FOR INTERNAL AUDIT LEADERS IN LOCAL GOVERNMENT
Most IT audit plans run on rotation, not risk. Your audit committee can tell.
A rotation schedule looks orderly — every system gets its turn — but it sequences your work by time since the last audit, not by risk. That's the gap a committee probes, and it's the hardest one to close when specialized IT audit skills are scarce and public sector budgets are tight. Bring us your FY27 plan and get a senior read on where the risk isn't accounted for.
Twenty minutes with Paul Ashe — Securance's founder, with 30 years spent finding what's broken in complex IT environments — not an SDR, not a junior associate. If you move forward, senior consultants with 15+ years will run the whole engagement, from planning through the final report.
THE PROBLEM
A rotation-based plan looks organized. It just can't answer "why" when the committee asks.
Most multi-year IT audit plans don't hold up under audit-committee scrutiny because they're built on convention, not evidence. Here's where they typically break down.

Rotation, not risk.
Most plans rotate through systems on a familiar cadence and present that rotation to the committee as coverage. It reads fine until someone asks why the financial ERP is in year 3 and not year 1 — and the only answer is that's where the rotation put it last cycle too. That's inertia wearing the costume of a risk decision.

Ranking by risk takes expertise you can't easily hire.
Scoring every system by risk and defending the composite is as much a security discipline as an audit one — and it's the specialized depth that public sector pay scales put out of reach. Local government feels the squeeze most, which is where outside depth pays for itself.

It's the most scrutinized thing you produce.
Your multi-year plan is the clearest signal the committee gets about whether internal audit is focused on what matters. A rotation-based plan chips away at that confidence, one unanswered "why" at a time. A risk-ranked one lets you walk in and defend every line — and pass the one-page test: could your committee chair explain the logic of your audit sequence in about a minute, on a single page?

THE RISK CATEGORIES
Composite scores beat single-axis scores. Every time.
If you only score on "security threat," you miss the fact that an aging on-prem ERP might rate moderate on threat but high on financial exposure, customer impact, and admin burden. So we score on all ten.
Example categories — yours may differ:
1
Corporate Reliance
2
Technology Complexity
3
Vanilla vs. Heavily Customized
4
Adequacy of IT Professional Staff
5
Internal Customer Impact
6
External Customer Impact
7
Financial Exposure
8
Security Threat
9
Level of Admin Tasks
10
Major Recent Change
THE DELIVERABLE
Here’s what a risk-driven audit plan looks like.
The following components make up a standard SCGRC audit plan, built from your environment, scored on your categories, sequenced across your audit cycle.
Multi-category risk methodology
The full framework, with definitions for each category and how they're scored.
53 auditable technologies and processes, independently scored
Enterprise applications, infrastructure applications, and IT processes — each scored across the ten selected risk categories.
3-year audit sequence
Year 1 through Year 3 audits prioritized by composite risk score. Defensible. Auditable.
Items considered and excluded
The credibility multiplier most plans skip. The sample includes a full exclusion log explaining what we evaluated and why it didn't make the cut. Audit committees ask. Now you'll have an answer.
3-YEAR IT AUDIT PLAN — YEAR 1
Top-risk technologies & processes
Scored across 10 categories. High Risk = composite ≥ 35.
Patch Management
39
HIGH
Disaster Recovery Planning
38
HIGH
Accela
36
HIGH
Change Management
36
HIGH
Firewall / Router / Switch
36
HIGH
NorthStar
35
HIGH
Database Security
34
MED
Vendor Management
33
MED
Page 10 of 17 — Redacted sample plan
securanceconsulting.com
Securance has performed IT audits for Louisville Metro Government for over ten years. We have always been very pleased with the work product and the cost value that Securance offers.
Louisville Metro Government Office of Internal Audit
THE SECURANCE DIFFERENCE
A senior read on your plan — before your committee gives you theirs.
Most "second opinions" are really a checklist run by a junior associate, or a template you fill in yourself. Securance is different: twenty minutes with someone who has built risk-ranked plans for cities and counties and sat across from the committees that scrutinized them. You get judgment on where your sequence is exposed and what a committee will challenge — not another worksheet.
Every engagement is run by senior consultants with 15+ years of experience, from planning through the final report. Anything you share is confidential; Securance never publishes client plans, scores, or names.
.png)
