top of page
FOR LOCAL GOVERNMENT INTERNAL AUDIT
A multi-year IT audit plan that holds up.
Securance's IT audit planning process builds risk-based plans for counties, cities, school districts, and special districts — scored across 10 risk categories and delivered by senior consultants with 15+ years of experience.
Building a defensible IT audit plan requires technical expertise most internal audit teams don't have in-house. SCGRC closes that gap. The web-based tool walks your team through a structured risk assessment, scores each technology across your selected risk categories, and produces a three-year audit sequence your committee can review and your team can execute.
10 Risk Categories
3-Year Audit Sequence
Every technology and process scored across 10 categories, composite — not single-axis
A defensible, risk-ranked sequence your audit committee can read in minutes.
WHY SECURANCE
The three pillars of a defensible audit plan.
Most multi-year IT audit plans don't hold up under audit-committee scrutiny because they're built on convention, not evidence. Here's how we build them differently.

01 METHODOLOGY
Risk-aligned, multi-category scoring
Every plan starts with a risk assessment scored across dimensions like Corporate Reliance, Customer Impact, Financial Exposure, and Security Threat. Clients select from a full list or define their own — so the scoring reflects your environment, not a default configuration.

02 OUTPUT
Audit-committee ready
Each technology in scope receives a composite risk ranking — High, Medium, or Low — that determines its place in the three-year audit sequence. The result is a plan the committee can read in minutes: plain English, no IT jargon, sequenced by risk.

03 DELIVERY
Senior-led. Start to finish.
The risk assessment isn't a form you fill out. Senior consultants conduct the stakeholder interviews, make the scoring judgments, and build the audit plan. No bait-and-switch staffing. The person scoping your work is the person doing your work.

THE RISK CATEGORIES
Composite scores beat single-axis scores. Every time.
If you only score on "security threat," you miss the fact that an aging on-prem ERP might rate moderate on threat but high on financial exposure, customer impact, and admin burden. So we score on all ten.
Example categories — yours may differ:
1
Corporate Reliance
3
External Customer Impact
5
Future Life
7
Level of Admin Tasks
9
Prior Audit History
2
Internal Customer Impact
4
Financial Exposure
6
Security Threat
8
Commercial vs. Internal
10
Recent Major Change
THE DELIVERABLE
Here’s what a risk-driven audit plan looks like.
The following components make up a standard SCGRC audit plan, built from your environment, scored on your categories, sequenced across your audit cycle.
Multi-category risk methodology
The full framework, with definitions for each category and how they're scored.
53 auditable technologies and processes, independently scored
Enterprise applications, infrastructure applications, and IT processes — each scored across the ten selected risk categories.
3-year audit sequence
Year 1 through Year 3 audits prioritized by composite risk score. Defensible. Auditable.
Items considered and excluded
The credibility multiplier most plans skip. The sample includes a full exclusion log explaining what we evaluated and why it didn't make the cut. Audit committees ask. Now you'll have an answer.
3-YEAR IT AUDIT PLAN — YEAR 1
Top-risk technologies & processes
Scored across 10 categories. High Risk = composite ≥ 35.
Patch Management
39
HIGH
Disaster Recovery Planning
38
HIGH
Accela
36
HIGH
Change Management
36
HIGH
Firewall / Router / Switch
36
HIGH
NorthStar
35
HIGH
Database Security
34
MED
Vendor Management
33
MED
Page 10 of 17 — Redacted sample plan
securanceconsulting.com
Securance has performed IT audits for Louisville Metro Government for over ten years. We have always been very pleased with the work product and the cost value that Securance offers.”
Louisville Metro Government Office of Internal Audit
We will assess your current plan and outline what a risk-ranked alternative would look like for your environment.
bottom of page
.png)