IT audits, from universe to report
Keep an audit universe, scope engagements from it, test controls for design and operating effectiveness, and follow findings through to closure, all in one place instead of spreadsheets and shared folders.
Inside IT Audit
An engagement moves through checked stages
Planning
Objective, scope from the audit universe, audit period, team and the risk & control matrix.
Fieldwork
Opens only when the objective, period and lead are set and every risk is mapped to a control. Design and operating-effectiveness tests are recorded here.
Reporting
Needs a concluded test for every key control. Exceptions become findings with a suggested severity.
Closed
No draft findings left. Scope, matrix and tests become read-only; remediation tracking stays open.
What IT Audit does today
IT Audit is in early access. Everything on this list works in the application now.
Audit universe
- Auditable entities with type, owner, risk rating and last audit date
- Optional link from an entity to an AI system in AI Governance
- Add, edit and remove entities as the organization changes
Engagements
- Objective, in-scope and out-of-scope notes, audit period and fieldwork dates
- Scope picked from the audit universe; team members as lead, auditor or reviewer
- Engagement codes generated automatically (ENG-YYYY-NNN) or set by you
- Planning, fieldwork, reporting and closed stages; each stage after planning is checked before it opens
Risk & control matrix
- Risks with reference, assertion and rating
- Controls marked key or non-key, with nature, automation, frequency, owner and planned procedure
- Warnings for risks without a control and controls without a risk
Design and operating-effectiveness testing
- Procedure, population, sample size, tester and date
- Result: effective, exceptions or ineffective, with the exceptions listed
- Evidence notes and a written conclusion for each test
- Every key control needs a concluded test before reporting starts
Findings lifecycle
- Raise a finding from a failed test, drafted from its exceptions with a suggested severity
- Draft, agreed, remediating and closed, with root cause and recommendation
- Agreement needs a management response, action owner and due date
- Overdue findings highlighted; findings list across engagements with filters
Report and oversight
- Printable engagement report (print or save as PDF): scope, team, coverage, results and findings by severity
- Report marked as draft until the engagement is closed
- Overview of engagements by stage, open findings by severity and overdue items
- Read-only access for viewers; every change written to the audit log
Works on its own, better with the other applications
IT Audit runs in the same Starkguard workspace as AI Governance and Business Continuity. You can use it alone; when you use more than one application, they share the core below.
How the shared core worksToday
- Same workspace, members and roles as AI Governance and Business Continuity
- Audit universe entities can link to AI systems registered in AI Governance
- Changes are written to the same organization audit log
NextOn the roadmap
- Engagement scope picked from one shared inventory of applications, services and third parties
- Findings in one issues & actions list with AI Governance and Business Continuity actions
- Assigned tests and findings in each person's My Work queue
Built with the standards your reviewers use
The engagement lifecycle, risk and control matrix and two-stage control testing follow the way internal audit teams already work. The standards below are the ones IT audit teams in the GCC most often plan against.
- IIA Global Internal Audit Standards
- NCA Essential Cybersecurity Controls (ECC)
These standards are reference points for how the application is structured. Using Starkguard does not by itself make an organization compliant or certified; that depends on your own programme and, where relevant, an independent assessment.
What comes next for IT Audit
Not available yet. Listed so you can see where the application is going; order and scope may change.
Risk-based audit planning
Scoring the audit universe and building the annual audit plan from it.
Workpapers and review
Walkthroughs as separate records, workpapers, reviewer sign-off and review notes.
Sampling and evidence requests
Population handling, sampling methods, and evidence requests with uploads from control owners.
Matrix templates and versioning
Reusable risk and control matrix templates with versions and approval.
Report workflow and exports
Report review and clearance, and PDF or DOCX export beyond browser printing.
Follow-up audits
Follow-up procedures on remediated findings and a closure checklist.
Plan, test and report IT audits in one place.
Talk to us about IT Audit for your organization in KSA, the UAE or the EU.