CORAA

SIA 520 — Internal Auditing in an Information Technology Environment

ICAI Internal Audit Standards Board · October 2022 compendium · 500 series
Reviewed 1 October 2026

SIA 520 covers internal audit work in an information technology environment. The internal auditor has to understand the entity's IT strategy, policies, procedures and governance, and build the audit on an independent risk assessment of that environment together with an evaluation of the controls that mitigate those risks.

This page covers SIA 520 as it stands in ICAI’s October 2022 compendium. ICAI’s February 2026 compendium, applicable from 1 April 2026, renumbers the standards, so check the current number and text in that compendium before citing it in a report.

What the internal auditor has to do

  • Understand the entity's IT strategy, policies, procedures and governance.
  • Carry out an independent risk assessment of the IT environment.
  • Evaluate the controls that mitigate the risks identified.

How SIA 520 shows up in the internal audit file

  • A note of the team's understanding of the IT environment.
  • The risk assessment of that environment.
  • The evaluation of the mitigating controls and the conclusion reached.

Common mistakes in practice

  • Testing reports and system outputs without first understanding the IT environment that produced them.
  • Confusing this standard with the Information Systems Audit Standards.

The file checklist and the mistakes above are practice points drawn from the requirements of the standard. They are not text from the standard.

Note
Do not confuse SIA 520 with the Information Systems Audit Standards (ISAS). ISAS were published in February 2026 by a different ICAI board, the Digital Accounting and Assurance Board. They are a separate set of standards.

Related standards

SIA 120 · Internal ControlsSIA 530 · Third Party Service ProviderSIA 310 · Planning the Internal Audit Assignment

Status and source

This standard is described here as it stands in the October 2022 compendium, which is the earlier set. ICAI's Internal Audit Standards Board lists its Compendium of Standards on Internal Audit (as on February 2026) as applicable from 1 April 2026 (source: the Board's compendium page, checked on 1 October 2026). That compendium renumbers the standards, so check the current number and text there before citing this standard in a report. ICAI's compendium page does not say whether the standards are mandatory or recommendatory, so we do not describe any standard as mandatory. The effective-date clause in each 2019 standard said it applied to internal audits beginning on or after a date to be notified by the Council of ICAI.

These pages summarise each standard as it stands in ICAI's Compendium of Standards on Internal Audit (as on 1 October 2022), working from an extract of that document. They are summaries and close paraphrases, not the text of the standards. ICAI's Internal Audit Standards Board lists its Compendium of Standards on Internal Audit (as on February 2026) as applicable from 1 April 2026 (source: the Board's compendium page, checked on 1 October 2026). For that current set we have only the titles, taken from the Board's 2025-26 annual report; its text is available from ICAI through a registration form on the compendium page and is not summarised here. ICAI's compendium page does not say whether the standards are mandatory or recommendatory, so we do not describe any standard as mandatory. Before you cite a number, a paragraph or a status in a report, check the February 2026 compendium. internalaudit.icai.org

Free working files for SIA 520

Take the working versions with you

Editable formats and tools from CORAA’s internal audit library that put SIA 520 into practice. Free to use.

IT general controls audit workbook →IT general controls internal audit checklist →

SIA 520 — frequently asked

What is SIA 520?

SIA 520, Internal Auditing in an Information Technology Environment, is a Standard on Internal Audit issued by the Internal Audit Standards Board of ICAI. SIA 520 covers internal audit work in an information technology environment. The internal auditor has to understand the entity's IT strategy, policies, procedures and governance, and build the audit on an independent risk assessment of that environment together with an evaluation of the controls that mitigate those risks.

Is SIA 520 mandatory?

ICAI's compendium page does not say whether the Standards on Internal Audit are mandatory or recommendatory, so we do not describe SIA 520 as mandatory. ICAI's Internal Audit Standards Board lists its Compendium of Standards on Internal Audit (as on February 2026) as applicable from 1 April 2026 (source: the Board's compendium page, checked on 1 October 2026). SIA 520 as described on this page is from the earlier October 2022 compendium. The February 2026 compendium renumbers the standards, so check the current number and text there before citing it in a report.

What should the internal audit file show for SIA 520?

A note of the team's understanding of the IT environment. The risk assessment of that environment. The evaluation of the mitigating controls and the conclusion reached.

← Previous
SIA 390 — Monitoring and Reporting of Prior Audit Issues
Next →
SIA 530 — Third Party Service Provider