The IS Audit Process, Phase by Phase
Ten phases, one order. Most DISA process questions are really asking what comes first.
An IS audit runs on the same skeleton as any assurance engagement: agree the mandate, understand the entity, assess risk, test controls, evaluate evidence, report and follow up. What changes is the object. You are forming a view on whether IT controls protect the confidentiality, integrity and availability of information, not only whether the numbers are fairly stated.
ICAI's Module 1 material lays the engagement out in phases, and the Assessment Test leans on that order. Many questions are really asking "what comes first?" or "which phase does this belong to?", so knowing the sequence is worth more than memorising any single definition.
You save ₹450
- Full-length timed mocks
- Module-wise practice
- Emerging-tech coverage
One payment, no subscription · Valid for 2 months
The Phases of an IS Audit
The sequence as ICAI's background material presents it, with what each phase produces.
- 1
Mandate: charter or engagement letter
An internal IS audit function works under an audit charter approved at an appropriate level, setting out purpose, responsibility, authority and accountability. An external engagement works under an engagement letter that fixes scope and objectives.
- 2
Scope and objectives
Which systems, locations, processes and period are covered, and what the audit must conclude on. Scope limitations agreed here must surface again in the report.
- 3
Planning and understanding the auditee
Business, organisation structure, IT infrastructure, and the laws, standards and policies that apply. For a bank this means the core banking system, its interfaces and the regulator's IT directions; for a manufacturer, the ERP and its plant integrations.
- 4
Risk assessment
Identify what can go wrong, rate it, and decide where audit effort goes. The output feeds the audit programme and sample sizes.
- 5
Risk and control matrix (RCM)
One line per risk: the control objective, the control the entity actually runs, its owner, and the test you will perform. The RCM doubles as the audit notebook.
- 6
Testing
Test design effectiveness (a walkthrough shows the control exists and would work) and operating effectiveness (a sample shows it did work throughout the period). Where controls fail, extend substantive testing.
- 7
Evidence and documentation
Gather sufficient, appropriate evidence and record it so a qualified independent reviewer could re-perform the work and reach the same conclusion.
- 8
Evaluate and rank findings
Judge each weakness by materiality and risk; aggregate minor deficiencies that together become significant.
- 9
Report and exit meeting
Confirm facts with auditee management, agree action plans and dates, then issue the report to the intended recipients.
- 10
Follow-up
A limited-scope review of whether agreed actions were taken on time. It does not reopen the whole audit.
Compliance Testing vs Substantive Testing
The pair the material keeps returning to, because every RCM line ends in one or the other.
Question it answers
Compliance (test of controls)
Is the control operating as designed, throughout the period?
Substantive
Are the transactions and balances complete, accurate and valid?
Typical IS example
Compliance (test of controls)
Sample of program changes in the core banking system, each checked for approval, testing and segregated migration
Substantive
Recompute interest on a sample of loan accounts; run a duplicate-payment test over the full vendor ledger
When it expands
Compliance (test of controls)
Control is relied on and risk is higher
Substantive
Controls are found ineffective, or cannot be relied on
| Compliance (test of controls) | Substantive | |
|---|---|---|
| Question it answers | Is the control operating as designed, throughout the period? | Are the transactions and balances complete, accurate and valid? |
| Typical IS example | Sample of program changes in the core banking system, each checked for approval, testing and segregated migration | Recompute interest on a sample of loan accounts; run a duplicate-payment test over the full vendor ledger |
| When it expands | Control is relied on and risk is higher | Controls are found ineffective, or cannot be relied on |
Quick practice on audit concepts. No signup.
Internal and External IS Audit Use the Same Phases
ICAI's material notes the scope and approach differ: an internal IS auditor reviews the control environment in detail, while an external IS auditor takes an overall view and leans on substantive testing within the engagement letter's scope. ICAI's SIA 520 sets out the same flow for internal auditors working in an IT environment: understand the environment, assess risk, scope, plan, test design, implementation and operating effectiveness, document, and agree action plans.
How the DISA Assessment Test Tests This
Expect sequencing and "FIRST" or "MOST" questions built on the phase order, not definition recall alone.
- check_circle"The first step in preparing the annual IS audit plan": the answer is a risk ranking of systems, not a meeting with the audit committee or carrying forward last year's plan. Risk drives everything that follows.
- check_circle"Which would an IS auditor NOT do during pre-audit planning?": compliance testing. Testing belongs to fieldwork, not planning.
- check_circle"The primary purpose of an audit charter": to state the authority and responsibility of the audit function. Candidates pick "document the audit process" because it sounds procedural.
- check_circleFollow-up questions test the limited scope: it checks agreed actions, it does not re-audit the area.
FAQs
What are the phases of an IS audit?expand_more
Mandate (charter or engagement letter), scope, planning and understanding the auditee, risk assessment, building the risk and control matrix, testing, evidence and documentation, evaluating findings, reporting, and follow-up.
What is the difference between an audit charter and an engagement letter?expand_more
A charter is the standing mandate of an internal audit function, approved within the organisation. An engagement letter governs a specific external assignment and fixes its scope, objectives and terms.
What is a risk and control matrix in IS audit?expand_more
A working paper listing each identified risk, the control objective that should address it, the control actually in place, and the test performed. It links the risk assessment to the testing and the findings.
Is a follow-up review a fresh audit?expand_more
No. It is a limited review of whether management implemented the actions it agreed, by the dates it committed to.
Next steps
- Risk-Based Auditarrow_forward
- IS Audit Reportarrow_forward
- CAATs & Evidencearrow_forward
- Syllabusarrow_forward
Assessment Test format, timed and scored.
