IT Governance & Service Management
DETAIL

ISACA ITAF – IT Audit Framework: A Professional Practices Framework for IT Audit

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

Overview

ISACA's IT Audit Framework (ITAF) is a professional practices framework for IT audit. It establishes standards that address IT audit and assurance practitioners' roles and responsibilities, ethics, expected professional behavior, and required knowledge and skills; defines terms and concepts specific to IT audit and assurance; and provides guidance and techniques for the planning, performing, and reporting of IT audit and assurance engagements. Its standards are mandatory for ISACA-certified professionals, and its guidelines and tools support their application.

ISACA publishes ITAF and makes it available free of charge. The 4th edition, released in October 2020, updated the 2014 edition with expanded IT-specific guidance, a stronger emphasis on risk assessment in audit planning, and a restructured format; it is the edition most GRC and audit programs still cite. ISACA released the 5th edition on 26 February 2026, modernizing the framework for cloud, artificial intelligence, business automation, data analytics, agile auditing, continuous assurance, and digital trust, and updating the companion guideline 2208 on IT audit sampling.

IT audit functions implement ITAF by adopting its general standards as the charter and conduct rules for the function, applying its performance standards to plan, execute, and supervise each engagement, and following its reporting standards for communicating results and following up on findings. The guidelines and tools translate the standards into practice, and many organizations align ITAF engagements with COBIT for governance objectives and with the IIA's Global Internal Audit Standards where IT audit sits inside internal audit.

Why it Matters

IT audit findings are only as credible as the standards behind them, and regulators, audit committees, and external auditors expect IT assurance work to follow a recognized professional framework. ITAF is that framework for the IT audit profession: it is the basis of ISACA's certifications, it is free, and its structure of standards, guidelines, and tools maps directly onto how an engagement is planned, performed, and reported.

Key benefits include:

  • Mandatory professional standards

ITAF standards are binding on ISACA-certified practitioners, giving IT audit work a defined professional baseline that stakeholders can rely on.

  • Coverage of the whole engagement

General, performance, and reporting standards address independence and competence, planning and evidence, and reporting and follow-up in one framework.

  • Guidelines that show how

Each series of standards is mirrored by guidelines that explain how to meet them, with tools and techniques such as audit programs and white papers.

  • Current with technology

The 5th edition addresses cloud architectures, AI and automation, data-driven testing, continuous assurance, and governance accountability.

  • Free and widely translated

ISACA publishes ITAF and its translations at no cost, so functions of any size can adopt it.

How it Works

ITAF is built in three layers. The standards are organized as general standards (1000 series), which set the guiding principles under which the IS assurance profession operates, including the audit charter, organizational and professional independence, reasonable expectation, due professional care, proficiency, assertions, and criteria; performance standards (1200 series), which address the conduct of the engagement, including engagement planning, risk assessment in planning, performance and supervision, materiality, evidence, using the work of other experts, and irregularities and illegal acts; and reporting standards (1400 series), which address reporting and follow-up activities. The guidelines mirror the standards in the 2000, 2200, and 2400 series and are designed to directly support them, and the tools and techniques include white papers, audit and assurance programs, and reference material such as the COBIT family.

An IT audit function applies ITAF by establishing its charter and independence under the general standards, planning each engagement with a risk assessment and defined scope, materiality, and resources under the performance standards, gathering and evaluating evidence with appropriate supervision, and reporting findings with clear conclusions and follow-up under the reporting standards. Guideline 2208 governs audit sampling; other guidelines cover topics such as using the work of other experts and reporting. The 5th edition's shifts, from isolated controls to digital ecosystems, from periodic reviews to continuous insight, from sampling to data-driven testing, and from operational focus to governance and accountability, change how those steps are carried out rather than the standards' structure.

Within SmartSuite, IT audit teams run ITAF engagements as connected records: the audit universe and risk assessment drive the plan, each engagement carries its scope, materiality, program, and staffing, workpapers and evidence attach to the procedures they support with reviewer sign-off, and findings flow into reports and follow-up tracking, so conformance with the general, performance, and reporting standards is documented as the engagement proceeds.

Key Elements

  • General standards (1000 series)

Guiding principles for the profession: audit charter, organizational independence, professional independence, reasonable expectation, due professional care, proficiency, assertions, and criteria.

  • Performance standards (1200 series)

Conduct of the engagement: engagement planning, risk assessment in planning, performance and supervision, materiality, evidence, using the work of other experts, and irregularity and illegal acts.

  • Reporting standards (1400 series)

Reporting and follow-up activities, covering the types of reports, the means of communication, and the information communicated.

  • Guidelines (2000, 2200, and 2400 series)

Recommended guidance that mirrors each standard and explains how to achieve alignment with it, including guideline 2208 on IT audit sampling.

  • Tools and techniques

White papers, IS audit and assurance programs, reference books, and related ISACA frameworks that support engagements.

  • Terms and concepts

Definitions specific to IT audit and assurance that give engagements a common vocabulary.

  • Digital trust and emerging technology coverage

The 5th edition integrates digital trust concepts and guidance on cloud, AI, automation, analytics, agile auditing, and continuous assurance.

Framework Scope

ITAF applies to IT audit and assurance engagements performed by practitioners in organizations of all sizes and sectors, whether in internal audit, external assurance, or specialist IT audit functions. Its standards are mandatory for holders of ISACA certifications such as CISA, and its guidelines are recommended practice. The framework covers the conduct of engagements and the professional obligations of practitioners; it does not itself define control objectives, which come from frameworks such as COBIT, ISO/IEC 27001, and NIST SP 800-53 that ITAF engagements assess against.

Framework Objectives

ITAF exists so that IT audit and assurance work is performed to consistent, recognized professional standards.

Define the roles, responsibilities, ethics, and competencies expected of IT audit and assurance practitioners.

Set mandatory standards for the planning, performance, supervision, and reporting of engagements.

Provide guidelines and tools that show practitioners how to meet the standards.

Establish a common vocabulary for IT audit and assurance.

Keep IT audit practice current with cloud, AI, automation, and continuous assurance.

Support the credibility of IT assurance for boards, regulators, and external auditors.

Framework in Context

ITAF is the IT audit companion to ISACA's COBIT 2019 governance framework, which supplies the objectives and practices that ITAF engagements commonly assess, and it operates alongside the IIA's Global Internal Audit Standards where IT audit is part of internal audit. IT audit engagements under ITAF regularly test controls drawn from ISO/IEC 27001, NIST SP 800-53, the NIST Cybersecurity Framework, and ITIL 4 service management practices, and IT general controls work supports the integrated ICFR audit under PCAOB AS 2201 and SOX. Assurance reports under ISAE 3000 and SOC 2 draw on comparable performance and reporting expectations.

Common Framework Mappings

ITAF is commonly mapped to the governance and control frameworks its engagements assess against and to the audit and assurance standards it operates alongside.

Mapped frameworks include:

COBIT 2019

IIA Global Internal Audit Standards

ISO 27001:2022

NIST 800-53 Rev.5

NIST CSF 2.0

ITIL 4

ISAE 3000

SOC 2

SOX

PCAOB AS 2201

At a Glance
ISACA ITAF – IT Audit Framework: A Professional Practices Framework for IT Audit
  • Classification
    Category
    IT Governance & Service Management
    Domain
    IT Governance
    Framework Family
    Other
  • Regulatory Context
    Type
    Standard
    Legal Instrument
    Standard
    Sector
    Cross-Sector
    Industry
    Cross-Industry
  • Region / Publisher
    Region
    Global
    Region Detail
    International
    Publisher
    ISACA
  • Versioning
    Version
    5th Edition (2026); 4th Edition (2020) widely cited
    Effective Date
    February 26, 2026 (5th Edition)
    Issue Date
    October 22, 2020 (4th Edition); February 26, 2026 (5th Edition)
  • Adoption
    Adoption Model
    Industry Requirement
    Implementation Complexity
    Medium
  • Official Reference
License Information

License included / downloadable: Yes

ISACA publishes ITAF and its translations free of charge, and its standards structure is included with the platform.

Framework text is licensed by its publisher and is included only where stated above.

Official Resources
IT Audit Framework (ITAF), 5th Edition
ISACA's product page for the current edition of ITAF, available for free download.
ISACA press release on ITAF, 5th Edition
The 26 February 2026 announcement of the updated framework and its coverage of cloud, AI, automation, and digital trust.
ISACA Frameworks, Standards and Models
ISACA's overview of ITAF alongside COBIT and its other frameworks.
Why ITAF 5 Matters: Six Big Shifts
ISACA Now blog post describing the shifts in IT audit practice that the 5th edition reflects.
SMARTSUITE

How SmartSuite Supports ISACA ITAF

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.

For ISACA ITAF, SmartSuite runs the audit universe, risk-based plan, engagement programs, workpapers, findings, and follow-up in one workspace, so conformance with the general, performance, and reporting standards is documented as each engagement proceeds.

IT Audit Universe and Standards Library

Hold the ITAF standards and guidelines alongside the audit universe, risk assessment, and control frameworks engagements are assessed against.

Ownership, Cadence, and Accountability

Assign engagement leads, reviewers, and supervisors, schedule the audit plan, and route charter, scope, and report approvals through workflows.

Evidence Collection and Audit Trail

Attach workpapers, samples, and analytics outputs to each procedure with timestamps and reviewer sign-off in line with the evidence standard.

Engagement Planning and Fieldwork

Plan scope, materiality, and resources from the risk assessment and track procedures, sampling, and supervision through fieldwork.

Framework and Control Alignment

Map engagement procedures to COBIT, ISO/IEC 27001, NIST SP 800-53, and ITIL practices so one test serves several frameworks.

Reporting and Follow-Up

Produce reports under the 1400 series, track findings and management actions, and report status to the audit committee.

Related frameworks

COBIT 2019

COBIT 2019 is a governance framework that helps organizations govern and manage IT to meet business goals, risks, and compliance.

ITIL 4

ITIL 4 is a service management framework that helps organizations align IT services with business goals and improve service delivery.

ISO 27001:2022

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

NIST 800-53 Rev.5

NIST SP 800-53 Rev. 5 provides a catalog of security and privacy controls to manage risks to information systems.

NIST CSF 2.0

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.

ISAE 3000

ISAE 3000 is an international assurance standard for independent assessments of nonfinancial information, internal controls, risk management, and compliance.

SOC 2

SOC 2 assesses and reports on a service organization's controls for security, availability, processing integrity, confidentiality, and privacy.

SOX

The Sarbanes-Oxley Act requires public companies to maintain reliable financial reporting and robust internal controls to prevent fraud.

ONBOARDING FAQS

Frequently Asked Questions For ISACA ITAF

What is ISACA ITAF?

ITAF, the IT Audit Framework, is ISACA's professional practices framework for IT audit. It establishes standards for practitioners' roles, ethics, and competencies, defines IT audit terms, and provides guidance and techniques for planning, performing, and reporting IT audit and assurance engagements.

Are ITAF standards mandatory?

The standards are mandatory requirements for ISACA-certified practitioners, while the guidelines are recommended guidance designed to help practitioners achieve alignment with the standards. Tools and techniques are supporting material.

How is ITAF structured?

Standards fall into general standards (1000 series), performance standards (1200 series), and reporting standards (1400 series). Guidelines mirror them in the 2000, 2200, and 2400 series, and tools and techniques such as audit programs and white papers support both.

Which edition is current?

ISACA released ITAF, 5th Edition, on 26 February 2026. The 4th edition, released in October 2020, remains the edition many programs cite; the 5th edition modernizes it for cloud, AI, automation, analytics, agile auditing, continuous assurance, and digital trust.

Is ITAF free?

Yes. ISACA makes ITAF and its translations available free of charge for download.

How does ITAF relate to COBIT?

COBIT is ISACA's governance and management framework for enterprise IT and supplies objectives and practices that IT audits assess against; ITAF governs how the audit itself is performed and reported. The two are designed to be used together.

How does SmartSuite support ITAF?

SmartSuite holds the audit universe, risk assessment, engagement plans, workpapers, evidence, findings, and follow-up in one workspace, mapped to the control frameworks each engagement tests, so conformance with ITAF's standards is documented as the work proceeds.

Operationalize ISACA ITAF with Connected Workflows

Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.