ISACA ITAF – IT Audit Framework: A Professional Practices Framework for IT Audit

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
ISACA's IT Audit Framework (ITAF) is a professional practices framework for IT audit. It establishes standards that address IT audit and assurance practitioners' roles and responsibilities, ethics, expected professional behavior, and required knowledge and skills; defines terms and concepts specific to IT audit and assurance; and provides guidance and techniques for the planning, performing, and reporting of IT audit and assurance engagements. Its standards are mandatory for ISACA-certified professionals, and its guidelines and tools support their application.
ISACA publishes ITAF and makes it available free of charge. The 4th edition, released in October 2020, updated the 2014 edition with expanded IT-specific guidance, a stronger emphasis on risk assessment in audit planning, and a restructured format; it is the edition most GRC and audit programs still cite. ISACA released the 5th edition on 26 February 2026, modernizing the framework for cloud, artificial intelligence, business automation, data analytics, agile auditing, continuous assurance, and digital trust, and updating the companion guideline 2208 on IT audit sampling.
IT audit functions implement ITAF by adopting its general standards as the charter and conduct rules for the function, applying its performance standards to plan, execute, and supervise each engagement, and following its reporting standards for communicating results and following up on findings. The guidelines and tools translate the standards into practice, and many organizations align ITAF engagements with COBIT for governance objectives and with the IIA's Global Internal Audit Standards where IT audit sits inside internal audit.
Why it Matters
IT audit findings are only as credible as the standards behind them, and regulators, audit committees, and external auditors expect IT assurance work to follow a recognized professional framework. ITAF is that framework for the IT audit profession: it is the basis of ISACA's certifications, it is free, and its structure of standards, guidelines, and tools maps directly onto how an engagement is planned, performed, and reported.
Key benefits include:
- Mandatory professional standards
ITAF standards are binding on ISACA-certified practitioners, giving IT audit work a defined professional baseline that stakeholders can rely on.
- Coverage of the whole engagement
General, performance, and reporting standards address independence and competence, planning and evidence, and reporting and follow-up in one framework.
- Guidelines that show how
Each series of standards is mirrored by guidelines that explain how to meet them, with tools and techniques such as audit programs and white papers.
- Current with technology
The 5th edition addresses cloud architectures, AI and automation, data-driven testing, continuous assurance, and governance accountability.
- Free and widely translated
ISACA publishes ITAF and its translations at no cost, so functions of any size can adopt it.
How it Works
ITAF is built in three layers. The standards are organized as general standards (1000 series), which set the guiding principles under which the IS assurance profession operates, including the audit charter, organizational and professional independence, reasonable expectation, due professional care, proficiency, assertions, and criteria; performance standards (1200 series), which address the conduct of the engagement, including engagement planning, risk assessment in planning, performance and supervision, materiality, evidence, using the work of other experts, and irregularities and illegal acts; and reporting standards (1400 series), which address reporting and follow-up activities. The guidelines mirror the standards in the 2000, 2200, and 2400 series and are designed to directly support them, and the tools and techniques include white papers, audit and assurance programs, and reference material such as the COBIT family.
An IT audit function applies ITAF by establishing its charter and independence under the general standards, planning each engagement with a risk assessment and defined scope, materiality, and resources under the performance standards, gathering and evaluating evidence with appropriate supervision, and reporting findings with clear conclusions and follow-up under the reporting standards. Guideline 2208 governs audit sampling; other guidelines cover topics such as using the work of other experts and reporting. The 5th edition's shifts, from isolated controls to digital ecosystems, from periodic reviews to continuous insight, from sampling to data-driven testing, and from operational focus to governance and accountability, change how those steps are carried out rather than the standards' structure.
Within SmartSuite, IT audit teams run ITAF engagements as connected records: the audit universe and risk assessment drive the plan, each engagement carries its scope, materiality, program, and staffing, workpapers and evidence attach to the procedures they support with reviewer sign-off, and findings flow into reports and follow-up tracking, so conformance with the general, performance, and reporting standards is documented as the engagement proceeds.
Key Elements
- General standards (1000 series)
Guiding principles for the profession: audit charter, organizational independence, professional independence, reasonable expectation, due professional care, proficiency, assertions, and criteria.
- Performance standards (1200 series)
Conduct of the engagement: engagement planning, risk assessment in planning, performance and supervision, materiality, evidence, using the work of other experts, and irregularity and illegal acts.
- Reporting standards (1400 series)
Reporting and follow-up activities, covering the types of reports, the means of communication, and the information communicated.
- Guidelines (2000, 2200, and 2400 series)
Recommended guidance that mirrors each standard and explains how to achieve alignment with it, including guideline 2208 on IT audit sampling.
- Tools and techniques
White papers, IS audit and assurance programs, reference books, and related ISACA frameworks that support engagements.
- Terms and concepts
Definitions specific to IT audit and assurance that give engagements a common vocabulary.
- Digital trust and emerging technology coverage
The 5th edition integrates digital trust concepts and guidance on cloud, AI, automation, analytics, agile auditing, and continuous assurance.
Framework Scope
ITAF applies to IT audit and assurance engagements performed by practitioners in organizations of all sizes and sectors, whether in internal audit, external assurance, or specialist IT audit functions. Its standards are mandatory for holders of ISACA certifications such as CISA, and its guidelines are recommended practice. The framework covers the conduct of engagements and the professional obligations of practitioners; it does not itself define control objectives, which come from frameworks such as COBIT, ISO/IEC 27001, and NIST SP 800-53 that ITAF engagements assess against.
Framework Objectives
ITAF exists so that IT audit and assurance work is performed to consistent, recognized professional standards.
Define the roles, responsibilities, ethics, and competencies expected of IT audit and assurance practitioners.
Set mandatory standards for the planning, performance, supervision, and reporting of engagements.
Provide guidelines and tools that show practitioners how to meet the standards.
Establish a common vocabulary for IT audit and assurance.
Keep IT audit practice current with cloud, AI, automation, and continuous assurance.
Support the credibility of IT assurance for boards, regulators, and external auditors.
Framework in Context
ITAF is the IT audit companion to ISACA's COBIT 2019 governance framework, which supplies the objectives and practices that ITAF engagements commonly assess, and it operates alongside the IIA's Global Internal Audit Standards where IT audit is part of internal audit. IT audit engagements under ITAF regularly test controls drawn from ISO/IEC 27001, NIST SP 800-53, the NIST Cybersecurity Framework, and ITIL 4 service management practices, and IT general controls work supports the integrated ICFR audit under PCAOB AS 2201 and SOX. Assurance reports under ISAE 3000 and SOC 2 draw on comparable performance and reporting expectations.
Common Framework Mappings
ITAF is commonly mapped to the governance and control frameworks its engagements assess against and to the audit and assurance standards it operates alongside.
Mapped frameworks include:
COBIT 2019
IIA Global Internal Audit Standards
ISO 27001:2022
NIST 800-53 Rev.5
NIST CSF 2.0
ITIL 4
ISAE 3000
SOC 2
SOX
PCAOB AS 2201
- ClassificationCategoryIT Governance & Service ManagementDomainIT GovernanceFramework FamilyOther
- Regulatory ContextTypeStandardLegal InstrumentStandardSectorCross-SectorIndustryCross-Industry
- Region / PublisherRegionGlobalRegion DetailInternationalPublisherISACA
- VersioningVersion5th Edition (2026); 4th Edition (2020) widely citedEffective DateFebruary 26, 2026 (5th Edition)Issue DateOctober 22, 2020 (4th Edition); February 26, 2026 (5th Edition)
- AdoptionAdoption ModelIndustry RequirementImplementation ComplexityMedium
- Official ReferenceOpen Link in New TabSource
License included / downloadable: Yes
ISACA publishes ITAF and its translations free of charge, and its standards structure is included with the platform.
Framework text is licensed by its publisher and is included only where stated above.
How SmartSuite Supports ISACA ITAF
SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
For ISACA ITAF, SmartSuite runs the audit universe, risk-based plan, engagement programs, workpapers, findings, and follow-up in one workspace, so conformance with the general, performance, and reporting standards is documented as each engagement proceeds.
IT Audit Universe and Standards Library
Hold the ITAF standards and guidelines alongside the audit universe, risk assessment, and control frameworks engagements are assessed against.
Ownership, Cadence, and Accountability
Assign engagement leads, reviewers, and supervisors, schedule the audit plan, and route charter, scope, and report approvals through workflows.
Evidence Collection and Audit Trail
Attach workpapers, samples, and analytics outputs to each procedure with timestamps and reviewer sign-off in line with the evidence standard.
Engagement Planning and Fieldwork
Plan scope, materiality, and resources from the risk assessment and track procedures, sampling, and supervision through fieldwork.
Framework and Control Alignment
Map engagement procedures to COBIT, ISO/IEC 27001, NIST SP 800-53, and ITIL practices so one test serves several frameworks.
Reporting and Follow-Up
Produce reports under the 1400 series, track findings and management actions, and report status to the audit committee.
Related frameworks

COBIT 2019 is a governance framework that helps organizations govern and manage IT to meet business goals, risks, and compliance.

ITIL 4 is a service management framework that helps organizations align IT services with business goals and improve service delivery.

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

NIST SP 800-53 Rev. 5 provides a catalog of security and privacy controls to manage risks to information systems.

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.

ISAE 3000 is an international assurance standard for independent assessments of nonfinancial information, internal controls, risk management, and compliance.
Frequently Asked Questions For ISACA ITAF
ITAF, the IT Audit Framework, is ISACA's professional practices framework for IT audit. It establishes standards for practitioners' roles, ethics, and competencies, defines IT audit terms, and provides guidance and techniques for planning, performing, and reporting IT audit and assurance engagements.
The standards are mandatory requirements for ISACA-certified practitioners, while the guidelines are recommended guidance designed to help practitioners achieve alignment with the standards. Tools and techniques are supporting material.
Standards fall into general standards (1000 series), performance standards (1200 series), and reporting standards (1400 series). Guidelines mirror them in the 2000, 2200, and 2400 series, and tools and techniques such as audit programs and white papers support both.
ISACA released ITAF, 5th Edition, on 26 February 2026. The 4th edition, released in October 2020, remains the edition many programs cite; the 5th edition modernizes it for cloud, AI, automation, analytics, agile auditing, continuous assurance, and digital trust.
Yes. ISACA makes ITAF and its translations available free of charge for download.
COBIT is ISACA's governance and management framework for enterprise IT and supplies objectives and practices that IT audits assess against; ITAF governs how the audit itself is performed and reported. The two are designed to be used together.
SmartSuite holds the audit universe, risk assessment, engagement plans, workpapers, evidence, findings, and follow-up in one workspace, mapped to the control frameworks each engagement tests, so conformance with ITAF's standards is documented as the work proceeds.
Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.

