Skip to content
Review Open access

Risk-Based IT Auditing and Cybersecurity Assurance in Regulated U.S. Organizations: A Review of Governance, Methods, and Outcomes

Jul 2026 · Magna Scientia Advanced Research and Reviews · 0 citations

TL;DR

This review synthesizes peer-reviewed literature on governance structures, auditing methods, and resulting outcomes across key sectors including financial services, capital markets, healthcare, and critical infrastructure to reveal consistent emphasis on integrated governance approaches alongside persistent implementation tensions.

Abstract

Risk-based IT auditing and cybersecurity assurance have become central mechanisms for protecting regulated organizations amid evolving digital threats. This review synthesizes peer-reviewed literature on governance structures, auditing methods, and resulting outcomes across key sectors including financial services, capital markets, healthcare, and critical infrastructure. Drawing from a broad body of literature, it examines how regulatory frameworks shape risk identification and control deployment while highlighting assurance practices that contribute to measurable improvements in threat mitigation and compliance. The analysis reveals consistent emphasis on integrated governance approaches alongside persistent implementation tensions, such as mismatches between risk-based ideals and practical application. Key insights underscore the role of adaptive controls, outcome-focused assurance, and sector-specific adaptations in enhancing overall cybersecurity posture. The review also identifies areas where current practices fall short, offering grounded directions for advancing both theory and practice in regulated environments.

Read PDF

Similar papers

Review Open access Jul 2026

A Critical Integrative Review of Technology Assurance for Operational Resilience in U.S. Regulated Organizations

Technology assurance practices have become central to efforts aimed at strengthening operational resilience across U.S. regulated sectors, including finance, healthcare, and critical infrastructure. This integrative review examines how audits, compliance mechanisms, governance frameworks, and emerging-technology controls are discussed in the recent peer-reviewed literature. Drawing on a synthesis of recent peer-reviewed studies, the analysis reveals recurring attention to traditional compliance-oriented approaches alongside growing interest in adaptive practices and data-protection balances. Studies consistently identify resource constraints, static checklists, and dynamic threats as barriers that limit the translation of assurance activities into sustained resilience. In financial and healthcare contexts, audits and regulatory implementation show promise for risk mitigation but frequently lack integration with broader operational strategies. Similar patterns appear in utility-sector discussions of cyber-physical threats and in examinations of AI governance, where qualitative reviews emphasize ethical and compliance balances without extensive empirical outcome data. Disclosure quality and framework application are linked to market or organizational responses, yet long-term quantitative evaluation remains underdeveloped. Overall, the literature suggests alignment around the identification of barriers and the need for adaptive cultures, while remaining fragmented on consistent linkages to resilience outcomes and silent on cross-sector empirical validation. These insights point to practical implications for regulated organizations seeking to move beyond compliance checklists toward more responsive assurance systems. The review contributes a grounded perspective on current evidence and highlights targeted areas for future inquiry.

Matilda Konotey, Daniel Bamfo, G. Apaflo · 0 citations
Review Open access Aug 2026

From It Audit Findings to Cybersecurity Governance: A Risk-Based Remediation Framework for Critical Digital Infrastructure

An IT audit finding does not reduce risk. Risk falls only when an organisation understands the finding, connects it to a critical system or business service, determines its risk level, assigns an accountable owner, implements a treatment, verifies that the treatment worked, formally addresses whatever risk remains, and reports progress to those charged with oversight. Evidence from the auditing and information systems literatures indicates that this chain breaks routinely, and that findings accumulate as open items rather than closing as reduced exposure. This article asks how organisations can convert audit findings into prioritised, accountable, measurable, and verified remediation, with particular attention to critical digital infrastructure, where an unremediated weakness affects service continuity for dependent sectors rather than the audited organisation alone. Using a structured narrative literature review of thirty peer-reviewed sources and seven authoritative frameworks, the review identifies four recurring failure modes: findings disconnected from business impact, ownership that is nominal rather than accountable, verification treated as administrative closure, and residual risk accepted informally. Drawing on enterprise risk management integration guidance, governance accountability models, and exploit-based prioritization research, the article proposes an eleven- stage risk-based remediation framework running from finding validation through continuous monitoring, together with eight measures spanning timeliness, ownership, verification quality, and business linkage. The framework is proposed rather than empirically validated, and no claim is made that it has produced measured improvement in any organisation

Josephat Deogratius Katundabwile, David Mbui Kamau · 0 citations
Review Open access Aug 2026

CYBER-AUDITING THE FUTURE: HOW CONCEPTUAL FOUNDATION OF DIGITAL ASSURANCE REDEFINES RISK, ACCOUNTABILITY, AND TRANSPARENCY IN MULTINATIONAL FIRMS

The rapid digitalization of global business operations and escalating cyber risks have redefined assurance and accountability in multinational firms. This study examines how cyber-auditing and Conceptual Foundation of Digital Assurance reshape auditors' roles in mitigating digital risks and enhancing transparency across complex cross-jurisdictional environments. Employing a Systematic Literature Review (SLR) integrated with the Manual Data Analysis Procedure (MDAP), the study synthesizes evidence from forty Scopus Q1 journal articles published between 2022 and 2025 using open, axial, and selective coding. The findings demonstrate that cyber-auditing functions as a continuous, technology-enabled risk mitigation mechanism by integrating automation, data analytics, and artificial intelligence into audit practices. Conceptual Foundation of Digital Assurance further strengthens the credibility of ESG and sustainability reporting by reinforcing transparency and reducing greenwashing. Nevertheless, audit effectiveness remains contingent upon auditor competence, technological literacy, and institutional coordination across jurisdictions. The study proposes the Conceptual Foundation of Digital Assurance Governance Model (DAGM), explaining how digital audit technologies and institutional governance collectively strengthen accountability, transparency, and trust in the digital economy.

Idham Idham, Chusnul Rofiah · 0 citations
Review Open access Aug 2026

Cybersecurity Governance Deficiencies in External Audit: A Structured Review and Control-to-Assertion Framework

Digital financial reporting depends on identity services, enterprise systems, cloud platforms, automated controls and system-generated evidence. Cybersecurity weaknesses therefore enter external audit when a governance condition or control deficiency affects a material reporting process, an assertion, a disclosure, an estimate or the reliability of audit evidence. This article develops a non-deterministic control-to-assertion framework through a structured integrative review. The search, completed on 16 July 2026, covered English-language journal work published from 2000 to 15 July 2026 through Google Scholar and publisher search services. The final analytic set contains 32 peer-reviewed journal articles, four institutional sources and two public company filings used for worked application. The revision separates organisation-level cybersecurity governance deficiencies from process-level cyber control deficiencies. It also locates the model against COSO, COBIT 2019, NIST CSF 2.0, IT general control methods and relevant International Standards on Auditing. Existing sources provide taxonomies for governance, internal control, security outcomes and audit procedures. The new framework supplies the missing translation route between those taxonomies: governance condition, control state, financial reporting dependency, assertion-level misstatement risk, audit-evidence reliability, audit response and reassessment. Compensating, detective and corrective controls might interrupt or reduce the route, so no governance deficiency automatically produces a control failure or a material misstatement. Two worked documentary applications, The Clorox Company and MGM Resorts International, show how public incident facts enter account, assertion, evidence and procedure analysis. The framework does not estimate incident probability, expected loss or a cyber risk score. It provides a file-ready reasoning structure for entity-specific risk assessment under the auditing standards. Its main contribution lies in the separate treatment of misstatement risk and evidence reliability, followed by a traceable link to accounts, assertions, evidence sources, specialist input and audit procedures.

Alessio Faccia, S. Tangjitsitcharoen · 0 citations
Review Open access 2023

Cybersecurity Governance in Smart Campus Environments: Balancing ISO 27001, GDPR, and HIPAA Compliance in University IT Systems

The study concludes that universities require a layered, integrated governance model rather than separate compliance silos, and recommends multidisciplinary oversight, harmonised control catalogues, precise data classification, Zero Trust access, privacy and security by design, recurring impact assessments, supplier accountability, and measurable assurance.

Dominic Feboh, Ayokunle Olamide Ijagbemi, Stanley Nwakamma et al. · 0 citations
Review Open access Jul 2026

From Risk Reporting to Resilience: A Narrative Integrative Review of Cybersecurity Governance Practices in Organizations

Cybersecurity has moved from a peripheral technical function to a core pillar of organizational governance, driven by the escalating frequency and cost of digital intrusions, tightening disclosure regulation, and growing recognition that technical controls alone cannot guarantee continuity of operations. This narrative integrative review synthesises contemporary academic literature on cybersecurity governance, tracing its evolution from a compliance-oriented, risk-reporting paradigm toward an integrated model of organizational cyber resilience. The review examines governance structures and board oversight arrangements, the integration of cybersecurity into enterprise risk management, the conceptual architecture of organizational cyber resilience, the human and cultural determinants of governance effectiveness, sector-specific and supply-chain vulnerabilities, financial and insurance mechanisms for risk transfer, the regulatory and standards landscape, and approaches to measuring governance maturity. Findings indicate that although disclosure obligations and formal oversight structures have proliferated, substantive board-level expertise remains scarce, enterprise risk management integration is uneven, and resilience-building efforts are frequently undermined by fragmented accountability and inconsistent measurement practices. The review argues that a durable shift from reactive risk reporting to genuine organizational resilience requires coherent alignment across governance structures, cultural investment, supply-chain oversight and outcome-based metrics. Directions for future research and the practical implications of these findings for boards, risk officers and regulators are discussed.

William Asare Yirenkyi, Apaflo Godson Teye, Matilda Konotey et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.