Practice tool for IT audit & GRC
Weak findings get redlined. Strong ones get signed off.
Thirty real-world scenarios — ITGC and SOX testing, evidence and sampling judgment, findings and follow-up. You draft the condition, criteria, cause, effect and recommendation. You get a score out of 10, an element-by-element critique, and the model answer to compare against.
The five-part structure you’re graded on
Each element is scored 0–2. Two marks means it would survive manager review, not that it reads nicely.
- 01
Condition
What you observed — specific, factual, quantified.
- 02
Criteria
The standard, policy or regulation actually breached.
- 03
Cause
The root cause at process or design level, not “human error”.
- 04
Effect
Business impact: loss, disruption, regulatory exposure.
- 05
Recommendation
A proportionate fix that targets the cause, with a named owner.
Scenarios from real testing
Late leaver access, unvalidated system-generated reports, repeat findings, aggregated deficiencies, and the cases where escalating would be the wrong call.
Scored against a rubric
Vague conditions, unnamed criteria and symptom-level recommendations lose marks — exactly as they would in review.
Compare to the model answer
Every element opens side by side with a model version, so you can see what the extra mark actually requires.