<p>As organizations begin to transition services to the cloud, there is a need for ongoing assurances from both cloud customers and cloud service providers that controls are put in place and are operating as intended. The internal audit function can also play a “trusted” advisor role and proactively be involved by working with IT and the business in identifying and addressing the risk associated with the various cloud services and deployment models.</p>



<p>An organization’s internal audit can provide visibility into:</p>



<ul class="wp-block-list"><li>The cloud program’s effectiveness</li><li>Assurance to the board and risk management team on the organization’s cloud risk exposure</li><li>If the business practices are helping the business manage the risk and meet its strategic objectives</li></ul>



<p>External audits are typically provided by an external company that has an association of registered auditors. External audits typically:</p>



<ul class="wp-block-list"><li>Provide assurance that legal, regulatory, or contractual requirements are being met</li><li>Occur annually unless otherwise specified</li><li>Provide assurance to parties consuming services that the provider has and is maintaining required controls</li></ul>



<p>In line with financial, compliance, regulatory, and other risk-related audits, the requirement for scoping and ensuring the appropriate focus and emphasis on components most relevant to cloud computing (and associated outsourcing) should include the following phases:</p>



<figure class="wp-block-image size-large is-resized"><img src="https://www.thecloudxperts.co.uk/wp-content/uploads/2022/09/image-1024x239.png" alt="" class="wp-image-823" width="880" height="205"/></figure>



<p>Ensure the audit has a clear <strong>objective </strong>and well-defined <strong>scope</strong>. </p>



<ul class="wp-block-list"><li>Document list of current services/resources utilized from cloud service provider(s)</li><li>Define key components of services (storage, utilization, processing, etc.)</li><li>Define cloud services to be audited (IaaS, PaaS, SaaS)</li><li>Define geographic locations permitted/required</li><li>Define locations for audits to be undertaken</li><li>Define key stages to audit (information gathering, workshops, gap analysis, verification evidence, etc.)</li><li>Document key points of contact within cloud service provider and internal to organization</li><li>Define escalation and communication points</li><li>Define criteria and metrics by which the cloud service provider will be assessed</li><li>Ensure criteria is consistent with the SLA and contract</li><li>Factor in “busy periods” or organizational periods (financial year end, launches, new services, etc.)</li><li>Ensure findings captured in previous reports or stated by the cloud service provider are actioned/verified</li><li>Ensure previous nonconformities/high-risk items are reassessed/verified as part of the audit process</li><li>Ensure any internal operational or business changes have been captured as part of the audit plan (reporting changes, governance, etc.)</li><li>Agree on final reporting dates (conscious of business operations and operational availability)</li><li>Ensure findings are captured and communicated back to relevant business stakeholders/executives</li><li>Confirm report circulation/target audience</li><li>Document risk management/risk treatment processes to be utilized as part of any remediation plans</li><li>Agree on an auditable process for remediation actions (ensuring traceability and accountability)</li></ul>

