r/itaudit

What's your broader view on where governance is heading from an auditos pov?

Having recently finished up a role heading up customer data and governance, I’ve had some downtime to reflect on where data governance is actually heading versus where vendors say they’re heading.

Here is the key friction point I’m seeing currently.

Big tech wants you to centralize everything in their stack, automate every business process, plug in their native AI, and rely on their built-in, proprietary governance features.

In contrast, most organizations are actively building decoupled operating models to avoid vendor lock-in, maintain agility, and avoid single points of failure.

For auditors, you're left stuck in the middle trying to piece together compliance, automated logic, and data integrity across a fragmented web of systems that don't natively trust each other.

As a result, I foresee the emergence of an independent, third-party forensic witness layer, an out-of-ecosystem system that immutably logs and verifies automated decisions outside of the platform where the decision actually happened.

I'm keen to hear what auditors think based on what they're experiencing currently.

reddit.com
u/bewaredropbear_ — 3 days ago
▲ 11 r/itaudit+1 crossposts

An IT Auditor transitioning to AI Governance or AI Audit

Hello everyone, I am an IT Auditor with about 7 years total experience but 3 in IT Auditor. I ama senior now and have a pathway to Lead or Manager in 2-3 years.

I do a lot 70% SOX, 20% Ops Audit and 10% doing fun stuff like AI Enablement projects.

I enjoy the AI Enablement stuff more than what I do mostly. I am tired of the hostile findings conversations, boring audits. I want to pivot to heavy AI audit or AI Governance.

I am a little bit confused on what a pathway looks like since it is relatively new. What are some skills and knowledge I should gather and where can I learn more.

reddit.com
u/Fragrant_Ad_7943 — 4 days ago
▲ 17 r/itaudit

Average Hours in Industry for IT Audit

Hi!

Longer time lurker here! I just wanted advice about this industry. I have been working in IT audit for 1.5 years now at a Big 4 firm in the US. This is my first job out of college and I am a first generation student, so I'd really appreciate the advice.

While the experience has been great, the work culture is super toxic. Everyone says there's a "busy season" but it never really ends. Even though it is summer right now, I still average 50 hours a week.

During my first year, I worked through busy season and studied for the CISA. I took it recently for the first time and failed by 7 points (score was 443). I don't have plans to take it again anytime soon since I am dealing with family issues at the moment.

With that being said, I want to leave Big 4 by the end of 2.5/3 years before promotion to senior. I know everyone says to stick it out until senior but I am so burnt out. I do plan on retaking my CISA after I transition to another job.

I actually love the work, but the hours are insane. Mentally, I am checked out. I am curious if it is any different if I switched to IA in industry. Are the hours better since I don't have to juggle multiple clients? Is this work culture only a Big 4 thing or an industry thing as a whole? If I want to get into GRC, would I need my CISA?

Any advice welcome! Thanks :)

reddit.com
u/Kitchen-Coffee1511 — 5 days ago
▲ 14 r/itaudit

ITGC Scoping

Team, can someone please clarify how you approach ITGC scoping for SOX?

What I have seen as a common trend is that ITGCs generally fall under three areas: Logical Access, Change Management, and Computer Operations (job scheduling, backups, incident management, etc.).

However, when I ask how we arrived at these specific areas, or what authoritative guidance or standard drives that scope, I rarely get a definitive answer.

For example, I have seen some SOX programs include physical security and backups within ITGC scope, while others exclude them. This makes me wonder: what actually drives these differences in scope across SOX programs?

Interested in hearing how others approach and defend their ITGC scope, especially with external auditors.

reddit.com
u/Cold-Meringue4200 — 8 days ago
▲ 5 r/itaudit+2 crossposts

Throwing away a decent offer to gamble on a different path — sanity check?

Long-time lurker, first time posting. Could use some outside perspective since I'm too close to this to think straight anymore.

Background: 5+ years in IT Audit at a large bank, have my CISA, and just finished a master's in Data Science. Built some Python automation for audit testing along the way (access reviews, vulnerability analysis) and used data analytics to improve testing coverage.

The situation: I got a verbal offer for a Senior IT Auditor role at another big bank — $135k base (up from my current $115k, which I've maxed out where I am), plus $20k bonus. Solid comp bump, but it's still... audit. Same lane I'm already in.

I turned it down.

Why: I've realized I want to move into GRC/Tech Risk instead of staying in pure audit — more governance/control-design focused work, less "test after the fact." I also happened to land an interview for a Technology Risk & Control role (same company, different team) that's much more aligned with where I want to go. That interview is in a few days. If I get it, great — it's the direction I actually want, even at potentially lower comp than the audit offer. If I don't get it, I'm back to square one with nothing, since I already declined the audit offer and I'd already maxed out my salary at my current job anyway.

My reasoning for turning down the sure thing:

  • I'm bored and under-managed in my current role — no real projects, minimal oversight
  • The audit offer didn't feel like it was worth leaving for if it was just more of the same
  • I said to myself if I'm staying in audit, I need a bigger jump (like 20%+ on base) to make it worth it; if I'm moving into GRC, I'd take less because the direction matters more to me

Where I'm second-guessing myself: Did I just torch a solid, real offer for a maybe? Is "I want to do something different" a good enough reason to walk away from a locked-in $20k raise? Or is this exactly the kind of calculated risk people are supposed to take early-ish in their career when they can afford it?

Would love to hear from anyone who's made a similar jump (or regretted not making one). What would you have done?

reddit.com
u/Royal_mistress6182 — 8 days ago
▲ 16 r/itaudit

What got you into IT Audit? What would you say to people considering it?

A bit of an overall engagement post for those who have worked in IT Audit already, what got you started in the business?

My first encounter with IT Audit was being on the receiving end of a major audit issue where they pulled me in as a data SME to answer questions and go through a LOT of logs. That eventually lead to a pivot into the IA department and then getting a slew of ISACA certifications as I gained experience.

reddit.com
u/RigusOctavian — 12 days ago
▲ 6 r/itaudit+3 crossposts

Is there AU opportunities for IT audit?

Wondering if there is any, willing to relocate or if not, remotely working in PH. ✅CISA ✅10 years work exp ✅With big4 exp

reddit.com
u/Easy-Writer-0915 — 13 days ago

Been job hunting for a year as a SWE, got a PhD offer I don't want, and now I'm considering an audit M2 instead. Someone talk me through this.

Throwing this out here because I'm going in circles in my own head and I need it out of there.

Context I'm a software engineer, mostly full-stack + some AI/ML stuff (built real-time audio pipelines, churn models, the usual DevOps/CI-CD toolkit). I graduated a year ago and it's been a full year of unemployment since. The market in 2026 is just... brutal. Applications into a void, a handful of interviews that go nowhere, the occasional "we went with someone with more experience" for a junior role. I know I'm not alone in this but it doesn't make it less exhausting.

Somewhere in the middle of all this, I landed a PhD offer. On paper it's a good opportunity. In reality? I'm not excited about it at all. I think I'd be doing it because it's there, not because I actually want it, and I know that's not a good enough reason to commit years of my life to something.

So now I'm eyeing a different escape hatch: an M2 (master's) in audit at a solid school. Different world entirely, more stable hiring pipeline, a real credential, a reset button on this whole job search nightmare.

Except here's the annoying part: I can't let go of the "I'm a software engineer" identity. I've built things I'm proud of. I like the work. Some small stubborn part of me feels like switching to audit would mean giving up on something I actually wanted, just because the timing and the market screwed me over.

So I'm stuck between three options that all feel wrong in a different way:

  • Keep grinding the SE job search and hope it turns around
  • Take the PhD offer despite not being into it, because it's "something"
  • Pivot to audit M2 and try to make peace with leaving SE behind

Anyone else been in this exact kind of limbo job market forcing your hand into a path you didn't actually choose? How did you figure out what to do? Did the pivot end up feeling right, or did you regret not sticking it out?

Not really looking for "just keep applying, it'll work out" I've heard that a lot and at some point it stops being useful advice. Looking more for how people actually made this kind of decision when none of the options felt exciting.

reddit.com
u/Ok-Guidance9730 — 14 days ago