Your learning

Complete IT Audit Lab 4 – Governance & Framework Mapping

Open Lab 4 on the same AkwaabaPay engagement, map Lab 3 procedures to primary and supporting criteria, submit the Criteria / Framework Mapping, and complete the debrief.

Last reviewed: 28 August 2026

Before you begin

  • You have finished Lab 3: submitted the Audit Programme and Evidence Request List and saved the debrief.
  • The IT Audit Practical Laboratory is still attached and enabled on your Course Offering.

Open Lab 4

  1. Open My Learning and the Course Offering Learning Experience.
  2. Open Laboratories and launch IT Audit Practical Laboratory.
  3. On the hub, open Practical Audit Lab 4 – Governance & Framework Mapping.
  4. Select Start Lab 4 (or Continue Lab 4).

Lab 4 uses the same AkwaabaPay engagement file. You do not re-type Lab 1 risks, Lab 2 controls, or Lab 3 procedures.

Work the engagement

Use the Audit file menu:

  1. Briefing — without criteria, an observation is only an opinion. Read the primary versus supporting distinction and the privileged-access worked example.
  2. Labs 1–3 input — your risk register, RCM, and audit programme.
  3. Reference pack — REF-4.01 to REF-4.08. Some extracts are highly relevant, some overlap, and some look relevant by keyword but are not the best fit.
  4. Select procedures — choose at least six Lab 3 procedures to map.
  5. Criteria mapping — for each selected procedure, confirm the control objective, choose one primary criterion, add supporting criteria only where they help, rate relevance, and write a justification.
  6. Governance — map the overdue Audit Committee actions (or another governance item). Lab 4 sets the criterion only; testing is Lab 5.
  7. ISO assertion — respond to management’s claim that ISO 27001 alignment makes access controls adequate.
  8. Coverage — check procedures with no primary criterion and the framework matrix.
  9. Submit — submit the Criteria / Framework Mapping.
  10. Debrief — answer every “Defend your criteria” question.

What “good enough” looks like

  • At least six procedures mapped, each with a primary criterion and a written justification.
  • At least two mappings use an internal policy or standard as the primary criterion.
  • COBIT, ISO/IEC 27001, or NIST is used where it is relevant — not pasted onto every row.
  • One governance mapping is complete.
  • You could defend the Criteria element of a later finding using this mapping.

Internal policy is often more direct than a framework clause. More frameworks do not automatically make the conclusion stronger.