This is the first time the cloud guide has been updated since 2021, so the NAO said it was necessary to revise to take into account the latest changes in this fast moving space.
Although it is aimed at public sector organisations, it provides an excellent overview for all audit committees of the key issues to consider when auditing cloud services from due diligence and cybersecurity, to staffing resources, contract negotiations, exit strategies and bespoke versus off the shelf considerations.
‘Gaining suitable assurance is complex and difficult, and our aim is to help audit committees understand the cloud-related questions they might need to ask of management,’ the NAO said.
‘Since we last published this guidance, more of the public sector has adopted cloud services, with a matching increase in government spending with the big cloud providers.’