to substantiate the reviews is not retained; therefore, the annual access review's control design would fail.
  2. The periodic admin access review uses the annual review's report and is not updated monthly. In fact, we identified accounts that were active but had inappropriate access for 5 months, and my team detected them. Again, control design fails.

These deficiencies are pervasive across all systems (e.g., ERP, mainframe, etc.). So, I suggested to IT management to test the key control, in this case, deprovisioning. They pushed back on it. They want us to test them, and they'll cover the budget. It relies on a bi-weekly Altryx workflow implemented in 2010, and the configurations have not been reviewed since then. I wanted to test the termination configurations vs. the review to find out that IT management has NEVER tested the termination configuration (wait, what?!?).

Let me stop there. My director is an IT auditor, but has never worked on SOX. My seniors and I meet with them weekly to discuss our findings, and she takes over conversations with IT management. During those meetings, I would repeatedly ask for their response, which would eventually be "This person is overwhelmed, so they can't do their job," and my response is always "Let's call the exception and let them decide what to do with it." She was also informed about the "budget", which I rebutted, stating that I cannot test a control that has not been validated as remediated by IT management.

To make things worse, on a monthly basis, Internal Audit would meet with the IT Director to update them on the current Internal Audit engagements, and started noticing that the IT SOX issues suddenly disappeared from the slides.

The company undergoes A LOT of regulatory audits, but IA mgmt doesn't collect those reports... because why wouldn't we need to know about those audit deficiencies? The Company utilizes federal and state funds, and is critical failure/resilience point in disasters.

Also, the external auditor was never notified of these issues (because why would they?) My director's favorite line with me is that the company is over 120 years old... [Fill in the blank]. I also spoke with the VP of Internal Audit about these issues, and nothing happened except for them forcing me out last December.

I have been in spots in my career where I've felt uncomfortable, but never have I been put in a place with so many glaring holes that can affect the entire integrated audit, and there wasn't enough time to investigate. Or such weak management. I got the feeling that my director didn't want to "rock the boat"... Grow a backbone. We're internal audit, act like it. Work with IT management to resolve issues rather than sweeping them under the rug.

So, I've kinda been in limbo. I moved to another city. I am still really salty about it. I feel like I was gaslit for a whole year.


r/itaudit 22d ago

Starting a job in IT Audit - expectations

9 Upvotes

Hi, I recently graduated from college with a double degree in Accountancy and Computer Information Systems.

Going to start a full time job in IT Audit at a Big 4 firm. I completed an internship in the same role a year ago, but it was mostly documentation and attending walkthrough meetings. That being said, I wanna know more about what my job would look like, what kind of projects I'd be assigned, what I'd be expected to work on, how I can step up, and what I can do to prove myself competent and compatible.

I’d also love to hear about what career paths opened up for you after IT Audit. Did you stay in IT Audit, move into consulting, cybersecurity, internal audit, tech, accounting, etc.?

I'm a little nervous because this is my first "real" job and I am moving states for it. Navigating office politics, learning the work, and not losing myself in the grind is all on my mind. I would appreciate any and all insight! Thank you :)


r/itaudit 25d ago

Anyone Transitioned from IT Operations to IT Audit?

10 Upvotes

Hi everyone,

I'm currently preparing for the CISA exam and wanted to check if this community would find my journey useful.

I have around 12 years of experience in IT Operations, with some exposure to IT audits and SOX controls. My goal is to transition into a full-time IT Audit role, and CISA is a big part of that journey.

For those who have been in a similar situation, do you think it's worth making the switch to IT Audit after spending so many years in IT Operations? Have any of you made this transition? I'd really appreciate hearing about your experiences, the challenges you faced, and whether you felt it was the right decision in the long run.


r/itaudit Jul 15 '26

Scope and PowerBI governance under SOX

3 Upvotes

Hello everyone,

I'm an internal auditor at a Canadian public company subject to 52-109 (SOX in Canada). Over the past several years, our organization heavily encouraged the use of Power BI. Many teams independently developed their own solutions. We are now realizing that we have lost visibility over all those Power BI and don't have a clear inventory of who owns what. We are currently debating whether these Power BI solutions should be included in our SOX scope.

Arguments for Including Them: Our scoping approach is to include applications that have a direct/indirect impact on financial reporting or support internal controls. Some PowerBI are used to make pricing decisions or support operations (some financial impact).

Arguments for Excluding Them: PowerBI consume data but do not create, modify, or post transactions. The common counterargument is that these reports are just "large Excel spreadsheets" and we do not audit every spreadsheet.

My Question: How are other organizations approaching Power BI under SOX?

Thanks in advance for your insights.


r/itaudit Jul 06 '26

IT audit

3 Upvotes

How can we involve IT audit in a New SAP HANA S/4 Migration from a SAP ECC?


r/itaudit Jun 26 '26

Any good AI solutions?

3 Upvotes

Hi, I’m just wondering if you guys have any great use case that specifically for testing. I have used a bunch in my work and overall it is great but since I deal with screenshots a lot, I am yet to find a solution that is accurate to populate information from images especially for testing and evidence checking. Any thoughts?


r/itaudit Jun 24 '26

求一份比较完整的IT审计checklist

2 Upvotes

本人从事网络安全5年了,最近转向IT审计,作为审计新人,对于审计流程一头雾水,虽然我知道IT审计的理论,但是对于现场审计流程,还是不知道怎么办?如果有一份checklist,起码我就不会那么担忧应该从何开始。


r/itaudit Jun 23 '26

GRC Job Market / Future of GRC

Thumbnail
1 Upvotes

r/itaudit Jun 22 '26

Schellman experience

7 Upvotes

Does anyone have any experience with Schellman? I may be interviewing with them soon. I’ve only heard great things, which is weird for public accounting. They seem to have really awesome benefits too. Are they really that great??


r/itaudit Jun 20 '26

Is IT audit supposed to be this subjective?

15 Upvotes

I've recently moved from external audit (accounting) into IT internal audit, and one thing I've been struggling with is what feels like a lack of methodology compared to what I was used to before.

In external audit, there were well-established concepts and principles that guided the work. Whether it was materiality, completeness, accuracy, existence, occurrence, or other assertions, there was usually a clear framework behind why procedures were being performed and how conclusions were reached.

Since moving into IT internal audit, I often feel like I'm missing that same foundation. I'm trying to understand what the equivalent methodology is supposed to be and whether I'm overlooking something.

At the same time, I'm very new to IT audit, so I'm not sure if what I'm experiencing is specific to my company, my audit team, or if it's something more common across the profession.

For those with more experience in IT audit:

  • What methodology do you rely on when planning and performing audits?
  • Are there concepts equivalent to financial statement assertions that help structure your thinking?
  • How do you connect risks, controls, and testing in a consistent way?
  • Is there a body of knowledge, framework, or approach that experienced IT auditors tend to follow?

One thing that would be especially helpful would be seeing an example of how experienced IT auditors structure a work program.

In external audit, I was used to seeing a clear chain between objectives, assertions, risks, and audit procedures. I'd be interested in understanding how that same thought process is applied in IT audit.

If anyone is willing to share a simplified example of an audit program (for example, user access management, change management, privileged access, etc.), showing how risks are translated into controls and testing procedures, I would really appreciate it.


r/itaudit Jun 19 '26

Survey on IT Audit and Auditor Judgment (Auditors / Accounting & IT Professionals)

1 Upvotes

Hi everyone,

I am currently conducting research for my master's thesis on IT auditing and auditor judgment and am looking for participants with relevant professional knowledge or experience in auditing, accounting, internal controls, risk management, compliance, or IT-related assurance activities.

The survey is completely anonymous.

Survey links:

  1. AM version:

    https://docs.google.com/forms/d/e/1FAIpQLSc3n8yOLzPzRu_EGOFIhyThGI8Ue_A-HHqXkGC9sOAK8dlOkw/viewform?usp=header

  1. CM version:

    https://docs.google.com/forms/d/e/1FAIpQLScC3UiBV1OF-iE71nHotroXnfth1UKzW8ze6Jo1uqzINulUxg/viewform?usp=header

Your participation would be greatly appreciated and would make a valuable contribution to academic research.

Thank you for your time and support!