Home › HRMS › Job roles › Information Technology › IT Auditor
Information Technology · Mid level

IT Auditor job description

An IT Auditor checks whether a company's IT systems and controls can be trusted: who has access, how changes reach production, whether backups work, how data is protected and whether application controls stop errors and fraud. They plan and run audits of IT general controls, ERP and business applications, cybersecurity and outsourced vendors, and report findings to management and the audit committee. The role sits in internal audit, risk or a consulting firm. A good IT Auditor finds real risk, explains it in business terms and follows each finding to closure.

DetailFor this role
DepartmentInformation Technology
LevelMid level
Reports toInternal Audit Manager
Direct reportsNone
Experience3 to 6 years in IT audit, IT risk or information security compliance

IT Auditor job description template

Copy this job description, replace the text in square brackets and post it on your careers page or a job portal.

Job title: IT Auditor

Department: Information Technology

Reports to: Internal Audit Manager

Location: [City], [office, branch or site]

About the role

An IT Auditor checks whether a company's IT systems and controls can be trusted: who has access, how changes reach production, whether backups work, how data is protected and whether application controls stop errors and fraud. They plan and run audits of IT general controls, ERP and business applications, cybersecurity and outsourced vendors, and report findings to management and the audit committee. The role sits in internal audit, risk or a consulting firm. A good IT Auditor finds real risk, explains it in business terms and follows each finding to closure.

Key responsibilities

  • Prepare the annual IT audit plan with the internal audit manager, ranking systems, processes and vendors by risk.
  • Scope each audit, request documents and system reports, and hold opening meetings with IT and business owners.
  • Test IT general controls: user and privileged access, change management, backups, job scheduling and incident handling.
  • Review ERP application controls such as approval limits, segregation of duties, three-way match and master data changes.
  • Assess cybersecurity controls against ISO 27001, company policy and any regulator circulars that apply to the business.
  • Sample transactions and logs, record test steps and evidence, and keep working papers ready for review.
  • Write findings with risk rating, root cause, business impact and practical recommendations, and agree action plans with owners.
  • Follow up open findings every month and check closure evidence before marking them closed.
  • Support statutory auditors with IT control testing for the financial audit.
  • Audit outsourced IT and cloud vendors through questionnaires, SOC reports and site visits.

Requirements

  • B.Com, B.E., B.Tech, BCA or MCA
  • CISA certification from ISACA
  • CA, DISA from ICAI or ISO 27001 Lead Auditor is an advantage
  • 3 to 6 years in IT audit, IT risk or information security compliance

KRAs and KPIs for a IT Auditor

Key result areas for the appraisal form, each with a KPI you can measure every month or quarter.

Key result areaHow to measure it
Audit plan deliveryAt least 90 percent of planned IT audits completed within the audit year
Report timelinessDraft audit report issued within 10 working days of fieldwork ending
Finding qualityEvery finding carries a root cause and an agreed action plan, with none reversed on review
Follow-upOpen findings reviewed monthly, with closure evidence verified before sign-off
Working papersWorking papers completed and reviewed within 5 working days of each audit
Auditee feedbackFeedback score of 4 or more out of 5 from auditees after each audit

Skills and tools

IT general controls testingERP application controls such as SAPISO 27001 and COBIT frameworksSegregation of duties analysisData analytics in Excel, SQL or ACLRisk assessmentAudit report writingProfessional scepticismTact with auditeesConfidentiality

Tools used day to day: Excel and Power Query, ACL or IDEA, SQL, SAP GRC or SAP access reports, TeamMate or other audit software, GRC tool.

Reporting line and career path

Internal Audit ManagerIT Auditor

Interview questions for a IT Auditor

  1. How would you test whether employees who left still have access to the ERP?
  2. What is segregation of duties? Give an example of a conflict in purchase to pay.
  3. A developer has access to production. Is that always a finding, and how do you judge it?
  4. Walk me through how you would audit the change management process.
  5. How do you write a finding so that management actually acts on it?
  6. The IT head disagrees with your risk rating. What do you do?

Managing a IT Auditor in ZeniaHR

Hire and manage your information technology team in one place

Post the role, onboard the new hire, and track attendance, leave and KRAs in ZeniaHR. Free for your first 50 employees.

Book a free demoSee pricing

Frequently asked questions

What does an IT auditor do?

An IT auditor checks whether IT systems and controls work as intended. They test user access, change management, backups, ERP application controls, cybersecurity and vendor controls, collect evidence, write findings with recommendations and follow up until issues are fixed. Their reports go to management and often to the audit committee.

Is CISA required for an IT auditor?

CISA is the best known IT audit certification, and many Indian employers, including banks and large audit firms, list it as required or preferred. Chartered accountants often add DISA from ICAI. You can start in IT audit without it, but most professionals complete CISA within their first few years.

What is the difference between an IT auditor and an internal auditor?

An internal auditor reviews business processes and financial controls such as purchasing, sales, payroll and inventory. An IT auditor reviews the technology behind them: access, system changes, data security and automated controls in the ERP. The two often work on the same audit, and both usually report to the head of internal audit.