What is an ITGC assessment, and who needs one?
An ITGC assessment tests the IT general controls — access management, change management, IT operations and backup/recovery — that underpin the reliability of your significant systems. Organisations need one when external auditors want to place reliance on systems, when a regulator such as SAMA expects evidence of control effectiveness, or when management wants independent assurance before an inspection.
Do Saudi regulators require IT audits?
Yes. SAMA-regulated institutions are expected to subject technology and cybersecurity controls to periodic independent audit under the SAMA Cyber Security Framework and IT Governance Framework, and NCA ECC requires periodic cybersecurity review and audit of control implementation. Internal audit functions are also expected to cover technology as part of third-line assurance.
Can you co-source technology audits with our internal audit team?
Yes. We provide co-sourced and fully outsourced technology audit capacity — executing audits from your approved plan under your methodology, or bringing ours. We also build IT audit methodologies, workpaper standards and audit universes so your function can run technology audits independently over time.
Which frameworks do you audit against?
SAMA CSF and the SAMA IT Governance Framework, NCA ECC and the NCA Cloud Cybersecurity Controls, ISO 27001, and COBIT 2019 — alongside your own policies and control library. Findings are mapped to the specific control references your regulator supervises against.