Your learning
Complete IT Audit Lab 4 – Governance & Framework Mapping
Open Lab 4 on the same AkwaabaPay engagement, map Lab 3 procedures to primary and supporting criteria, submit the Criteria / Framework Mapping, and complete the debrief.
Before you begin
- You have finished Lab 3: submitted the Audit Programme and Evidence Request List and saved the debrief.
- The IT Audit Practical Laboratory is still attached and enabled on your Course Offering.
Open Lab 4
- Open My Learning and the Course Offering Learning Experience.
- Open Laboratories and launch IT Audit Practical Laboratory.
- On the hub, open Practical Audit Lab 4 – Governance & Framework Mapping.
- Select Start Lab 4 (or Continue Lab 4).
Lab 4 uses the same AkwaabaPay engagement file. You do not re-type Lab 1 risks, Lab 2 controls, or Lab 3 procedures.
Work the engagement
Use the Audit file menu:
- Briefing — without criteria, an observation is only an opinion. Read the primary versus supporting distinction and the privileged-access worked example.
- Labs 1–3 input — your risk register, RCM, and audit programme.
- Reference pack — REF-4.01 to REF-4.08. Some extracts are highly relevant, some overlap, and some look relevant by keyword but are not the best fit.
- Select procedures — choose at least six Lab 3 procedures to map.
- Criteria mapping — for each selected procedure, confirm the control objective, choose one primary criterion, add supporting criteria only where they help, rate relevance, and write a justification.
- Governance — map the overdue Audit Committee actions (or another governance item). Lab 4 sets the criterion only; testing is Lab 5.
- ISO assertion — respond to management’s claim that ISO 27001 alignment makes access controls adequate.
- Coverage — check procedures with no primary criterion and the framework matrix.
- Submit — submit the Criteria / Framework Mapping.
- Debrief — answer every “Defend your criteria” question.
What “good enough” looks like
- At least six procedures mapped, each with a primary criterion and a written justification.
- At least two mappings use an internal policy or standard as the primary criterion.
- COBIT, ISO/IEC 27001, or NIST is used where it is relevant — not pasted onto every row.
- One governance mapping is complete.
- You could defend the Criteria element of a later finding using this mapping.
Internal policy is often more direct than a framework clause. More frameworks do not automatically make the conclusion stronger.