AUDITING IN A COMPUTERIZED ENVIRONMENT
AUDITING IN A COMPUTERIZED ENVIRONMENT
CHARACTERISTICS OF CIS
Lack of visible transaction trails
In a manual system, it is normally possible to follow a transaction through the system by examining source
documents, entity’s records, and financial reports. In a CIS environment, data can be entered directly into the
computer system without supporting documents. Furthermore, records and files may not be printed and cannot
be read without using the computer.
Consistency of Performance
CIS performs functions exactly as programmed. If the computer is programmed to perform specific data
processing task, it will never get tired of performing the assigned task in exactly the same manner.
Ease of Access to Data and Computer Programs
In a CIS environment, data and computer programs may be accessed and altered by unauthorized persons
leaving no visible evidence. It is important, therefore, that appropriate controls are incorporated to the system to
limit access to data files and programs only to authorized personnel.
Concentration of Duties
Proper segregation of duties is an essential characteristic of a sound internal control system. However, because
of the ability of the computer to process data efficiently, there are functions that are normally segregated in
manual processing that are combined in a CIS environment.
Systems generated transactions
Certain transactions may be initiated by the CIS itself without the need for an input document. For example,
interest may be calculated and charged automatically to customers’ account balance on the basis of pre–
authorized terms contained in a computer program.
Vulnerability of data and program storage media
In a manual system, the records are written in ink on substantial paper. The only way to lose the information is to
lose or to destroy the physical records. The situation is completely different in a CIS environment.
Internal Control in a CIS Environment
Many of the control procedures used in manual processing also apply in a CIS environment. Examples of such
control procedures include authorization of transactions, proper segregation of duties, and independent
checking. The elements of internal control are the same, the computer just changes the methods by which these
elements are implemented.
General Controls – control policies and procedures that relate to the overall CIS.
1. Organizational Controls
Just in a manual system, there should be a written plan of the organization, with clear assignment of
authority and responsibility. In a CIS environment, the plan of an organization for an entity’s computer
system should include segregation between the user and CIS department, and segregation of duties within
the CIS department.
AUDIT PROCEDURES RELATING TO ORGANIZATIONAL STRUCTURES
– obtain and review the corporate policy on computer security
– review relevant documentation to determine if individuals or groups are performing incompatible
functions
– review systems documentation and maintenance records for a sample of applications
– through observation, determine that the segregation policy is being followed in practice
– review user rights and privileges to verify that programmers have access privileges consistent with their
job description.
a. Segregation between the CIS department and the user department
CIS department must be independent of all departments within the entity that provide input data or
that use output generated by the CIS.
The function of CIS department is to process transactions. However, no transaction will be processed
unless it is initiated by the user department. Therefore, all changes in computer files must be initiated
and authorized by the user department.