IT plays an increasingly important role within organisations. From financial processes to operational management, data and technology are indispensable. However, this growing dependence also brings risks, such as cyberattacks, data breaches and unreliable management information.
RSM IT Audit helps organisations make the most of the opportunities offered by IT while managing the associated risks. We assess the reliability of your systems, support compliance with laws and regulations and identify cyber and other IT risks. Our auditors provide process based audits, data analysis and assurance reporting to help demonstrate that your organisation is in control.
IT Audit for risk management, compliance and information security
We perform independent IT audits that provide insight into the operation, control and security of your systems. Our services focus on:
- assessing internal controls within your organisation or outsourced processes
- performing mandatory and other audits, including ENSIA, DigiD, WPG, VIPP, NIS2 and IDRS
- assessing IT risks and security measures
- making data accessible for reporting and analysis
- developing dashboards and visualisations for management purposes
Our IT Audit services
Have you outsourced processes to third parties or do you use standard software? You remain responsible for the quality and control of these services. An ISAE 3402 report or TPM (RSO) provides objective assurance over the performance of outsourced services.
ISAE 3402 Type I and Type II for internal controls, financial processes and continuity
TPM (RSO) reports on IT services and information security
support with audit readiness and certification
These reports are relevant for organisations working with external service providers, such as payroll providers, cloud hosting providers or administrative service providers.
ENSIA stands for Eenduidige Normatiek Single Information Audit and is based on the Baseline Informatiebeveiliging Overheid (BIO), the Dutch Government Information Security Baseline. Dutch municipalities are required to perform an annual ENSIA audit as part of their accountability for information security.
RSM IT Audit supports municipalities with:
- preparing for and performing the annual ENSIA assessment
- meeting the annual audit requirement
- embedding information security within the Planning and Control cycle
We are familiar with the municipal context and work with several medium sized and large municipalities.
Organisations that use DigiD are required to have their connection assessed annually. RSM IT Audit performs these DigiD audits in accordance with Logius guidelines.
- initial assessment when applying for a DigiD connection
- annual reassessment before 1 May
- assessment based on the current Logius standards
We provide a structured approach and timely delivery.
Digital incidents occur every day. Data breaches, ransomware and misconfigurations can cause significant damage. RSM IT Audit helps organisations with:
- identifying IT risks
- assessing security measures
- improving resilience through practical recommendations
- using automated tools for risk analysis and reporting
We help you prepare for incidents and support both prevention and recovery.
Why choose RSM IT Audit?
Registered IT Auditors (RE) with experience in both profit and non profit organisations
Our Registered IT Auditors have experience in both profit and non profit organisations and combine expertise in IT controls, information security and auditing.
A broad range of process based and mandatory audits
From ENSIA and DigiD to ISAE 3402 and cybersecurity, we support organisations with a wide range of IT control and compliance matters.
A pragmatic approach tailored to your organisation
We look beyond the audit requirements and consider what they mean for your processes and organisation.
More about out IT Audit services
Would you like to know more?
Would you like to know how RSM IT Audit can help your organisation gain greater control over information security, IT controls or outsourcing matters?
Please contact:
Frequently asked questions about IT Audit:
An IT audit provides insight into the control, reliability and security of IT systems and processes. It considers areas including internal controls, IT risks and information security.
An IT audit may be required due to laws and regulations, requirements from clients or other stakeholders, or when you want greater insight into IT risks and the control of your systems and processes.
RSM IT Audit performs various audits and assessments, including ISAE 3402 and TPM (RSO) reports, ENSIA audits and DigiD audits. We also support organisations with information security and cybersecurity.
IT Audit focuses on assessing the control, reliability and operation of IT processes and systems. Cybersecurity and information security focus on identifying IT risks, assessing security measures and improving digital resilience.
Yes. RSM IT Audit supports organisations in preparing for and performing various mandatory audits. Depending on the type of audit, we help clarify the requirements and prepare your organisation for the assessment.