IT Risk/Audit Transformation

Gezien de ontwikkelingen rondom het coronavirus in Nederland, kunnen we onze trainingen tot in ieder geval 31 maart niet langer klassikaal aanbieden. Wij werken eraan om onze trainingen via virtual classroom aan te bieden. Zodra wij hierover meer informatie hebben, publiceren wij dit op onze website. In de tussentijd kunt u zich gewoon inschrijven. Mensen die zich al ingeschreven hebben, informeren wij per mail over de voortgang. Mocht u nog vragen hebben, neem gerust contact met ons op via +31 (0)88 792 86 70.
Wij volgen de richtlijnen en adviezen van het RIVM binnen Nederland en zullen deelnemers van onze trainingen tijdig informeren wanneer de situatie aanzienlijk verandert.

How to stay relevant as an IT Risk/Audit professional in an agile and DevOps setting?

Assurance functions like IT risk management and IT audit face a huge challenge to provide assurance on new IT risks, increasing IT automation and renewed IT operating models. As the conventional IT controls are replaced by high-level IT automation, assurance functions are required to re-design their IT risk management and IT control frameworks to remain relevant. This requires new knowledge and skills to assess the risks. This training helps you to require the necessary skills and insights.

"Conventional IT risk and control frameworks are not ‘fit for purpose’ anymore”.

Seda Foppen, Director IT Risk and Regulations, PwC

About this course

This course includes

Successful firms of the future will likely be those that can adapt quickly, move fast, learn rapidly and embrace dynamic customer demands. IT functions of these firms respond to the business expectation of agility by eg implementing agile software development methodologies and changing their working style to DevOps, for example. To help you remain relevant and cope with the challenges, these will be learning goals of this training:

  • Understand new concepts such as Agile, DevOps, Continuous Integration/Continuous Delivery pipelines, automated infra delivery ecosystem, Cloud
  • Understand the skillset/capabilities required for assurance professionals to develop for the future
  • Recognize the potential adjustments required to IT risk and control frameworks in order to accommodate the implementation of DevOps and agile way of working
  • Be motivated to learn the capabilities required for IT risk agility and apply them into the daily practice


View more

Target audience

This training is for:

  • IT risk and/or IT security professionals
  • IT auditors
  • Software engineers who would like to build IT risk management skills and/or demonstrate that the IT risks are managed effectively


View more


Laurens Jan Terwee is a senior associate with experience as both an IT auditor and IT risk consultant. Laurens Jan focusses on technology and the impact of DevOps on internal control frameworks.

"As processes and controls are being automated we increase consistency, reliability and scalability; however, we also increase the complexity. Data-driven insights are key to staying in control in an ever-evolving IT landscape."  

Seda Foppen is a director with 17 years of experience in IT risk governance, IT regulations & compliance, IT internal control frameworks and transformation of the assurance functions (in particular IT risk & IT audit).

“PwC plays an important role as an external auditor and advisor in IT audit space in how we look at IT controls automation and compliance vs digital IT transformation, important influencial party.”

View more


  • 11 & 12 May 2020

Both sessions include lunch.


The classroom trainings will take place at the PwC Office in Utrecht.


The costs are 1250 euro, exempt from VAT, including the preparation and the two classroom trainings. Also included are the training materials, lunch for both sessions, and drinks.


The training consists of several components: self study to update your basic knowledge on the relevant topics, and one and a half day classroom sessions to translate the topics to the situation and road ahead for your organization.

We will take you through the following topics:

Day 1  

9.00 hours

Welcome participants

9.30 – 10.00 hours

Start programme, introduction, getting to know each other, learning goals

10.00 – 10.45 hours

Agile journey of the IT function of a digital enterprise

10.45 – 11.00 hours


11.00 – 12.00 hours

Foundation and key principles – IT agility and DevOps way of working

12.00 – 13.00 hours


13.00 – 14.00 hours

Key capabilities required for IT functions in their agile/DevOps transformation

14.00 – 14.45 hours

The impact of agile/DevOps on the IT risk control frameworks

14.45 – 15.00 hours


15.00 – 16.00 hours

Principles for ‘DevOps in control’ framework

16.00 – 17.00 hours

Closing programme, questions, recap and evaluation

Day 2    

9.00 hours

Welcome participants


9.30 – 10.00 hours

Start programme, Agenda + recap of day 1


10.00 – 10.15 hours

The impact of IT agility on the assurance functions (three lines of defense model)


10.15 – 10.45 hours

Key capabilities of agile assurance functions of the future (IT risk/IT audit)


10.45 – 11.00 hours



11.00 – 12.00 hours

Presentation of a demo CI/CD pipeline and automation of software testing


12.00 – 12.30 hours

Closing programme, questions and evaluation


12.30 hours



PE hours Accountants

The training courses of the Academy meet the requirements for Permanent Education of the NBA. By completing this training, accountants (AA and RA) receive 9 PE hours. The certificate of attendance will be provided within 4 weeks after the last training session.

PE points RC’s

By completing this training, registered controllers receive 9 PE points. The certificate of attendance will be provided within 4 weeks after the last training session.



When you register we will send you a confirmation with additional information about the training session. Please note that the number of available places is limited. We therefore advise you to apply as soon as possible. If later you are unable to attend, a colleague can take your place. If this is the case, please inform us by sending an e-mail to


Contact us

PwC’s Academy

Onderdeel van/Part of, PwC Netherlands

Tel: +31 (0)88 792 86 70

Volg ons