2022-05-20
Regulators require financial institutions and service providers to maintain independent IT audit programs that assess risk exposure and internal control quality across all technology operations. The document establishes a five-tier rating system evaluating audit independence, risk analysis methodology, reporting timeliness, and adherence to professional standards. Ratings range from 1 for strong performance, allowing examiner reliance, to 5 for critically deficient performance where results cannot be relied upon.