Home/Services/IT Audit & Technology Assurance/IT Audit & Controls Assurance
IT Audit & Technology Assurance · IT general controls

IT Audit & Controls Assurance

Independent testing of whether your IT general controls, application and SAP controls actually operate, not just whether they exist. We test against evidence, prove where controls fail, and hand you a prioritised path to close the gaps.

Typical duration: 3–5 weeksCOBIT & King IV-aligned methodologyIssue-closure retest included
Overview

What it is, and who it’s for

What it is

An independent audit of your IT control environment: access management, change control, IT operations and the application and SAP controls your business relies on. We test design and operating effectiveness against evidence to demonstrate genuine control reliability, not just documented intent.

Who it’s for

  • Regulated firms needing control evidence for external audit or the board
  • Teams meeting SOX-aligned ITGC, King IV or ISO 27001 requirements
  • Organisations after an ERP or SAP implementation, migration or major change

The South African angle

Findings are framed for King IV and POPIA from the outset. Work is conducted from local infrastructure to respect data-residency expectations, and every report speaks directly to the board’s technology governance duties, so your audit committee and compliance teams aren’t left translating.

Our approach

Scope → Fieldwork → Report → Remediate → Retest

A defined lifecycle, not a one-off review. Every engagement runs the same five stages so results are repeatable and defensible.

1

Scope

We agree the control environment, systems in scope, evidence requests and access. Objectives and rules of engagement are documented before fieldwork begins.

2

Fieldwork

Design and operating-effectiveness testing by senior auditors, using data analytics to examine whole populations and traceable evidence for every conclusion.

3

Report

A board-ready summary over a technical appendix. Every finding carries a risk rating, evidence, business impact and clear remediation guidance.

4

Remediate

We walk your engineers through fixes, prioritised by risk, and stay available for questions while your team closes the gaps.

5

Retest

Once fixes are in, we re-test the findings and issue an issue-closure verification confirming closure, the evidence your auditors want.

What you receive

Deliverables

Executive & technical report

A board-ready narrative with a risk-rated finding register, control ratings, evidence and step-by-step remediation.

Remediation tracker

A live register of findings with owners, priorities and status, mirrored in the assurance dashboard.

Issue-closure verification

Independent confirmation that critical and high findings have been resolved, suitable for auditors and regulators.

Debrief workshop

A live walkthrough for your technical and leadership teams, with attack narratives and prioritised next steps.

Mapped to

Relevant frameworks

This engagement directly supports the control and assurance requirements of the frameworks your regulators and partners expect.

COBIT Governance & management objectivesKing IV Principle 12ISO 27001 Annex A controlsCIS Controls v8.1 safeguardsPOPIA §19 security safeguards
Questions

Frequently asked

No, the engagement is designed around your operations. We agree scope, timing and evidence requests up front, work through read-only access wherever possible, and keep a single point of contact live throughout so requests stay coordinated.

A checklist tells you whether a control exists; it can't tell you whether it actually operates. Our auditors test design and operating effectiveness against evidence, use data analytics to examine whole populations rather than samples, and rule out the false comfort that tick-box reviews create.

Yes. Once you've remediated, we re-test every high and critical finding and issue a verification confirming closure, at no extra cost within the agreed engagement window. It's the evidence auditors and the board actually ask for.

Work runs from South African infrastructure, evidence is stored encrypted and purged on an agreed schedule, and our team operates under a signed engagement and NDA. Reports are written to speak directly to POPIA and the Information Regulator's expectations.

Senior, experienced IT auditors based in South Africa, never outsourced or offshored. You'll know your engagement lead by name, and they'll be the one presenting your debrief.

Request an IT audit

Tell us about your control environment and we’ll scope an audit, with clear timing, a fixed price, and an issue-closure retest built in.

IT Audit & Controls Assurance | Resilitech South Africa · Resilitech