1
IT Audit Considerations
1. Introduction
Many aspects of GAM are based on the risk assessment concept and we apply judgment to
identify, assess and respond to identified risks of material misstatement of the financial
statements. This concept equally applies to the information technology (IT) environment.
This document provides audit teams with additional guidance on how to determine an
appropriate audit strategy related to an entity’s IT environment and emphasizes the flexibility
in GAM to scope IT General Control (ITGC) procedures based on the risks of material
misstatement posed by processing financial transactions in the IT environment.
While IT offers many benefits, the use of IT in the authorization, initiation, recording,
processing, correcting when necessary, and reporting of transactions poses specific risks
that could lead to a material misstatement of the financial statements. The risks that the use
of IT poses include:
Reliance on systems or programs that are inaccurately processing data, processing
inaccurate data, or both
Unauthorized access to data that may result in destruction of data or improper
changes to data, including the recording of unauthorized or non-existent transactions,
or inaccurate recording of transactions. Particular risks may arise where multiple
users access a common database.
The possibility of IT personnel gaining access privileges beyond those necessary to
perform their assigned duties thereby breaking down segregation of duties
Unauthorized changes to data in master files
Unauthorized changes to systems or programs
Failure to make necessary changes to systems or programs
Inappropriate manual intervention
Potential loss of data or inability to access data as required
1
We make scoping decisions at different stages of the audit to determine our approach and
then focus our procedures on the areas of higher risk. There are four key decision points
related to IT:
A. Determine the in-scope IT applications
B. Determine the preliminary audit strategy for each in-scope IT application
C. Determine the categories of ITGCs that are relevant, and which of those categories
will be evaluated and tested
D. Determine the relevant ITGCs for the selected categories of the in-scope applications
for which ITGCs are to be evaluated and tested
The following chart illustrates the decision points.
1
ISA 315.A63
2
Identify significant accounts
and disclosures (P08_1)
Determine relevant assertions
(P08_2)
Identify Significant Classes of
Transactions (SCOTs) and
significant disclosure
processes (S02_1)
Understand the critical path of
the SCOTs and significant
disclosure processes (S03_2)
Identify WCGWs in SCOTs
and significant disclosure
processes (S03_4)
Identify controls that are
relevant to the audit (S03_6)
Identify IT applications supporting
the SCOTS, significant disclosure
processes & EAE (S02_2)
Identify IT applications in scope
Effect of IT on SCOTs and
significant disclosure processes
(S03_3)
Identify ITGC categories in scope
(S07_2)
Identify ITGCs, and related PCPs,
for categories in scope (S07_2.1)
Perform walkthroughs (S04)
Design and test controls
(S09, E02)
Update tests of controls (E04)
Update tests of ITGCs (E04)
Reassess combined risk
assessments (E07)
In-scope IT
applications
ITGC Category (MC,
LA, Other ITGCs)
Relevant ITGCs,
related PCPs
EY GAM
GAM – IT Audit Activities
Riskbased approach to scoping IT
Risk assessments
GAM – Financial
Statement Audit Activities
Determine our preliminary
audit strategy (S03_5)
Note: The gold shaded-boxes are performed when our
strategy is to rely on ITGCs
Evaluate ITGCs,
Directly test
controls & EAE, or
Substantively test
A
B
C
D
IT-related decision points
3
2. Determining the in-scope IT applications
As part of “understanding the business,” we gain an understanding the role of IT in the entity.
IT can significantly affect the entity’s ability to achieve its business objectives and is often an
integral component in producing information used to support decisions made by
management. We obtain an understanding of the extent to which the entity uses IT to
process or generate information and determine whether the use of IT gives rise to risks of
material misstatements within the financial statements.
The next steps in our audit process are to:
Identify significant accounts and disclosures (P08_1)
Determine relevant assertions related to those significant accounts and disclosures
(P08_2)
Identify significant classes of transactions (SCOTs) and significant disclosure
processes related to those relevant assertions (S02_1)
When we have completed these steps we gain an understanding of, and document, the
critical path of the SCOTs and significant disclosure processes and how IT supports those
paths and processes. We identify IT applications relevant to the audit (i.e., that support any
of the following):
SCOTs from initiation, recording, processing, correcting as necessary, and reporting
in the financial statements
Significant disclosure processes by which transactions, events, or conditions required
to be disclosed by the applicable financial reporting framework are accumulated,
recorded, processed, summarized and appropriately reported in the financial
statements
The production of electronic audit evidence (EAE), including spreadsheets, prepared
by the entity or the entity’s systems, and used as audit evidence (e.g., used by the
entity in the execution of a control that we plan to test or used by us in the
performance of substantive procedures)
Our understanding of the SCOTs and significant disclosure processes includes an
understanding of the automated aspects of those processes. It is important to understand
whether separate report writing software is in use. In such cases, the report writing software
is identified as an in-scope application. It is also important to understand the use of data
warehouses or other data repositories that are different from the databases used by the
application. Such data warehouses are used to improve the performance of an application
by limiting the interactions with the application to those needed to process data. When the
reporting is from data warehouse rather than the application that processes the data, the
data warehouse should be in scope for ITGCs and controls should be identified to address
the risk of inaccurate or incomplete loading of data into the warehouse.
A risk-based approach requires a detailed understanding of the effects IT has on the
financial reporting of the entity. For non-complex entities, the NCE AA provides guidance on
determining the appropriate audit strategy refer to NCE 1-1.1b and NCE11. For more
complex entities, there is a need for a robust planning discussion and agreement between
the financial and IT auditors on the level of risk associated with the information processed
and stored by the IT applications and related databases.
4
3. Determining our audit strategy for each in-scope IT application
For each IT application identified, we determine our audit strategy to address the risks of
material misstatement arising from the use of IT. We ask ourselves what the best options are
and take into account a mix of elements in considering how best to address the risks of
material misstatement associated with the in-scope IT applications. Sometimes it is
appropriate to decide not to rely on the entity’s IT systems (and related controls). In such
situations, our audit strategy would be to directly test the data and reports we rely on in the
audit. Our determination of the most effective and efficient audit strategy with respect to IT is
based on a number of factors, including:
The number of application and IT dependent manual (ITDM) controls identified for
each IT application. The more application and ITDM controls we identify as relevant
to the audit, the more effective and efficient it may be to test and rely on ITGCs.
The extent of EAE generated by each IT application. The greater extent we use EAE
in the performance of our audit procedures, the more effective and efficient it may be
to test and rely on ITGCs.
The extent to which the entity has ITGCs implemented and evidenced. We consider
how the entity manages IT and our overall preliminary assessment of the
effectiveness of ITGCs, which may be obtained from our prior year audit. Testing and
relying on ITGC in an IT environment with historically effective ITGCs is likely to lead
to a more efficient and effective audit.
The extent to which the ITGCs, and the people who execute them, are the same
across many applications. Evaluating and testing one set of ITGCs may lead to a
more efficient and effective audit.
Whether there are sufficient non-IT dependent controls that address the IT risks of
material misstatement in the SCOT or significant disclosure processes. An entity
having sufficient non-IT dependent controls to address all risks associated with the
use of IT applications is highly unusual for most organizations.
S07_1 of EY GAM provides a number of options for addressing the risks of material
misstatement arising from the use of IT. These options are:
Identify, understand, walkthrough, test and evaluate ITGCs (i.e., rely on ITGCs)
Perform direct testing of application controls and ITDM controls (through performing
substantive procedures to confirm the completeness and accuracy of underlying data
used in these controls). We also perform procedures to obtain reasonable assurance
that the relevant application and ITDM controls, and automated controls over EAE,
function effectively throughout the audit period and are not materially changed during
the period.
Perform substantive procedures to support that the data presented in EAE is
complete and accurate. We perform this testing each time we rely on the relevant
EAE.
For example, an entity’s fixed asset process may be supported by a separate IT application.
The fixed assets register (FAR) from that IT application shows the specifics of the assets: the
costs, the depreciation, the residual value, etc. The entity has identified few application and IT-
dependent manual controls related to fixed asset accounts and the EAE is relatively simple and
straightforward.
We consider the factors above when determining the audit strategy for our IT testing related to
this application. In this example, in a financial statement audit, it may be more efficient to
substantively audit the information presented in the FAR than test ITGCs over the IT application
that processes and maintains the fixed asset information or the related application and ITDM