Most audit findings are not surprises. They are things the IT team already suspected: a firewall rule nobody can explain, a switch that has not been updated in years, a diagram that no longer matches the building. The audit simply makes them visible, in writing, with a deadline attached.
For a bank, the network is the first place an auditor looks, because every other control depends on it. This article explains what auditors typically ask for, where banks usually fall short, and how to prepare in a few weeks rather than a few days.
Start with the question auditors really ask
Whatever the framework, internal audit, a central bank review or an external assessor, the underlying question is the same: can you show, with evidence, that you know what is on your network and that you control who and what can reach it?
Notice the words "show" and "evidence". Auditors rarely accept "we do that". They want a document, a configuration export, a log or a ticket that proves it. Preparation is mostly about making sure that evidence exists and is current.
1. An accurate inventory and network diagram
Expect to be asked for:
- A list of network devices (firewalls, routers, switches, wireless controllers) with model, firmware version, location and owner.
- A current diagram showing branches, the head office, links to third parties and internet exits.
- A list of critical systems (core banking, payments, ATM and card switches, email) and where they sit on the network.
The common gap is not a missing diagram but an outdated one. If a branch was added or a link replaced last year and the diagram was not updated, the auditor will notice quickly and begin to doubt the rest of the documentation.
2. Segmentation between zones
A flat network, where a teller's PC can reach the core banking database directly, is one of the most common findings. Auditors look for clear zones, typically:
- Core banking and payment systems
- Server and database zone
- Staff workstations
- Branch networks
- Guest and visitor Wi-Fi
- Management network for administering devices
- Third-party and vendor access
They then look at the rules between zones. Each rule should have a business reason, an owner and, ideally, a review date. We cover this topic in more depth in our guide to designing resilient networks.
3. Firewall rules and change control
Firewalls are examined closely. Typical requests:
- An export of the rule base, reviewed within a defined period.
- Evidence that "any-any" or overly broad rules were removed or justified.
- A change process: who requested a change, who approved it, who implemented it and when.
- Confirmation that the default action for unmatched traffic is deny.
Old rules accumulate. A rule created for a vendor project three years ago and never removed is exactly the kind of item that appears in a report. A scheduled rule review, recorded in a ticket, solves most of this.
4. Remote access and administrative access
Auditors pay special attention to how people connect from outside and how administrators manage devices:
- Remote access (VPN) should require multi-factor authentication.
- Administrative access to network devices should use named accounts, not a shared "admin" login, and should come only from a management network.
- Default passwords and unused accounts should be removed.
- Vendor access should be time-limited and logged.
Shared administrator accounts are a frequent finding because they make it impossible to say who changed what.
5. Patching and lifecycle
Auditors compare your device firmware and software versions against what the vendor still supports. Equipment that has reached end of support, or firmware with known vulnerabilities that are published in vendor advisories, is flagged. You do not need to be on the newest release everywhere, but you need a documented patch process and a plan, with dates, for anything unsupported. The CISA Known Exploited Vulnerabilities catalog is a useful public list to check your device models against.
6. Logging, monitoring and time
If something happened last month, can you reconstruct it? Auditors ask:
- Are firewall, VPN and authentication logs collected centrally?
- How long are they kept, and who can alter or delete them?
- Is anyone watching alerts, and what happens when an alert fires?
- Are device clocks synchronised (NTP), so logs from different systems line up?
In practice, many organisations collect logs but nobody reads them, and the retention period is whatever the disk happened to hold. Define a retention period, protect the logs from modification and assign a person or a service to review them. This is the kind of work a managed IT service with 24/7 monitoring takes off a small internal team.
7. Resilience and recovery
Banks are expected to keep operating through power cuts and link failures, which are everyday realities in Libya. Auditors typically ask about redundant links to branches, redundant firewalls at the core, backup of device configurations and a tested recovery procedure. "Tested" matters: a recovery plan that has never been exercised is treated as a draft.
A four-week preparation plan
Week 1: Know what you have.
- Export the device inventory and confirm firmware versions.
- Update the network diagram and have a second engineer check it.
Week 2: Clean the rules and access.
- Review the firewall rule base; remove or document every broad rule.
- Remove shared and unused administrator accounts; enable MFA on remote access.
Week 3: Evidence and logging.
- Confirm logs reach a central system, set a retention period and test that time sync works.
- Collect change tickets for the last few firewall changes.
Week 4: Rehearse.
- Walk through the diagram and rule base with someone who did not build them.
- Test a configuration restore and a failover, and record the result.
- List known gaps with an owner and a target date. A gap with a credible plan is far better received than a gap that was hidden.
Be honest about the gaps
An audit is not an exam you must pass with a perfect score. Auditors expect to find issues; what they judge is whether you know about them and manage them. A short, honest remediation list with owners and dates builds more confidence than a polished folder that falls apart under one question.
Next step
SmartSITT has more than 15 years of experience in enterprise IT and works with banks and other regulated organisations on network infrastructure and cybersecurity. If you are preparing for an audit and want an engineer to review your network against this checklist, tell us what you need and we will reply with a plan.