ask@acsmb.com | | Register
Home
Courses / Free Preview Practical Risk-Based IT Auditing

Free Preview Practical Risk-Based IT Auditing

0.0 (0 reviews)
3 students
All levels
Bernard Wanyama
Course Instructor
Bernard Wanyama

About this course

Get a practical preview of our upcoming webinar, Practical Risk-Based IT Auditing,” scheduled for 17 September 2026. In this 60-minute preview session, Bernard Wanyama (CISA, CISM, CRISC, CGEIT) takes you through a realistic fintech case study - SendCashQuickest - demonstrating how to scope an IT audit around the risks a business actually faces.

Using NIST CSF 2.0 and SEC cybersecurity disclosure requirements as key reference points, you’ll see how effective risk-based auditing moves beyond checklists to focus on what matters most to the business.

What You’ll Experience

  • Risk-based IT audit scoping
  • Triangulating evidence from real-world artifacts
  • Building and defending an effective exclusion log
  • Identifying findings that matter to management
  • Translating audit results into actionable business decisions
  • Understanding how risk-based auditing can drive better investment and accountability

This preview gives you a hands-on taste of the full webinar and the practical approach you can expect on 17 September 2026.

Take the quiz to test what you learned from the preview — and discover what’s waiting for you in the full webinar.

Course Objectives

Explain why a technically correct IT audit can still fail to drive management action, and identify the common root cause.
Apply a risk-based approach to scoping an IT audit, anchored in risks the business already owns rather than a static audit universe.
Use NIST CSF 2.0 — including its new GOVERN function — as a scoping and stakeholder-conversation tool rather than a control checklist.
Interpret the SEC cybersecurity disclosure rules (10-K Item 1C and 8-K Item 1.05), including the four-business-day materiality clock, and explain their relevance even outside the United States.
Triangulate audit scope from multiple real inputs — penetration test reports, privacy/DPIA assessments, risk registers, fraud and incident data, change/release logs, and prior audit findings.
Build and defend a risk-based scoping matrix that ties candidate audit areas to evidence and business impact.
Construct and justify an exclusion log (“out-list”) that documents what was scoped out, why, who agreed, and when it will be revisited.
Describe how a control gap is escalated into a funded management decision using the “materiality bridge.”
Understand how the full two-day master class builds on this scoping objective through fieldwork, findings, report writing, and stakeholder interaction.

Key Takeaways

Scoping is not an administrative step — it is the first and largest risk decision on an engagement, made before any evidence is collected.
The core heuristic: an area that appears in one input is an opinion; in two inputs, it is a candidate; in three or more inputs, it is your defensible scope.
Technically correct audits fail for a single underlying reason: scope anchored in the audit universe rather than in a risk the business already owns and worries about.
Certifications such as ISO 27001 confirm that a management system exists — they do not confirm that controls actually work; certification is an input to risk assessment, never a substitute for it.
Control failures typically occur at the handoffs between teams (e.g., change management and fraud operations), which are invisible to audits scoped by department.
NIST CSF 2.0 describes outcomes, not controls, which makes it a scoping and conversation tool that also cross-references to ISO 27001, PCI-DSS, and COBIT.
Under SEC rules, the four-business-day disclosure clock starts at the materiality determination, not at discovery of the incident — and this pattern is being echoed globally by DORA, NIS2, and other regulators.
A finding only becomes fundable once it climbs all four rungs of the materiality bridge: control gap → plausible incident → business impact → board consequence.

You Might Be Interested In

Explore more courses that match your interests

Browse All Courses