IT audit of infrastructure, data flows and AI systems

IT Audit and Internal Audit

Financial Statement Audits and IT Audits

Well prepared for the annual audit

For many companies, the annual financial statement audit involves considerable organisational effort. Audit-ready documentation, process descriptions, evidence of controls, and information about relevant IT systems and service providers must be available in a clear and traceable form.

Early and structured preparation can reduce follow-up questions, clarify responsibilities and make the audit process more efficient.

For IT-related audit procedures, the requirements of ISA 315 (Revised 2019) and ISA 330 are particularly relevant. The risk-based audit approach requires a detailed understanding of the information system, relevant applications, data flows, IT-supported business processes and the related controls.

Audit and advisory support throughout the year

IT audits performed during the year provide transparency over technical and organisational risks before they affect the financial statements, business operations or major transformation projects. Our work focuses on the IT infrastructure actually in use, the processing and transfer of business-critical data, and the integration of cloud and AI systems into relevant processes.

Our audit focus includes:

  • IT infrastructure and technical components, including servers, networks and endpoints;
  • IT-supported business processes and general IT controls;
  • access, authorisation and segregation-of-duties concepts;
  • changes to ERP, financial and other business-critical systems;
  • interfaces, data transfers and the traceability of relevant data flows;
  • cloud services, outsourcing arrangements and external IT service providers;
  • AI systems and automated procedures with regard to governance, controls and auditable evidence; and
  • business continuity, recovery arrangements and preparation for external audits.
IT auditor reviewing infrastructure, data flows and AI processing

An early review does not replace the responsibilities of management or process owners. It provides an additional opportunity to identify risks, missing evidence and improvement needs in good time.

Support for Your Internal Audit Function

Independent assurance and advisory services

If your organisation does not maintain its own internal audit function, or if specialist support is required, we can perform selected audit assignments within an agreed scope.

Our services include:

  • risk-based audit planning;
  • process and organisational audits;
  • reviews of the internal control system;
  • IT and information-security audits;
  • data-protection and compliance audits;
  • gap analyses against legal and regulatory requirements;
  • reviews of service providers and outsourcing arrangements;
  • follow-up of agreed corrective actions; and
  • reporting to management, supervisory boards or audit committees.

The audit objective, scope, criteria and intended recipients are defined with you before the engagement begins.

Your benefit

You receive an independent and transparent assessment of whether material risks are identified, controls are appropriately designed, processes operate as intended, responsibilities are clearly assigned and relevant evidence is available.

Depending on the engagement, our work may draw on applicable IDW auditing standards, the International Professional Practices Framework for Internal Auditing and relevant statutory or regulatory requirements.

Contact

Would you like to prepare more effectively for your annual audit, review risks during the year or strengthen your internal audit function?

Contact us to discuss an appropriate audit or support scope for your organisation.

office(at)collegium-auditores.de