Skip to main content
Image coming soon

The Senior IT Auditor's Bank Tech Audit Workpaper Playbook

$199.00
Adding to cart… The item has been added

A focused course, tailored for you

The Senior IT Auditor's Bank Tech Audit Workpaper Playbook

Build defensible IT audit workpapers for core banking, identity, change, and cloud at a US retail bank, without rebuilding them every cycle.

The scope memo for the next IT audit cycle has the same access review findings you wrote up last cycle, and the Chief Auditor's coverage map wants the workpapers tighter.

$199 one-time
Tailored to your situation. Access within 24 hours. 30-day money-back.

Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.

Why this course

Senior IT Auditors at large US retail banks carry an audit universe that spans core banking ledgers, identity and access platforms, change and release pipelines, cloud landing zones the bank is migrating workloads into, key management and HSM, and a growing list of third-party SaaS the business signed without telling Risk. Internal Audit leadership wants workpapers that pass quality review on the first pass, sampling logic that survives an OCC look, and a control rationale tied back to the bank's own risk taxonomy rather than a generic IT auditing textbook. The platform owners argue every finding. The same three access review findings come back every cycle because compensating controls were accepted last time. The retail platform team and the wholesale platform team test the same control four different ways because the workpaper template has drifted. This course rebuilds the workpaper shape from the control objective down, for each major IT domain in a US retail bank's audit universe, so the next cycle's workpapers are tight, defensible, and reusable.

What you walk away with

  • Rebuild the IT general controls workpaper template so it passes QA review on the first pass and holds up under regulator inspection.
  • Tie every control test back to the bank's own risk taxonomy and the named risk owner, not a generic IT auditing textbook reference.
  • Stop re-litigating the same access review findings every cycle by closing the compensating-control loophole at the workpaper level.
  • Produce sampling logic that defends itself to the OCC and the audit committee on platforms that resist statistical sampling.
  • Hand the next IT audit cycle a reusable workpaper library covering core banking, identity, change, cloud, key management, third-party SaaS, and operational resilience evidence.

The 12 modules

Module 1. Scoping the IT audit universe for a US retail bank
Walk the audit universe a Senior IT Auditor at a US retail bank actually owns: core banking ledgers, retail and wholesale channels, identity and access platforms, change and release, cloud landing zones, key management, third-party SaaS, and operational resilience evidence. The module shows how to map each platform to a risk owner the Chief Auditor will accept, and how to push back when the line of business claims a platform is out of scope.
Module 2. Workpaper shape that passes QA on the first pass
Take the standard workpaper template and rebuild it from the control objective down: objective, risk statement tied to the bank's own taxonomy, control description in the platform owner's language, test step, sample, evidence reference, conclusion, and exception write-up. The module walks a worked example for an access review workpaper that failed QA last cycle and shows the rewrite that passed.
Module 3. IT general controls for core banking platforms
Apply the workpaper shape to a core banking platform: batch job scheduling, end-of-day processing, general ledger interface, branch posting, and reconciliations. The module shows the control objectives the platform owner will accept, the evidence the operations team can actually produce, and the sampling logic that survives both QA review and regulator inspection on a high-volume transaction platform.
Module 4. Identity and access at joiner-mover-leaver granularity
Close the loophole that brings the same access review findings back every cycle. The module walks the workpaper for joiner-mover-leaver controls across core banking, the data warehouse, the cloud landing zones, and privileged-access management tools, and shows how to write a compensating-control rationale that does not silently re-open the same gap next cycle.
Module 5. Change and release controls against production
Audit the change ticket against the production deployment, not the change policy against itself. The module shows the workpaper shape for change management on core banking, the data platform, the customer-facing channels, and the cloud landing zones, including emergency change, standard change, and the grey area where the platform owner argues a config flip is not a change.
Module 6. Cloud landing zone controls during a multi-year migration
The bank is mid-migration into one or more cloud landing zones. The module walks the workpaper shape for landing zone guardrails, account provisioning, IAM federation, network segmentation, logging and monitoring pipelines, and the shared-responsibility line where the platform owner and the cloud provider both claim the other owns the control. Includes the evidence the cloud team can produce and the evidence they will resist producing.
Module 7. Key management, HSM, and cryptographic controls
Audit the key lifecycle across payment processing, customer authentication, data-at-rest encryption, and tokenisation. The module shows the workpaper shape for HSM access, key rotation, key escrow, and the audit trail the regulator expects on key-using applications, including the pushback the platform owner will give on dual control and split knowledge.
Module 8. Third-party SaaS that the line of business signed
Audit the third-party SaaS platforms the lines of business signed without Risk knowing. The module shows the workpaper shape for SaaS inventory, contract review, data classification, access provisioning into the SaaS, monitoring pipelines back to the bank, and the exit clause. Includes the conversation with the line-of-business sponsor that turns a shadow SaaS into a tracked one without blowing up the business relationship.
Module 9. Operational resilience evidence under OCC heightened standards
Build the workpaper that maps the bank's critical operations to the platforms supporting them, the recovery time objectives, the testing evidence, and the impact tolerance language. The module shows how to write the workpaper so the operational resilience evidence the OCC is asking peer banks for is already there at the workpaper level, not assembled from scratch when the request lands.
Module 10. Sampling logic that defends itself to the OCC
Walk the sampling decision: when to use attribute sampling, when to use judgmental, when to use full population, and how to write the rationale so the OCC reviewer does not send the workpaper back. Includes the platforms where statistical sampling fails, the platforms where it survives, and the rationale language the Chief Auditor will accept for both.
Module 11. Exception write-up, root cause, and management response
Write the exception so the platform owner reads it as a finding they can fix, not as a finding they will argue with for six weeks. The module walks the language for root cause, control breakdown, business impact, and the management response that closes the finding without re-opening it in the next cycle. Includes the language that survives audit committee questioning.
Module 12. A reusable workpaper library for the next audit cycle
Assemble the workpaper library covering every module in the course, sized to the audit universe of a US retail bank. The module shows how to hand the library to the next staff auditor, how to keep it current as the platforms change, and how to defend the library to the Chief Auditor, the audit committee, and the regulator on a single page.

How this addresses your situation

Specific modules that map to what you said you are dealing with.

Modules 1 to 2 rebuild the audit universe and the workpaper template.
Modules 3 to 7 walk the workpaper shape across every major IT domain the bank owns.
Modules 8 to 9 cover the third-party SaaS and operational resilience evidence the regulator is most actively asking for.
Modules 10 to 12 cover sampling, exception write-up, and the reusable workpaper library you hand to next cycle's team.

What you get with this course

  • Twelve text-based modules with worked examples for every IT domain in a US retail bank's audit universe.
  • Downloadable workpaper templates for IT general controls, access reviews, change management, cloud landing zones, key management, third-party SaaS, and operational resilience evidence.
  • Sampling logic worked examples sized to high-volume transaction platforms.
  • Exception write-up and management response language that survives audit committee questioning.
  • A hand-built implementation playbook sized to your audit universe and the platforms actually in scope, delivered alongside course access.

What you will have in hand by Day 1, Week 1, Month 1

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

Modules 1 to 2 in week one rebuild the audit universe and the workpaper template.

Modules 3 to 7 in weeks two to four walk every major IT domain.

Modules 8 to 9 in week five cover third-party SaaS and operational resilience.

Modules 10 to 12 in week six finish sampling, exception write-up, and the reusable workpaper library.

Before and after

Before

Workpapers come back from QA with the same flags every cycle, the same three access review findings re-open, sampling rationale gets pushed back by the regulator, and the workpaper template drifts further every quarter.

After

Workpapers pass QA on the first pass, the access review findings stay closed, sampling logic survives regulator inspection, and the workpaper library is reusable by the next staff auditor without a rebuild.

What happens if you do not address this

The next audit cycle ships with the same workpaper template that failed QA last cycle, the same access review findings re-open, the operational resilience evidence is assembled from scratch under regulator pressure, and the Chief Auditor's coverage map slips again. The cost is not just the rework, it is the loss of credibility with the audit committee and the regulator when the same findings keep coming back.

Who it is for

A Senior IT Auditor inside a US retail bank's Internal Audit function, owning IT general controls and application controls across core banking, identity, change, cloud, and third-party platforms. Reports through a Chief Auditor or Audit Director. Has been in the role long enough to know which platform owners argue, which findings come back every cycle, and which workpaper sections fail QA review. Wants a workpaper shape that holds up under regulator inspection and audit committee questioning.

Who this is NOT for. Not for first-year IT audit staff who have not yet touched a core banking platform or sat in a control rationale debate with a platform owner. Not for SOX-only external auditors. Not for IT auditors at fintech startups where the control universe is one cloud account and a payment processor.

How it arrives

Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.

Time investment. Six to eight hours per week for six weeks, with the heaviest week being the cloud landing zone module if your bank is mid-migration. The workpaper templates are reusable from the moment you download them.

Why $199 is the right number

External IT audit training from the large firms teaches IT auditing in the abstract and does not address the platforms a US retail bank actually owns. Internal Audit's own training programme covers methodology but not platform-specific workpapers. The IIA and ISACA membership content covers principles but not worked examples sized to a bank's audit universe. This course is platform-specific, workpaper-specific, and sized to the role.

FAQ

Do I need to be at a specific seniority?
The course is built for a Senior IT Auditor or equivalent at a US retail bank. First-year staff and external SOX-only auditors will not get the full value.
Does the course assume a specific core banking platform?
No. The workpaper shapes apply across the major US retail bank core banking platforms. The implementation playbook delivered alongside course access is sized to the platforms in your actual audit universe.
Is the implementation playbook generic?
No. It is hand-built after purchase, sized to your audit universe and the platforms in scope, and delivered alongside course access.
Will the workpaper templates pass my QA team?
The templates are designed against the QA review criteria a US retail bank Internal Audit function actually uses. Module 2 walks a worked example of a workpaper that failed QA and the rewrite that passed.
Does the course cover operational resilience?
Yes. Module 9 covers operational resilience evidence under OCC heightened standards, including the workpaper shape that has the evidence already assembled at the workpaper level.

30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.