AUDITING IN A COMPUTERIZED ENVIRONMENT
AUDITING IN A COMPUTERIZED ENVIRONMENT
CHARACTERISTICS OF CIS
Lack of visible transaction trails
In a manual system, it is normally possible to follow a transaction through the system by examining source
documents, entity’s records, and financial reports. In a CIS environment, data can be entered directly into the
computer system without supporting documents. Furthermore, records and files may not be printed and cannot
be read without using the computer.
Consistency of Performance
CIS performs functions exactly as programmed. If the computer is programmed to perform specific data
processing task, it will never get tired of performing the assigned task in exactly the same manner.
Ease of Access to Data and Computer Programs
In a CIS environment, data and computer programs may be accessed and altered by unauthorized persons
leaving no visible evidence. It is important, therefore, that appropriate controls are incorporated to the system to
limit access to data files and programs only to authorized personnel.
Concentration of Duties
Proper segregation of duties is an essential characteristic of a sound internal control system. However, because
of the ability of the computer to process data efficiently, there are functions that are normally segregated in
manual processing that are combined in a CIS environment.
Systems generated transactions
Certain transactions may be initiated by the CIS itself without the need for an input document. For example,
interest may be calculated and charged automatically to customers’ account balance on the basis of pre
authorized terms contained in a computer program.
Vulnerability of data and program storage media
In a manual system, the records are written in ink on substantial paper. The only way to lose the information is to
lose or to destroy the physical records. The situation is completely different in a CIS environment.
Internal Control in a CIS Environment
Many of the control procedures used in manual processing also apply in a CIS environment. Examples of such
control procedures include authorization of transactions, proper segregation of duties, and independent
checking. The elements of internal control are the same, the computer just changes the methods by which these
elements are implemented.
General Controls – control policies and procedures that relate to the overall CIS.
1. Organizational Controls
Just in a manual system, there should be a written plan of the organization, with clear assignment of
authority and responsibility. In a CIS environment, the plan of an organization for an entity’s computer
system should include segregation between the user and CIS department, and segregation of duties within
the CIS department.
AUDIT PROCEDURES RELATING TO ORGANIZATIONAL STRUCTURES
obtain and review the corporate policy on computer security
review relevant documentation to determine if individuals or groups are performing incompatible
functions
review systems documentation and maintenance records for a sample of applications
through observation, determine that the segregation policy is being followed in practice
review user rights and privileges to verify that programmers have access privileges consistent with their
job description.
a. Segregation between the CIS department and the user department
CIS department must be independent of all departments within the entity that provide input data or
that use output generated by the CIS.
The function of CIS department is to process transactions. However, no transaction will be processed
unless it is initiated by the user department. Therefore, all changes in computer files must be initiated
and authorized by the user department.
b. Segregation of duties within the CIS department
Functions should be properly segregated for good organizational controls. The entity’s organizational
structure should provide for definite lines of authority and responsibility within the CIS department.
Position
Primary Responsibility
CIS Director
Exercises control over the CIS operation
Systems Analyst
Designs new system, evaluates and improves
existing system, and prepares specification for
programmers
Programmer
Guided by the specifications of the systems
analyst, the programmer writes a program, tests
and debugs such programs, and prepares the
computer operating instructions.
Computer Operator
Using the program and detailed operating
instructions prepared by the programmer,
computer operator operates the computer to
process transactions.
Data Entry Operator
Prepares and verifies input data for processing
Librarian
Maintains custody of systems documentation,
programs, and files
Control Group
Reviews all input procedures, monitors computer
processing, follow up data processing errors,
reviews the reasonableness of output, and
distribute output to authorized personnel.
2. Systems development and documentation controls
Systems development as well as changes thereof must be approved by the appropriate level of management