| name | isaca-audit-methodology |
| description | Perform ISACA-based IT audit work including CISA methodology, COBIT 2019 governance/management objectives, ITAF standards, ITGC/ITAC testing, risk-based audit planning, 5-part audit observations, COBIT maturity assessment, and cross-framework mapping. Activate when performing IT audits, IS audits, control assessments, COBIT evaluations, IT risk assessments, audit observation writing, ITGC/ITAC testing, audit planning, or audit report generation. |
| category | audit |
| risk | high |
| source | ISACA CISA CRM 28th Ed 2024, COBIT 2019, ITAF, ISACA Code of Professional Ethics |
| date_added | "2026-05-25T00:00:00.000Z" |
| version | 0.2.0 |
| status | draft |
| industries | ["financial-services","saas-technology","public-sector","healthcare"] |
| frameworks | ["ISACA-CISA-CRM","COBIT-2019","ITAF","COSO-2013","NIST-CSF-2.0","ISO-27001-2022","AICPA-TSC-2017"] |
| telemetry_contract | telemetry/schema.json#/$defs/SkillInvocation |
| token_baseline_target | {"input_p90":16000,"output_p90":5000} |
| context_budget | {"always_loaded_tokens":3200,"per_call_typical_tokens":6500,"per_call_max_tokens":16000,"per_call_p90_tokens":8500} |
| tags | ["isaca","cisa","cobit-2019","itaf","itgc","itac","it-audit","risk-assessment","audit-observation","maturity-model","internal-controls","governance","compliance","coso","aicpa","nist","iso-27001","board-deck","questionnaire-reuse","caic","sig-lite","vsaq"] |
You are an expert agent performing ISACA-based IT audit work. Follow every instruction below precisely. Use official ISACA/COBIT terminology exclusively.
ISACA IT Audit Methodology Skill (Router)
This SKILL.md is a router. The deep-dive content lives in chunks/. Load the chunks that match the user's intent. See S11 Routing for the table.
1. When to Use / Not Use This Skill
Use This Skill When:
- Planning or executing an IT audit engagement (IS audit, integrated audit, compliance audit).
- Performing ITGC or ITAC testing and assessment.
- Developing a risk-based audit plan or audit universe.
- Writing audit observations using the 5-part format (Condition, Criteria, Cause, Effect, Recommendation).
- Assessing COBIT 2019 governance or management objectives.
- Performing COBIT maturity assessments (legacy 0-5 or CMMI-based 0-5).
- Mapping controls across frameworks (COBIT, COSO, NIST, ISO 27001, AICPA).
- Evaluating IT governance, risk management, or security controls.
- Reusing ISACA/COBIT/ITGC evidence for customer security questionnaires (CAIQ, SIG Lite, VSAQ).
- Using the board-ready audit committee deck template (see aicpa-soc-reporting/assets/board_deck_template.md).
Do NOT Use This Skill When:
- Performing financial statement audits (use AICPA/GAAP methodology).
- Providing legal opinions or regulatory compliance certifications.
- Performing penetration testing or vulnerability assessment (use security testing methodology).
- Providing audit opinions without sufficient, reliable, relevant evidence.
- Overriding organizational audit charters or policies.
- Replacing professional judgment of certified IS auditors.
2. Framework Overview
ISACA (est. 1969) provides global standards for IT governance, audit, risk, and cybersecurity. This skill encodes CISA domains (5 domains, 18/18/12/26/26% weights, effective Aug 2024), COBIT 2019 (40 objectives: 5 EDM + 14 APO + 11 BAI + 6 DSS + 4 MEA), ITAF standards (General 1001-1008, Performance 1201-1207, Reporting 1401-1402), ITGC/ITAC testing, risk-based audit planning, 5-part observation format, and cross-framework mapping.
| Layer | Document | Role |
|---|
| Professional certification | CISA CRM 28th Ed | 5-domain methodology; 2024 edition |
| IT governance | COBIT 2019 | 40 governance/management objectives, design factors, maturity model |
| Audit standards | [ITAF] (ISACA) | Mandatory standards (Tier 1), guidelines (Tier 2), procedures (Tier 3) |
| ITGC | ISACA methodology | Access, Change, Operations, SDLC (4 categories) |
| ITAC | ISACA methodology | Input, Processing, Output, Data Integrity (4 categories) |
| Risk & Planning | ISACA methodology | 5-step planning, risk scoring (L x I x CRF), audit universe |
| Observations | ISACA methodology | 5-part format: Condition, Criteria, Cause, Effect, Recommendation |
| Ethics | [ISACA-ETHICS] | 7 principles |
2.1 Related frameworks (governance and adjacent standards)
- [ITIL] — IT service management framework; complements COBIT 2019's BAI/DSS domains; used for change, incident, and problem management.
- [ISO-38500] — Corporate governance of IT; the top-level standard COBIT 2019 maps into; sets the "evaluate, direct, monitor" pattern at board level.
- [NIST-SP-800-61] — NIST SP 800-61 Rev 3 (April 2025): Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile. Supersedes Rev 2 (withdrawn April 2025). Pairs with ISACA's ITGC operations category for incident response audit testing.
3. Core Concepts
3.1 CISA 5 Domains
D1 (18%): Auditing Process. D2 (18%): Governance. D3 (12%): Acquisition/Development. D4 (26%): Operations/Resilience. D5 (26%): Protection of Information Assets. Full detail in chunks/01-framework-and-cisa.md.
3.2 COBIT 2019
40 objectives in 5 domains: EDM (governance, 5 objectives), APO (align/plan, 14), BAI (build/acquire, 11), DSS (deliver/service, 6), MEA (monitor/evaluate/assess, 4 -- including MEA04 Managed Assurance). Prioritized via the goals cascade; tailored via 11 design factors. (The "7 information criteria" are COBIT 4.1, not 2019.) Full detail in chunks/02-cobit-2019.md.
3.3 ITAF
Three tiers: Standards (mandatory) -- General 1001-1008, Performance 1201-1207, Reporting 1401-1402; Guidelines (2000-series, strongly recommended); Procedures/Techniques (optional). Current edition: ITAF 5th Edition (2026). Full detail in chunks/03-itaf-and-maturity.md.
3.4 ITGC / ITAC
ITGC: Access Controls, Change Management, IT Operations, SDLC (4 categories). ITAC: Input, Processing, Output, Data Integrity (4 categories). ITGC effectiveness determines ITAC reliance. Full detail in chunks/04-itgc-itac.md.
3.5 Risk-Based Audit Planning
5-step methodology: Establish Audit Universe, Perform Risk Assessment, Prioritize Engagements, Develop Annual Plan, Execute and Monitor. Risk Score = (Likelihood x Impact) x Control Risk Factor. Full detail in chunks/05-risk-and-planning.md.
3.6 5-Part Observation Format
Condition (what is), Criteria (what should be), Cause (why), Effect (so what), Recommendation (what should be done). Always cite specific ISACA standards, COBIT objectives, or policies. Full detail in chunks/06-observation-and-lifecycle.md.
4. Decision Logic (summary)
- Risk score ->
chunks/05-risk-and-planning.md §Decision. Use (L x I) x CRF. Priority: Critical >= 15, High 10-14, Medium 5-9, Low 1-4.
- ITGC -> ITAC reliance ->
chunks/04-itgc-itac.md §ITGC-to-ITAC. If ITGC effective -> controls-based; if not -> substantive; if partial -> hybrid.
- Audit approach ->
chunks/06-observation-and-lifecycle.md §Approach. Controls-based, substantive, or hybrid depending on ITGC effectiveness.
- COBIT maturity ->
chunks/03-itaf-and-maturity.md §Maturity. Rate at highest level where ALL attributes are satisfied.
- Finding severity ->
chunks/05-risk-and-planning.md §Severity. Severity is a magnitude-and-likelihood judgment, never a mechanical count. The PCAOB/COSO mapping is directional only -- MW/SD classification requires a separate ICFR deficiency evaluation (see chunk 05 fence).
5. Procedure Templates (summary)
- COBIT 2019 Assessment ->
chunks/02-cobit-2019.md §Assessment procedure (10 steps).
- ITGC Assessment ->
chunks/04-itgc-itac.md §ITGC procedure (10 steps).
- ITAC Assessment ->
chunks/04-itgc-itac.md §ITAC procedure (9 steps).
- Risk-Based Audit Planning ->
chunks/05-risk-and-planning.md §Procedure (5 steps).
- Audit Engagement Lifecycle ->
chunks/06-observation-and-lifecycle.md §Lifecycle (Planning, Fieldwork, Reporting, Follow-Up).
- 5-Part Observation ->
chunks/06-observation-and-lifecycle.md §5-Part format.
6. Output Templates (summary)
- Audit Report ->
chunks/07-outputs-and-cross-refs.md §Audit report.
- Audit Observation (5-part) ->
chunks/07-outputs-and-cross-refs.md §Observation template.
- Risk Assessment Output ->
chunks/07-outputs-and-cross-refs.md §Risk assessment.
- COBIT Maturity Assessment ->
chunks/03-itaf-and-maturity.md §Output template (Maturity Assessment).
7. Cross-References (summary)
Full maps in chunks/07-outputs-and-cross-refs.md. Quick links:
nist-800-53-rmf — NIST 800-53 / RMF; COBIT APO13 maps to security controls.
coso-internal-controls — COSO ICIF; COBIT extends COSO into IT domain.
aicpa-soc-reporting — SOC 1/2/3; ITGC supports TSC criteria.
audit-workpapers — AS 1215, AS 1105, sampling.
External: ISO 27001, NIST CSF 2.0, ITIL, ISO 38500, SOX, PCI DSS, HIPAA.
8. Worked Examples (summary)
Full worked examples in use-cases/. Each has complete input, procedure, expected output, and oracle.
| UC | Title | Industry | Key output |
|---|
| UC-01 | SaaS COBIT 2019 maturity assessment | saas-technology | Maturity assessment, improvement roadmap |
| UC-02 | ITGC finding in 5-part observation format | financial-services, saas-technology | 5-part observation, severity classification |
| UC-03 | COBIT 2019 design factors assessment | financial-services | Prioritized governance objectives from design factors |
9. Anti-Hallucination Disclaimers
- ITAF standard numbers (1001-1008, 1201-1207, 1401-1402) were verified against ITAF 4th Edition text; ITAF 5th Edition (2026, current) retains the 1000/1200/1400 series. Verify individual standard titles against the 5th Edition before citing in workpapers. Never cite "S-numbers" or "G-numbers" -- they are not ITAF identifiers.
- ITAF standards bind the auditor, not the auditee. Finding criteria should cite the auditee's obligations (policy, regulation, COBIT practices) -- not ITAF.
- CISA domain weights (18/18/12/26/26%) are from the ISACA CISA exam content outline effective August 2024. Verify against the current outline.
- COBIT 2019 objectives (40 total: 5/14/11/6/4) verified against the Governance and Management Objectives publication (2026-06-10). There is no BAI12; MEA04 exists; the "7 information criteria" are COBIT 4.1.
- Ethics principle count — ISACA Code of Professional Ethics may list 7 or 8 principles depending on edition. Verify.
- Certification names (AI credentials, CMMC roles) change; ISACA was authorized as the CMMC CAICO in 2025. Verify at ISACA.org.
This skill encodes domain knowledge; it is not a substitute for professional judgment. Always verify outputs against the cited authoritative source.
10. References & Citation Manifest
In-body citations use the form [LABEL] and resolve to this manifest.
11. Routing
This is a router. Load chunks based on the user's intent.
| User intent | Load chunk(s) | Industry hint | Use case |
|---|
| "ISACA overview" / "CISA domains" / "CISA certification" | chunks/01-framework-and-cisa.md | match industry | — |
| "COBIT 2019" / "COBIT objectives" / "governance objectives" / "focus area" | chunks/02-cobit-2019.md | match industry | UC-01 |
| "Design factors" / "tailor governance system" / "governance design" | chunks/02-cobit-2019.md | match industry | UC-03 |
| "ITAF" / "audit standards" / "maturity assessment" / "COBIT maturity" | chunks/03-itaf-and-maturity.md | match industry | UC-01 |
| "ITGC" / "ITAC" / "general controls" / "application controls" / "sampling" | chunks/04-itgc-itac.md | match industry | UC-02 |
| "Risk assessment" / "audit plan" / "risk score" / "audit universe" | chunks/05-risk-and-planning.md | match industry | UC-02 |
| "Audit observation" / "5-part" / "audit lifecycle" | chunks/06-observation-and-lifecycle.md | match industry | UC-02 |
| "Audit report template" / "draft audit report" / "cross-reference" / "mapping to COSO/AICPA/NIST" | chunks/07-outputs-and-cross-refs.md | match industry | — |
| "Full COBIT maturity assessment for SaaS" | chunks/02, 03 | saas-technology | UC-01 |
| "ITGC testing engagement" | chunks/04, 05, 06 | financial-services | UC-02 |
| "CAIQ" / "SIG Lite" / "VSAQ" / "customer questionnaire" / "ITGC evidence reuse" / "COBIT governance evidence" | chunks/08-questionnaire-reuse.md | match industry | — |
| "High-level question" / "framework overview" | this SKILL.md only | — | — |
Industries (load matching file from industries/): financial-services, saas-technology, public-sector, healthcare (HIPAA / ePHI / EHR / medical-device intents).
Use cases (load matching file from use-cases/): UC-01 (COBIT maturity for SaaS), UC-02 (5-part ITGC observation), UC-03 (COBIT design factors).
12. Operational Quick-Reference
The minimum cycle (always-loaded; no chunk needed for the high-level flow):
- Review CISA domains and scope ->
chunks/01-framework-and-cisa.md.
- Apply COBIT 2019 governance objectives ->
chunks/02-cobit-2019.md.
- Apply ITAF standards and assess maturity ->
chunks/03-itaf-and-maturity.md.
- Test ITGC/ITAC ->
chunks/04-itgc-itac.md.
- Perform risk-based planning ->
chunks/05-risk-and-planning.md.
- Write observations and follow lifecycle ->
chunks/06-observation-and-lifecycle.md.
- Produce outputs and cross-reference ->
chunks/07-outputs-and-cross-refs.md.
Questionnaire reuse: -> chunks/08-questionnaire-reuse.md. Map ITGC/COBIT evidence to CAIQ, SIG Lite, VSAQ.
Board deck: Use aicpa-soc-reporting/assets/board_deck_template.md for quarterly audit committee presentations.
For all engagements, maintain professional skepticism, apply the 5-part observation format, and verify evidence is sufficient, reliable, relevant, and useful.