Skip to content
Technology & Risk

IT Audit Checklist: What Boards Should Ask About Financial Systems and Cyber Risk

As finance and operations become more digital, boards need assurance that system access, backups, changes and cyber controls protect the integrity and availability of business information.
As finance and operations become more digital, boards need assurance that system access, backups, changes and cyber controls protect the integrity and availability of business information.

As finance and operations become more digital, boards need assurance that system access, backups, changes and cyber controls protect the integrity and availability of business information.

Access and identity

Review privileged accounts, dormant users, shared credentials and the process for joiners, movers and leavers. Multi-factor authentication should be considered for important systems where supported.

Segregation of duties matters in systems too: users should not have conflicting capabilities without compensating review controls.

Backups, recovery and resilience

Define what data must be backed up, how frequently and how long it is retained. Keep appropriate protection from ransomware and periodically test whether systems can actually be restored within business requirements.

Change and vendor risk

Control changes to financial systems, integrations and configurations. Understand which third parties host or process important information and what would happen if a key provider became unavailable.

How AS Chartered Accountants can help

Good financial governance is easier when accounting, tax, assurance and advisory work from the same reliable information. AS Chartered Accountants provides partner-led support designed around the realities of operating in Zimbabwe. Explore IT Audit & Cyber Security and Audit & Assurance.

Contact AS Chartered Accountants to discuss your organisation’s requirements and the scope of support that may be appropriate.

Key takeaways

  • Know who has privileged access to critical systems.
  • Test backup restoration rather than assuming backups work.
  • Connect cyber risk to financial reporting and business continuity.

Need help applying this?

Discuss the practical implications with ASCA.

We can help translate these issues into decisions, controls and reporting improvements tailored to your organisation.

More insights

Related articles

Continue exploring topics relevant to finance teams and business leaders.

Statutory Audit in Zimbabwe: A Practical Readiness Guide
Audit & Assurance

Statutory Audit in Zimbabwe: A Practical Readiness Guide

5 min read

Preparing early for a statutory audit can reduce disruption, improve evidence quality and turn the engagement into a useful review of financial reporting and controls.

Read article
Internal Audit vs External Audit: What Zimbabwean Businesses Should Know
Audit & Assurance

Internal Audit vs External Audit: What Zimbabwean Businesses Should Know

5 min read

Internal and external audit serve different purposes. Understanding the distinction helps boards and management use each form of assurance more effectively.

Read article
Grant and Donor-Funded Project Audits: How NGOs Can Stay Audit-Ready
Audit & Assurance

Grant and Donor-Funded Project Audits: How NGOs Can Stay Audit-Ready

5 min read

NGOs and grant-funded programmes need financial records that satisfy both organisational controls and the specific accountability requirements attached to donor funding.

Read article