May 20, 2020 By Kim Walsh Governance and Compliance, Industry News

I have been doing IT audits for a long time and I have always believed that being in the room matters. Not just for the formal interviews and the process walkthroughs, but for the informal conversations that happen in hallways, the observations you make by simply being present in an environment, and the relationship-building that makes subsequent audit cycles easier and more productive.

March 2020 removed that option for most of us and the question now is not whether remote auditing is going to be part of our practice but how we do it well.

The core challenge with remote auditing is not the technology. Most organizations have videoconferencing platforms, document sharing capabilities, and screen-sharing tools that can replicate most of what an in-person fieldwork visit accomplishes. The challenge is discipline and rigor. When you are sitting across from a process owner in a conference room, the structure of that interaction tends to keep things focused. Remote interviews require more deliberate preparation, more explicit agenda-setting, and more careful documentation of what was observed and how, because you will not be able to supplement your notes with the contextual observations you would have made in person.

Evidence gathering requires more structured coordination. In a traditional audit, handing someone a request list and sitting nearby to answer questions as they pull documentation creates a natural workflow. Remotely, you need to be more explicit about evidence format, submission mechanisms, and how you will verify that what you receive matches what you requested. Screen-sharing walkthroughs of system configurations and access controls, when documented properly with screenshots and timestamps, can be a reasonable substitute for observing a live demonstration in person.

The internal control frameworks that guide IT audit practice have not fundamentally changed because of remote work, but the audit programs we use to test those controls need to be updated to reflect remote-appropriate procedures. ISACA has been developing guidance on this and their resources are worth reviewing as you update your audit programs. Their published standards and guidance documents are available at ISACA’s resource library.

From a certification and professional development standpoint, the skill set that remote auditing demands, structured communication, rigorous documentation, technology-mediated evidence gathering, is consistent with what CISA and related credentials have always tested. The fundamentals have not changed. The methods have adapted. Audit professionals who update their fieldwork practices accordingly will find that remote audit is a workable, if imperfect, substitute for the real thing. And given that some version of hybrid remote work is likely to persist beyond this crisis, getting good at remote audit methods now is genuinely worth the investment.

Kim Walsh

Kim Walsh is a CISSP and seasoned cybersecurity practitioner with deep, hands-on experience in enterprise security architecture, risk management, and compliance. She is passionate about bringing the next generation into the IT and AI space, actively mentoring young people who are just finding their footing in the field. As the mother of five kids, she has both the patience and the battle-tested communication skills to explain just about anything to just about anyone.