A focused course, tailored for you
IT Control Testing for Banking Internal Audit
Evidence methodology for IT audit managers at regulated banks who need findings that close in one cycle.
The evidence request went to six IT owners. Three sent screenshots. Two sent policy PDFs marked version 1.0. One sent nothing. The finding written from that package stays open for fourteen months.
Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.
Why this course
IT audit managers at regulated banks operate inside a structural gap. On one side: audit methodology that requires testable evidence mapped to control objectives. On the other: IT teams who interpret evidence requests as requests for whatever documentation they already have. The gap produces incomplete working papers, findings that cannot be closed, and audit coverage that does not survive supervisory examination. DORA has added a further layer, with ICT risk management audit requirements that most internal audit methodologies have not yet absorbed. The result is a function that produces substantial audit activity but struggles to demonstrate that IT risk is actually under control.
What you walk away with
- Write evidence requests that IT teams can fulfill accurately on the first pass, without follow-up.
- Produce working papers that pass internal quality assurance and external auditor review.
- Classify and rate IT findings consistently using a banking-appropriate impact and likelihood framework.
- Audit DORA ICT risk management and third-party ICT risk with a structured evidence checklist.
- Build audit reports that the board audit committee and CRO read as action documents, not compliance summaries.
The 12 modules
How this addresses your situation
Specific modules that map to what you said you are dealing with.
What you get with this course
- 12 written modules covering IT control testing, evidence methodology, DORA ICT audit overlay, and regulatory examination preparation.
- Downloadable templates for evidence requests, working papers, finding write-ups, third-party ICT review, and DORA audit evidence checklists.
- Hand-built implementation playbook tailored for your account and delivered alongside course access.
- Access to the Art of Service learning environment, self-paced, with no expiration.
What you will have in hand by Day 1, Week 1, Month 1
Access to the course provisioned within 24 hours of purchase.
Tailored implementation playbook delivered alongside course access.
Before and after
Each IT audit cycle produces findings that stay open for eight to fourteen months because IT owners do not understand what remediated looks like, working papers fail quality review, and the evidence package does not survive regulatory examination.
Evidence requests are fulfilled accurately on the first pass, working papers pass quality assurance and external auditor review, findings close in one cycle, and DORA ICT audit coverage is documented and defensible.
What happens if you do not address this
IT audit functions that cannot produce clean evidence packages face increasing scrutiny from supervisors, lose credibility with internal technology teams, and accumulate open findings that become material at the point of the next regulatory examination.
Who it is for
IT audit managers and senior auditors at global and regional banks who run audits of technology systems, applications, and infrastructure. Three to ten years of audit experience. Familiar with COBIT, ISO 27001, and ITGC theory. The gap is between knowing the framework and being able to extract clean, defensible evidence from IT teams who do not speak audit.
How it arrives
Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.
Time investment. 12 modules, self-paced, typically completed across two to three working days.
Why $199 is the right number
Banking IT audit training typically runs through broad certification tracks that do not address banking-specific evidence methodology or DORA ICT audit requirements. This course covers the operational gap those certifications leave: how to extract clean, testable evidence from IT teams in a regulated banking environment and how to document it so that it survives supervisory examination.
FAQ
30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.