Skip to main content

      Are you a bit overwhelmed with all the different activities that should be performed when performing an IT audit? Don’t worry, KPMG can support you throughout your entire IT audit. We interviewed one of our IT audit specialists, Dorthe Neefs, to give you insights into the nature of IT audit projects, share highlights, and explain how she came to join the Digital Risk Management team.

      Dorthe, what is the typical duration of an IT audit project? What does a project look like?

      The duration of a project largely depends on the client. For large clients, projects generally run throughout the entire year, with a pause of one or two months. For smaller clients, the busiest periods typically occur between September or January - aligned with the timing of their fiscal year-end. Teams are rarely assigned to a project full-time; instead, they often work one or two days per week for several months. Auditors usually remain with the same client for multiple years, typically at least ten years (according to the Barnier law).

      The first year of working with a new client is often the most challenging, as it involves familiarizing oneself with the client's systems and identifying key contacts. In subsequent years, the process becomes more efficient and focused. You know who to reach out to, you dive deeper into the client's operations, and you often discover new insights. This ongoing learning keeps the work engaging and dynamic.

      Dorthe Neefs, Sr. Manager Advisor

      Dorthe Neefs, Sr. Manager Advisor, Enterprise Risk Services

      What is your most memorable project?

      One of my most memorable projects was a large SOX client, which I started working on in 2018. It was one of my first projects and, initially, things were not going so well due to a lack of maturity in the process. At the beginning, we were testing around 10 reports, but over the years that has grown significantly; now we are testing about 80 reports. The project has changed a lot over time. Just last year, we had a review similar to a SOX quality review, where PCOAB selects a random client to conduct a quality assessment. Last year, this review was conducted on our project and was considered to be of very high quality. We continuously strive to improve the project each year.

      How did you end up in the KPMG IT audit team?

      I joined KPMG in 2018, right after finishing my business engineering studies. During school, I took a few data-related courses, which got me interested in IT.

      My path to KPMG was quite unexpected. I went to a networking event where I met some employees, including Thomas De Backer, who is currently the director of the Tech Risk (IT audit) department at KPMG. At first, I wasn’t sure if I wanted to apply because I was still early in my studies. But the recruiters stayed connected and encouraged me to think about it after my exams. Soon after attending a tech-focused event they organized, I decided to apply and got the job. From day one, I worked in the IT audit team. September is usually the busiest time, but over time I also gained experience in other areas. I gradually built up my skills in governance, risk, and compliance (GRC) and assurance. When I became a manager, I started combining IT audit with GRC, which helped me grow a broader skill set.

      Why should people come to work at KPMG?

      I wasn’t really sure what I wanted to do after school. I didn’t know much about IT audit, so it felt like taking a leap into the unknown. What kept me in IT audit was realizing how interesting it actually is. My background in business engineering gave me a good understanding of business processes and accounting. That helped me to see how IT audit fits into the bigger picture of a company’s operations, which made the work meaningful and engaging.

      What is your experience as a woman working in IT?

      When it comes to women in IT audit, we don’t differentiate based on gender; our focus is, and has always been, on capability, curiosity, and character. Over the years, we’ve seen strong growth in our IT audit team, not just in size but in the range of skills, experiences, and perspectives people bring. The number of women in our team has grown organically as part of that evolution. We provide equal opportunities for everyone, and career progression is driven by performance, impact, and continuous learning. We’ve had women leading complex cyber and technology risk engagements, mentoring new joiners, and contributing to strategic innovation in how we deliver audit. We’re making sure the right people are in the right roles, and that they are empowered to succeed.



      Do you have questions related to IT Audit?

      For guidance or further information on IT Audit-related topics, feel free to reach out to Benny Bogaerts.

      Benny Bogaerts

      Partner, Technology | Advisory

      KPMG in Belgium



      Digital Risk Management

      KPMG Technology services.
      Technology advisory

      Stay informed

      Be the first to know about top business trends that can drive success for your company.

      stay informed