Pre-Screening Interview Questions to Ask an IT Auditor

Last updated on

An audit that tests whether a control exists rather than whether it works finds nothing. These questions test evidence, judgement and what happened when someone disagreed.

TL;DR, what to screen for

The best pre-screening questions for an IT auditor test four things: audits that produced findings which changed something, whether testing examines operating effectiveness rather than existence, whether findings are written so they get acted on, and whether they hold a finding under pushback. Ask about a finding management disputed.

  • Findings that changed things
  • Tests effectiveness
  • Written to be acted on
  • Held under pushback

Why pre-screen IT auditors before the interview

There is a large difference between confirming a policy exists and testing whether the control operated on every one of the last two hundred changes. The second finds things; the first produces a clean report. Auditors worth hiring sample and test, and have had a finding disputed by someone senior. A short screen asks about that dispute, which reveals both method and backbone.

What actually matters when screening IT Auditor candidates

  1. 01

    Technical depth

    Check command of ITGC domains: access provisioning reviews, change management, job scheduling, and backup testing across SAP, Active Directory, or Oracle, plus COBIT, ISO 27001, and CISA credentials.

  2. 02

    Real incidents and findings

    Probe actual findings raised: segregation of duties conflicts, orphaned privileged accounts, unapproved production changes. Ask for evidence gathered, workpaper structure, and how management disputed the exception.

  3. 03

    Risk judgement

    Assess how they rate residual risk versus inherent risk, decide which exceptions are material to SOX, and scope audits when systems and time are limited.

  4. 04

    Getting things fixed

    Test follow-through on remediation: tracking management action plans, retesting closed items, escalating overdue findings to the audit committee, and negotiating realistic dates with IT leadership.

Pre-screening questions to ask IT Auditor candidates

12 questions grouped by what they test. Ask the same set in every screen and score answers on a consistent scale, or send them as an async video screen and compare answers side by side.

Findings that changed things

3 questions
  1. 01Can you describe a situation where your findings led to significant change?

    Listen for

    A finding that produced a real control change, with how it was evidenced and escalated described.

    Findings issued with no remediation, or changes claimed with no follow-up verification.

  2. 02Do you have experience improving internal control procedures?

    Listen for

    Controls redesigned to be workable, with the business consulted so the new control is actually followed.

    Controls recommended that teams cannot follow, or design done without operational input.

  3. 03Do you have experience with forensic or investigative audits?

    Listen for

    Evidence handling and confidentiality treated carefully, with legal and HR involved appropriately.

    Investigations conducted without HR or legal, or evidence handled without preservation.

Tests effectiveness

4 questions
  1. 04How do you go about planning an IT audit?

    Listen for

    Scope driven by risk with the highest exposure areas prioritised, and the plan agreed before fieldwork.

    Scope copied from last year's audit, or planning driven by what is easy to test.

  2. 05What types of evidence would you look for during an audit?

    Listen for

    Evidence extracted independently from systems, with samples tested rather than assurances accepted.

    Screenshots accepted from the audited team, or evidence limited to policy documents.

  3. 06Are you familiar with data analysis tools for audit work?

    Listen for

    Full population testing where data allows, rather than small samples chosen for convenience.

    Sampling used where the whole population could be tested, or no data analysis capability.

  4. 07Describe a situation where your attention to detail uncovered an issue.

    Listen for

    A finding that came from following a discrepancy rather than from a checklist item.

    Findings that all came from a standard programme, or no issue found outside the planned tests.

Written to be acted on

2 questions
  1. 08What steps do you take when preparing an audit report?

    Listen for

    Findings written with the risk, the evidence and a practical recommendation, rated defensibly.

    Reports that list observations without risk, or ratings assigned with no consistent basis.

  2. 09How confident are you conveying technical findings to a non-technical audience?

    Listen for

    Findings expressed as business consequence, so a committee can decide without technical translation.

    Reports written in technical language, or severity not explained in terms the business understands.

Held under pushback

3 questions
  1. 10How have you handled people who disagreed with your findings?

    Listen for

    A position held with evidence, with the finding revised only where the evidence genuinely changed.

    Findings downgraded under pressure, or disputes resolved by removing the finding entirely.

  2. 11Can you discuss your knowledge of security and compliance frameworks?

    Listen for

    Frameworks applied to test real controls, with an understanding of what each does and does not cover.

    Frameworks used as checklists, or certification treated as evidence that controls operate.

  3. 12Do you have experience working alongside external auditors?

    Listen for

    Constructive working relationship with reliance and duplication managed sensibly between the two.

    External audit treated as an adversary, or internal work duplicated without coordination.

How to score responses

Score every candidate on the same four criteria immediately after the screen. At this stage you are shortlisting for panel interviews, not making the final call.

  1. Technical depth

    35%

    5Names specific control objectives, walks through sampling logic for user access reviews, and cites frameworks applied on real audit engagements.

  2. Real incidents and findings

    30%

    5Describes named findings with root cause, evidence trail, severity rating, and how the issue survived challenge from IT owners.

  3. Risk judgement

    20%

    5Distinguishes a control deficiency from a significant deficiency with reasoning, and justifies scoping decisions against financial statement relevance.

  4. Getting things fixed

    15%

    5Shows closure rates or retest outcomes, and explains how they held owners to dates without losing working relationships.

Confirming a policy exists is not testing whether the control operated. A one-way video screen asks about a disputed finding.

Try it on Hirevire

Screening FAQ

Process basics

How long should a pre-screening round for this role take?

Fifteen minutes across eight to ten questions, answered async. Enough to establish findings that changed something, test their evidence approach, and hear how they handled a dispute.

How technical does an IT auditor need to be?

Technical enough to extract and interrogate evidence themselves. An auditor who accepts screenshots from the team being audited is verifying what they were shown rather than what happened.

Evaluating answers

What is the strongest signal when screening this role?

A finding management disputed and how it was resolved. Auditors with substance have one. Anyone whose findings were always accepted may not have found anything uncomfortable.

How do I judge their testing method?

Ask how they test a change control process. Real answers describe sampling actual changes and tracing evidence. Anyone who reviews the procedure document is testing existence, not effectiveness.

Go deeper on this role

Sanat Hegde
Sanat Hegde
Founder, Hirevire

Sanat has been hiring since 2012 and watching the recruitment industry change up close ever since, and turned that screening process into Hirevire's video screening platform. LinkedIn

Trusted by 500+ Companies

Screen IT Auditor candidates on Hirevire

Turn this question list into an async video screen in minutes. Every applicant answers the same evidence, findings and independence questions on camera, so you compare judgement rather than certifications.