CPA (ISC) • INFORMATION SYSTEMS

Assess IT Policies, Standards, And Procedures

Evaluating the governance frameworks that safeguard information systems and ensure organizational compliance.

Historical Context & Motivation

The need to formally assess IT policies, standards, and procedures grew directly out of the increasing dependence of business operations on computerized information systems. In the 1960s and 1970s, early mainframe environments were governed informally—often by a handful of technicians who understood the hardware. As organizations migrated to distributed computing and client-server architectures in the 1980s and 1990s, the volume of data, the number of access points, and the complexity of transactions expanded dramatically. Regulators and auditors recognized that without structured governance documents, organizations could neither demonstrate compliance nor effectively manage operational risk. This realization catalyzed the development of comprehensive IT governance frameworks that remain central to modern auditing practice.

1977
Foreign Corrupt Practices Act (FCPA)
The FCPA mandated internal controls for publicly traded companies, indirectly requiring documentation of information-handling practices and laying the groundwork for formal IT policy assessment.
1996
COBIT 1.0 Released by ISACA
The Control Objectives for Information and Related Technologies framework gave auditors a standardized reference to evaluate IT governance, including policies, standards, and procedures across the enterprise.
2002
Sarbanes-Oxley Act (SOX)
Section 404 required management and external auditors to assess the effectiveness of internal controls over financial reporting, elevating IT policy assessment to a regulatory imperative for CPAs.
2013
COSO Internal Control–Integrated Framework Update
The updated COSO framework explicitly incorporated technology-related control principles, reinforcing the need for documented IT policies and their periodic assessment.
2019
COBIT 2019 & Modern IT Governance
COBIT 2019 introduced design factors and governance system principles, reflecting cloud computing, cybersecurity, and evolving regulatory demands that make IT policy assessment an ongoing, adaptive process.

This historical trajectory poses a central question for today's CPA candidates: How does an auditor systematically evaluate whether an organization's IT governance documents are adequately designed, properly implemented, and operating effectively to mitigate information system risks? Answering that question requires understanding the distinct roles of policies, standards, and procedures and the frameworks auditors use to assess them.

Core Principles & Definitions

Before an auditor can assess IT governance documents, it is essential to distinguish among the three hierarchical layers: policies, standards, and procedures. Although these terms are often used interchangeably in casual conversation, they occupy distinct positions in the governance hierarchy, each serving a different function. An IT policy is a high-level statement of intent issued by senior management or the board of directors; it articulates the organization's position on a particular area of IT governance, such as acceptable use, data classification, or access control. Standards translate that intent into mandatory, measurable requirements—for example, specifying that passwords must contain at least twelve characters. Procedures are the step-by-step instructions that employees follow to comply with standards and, by extension, with the overarching policy.

1

IT Policy

A high-level directive approved by senior management or the board, expressing the organization's intent and expectations regarding a specific IT domain. Policies set the 'why' and the 'what' without specifying technical details.
2

IT Standard

A mandatory requirement that specifies the measurable criteria for compliance with a policy. Standards define the 'how much' and 'to what level,' such as minimum encryption strength or patch-cycle frequency.
3

IT Procedure

A step-by-step operational guide that tells personnel exactly how to carry out activities in compliance with a standard. Procedures address the 'how,' detailing tasks, responsible parties, and sequences.
4

IT Governance

The overarching leadership and organizational structure that ensures IT investments support business objectives, manage risk appropriately, and comply with applicable laws and regulations. Governance is the umbrella under which policies, standards, and procedures reside.
5

Control Objective

A desired outcome of a control activity—for example, ensuring that only authorized users gain access to financial reporting systems. Control objectives serve as the benchmarks against which policies, standards, and procedures are assessed.
KEY TAKEAWAY
Think of IT governance documentation like the structure of a corporation's financial reporting. The policy is analogous to the board's declaration that 'financial statements will conform to GAAP.' The standard is like the specific accounting standard (e.g., ASC 606 for revenue recognition) that sets measurable criteria. The procedure is the detailed journal-entry process the accounting team follows each month to record revenue in compliance with that standard. An auditor must evaluate all three layers to determine whether the governance system is sound—just as a financial audit examines assertions at every level from the entity down to individual transactions.

Visual Explanation — The IT Governance Hierarchy

The pyramid illustrates how policies sit at the strategic apex and drive standards at the tactical level, which in turn inform procedures at the operational base. An auditor assesses each tier for design adequacy, implementation completeness, and operating effectiveness.

The visual above captures a critical concept for the CPA exam: governance documents form a cascading hierarchy in which each layer adds specificity. When assessing these documents, the auditor examines alignment—whether the standards faithfully translate the policy intent and whether the procedures faithfully operationalize the standards. Misalignment at any junction introduces control gaps that can lead to data breaches, regulatory violations, or financial misstatement. For instance, if a policy mandates encryption of all customer financial data but the standard only references data at rest (ignoring data in transit), the organization has a gap that an auditor must flag and report. The assessment therefore proceeds both top-down (does each lower layer implement the layer above?) and bottom-up (do the procedures actually produce evidence of compliance that can be tested?).

How Auditors Assess IT Policies, Standards, and Procedures

The assessment methodology mirrors the general audit approach of understanding the entity, evaluating design, and testing operating effectiveness. However, IT policy assessment introduces domain-specific considerations drawn from frameworks like COBIT, ISO/IEC 27001, and NIST Cybersecurity Framework. An auditor typically begins by obtaining and reading the governance documents, interviewing process owners, and mapping the documents to the applicable control objectives. Four key assessment dimensions drive the evaluation.

Four Assessment Dimensions

1

Completeness

Does the organization have documented policies, standards, and procedures covering all relevant IT domains (access control, change management, incident response, data classification, business continuity)? Missing documentation signals unmanaged risk.
2

Alignment

Do the standards and procedures directly trace back to and support the policy intent? Alignment is evaluated through mapping matrices that link each standard to its parent policy and each procedure to its parent standard.
3

Currency

Are the documents current and subject to a regular review cycle? IT environments change rapidly; policies and standards that have not been reviewed within 12 to 24 months may no longer address emerging threats or technologies.
4

Operating Effectiveness

Are the procedures actually followed in practice? The auditor tests effectiveness through inquiry, observation, inspection of documentation, and re-performance.
The process flow shows the four-stage audit methodology—obtain, evaluate design, test effectiveness, and report—alongside common criteria and deficiency types encountered during IT policy assessment.

The diagram above is the operational backbone of an IT governance assessment. In Stage 1 (Obtain), the auditor requests a complete inventory of governance documents, ideally organized by IT domain. Stage 2 (Evaluate Design) is a desk review where the auditor checks completeness, alignment, and currency against applicable frameworks and regulatory requirements. Stage 3 (Test Effectiveness) moves from paper to practice; the auditor gathers evidence that the procedures are being carried out as documented. Stage 4 (Report) communicates findings, often categorizing deficiencies as significant deficiencies or material weaknesses depending on their severity relative to financial reporting risk.

Frameworks & Classification of IT Governance Areas

A CPA assessing IT policies does not work in a vacuum; instead, the auditor benchmarks the organization's documentation against recognized IT governance frameworks. The most commonly referenced frameworks in the context of financial audits are COBIT, ISO/IEC 27001, and the COSO Internal Control–Integrated Framework. Each offers a different lens. COBIT is process-oriented and particularly relevant for IT-specific control objectives. ISO 27001 focuses on information security management systems and provides an internationally recognized standard for certifying that an organization's security controls are adequate. COSO, while broader than IT, defines internal control in terms of five interrelated components—control environment, risk assessment, control activities, information and communication, and monitoring activities—that map directly to IT governance. The table below compares key dimensions of each framework as they relate to IT policy assessment.

Comparison of major frameworks used in IT policy assessment
DimensionCOBIT 2019ISO/IEC 27001COSO 2013
Primary FocusIT governance and management objectives across 40 processesInformation security management system (ISMS) with 93 controls (Annex A)Enterprise-wide internal control over financial reporting (ICFR)
Policy GuidanceGovernance objectives require documented policies for each process domainClause 5.2 mandates an information security policy approved by top managementPrinciple 12 requires policies that deploy control activities through procedures
Standards ApproachCapability levels (0–5) define maturity of process executionControls in Annex A serve as mandatory standards when declared applicable17 principles form the criteria against which controls are evaluated
ProceduresManagement practices describe activities; procedures derive from theseStatement of Applicability links procedures to selected controlsControl activities are performed through documented procedures at all levels
CPA RelevanceMost commonly tested IT governance framework on CPA ISC examReferenced in SOC 2 Type II engagements and international auditsFoundation for SOX Section 404 assessments of ICFR

Key IT Governance Domains to Assess

  • Access Control: Policies governing user authentication, authorization, and segregation of duties; standards specifying password complexity, multi-factor authentication, and access review frequency; procedures for provisioning and de-provisioning user accounts.
  • Change Management: Policies requiring formal approval for changes to production systems; standards defining emergency change thresholds and testing requirements; procedures for logging, testing, and migrating changes.
  • Incident Response: Policies establishing the obligation to detect, report, and remediate security incidents; standards defining severity classifications and response time targets; procedures detailing escalation paths and forensic preservation.
  • Business Continuity & Disaster Recovery: Policies mandating continuity planning; standards specifying recovery time objectives (RTO) and recovery point objectives (RPO); procedures for backup testing and failover activation.
  • Data Classification & Privacy: Policies defining data sensitivity levels and ownership; standards specifying encryption requirements by classification tier; procedures for labeling, handling, and disposing of data.

Worked Example — Assessing an Access Control Policy

Consider the following scenario: You are a CPA engaged to assess the IT general controls of Meridian Financial Services, a mid-sized brokerage firm. Your focus is the firm's access control policy and related standards and procedures. Meridian's IT department has provided you with (1) an 'Information Security Policy' last updated 18 months ago, (2) an 'Access Control Standard' specifying password complexity and review cycles, and (3) a 'User Provisioning Procedure' describing how IT staff create and disable accounts.

Assessing Meridian's Access Control Governance
1
Step 1 — Obtain and Inventory Governance DocumentsRequest and catalog all documents related to access control. Verify that the inventory includes a policy, at least one standard, and corresponding procedures. In Meridian's case, you receive three documents. Confirm the completeness by mapping these to COBIT's 'Manage Identity and Build Access' process (DSS05.04). Note any missing areas, such as remote-access-specific policies or third-party access standards.
Finding: No separate standard for remote access or third-party vendor access. Completeness gap identified.
2
Step 2 — Evaluate Design of the PolicyRead the Information Security Policy and assess whether it articulates management's intent regarding access control—specifically, does it address the principles of least privilege, segregation of duties, and user accountability? Check that the policy is signed by an appropriate authority (e.g., CIO or CISO) and references applicable regulations such as the SEC's Regulation S-P for broker-dealers. Evaluate whether the policy contains a review schedule.
Finding: Policy addresses least privilege and user accountability but does not explicitly reference segregation of duties. The policy was approved by the CIO 18 months ago. Design partially adequate; segregation-of-duties gap noted.
3
Step 3 — Evaluate Design of the StandardExamine the Access Control Standard for measurable requirements. Meridian's standard specifies: (a) passwords must be at least 8 characters, (b) access reviews are conducted annually, and (c) terminated-user accounts must be disabled within 5 business days. Compare these to industry best practices (NIST 800-63B recommends a minimum of 8 characters but encourages longer passphrases; many organizations now target quarterly access reviews). Assess whether the standard aligns with the policy's stated intent.
Finding: The password length meets the minimum NIST threshold but is below the firm's own policy language calling for 'strong authentication.' Annual access reviews may be insufficient for a brokerage handling sensitive client data. Alignment concern and potential inadequacy in review frequency.
4
Step 4 — Test Operating Effectiveness of the ProcedureSelect a sample of 25 terminated employees from the past 12 months and trace each to the date the IT account was disabled. Compare the termination date to the account-disable date. Separately, review access-review documentation to confirm that the annual review was completed and that inappropriate access was remediated. Finally, attempt a re-performance test by verifying that a newly created test account requires the mandated password complexity.
Finding: 4 of 25 terminated-user accounts (16%) were disabled more than 5 business days after termination. Annual access review was completed but 2 accounts with excessive privileges were identified and not remediated within the standard's 30-day cure period. Operating effectiveness deficiency — control is not functioning as designed.
5
Step 5 — Report and Classify FindingsAggregate findings into a deficiency report. Classify each finding by severity. The 16% non-compliance rate in account disablement, combined with the unresolved excessive-privilege accounts, represents a significant deficiency in IT general controls because unauthorized access to brokerage systems creates a reasonable possibility that a material misstatement in financial reporting could occur and not be prevented or detected on a timely basis. Recommend that Meridian: (1) add remote-access and third-party standards, (2) update the policy to include segregation of duties explicitly, (3) shorten the access-review cycle to quarterly, and (4) implement automated account-disablement workflows tied to HR termination events.
Final Classification: Significant deficiency in IT general controls over access management, with four specific remediation recommendations.

Strengths, Limitations, and Common Pitfalls

A rigorous assessment of IT policies, standards, and procedures provides significant value, but auditors must also recognize its limitations and the common pitfalls that can undermine the exercise. The table below summarizes the key strengths alongside the inherent constraints.

Strengths and limitations of IT policy, standard, and procedure assessment
StrengthsLimitations
Provides systematic, repeatable evidence of control design and operation.Documentation may look compliant on paper while actual practices diverge—sometimes called 'shelf-ware.'
Directly supports compliance with SOX 404, SEC regulations, and industry standards.Rapidly evolving technology can render policies obsolete between review cycles, creating a lag in coverage.
Identifies control gaps before they result in security incidents or financial misstatements.Sampling-based effectiveness testing may fail to detect low-frequency non-compliance events.
Improves organizational accountability through clear documentation of roles and responsibilities.The assessment is only as useful as the auditor's understanding of the IT environment—domain expertise is critical.
Enables benchmarking against recognized frameworks (COBIT, ISO 27001, COSO).Smaller organizations may lack the resources to maintain comprehensive governance documentation, potentially leading auditors to apply frameworks disproportionately.
KEY TAKEAWAY
Think of IT governance documents like a company's internal audit manual for financial controls. If the manual exists but nobody follows it, an auditor would not conclude that controls are effective—even if the manual is perfectly written. The same logic applies to IT policies. A beautifully documented access-control policy is worthless if system administrators routinely grant superuser privileges without following the provisioning procedure. The CPA's job is to look beyond the paper to the practice, using the four assessment dimensions of completeness, alignment, currency, and operating effectiveness as the compass.

Connection to Advanced IT Audit and Governance Topics

The assessment of IT policies, standards, and procedures is foundational, but it connects to more advanced topics that CPA candidates should appreciate. As organizations adopt cloud computing, robotic process automation (RPA), and artificial intelligence, the scope and complexity of IT governance expands considerably. An organization migrating financial reporting systems to a cloud environment, for example, must revise its data-classification policy to address shared-responsibility models, update its standards to incorporate the cloud provider's security certifications (e.g., SOC 2 Type II), and rewrite its procedures to reflect new access-management workflows. The table below contrasts the foundational assessment covered in this lesson with the advanced governance considerations that arise in modern environments.

Foundational vs. advanced IT governance assessment
DimensionFoundational AssessmentAdvanced IT Governance
ScopeOn-premises IT systems and traditional enterprise applicationsHybrid and multi-cloud environments, third-party SaaS platforms, API integrations
Policy ComplexitySingle-entity policies approved by internal managementMulti-jurisdictional policies addressing GDPR, CCPA, and cross-border data transfers
Standards MappingCOBIT or ISO 27001 mapped to internal controlsSOC 2 Trust Services Criteria, CSA Cloud Controls Matrix, NIST 800-53 Rev. 5
Effectiveness TestingManual sampling of logs, access reviews, and change ticketsContinuous monitoring using SIEM tools, automated compliance dashboards, and exception-based testing
ReportingInternal deficiency reports and management lettersSOC 1/SOC 2 reports, integrated audit reports, and real-time risk dashboards for audit committees

Understanding the foundational assessment process prepares you to scale your audit approach as technology evolves. The principles remain constant—completeness, alignment, currency, and operating effectiveness—even as the specific policies, standards, and procedures become more technically complex. On the CPA ISC exam, expect scenarios that test your ability to evaluate governance documents in both traditional and emerging technology environments, and to identify which framework best applies to a given situation.

Practice Problems

PROBLEM 1CONCEPTUAL
Explain the difference between an IT policy, an IT standard, and an IT procedure. Why is it important for an auditor to assess all three layers rather than just one?
PROBLEM 2BASIC CALCULATION
An auditor selects a sample of 40 terminated-employee accounts to test compliance with a standard requiring account disablement within 3 business days. The auditor finds that 6 accounts were disabled after the 3-day threshold. Calculate the non-compliance rate and state whether this finding likely constitutes a deficiency.
PROBLEM 3INTERMEDIATE
During your assessment of a manufacturing company's IT governance, you discover that the organization has an access-control policy and a corresponding standard but no documented procedure for user provisioning. The IT manager states that provisioning is handled informally by the two system administrators who 'know what to do.' How would you evaluate this situation using the four assessment dimensions (completeness, alignment, currency, operating effectiveness)?
PROBLEM 4APPLIED
A publicly traded financial services firm is migrating its core trading platform from on-premises servers to Amazon Web Services (AWS). The firm's existing IT policies were written for an on-premises environment. As the CPA assessing IT controls for the SOX 404 audit, identify three specific ways in which the firm's policies, standards, or procedures likely need to be updated to address the cloud migration, and explain how you would test each update for operating effectiveness.
PROBLEM 5CRITICAL THINKING
A mid-sized bank has achieved ISO 27001 certification for its information security management system. The bank's management argues that the certification alone provides sufficient evidence that IT policies, standards, and procedures are adequate and effective, and therefore no further assessment by the external auditor is necessary for the SOX 404 engagement. Critically evaluate this argument. Under what circumstances, if any, might the auditor agree with management's position?

Summary — Assessing IT Policies, Standards, and Procedures

Assessing IT policies, standards, and procedures is a core competency for CPAs engaged in information systems auditing. The assessment process recognizes a three-tier governance hierarchy: policies express senior management's intent, standards translate that intent into measurable requirements, and procedures provide step-by-step operational guidance. Auditors evaluate these documents across four critical dimensions: completeness (are all relevant domains covered?), alignment (does each layer faithfully support the one above?), currency (have documents been reviewed and updated recently?), and operating effectiveness (are procedures actually followed in practice?).

The assessment is anchored in recognized frameworks such as COBIT, ISO/IEC 27001, and COSO, and it is driven by regulatory mandates including SOX Section 404. Key IT governance domains—access control, change management, incident response, business continuity, and data classification—require documented policies, standards, and procedures that the auditor tests through inquiry, observation, inspection, and re-performance. Deficiencies are classified as control deficiencies, significant deficiencies, or material weaknesses depending on their potential impact on financial reporting. As technology environments evolve toward cloud, automation, and artificial intelligence, the fundamental assessment principles remain constant—only the scope and technical complexity increase.

Varsity Tutors • CPA (ISC) • Assess IT Policies, Standards, And Procedures