Financial Audits Have Extended Into the IT Landscape
- richard vonk
- May 17
- 3 min read
Financial audits are no longer confined to financial transactions. Over the past several years, the scope of a standard financial audit has expanded to include the technology systems that produce and process those transactions — and most IT teams were not prepared for the change.
The shift has a regulatory anchor. The revised ISA 315 standard, which governs how auditors identify and assess risks of material misstatement, explicitly requires auditors to understand the IT environment that supports financial reporting. This means understanding which systems generate the numbers, how those systems connect, what controls are in place, and what the risk profile of the underlying technology estate looks like. Auditors who previously could complete their work by reviewing financial records and speaking to the finance team now need structured information about the IT landscape to do their job to standard.
For most organisations, this creates a practical problem that was not anticipated when the audit was scoped. The finance team does not hold the information the auditor needs. The IT team does — but the IT team has not historically been part of the financial audit process, was not given time to prepare for the engagement, and does not always speak the same language as the auditor asking the questions.
The result is a dynamic that creates unexpected pressure on both sides. The auditor needs to understand the technology estate before they can assess the risk. The IT team needs to produce that picture under time pressure, alongside their normal operational demands, without having prepared a structured view of it in advance. Financial audit timelines are not flexible. The information has to be assembled and communicated within a window that was not designed with IT participation in mind.
The complexity is compounded by the fact that the IT risk profile varies significantly between organisations. An organisation running a modern SaaS stack — where security patching, infrastructure management, and compliance obligations are largely handled by the software vendor — presents a very different picture to one running significant volumes of bespoke or legacy systems, undocumented integrations, and business-critical processes supported by spreadsheets and macros. The auditor cannot know which they are dealing with until they understand the landscape. Understanding the landscape takes time that the audit timeline may not accommodate.
There is a further dimension worth understanding. A modern SaaS application, maintained by a commercial vendor with regular security updates and contractual compliance obligations, may represent lower IT risk than a legacy homegrown system that has not been patched or reviewed in years — regardless of how operationally critical each is to the business. But an organisation that has not documented its landscape cannot make that distinction clearly, which means the auditor cannot make it either. The absence of documentation is itself a risk finding.
The organisations that manage this well are not necessarily the ones with the cleanest technology estate. They are the ones that can describe their estate accurately and quickly — which systems exist, what they do, which processes they support, how they connect, and where the significant risk concentrations are. That description does not need to be perfect. It needs to be honest, structured, and retrievable under audit conditions.
The organisations that struggle are the ones encountering this requirement for the first time during an active audit, assembling the picture from memory and scattered documentation under time pressure, and discovering gaps in what they can account for at the moment they are most exposed.
The practical implication is straightforward: engaging with the auditor before fieldwork begins, understanding specifically what IT information they require, and allocating time to prepare a structured view of the technology estate rather than assembling it reactively, changes the experience significantly. The information that auditors need under ISA 315 is the same information that is useful for governance, investment planning, and risk management in any context. Building it in advance of an audit is not audit preparation. It is basic operational hygiene that happens to make audits manageable.

Comments