CORAA

Cybersecurity Internal Audit Checklist

Broader than ITGC — vulnerability management, incident response readiness, security awareness and third-party access, alongside the financial-reporting-relevant IT controls ITGC already covers.

Free · CORAA original — SA-aligned
Updated 28 Jul 2026
Scope
Beyond ITGC — vulnerability mgmt, incident response, awareness
Key test
Patch SLA adherence on internet-facing systems
Common gap
Incident response plan exists but was never actually drilled
Format
Microsoft Word (.docx)
Share this template
Your firm — letterhead
Appears at the top of the document as the audit firm letterhead.
Used as the letterhead block.
Engagement details
The client and period this document is for.
What’s inside

An excerpt from the template.

CYBERSECURITY INTERNAL AUDIT CHECKLIST

Entity: ___ · Period: ___

Scope: the entity's cybersecurity posture beyond the financial-reporting-relevant IT General Controls already tested separately (see the ITGC checklist for access management, change management and segregation of duties within financially relevant systems) — vulnerability management, incident response readiness, security awareness, and third-party/vendor network access.

Risk & Control Matrix

↑ Excerpt only — the full template is what you download as Word
About this template

What you’re downloading, and when to use it.

This template follows the format published by the Institute of Chartered Accountants of India (ICAI) in the AASB Audit Working Paper Templates (June 2023), the authoritative reference for Indian statutory-audit documentation. Fill in your firm’s letterhead and the engagement details on the form above, click Download Word file, and you’ll get a fully formatted .docx ready to use.

Everything is generated in your browser and on a stateless API endpoint — no account, nothing stored on our servers. We’ll ask for a work email once before your first download so we can send you the file and the occasional relevant update; after that, downloads on this device are instant. Edit freely in Word, Google Docs or Pages before sending to your client.

Common questions

FAQs.

How is this different from the ITGC checklist?
ITGC (IT General Controls) focuses specifically on the IT controls relevant to financial reporting accuracy — access management, change management and segregation of duties within financially significant systems, framed for an ICFR/Sec 143(3)(i) conclusion. This checklist is broader operational cybersecurity — vulnerability management, incident response, security awareness and third-party access — relevant to overall security risk, not just financial-statement risk. Many entities need both; they test different things.
Does a written incident response plan satisfy this checklist?
Not on its own. A plan that has never been tested through an actual drill or tabletop exercise carries materially higher risk than one with evidence of a recent, real test — similar to the BCP/DR distinction between a plan existing and a plan actually working when invoked. Look for drill records, not just the policy document.
Is this checklist a substitute for a technical penetration test?
No. This is a controls-and-process checklist an internal auditor can complete through inquiry, observation and document review — it is not a technical vulnerability assessment or penetration test, which requires specialist tooling and expertise. Where the entity has never had one performed, that itself is worth noting as a finding.
Related templates

You might also need.

IT General Controls (ITGC) Checklist
Free IT General Controls (ITGC) checklist for internal audit. Access management, change management, SoD, backu
Third-Party / Outsourcing Risk Audit Checklist
Free third-party and outsourcing risk internal audit checklist. Vendor risk tiering, SLA monitoring, sub-outso
Business Continuity & Disaster Recovery (BCP/DR) Audit Checklist
Free BCP/DR internal audit checklist. Tests RTO/RPO, backup verification, DR drill documentation. Editable Wor