Skip to main content
Image coming soon

IT Control Testing for Banking Internal Audit

$199.00
Adding to cart… The item has been added

A focused course, tailored for you

IT Control Testing for Banking Internal Audit

Evidence methodology for IT audit managers at regulated banks who need findings that close in one cycle.

The evidence request went to six IT owners. Three sent screenshots. Two sent policy PDFs marked version 1.0. One sent nothing. The finding written from that package stays open for fourteen months.

$199 one-time
Tailored to your situation. Access within 24 hours. 30-day money-back.

Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.

Why this course

IT audit managers at regulated banks operate inside a structural gap. On one side: audit methodology that requires testable evidence mapped to control objectives. On the other: IT teams who interpret evidence requests as requests for whatever documentation they already have. The gap produces incomplete working papers, findings that cannot be closed, and audit coverage that does not survive supervisory examination. DORA has added a further layer, with ICT risk management audit requirements that most internal audit methodologies have not yet absorbed. The result is a function that produces substantial audit activity but struggles to demonstrate that IT risk is actually under control.

What you walk away with

  • Write evidence requests that IT teams can fulfill accurately on the first pass, without follow-up.
  • Produce working papers that pass internal quality assurance and external auditor review.
  • Classify and rate IT findings consistently using a banking-appropriate impact and likelihood framework.
  • Audit DORA ICT risk management and third-party ICT risk with a structured evidence checklist.
  • Build audit reports that the board audit committee and CRO read as action documents, not compliance summaries.

The 12 modules

Module 1. Control Objective Architecture
How to decompose a COBIT 2019 governance objective or DORA article into specific, testable control points. The difference between a control statement and a control objective that produces a testable evidence requirement. Worked example: mapping DORA Article 9 on ICT security testing to six testable control points, each with a named evidence type and a named system source. Most auditors skip this decomposition step, which is why their evidence requests produce useless responses.
Module 2. Evidence Request Engineering
How to write an evidence request that names the system, the date range, the specific field or log, and the exact format expected. Practical templates for the five most common banking IT control domains: access management, change management, backup and recovery, incident management, and network security. How to handle IT owners who claim data is unavailable or inaccessible, and what that claim means for the audit finding.
Module 3. IT General Controls Testing
Structured approach to testing the four ITGC domains in a banking environment: program development, change management, computer operations, and access to programs and data. For each domain: how to define the population, how to sample, what an exception looks like, and how to document the test conclusion. Banking-specific examples for core banking application access reviews, payments infrastructure change controls, and disaster recovery testing.
Module 4. Working Paper Standards for Regulated Banks
How to structure a working paper that passes three reviews: internal quality assurance, external auditor reliance review, and supervisory examination. The tick-mark methodology, cross-reference system, and exception notation. How to document management responses within the working paper so the finding is self-contained. Common gaps found in supervisory reviews of banking IT audit working papers and how to close them before the examiner arrives.
Module 5. Finding Classification and Risk Rating
Banking-appropriate risk rating methodology using impact and likelihood. How to write the condition, criteria, cause, effect, and recommendation sections of an IT audit finding so the risk committee, the CRO, and the IT owner each read what they need. How to avoid the two most common rating errors: over-inflating access management findings and under-rating change management exceptions that create financial reporting exposure.
Module 6. Auditing DORA ICT Risk Management
Each DORA governance pillar examined from an auditor's standpoint. For ICT governance: what board-level documentation is testable and how to assess it. For ICT risk management: how to audit the framework rather than individual controls. For digital operational resilience testing: what a TLPT evidence package looks like and how to evaluate it. Includes a DORA audit evidence checklist aligned to EBA regulatory technical standards.
Module 7. Third-Party ICT Risk Audit
How to audit outsourced IT arrangements and critical third parties under DORA and EBA outsourcing guidelines. What evidence to pull for each phase: due diligence, contract review, ongoing monitoring, and exit capability assessment. How to use a vendor SOC 2 report as part of your audit file without over-relying on it. Common findings in third-party ICT audits at large banks and how to write them with enough specificity to drive remediation.
Module 8. SOX ITGC for Global Banks
Section 404 IT control testing scoped to global banking operations. How to link ITGC domains to financial statement assertions for core banking, trading, and payments systems. Managing the reliance relationship with external auditors: what evidence they need, what reliance memo language commits you to, and how to avoid accountability for findings in systems outside your agreed scope.
Module 9. Regulatory Examination Preparation
What supervisory teams and technology examiners look for when they review an internal IT audit function. How to present your audit universe, your coverage plan, and your open findings in a way that demonstrates control over the IT risk landscape. How to respond to a supervisory information request without creating new findings or expanding commitments beyond what the function can deliver.
Module 10. Remediation Tracking and Validation
How to build a sustainable finding management process. The difference between validating that a specific control is remediated and validating that the root cause is addressed. How to write a validation testing memo that external auditors accept as evidence of closure. How to escalate past-due items to the audit committee with framing that makes further deferral by IT owners visible at board level.
Module 11. Audit Reporting for the Board and CRO
How to translate a technical IT finding about privileged access or change management into a board audit committee report that the CFO and CRO can act on. How to structure the IT audit report: executive summary, heat map of open issues by risk domain, trend analysis, and closed findings for the period. How to frame a negative finding so the technology owner does not contest the final report.
Module 12. Continuous IT Audit Monitoring
How to build a data analytics-based monitoring program that pre-tests key IT controls between formal audit cycles. Practical approach for access management monitoring using identity and access management log exports, change management monitoring using service desk ticket data, and incident monitoring using SIEM extracts. The monitoring output feeds directly into the evidence package for your next formal audit cycle.

How this addresses your situation

Specific modules that map to what you said you are dealing with.

Evidence packages from IT teams that do not map to control objectives, requiring repeated follow-up and creating deferred findings that age into regulatory exposure.
Audit committee and CRO who question risk ratings on IT findings, delaying final report approval and reducing the function's credibility with senior stakeholders.
Supervisory examinations that surface working paper gaps not caught by internal quality review, creating remediation commitments for the audit function itself.
DORA implementation creating a new ICT risk audit scope that existing methodology and working paper templates do not yet cover.

What you get with this course

  • 12 written modules covering IT control testing, evidence methodology, DORA ICT audit overlay, and regulatory examination preparation.
  • Downloadable templates for evidence requests, working papers, finding write-ups, third-party ICT review, and DORA audit evidence checklists.
  • Hand-built implementation playbook tailored for your account and delivered alongside course access.
  • Access to the Art of Service learning environment, self-paced, with no expiration.

What you will have in hand by Day 1, Week 1, Month 1

Access to the course provisioned within 24 hours of purchase.

Tailored implementation playbook delivered alongside course access.

Before and after

Before

Each IT audit cycle produces findings that stay open for eight to fourteen months because IT owners do not understand what remediated looks like, working papers fail quality review, and the evidence package does not survive regulatory examination.

After

Evidence requests are fulfilled accurately on the first pass, working papers pass quality assurance and external auditor review, findings close in one cycle, and DORA ICT audit coverage is documented and defensible.

What happens if you do not address this

IT audit functions that cannot produce clean evidence packages face increasing scrutiny from supervisors, lose credibility with internal technology teams, and accumulate open findings that become material at the point of the next regulatory examination.

Who it is for

IT audit managers and senior auditors at global and regional banks who run audits of technology systems, applications, and infrastructure. Three to ten years of audit experience. Familiar with COBIT, ISO 27001, and ITGC theory. The gap is between knowing the framework and being able to extract clean, defensible evidence from IT teams who do not speak audit.

Who this is NOT for. IT security operations staff preparing for an external audit, consultants building audit tools, or professionals with no banking or financial services audit background.

How it arrives

Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.

Time investment. 12 modules, self-paced, typically completed across two to three working days.

Why $199 is the right number

Banking IT audit training typically runs through broad certification tracks that do not address banking-specific evidence methodology or DORA ICT audit requirements. This course covers the operational gap those certifications leave: how to extract clean, testable evidence from IT teams in a regulated banking environment and how to document it so that it survives supervisory examination.

FAQ

Is this relevant to internal IT audit at a bank operating under ECB or ACPR supervision?
Yes. Module 9 addresses supervisory examination preparation for ECB and ACPR-supervised entities specifically. Modules 6 and 7 cover DORA requirements that apply to all EU-regulated banks.
How quickly can I apply what I learn?
Most modules include downloadable templates. An evidence request template from Module 2 can be put into your next audit cycle immediately. The DORA audit evidence checklist from Module 6 is usable as a standalone tool.
Does this cover both application controls and IT general controls?
Yes. Module 3 covers ITGC testing in depth. Application control testing is addressed within the control objective decomposition work in Module 1 and the evidence request methodology in Module 2.

30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.