3
2. Determining the in-scope IT applications
As part of “understanding the business,” we gain an understanding the role of IT in the entity.
IT can significantly affect the entity’s ability to achieve its business objectives and is often an
integral component in producing information used to support decisions made by
management. We obtain an understanding of the extent to which the entity uses IT to
process or generate information and determine whether the use of IT gives rise to risks of
material misstatements within the financial statements.
The next steps in our audit process are to:
Identify significant accounts and disclosures (P08_1)
Determine relevant assertions related to those significant accounts and disclosures
(P08_2)
Identify significant classes of transactions (SCOTs) and significant disclosure
processes related to those relevant assertions (S02_1)
When we have completed these steps we gain an understanding of, and document, the
critical path of the SCOTs and significant disclosure processes and how IT supports those
paths and processes. We identify IT applications relevant to the audit (i.e., that support any
of the following):
SCOTs from initiation, recording, processing, correcting as necessary, and reporting
in the financial statements
Significant disclosure processes by which transactions, events, or conditions required
to be disclosed by the applicable financial reporting framework are accumulated,
recorded, processed, summarized and appropriately reported in the financial
statements
The production of electronic audit evidence (EAE), including spreadsheets, prepared
by the entity or the entity’s systems, and used as audit evidence (e.g., used by the
entity in the execution of a control that we plan to test or used by us in the
performance of substantive procedures)
Our understanding of the SCOTs and significant disclosure processes includes an
understanding of the automated aspects of those processes. It is important to understand
whether separate report writing software is in use. In such cases, the report writing software
is identified as an in-scope application. It is also important to understand the use of data
warehouses or other data repositories that are different from the databases used by the
application. Such data warehouses are used to improve the performance of an application
by limiting the interactions with the application to those needed to process data. When the
reporting is from data warehouse rather than the application that processes the data, the
data warehouse should be in scope for ITGCs and controls should be identified to address
the risk of inaccurate or incomplete loading of data into the warehouse.
A risk-based approach requires a detailed understanding of the effects IT has on the
financial reporting of the entity. For non-complex entities, the NCE AA provides guidance on
determining the appropriate audit strategy – refer to NCE 1-1.1b and NCE11. For more
complex entities, there is a need for a robust planning discussion and agreement between
the financial and IT auditors on the level of risk associated with the information processed
and stored by the IT applications and related databases.