For best experience please turn on javascript and use a modern browser!
You are using a browser that is no longer supported by Microsoft. Please upgrade your browser. The site may not present itself correctly if you continue browsing.

Introduction

Edouard van den Heuvel is an external PhD candidate at the Amsterdam Business School, University of Amsterdam, where he is also affiliated as a lecturer. He holds a bachelor's degree in Business IT, a double master's degree in Business Administration and Information Science, and completed the post-master's IT audit programme (RE). He is a registered IT auditor affiliated with NOREA. After several years at PwC, Edouard is now Partner at Risk Boutique, a specialised advisory firm in non-financial risk management (NFRM) that works predominantly for financial institutions. In addition, he acts as thematic partner reviewer on IT audit and third-party assurance engagements at several of the larger accountancy firms in the Netherlands. In these roles, his academic research and professional practice inform one another.

Summary

Edouard's dissertation examines the evolving role of the IT auditor in rapidly changing, regulated environments. The dissertation comprises four studies, each grounded in an established theoretical perspective and combined with insights from professional practice. Together, they contribute to a theoretically informed understanding of how the IT audit profession responds to technological change, new regulatory frameworks, and shifting organisational expectations.

The first study, Evolution of IT Auditing: Journey Towards a Dynamic Landscape, traces the historical development of IT auditing and the drivers that have shaped its current form, including the growing complexity of IT environments, evolving compliance frameworks, and the expanding advisory expectations placed on IT auditors. Building on earlier historiographies of the profession, this study provides the conceptual foundation for the chapters that follow. The study has been published in Maandblad voor Accountancy en Bedrijfseconomie (MAB).

The second study, Reliance without Access? A Principal-Agent Analysis of Cloud Outsourcing Assurance, applies principal-agent theory to the question of how financial institutions and their auditors can rely on assurance over outsourced cloud services when direct access to the service provider is limited. The study conducts a structured gap analysis of the prevailing normative frameworks, including DORA (Articles 28 to 30), the EBA Guidelines on outsourcing arrangements, ISAE 3402, and SOC 2. A systematic document analysis based on a detailed codebook is complemented by semi-structured interviews with registered IT auditors, in order to identify where current assurance instruments leave gaps in the chain between user organisations, cloud service providers, and their auditors.

The third study draws on institutional theory to analyse the implementation of the European Union Aviation Safety Agency's Part-IS regulation, which requires the integration of information security management into aviation safety frameworks as of February 2026. The study examines the readiness and implementation priorities of European airlines, distinguishing between regulative, normative, and cultural-cognitive dimensions of institutionalisation. This research was conducted with Riana Steen and Maria Papanikou and was accepted for the ESREL 2026 conference in Braga. A sole-authored follow-up study extends the analysis longitudinally to the 2025 annual reports of six European airlines, examining the depth of institutionalisation of Part-IS requirements and the implications for the assurance mandate of IT auditors.

The fourth study, Navigating the Tightrope: IT Auditors between Speed, Innovation, and Compliance in DevOps Environments, draws on paradox theory and the concept of enabling formalisation to investigate how IT auditors can provide assurance in DevOps environments without undermining the speed and agility these practices are designed to achieve. The study combines a qualitative problem analysis, in which AI-assisted pattern analysis was applied to practitioner responses, with a survey of 45 professionals, and develops a risk-based set of general IT controls for DevOps environments. The study also reflects on the growing presence of artificial intelligence in DevOps pipelines as an emerging object of audit.

Across the four studies, the dissertation combines principal-agent theory, institutional theory, and paradox theory with systematic document analysis, survey research, and expert interviews. In doing so, it aims to contribute both to the academic literature on auditing and assurance and to professional practice, offering guidance for auditors, standard setters, and the organisations they serve.