Audit
IT Audit: A Career Path Testing the Controls Around Every System
IT auditors don't build systems or defend them from attackers. They test whether access, change management, and operations controls around technology are strong enough that everyone downstream can rely on them. Here is what the job involves and how to get in.

A regional bank rolls out a new loan origination system, and six months after go-live the IT audit team runs its first access review. Forty accounts still sit in the system's admin group, most of them belonging to contractors who rolled off the implementation project months earlier. The change log shows two configuration changes pushed straight to production with no ticket, no testing evidence, and no sign-off from the change advisory board. Nothing has gone wrong yet — no fraud, no outage, no bad loan approved because of it. But the auditor now has to decide whether these gaps are severe enough to mean nobody can rely on any control built on top of that system, including the application controls the external auditor is counting on for the company's SOX opinion. That judgment call — not configuring firewalls, not deciding whether the project should have launched — is the actual job of IT audit.
Why this role is distinct from IT security and financial audit
IT audit sits inside the internal audit function and tests IT general controls, commonly shortened to ITGCs: the controls around who can access a system, what changes are allowed to reach it, and how it is operated day to day. That is a different job from IT security, which builds and runs those controls, and a different job from a cybersecurity compliance analyst, who manages the evidence trail for external attestations like SOC 2 or ISO 27001 on a recurring commercial cycle. It is also different from a financial auditor testing business-process controls, because IT audit provides assurance over the technology environment as a whole, not only the systems that touch financial reporting.
The reason the role exists as its own specialty is that ITGCs are foundational. If access controls or change management around a system are weak, every application control that depends on that system — an automated three-way match, a system-enforced approval limit, a calculated interest accrual — becomes unreliable, because someone could have altered the logic or the data without anyone knowing. An IT auditor's conclusion about the general controls determines how much weight the rest of the audit can place on anything the system produces.
The four control domains that structure almost every ITGC audit
Nearly every IT audit, regardless of industry or system, tests some combination of the same four areas:
- **Access management.** Who can get into the system, how they were provisioned, whether access matches their current job, and whether it was removed when they changed roles or left. This includes segregation-of-duties checks in ERP systems, where the same person should not be able to, for example, create a vendor and also approve payment to it.
- **Change management.** Whether changes to the system — code, configuration, infrastructure — go through a documented request, review, testing, and approval process before reaching production, and whether emergency changes are logged and reviewed after the fact rather than left undocumented.
- **Computer operations.** Whether backups run and are tested for restoration, whether scheduled jobs that move or calculate data actually complete and get investigated when they fail, and whether incidents are logged and resolved on a defined timeline.
- **Program development.** For systems built or heavily customized in-house, whether the development lifecycle includes independent testing and a formal go-live approval before a new system or major change is deployed.
A given engagement might scope tightly to the systems that support financial reporting, which is what a SOX ITGC audit does, or it might run against a broader technology risk universe that includes cloud infrastructure, data centers, and systems with no financial reporting role at all. The methodology is the same either way; the scoping decision determines which systems make the list.
What the work looks like day to day
The center of the job is evidence gathering against a control that someone else operates, which means most of the week is spent outside your own team.
- **Walkthroughs.** You sit with a system administrator or process owner and trace how access is requested, approved, and provisioned, or how a change moves from request to production, to confirm the control works the way the design documentation says it does.
- **Population and sample testing.** You pull the full population of users, changes, or job runs for the period, select a sample using a defined methodology, and test each item against the standard — comparing an access list against HR termination data, or a change ticket against the change advisory board's approval log.
- **Exception follow-up.** When a sample item fails, you determine whether it is isolated or a sign the control does not operate consistently, which changes whether it becomes a passing exception or a reportable deficiency.
- **Data analytics.** Increasingly, IT auditors pull entire populations rather than samples, using SQL or tools built for the purpose, to test every access grant or every change ticket in a period instead of forty of them. This catches patterns a sample would miss and is one of the more transferable technical skills in the field.
- **Writing and negotiating findings.** A finding needs a clear description of the control gap, why it matters, and a remediation date the system owner actually agrees to, not one imposed on them. Findings that IT teams cannot follow or dispute on the merits do not get fixed; they get argued about at the next audit committee meeting instead.
Certifications and the background that gets you hired
The Certified Information Systems Auditor (CISA) credential from ISACA is the one hiring managers look for by name in this field, more consistently than in general internal audit or cybersecurity compliance roles, because it is built specifically around IT audit and controls testing. The Certified Internal Auditor (CIA) from the IIA is valuable if you are building toward a broader internal audit career rather than staying IT-specialized. Familiarity with a major ERP platform such as SAP or Oracle, or with a ticketing and change management system like ServiceNow, makes a candidate more useful immediately, because a large share of the testing is platform-specific even though the control concepts are universal. Basic SQL is worth learning early; it is the single skill most likely to separate a candidate who can test a sample from one who can test an entire population.
How people actually get in
Three entry paths account for most IT auditors. Some come from IT operations, help desk, or systems administration roles and move into audit because they already understand the systems being tested and want more structured career progression than an operations track typically offers. Some come from a general internal audit background and pick up IT specialization because ITGC testing is consistently understaffed relative to demand — nearly every audit plan needs it, and few generalist auditors are comfortable owning it end to end. And a share enter directly out of college into a Big 4 or large company's technology audit practice, usually with a degree in management information systems, computer science, or accounting information systems, learning the audit methodology on the job the way financial audit associates do.
Entry-level titles to search for include IT auditor, technology audit associate, ITGC analyst, and IT internal controls analyst. Read the job description for testing, controls, and evidence rather than administer, configure, or build, which usually signal an operations role instead.
Where the career goes
An IT audit associate typically moves to senior IT auditor within two to three years, at which point you are leading walkthroughs independently and drafting findings rather than executing assigned test steps. From senior, the path splits. Some move into IT audit management, owning the technology portion of the annual audit plan and presenting results directly to the audit committee. Others specialize further into a narrower technology risk area — cloud infrastructure audits, data privacy and governance, or operational technology in industrial environments — where deep platform knowledge commands a premium. A meaningful share move sideways into cybersecurity compliance or GRC roles, trading the audit function's independence for closer, ongoing ownership of a security program. Others move into IT risk management or even back into IT operations, using the audit background as a credential that they understand not just how a system is built, but how its controls will be judged when something eventually goes wrong.