ISACA ITAF Audit Framework Application Training Course
| Course code | SD-A-071 |
|---|---|
| Duration | 5 days |
| Level | Intermediate |
| Category | Auditing |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Technology audit teams are expected to produce work that is defensible to audit committees, regulators, external auditors and senior management. That requires more than technical knowledge: auditors must apply a recognised framework to define independence, scope engagements, assess risk, collect sufficient evidence, document conclusions and report issues with appropriate severity. This course addresses the practical challenge of applying ISACA’s ITAF to real audit assignments, from annual planning through workpaper review and final reporting.
Participants work through the structure and mandatory requirements of the ISACA Information Technology Audit Framework (ITAF), including ITAF standards, guidelines and tools and techniques. They learn to translate ITAF requirements into an audit charter, engagement plan, risk-and-control matrix, test procedures, evidence records, issue statements and management action tracking. The course also connects ITAF application with COBIT 2019 governance objectives and NIST SP 800-53 control concepts, helping participants position IT audit work within established enterprise control environments.
Delivery combines instructor-led framework interpretation with audit-file exercises, group review sessions and a multi-stage case study. Participants draft and critique core engagement documentation, test sample controls, evaluate evidence sufficiency, rate findings and prepare an audit report for a simulated technology environment. Each participant leaves with an ITAF-aligned audit engagement pack containing reusable templates, completed working papers and a personal application plan. A certificate of completion is awarded at the end of the five-day course.
The programme is designed for professionals who already understand basic audit or control concepts and now need a disciplined method for conducting, supervising or reviewing IT audit engagements under the ISACA ITAF framework.
Course objectives
By the end of this course, participants will be able to:
- Interpret ISACA ITAF standards, guidelines and tools in the context of a technology audit engagement
- Develop an ITAF-aligned audit charter and engagement planning memorandum
- Construct a risk-and-control matrix linking business risks, controls, test objectives and evidence requirements
- Define audit scope, materiality considerations, resource requirements and engagement timelines using risk assessment results
- Design control test procedures that specify populations, samples, expected evidence and evaluation criteria
- Evaluate evidence for sufficiency, reliability, relevance and appropriateness under ITAF requirements
- Draft evidence-based audit findings with condition, criteria, cause, risk, recommendation and management action
- Assemble an ITAF-compliant audit file and quality-review checklist for a completed engagement
Benefits of attending
For you
- Apply a recognised ISACA framework when planning, performing and documenting IT audit work
- Produce stronger workpapers that demonstrate how conclusions are supported by audit evidence
- Improve credibility when discussing audit scope, control failures and recommendations with technology leaders
- Build a reusable set of ITAF-aligned templates for future audit engagements
- Prepare more effectively for IT audit responsibilities associated with CISA-oriented career paths
For your organisation
- Increase consistency in how IT audit engagements are scoped, tested, documented and reported
- Reduce quality-review rework through clearer evidence standards and workpaper structure
- Strengthen the defensibility of audit conclusions presented to management, audit committees and external assurance providers
- Improve prioritisation of audit resources by linking engagement scope to technology risk and control objectives
- Produce more actionable remediation plans through disciplined finding statements and management action tracking
Target competencies
Who should attend
- IT Auditors — who need to execute and document engagements against the ISACA ITAF framework
- IT Audit Managers — who review workpapers, approve audit scope and maintain consistent audit quality
- Internal Auditors — who audit technology-enabled business processes and require a recognised IT audit method
- Information Security Auditors — who assess security controls and need defensible evidence and reporting practices
- Risk and Compliance Managers — who oversee control assurance activities and remediation reporting
- External Audit Professionals — who evaluate IT general controls and rely on structured audit evidence
Requirements and prerequisites
Participants should have working familiarity with internal audit concepts, including audit objectives, risks, controls, evidence, findings and management responses. Experience participating in at least one audit, controls review, compliance assessment or IT risk assessment is strongly recommended. Familiarity with common IT general controls—such as access management, change management, backup or incident management—will help participants engage fully with the case work. Participants should be able to use Microsoft Excel for simple tables and filtering. Prior ISACA membership, CISA certification, COBIT certification, specialist cybersecurity knowledge and previous use of ITAF are not required.
Training methodology
The course uses short instructor-led sessions to interpret ITAF requirements, followed by structured application to a simulated organisation’s identity, change and security controls. Participants build an engagement file progressively: they assess risks, define scope, complete a risk-and-control matrix, write test steps, review evidence and draft findings. Small-group work focuses on resolving evidence and finding-severity disagreements that arise in practice. Facilitated peer review applies an ITAF quality checklist to workpapers. On day five, each participant completes an application plan for adapting the methods and templates to a live audit assignment.
Course outline
Day 1: ISACA ITAF foundations and audit governance
- ISACA ITAF architecture: standards, guidelines and tools and techniques
- ITAF professional ethics, due care and auditor competence requirements
- Audit independence, objectivity and impairment assessment
- IT audit charter purpose, authority and accountability
- Relationship between ITAF, COBIT 2019 and enterprise governance
- Audit universe development for technology risks and processes
- Engagement lifecycle from planning through follow-up
Workshop: Participants assess a simulated audit function against ITAF governance requirements and produce an audit charter gap log.
Day 2: Risk-based engagement planning
- Business process and technology environment scoping
- Inherent risk, control risk and residual risk assessment
- Audit objective formulation and measurable control criteria
- COBIT 2019 objectives as control assessment references
- Risk-and-control matrix design and traceability
- Engagement materiality, significance and prioritisation decisions
- Audit programme, resource plan and planning memorandum preparation
Workshop: Participants create a risk-and-control matrix and ITAF-aligned engagement plan for a privileged-access management audit.
Day 3: Fieldwork, testing and audit evidence
- Evidence sufficiency, reliability, relevance and appropriateness
- Population definition and sampling approaches for control testing
- Inquiry, observation, inspection and reperformance techniques
- Designing test procedures with expected evidence and pass-fail criteria
- Testing access provisioning and periodic access review controls
- Testing change management approvals and production migration controls
- Workpaper indexing, cross-referencing and evidence retention
Workshop: Participants test a sample of access and change records, document exceptions and prepare indexed workpapers with evidence references.
Day 4: Findings, reporting and quality assurance
- Evaluating control exceptions against audit criteria
- Root cause analysis using the five whys method
- Risk rating models and impact-likelihood assessment
- Finding structure: condition, criteria, cause, consequence and recommendation
- Management action plans, owners, target dates and acceptance of risk
- Audit report structure and communication with senior stakeholders
- ITAF engagement supervision and quality assurance review
Workshop: Participants convert documented exceptions into risk-rated audit findings and conduct a peer quality review of a draft report.
Day 5: Integrated ITAF audit application
- End-to-end ITAF engagement case briefing
- Scope challenge and stakeholder expectation management
- Evidence conflict resolution and professional judgement
- NIST SP 800-53 control concepts in audit evidence evaluation
- Audit issue aggregation and thematic risk analysis
- Final engagement file review against an ITAF checklist
- Post-audit follow-up and remediation validation planning
Workshop: Participants complete and present an ITAF-aligned audit engagement pack, including scope, matrix, workpapers, findings, report summary and follow-up plan.
Tools & standards covered
ISACA Information Technology Audit Framework (ITAF), COBIT 2019, NIST SP 800-53, Microsoft Excel
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Auditing
Grant Compliance Auditing for NGO Finance Teams Training Course
NGO finance teams must demonstrate that restricted funds were spent for the approved purpose, charged to the correct grant, supported by rel…
ISO 19011 Management System Auditing Training Course
Finance and accounting teams depend on controlled processes for close, reconciliations, expense approvals, revenue recognition, master-data …
Cybersecurity Audit Evidence for Information Security Auditors Training Course
Information security auditors are expected to substantiate conclusions about access control, logging, vulnerability management, change contr…
Advanced Forensic Audit Investigation and Interviewing Training Course
Suspected fraud, financial misconduct, and control override require more than routine audit testing. Investigators must turn an allegation, …