Audit, assurance & evidence · Working
Information-technology audit
Also called: IT audit, IS audit
ELI5
An audit of systems, security, change, access or technology controls.
Used in conversation
“Do not describe information-technology audit as assured beyond the scope of the engagement.”
Pitch context
You will see “Information-technology audit” in board papers, contracts, policies, risk registers and compliance reports when the discussion reaches audit, assurance & evidence.
Why it matters: In audit, assurance & evidence, a loose definition can change rights, obligations, approval, disclosure or enforceability.
Caution
Meaning, enforceability and required process vary by jurisdiction and agreement; this definition is not legal advice.
Sources & evidence · 5
Direct term-level sources and supporting source families.
- IFRS Foundation — IFRS GlossaryDirect source · primary · checked 2026-08-16
- Financial Accounting Standards Board — FASB Accounting Standards CodificationDirect source · primary · checked 2026-08-16
- OECD — G20/OECD Principles of Corporate Governance 2023Direct source · institutional · checked 2026-08-16
- U.S. Securities and Exchange Commission — EDGAR and filing resourcesSupporting source family · primary · checked 2026-08-16
- National Institute of Standards and Technology — Computer Security Resource Center GlossarySupporting source family · primary · checked 2026-08-16