IT Audit Factory — evidence-first audit & compliance operations
Free • Professional • MSP
Frameworks & Controls

FFIEC IT examination readiness

89 scoped preparation workpapers and 299 evidence review actions

All available frameworks

What the app checks

Technical checks run for the selected scope, available connectors and credentials. Results provide evidence for review; missing data is not a pass.

Explicit requirement-to-test mappings

RequirementCollector / testWhat it checks or supports
FFIEC-IS-O04WINDOWS / WIN-INVENTORY-COVERAGE-001Asset observations support risk-identification population review. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision.
FFIEC-IS-O06ADSEC / AD-LIFECYCLE-001Account observations support access-control procedure review. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision.
FFIEC-IS-O06ADSEC / AD-PRIV-001Privileged groups support least-privilege review. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision.
FFIEC-IS-O06CERTTLS / CERTTLS-POSTURE-001TLS observations support encryption review. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision.
FFIEC-IS-O06WINDOWS / WIN-FW-001Host firewall state supports network-protection review. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision.
FFIEC-IS-O06WINDOWS / WIN-AV-001Endpoint protection state supports malware-control review. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision.
FFIEC-IS-O06STORAGE / STOR-AT-REST-ENCRYPTION-001Storage encryption state supports data-protection review. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision.
FFIEC-IS-O08WINDOWS / WIN-PATCH-FRESHNESS-001Patch observations support security-operations review. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision.
FFIEC-IS-O10VULN / VULN-IMPORT-001External vulnerability findings support assurance review; they do not replace independent penetration testing. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision.
FFIEC-BCM-O06BACKUP / VEEAM-JOB-001Backup job results support resilience review; restoration and continuity exercises remain manual. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision.
FFIEC-BCM-O06BACKUP / VEEAM-REPO-001Repository observations support backup protection review. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision.
FFIEC-AIO-O04WINDOWS / WIN-INVENTORY-COVERAGE-001Host population observations support IT asset management. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision.
FFIEC-AIO-O04NETWORK / NET-INVENTORY-001Network device inventory supports IT asset management. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision.
FFIEC-AIO-O13CERTTLS / CERTTLS-POSTURE-001Endpoint transport observations support infrastructure security review. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision.
FFIEC-AIO-O14WINDOWS / WIN-AV-001Endpoint protection supports operational safeguard review. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision.
FFIEC-DAM-O13WINDOWS / WIN-PATCH-INVENTORY-001Installed patch inventory supports maintenance review; change approval and testing remain manual. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision.

What requires manual review

Confirm scope and applicability, review the requirement guidance, collect policies and records, conduct interviews or observations where needed, and assess evidence relevance and freshness. Record owners, rationale, workpaper conclusions and remediation. An assessor makes the final decision; a technical pass does not approve the whole framework.

Seven core IT booklets: Audit; Business Continuity Management; Development, Acquisition, and Maintenance; Information Security; Management; Architecture, Infrastructure, and Operations; Outsourcing Technology Services. Payments-system and supervisory-program booklets and agency-specific requirements need separate review. This is examination preparation, not the retired FFIEC CAT, an official rating, or a regulatory examination. Scope steps according to risk and applicable regulator guidance. Original IT Audit Factory preparation workpapers with public U.S. government source references. ITAF identifiers are not official assessment procedure IDs. No paid or proprietary control catalog is bundled. No publisher or government endorsement is implied.

Where it is available

This preparation framework is listed in the C32 Professional/MSP application catalog. Free retains its ISO assessment limits. Availability of a framework is separate from the extent of automated scanning.

Coverage shown here comes from the application’s C32 requirement and mapping catalogs.