Learning path
IT Audit Learning Path
Become the CPA everyone trusts with IT controls, SOC and tech risk.
A practical, CPA-led IT auditing path built for SOX, SOC and internal audit work — not for IT engineers.
Most courses included. The following courses on this learning path require the Premium planOffensive and Defensive Security4.5 CPESOC 2 Assessment Capstone5.5 CPESee the Premium plan
Why CPAs are being asked to learn IT auditing.
Modern audits don’t fail because of debits and credits. They fail because of systems, access and controls. Today’s auditors are expected to do all of this:
Evaluate IT general controls
ITGCs sit underneath every application control you rely on. If they fail, the rest is unreliable too.
Read SOC 1 and SOC 2 reports
They land in the file whether or not anyone on the engagement can tell you what they don’t cover.
Assess cloud systems and SaaS
The controls you depend on now live inside someone else’s environment, under a shared responsibility model.
Identify technology risk
Access, change and availability shape the financial statements as directly as any estimate.
Most CPAs were never formally trained in any of it. This path fixes that — without turning you into an IT specialist.
Your complete learning journey.
Nine courses in three stages. Each course assumes the one before it, and the last one puts the whole path to work on a single SOC 2 engagement.
Learn the terrain
What IT risk is, what an IT audit is for, and what the systems underneath it actually are.
IT Risk and Control Fundamentals
The essentials of IT risk management, controls and governance frameworks, for professionals who need to understand today’s digital risks and compliance requirements.
Principles of IT Audit
The types of IT audit, the audit lifecycle, and how to write clear, actionable audit reports — with real-world case studies connecting the theory to practice.
IT Infrastructure and Cloud Basics
Servers, networks and cloud service models, introduced from the ground up, with the security, compliance and audit considerations attached to each.
Test the controls
The four areas carrying most of the risk in an IT-dependent audit — and how to test each one.
Auditing ITGCs and Application Controls
How to evaluate design and operating effectiveness, spot the red flags that surface first, and document findings — worked through real engagement examples.
Network Security and Infrastructure Auditing
Evaluating and testing network security from an auditor’s seat: network architectures, infrastructure as code, vulnerability scanning and penetration testing.
Auditing Software Development and DevOps
SDLC controls, CI/CD pipelines, code repositories and security testing — how to assess risk and evaluate evidence in a fast-moving development shop.
Auditing Identity and Access Management
A deep dive into IAM: how to evaluate access controls, identify risk, and assess provisioning and privileged access across modern systems.
Run the engagement
How attacks and defences work, then a full SOC 2 examination worked start to finish.
Offensive and Defensive Security
How organisations actually defend themselves — red teams, blue teams and incident response — with the real tools and attack simulations behind each.
SOC 2 Assessment Capstone
A complete SOC 2 examination from start to finish: evaluating system controls, testing operating effectiveness, interpreting the Trust Services Criteria and assembling a full report on one case study.
Your instructor
Michael Carroll, CPA, CISA, CISM
Michael is an accounting and information security professional, and an adjunct professor at several institutions, where he teaches accounting and information technology courses.
He earned his MBA in Accounting and a B.S. in Accounting / Accounting Information Systems from Canisius University. He is a Certified Public Accountant and a Certified Information Systems Security Professional, a current member of the NYCPA’s Education Committee, and an Advisory Board Member for the Academy of Finance since 2020.
What you’ll be able to do.
By the end of the path, you will be able to:
- Walk into IT-dependent audits with confidence
- Evaluate access controls, change management and system risk
- Support SOX, SOC 1 and SOC 2 engagements
- Speak fluently with IT teams — and challenge a weak explanation
- Position yourself for IT audit, internal audit and advisory roles
Durable skill for CPAs in a technology-driven profession.
Who it’s for.
The path is built for professionals who are:
- CPAs or auditors expanding into IT-dependent audits
- Supporting SOX, SOC 1 or SOC 2 engagements
- Working in internal audit or risk advisory
- Moving from financial audit into IT audit
- Early-career and building future-ready audit skills
If your work touches technology, controls or compliance, this path is built for you.
How each course works.
Self-paced
Video, on your schedule.
Start, stop and come back. Your place is kept.
Assessed
A final exam on each course.
Work through the lessons, then pass the final exam to complete the course — the standard a NASBA sponsor has to hold.
Credited
Your CPE record, kept for you.
NASBA credit for each course is filed to your record the moment you pass.
Take the next step in your IT auditing journey.
- All nine courses published and available now
- Expert CPA-led instruction
- 40.5 NASBA CPE, filed to your record automatically
Most courses included. The following courses on this learning path require the Premium planOffensive and Defensive Security4.5 CPESOC 2 Assessment Capstone5.5 CPESee the Premium plan
