Skip to main content
About

IT auditor.Ex-Big 4. In-house now.

Himanshu Pokharkar

I'm Himanshu. I've spent the last eight years in IT audit and GRC: external audit at Deloitte and PwC in India, cyber consulting at Deloitte UK, and now internal audit at a private bank in London.

This site is where I put the tools, notes, and resources I wish I'd had when I started. If any of it saves you time on an audit, sharpens a GRC decision, or helps you land your first role in this world, I've done my job.

The Path

How I got here.

I didn't plan on IT audit. My degree was in Electronics & Telecommunications at the University of Mumbai. But my first job as a Risk Analyst at Deloitte in 2018 put me in front of real IT systems and control frameworks, and something clicked. Auditing was less about ticking boxes and more about understanding how things could break.

Four years at Deloitte and PwC in Mumbai gave me the technical foundation: ITGCs, application controls, and external audits across banks, insurers, and manufacturers. In 2021 I moved to the UK to do an MSc in Information Security at the University of Surrey (NCSC-accredited).

After graduating I joined Deloitte's UK cyber practice, working on data and digital risk projects. In late 2023 I moved in-house. That was the shift that mattered most. What in-house means, for me, is that audit findings actually land on the desks of people who act on them. That changed how I think about what a good audit looks like.

Now I write, build tools, and mentor early-career auditors, because the field needs less mystique and more people who can explain it plainly.

The work itself has spanned ITGCs and application controls, ITIL processes like change and configuration management, and cyber assessments across patching, vulnerability, and endpoint security. On the regulatory side, I've led compliance reviews against FCA, BaFin, and DORA, and worked with frameworks including ISO 27001, NIST, and COBIT. Not glamorous work, but the kind that adds up to actually understanding how IT breaks and how organisations control it.

Right Now

What I’m working on.

Credentials

The paperwork.

  • CISA

    Certified Information Systems Auditor, ISACA (Aug 2021)

  • MSc Information Security

    University of Surrey, NCSC-accredited (2021–2022). Thesis on evaluating risk rating tools for third-party risk management. Selected for the NCSC Innovator’s Challenge.

  • BE Electronics & Telecommunication

    University of Mumbai (2013–2017)

References

What people say.

I worked with Himanshu where he consistently demonstrated proficiency in IT Audit and GRC. His understanding of compliance frameworks aided our deliverables effectively. Himanshu is skilled in time management and has strong interpersonal skills, making him a reliable team member.

Janet F Freeman, IT Audit Director, UK/Europe & APAC

December 2023

Himanshu had worked with me on few clients with complex IT structure during his stint with PwC. He was one of the most dynamic team members and demonstrated good technical skillset, great communication skills and is adept at managing clients.

Jithin James, Senior Manager

August 2022

Himanshu is knowledgeable in his auditing domain including GRC (Governance, Risk & Compliance), which is highly supported by time management and people skill which is much needed. He is a very good resource.

Durgesh Mankar, CISO at Pluxee India

January 2022

He is very focused, quick learner and technically sound. Himanshu has great exposure in IT Security audits and ITGCs. He is confident while communicating to clients and team members across hierarchy.

Emiliana Jockey Crass, Audit Project Leader at PSEG Long Island

July 2021

The two most important qualities about Himanshu are perseverance and calmness, even at times when deliverables are on the edge. He possesses an excellent understanding of IT Audits and Compliance.

Trushna Palo Patjoshi, Governance Risk Compliance Consultant

January 2020

He is a worthy asset to any organization. He is an extremely hard working individual and has accumulated niche skill sets like Risk Management, ITGC, Business Automated Controls and has worked on multiple Cyber Security projects.

Gaurav Gwalia, Associate Director

September 2019

Let’s Talk

Get in touch.

If you're a student figuring out IT audit as a career, a fellow auditor with a war story to trade, or someone who wants to collaborate on making this hub better, my inbox and LinkedIn are open.

LinkedIn