CORAA
Resources - IT Services Internal Audit

IT services and SaaS internal audit checklist.

IT services audit quality depends on connecting contract evidence, delivery evidence, system evidence and finance evidence. The file should tie subscription masters, project milestones, timesheets, cloud spend, access logs, deployment controls, export documents and GST return mapping into one RCM.

Build SaaS audit workbookOpen ITGC checklist
RCM map

Nine areas to test areas

Subscription revenue, billing and contract changes

Risk: MRR/ARR, licence counts, upgrades, downgrades, credits or renewals are billed or recognised from incomplete contract and usage evidence.

Controls
  • Approved contract master
  • Plan and price change workflow
  • Usage-to-billing reconciliation
  • Credit note approval
Tests
  • Trace sampled customers from order form to subscription master and invoice
  • Recompute upgrades, downgrades, discounts and credits
  • Review manual invoice overrides
  • Test cut-off around activation, renewal and cancellation
Evidence

Order form, MSA, subscription master, usage report, invoice, credit note, approval ticket and collection proof.

Project delivery, milestones and timesheets

Risk: Fixed-fee, T&M or milestone revenue is billed without delivery acceptance, time evidence or contract milestone support.

Controls
  • Project code setup
  • Milestone acceptance control
  • Timesheet approval
  • Revenue cut-off review
Tests
  • Match project invoice to SOW, milestone sign-off and delivery evidence
  • Review unbilled revenue and deferred revenue
  • Test timesheet approvals and rate cards
  • Analyse old WIP and overruns
Evidence

MSA/SOW, project plan, milestone acceptance, timesheet, rate card, invoice, WIP report and deferred revenue working.

Customer onboarding, KYC and collections

Risk: Customers are onboarded, provisioned or extended credit without approval, contract checks, tax setup or receivable follow-up.

Controls
  • Customer master approval
  • Contract/legal review
  • Credit terms approval
  • Collection ageing review
Tests
  • Review new customer setup and contract approvals
  • Sample tax/customer master fields
  • Age receivables and unallocated collections
  • Test write-offs and service suspensions
Evidence

Customer master, contract approval, tax setup, credit approval, ageing, collection proof, write-off note and suspension log.

Cloud infrastructure, tooling and vendor spend

Risk: Cloud, SaaS tools, APIs, licences or contractors are procured and consumed without approval, allocation, renewal review or unused-spend controls.

Controls
  • Cloud budget and tagging
  • Vendor onboarding
  • Renewal calendar
  • Usage and idle-resource review
Tests
  • Reconcile cloud invoices to usage tags and approvals
  • Review idle resources and unusual spend spikes
  • Test tool licence leavers
  • Review vendor renewal and rate-card changes
Evidence

Cloud invoice, usage export, tag report, budget approval, vendor master, contract, renewal tracker and access list.

Engineering change, release and incident controls

Risk: Production changes, hotfixes, deployments or incidents bypass approval, testing, rollback and incident closure evidence.

Controls
  • Change ticket workflow
  • Code review and CI/CD approval
  • Release checklist
  • Incident post-mortem
Tests
  • Sample deployments to tickets, approvals and test evidence
  • Review emergency changes and rollback evidence
  • Trace incidents to root cause and closure
  • Check segregation between developer and production access
Evidence

Change ticket, pull request, CI/CD log, test result, release note, incident ticket, rollback log and access matrix.

Logical access, privileged users and data security

Risk: Employees, contractors, vendors or bots retain excessive access to source code, production, customer data, finance systems or cloud consoles.

Controls
  • Role-based access
  • Joiner-mover-leaver control
  • Privileged access review
  • Audit-log monitoring
Tests
  • Match user access to HR/vendor list and role matrix
  • Review leaver and contractor access
  • Sample admin activity logs
  • Test MFA, shared IDs and service accounts
Evidence

User list, HR/vendor list, role matrix, leaver report, admin log, MFA report, service account inventory and access review sign-off.

GST export, LUT, SEZ/STPI and forex evidence

Risk: Export invoices, LUT, place-of-supply, SEZ/STPI records, Softex support or forex realisation evidence are incomplete or inconsistent.

Controls
  • Export invoice review
  • LUT tracker
  • Softex/STPI or SEZ file
  • FIRC/BRC reconciliation
Tests
  • Match export invoices to contract, LUT and receipt evidence
  • Review SEZ/STPI/Softex records where applicable
  • Check forex realisation and write-offs
  • Test GST return mapping for export turnover
Evidence

Export invoice, contract, LUT, SEZ/STPI/Softex record where applicable, FIRC/BRC, bank advice and GST return working.

Payroll, contractors and IP assignment

Risk: Engineering payroll, consultants, contractors, bonuses, reimbursements or IP assignments are unsupported or not allocated to projects.

Controls
  • HR master control
  • Contractor onboarding
  • Timesheet/project allocation
  • IP assignment evidence
Tests
  • Match payroll and contractor payments to HR/vendor records
  • Review timesheet allocation to projects
  • Sample consultant deliverables and TDS
  • Check IP/confidentiality documents for contractors
Evidence

HR master, contract, timesheet, deliverable, bank proof, TDS support, IP assignment and confidentiality agreement.

Product, data and customer support controls

Risk: Customer support, product data, SLAs, credits, refunds, uptime reporting or data-retention commitments are not governed or evidenced.

Controls
  • SLA tracker
  • Support escalation workflow
  • Refund/credit approval
  • Data retention and deletion control
Tests
  • Review SLA exceptions and service credits
  • Sample customer complaints to closure evidence
  • Test refunds and credits
  • Review data deletion and retention tickets
Evidence

Support ticket, SLA report, credit/refund approval, customer communication, deletion ticket, retention policy and audit log.

Continuous monitoring

SaaS rules worth automating rules

RuleException logic
MRR varianceCurrent MRR differs from contract/order form, plan, licence count, discount or approved renewal terms.
Manual billing overrideInvoice, credit note or subscription change was manually overridden without ticket and approval evidence.
Cloud spend spikeCloud/API/tool spend exceeds budget, tag owner, customer allocation or previous-period trend beyond threshold.
Leaver accessExited employee, contractor, vendor or bot account remains active in production, cloud, source code or finance systems.
Unbilled or deferred revenue ageingDelivered milestones, old WIP, unbilled revenue or deferred revenue balances exceed ageing thresholds.
Export evidence gapExport invoice lacks LUT, receipt realisation, SEZ/STPI/Softex support where applicable or GST return mapping.
Export SaaS workbookOpen monitoring repository
Downloads

Templates and linked tools workpapers

IT Services SaaS Audit Workbook

Generate an Excel/PDF workbook for subscription revenue, project billing, cloud spend, access, releases, exports and support controls.

Open ->
O2C Internal Audit Checklist

Use for SaaS billing, collections, credit notes, receivables and revenue cut-off.

Open ->
H2R Internal Audit Checklist

Use for payroll, contractors, access removal and reimbursement controls.

Open ->
ITGC Internal Audit Checklist

Use for access, change management, backup, interface, job and audit-log controls.

Open ->
Internal Audit RCM Builder

Convert IT services and SaaS risks into an engagement-specific RCM.

Open ->
Internal Audit Monitoring Rules

Use recurring exception logic for billing, revenue, cloud spend, access and export evidence.

Open ->
Authority

References to verify sources

Use this as an internal-audit workpaper starting point, not as GST, export, SEZ, STPI, RBI/FEMA, information-security or legal advice. Requirements vary by entity model, customer geography, export status, SEZ/STPI registration, LUT, contract terms, data processing obligations and audit period.

ICAI IASB - Industry Specific Internal Audit Guides ->ICAI IASB - Compendium of Standards on Internal Audit ->STPI - Statutory services for software exports ->SEZ India - Instructions and circulars ->GST portal - Letter of undertaking services ->RBI - Master Direction on Export of Goods and Services ->
FAQ

IT services internal audit FAQs questions

What should an IT services or SaaS internal audit cover?

An IT services or SaaS internal audit should cover subscription revenue, project billing, delivery evidence, customer onboarding, receivables, cloud spend, vendor tools, change and release controls, logical access, GST export evidence, SEZ/STPI records where applicable, payroll, contractors, IP assignment and support/SLA controls.

Which SaaS audit checks are best for continuous monitoring?

High-value monitoring checks include MRR variance, manual billing overrides, credit notes without approval, cloud spend spikes, idle cloud resources, leaver access, privileged-user activity, old unbilled revenue, deferred revenue ageing and export invoices without LUT or receipt evidence.

Is this checklist a GST, SEZ or export compliance opinion?

No. This is an internal-audit workpaper starter. GST export, LUT, SEZ, STPI, Softex and foreign exchange requirements must be verified against current law, registration status, customer contract facts and the audit period before any compliance conclusion is made.

How is SaaS internal audit different from a normal O2C audit?

A normal O2C audit covers order, invoice, collection and credit notes. SaaS audit adds subscription master changes, usage-to-billing reconciliation, MRR/ARR movement, deferred revenue, activation and cancellation cut-off, cloud cost allocation, release controls and customer data/security commitments.