Why pre-screen IT auditors before the interview
There is a large difference between confirming a policy exists and testing whether the control operated on every one of the last two hundred changes. The second finds things; the first produces a clean report. Auditors worth hiring sample and test, and have had a finding disputed by someone senior. A short screen asks about that dispute, which reveals both method and backbone.
What actually matters when screening IT Auditor candidates
- 01
Technical depth
Check command of ITGC domains: access provisioning reviews, change management, job scheduling, and backup testing across SAP, Active Directory, or Oracle, plus COBIT, ISO 27001, and CISA credentials.
- 02
Real incidents and findings
Probe actual findings raised: segregation of duties conflicts, orphaned privileged accounts, unapproved production changes. Ask for evidence gathered, workpaper structure, and how management disputed the exception.
- 03
Risk judgement
Assess how they rate residual risk versus inherent risk, decide which exceptions are material to SOX, and scope audits when systems and time are limited.
- 04
Getting things fixed
Test follow-through on remediation: tracking management action plans, retesting closed items, escalating overdue findings to the audit committee, and negotiating realistic dates with IT leadership.
Pre-screening questions to ask IT Auditor candidates
12 questions grouped by what they test. Ask the same set in every screen and score answers on a consistent scale, or send them as an async video screen and compare answers side by side.
Findings that changed things
3 questions01Can you describe a situation where your findings led to significant change?
Listen forA finding that produced a real control change, with how it was evidenced and escalated described.
Findings issued with no remediation, or changes claimed with no follow-up verification.
02Do you have experience improving internal control procedures?
Listen forControls redesigned to be workable, with the business consulted so the new control is actually followed.
Controls recommended that teams cannot follow, or design done without operational input.
03Do you have experience with forensic or investigative audits?
Listen forEvidence handling and confidentiality treated carefully, with legal and HR involved appropriately.
Investigations conducted without HR or legal, or evidence handled without preservation.
Tests effectiveness
4 questions04How do you go about planning an IT audit?
Listen forScope driven by risk with the highest exposure areas prioritised, and the plan agreed before fieldwork.
Scope copied from last year's audit, or planning driven by what is easy to test.
05What types of evidence would you look for during an audit?
Listen forEvidence extracted independently from systems, with samples tested rather than assurances accepted.
Screenshots accepted from the audited team, or evidence limited to policy documents.
06Are you familiar with data analysis tools for audit work?
Listen forFull population testing where data allows, rather than small samples chosen for convenience.
Sampling used where the whole population could be tested, or no data analysis capability.
07Describe a situation where your attention to detail uncovered an issue.
Listen forA finding that came from following a discrepancy rather than from a checklist item.
Findings that all came from a standard programme, or no issue found outside the planned tests.
Written to be acted on
2 questions08What steps do you take when preparing an audit report?
Listen forFindings written with the risk, the evidence and a practical recommendation, rated defensibly.
Reports that list observations without risk, or ratings assigned with no consistent basis.
09How confident are you conveying technical findings to a non-technical audience?
Listen forFindings expressed as business consequence, so a committee can decide without technical translation.
Reports written in technical language, or severity not explained in terms the business understands.
Held under pushback
3 questions10How have you handled people who disagreed with your findings?
Listen forA position held with evidence, with the finding revised only where the evidence genuinely changed.
Findings downgraded under pressure, or disputes resolved by removing the finding entirely.
11Can you discuss your knowledge of security and compliance frameworks?
Listen forFrameworks applied to test real controls, with an understanding of what each does and does not cover.
Frameworks used as checklists, or certification treated as evidence that controls operate.
12Do you have experience working alongside external auditors?
Listen forConstructive working relationship with reliance and duplication managed sensibly between the two.
External audit treated as an adversary, or internal work duplicated without coordination.
How to score responses
Score every candidate on the same four criteria immediately after the screen. At this stage you are shortlisting for panel interviews, not making the final call.
Technical depth
35%5Names specific control objectives, walks through sampling logic for user access reviews, and cites frameworks applied on real audit engagements.
Real incidents and findings
30%5Describes named findings with root cause, evidence trail, severity rating, and how the issue survived challenge from IT owners.
Risk judgement
20%5Distinguishes a control deficiency from a significant deficiency with reasoning, and justifies scoping decisions against financial statement relevance.
Getting things fixed
15%5Shows closure rates or retest outcomes, and explains how they held owners to dates without losing working relationships.
Confirming a policy exists is not testing whether the control operated. A one-way video screen asks about a disputed finding.
Try it on HirevireScreening FAQ
Process basics
How long should a pre-screening round for this role take?
Fifteen minutes across eight to ten questions, answered async. Enough to establish findings that changed something, test their evidence approach, and hear how they handled a dispute.
How technical does an IT auditor need to be?
Technical enough to extract and interrogate evidence themselves. An auditor who accepts screenshots from the team being audited is verifying what they were shown rather than what happened.
Evaluating answers
What is the strongest signal when screening this role?
A finding management disputed and how it was resolved. Auditors with substance have one. Anyone whose findings were always accepted may not have found anything uncomfortable.
How do I judge their testing method?
Ask how they test a change control process. Real answers describe sampling actual changes and tracing evidence. Anyone who reviews the procedure document is testing existence, not effectiveness.
























