Why Internal Audit Teams Are Struggling to Hire People Who Understand Both IT and the Business

There’s an interesting shift happening in Internal Audit recruitment that we’re seeing more and more: companies aren’t necessarily looking for pure IT Auditors anymore. They’re looking for auditors who understand technology and understand the business.

As organisations become increasingly dependent on ERP systems, cloud platforms, AI and automated processes, the line between traditional Internal Audit and IT Audit is becoming less clear.

A candidate might have spent years auditing finance, procurement or supply chain processes — but if those processes are now heavily dependent on technology, understanding the underlying systems and controls becomes just as important.

The problem with the traditional hiring approach

Historically, hiring managers could fairly easily separate their requirements:

Internal Audit: financial, operational and compliance auditing.

IT Audit: ITGCs, applications, cybersecurity and technology controls.

That distinction is becoming less straightforward.

A modern operational audit might involve reviewing automated controls within SAP.

A procurement audit might require an understanding of system access, segregation of duties and data integrity.

A cybersecurity audit might involve understanding how technology risk impacts the wider business.

This is creating demand for what we would describe as hybrid audit profiles.

What does a hybrid auditor look like?

They don’t necessarily need to be a cybersecurity expert or an IT engineer.

Instead, we’re seeing more value in auditors who can sit comfortably between the business and technology teams.

For example, someone who has:

  • Strong Internal Audit fundamentals
  • Experience auditing ERP environments
  • Exposure to ITGCs or application controls
  • Understanding of data and analytics
  • Experience working with technology or cybersecurity teams
  • The ability to translate technical risks into business risks
  • Strong stakeholder management skills

These candidates can be particularly difficult to find because they don’t always fit neatly into an organisation’s traditional job description.

And that’s where recruitment becomes interesting

Some of the strongest candidates we speak to aren’t actively looking for an “IT Audit” position.

They may see themselves as Internal Auditors who happen to have significant technology exposure.

Equally, an IT Auditor with strong commercial and operational understanding may be capable of moving into a much broader Internal Audit role.

The job title doesn’t always tell the full story.

For hiring managers, this means looking beyond keywords such as Internal Audit or IT Audit when assessing the market.

The better question may be:

Can this person understand the risk, understand the technology behind it, and explain it to the business?

That combination is becoming increasingly valuable.

The recruitment challenge

The difficulty is that these candidates are in demand from several directions — Internal Audit, IT Audit, Cybersecurity, GRC, Risk and Technology Risk teams are all competing for similar skill sets.

And when you add hybrid-working expectations, salary requirements and increasingly specialised roles into the mix, finding the right person becomes considerably more difficult.

For businesses building or strengthening their audit function, the answer may not be hiring a traditional Internal Auditor or a pure IT Auditor. It may be finding someone who can genuinely bridge the two.

From the same category