How does an IT auditor come up with an effective approach to something as broad and nebulous as IT risk assessment? The good news is there is a very effectual approach that has been developed and defined to lead the IT auditor through an audit of IT risk assessment in a manner that should lead to an accurate assessment of those IT risks that actually exist at a level of substantial adverse effects related to IT. It is ISACA’s ITAF.