IT Auditing | Lebone Marang and Summer




IT Consulting and Assurance

Know What Is Really
Happening in Your IT.

Most organisations assume their IT controls are working.
An independent audit tells you whether they actually are —
and gives you the evidence, the findings, and the remediation
path to fix what is not.


Request an Audit Assessment

Book a Discovery Call

Fully Independent Advisory

Info-Tech Research Partner

Controls, Compliance and Assurance


Strategic Partner
Info-Tech Research Group

63%
of organisations have significant IT control gaps they are unaware of until an audit surfaces them
Info-Tech Research Group

more likely to experience a material compliance breach without a structured IT audit programme
Info-Tech Research Group
74%
of audit findings that go unremediated within 90 days recur in the following audit cycle
Info-Tech Research Group

Info-Tech Research Insight

An Assumption Is Not a Control

Info-Tech’s IT Audit and Assurance research consistently finds that the gap between
what organisations believe their controls are doing and what they are actually doing
is where the most serious risks live.

Info-Tech Research Group’s IT Audit framework identifies four phases of a mature
audit programme. Organisations that complete all four phases are significantly more
likely to maintain continuous compliance, reduce repeat findings, and build board-level
confidence in IT governance.
The Four Phases of a Mature IT Audit Programme

01

IT Controls Review

  • Identify and document all in-scope IT controls
  • Test design and operating effectiveness
  • Benchmark against industry standards (COBIT, ISO 27001)
  • Rate control gaps by risk severity


Continuous
Assurance
Cycle

02

Compliance Audits

  • Assess compliance against regulatory requirements
  • Map controls to King IV, POPIA, GDPR as applicable
  • Identify compliance exposure and remediation priority
  • Produce auditable compliance evidence


03

Findings Remediation

  • Develop a prioritised remediation action plan
  • Assign ownership and accountability for each finding
  • Track remediation progress against agreed timelines
  • Validate closure before sign-off


04

Assurance Reporting

  • Executive and board-ready assurance reports
  • Risk-rated findings with clear management actions
  • Trend analysis across audit cycles
  • Continuous improvement recommendations

The Challenges We Help You Solve

Does Any of This Sound Familiar?

These are the six most common IT audit and assurance failures that Info-Tech’s
research surfaces across organisations. If more than two resonate,
your audit programme needs attention now.

Controls That Exist on Paper Only

Documented controls that have never been tested, are no longer enforced, or do not reflect how the organisation actually operates.

Compliance Exposure You Cannot See

Regulatory requirements — King IV, POPIA, sector-specific mandates — that the organisation is not meeting, without knowing it yet.

Findings That Keep Coming Back

The same audit findings appearing cycle after cycle because there is no structured remediation programme to close them properly.

Reports That Do Not Drive Action

Audit reports that are technically correct but written for auditors rather than executives — so they sit unread and nothing changes.

No Audit Programme at All

IT audits happen reactively — after an incident, a regulator request, or a board question — rather than as a proactive governance discipline.

No Accountability for Remediation

Findings are identified but no one owns them. Without clear accountability and tracking, remediation stalls and risk accumulates quietly.

Info-Tech Research Group finds that organisations without a structured IT audit
programme are 3× more likely to experience a material compliance breach
and that the average cost of a compliance breach is significantly higher than the
cost of the audit programme that would have prevented it.

Our Approach and Deliverables

Independent. Evidence-Based. Action-Oriented.

We do not just identify what is wrong. We give you a clear, prioritised,
accountable path to fix it — and the reporting your board and executives
need to understand the risk landscape and act with confidence.

01
How We Work

  • IT controls identification, documentation, and effectiveness testing
  • Compliance gap assessment mapped to King IV, POPIA, ISO 27001, and sector requirements
  • Risk-rated findings with root cause analysis for each control gap
  • Prioritised remediation planning with assigned ownership and timelines
  • Remediation tracking and closure validation before sign-off
  • Executive and board-ready assurance reporting throughout
  • Trend analysis and continuous improvement recommendations across cycles

What You Receive

  • IT Controls Assessment Report
  • Compliance Gap Analysis (mapped to applicable frameworks)
  • Risk-Rated Findings Register
  • Remediation Action Plan with ownership matrix
  • Remediation Progress Tracking Dashboard
  • Closure Validation Report
  • Executive Assurance Report
  • Board-Ready Risk Summary

Business Outcomes We Deliver

Organisations partnering with us can expect to:

  • Gain accurate visibility into the real state of IT controls
  • Reduce compliance exposure and regulatory risk materially
  • Break the cycle of repeat findings through structured remediation
  • Give executives and the board confidence in IT governance
  • Build a proactive audit programme rather than a reactive one
  • Demonstrate assurance to regulators, customers, and stakeholders
  • Improve overall IT governance maturity over successive audit cycles

Why Lebone Marang and Summer

We are entirely independent. We have no relationship with your technology vendors, no implementation work to protect, and no incentive to soften findings. You get an honest picture of where your IT controls stand.

Our audit methodology is grounded in Info-Tech Research Group’s IT Audit and Assurance framework — giving you access to global benchmarks, maturity models, and best practice standards at every stage of the engagement.

We write for executives, not for auditors. Every report we produce is designed to drive decisions and actions, not to sit in a filing system.

Know the Truth. Fix What Matters. Build Lasting Assurance.

Strategic Outcomes

What Changes After the Engagement

These are the measurable shifts organisations experience when IT audit moves
from a reactive compliance exercise to a proactive governance discipline.


Full Control Visibility

You know exactly which controls are working, which are not, and why


Reduced Compliance Risk

Regulatory exposure is identified and remediated before it becomes a breach


Findings That Get Fixed

Structured remediation means findings close and do not return in the next cycle


Growing Audit Maturity

Each audit cycle builds on the last, progressively strengthening governance across the organisation

Are your IT controls actually working?

There is only one way to know for certain. Let us run an independent
assessment and give you an honest picture — with a clear path forward.



Request an Audit Assessment

Book a Discovery Call