Evaluate IT operational risk by starting from the business: which systems would stop revenue or operations if they failed? Who depends on them? Are they documented? Are they recoverable, and would a trained person know how in time?
Then look at control: can a single lost admin account or a single provider disrupt you? Are backups restorable and protected? Is vendor dependency manageable?
You do not need to be technical to evaluate this. You need honest answers to a short set of questions. An independent audit is a structured way to obtain them with evidence.