Audit & Risk

Internal audit departments "falling short on IT risks"

Most internal audit teams are still failing to place enough emphasis on understanding and assessing their organisations’ IT risks, according to the findings of a new poll.

in News.

An IT audit benchmarking survey by consulting firm Protiviti has found that many organisations, including one in four with revenues of up to $1bn, have not conducted any kind of IT audit risk assessment. In addition, 42 per cent of respondents acknowledged that there were specific parts of their IT audit plans that they could not address properly owing to a lack of resources and expertise.

The survey confirmed that the smaller the company, the less likely it was to have an IT audit function: 43 per cent of companies turning over less than $100m a year had no such department. Of organisations with annual revenues of $100m to $1bn, 82 per cent did not have a designated IT audit director or an equivalent role.

Protiviti also found that nearly 70 per cent of North American companies and nearly 80 per cent of companies in Europe, Africa and Asia had not completed an evaluation and assessment of their IT governance process, as outlined in the IIA’s standard 2110.A2.

Mark Peters, UK director at Protiviti, said: “If an internal audit function is not thinking about IT governance, IT risks and conducting an IT risk assessment, it should be. The increased use of, and demand for, technology and data compel companies to review how they are used and the risks this creates.” 

For more information about the survey, visit bit.ly/qH2pxF

The IIA: find out more

Visit the main IIA site

Jobs

Senior Internal Auditor

London
Circa £40,000 per annum dependent upon experience and qualification status (PIIA qualified is a minimum requirement)

Careers advice

Moving up

Two former heads of internal audit explain what the role taught them and how it helped to prepare them for a seat on the board.

Every secondment counts

If you are offered a temporary work placement with another employer – perhaps even in a different function from internal audit – you’d be well advised to jump at the chance. So says Chris Monk, whose organisation, Uniac, and its staff have long reaped the benefits of secondments.

The inbetweeners

Historically a stopgap for internal auditors searching for a more permanent role, interim management is now more likely to be the consequence of a positive and actively chosen career path. Why has it become such a growth area? Barclay Simpson's Andy Whyte explains.

Training & Development

Challenging conversations are habit-forming

“Any challenging conversation needs to be handled with care because people need to be handled with care. Forget this at your peril,” says Adrian Thompson, chief internal auditor, Norfolk County Council.

Q&A

Our technical helpline provides valuable advice to members on a host of professional issues. Here are some of the questions you’ve submitted recently.

Erratum: Audit & Risk

In the November/December 2012 edition of Audit & Risk magazine, an error appeared in the listings of the IIA members who were successful in the June 2012 exams.

Tools

You asked us

Our technical helpline provides valuable advice to members on a host of professional issues. Here are some of the questions you’ve submitted recently.

A world of knowledge

The IIA is always working to produce guidance aimed at helping internal auditors to stay at the cutting edge of best practice. Pauline Scott, technical coordinator, reports on the technical team’s recent work to support members.

EQA FAQs

The institute’s technical manager, Chris Baker CMIIA, explains the value of an external quality assessment, what happens during the review process – and how best to prepare for one.