top of page

FOR INTERNAL AUDIT LEADERS IN LOCAL GOVERNMENT

Most IT audit plans run on rotation, not risk. Your audit committee can tell.

A rotation schedule looks orderly — every system gets its turn — but it sequences your work by time since the last audit, not by risk. That's the gap a committee probes, and it's the hardest one to close when specialized IT audit skills are scarce and public sector budgets are tight. Bring us your FY27 plan and get a senior read on where the risk isn't accounted for.

Get the redacted sample plan

4629e2_226ed045b1fc40aeb5855dc06039c7b2~mv2.png

Twenty minutes with Paul Ashe Securance's founder, with 30 years spent finding what's broken in complex IT environments — not an SDR, not a junior associate. If you move forward, senior consultants with 15+ years will run the whole engagement, from planning through the final report.

THE PROBLEM

A rotation-based plan looks organized. It just can't answer "why" when the committee asks.

Most multi-year IT audit plans don't hold up under audit-committee scrutiny because they're built on convention, not evidence. Here's where they typically break down.

Image 1- Rotation_edited.jpg

Rotation, not risk.

Most plans rotate through systems on a familiar cadence and present that rotation to the committee as coverage. It reads fine until someone asks why the financial ERP is in year 3 and not year 1 — and the only answer is that's where the rotation put it last cycle too. That's inertia wearing the costume of a risk decision.

Image 2 - Expertise ranking.png

Ranking by risk takes expertise you can't easily hire.

Scoring every system by risk and defending the composite is as much a security discipline as an audit one — and it's the specialized depth that public sector pay scales put out of reach. Local government feels the squeeze most, which is where outside depth pays for itself.

Image 3 - under scrutiny_edited.jpg

It's the most scrutinized thing you produce.

Your multi-year plan is the clearest signal the committee gets about whether internal audit is focused on what matters. A rotation-based plan chips away at that confidence, one unanswered "why" at a time. A risk-ranked one lets you walk in and defend every line — and pass the one-page test: could your committee chair explain the logic of your audit sequence in about a minute, on a single page?

Woman Looking at IT Audit Screen

THE RISK CATEGORIES

Composite scores beat single-axis scores. Every time.

If you only score on "security threat," you miss the fact that an aging on-prem ERP might rate moderate on threat but high on financial exposure, customer impact, and admin burden. So we score on all ten.

Example categories — yours may differ:

1

Corporate Reliance

2

Technology Complexity

3

Vanilla vs. Heavily Customized

4

Adequacy of IT Professional Staff

5

Internal Customer Impact

6

External Customer Impact

7

Financial Exposure

8

Security Threat

9

Level of Admin Tasks

10

Major Recent Change

THE DELIVERABLE

Here’s what a risk-driven audit plan looks like.

The following components make up a standard SCGRC audit plan, built from your environment, scored on your categories, sequenced across your audit cycle.

Multi-category risk methodology

The full framework, with definitions for each category and how they're scored.

53 auditable technologies and processes, independently scored

Enterprise applications, infrastructure applications, and IT processes — each scored across the ten selected risk categories.

3-year audit sequence

Year 1 through Year 3 audits prioritized by composite risk score. Defensible. Auditable.

Items considered and excluded

The credibility multiplier most plans skip. The sample includes a full exclusion log explaining what we evaluated and why it didn't make the cut. Audit committees ask. Now you'll have an answer.

3-YEAR IT AUDIT PLAN — YEAR 1

Top-risk technologies & processes

Scored across 10 categories. High Risk = composite ≥ 35.

Patch Management

39

HIGH

Disaster Recovery Planning

38

HIGH

Accela

36

HIGH

Change Management

36

HIGH

Firewall / Router / Switch

36

HIGH

NorthStar

35

HIGH

Database Security

34

MED

Vendor Management

33

MED

Page 10 of 17 — Redacted sample plan

securanceconsulting.com

Securance has performed IT audits for Louisville Metro Government for over ten years. We have always been very pleased with the work product and the cost value that Securance offers.

Louisville Metro Government Office of Internal Audit

THE SECURANCE DIFFERENCE

A senior read on your plan before your committee gives you theirs.

Most "second opinions" are really a checklist run by a junior associate, or a template you fill in yourself. Securance is different: twenty minutes with someone who has built risk-ranked plans for cities and counties and sat across from the committees that scrutinized them. You get judgment on where your sequence is exposed and what a committee will challenge — not another worksheet.

Get a senior read on your FY27 plan.

Twenty minutes, one-on-one. Bring your current or draft plan and leave knowing where it's exposed and what your committee will push on. No obligation, no pitch.

Not ready to share your plan?

​See what a defensible one looks like — a redacted, multi-year, risk-ranked plan from a real U.S. city engagement.

Every engagement is run by senior consultants with 15+ years of experience, from planning through the final report. Anything you share is confidential; Securance never publishes client plans, scores, or names.

bottom of page