8
Copyright © 2014 Deloitte Development LLC. All rights reserved. IT Internal Audit Auditing What Matters

IT internal audit: auditing what matters

Embed Size (px)

DESCRIPTION

In both favorable and challenging economic environments, an organization’s need for counsel, competency and analytical skill remains high. The Internal Audit (IA) function can help meet these needs through its specialization in process efficiency, fraud detection, operational quality, internal control and regulatory compliance. Deloitte’s Internal Audit Transformation (IAT) services help boards and senior executives more effectively manage enterprise risks and execute strategy by assisting organizations with protecting shareholder value and enhancing the effectiveness, quality and value received from internal audit. We have experienced practitioners and thought leaders who specialize in pressing internal audit issues. Our broad understanding of risks and areas of operational improvement — particularly the nuances of specific industry sectors and markets — can help IA functions improve their performance and operating efficiency and bring greater value to their organizations.

Citation preview

Copyright © 2014 Deloitte Development LLC. All rights reserved.

IT Internal AuditAuditing What Matters

Copyright © 2014 Deloitte Development LLC. All rights reserved.

IT Internal Audit Approach

Risk

Value

Level 1Core

Level 2Advanced

Level 3Emerging

A

BC

D

E

F

G

HIJ

K

L

M

N O

P

Q

2

Copyright © 2014 Deloitte Development LLC. All rights reserved.

• Repetitive services• Compliance focused• Comprises most of

current audit universes• Commoditized audits

IT Internal Audit Projects

Core

ITGCs

SOX Testing

DRP

Other Compliance

SoD

A

B

C

D

E

Level 13

Copyright © 2014 Deloitte Development LLC. All rights reserved.

• Repetitive services• Compliance focused• Comprises most of

current audit universes• Commoditized audits

IT Internal Audit Projects

Core

ITGCs

SOX Testing

DRP

Other Compliance

SoD

A

B

C

D

E

• Maturing technologies that haven’t been a focus

• Some compliance aspects

• Opportunities to add value

Advanced

IT Governance

Attack and Pen

IAM

End User Computing

Software Asset Mgmt

GRC

F

G

H

I

J

Level 1 Level 2

K

4

Copyright © 2014 Deloitte Development LLC. All rights reserved.

• Repetitive services• Compliance focused• Comprises most of

current audit universes• Commoditized audits

IT Internal Audit Projects

Core

ITGCs

SOX Testing

DRP

Other Compliance

SoD

A

B

C

D

E

• Maturing technologies that haven’t been a focus

• Some compliance aspects

• Opportunities to add value

Advanced

IT Governance

Attack and Pen

IAM

End User Computing

Software Asset Mgmt

GRC

F

G

H

I

J

• New technologies• High visibility/risk• Highly strategic• Significant opportunities

to provide additional value

Emerging

Mobile Endpoint

Cyber Terrorism

Privacy

IT Risk Mgmt

Enterprise Record Mgmt

Social Media

Cloud Computing

L

M

N

O

P

Level 1 Level 2 Level 3

KQ

5

R

Copyright © 2014 Deloitte Development LLC. All rights reserved.

Current State

Level 1Level 2Level 3

IT Internal Audit Universe Allocation

Future State

Level 1Level 2Level 3

6

Copyright © 2014 Deloitte Development LLC. All rights reserved.

Contacts

7

Michael JuergensManaging PrincipalInformation Technology Internal AuditDeloitte & Touche LLP+1 213 688 [email protected]

Twitter: @michaeljuergensLinkedIn: www.linkedin.com/pub/michael-juergens/2/221/988/

Tune in to this brief audio/visual presentation at:http://event.on24.com/clients/deloitte/portal/index.html?playlist=itia&event=700466

Copyright © 2014 Deloitte Development LLC. All rights reserved.

This publication contains general information only and is based on the experiences and research of Deloitte practitioners. Deloitte is not, by means of this publication, rendering business, financial, investment, or other professional advice or services. This publication is not a substitute for such professional advice or services, nor should it be used as a basis for any decision or action that may affect your business. Before making any decision or taking any action that may affect your business, you should consult a qualified professional advisor. Deloitte, its affiliates, and related entities shall not be responsible for any loss sustained by any person who relies on this publication.

About DeloitteDeloitte refers to one or more of Deloitte Touche Tohmatsu Limited, a UK private company limited by guarantee, and its network of member firms, each of which is a legally separate and independent entity. Please see www.deloitte.com/about for a detailed description of the legal structure of Deloitte Touche Tohmatsu Limited and its member firms. Please see www.deloitte.com/us/about for a detailed description of the legal structure of Deloitte LLP and its subsidiaries. Certain services may not be available to attest clients under the rules and regulations of public accounting.