Skip to main content

IT Systems Audit

Information systems audit: ITGC, application controls, data reliability, application security and ISA 315 / COBIT compliance.

ITGC COBIT ISA 315 IS Audit
Financial documents, calculator and audit magnifier

Key features

Standards covered

ISA 315 ISA 330 COBIT 2019 ITGC AUDCIF

The chain that produces your accounts is an audit object

Your financial statements do not come out of a hand-kept ledger: they come out of an application chain — ERP, interfaces, consolidation tools — whose reliability conditions that of the accounts. The international auditing standards have made it explicit: ISA 315 requires an understanding of the information systems underlying the accounts, ISA 330 requires responses tailored to the identified risks. That is exactly the portion we carry, in co-engagement with statutory auditors, for OHADA entities — consistent with the profession’s AUDCIF directives.

Our angle is singular: we audit systems we know from the inside. The ERPs whose application controls we test are the ones we deploy elsewhere — we know where configurations give way. And our auditors work on HOLOS, the ISA audit platform we built: ISA 300 engagement plans, structured files, multi-standard general report. Where the audit reveals weaknesses to fix over time, the natural continuation is a hardening and compliance programme.

Three moments justify the engagement: before an ERP go-live, to secure controls at design time rather than in remediation; after a migration, to verify data integrity and the preservation of audit trails; and as an annual recurring engagement, integrated into the statutory audit cycle.

Method

How we work

  1. 01

    Planning

    1 to 2 weeks

    Understanding of the application landscape, identification of the systems feeding financial reporting, IS risk analysis and definition of the test scope — validated with the statutory auditor when the engagement is a co-engagement.

  2. 02

    Test execution

    2 to 6 weeks depending on scope

    Access controls (identities, segregation of duties, privileged accounts), change controls (development, testing, production release), operations controls (backups, continuity, monitoring) and application controls on critical cycles — purchases, sales, payroll, fixed assets.

  3. 03

    Readout

    1 to 2 weeks

    Written synthesis of findings with risk levels, prioritised recommendations and a remediation plan. For co-engagements, the deliverable meets the signing auditor's expectations.

Deliverables

What you receive

IS audit report

Findings ranked by risk, prioritised recommendations, actionable remediation plan.

Map of contributing systems

The application chain behind financial reporting, interfaces, identified control points.

Documented test files

ITGC and application test evidence, reusable from one financial year to the next.

Co-engagement deliverable

An ISA 315 / 330-compliant IS section, ready to integrate into the statutory auditor's file.

Commitment

We audit with the platform we built for it.
Our CISA, CIA and ACCA-certified auditors work on HOLOS, our own ISA audit platform — engagement plans, files, multi-standard general report. Few firms know both the systems they audit and the tool they audit them with.

Getting started

How to get started

  1. 1

    Scoping interview

    45 minutes with your finance leadership, your statutory auditor or your internal audit.

  2. 2

    Scope delimited

    Contributing systems, critical cycles, certification deadlines.

  3. 3

    Within 48 business hours

    A written engagement proposal, no commitment.

FAQ

Frequently asked questions

What is the difference between ITGC and application audits?

ITGC covers general controls (access, change, operations); application audits verify controls inside your ERPs and business applications — integrity, completeness, accuracy.

Do you work with statutory auditors?

Yes, in co-engagement: we cover the IT dimension of statutory audits under ISA 315 and ISA 330, with deliverables meeting the signing auditor's expectations.

When should an IT audit be performed?

Ideally before an ERP go-live (pre-implementation), after a migration, or as an annual engagement within the statutory audit cycle.

Let's talk about your project

A demo, an audit, an ERP to roll out? One message is enough to start the conversation.