Your learning
Complete IT Audit Lab 2 – GITCs & Application Controls
Open Lab 2 on the same AkwaabaPay engagement, evaluate controls against your Lab 1 risks, build a Risk and Control Matrix, submit it, and complete the debrief.
Before you begin
- You have finished Lab 1: submitted the IT Risk Register and saved the debrief.
- The IT Audit Practical Laboratory is still attached and enabled on your Course Offering.
Open Lab 2
- Open My Learning and the Course Offering Learning Experience.
- Open Laboratories and launch IT Audit Practical Laboratory.
- On the hub, open Practical Audit Lab 2 – GITCs & Application Controls.
- Select Start Lab 2 (or Continue Lab 2).
Lab 2 uses the same AkwaabaPay engagement file. You do not re-type Lab 1 risks.
Work the engagement
Use the Audit file menu:
- Briefing — management assertion is not control reliance.
- Lab 1 input — your risk register, ratings, and assumed controls.
- Evidence — Lab 1 items stay available. Lab 2 adds policy, access, change, backup, settlement, and vendor records (EVD-09 to EVD-19). Some policy wording is stronger than the extracts. That is intentional.
- Select risks — choose at least six. Prefer the highest Lab 1 priorities. If you pick a lower-priority risk, record why.
- Risk & Control Matrix — for each selected risk, add a control objective and one or more controls. Classify GITC vs application, timing, and operation model. Assess design and implementation. Leave operating effectiveness as Not yet tested unless you have a preliminary concern and evidence.
- Information gaps — record what you still need before you can rely on a control.
- Control reconciliation — confirm, partially confirm, or reject the controls you assumed in Lab 1. If residual risk no longer holds, restate it. The Lab 1 rating stays on the file.
- Submit the Risk and Control Matrix, then complete the eight debrief questions.
After Lab 2
Your RCM stays on the engagement file for Lab 3 (audit programme). There is no single correct matrix. Lecturers score whether your conclusions are defensible against the evidence.