A focused course, tailored for you
The Senior IT Auditor's Bank Tech Audit Workpaper Playbook
Build defensible IT audit workpapers for core banking, identity, change, and cloud at a US retail bank, without rebuilding them every cycle.
The scope memo for the next IT audit cycle has the same access review findings you wrote up last cycle, and the Chief Auditor's coverage map wants the workpapers tighter.
Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.
Why this course
Senior IT Auditors at large US retail banks carry an audit universe that spans core banking ledgers, identity and access platforms, change and release pipelines, cloud landing zones the bank is migrating workloads into, key management and HSM, and a growing list of third-party SaaS the business signed without telling Risk. Internal Audit leadership wants workpapers that pass quality review on the first pass, sampling logic that survives an OCC look, and a control rationale tied back to the bank's own risk taxonomy rather than a generic IT auditing textbook. The platform owners argue every finding. The same three access review findings come back every cycle because compensating controls were accepted last time. The retail platform team and the wholesale platform team test the same control four different ways because the workpaper template has drifted. This course rebuilds the workpaper shape from the control objective down, for each major IT domain in a US retail bank's audit universe, so the next cycle's workpapers are tight, defensible, and reusable.
What you walk away with
- Rebuild the IT general controls workpaper template so it passes QA review on the first pass and holds up under regulator inspection.
- Tie every control test back to the bank's own risk taxonomy and the named risk owner, not a generic IT auditing textbook reference.
- Stop re-litigating the same access review findings every cycle by closing the compensating-control loophole at the workpaper level.
- Produce sampling logic that defends itself to the OCC and the audit committee on platforms that resist statistical sampling.
- Hand the next IT audit cycle a reusable workpaper library covering core banking, identity, change, cloud, key management, third-party SaaS, and operational resilience evidence.
The 12 modules
How this addresses your situation
Specific modules that map to what you said you are dealing with.
What you get with this course
- Twelve text-based modules with worked examples for every IT domain in a US retail bank's audit universe.
- Downloadable workpaper templates for IT general controls, access reviews, change management, cloud landing zones, key management, third-party SaaS, and operational resilience evidence.
- Sampling logic worked examples sized to high-volume transaction platforms.
- Exception write-up and management response language that survives audit committee questioning.
- A hand-built implementation playbook sized to your audit universe and the platforms actually in scope, delivered alongside course access.
What you will have in hand by Day 1, Week 1, Month 1
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.
Modules 1 to 2 in week one rebuild the audit universe and the workpaper template.
Modules 3 to 7 in weeks two to four walk every major IT domain.
Modules 8 to 9 in week five cover third-party SaaS and operational resilience.
Modules 10 to 12 in week six finish sampling, exception write-up, and the reusable workpaper library.
Before and after
Workpapers come back from QA with the same flags every cycle, the same three access review findings re-open, sampling rationale gets pushed back by the regulator, and the workpaper template drifts further every quarter.
Workpapers pass QA on the first pass, the access review findings stay closed, sampling logic survives regulator inspection, and the workpaper library is reusable by the next staff auditor without a rebuild.
What happens if you do not address this
The next audit cycle ships with the same workpaper template that failed QA last cycle, the same access review findings re-open, the operational resilience evidence is assembled from scratch under regulator pressure, and the Chief Auditor's coverage map slips again. The cost is not just the rework, it is the loss of credibility with the audit committee and the regulator when the same findings keep coming back.
Who it is for
A Senior IT Auditor inside a US retail bank's Internal Audit function, owning IT general controls and application controls across core banking, identity, change, cloud, and third-party platforms. Reports through a Chief Auditor or Audit Director. Has been in the role long enough to know which platform owners argue, which findings come back every cycle, and which workpaper sections fail QA review. Wants a workpaper shape that holds up under regulator inspection and audit committee questioning.
How it arrives
Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.
Time investment. Six to eight hours per week for six weeks, with the heaviest week being the cloud landing zone module if your bank is mid-migration. The workpaper templates are reusable from the moment you download them.
Why $199 is the right number
External IT audit training from the large firms teaches IT auditing in the abstract and does not address the platforms a US retail bank actually owns. Internal Audit's own training programme covers methodology but not platform-specific workpapers. The IIA and ISACA membership content covers principles but not worked examples sized to a bank's audit universe. This course is platform-specific, workpaper-specific, and sized to the role.
FAQ
30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.