BINDURA UNIVERSITY OF SCIENCE EDUCATION
FACULTY OF SCIENCE
NAME : FORTUNE
SURNAME : DANGA
REG.NUMBER : B1953014
COURSE CODE : IT 211
COURSE : INFORMATION SYSTEMS AUDITING
PROGRAM : INFORMATION TECHNOLOGY
PART : 2.2
ASSIGNMENT : ONE
1 a) What is the sole purpose of an Information System (IS) Audit? [5]
Answer
Information systems auditing, is an examination of the management controls within
an Information technology (IT) infrastructure and business applications. The purpose of
Information systems auditing is to establish whether information systems are safeguarding
corporate assets, maintaining the integrity of stored and communicated data, supporting
corporate objectives effectively, and operating efficiently, to compare actual and planned
performance.
In other words; Information systems auditing is undertaken to verify that the stated objectives of
system are still valid in current environment, to evaluate the achievement of stated objectives, to
ensure the reliability of computer based financial and other information. To ensure all records
included while processing and to ensure protection from frauds.
b) Discuss any five contents of an information system audit charter. [10]
Answer
The information systems auditing charter is a formal document that clearly defines and
articulates “marching orders” for the internal audit function from the governing body
(typically the audit committee) and management. The Charter also defines others’
responsibilities for providing access and cooperation during audits or other reviews. It should
be reviewed and approved by the governing body on an annual basis. Discussed below are
the five vital components contents of an information system audit charter.
Mission and Purpose; the charter should define both the mission and the purpose of the internal
audit function. The mission should be to enhance and protect organizational value by providing
risk-based and objective assurance, advice, and insight. Internal audit’s independent and
objective assurance and consulting services should be designed to add value and improve the
organization’s operations.
Authority ; a statement should be included in the charter affirming that the governing body will
establish, maintain, and assure that the internal audit function has sufficient authority to fulfill its
duties.
Quality Assurance and Improvement Program – The charter should define the internal audit’s
Quality Assurance and Improvement Program (QAIP), which covers all aspects of the internal
audit function including:
Evaluation of conformance to IIA Standards and requirement to report the results of its
QAIP periodically to senior management and the governing body
An external assessment of the activity at least once every five years
Independence and Objectivity; the charter should state that the CAE will ensure independence
and objectivity of the internal audit function to carry out its duties in an unbiased manner.
Furthermore, internal audit should have no direct operational responsibility or authority over any
of the activities audited.
Scope of Internal Audit Activities; the charter should define the scope of the internal audit
function. The scope should include providing independent assessments of the adequacy and
effectiveness of governance, risk management, and control processes.
c.) Discuss the various issues that are of primary concerns for an auditor involved in
information system audit [10]
Answer
Carrying out an audit requires the auditor to consider 3 types of risks. Firstly, inherent risk – The
‘natural’ risk that will occur with every information system. Different information systems have
different degree of risks. For example, a company’s logistics information system might face less
inherent risks as compared to its financial information system (simply because the financial
information system is more attractive to people looking to commit fraud).
Moreover, control risk – This type of risk occurs because of poor internal controls. Any type of
information system will have control risks if it has poor controls. For example, if the payroll
department’s files are not securely locked in a separate room, it faces a higher control risk.
Furthermore, detection risk – The risk that auditors face: The audit may not be able to detect
material flaws or errors in the system.
An Auditor should also be concerned about, Cybersecurity; cyber security audit is designed to be
a comprehensive review and analysis of your business’s IT infrastructure. It encompasses
everything that pertains to protecting our sensitive data, personally identifiable information,
protected health information, personal information, intellectual property data and governmental
and industrial information systems. It helps mitigate the consequences of a breach and
demonstrate that your organization has taken the necessary steps to protect client and company
data
Additionally, an Auditor should also be concerned about finding the right staff and emerging
technology and infrastructure changes.
4.(a)A company has decided to outsource the IS audit function. Explain the reasons why
some organizations outsource information systems audit activity. State three advantages
and three disadvantages of outsourcing the audit function. [6]
Answer
Service providers have good quality staff i.e. have specialized skill and assess what management
wants them to do. Also they have a high degree of professionalism since the service providers
are trained in many areas enhancing the quality of advice to the management on best practices.
Some organizations outsource information systems audit activity, in order to get an immediate
audit department instead of employing audit staff thereby cutting costs e.g. salaries to the
employees, benefits and allowances. Furthermore, to enhance independence and thereby
minimizing room for collision thereby giving value added reports i.e. there is real value for
money. Moreover, some organizations outsource information systems audit activity to enhance