IT & Cyber Audit
Backup & Recovery Assurance
Reliability of system backups and the success of disaster-recovery restore tests.
Why backups are an audit and continuity imperative
Reliable backups and tested recovery underpin the integrity and availability of financial systems, and the AGSA increasingly raises IT general control findings where disaster recovery is undocumented or untested. Under COSO and the ISSAI framework, availability of records is part of the control environment that financial assurance depends on. AuditPro Core surfaces backup success rates and restore-test outcomes so management can prove recoverability rather than assume it.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
Backup success rate
96%
▲ 2 pts
Failed backups
23
last 30 days
Restore tests passed
9 / 12
Systems untested
5
Backup success by system
Restore-test results
| System | Last test | RTO (hrs) | Result |
|---|---|---|---|
| Financial ledger | 2026-04-12 | 4 | Pass |
| Payroll | 2026-03-28 | 6 | Pass |
| Billing | 2025-11-15 | 12 | Fail |
| HR | 2026-02-09 | 8 | Pass |
| Asset register | — | 0 | Not tested |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
A backup is unproven until it is restored
Successful backup jobs say nothing about whether the data can actually be recovered. The only meaningful assurance comes from periodic restore tests against a defined recovery objective.
Recovery objectives set the standard
Recovery time and recovery point objectives define how much data and downtime the institution can tolerate. Backup frequency and retention must be designed to meet them, not chosen arbitrarily.
Coverage gaps are silent risks
Systems added without being onboarded into the backup schedule fail silently until a disaster exposes them. Reconciling backed-up systems to the full application inventory closes this gap.
How AuditPro Core Bridges the Gap
- Restore-test logging: AuditPro Core records each recovery test, its outcome and the systems covered, distinguishing tested from merely backed-up.
- Success-rate monitoring: backup job results are trended so recurring failures on critical systems are escalated promptly.
- Coverage reconciliation: the backed-up inventory is compared to the application register to expose unprotected systems.
- Audit-ready evidence: restore results and schedules export as a DR assurance pack for the IT general controls file.
Key Takeaways
- Only a successful restore test proves recoverability.
- Backup design must be driven by defined RTO and RPO targets.
- Reconcile protected systems to the full inventory to find silent gaps.
- Documented, dated restore tests are what auditors expect to see.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.
