Your learning

Complete IT Audit Lab 1 – IT Risk Assessment

Open the IT Audit Laboratory from Learning Experience, inspect the AkwaabaPay evidence pack, build an IT Risk Register, submit it, and complete the debrief.

Last reviewed: 28 August 2026

Before you begin

  • Your institution has enabled Domain Laboratories.
  • You have an active enrolment on the Course Offering.
  • Teaching staff have attached and enabled the IT Audit Practical Laboratory for your offering.

Open the laboratory

  1. Open My Learning and enter the Course Offering Learning Experience.
  2. Open Laboratories.
  3. Select Launch (or Continue) for IT Audit Practical Laboratory.
  4. You stay inside Learning Experience. The hub shows the AkwaabaPay engagement and the six-lab path.

Start Lab 1

  1. On the laboratory hub, open Practical Audit Lab 1 – IT Risk Assessment.
  2. Select Start Lab 1 (or Continue Lab 1 if you already started).
  3. Use the Audit file menu: Briefing, Evidence, Information gaps, Risk register, Risk matrix, Submit, Debrief.

Work the engagement

  1. Read the Briefing so you understand AkwaabaPay, its systems, and current pressures.
  2. Inspect all eight Evidence items (EVD-01 to EVD-08). Some items are incomplete, old, or conflict with management interview notes. That is intentional. A management claim is not audit evidence.
  3. Record Information gaps — what is missing, why it matters, what you would request, and from whom.
  4. Add at least eight risks to the Risk register. For each risk:
    • Name a specific asset or data set (not “IT Department”).
    • State threat, vulnerability, and a business impact.
    • Write the risk as cause/event → business consequence.
    • Record existing controls only when the pack supports them, and attach evidence references.
    • Rate inherent likelihood and impact (the matrix calculates the inherent rating).
    • Rate residual risk. If you reduce the rating, name the control and explain why.
    • Assign a unique audit priority. High residual risk is not automatically Priority 1.
  5. Check the Risk matrix. Click a plotted risk to review it.
  6. Open Submit. Fix any blockers (missing fields, unexplained residual reduction, duplicate priorities, control without evidence, vulnerability-only statements).
  7. Submit the AkwaabaPay IT Risk Register.
  8. Answer all six Debrief questions and save to complete Lab 1.

After Lab 1

Your risks stay on the same audit engagement file. Later labs reuse them. Teaching staff can review, comment, score, or reopen the register.

There is no single correct risk register. Different teams can produce different defensible registers.