IT Audit
Audits against COBIT, NIST and the requirements of local regulators.
Request an initial assessmentMH Consulting brings over 10 years of hands-on IT audit experience in the banking sector and other highly regulated environments, including complex audits aligned with international standards and central bank regulatory requirements.
An IT audit gives you an independent view of how well the controls over your systems, data and technology processes work, and what needs to improve.
What it covers
- IT governance and strategy
- IT general controls (access, change, operations)
- Information security and cyber security
- Business continuity and disaster recovery
- Third-party and outsourcing management
- Compliance with regulatory requirements
- ISAE 3402 and SSAE 18 audits
Frequently asked questions
IT Audit
Who needs an IT audit?
Banks and other regulated institutions, for which an information systems audit is a regulatory requirement, and any organization that depends on its systems and wants an independent assessment.
How is an IT audit different from a penetration test?
An IT audit assesses whether controls and processes are designed and operating as they should. A penetration test looks for technical weaknesses by simulating attacks. The two complement each other.
Can you support our internal audit function?
Yes. We work as IT specialists for your internal audit team, on individual audits or across the whole annual plan.
Services
Other services
Cybersecurity and Resilience
Risk assessment, security frameworks, business continuity and incident response.
Learn moreAI Compliance and Security
EU AI Act, ISO/IEC 42001, risk assessment and governance frameworks for AI systems.
Learn moreGovernance, Risk and Compliance (GRC)
Integrated GRC frameworks, risk assessments, compliance audits and GRC platforms.
Learn moreCloud Security Architecture
Secure-by-design AWS, Azure and GCP environments, with monitoring and DevSecOps.
Learn moreSOX and J-SOX Compliance
Internal control assessments, risk management and audits.
Learn moreESG and Sustainability Reporting
ESG risk assessments, GRI and SASB reporting, and climate strategy.
Learn moreLet's talk about your next engagement.
Tell us about your engagement — we typically respond within one business day.
