FirstHR

IT Auditor Interview Questions and Scorecard

IT auditor interview questions for small businesses: 6 sets covering controls, frameworks, evidence, and independence, plus a scorecard. Download as DOCX.

Nick Anisimov

Nick Anisimov

FirstHR Founder

Hiring
15 min

IT Auditor Interview Questions and Scorecard

39 interviewer questions across five areas, each with what a strong answer sounds like, plus a 1-to-5 scorecard, a red-flag list, and a scope checklist. Built for companies hiring without an HR department. Download as DOCX.

The first time I sat across from an IT auditor candidate, I had no honest way to grade half of what he said. He talked fluently about control frameworks and testing cycles, and I nodded along, because the customer contract that triggered the whole search did not care whether I understood the vocabulary. What saved that interview was a single unglamorous question about where his evidence came from.

That is the practical problem with hiring an IT auditor at a small company. The person is being hired precisely because nobody inside already has the skill, so the interviewer is evaluating a specialty they do not hold. The fix is not to learn IT audit before Friday. It is to ask questions whose answers have a recognizable shape, and to score every candidate against the same rubric.

At FirstHR, we build for companies that hire without an HR department, where the founder or the operations lead runs the interview alone. This page gives you 39 interviewer questions across five areas, each with a note on what a good answer sounds like, plus a downloadable scorecard, a red-flag list, and a scope checklist to complete before anyone gets system access.

TL;DR
Interview an IT auditor on five areas: audit methodology, IT general controls, frameworks and audit types, testing and evidence, and independence and behavior. The most revealing question is what they do with a report the system owner prepared: a strong auditor verifies it before relying on it. Ask every candidate the same questions and score six areas 1 to 5. Download 39 questions and the scorecard as DOCX.

What to Assess in an IT Auditor

Assess an IT auditor on how they gather evidence, how they scope from risk, and how they behave when a finding is unpopular, not on how many frameworks they can name. Framework knowledge is the easiest part of the job to acquire and the easiest to fake in an interview. Evidence discipline and independence are neither.

The role itself is narrower than it sounds. Most of the work is IT general controls: who has access and who approved it, whether access disappears when people leave, how a change reaches production, and whether a backup has ever actually been restored. Application controls, security configuration, and vendor assurance sit on top of that base, but the base is where an audit at a small company lives.

The most reliable way to evaluate all of this is a structured interview, where every candidate answers the same core questions and is scored on the same rubric. That matters more than usual here, because a candidate who happens to share your technology stack is easy to talk to for an hour without testing anything at all.

The Six Question Sets

The questions below are grouped into five areas plus a scorecard. Each area targets a different part of the role, and a strong candidate should hold up across all of them rather than only in the framework discussion they have rehearsed most.

Fundamentals and Method
Start here
Scoping, risk-based planning, design versus operating effectiveness, and sampling. Tells you whether the candidate audits from a plan or from a checklist.
IT General Controls
The daily work
Access, terminations, segregation of duties, change management, backup and recovery. Ask at least four of these of every candidate.
Frameworks and Audit Types
Tools, not vocabulary
Whether they choose a framework to fit the business and scale it down, and whether they know an audit from a penetration test.
Testing and Evidence
Technical depth
Report completeness, log analysis, population testing, and database change review. Contains the single best question on the page.
Independence and Behavior
Judgment under pressure
Holding a finding when IT disagrees, flagging conflicts unprompted, and writing findings that actually get fixed.
Scorecard and Red Flags
Decide on evidence
A 1-to-5 rubric across six areas, a red-flag list, and a scope checklist to complete before you grant anyone access.
Do Not Skip the Boring Sets
Candidates arrive rehearsed on frameworks and on their proudest finding. The sets that actually separate people are IT general controls, where vague answers about access reviews are common, and testing and evidence, where you learn whether they go to the source system or accept whatever the system owner hands them. Ask at least four questions from the controls set and three from the evidence set of every candidate, whatever the seniority of the role, and record the answers on the scorecard as you go.

39 Questions and a Scorecard to Download

Download all six as a single Word document, or copy the individual sets you need. Each set follows the same structure: when to use it, the questions with notes on what a good answer sounds like, what to listen for, and space for notes. The final file is the scorecard, the red-flag list, and the scope checklist.

Download All 6 IT Auditor Question Sets
Fundamentals, IT general controls, frameworks, testing and evidence, independence and behavior, plus a scoring rubric. All in one DOCX.

Set 1: IT Audit Fundamentals and Methodology

Scoping, risk-based planning, design versus operating effectiveness, and sampling. This set tells you whether the candidate builds an audit plan or executes one somebody else wrote.

IT Audit Fundamentals and Methodology
IT AUDIT FUNDAMENTALS AND METHODOLOGY
Candidate: __
Company: __
Interviewer: __
Date: _

HOW TO USE THIS SET

This is the opening set for every IT auditor interview. It tests whether the
candidate audits from a risk-based plan or simply runs a checklist someone handed
them. Ask 5 or 6 of these, and judge each answer against the note in parentheses.
You do not need to be technical to hear the difference between a candidate who
scopes an audit and one who recites a framework.

QUESTIONS

1. Walk me through an IT audit you ran end to end, from scoping to the final
report.
(Good answer: names the phases in order, planning, risk assessment, control
testing, evidence, findings, report, remediation follow-up, and describes a
real system rather than a generic process.)
2. How do you decide what to put in scope when you cannot audit everything?
(Good answer: starts from business risk and the systems that carry financial
or customer data, not from whatever is easiest to test.)
3. What is the difference between an IT general control and an application
control?
(Good answer: general controls govern the environment, access, change,
operations, backup, and application controls sit inside a single system, such
as an input validation or an approval limit. Knows that weak general controls
undermine every application control above them.)
4. How do you build a risk assessment for a company you have never audited?
(Good answer: inventories systems and data, talks to the people who run them,
ranks by likelihood and impact, and writes the plan down.)
5. What is the difference between a control design test and an operating
effectiveness test?
(Good answer: design asks whether the control would work if performed;
effectiveness asks whether it actually was performed over the period. A strong
candidate says both are needed and explains sampling across a period.)
6. How do you size a sample, and what do you do when the sample fails?
(Good answer: ties sample size to population and frequency, and escalates a
failure into a wider test rather than quietly enlarging the sample until it
passes.)
7. Tell me about an audit where your original scope turned out to be wrong. What
did you change?

WHAT TO LISTEN FOR

Risk drives the plan, not habit or a template
Clear vocabulary used correctly and explained plainly
Willingness to say what they did not test and why
A written plan, not an improvised walkthrough

NOTES

__
__

Set 2: IT General Controls

Access and terminations, segregation of duties, change management, backup and recovery, and hosted systems you do not control. The daily work of the job.

IT General Controls: Access, Change, and Operations
IT GENERAL CONTROLS QUESTIONS
Candidate: __
Company: __
Interviewer: __

WHEN TO USE THIS SET

IT general controls are the daily work of the job, and they are where a weak
candidate is easiest to spot. Access, change management, and operations cover
most of what an auditor will actually test at a small or mid-sized company. Ask
at least four of these of every candidate, whatever the seniority of the role.

ACCESS CONTROLS

1. How would you test whether user access is appropriate?
(Good answer: pulls the full user list from the system itself, compares it to
current staff and job roles, and tests a sample of grants back to an approval.
Does not accept a spreadsheet the administrator prepared as evidence.)
2. How do you test that access is removed when someone leaves?
(Good answer: starts from the payroll or HR termination list, not from the IT
ticket queue, and checks the date the account was actually disabled.)
3. What is segregation of duties in an IT environment, and how do you test it?
(Good answer: no single person can both make a change and approve it, or both
create a vendor and pay it. Tests by mapping roles to conflicting permissions.)
4. How do you audit privileged and administrator accounts?
(Good answer: counts them, questions why each exists, checks shared accounts,
and looks for logging and multi-factor authentication on all of them.)

CHANGE MANAGEMENT

5. Walk me through how you would audit a change management process.
(Good answer: samples changes from the production system, not from the change
log, then traces each back to a request, a test record, and an approval.)
6. How do you handle emergency changes made outside the normal process?
(Good answer: expects a documented after-the-fact approval, and treats a high
volume of emergencies as a finding in itself.)

OPERATIONS, BACKUP, AND RECOVERY

7. How do you audit backups?
(Good answer: verifies that a restore was actually tested, not just that a
backup job reports success. An untested backup is not a control.)
8. What would you look at first in a disaster recovery review?
(Good answer: the recovery time and recovery point the business needs, then
whether the plan and the last test support them.)
9. How do you audit a system the company does not host, such as a cloud payroll
or accounting platform?
(Good answer: reviews the provider assurance report, checks the user entity
controls it assumes the customer performs, and tests those internally.)

WHAT TO LISTEN FOR

Evidence pulled from the system, not handed over by the system owner
Termination testing anchored to the HR record
Backup answers that mention a restore test
Knows which controls stay the customer responsibility in a cloud service

NOTES

__
Still Using Spreadsheets for Onboarding?
Automate documents, training assignments, task management, and track onboarding progress in real time.
See How It Works

Set 3: Frameworks, Standards, and Audit Types

Whether frameworks are tools or vocabulary, how the candidate scales a large one down to a small IT team, and whether they know an audit from a penetration test.

Frameworks, Standards, and Audit Types
FRAMEWORKS, STANDARDS, AND AUDIT TYPES
Candidate: __
Company: __
Interviewer: __

WHEN TO USE THIS SET

Use this set to find out whether the candidate knows frameworks as tools or as
vocabulary. The goal is not to hear the most acronyms. It is to hear a candidate
choose a framework because it fits the business and then scale it down to a
company your size. Add or cut questions to match the obligations you actually
carry.

QUESTIONS

1. Which control frameworks have you worked with, and which would you apply here?
(Good answer: names what they have used, asks about our industry, customers,
and contracts before choosing, and can explain the difference between a
governance framework and a security control catalog.)
2. What is the difference between a framework and a regulation?
(Good answer: a framework is a voluntary structure you adopt; a regulation is
a legal obligation. Knows that adopting a framework does not by itself satisfy
a law.)
3. Our customers are starting to ask for a security attestation before they sign.
How would you approach that?
(Good answer: scopes the systems in question, runs a readiness assessment,
closes gaps, and is honest that the formal opinion comes from an independent
licensed firm, not from an internal auditor.)
4. How do you scale a large framework down for a company with a very small IT
team?
(Good answer: prioritizes by risk, accepts compensating controls, and does not
demand segregation of duties that headcount cannot support. Names the
compensating control, such as owner review of a monthly access report.)
5. What is the difference between an internal audit, an external audit, and a
penetration test?
(Good answer: distinguishes independent internal assurance, an outside opinion
for third parties, and a technical exercise that finds exploitable weaknesses.
Knows a penetration test is not an audit.)
6. How would you handle a requirement that we genuinely cannot afford to meet
this year?
(Good answer: documents the gap, proposes an interim compensating control, and
puts an accepted risk in writing with an owner and a review date.)
7. Which certification do you hold, and what did preparing for it change about
how you work?

WHAT TO LISTEN FOR

Chooses a framework after asking about the business
Distinguishes voluntary structure from legal obligation
Comfortable with compensating controls at small headcount
No acronym recital without a worked example behind it

NOTES

__

Set 4: Testing, Evidence, and Technical Depth

Report completeness, log analysis, population testing, database change review, and translating a technical finding into business impact. The first question in this set is the most revealing one on the page.

Testing, Evidence, and Technical Depth
TESTING, EVIDENCE, AND TECHNICAL DEPTH
Candidate: __
Company: __
Interviewer: __

WHEN TO USE THIS SET

This set separates an auditor who inspects the system from one who accepts a
screenshot. You do not have to grade the technical detail yourself. Listen for
whether the candidate goes to the source, tests the completeness of the data they
were given, and can explain the method to a non-technical owner.

QUESTIONS

1. The system owner sends you a report that shows the control working. What do
you do with it?
(Good answer: tests that the report itself is complete and accurate before
relying on it, by checking record counts, date ranges, and parameters, or by
regenerating it while watching. This is the single best question in the set.)
2. How do you use log analysis in an audit?
(Good answer: uses logs as independent evidence of what happened, checks that
logging is enabled and retained, and looks for gaps in the log itself.)
3. What tools or query languages do you use to test a full population rather than
a sample?
(Good answer: names real tools or writes queries, and can describe an actual
test they built. A candidate who only samples when the whole population is
available is leaving evidence on the table.)
4. How do you audit a database for unauthorized changes?
(Good answer: looks for direct back-end access, checks who holds it, and
compares change records against the approved change list.)
5. How would you test whether multi-factor authentication is enforced, not just
enabled?
(Good answer: checks the policy configuration and then samples real accounts,
including exceptions and service accounts.)
6. Give me an example of a finding you raised that turned out to be wrong. What
happened?
(Good answer: owns it, explains how the misunderstanding arose, and describes
the validation step they added afterwards.)
7. How do you keep audit evidence organized so someone else could re-perform your
test a year later?
8. Explain one of your technical findings the way you would explain it to an
owner with no IT background.
(Good answer: plain language, business impact first, technical detail second.)

WHAT TO LISTEN FOR

Tests the completeness and accuracy of any report handed to them
Goes to the system rather than accepting a screenshot
Population testing where the data supports it
Can translate a technical finding into business impact

NOTES

__
Companies Using FirstHR Onboard 3x Faster
Join hundreds of small businesses who transformed their new hire experience.
See It in Action

Set 5: Independence, Reporting, and Behavioral Questions

Holding a finding when IT disagrees, flagging conflicts of interest unprompted, writing findings that get fixed, and following up when a remediation date slips.

Independence, Reporting, and Behavioral Questions
INDEPENDENCE, REPORTING, AND BEHAVIORAL QUESTIONS
Candidate: __
Company: __
Interviewer: __

WHEN TO USE THIS SET

An IT auditor spends most of the job telling technical colleagues that something
they built is not working as intended. Judgment, independence, and the ability to
hold a finding under pressure matter as much as testing skill. Ask for real past
examples and press for the outcome, not the intention.

QUESTIONS

1. Tell me about a time the head of IT disagreed with a finding. What did you do?
(Good answer: separates the facts from the conclusion, revisits evidence
honestly, and keeps the finding when the evidence holds. Escalates through a
defined route rather than by argument.)
2. Have you ever been asked to soften or drop a finding? How did you respond?
(Good answer: a concrete story, a documented position, and no quiet deletion.)
3. If we hire you and you have to audit a system you helped configure, what
happens?
(Good answer: flags the independence conflict immediately and proposes someone
else test that area. At a small company this comes up constantly, so a
candidate who does not see the problem is a real risk.)
4. Describe the worst-controlled environment you have audited. How did you decide
where to start?
5. How do you write a finding so it gets fixed rather than filed?
(Good answer: clear condition, cause, and business impact, a named owner, and
an agreed date. Ranks findings so the small team knows what comes first.)
6. How do you follow up on remediation, and what do you do when a fix slips
twice?
7. Tell me about a time you found something serious that nobody wanted to hear.
8. What would your first 90 days here look like?
(Good answer: asks questions about our systems and obligations before
answering, then proposes an inventory and a risk assessment rather than an
immediate audit.)

WHAT TO LISTEN FOR

Real stories with outcomes, not stated principles
Raises independence conflicts without being prompted
Writes findings that a busy team can act on
Firm on evidence, flexible on tone

NOTES

__

Set 6: Scorecard, Red Flags, and Scope Checklist

A 1-to-5 rubric across six areas with space for evidence, a red-flag list, and a scope checklist to complete before you grant access. The asset most question lists leave out.

IT Auditor Scorecard, Red Flags, and Scope Checklist
IT AUDITOR SCORECARD AND RED-FLAG CHECKLIST
Candidate: __
Company: __
Interviewer: __
Date: _

HOW TO SCORE

Score every area right after the interview, while the answers are fresh, and
anchor each score to something the candidate actually said. If more than one
person interviews, each scores independently before anyone discusses. Use the
same rubric for every candidate. A consistent, evidence-based process produces
better hires and is far easier to stand behind later.
Rating scale:
5 = Strong, specific evidence 4 = Solid evidence 3 = Some evidence
2 = Weak or mixed evidence 1 = No evidence or red flags

SCORING AREAS

Audit methodology: risk-based scoping, design vs operating effectiveness, sampling
Score [ 1 ] [ 2 ] [ 3 ] [ 4 ] [ 5 ]
Evidence: ______
IT general controls: access, change management, backup and recovery
Score [ 1 ] [ 2 ] [ 3 ] [ 4 ] [ 5 ]
Evidence: ______
Technical testing and evidence: goes to the source, tests report completeness
Score [ 1 ] [ 2 ] [ 3 ] [ 4 ] [ 5 ]
Evidence: ______
Frameworks and judgment: fits the framework to the business, scales it down
Score [ 1 ] [ 2 ] [ 3 ] [ 4 ] [ 5 ]
Evidence: ______
Independence and integrity: holds a finding, flags conflicts unprompted
Score [ 1 ] [ 2 ] [ 3 ] [ 4 ] [ 5 ]
Evidence: ______
Communication: explains technical risk in business language
Score [ 1 ] [ 2 ] [ 3 ] [ 4 ] [ 5 ]
Evidence: ______

RED FLAGS (WEIGH CAREFULLY)

[ ] Recites frameworks but cannot describe one audit end to end
[ ] Accepts a screenshot or an owner-prepared list as evidence
[ ] Never mentions testing the completeness of a report given to them
[ ] Treats a penetration test and an audit as the same thing
[ ] Sees no problem auditing a system they configured
[ ] Cannot describe a single finding in plain business language
[ ] Vague about why a previous finding was dropped

SCOPE CHECKLIST BEFORE YOU HIRE

[ ] Systems and data the role will cover are written down
[ ] The obligation driving the hire is named (customer contract, regulator, insurer)
[ ] Reporting line keeps the auditor independent of the team being audited
[ ] Decided: employee, contractor, or an outside firm for this scope
[ ] Confidentiality agreement prepared before any access is granted
[ ] Access the auditor will need is listed, with read-only where possible

DECISION

Total score: ______ / 30
Recommendation: [ ] Strong yes [ ] Yes [ ] Maybe [ ] No
Notes: __

The Control Questions That Matter Most

If you only have time for four questions, take them from IT general controls, because that is where nearly every audit at a small company begins and where weak candidates are easiest to identify. Access, change, and recovery cover the majority of what the role will test in its first year.

Access management
Pulls the user list from the system itself
Tests terminations against the HR record
Counts and challenges every admin account
Change management
Samples changes from production, not the log
Traces each back to request, test, approval
Treats frequent emergency changes as a finding
Operations and recovery
Verifies a restore was tested, not just run
Starts recovery review from the business need
Reviews provider reports for hosted systems
Segregation of duties
Maps roles to conflicting permissions
Accepts compensating controls at small headcount
Names the compensating control explicitly

Two answers in this area carry more weight than the rest. When you ask how the candidate tests that access was removed after a termination, a strong auditor starts from the HR or payroll termination list, because that is the independent population; a weak one starts from the IT ticket queue, which only contains the terminations somebody remembered to log. And when you ask about backups, a strong auditor talks about a tested restore rather than a successful backup job.

AskWhat a strong answer includes
How do you test that access is appropriate?Pulls the user list from the system, traces grants to approvals
How do you test terminations?Starts from the HR list, measures the gap to account disablement
How do you audit change management?Samples changes from production, not from the change log
How do you audit backups?Verifies a restore was tested, not that the job reported success
How do you audit a hosted system?Reads the provider report, tests the controls left to the customer

Segregation of duties deserves one extra note. At a company with two people in IT, textbook segregation is impossible, and a candidate who insists on it is telling you they have never worked at your scale. The answer you want names a compensating control instead, such as an owner review of a monthly access change report, and records the accepted risk in writing.

Strong Answers, Weak Answers, and Red Flags

The questions open the door; the follow-ups decide the hire. Push for the actual system, the actual population, the actual outcome. Three questions in particular produce answers you can grade without any audit background of your own.

The system owner sends you a report showing the control working. What do you do with it?
Strong answer: A strong answer tests the report before relying on it: checks record counts and date ranges, confirms the parameters used, or watches it regenerate from the source system. The candidate treats an owner-prepared extract as an assertion to verify, not as evidence. This one answer tells you more about audit quality than any framework question.
Weak answer: A weak answer files the report as evidence, or says it would confirm with the owner that the report is complete, which is the same thing as taking their word for it.
How do you test that access is removed when someone leaves?
Strong answer: A strong answer starts from the termination list held by HR or payroll, because that is the independent population, then checks the date each account was actually disabled and measures the gap. It also looks at shared logins and third-party tools, which are where forgotten access usually survives.
Weak answer: A weak answer starts from the IT ticket queue, which only shows the terminations somebody remembered to raise a ticket for, and misses the exact population you are trying to find.
You have to audit a system you helped configure. What happens?
Strong answer: A strong answer raises the independence conflict before you finish the question, and proposes that someone else test that area or that the work be reviewed externally. At a small company an auditor is often asked to help fix what they found, so a candidate who sees the boundary clearly is worth a lot.
Weak answer: A weak answer says it would be fine because they would be objective. Good intentions are not a control, and an auditor who cannot see their own conflict will not surface anyone else’s.

Across the whole interview, the signals sort into a few patterns. Strong candidates go to the source for evidence, say plainly what they did not test, and put business impact before technical detail. Weak ones stack acronyms without a worked example behind any of them.

Method signals
Scopes from business risk, not habit
Separates design from operating effectiveness
Says plainly what was not tested and why
Evidence signals
Verifies any report handed to them
Pulls populations from the source system
Tests the whole population where data allows
Communication signals
Business impact before technical detail
Findings with an owner and a date
Ranks findings for a small team
Red flags
Acronyms with no worked example behind them
Calls a penetration test an audit
Sees no conflict in auditing their own work

One follow-up works on almost every answer: ask what happened next. A real auditor knows whether the finding was fixed, who owned it, and how long it took. A candidate describing work they only observed runs out of detail immediately.

Scoring the Interview

Score every candidate on the same six areas right after the interview, while the answers are still fresh, and anchor each score to something the person actually said. Scoring from memory a week later measures which conversation felt best, not who tested better. The rubric in Set 6 is built for this, and the same discipline underpins any good interview evaluation form.

Scoring areaWhat a 5 looks like
Audit methodologyScopes from risk, separates design from operating effectiveness
IT general controlsSpecific on access, change, and tested restores
Testing and evidenceVerifies any report given to them, tests populations
Frameworks and judgmentFits the framework to the business and scales it down
Independence and integrityRaises conflicts unprompted, holds a finding on evidence
CommunicationExplains a technical finding in business language

If more than one person interviews, each should score alone before the group talks. That matters here more than for most roles, because the head of IT is often on the panel and is also the person this auditor will review. Compare written scores first, then hold the feedback discussion against the evidence rather than the impressions.

Fair, Legal, and Structured Interviewing

A good interview is fair, legal, and structured, and those three reinforce each other. Asking the same job-related questions of every candidate keeps you compliant, reduces bias, and produces better hires at the same time. This is the part generic question lists leave out.

Ask about the job, not the person
Federal anti-discrimination law prohibits basing hiring decisions on protected characteristics, and questions that probe them create risk even when they are asked as small talk. Keep away from age, race, religion, national origin, sex, pregnancy or family plans, disability, and genetic information. For a technical audit role the common trap is a friendly detour into where a candidate is originally from, prompted by an unfamiliar certification body or a degree earned abroad. Ask instead whether they are legally authorized to work and whether they can perform the essential functions of the job. Every question in these sets is written to stay on the work. This is general information, not legal advice.
Use the same core questions for every candidate
Asking each candidate the same core questions is fairer and produces better hires. A structured interview, where everyone answers the same questions scored against the same rubric, predicts performance far better than a free-flowing conversation, and it makes the basis of your decision visible if it is ever questioned. IT audit interviews drift easily, because a candidate who shares your technology stack is easy to talk to for an hour without testing anything. Write the questions down in advance, ask them in the same order, and score them. The downloadable sets here are built for exactly that.
Score independently, then discuss
When more than one person interviews, each should complete the scorecard alone before the group talks. Otherwise the most technical voice in the room anchors everyone else, which is a particular hazard for an audit hire where the head of IT may sit on the panel and is also the person the auditor will be reviewing. Compare written evidence first, then discuss the gaps. A simple 1-to-5 rubric per area, filled in independently, turns a subjective debate into a structured decision that you can revisit months later.
Interview for the scope you actually have
An IT auditor for a regulated bank and one for a ten-person software company are different hires. Decide first what is driving the role, a customer contract, a regulator, an insurer, or a board, then weight the questions accordingly. If the obligation is customer assurance, lean on the frameworks and evidence sets. If it is a messy environment nobody has ever reviewed, weight fundamentals and independence instead. Interviewing for a generic enterprise audit function you do not need is the fastest way to hire someone who leaves within a year.
Same Questions, Scored on a Rubric
A structured interview, in which every candidate answers the same questions scored against a consistent rubric, predicts on-the-job performance more reliably than an unstructured conversation, and asking the same job-related questions of everyone also keeps you within the EEOC rules against basing decisions on protected characteristics. For a technical hire the discipline matters twice over, because rapport with a candidate who shares your stack is easy to mistake for evidence.

Keep every question tied to the work, and be careful with the friendly detours around a foreign degree or an unfamiliar certification body. If you want the legal boundaries in one place, the guide to questions employers cannot ask covers them. This is general information, not legal advice.

The frameworks themselves are worth a quick look before you interview, so the vocabulary is not new to you. The NIST Cybersecurity Framework is free, published by a federal agency, and organized around functions a non-specialist can follow, which makes it a reasonable hour of preparation for an owner who has never run an IT audit.

IT Auditor Pay and Level

There is no dedicated federal wage series for IT auditor, so benchmark against the two nearest classifications and place the role between them. Accountants and auditors anchors the audit side of the job; information security analysts anchors the technical side.

Benchmark Between Two Occupations (BLS, May 2025)
According to the Bureau of Labor Statistics Occupational Employment and Wage Statistics survey (May 2025), accountants and auditors had a median annual wage of $83,680, with the tenth percentile at $56,020 and the ninetieth at $144,090. Information security analysts had a median of $129,180, with the tenth percentile at $75,090 and the ninetieth at $199,850.

Most IT auditor roles sit between those anchors. The security end applies when the job is hands-on technical testing or carries a certification requirement; the audit end applies when the work is control review and reporting. Adjust for your local market, and remember that an engagement with a contractor is priced by scope rather than by salary.

TraitIT AuditorInternal Auditor
Tests access, change, and recovery controls
Reviews finance and operations processes
Tests application and database-level controls
Reads provider assurance reports for hosted systems
Writes findings with owners and remediation dates

If most of your risk sits in system access and customer data, hire for IT audit. If it sits in processes and policy adherence, the internal auditor question sets fit better, and many small companies eventually want both under one person.

Interviewing an IT Auditor Without HR

A large company hires an IT auditor through a specialist recruiter, a technical panel, and an audit committee that already knows what good looks like. A small company hires through the owner, who is usually meeting the vocabulary for the first time and running the interview between everything else. Three realities shape how to do this well at your size.

You are interviewing for a specialty you do not have yourself
Almost every owner hiring a first IT auditor is doing it because a customer, an insurer, or a regulator asked for something, not because they can grade IT audit work. That is manageable. You do not need to judge the technical detail; you need to hear whether the candidate goes to the source system for evidence, whether they can explain a finding in business language, and whether they scope from risk. Each question in these sets carries a note on what a good answer sounds like, so you can score the shape of the answer even when the content is outside your field. If you have a technical person on the team, put them on the panel for the testing set and score independently.
Independence is harder to protect at a small company than anywhere else
In a large organization the audit function reports past the people it reviews. In a ten-person company the auditor may report to the person who runs the systems, and may be asked to help fix what they found. That is why the independence questions are not filler. Ask directly what happens when they audit something they configured, and listen for whether they raise the conflict without being prompted. Then fix the structure on your side: decide the reporting line before the offer, keep the review of remediation separate from the remediation itself, and write down which systems the role covers. The scope checklist in the last set walks through this.
Employee, contractor, or an outside firm is a real decision here
Many small companies do not need a full-time IT auditor. A defined engagement with a contractor or a firm covers a one-off readiness review, while a permanent hire makes sense when audit work is continuous and internal knowledge compounds. Decide before you interview, because the questions you weight change: a contractor engagement leans on scope, deliverables, and availability, while an employee hire leans on judgment and growth. Whichever route you take, the people side still has to be handled properly. FirstHR covers that part: a signed offer with built-in e-signature, a confidentiality agreement before any access is granted, task workflows for system access, and documents stored on the employee profile. Applicant tracking is coming soon to FirstHR.

The role you are hiring for probably does not exist on paper yet either. Two neighboring templates are useful for drafting the posting and the scope: the internal auditor job description covers the audit half of the work, and the information security analyst job description covers the technical half.

Combine the sections that match the risk you actually carry, keep the scope narrow enough that one person can cover it, and browse the wider hiring templates for the rest of the process. Applicant tracking is coming soon to FirstHR, so for now the posting and the applicant replies stay in your own inbox.

From Interview to Onboarding

The interview is the first step. Once you choose someone, an audit hire has a few onboarding steps that most roles do not, because access and independence have to be settled before the work starts. That means a signed offer letter stating the scope and reporting line, a signed confidentiality agreement before any system access, and a written record of who approved each grant.

Offer and confidentiality first
Confirm role, scope, and reporting line in writing, and get a confidentiality agreement signed before the auditor sees a single system.
Grant access deliberately
List the systems the role needs, keep access read-only wherever testing allows, and record who approved each grant.
Set the reporting line in writing
Document who the auditor reports to and how a disputed finding escalates, so independence survives the first disagreement.
Store the records
Keep the signed offer, the confidentiality agreement, onboarding paperwork, and access approvals organized and easy to retrieve.

Do the ordinary parts properly too. Check references with specific questions about how the candidate handled a disputed finding, using a reference check structure rather than an open chat. A background check is common for a role that will hold broad access to your systems.

Then run the standard new hire paperwork on the same timeline as any other employee, and give the auditor a structured first week with an onboarding template so the system inventory starts before the first test does.

FirstHR connects the offer, the confidentiality agreement, e-signatures, and the access-and-policy checklist in one place, and stores the signed documents on the employee profile, so a company without an HR department can onboard an auditor with the record trail already intact. FirstHR is an onboarding and HR platform, not audit software or a security tool, so pair it with those. Applicant tracking is coming soon to FirstHR.

Key Takeaways
Assess an IT auditor on evidence discipline, risk-based scoping, and independence, not on how many frameworks they can name.
The most revealing question is what they do with a report the system owner prepared: a strong auditor verifies it before relying on it.
Termination testing should start from the HR list, and a backup answer should mention a tested restore, not a successful job.
At small headcount, expect compensating controls rather than textbook segregation of duties, named explicitly and written down.
Ask directly what happens when they audit a system they configured; a candidate who sees no conflict is a genuine risk.
Benchmark pay between two federal occupations: a median of $83,680 for accountants and auditors and $129,180 for information security analysts (BLS, May 2025).

Frequently Asked Questions

What questions should I ask an IT auditor candidate?

Ask across five areas: audit methodology, IT general controls, frameworks and audit types, technical testing and evidence, and independence and behavior. The strongest single question is what the candidate does when a system owner hands them a report that shows the control working; a good auditor tests the completeness and accuracy of that report before relying on it, while a weak one files it as evidence. Other high-value questions include how they test that access is removed when someone leaves, how they audit a change management process, how they scale a large framework down to a small IT team, and what happens when they must audit a system they helped configure. Ask the same core questions of every candidate and score each area on a rubric. This page gives you 39 questions grouped by area, each with a note on what a good answer sounds like, plus a downloadable scorecard.

What does an IT auditor actually do?

An IT auditor independently tests whether the controls around a company’s systems and data are designed properly and are actually working. The work centers on IT general controls: who has access and whether it was approved, whether access is removed when people leave, how changes reach production and who approved them, and whether backups have been restored rather than merely run. From there it extends to application controls inside individual systems, evidence gathering, and a written report with findings, owners, and remediation dates. At a small company the role is usually triggered by an outside requirement such as a customer security questionnaire, an insurer, a lender, or a regulator. The output is not a technical fix list; it is an assessment of risk that the business can act on, which is why plain-language communication matters as much as testing skill.

What is the difference between an IT auditor and an internal auditor?

An internal auditor reviews controls across the whole business, including finance, operations, and compliance, while an IT auditor specializes in the systems and data layer: access, change management, operations, security controls, and application controls. The two overlap heavily, because financial controls now sit inside software, and many internal auditors handle basic IT general controls themselves. The practical test is scope. If most of your risk is in processes, cash handling, and policy adherence, hire an internal auditor. If it sits in system access, customer data, and software change, hire an IT auditor. Small companies often start with one generalist and bring in specialist IT audit support for a specific engagement. Interview for the scope you actually have rather than the title you saw on a job board.

Does an IT auditor need a certification?

No, a certification is not required, and it is best treated as a signal rather than a filter. Professional certifications in IT audit, information security, and internal audit tell you the candidate has covered a common body of knowledge and committed to continuing education, which is genuinely useful when you cannot evaluate the technical depth yourself. They do not tell you whether the person can scope an audit at a company your size, hold a finding when the head of IT pushes back, or explain risk to an owner in plain language. A useful interview move is to ask which certification they hold and what preparing for it changed about how they work; a substantive answer beats the credential itself. Weight demonstrated audit work and judgment above any acronym on the resume.

How do I evaluate an IT auditor if I am not technical?

You do not need to grade the technical content; you need to recognize the shape of a strong answer. Listen for three things. First, where the evidence comes from: a good auditor pulls the population from the source system rather than accepting a list the system owner prepared. Second, whether they scope from business risk instead of running the same checklist everywhere. Third, whether they can explain one of their own technical findings to you, right there in the interview, in language you follow. Each question in these sets includes a note on what a good answer sounds like, so you can score against it. If you have a technical person available, put them on the panel for the testing questions and have both of you score independently before comparing notes.

Should I hire an IT auditor as an employee or a contractor?

It depends on whether the audit work is continuous or a defined project. A contractor or an outside firm fits a one-off readiness review, a customer-driven assessment, or a first look at an environment nobody has reviewed before, and it gives you specialist depth without a permanent salary. An employee fits when testing runs all year, when internal knowledge of your systems compounds, or when a regulator or contract expects an ongoing internal function. Decide before you interview, because the questions you weight change: a contractor engagement leans on scope, deliverables, availability, and independence from your team, while an employee hire leans on judgment, breadth, and how they would spend the first 90 days. Either way, define scope and reporting line in writing before granting any system access. This is general information, not legal advice.

How much does an IT auditor cost to hire?

There is no dedicated federal wage series for IT auditor, so benchmark against the two nearest classifications. According to the Bureau of Labor Statistics Occupational Employment and Wage Statistics survey (May 2025), accountants and auditors had a median annual wage of $83,680, with the tenth percentile at $56,020 and the ninetieth at $144,090. Information security analysts, the closer match for a security-weighted IT audit role, had a median of $129,180, with the tenth percentile at $75,090 and the ninetieth at $199,850. Most IT auditor roles land between those two anchors, with the security end of the range applying when the job leans technical or carries a certification requirement. Adjust for your local market, whether the role is hands-on or oversight, and whether you are hiring an employee or engaging a firm.

Are these IT auditor interview questions legal to ask?

Yes. Questions about audit experience, control testing, frameworks, evidence handling, and how a candidate handled a disputed finding are job-related and permitted. The legal caution is the general one that applies to all interviewing: avoid questions that touch protected characteristics such as age, race, color, religion, national origin, sex, pregnancy or family plans, disability, or genetic information, and keep every question tied to the job. For technical audit roles the common slip is a casual question about where someone is originally from, prompted by a foreign degree or an unfamiliar certification body. Ask instead whether they are authorized to work and whether they can perform the essential functions of the role. Using the same structured questions and the same scorecard for every candidate is itself a safeguard. This is general information, not legal advice.

Ready to transform your onboarding?

7-day free trial No credit card required
Start Your Free Trial