IT Audit Do’s and Don’ts
Do:
Remember that an auditor isn’t the person who orders the audit. Senior company leaders initiate most internal audits as a means of gaining mission-critical information and data.
Approach an audit as an opportunity to learn more about the audit process and how your team can be better prepared for the next audit.
Use the audit to communicate directly to senior management any IT resource or process concerns.
Budget accordingly for an audit, whether or not one is scheduled. Audits can happen at any time, so be prepared.
Don’t:
Consider an audit to be an adversarial situation. IT professionals and internal auditors are partners on the same corporate team.
Try to hide or minimize any bad news revealed during an audit. The truth will come out, regardless.
Allow scope-creep. If or when out-of-scope concerns are raised during an audit, it is important to adhere to the original audit scope, then notify management that additional audits will be required to address any out-of-scope concerns raised.