Become the CPA Everyone Trusts with IT Controls, SOC, and Tech Risk
9 Courses | 40.5 NASBA CPEs
The IT Auditing Learning Path is a practical, CPA-led IT Auditing learning path designed for SOX, SOC, and internal audit work — not IT engineers.
Why CPAs are being forced to learn IT Auditing
Modern audits don’t fail because of debits and credits — they fail because of systems, access, and controls.
Today’s auditors are expected to:
- Evaluate IT General Controls (ITGCs)
- Understand SOC 1 / SOC 2 reports
- Assess cloud systems and SaaS platforms
- Identify technology risks that impact financial reporting
Most CPAs were never formally trained in this. This learning path fixes that — without turning you into an IT specialist.
Our Complete Learning Journey

IT Risk and Control Fundamentals
Learn the essentials of IT risk management, controls, and governance frameworks in this introductory course designed for professionals seeking to understand today’s digital risks and compliance requirements.
📖 4.5 CPE Credits

Principles of IT Audit
Master the essentials of IT auditing with this beginner-friendly course. Learn the different types of IT audits, the audit lifecycle, and how to write clear, actionable audit reports—all with real-world case studies to connect theory to practice.
📖 4.5 CPE Credits

IT Infrastructure and Cloud Basics
Learn the fundamentals of IT infrastructure and cloud computing. This course introduces servers, networks, and cloud service models while highlighting key security, compliance, and audit considerations.
📖 4.5 CPE Credits

Auditing ITGCs and Application Controls
Master the essentials of auditing IT general controls (ITGCs) and application controls. Learn how to evaluate design and operating effectiveness, identify red flags, and document audit findings through real-world case studies and practical examples.
📖 4.0 CPE Credits

Network Security and Infrastructure Auditing
Learn how to evaluate and test network security and IT infrastructure from an auditor’s perspective. This course covers network architectures, Infrastructure as Code (IaC), vulnerability scanning, and penetration testing, equipping you with the skills to identify risks and ensure organizations maintain secure and compliant environments.
📖 3.5 CPE Credits

Auditing Software Development and DevOps
Learn how to audit modern software development and DevOps environments. This course explores SDLC controls, CI/CD pipelines, code repositories, and security testing—helping auditors assess risk, evaluate evidence, and ensure strong governance in fast-paced development settings.
📖 4.5 CPE Credits

Auditing Identity and Access Management
Strengthen your audit expertise with a deep dive into Identity and Access Management (IAM). Learn how to evaluate access controls, identify risks, and assess IAM processes to ensure data security and compliance across modern systems.
📖 5.0 CPE Credits

Offensive and Defensive Security
Learn how organizations defend against cyber threats by exploring offensive security (red teams), defensive security (blue teams), and incident response fundamentals. This beginner-friendly course introduces real-world tools, attack simulations, and practical strategies used to strengthen cybersecurity resilience.
📖 4.5 CPE Credits

Soc 2 Assessment Capstone
The SOC 2 Assessment Capstone guides you through a complete SOC 2 examination from start to finish. You’ll learn how auditors evaluate system controls, test operating effectiveness, interpret the Trust Services Criteria, and assemble a full SOC 2 report using a real-world case study. Ideal for professionals looking to deepen their IT audit and information security skills.
📖 5.5 CPE Credits
Michael Carroll, CPA, CISA, CISM
Michael is an accounting and information security professional. He is also an Adjunct Professor at several higher education institutions, where he is responsible for teaching various accounting and information technology courses.
Michael earned his MBA in Accounting and B.S. in Accounting / Accounting Information Systems from Canisius University. Additionally, Michael is a Certified Public Accountant (CPA) and a Certified Information Systems Security Professional (CISSP). Michael is a current member of the NYCPA’s Education Committee and has been an Advisory Board Member for the Academy of Finance (AOF) since 2020.
Michael enjoys traveling, hiking, and watching the Buffalo Bills. He has also participated in several marathon events.
📖
What This Unlocks for You
By the end of this program, you will be able to:
✔ Walk into IT-dependent audits with confidence
✔ Evaluate access controls, change management, and system risks
✔ Support SOX, SOC, and internal audit engagements
✔ Speak fluently with IT teams — and challenge weak explanations
✔ Position yourself for IT audit, internal audit, and advisory roles
This is career insurance for CPAs in a technology-driven profession!
👥
Who Should Enroll
This learning path is ideal for professionals who are:
✔ CPAs or auditors expanding into IT-dependent audits
✔ Supporting SOX, SOC 1, or SOC 2 engagements
✔ Working in internal audit or risk advisory functions
✔ Transitioning from financial audit into IT audit roles
✔ Early-career professionals building durable, future-ready audit skills
If your work touches technology, controls, or compliance — this path is built for you.
Take the Next Step in Your IT Auditing Journey
✅ Immediate access to published courses.
✅ Expert CPA – led instruction.
✅ Build in-demand IT auditing skills that set you apart in a technology-driven world.
You don’t just want exposure to IT auditing.
You want a clear, structured path to mastery — and this is it.