SIA 520 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Most of a company's accounting, billing and payroll now run on software, and much of that software is hosted, supported or operated by outside providers. SIA 520 tells the internal auditor how to audit IT systems the company manages; SIA 530 covers systems and processes that sit with a third party. For finance heads, these are the standards behind the questions the internal auditor asks about access, backups and vendor contracts.
This article is from the ICAI Compendium of Standards on Internal Audit (as on 1 October 2022). Both standards apply to internal audits beginning on or after a date to be notified by the Council. Under paragraph 5.1 of the Preface the Council decided to make the SIAs mandatory in a phased manner. Check the current versions on the ICAI internal audit board's site, internalaudit.icai.org.
The objectives of an internal audit do not change in an IT environment, but the risks and controls do (SIA 520, paragraph 1.3). The auditor starts with an independent IT risk assessment, tests design, implementation and operating effectiveness of IT controls, and documents the work under SIA 330. Where systems sit with a vendor, SIA 530 requires the auditor to review the company's due diligence, risk assessment and monitoring of that vendor and, where permitted, to audit the vendor or evaluate its assurance report.
SIA 520: internal audit in an IT environment
An information technology environment exists when information is captured, stored and processed by automated means under policies and procedures, and has two main components: IT infrastructure (hardware, architecture, operating systems, network, storage) and application software and data, such as ERP, customer relationship, e-commerce and robotic process automation (paragraph 1.2). The standard applies where the company manages its own IT systems (paragraph 1.4). Its aim is to evaluate the organisation's IT risks and whether IT-related controls suffice for business objectives (paragraph 1.3). Areas of assurance include security and reliability of information, efficiency of processing, reporting, continuous availability and compliance with IT-related laws (paragraph 2.1).
| Requirement | What the auditor does | Paragraph |
|---|---|---|
| Understand and assess risk | Learn business operations and the IT environment; make an independent IT risk assessment and identify the controls needed before starting IT audit work | 3.1, 4.1 |
| Skills | Have or acquire the qualifications and experience; specialised skills in IT governance, application controls, infrastructure, cyber security and data privacy are called essential | 3.2, 4.2 |
| Scope | Assess the environment to define scope and relevant controls; the level of risk drives nature, extent and timing | 3.3, 4.3 |
| Plan | Documented understanding, risk assessment, approach, project plan, skills and team | 3.4, 4.4 |
| Execute | Test design, implementation and operating effectiveness of relevant IT controls; identify gaps, deficiencies and violations of procedures or laws | 3.5, 4.5 |
| Document | Environment, scope, risk assessment, planning, testing and reporting, under SIA 330 | 3.6, 4.6 |
| Report | Share outcome with process owners, agree action plans, document the basis of the conclusion | 3.7, 4.7 |
The explanatory comments give practical detail. Execution involves interviews, review of documents and of system configuration and settings, inspection of systems, data and reports, use of data analytics and physical walkthroughs, with evidence that is sufficient, appropriate, reliable and consistent (paragraph 4.5). The documentation includes an IT risk and controls matrix, IT test work papers and system-generated reports with supporting documents (paragraph 4.6). Before concluding on a control test the auditor considers additional evidence or mitigating measures offered by the auditee, may look into the root cause and the impact on financials, and discusses the final deficiencies with executive management (paragraph 4.7). On skills, paragraph 4.2 names the Diploma in Systems Audit or an equivalent qualification as a way to build knowledge, and notes the credentials can be acquired externally and made available for the audit. The standard's annexures give an illustrative list of audit areas and a checklist of IT controls, which are not reproduced here.
What an internal auditor may ask your IT and finance teams
Our own illustration of typical requests, not a list from the standard: the list of applications and who administers them; user access lists with join, move and exit dates; evidence that backups are taken and restored; change and release records; system-generated reports used for accounting; and the interfaces between systems. For the statutory audit view of the same topic, see our article on audit in an IT environment. Businesses preparing their systems for such a review can ask our compliance advisory team for a readiness check.
SIA 530: third party service providers
SIA 530 deals with risks where parts of the entity's operations, processes and information sit with outside providers, to whom a function or processing is outsourced (paragraph 1.1). These risks touch processing, financial and operational management, information security, legal compliance and business continuity (paragraph 1.2). How much the internal auditor must do depends on the importance of the outsourced process and on whether the provider gives its customers a third party audit and assurance report (TPAA report) (paragraph 1.3). The standard applies both to the providers and to their user entities (paragraph 1.4).
| Requirement | What the auditor does | Paragraph |
|---|---|---|
| Governance of outsourcing | Study the scope of the provider's services and the user's governance and oversight of outsourcing, especially access to critical information | 3.1, 4.1 |
| Due diligence | Review pre-engagement and post-engagement due diligence by the user, including a control assessment of controls retained and outsourced; recommend one where management has not done it | 3.2, 4.2 |
| Risk assessment | Management assesses each arrangement periodically; the auditor reviews it | 3.3, 4.3 |
| Audit of the provider | Where permissible, audit the provider's entity-level, IT and process controls and the user's monitoring of service levels | 3.4, 4.4 |
| Assurance reports | If no audit of the provider is done, evaluate the TPAA report as work of an expert under SIA 240 | 3.5, 4.5 |
Paragraph 4.1 lists signs of sound oversight: a database of all third party arrangements with business owners, categorisation by criticality and risk, objective selection, documented contract terms including those after termination, service level agreements that are measured and monitored, controls over the user's information, and the right to audit or to receive assurance reports. Paragraph 4.3 gives the example of a call centre that handles no financial transactions yet holds a customer database, and so carries a data-breach risk; it also asks that the contract permit the internal auditor to perform the risk assessment and procedures at reasonable frequency. The standard also asks the auditor to review the controls the user keeps in-house when judging the overall control position (paragraph 4.5).
How this pairs with other standards: SIA 530 points to SIA 520 for IT reviews of the provider and to SIA 240 for evaluating a TPAA report. The assurance report a provider's auditor issues is the subject of our article on SAE 3402 type 1 and type 2 reports, and the statutory auditor's side is in our SA 402 guide.
Illustrative example
Illustrative: Nimbus Retail Ltd runs an ERP in-house and outsources payroll processing to a vendor. For the ERP, the internal auditor lists applications and the data flow, rates user access and change management as high risk, then tests whether new users receive approved access, whether a sample of leavers' accounts were disabled and whether program changes were approved before release. Two leaver accounts were active months after exit; the auditor traces the cause, discusses it with the IT head and records the agreed fix. For the payroll vendor, the auditor finds that the company never performed due diligence and has no right-to-audit clause. SIA 530 paragraph 4.2 therefore leads to a recommendation to do due diligence now, and the auditor evaluates the vendor's service auditor report, noting which controls remain with Nimbus's own HR team.
Common lapses
- Treating an IT audit as a review of policies with no testing of access and change logs.
- No IT risk assessment before choosing the tests.
- Accepting a vendor's assurance report without checking its scope and the controls the user retains.
- Contracts with vendors that give no right to audit or to receive assurance reports.
- Skills gaps filled by an expert whose independence was never checked.
Need help preparing for an IT or vendor review?
If you want your IT controls and vendor arrangements reviewed before an internal audit, our team can help through compliance advisory, including contract terms and service level monitoring.
Key takeaways
- An IT audit starts with an independent IT risk assessment and a documented understanding of the environment (SIA 520, paragraphs 3.1 and 3.4).
- The auditor tests design, implementation and operating effectiveness of relevant IT controls (SIA 520, paragraph 3.5).
- For outsourced processes, the auditor reviews due diligence, risk assessment and monitoring of the provider (SIA 530, paragraphs 3.2 to 3.4).
- A provider's assurance report is evaluated as the work of an expert (SIA 530, paragraph 3.5).
- Contracts should allow the right to audit and to receive assurance reports (SIA 530, paragraphs 4.1 and 4.3).
Read next
- SAE 3402: assurance reports on controls at a service organisation
- Audit in an IT environment
- Data analysis and digital evidence in forensic work
- SA 402: audit considerations for an entity using a service organisation
Disclaimer: Based on the Standards on Auditing, the review, assurance and related services standards, the Compendium of Standards on Internal Audit (as on 1 October 2022) and the Compendium of Forensic Accounting and Investigation Standards (as on September 2025) issued by the Institute of Chartered Accountants of India, in the versions named in the article, as consulted on 4 October 2026. ICAI revises standards from time to time; check the current text and effective dates on icai.org and the Companies Act provisions referred to. This article is general information, not legal advice; check the official text before acting.
