top of page
hero-background.png

PUBLIC SECTOR / MUNICIPAL / EDUCATION / HEALTH & SOCIAL SERVICES / CROWN & PARA-PUBLIC / PRIVATE ENTERPRISE / SMB

Independent IT Audit Services: Establish Security, Governance & Regulatory Compliance

An IT audit is a structured, evidence-based examination of your IT infrastructure, security controls, and governance practices. We evaluate your systems against recognized frameworks, producing a defensible record of actionable findings your leadership can account for.

Auditor_edited.jpg

2003

Serving Canadian organizations without interruption since.

4

Regions covered: Montréal, Laurentides, Toronto, Calgary.

6

Control domains examined in a full audit mandate.

EN / FR

Deliverables issued in both official languages.

OBLIGATION

Statutory Obligation & Stewardship

Public bodies administer citizen data and public funds. Private enterprises hold client records, payment data and commercial information under contract and law. In both cases an independent IT audit delivers the concrete evidence that these assets are protected with documented due diligence.

as-ic-independence-plate.webp

ASSURANCE

Independent Verification & Assurance

Internal reviews only confirm what your team already believes. An external IT audit rigorously tests your controls — delivering the objective assurance expected by councils, boards of directors, regulators, insurers, and enterprise clients running supplier due diligence.

as-page-bg-light.png

02 · CONSTITUENCIES

Organizations We Audit: Public Sector and Private Enterprise

Our audit mandates are customized to match the distinct operational realities, risk profiles, and legal obligations of each organization — from a twenty-person professional firm to a distributed public network.

C-01

Municipalities & Public Administration

Municipal administrations, RCMs, inter-municipal boards, Crown corporations and para-public bodies — covering critical systems for public works, permits, property taxation, and council operations.

as-ic-c04-crown.webp

C-04

Professional, Financial & Legal Services

Accounting, legal, notarial, engineering, insurance and advisory firms holding confidential client files under professional-order confidentiality obligations and client due-diligence requirements.

as-ic-c02-education.webp

C-02

Education & School Service Centres

Administrative networks, pedagogical environments, and student information systems (SIS) across school service centres, colleges and private institutions, with specialized focus on protecting minors' personal data.

as-ic-c05-parapublic.webp

C-05

Manufacturing, Distribution & Construction

Production, logistics and construction businesses where operational technology, ERP systems and supply-chain continuity carry direct and immediate revenue consequence.

 

as-ic-c03-health.webp

C-03

Health, Social Services
& Clinics

Public health establishments, affiliated organizations and private clinics handling electronic health records (EHR) and clinical data under Quebec and Canadian federal privacy laws.

as-ic-c06-civil-society.webp

C-06

Non-Profits, Foundations & Associations

Non-profit organizations, foundations and associations accountable to institutional grantors, donors, members, and the beneficiaries they serve.

 

03 · SCOPE

The Six Core IT Control Domains We Audit

A full audit mandate evaluates six foundational IT control domains. We also offer targeted audit reviews — such as Law 25 privacy readiness or business continuity testing — for upcoming board reporting deadlines.

as-ic-d01-governance-dark.webp

DOMAIN 01

Governance
& IT Accountability

Evaluation of policy frameworks, decision rights, delegation of authority, and whether documented cybersecurity responsibilities match day-to-day staff execution.
 

as-ic-d04-continuity-dark.webp

DOMAIN 04

Business Continuity & Disaster Recovery

Verification of backup integrity via live restoration testing — not console reports. Recovery Point Objectives (RPO) and Recovery Time Objectives (RTO) assessed against essential public service continuity.

as-ic-d02-cybersecurity-dark.webp

DOMAIN 02

Cybersecurity Controls & Infrastructure

Assessment of perimeter and endpoint defenses, Identity and Access Management (IAM), privilege access reviews, network segmentation, centralized logging, and patch management discipline.

as-ic-d05-operations-dark.webp

DOMAIN 05

IT Operations & Asset Lifecycle Management

Audit of IT asset inventory accuracy, end-of-support (EOS) hardware and software exposure, software license compliance, configuration consistency, and proactive monitoring coverage.

as-ic-d03-privacy-dark.webp

DOMAIN 03

Privacy & Regulatory Compliance (Law 25 & PIPEDA)

Review of personal information processing under Quebec's Law 25 and Canada's PIPEDA: data inventories, consent workflows, retention schedules, disclosure controls, and incident notification readiness.

as-ic-d06-vendor-risk-dark.webp

DOMAIN 06

Third-Party & Vendor Risk Management (TPRM)

Risk assessment of vendor access pathways, contractual security clauses, cloud hosting and data-residency compliance, and concentration risks among critical technology suppliers.

04 · FRAMEWORKS

Compliance Standards and Regulatory Frameworks We Audit Against

All audit findings are mapped directly to statutory requirements and industry standards, providing a transparent link between identified risks and legal obligations.

REGULATORY INSTRUMENT / STANDARD

APPLIES TO

AUDIT SCOPE & ASSESSMENT FOCUS

Law 25 (Quebec)

Public bodies and commercial enterprises in Quebec

Personal information governance, Privacy Officer designation, incident register compliance, privacy impact assessments (PIA / ÉFVP), retention and destruction protocols.

PIPEDA (Federal)

Commercial organizations across Canada

Consent mechanisms, organizational accountability, data safeguards, and individual access rights under federal jurisdiction.

Quebec Access Act

Quebec public sector bodies

System capabilities to accurately locate, retrieve, and redact digital records held in organizational databases and file stores.

ISO/IEC 27001 Standard

Any public or private organization

Information Security Management System (ISMS) structure, threat modelling, risk treatment, and control coverage.

CCCS Baseline Cyber Controls

Small and medium organizations

Canadian Centre for Cyber Security baseline guidelines applied as a practical security floor.

Internal Policy Instruments

Your organization

Testing real-world operational compliance against your organization's internal directives, by-laws, and security policies.

05 · METHODOLOGY

Our 5-Phase Evidence-Based Audit Methodology

Fixed scope, predictable timelines, and defensible results. Every finding in our final report is directly traceable to verified technical evidence.

PHASE 01

Mandate Definition & Scoping

Objectives, targeted systems, access parameters, and reporting schedules are established in writing. For mandates tied to municipal tenders or board deadlines, we structure timelines backward from your target date.

PHASE 02

Evidence Collection

Comprehensive documentation reviews, system configuration extraction, controlled technical assessments, and structured interviews with key IT and administrative personnel.

PHASE 03

Controls Testing & Analysis

We test controls rather than assume compliance. Data backups are actively restored, and user access controls are reconciled against personnel records. Every finding is validated prior to report drafting.

PHASE 04

Risk Rating & Impact Analysis

Findings are categorized using a severity matrix based on likelihood and potential impact — including operational downtime, legal liability, and harm to citizen privacy.

PHASE 05

Reporting & Remediation Roadmap

Delivery of an executive summary tailored for non-technical leadership, alongside a technical findings register and a prioritized, cost-estimated remediation plan.

Wide Server_result.webp

06 · DELIVERABLES

Audit Deliverables Built for Governance & Procurement

Our documentation is designed to be tabled before boards, filed with regulators, and integrated into procurement specifications — not abandoned in a slide deck.

Executive Summary

A high-level overview of your security posture, critical vulnerabilities, and strategic priorities tailored for city councils and corporate boards.

as-ic-dl2-findings-plate.webp

Detailed Findings Register

Complete technical documentation of every vulnerability, with system references, severity ratings, and recommended remediation actions.

as-ic-dl3-risk-matrix-plate.webp

Enterprise Risk Matrix

A consolidated breakdown of organizational exposure categorized by impact and probability, for enterprise risk management (ERM) reporting.

as-ic-dl4-roadmap-plate.webp

Sequenced Remediation Roadmap

Actionable, prioritized steps outlining technical dependencies and estimated resource requirements to streamline budget planning.

as-ic-dl5-evidence-plate.webp

Defensible Evidence Appendix

Supporting technical logs, configurations, and interview records retained to ensure audit findings withstand regulatory scrutiny.

Pen_And_Paper_result_edited.jpg
as-page-bg-light.png

07 · INDEPENDENCE

Strict Independence & Objectivity in IT Auditing

Art Systems Canada offers managed IT services, cloud infrastructure, and technical project delivery. This deep operational experience ensures our audit recommendations are realistic and actionable — we build and maintain the controls we audit.

Our Independence Commitment

We maintain strict neutrality per engagement. Art Systems Canada will never act as the audit authority on a project where we serve as the primary implementation vendor. If an operational overlap creates a potential conflict of interest, we formally declare it and decline the mandate.

08 · ENGAGEMENT

IT Audit Mandate Formats & Pricing Structures

Use these indicative ranges for annual budget preparation. Formal pricing is tailored to your scope and delivered as a fixed proposal suitable for public procurement processes.

Targeted Audit Review

$3,500 – $12,000 CAD

A deep-dive assessment into a single high-risk domain — most commonly Law 25 privacy compliance, cyber-insurance or business continuity readiness.

  • 1 selected control domain

  • Findings register & risk ratings

  • Executive summary report

Full IT Mandate

$12,000 – $45,000 CAD

Comprehensive examination across all six core IT control domains and primary enterprise software systems.

  • All 6 control domains

  • Active data restoration & access reconciliation

  • Risk matrix & sequenced remediation roadmap

  • Formal presentation to board or council

Multi-Site / Program Audit

$45,000 – $150,000+ CAD

Designed for distributed public entities, enterprise multi-site environments, and recurring multi-year compliance programs.

  • Multi-entity & distributed infrastructure scope

  • Annual or semi-annual audit cycles

  • Progress tracking & year-over-year remediation audits

09 · FREQUENTLY ASKED QUESTIONS

IT Audit FAQ

What is an independent IT audit?

​An independent IT audit is a structured examination of an organization's IT infrastructure, security controls, and governance practices. Evaluated against recognized standards such as ISO 27001 or Law 25, the audit produces a formal report containing severity-rated findings and a prioritized remediation roadmap to ensure legal and operational compliance.

How does an IT audit ensure compliance with Quebec's Law 25?

Law 25 requires organizations in Quebec — public bodies and private enterprises alike — to maintain strict governance over personal information, including designating a Privacy Officer, logging privacy breaches, and conducting privacy impact assessments. An IT audit tests these controls in practice, identifying technical vulnerabilities or policy gaps that require remediation.

Can IT audit deliverables be used in tender, procurement or insurance files?

Yes. Our audit deliverables — including the executive summary, findings register, and cost-estimated remediation roadmap — are structured to support procurement files, budget requests, cyber-insurance applications, and client due-diligence reviews.

How does Art Systems ensure independence if it also provides managed IT services?

We maintain strict role separation per engagement. Art Systems Canada never audits infrastructure or software projects where we act as the primary implementation vendor. If a potential conflict of interest arises, we declare it immediately and decline the mandate.

How often should an organization perform an IT audit?

We recommend a full IT audit annually as a baseline. Additionally, targeted audits should be triggered by major organizational milestones: cloud or system migrations, security incidents, mergers, acquisitions or amalgamations, insurance renewals, or significant regulatory updates.

Are audit deliverables provided in French and English?

Yes. Art Systems Canada operates bilingually and issues all audit deliverables, executive summaries, and board presentations in both French and English.

bottom of page