IT Audit application
Early access

IT audits, from universe to report

Keep an audit universe, scope engagements from it, test controls for design and operating effectiveness, and follow findings through to closure, all in one place instead of spreadsheets and shared folders.

Inside IT Audit

An engagement moves through checked stages

  1. Planning

    Objective, scope from the audit universe, audit period, team and the risk & control matrix.

  2. Fieldwork

    Opens only when the objective, period and lead are set and every risk is mapped to a control. Design and operating-effectiveness tests are recorded here.

  3. Reporting

    Needs a concluded test for every key control. Exceptions become findings with a suggested severity.

  4. Closed

    No draft findings left. Scope, matrix and tests become read-only; remediation tracking stays open.

Available in the application today

What IT Audit does today

IT Audit is in early access. Everything on this list works in the application now.

Audit universe

One list of what can be audited, kept up to date between engagements.
  • Auditable entities with type, owner, risk rating and last audit date
  • Optional link from an entity to an AI system in AI Governance
  • Add, edit and remove entities as the organization changes

Engagements

Each audit has its own scope, team and stages.
  • Objective, in-scope and out-of-scope notes, audit period and fieldwork dates
  • Scope picked from the audit universe; team members as lead, auditor or reviewer
  • Engagement codes generated automatically (ENG-YYYY-NNN) or set by you
  • Planning, fieldwork, reporting and closed stages; each stage after planning is checked before it opens

Risk & control matrix

Risks and controls for the engagement, mapped to each other.
  • Risks with reference, assertion and rating
  • Controls marked key or non-key, with nature, automation, frequency, owner and planned procedure
  • Warnings for risks without a control and controls without a risk

Design and operating-effectiveness testing

Two separate tests per control, recorded in the same place as the matrix.
  • Procedure, population, sample size, tester and date
  • Result: effective, exceptions or ineffective, with the exceptions listed
  • Evidence notes and a written conclusion for each test
  • Every key control needs a concluded test before reporting starts

Findings lifecycle

From test exception to agreed action and closure.
  • Raise a finding from a failed test, drafted from its exceptions with a suggested severity
  • Draft, agreed, remediating and closed, with root cause and recommendation
  • Agreement needs a management response, action owner and due date
  • Overdue findings highlighted; findings list across engagements with filters

Report and oversight

A readable summary for audit committees and management.
  • Printable engagement report (print or save as PDF): scope, team, coverage, results and findings by severity
  • Report marked as draft until the engagement is closed
  • Overview of engagements by stage, open findings by severity and overdue items
  • Read-only access for viewers; every change written to the audit log
Part of the suite

Works on its own, better with the other applications

IT Audit runs in the same Starkguard workspace as AI Governance and Business Continuity. You can use it alone; when you use more than one application, they share the core below.

How the shared core works

Today

  • Same workspace, members and roles as AI Governance and Business Continuity
  • Audit universe entities can link to AI systems registered in AI Governance
  • Changes are written to the same organization audit log

Next
On the roadmap

  • Engagement scope picked from one shared inventory of applications, services and third parties
  • Findings in one issues & actions list with AI Governance and Business Continuity actions
  • Assigned tests and findings in each person's My Work queue
Standards context

Built with the standards your reviewers use

The engagement lifecycle, risk and control matrix and two-stage control testing follow the way internal audit teams already work. The standards below are the ones IT audit teams in the GCC most often plan against.

  • IIA Global Internal Audit Standards
  • NCA Essential Cybersecurity Controls (ECC)

These standards are reference points for how the application is structured. Using Starkguard does not by itself make an organization compliant or certified; that depends on your own programme and, where relevant, an independent assessment.

On the roadmap

What comes next for IT Audit

Not available yet. Listed so you can see where the application is going; order and scope may change.

  • Risk-based audit planning

    Scoring the audit universe and building the annual audit plan from it.

  • Workpapers and review

    Walkthroughs as separate records, workpapers, reviewer sign-off and review notes.

  • Sampling and evidence requests

    Population handling, sampling methods, and evidence requests with uploads from control owners.

  • Matrix templates and versioning

    Reusable risk and control matrix templates with versions and approval.

  • Report workflow and exports

    Report review and clearance, and PDF or DOCX export beyond browser printing.

  • Follow-up audits

    Follow-up procedures on remediated findings and a closure checklist.

Plan, test and report IT audits in one place.

Talk to us about IT Audit for your organization in KSA, the UAE or the EU.