IT Risk Management Audit Program Assessment Form
Use this form to assess the effectiveness and coverage of your IT risk management audit program. All responses will be used to evaluate program scope, governance, risk coverage, controls, audit frequency, remediation follow-up, and overall effectiveness.
Department or Business Unit Assessed
*
What is the current scope of the IT risk management audit program?
*
Enterprise-wide
Business Unit/Division
Specific Systems/Processes
Other
How would you rate the governance structure for IT risk management?
*
Poor
1
2
3
4
Excellent
5
1 is Poor, 5 is Excellent
Which risk domains are covered by the audit program?
*
Cybersecurity
Data Privacy
Operational Risks
Third-party/Vendor
Regulatory Compliance
Other
Please rate the effectiveness of the following IT controls:
*
Rows
Not Effective
Somewhat Effective
Effective
Highly Effective
Access Control
1
2
3
4
Change Management
5
6
7
8
Incident Response
9
10
11
12
Backup & Recovery
13
14
15
16
Network Security
17
18
19
20
How frequently are IT risk audits conducted?
*
Annually
Semi-annually
Quarterly
Ad hoc
Is there a documented process for tracking remediation of audit findings?
*
Yes, fully documented
Partially documented
Not documented
How effective is the follow-up on remediation actions?
*
Not Effective
1
2
3
4
Highly Effective
5
1 is Not Effective, 5 is Highly Effective
Please rate the overall effectiveness of the IT risk management audit program.
*
1
2
3
4
5
Additional comments or observations
Submit
Should be Empty: