ISACA ITAF Audit Framework Application Training Course

5 days Auditing Certificate on completion
Course codeSD-A-071
Duration5 days
LevelIntermediate
CategoryAuditing
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Technology audit teams are expected to produce work that is defensible to audit committees, regulators, external auditors and senior management. That requires more than technical knowledge: auditors must apply a recognised framework to define independence, scope engagements, assess risk, collect sufficient evidence, document conclusions and report issues with appropriate severity. This course addresses the practical challenge of applying ISACA’s ITAF to real audit assignments, from annual planning through workpaper review and final reporting.

Participants work through the structure and mandatory requirements of the ISACA Information Technology Audit Framework (ITAF), including ITAF standards, guidelines and tools and techniques. They learn to translate ITAF requirements into an audit charter, engagement plan, risk-and-control matrix, test procedures, evidence records, issue statements and management action tracking. The course also connects ITAF application with COBIT 2019 governance objectives and NIST SP 800-53 control concepts, helping participants position IT audit work within established enterprise control environments.

Delivery combines instructor-led framework interpretation with audit-file exercises, group review sessions and a multi-stage case study. Participants draft and critique core engagement documentation, test sample controls, evaluate evidence sufficiency, rate findings and prepare an audit report for a simulated technology environment. Each participant leaves with an ITAF-aligned audit engagement pack containing reusable templates, completed working papers and a personal application plan. A certificate of completion is awarded at the end of the five-day course.

The programme is designed for professionals who already understand basic audit or control concepts and now need a disciplined method for conducting, supervising or reviewing IT audit engagements under the ISACA ITAF framework.

Course objectives

By the end of this course, participants will be able to:

  • Interpret ISACA ITAF standards, guidelines and tools in the context of a technology audit engagement
  • Develop an ITAF-aligned audit charter and engagement planning memorandum
  • Construct a risk-and-control matrix linking business risks, controls, test objectives and evidence requirements
  • Define audit scope, materiality considerations, resource requirements and engagement timelines using risk assessment results
  • Design control test procedures that specify populations, samples, expected evidence and evaluation criteria
  • Evaluate evidence for sufficiency, reliability, relevance and appropriateness under ITAF requirements
  • Draft evidence-based audit findings with condition, criteria, cause, risk, recommendation and management action
  • Assemble an ITAF-compliant audit file and quality-review checklist for a completed engagement

Benefits of attending

For you

  • Apply a recognised ISACA framework when planning, performing and documenting IT audit work
  • Produce stronger workpapers that demonstrate how conclusions are supported by audit evidence
  • Improve credibility when discussing audit scope, control failures and recommendations with technology leaders
  • Build a reusable set of ITAF-aligned templates for future audit engagements
  • Prepare more effectively for IT audit responsibilities associated with CISA-oriented career paths

For your organisation

  • Increase consistency in how IT audit engagements are scoped, tested, documented and reported
  • Reduce quality-review rework through clearer evidence standards and workpaper structure
  • Strengthen the defensibility of audit conclusions presented to management, audit committees and external assurance providers
  • Improve prioritisation of audit resources by linking engagement scope to technology risk and control objectives
  • Produce more actionable remediation plans through disciplined finding statements and management action tracking

Target competencies

ITAF standards applicationRisk-based audit planningControl test designAudit evidence evaluationFinding report writingWorkpaper quality review

Who should attend

  • IT Auditors — who need to execute and document engagements against the ISACA ITAF framework
  • IT Audit Managers — who review workpapers, approve audit scope and maintain consistent audit quality
  • Internal Auditors — who audit technology-enabled business processes and require a recognised IT audit method
  • Information Security Auditors — who assess security controls and need defensible evidence and reporting practices
  • Risk and Compliance Managers — who oversee control assurance activities and remediation reporting
  • External Audit Professionals — who evaluate IT general controls and rely on structured audit evidence

Requirements and prerequisites

Participants should have working familiarity with internal audit concepts, including audit objectives, risks, controls, evidence, findings and management responses. Experience participating in at least one audit, controls review, compliance assessment or IT risk assessment is strongly recommended. Familiarity with common IT general controls—such as access management, change management, backup or incident management—will help participants engage fully with the case work. Participants should be able to use Microsoft Excel for simple tables and filtering. Prior ISACA membership, CISA certification, COBIT certification, specialist cybersecurity knowledge and previous use of ITAF are not required.

Training methodology

The course uses short instructor-led sessions to interpret ITAF requirements, followed by structured application to a simulated organisation’s identity, change and security controls. Participants build an engagement file progressively: they assess risks, define scope, complete a risk-and-control matrix, write test steps, review evidence and draft findings. Small-group work focuses on resolving evidence and finding-severity disagreements that arise in practice. Facilitated peer review applies an ITAF quality checklist to workpapers. On day five, each participant completes an application plan for adapting the methods and templates to a live audit assignment.

Course outline

Day 1: ISACA ITAF foundations and audit governance

  • ISACA ITAF architecture: standards, guidelines and tools and techniques
  • ITAF professional ethics, due care and auditor competence requirements
  • Audit independence, objectivity and impairment assessment
  • IT audit charter purpose, authority and accountability
  • Relationship between ITAF, COBIT 2019 and enterprise governance
  • Audit universe development for technology risks and processes
  • Engagement lifecycle from planning through follow-up

Workshop: Participants assess a simulated audit function against ITAF governance requirements and produce an audit charter gap log.

Day 2: Risk-based engagement planning

  • Business process and technology environment scoping
  • Inherent risk, control risk and residual risk assessment
  • Audit objective formulation and measurable control criteria
  • COBIT 2019 objectives as control assessment references
  • Risk-and-control matrix design and traceability
  • Engagement materiality, significance and prioritisation decisions
  • Audit programme, resource plan and planning memorandum preparation

Workshop: Participants create a risk-and-control matrix and ITAF-aligned engagement plan for a privileged-access management audit.

Day 3: Fieldwork, testing and audit evidence

  • Evidence sufficiency, reliability, relevance and appropriateness
  • Population definition and sampling approaches for control testing
  • Inquiry, observation, inspection and reperformance techniques
  • Designing test procedures with expected evidence and pass-fail criteria
  • Testing access provisioning and periodic access review controls
  • Testing change management approvals and production migration controls
  • Workpaper indexing, cross-referencing and evidence retention

Workshop: Participants test a sample of access and change records, document exceptions and prepare indexed workpapers with evidence references.

Day 4: Findings, reporting and quality assurance

  • Evaluating control exceptions against audit criteria
  • Root cause analysis using the five whys method
  • Risk rating models and impact-likelihood assessment
  • Finding structure: condition, criteria, cause, consequence and recommendation
  • Management action plans, owners, target dates and acceptance of risk
  • Audit report structure and communication with senior stakeholders
  • ITAF engagement supervision and quality assurance review

Workshop: Participants convert documented exceptions into risk-rated audit findings and conduct a peer quality review of a draft report.

Day 5: Integrated ITAF audit application

  • End-to-end ITAF engagement case briefing
  • Scope challenge and stakeholder expectation management
  • Evidence conflict resolution and professional judgement
  • NIST SP 800-53 control concepts in audit evidence evaluation
  • Audit issue aggregation and thematic risk analysis
  • Final engagement file review against an ITAF checklist
  • Post-audit follow-up and remediation validation planning

Workshop: Participants complete and present an ITAF-aligned audit engagement pack, including scope, matrix, workpapers, findings, report summary and follow-up plan.

Tools & standards covered

ISACA Information Technology Audit Framework (ITAF), COBIT 2019, NIST SP 800-53, Microsoft Excel

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

No. The course does not require CISA certification, ISACA membership or prior formal training in ITAF. Participants do need practical familiarity with audit, risk or control concepts so they can work meaningfully with the engagement case.

Bring a laptop with Microsoft Excel or equivalent spreadsheet software for the workshop templates and evidence exercises. No specialist GRC platform, data analytics software or audit management system is required.

It is best suited to IT auditors, internal auditors, IT audit managers, security auditors and compliance professionals who already participate in assurance work. It is particularly useful for teams standardising their audit approach around ISACA ITAF.

COBIT courses focus on governance and management objectives, while CISA preparation focuses on examination domains and question practice. This course concentrates on applying ITAF as the working method for planning, performing, documenting, reviewing and reporting an IT audit engagement.

Participants can adapt the engagement plan, risk-and-control matrix, test procedure format, workpaper structure and finding template for their next audit. The application plan completed on day five identifies a specific live assignment and the documentation to introduce.

Participants leave with a completed ITAF-aligned engagement pack developed through the case study, plus reusable templates and a quality-review checklist. These materials include planning, testing, reporting and follow-up artefacts rather than only presentation slides.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Auditing

5 Days Certificate

Grant Compliance Auditing for NGO Finance Teams Training Course

NGO finance teams must demonstrate that restricted funds were spent for the approved purpose, charged to the correct grant, supported by rel…

5 Days Certificate

ISO 19011 Management System Auditing Training Course

Finance and accounting teams depend on controlled processes for close, reconciliations, expense approvals, revenue recognition, master-data …

5 Days Certificate

Cybersecurity Audit Evidence for Information Security Auditors Training Course

Information security auditors are expected to substantiate conclusions about access control, logging, vulnerability management, change contr…

5 Days Certificate

Advanced Forensic Audit Investigation and Interviewing Training Course

Suspected fraud, financial misconduct, and control override require more than routine audit testing. Investigators must turn an allegation, …