The course materials combine international standards with the Vietnamese business context; the instructor’s experience and supporting toolkits help improve practical management effectiveness.”
Internal IT Audit
Develop capabilities in audit planning, risk assessment, audit procedures, evidence collection, reporting findings, and following up corrective actions in IT environments.
Course Contents
1Course Overview
Are the organization’s IT systems secure and available when required? Could corporate data and information be disclosed without authorization? Is information produced by IT systems accurate, reliable, and timely? These critical information security concerns are examined in detail by the IT Internal Auditor. IT auditing evaluates the design and effectiveness of internal IT controls, including security protocols, development processes, monitoring, and IT governance. Implementing IT controls is essential, but controls alone do not guarantee adequate security.
Those responsible for security must periodically review implemented controls to determine whether they are operating effectively and, when a security breach occurs, ensure prompt action is taken to prevent recurrence. These requirements should be independently examined and reported by objective assessors performing the role of IT Internal Auditor.
Infochief’s "Internal IT Audit" course is built around enterprise information security and control assessment standards. The course is designed for auditors, IT managers, project managers, consultants, information security personnel, risk managers, IT procurement professionals, and executives. Participants should have experience working with at least one major IT system in development, operations management, or IT procurement.
2Training Objectives
- Apply recognized knowledge and methods for conducting IT audits based on international practices.
- Organize and implement internal IT audit activities in line with international best practices.
- Understand audit roles, establish an audit team, and propose audit activities within the organization.
- Define an appropriate IT audit scope.
- Schedule meetings with management to understand IT processes and policies.
- Develop effective interview questions for reviewing processes and IT system management controls.
- Identify risks to IT assets and recommend remediation steps to mitigate those risks.
- Determine audit priorities and the time required to complete each IT audit assignment.
- Comply with IT audit standards established by the organization’s audit function.
- Ensure previous IT audit recommendations are addressed and implemented.
- Develop IT audit reports that present findings and recommendations for risk management.
- Maintain clear and complete IT audit documentation.
3Target Participants
4Course Content
PART 01.THE ROLE OF INTERNAL IT AUDIT
- What is IT Audit?
- Roles and Responsibilities of an IT Auditor
- Professional Ethics for IT Auditors
- The IT Function’s Perspective on Internal IT Audit
- IT Audit Quality Standards
- Keys to Successful IT Auditing
PART 02.IT TECHNICAL, MANAGEMENT & GOVERNANCE KNOWLEDGE
- IT Systems Architecture
- Audit Process
- IT Governance
- IT Investment and Systems Development Lifecycle
- IT Services, Operations & System Maintenance
- Information Asset Protection
- Disaster Recovery & Business Continuity
PART 03.RISK IDENTIFICATION
- IT Asset Risks
- IT Workforce Risks
- Physical and Environmental Risks
- Operational Process Risks
- Access Risks
- IT Incident Risks
- Continuity and Contingency Risks
PART 04.IT RISK ASSESSMENT PROCESS
- What are risks in IT systems?
- What are IT system threats and vulnerabilities?
- Risk Treatment Measures
- IT Risk Management Procedures
- Inventory IT assets and current risk status
- Determine the impact scope of assets
- Analyze the likelihood of incidents
- Calculate IT risk levels
- Agree on IT risk treatment approaches
- Assign accountable owners
PART 05.IT AUDIT PROCEDURES
- Develop an IT Audit Plan
- Assess IT Risks
- Conduct the IT Audit
- IT Review and Assessment Methods
- Questioning Techniques in IT Audits
- Data Collection and Sampling Methods
- Techniques for Identifying Risk Evidence and Analyzing Impact
- Evidence Classification (poor / good / excellent)
- Audit Report Writing and Follow-up
- Presenting IT Audit Results
- Sample IT Audit Questionnaire
PART 06.IT AUDIT PRACTICE
- Audit Computers & Peripheral Devices
- Audit Servers
- Audit Internal and External Networks
- Audit Data Storage Operations
- Audit Database Management
- Audit Information Security
- Audit IT Change Management
- Audit IT Service Level Agreements (SLA)
- Audit IT Workforce Management
5Training Methodology
30% theory – 70% practice. The instructor presents the knowledge framework concisely, followed by discussions, case studies, self-assessments, scenario-based exercises, and action planning to strengthen workplace application.








6Class Information & Enrollment
Upcoming Public Training Schedule
| Expected Start Date | Schedule | Class Hours | Location | Tuition Fee | Early-bird Fee | Enroll |
|---|---|---|---|---|---|---|
| --/--/---- | Saturday – Sunday | 08:30 – 16:30 | Ho Chi Minh City | 8.500.000 VND | 7.500.000 VND | Enroll |
| --/--/---- | Monday – Friday | 18:00 – 21:30 | Hanoi | 8.500.000 VND | 7.500.000 VND | Enroll |
Total Training Duration: 3 days / 6 sessions.
In-house Training
| Duration | Class Size | Tuition Fee |
|---|---|---|
| 3 days / 6 sessions. | Up to 25 learners per class. | VND 58,500,000 per class delivered at the company’s office. |
Additional Costs (if applicable): Depending on the training location, instructor travel and accommodation costs may be charged separately.
Post-course Service: Practical Internal IT Audit consulting after the course. 1. Benefits: - Practice auditing IT systems directly within your organization. - Receive detailed guidance and direct consultation from an expert. - Improve audit effectiveness and quality. 2. Duration: 2 days / 4 sessions. 3. Service fee: VND 48,500,000.
Request In-house Consultation →7Learning Materials & Certification
Vietnamese course materials for each module, English reference materials, and sample practical exercises.
Forms, Checklists, Templates, Scorecards, Procedures, Flowcharts, Guidance, Samples, Rules, Policies, Questionnaires, Assessments, and Comparison Charts.
Explore the Toolkits →
Internal IT Audit
Learners who complete the full program and all end-of-course requirements will receive an “Internal IT Audit” certificate from Infochief Academy.
Certification Information →8Learner Testimonials
The systematic management content, together with toolkits, processes, and templates, gives learners a stronger foundation for implementing IT plans professionally.”
The modules closely reflect the needs of IT managers; discussions, real-world scenarios, and the final project strengthen practical application.”

The course helps systematize existing knowledge and adds practical lessons that are useful for day-to-day IT management.”
9Featured Clients
Completion of the Internal IT Audit course delivered at MobiFone Corporation, Hanoi.
Internal IT Audit training delivered for Bao Viet Securities Company (BVSC).
Completion of the Information Security Management course delivered at Axis Vietnam, Ho Chi Minh City.
Completion of the ITIL 4 Foundation course delivered at BVIS International School, Hanoi.
Completion of the IT Manager course for IT department managers, delivered as a Public program in Ho Chi Minh City.
Completion of the IT Management and Operations course delivered at Cam Ranh International Terminal JSC, Cam Ranh City.