1
Chapter 7 Auditing Information Technology-Based
Processes
Instructor Manual
Introduction to Auditing IT Processes. Most businesses rely upon computerized
systems to assist in the accounting function. Advancements in technology have
brought huge increases in the amount of information that is readily available for
Types of Audits and Auditors. The main purpose of an audit is to assure users of
financial information about the accuracy and completeness of the information by
evaluating evidence supporting the underlying procedures, transactions, and/or
account balances. This evidence is compared to established criteria. There are
three primary types of audits, including (1) compliance audits, (2) operational audits,
and (3) financial statement audits. Although each type of audit involves an
investigation of supporting evidence, each type has a different objective.
Compliance audits determine whether the client has complied with regulations
Internal auditors, IT auditors, and governmental auditors typically conduct
compliance audits and operational audits. Certified public accountants (CPAs) may
conduct any type of audit, but CPA firms tend to concentrate on financial statement
audits and other financial assurance services. It is important that CPAs be
independent, or objective and neutral, with respect to their audit clients and the
financial information being audited. Because many companies use sophisticated IT
Information Risk and IT-Enhanced Internal Control. Information risk is the
chance that information used by decision-makers may be inaccurate. Information
risk may be caused by:
The remoteness of information, or the extent to which the source of the
information is removed from the decision-maker.
The volume and complexity of the underlying data.
The motive, goals, or viewpoint of the preparer of the information.
The most common way to reduce information risk is to rely upon information that has
been audited by an independent party. This is why a chapter on information-based
processing and the related audit function is included in the study of accounting
information systems.
Authoritative Literature Used in Auditing. The work of an auditor must be
conducted in accordance with several sources of authoritative literature, including:
Generally accepted auditing standards (GAAS), which are broad guidelines for
an auditor’s professional responsibilities in the areas of general qualifications and
conduct (general standards), performance of the audit (standards of fieldwork),
and written communication of results (standards of reporting). Exhibit 7-1
presents the ten generally accepted auditing standards.
that pertain to attributes of internal audit activities, performance criteria, and
implementation guidance.
The Information Systems Audit and Control Association (ISACA) issues
information systems auditing standards (ISASs) that address control and security
issues and provide relevant guidelines for conducting and IT audit.
3
guidelines and other resources such as CPA firm’s own policies and procedures are
needed for such specific guidelines.
Management Assertions and Audit Objectives. Management assertions are
claims regarding the financial condition of the business organization and its
results of in terms of its operations, financial results, and compliance with
applicable laws and regulations. Management assertions relate to
Phases of an IT Audit. Exhibit 7-4 provides an overview of the four primary phases
of the audit: planning, tests of controls, substantive tests, and audit
completion/reporting. Through each phase of the audit, evidence is accumulated as
a basis for supporting the conclusions reached by the auditors. Auditors use
combinations of various techniques to collect evidence, including physically
examining and inspecting assets or supporting documentation, obtaining written
confirmation from an independent source, rechecking or recalculating information,
observing activities, making inquiries of client personnel, and analyzing financial
relationships and trends.
o Audit Planning. Auditors must gain a thorough understanding of the company’s
business and financial reporting systems during the planning phase of the audit.
process of convergence, changes in the audit approach should be anticipated .
Use of Computers in Audits. The audit planning tasks of evaluating internal
controls and designing meaningful audit tests is more complex for automated
accounting systems than for manual systems. In recognition of the fact that
accounting records and files often exists in both paper and electronic form,
4
Misstatements may occur through the data entry and processing functions of the
system. Auditors must consider the effects of such computer processing on the
system. It requires the auditors to understand the computer system logic and
related IT controls. Auditing through the computer is necessary when the
auditor wants to test computer controls as a basis for reducing the amount of
substantive testing required, when the auditor is required to report on internal
controls of a public company, and when supporting documents are available
functioning in compliance with management’s intentions. Both general
controls and application controls must be considered.
General Controls. The effectiveness of general controls is the foundation
of the IT control environment because general controls affect all computer
applications. If general controls are not functioning as designed, auditors
IT administration. IT departments should be organized so that an effective
and efficient workplace is created and supported. The important aspects of
administrative control include personal accountability and segregation of
incompatible responsibilities, job descriptions and clear lines of authority,
5
Security controls. Auditors must be concerned about whether a company’s
computer system has controls in place to prevent unauthorized access that
may result in the destruction or alteration of information within the accounting
information systems. Unauthorized access may be from an internal or
external source, and can be controlled internally through the use of various
Application Controls. Since companies tend to use many different computer
programs in their day-to-day business, there may be different types of application
controls to consider in an audit. However, application controls are considered
only if general controls have already been tested and found to be operating
effectively. It would not be worthwhile to test application controls if the auditor
already knew that the underlying general controls were weak.
The three main functions of computer applications include input, processing, and
output. Each of these functions should be tested by the auditor.
Auditors are concerned about whether errors are being prevented or detected
Data accuracy tests are typically performed to evaluate the processing
integrity of a company’s computer systems. Limit tests, balancing tests, run
to-run totals, mathematical accuracy tests, and completeness or redundancy
tests can each be performed to test for the possibility of lost, altered, or
unprocessed data. When evaluating financial information, auditors can often
use Benford’s Law to help discover whether errors or fraud may exist in a
data set. Benford’s Law applies to large data sets of naturally-occurring
6
Audit tests that evaluate general controls over access and backup procedures
may also be used in the testing of specific computer application outputs.
Regardless of whether the outputs are printed or retained electronically,
o Tests of Transactions and Tests of Balances. When auditors test the
accuracy of monetary amounts of transactions and account balances, this is
known as substantive testing. Substantive testing therefore determines whether
financial information is accurate, whereas control tests determine whether the
financial information is managed under a system that promotes accuracy. Some
level of substantive testing is required on all financial statement audits, however,
the results of the tests of controls will determine the extent of substantive testing.
There is an inverse relationship between the two: the stronger the internal
controls, the less substantive testing is required, and vice versa.
Some testing strategies used to test controls can also be used to perform
substantive testing. For instance, parallel simulations, the test data method, the
embedded audit module, and the integrated test facility can be used for both
also approve of the use of continuous auditing. Continuous auditing helps
auditors stay involved in their client’s business and perform audit testing in a
more thorough manner. This requires that the auditors have online access to the
company’s systems so that data can be obtained on an ongoing basis. Then the
data are downloaded and tested by auditors within a very short timeframe. Most
CPA firms used generalized audit software (GAS) or data analysis software
7
Audit Completion/Reporting. The final phase of the audit involves overall
evidence accumulation and drawing final conclusions. The auditors must
determine whether the financial statements are presented fairly and whether all
of the evidence supports the financial information presented. The auditors must
also consider whether the extent of testing has been adequate in light of the risks
and controls identified during the planning phase versus the results of
procedures performed in the testing phases.
Auditors have four choices from which to select a report that communicates the
final conclusions of the audit. The four types of reports include an unqualified
opinion, which states that the financial statements are fairly stated; a qualified
Other Audit Considerations.
o Different IT Environments. Auditors are responsible for understanding how
information is managed so that it is reliable. A company’s computer systems may
include mainframe and client-server systems, microcomputers and personal
computers (PCs), networks, database management systems, and/or e
commerce systems. PCs may face a greater risk of loss and therefore require
strong controls such as locked hard drives, password protection, separation of
operating and programming functions, backup procedures, and virus protection.
All of the risks and audit procedures that apply to PCs are also likely to exist in
networks, but the potential for loss is much greater because of the larger number
8
to merely identifying the threats inherent in a cloud computing environment, it is
particularly difficult to estimate their potential costs and overall impact. Exhibit 7
11 presents the general areas of risk assessment that should be addressed by
auditors, and some sample questions for each area. Useful guidance in
conducting audit procedures for cloud computing is available from ISACA’s IT
Assurance Framework, the International Organization for Standardization (ISO)
user guides, and the AICPA’s Service Organization Controls (SOC) Framework.
Auditors can perform their own testing, as described previously, or they can rely
upon SOC reports from the service provider’s auditors. The SOC 1 report
addresses internal controls over financial reporting. A SOC 1 Type I report
o Changes in a Client’s IT Environment. When a company changes the type of
hardware or software used or otherwise modifies its IT environment, auditors
should consider applying tests of controls at multiple times throughout the period
in order to determine the effectiveness of controls under each of the systems.
Auditors must evaluate a client’s procedures for developing, implementing, and
maintaining new systems or changes in existing systems.
o Sampling. Auditors must rely on sampling to test a limited number of items and
then use these limited tests to draw conclusions about the overall control
always some risk that a sample may not represent the population as a whole.
Ethical Issues Related To Auditing.
The AICPA has established a Code of Professional Conduct to provide the
foundation for ethical behavior expected of CPAs. The six principles of the Code
include:
Responsibilities
9
could create bias.
Internal auditors and IT auditors must abide by ethical standards established by
the IIA and ISACA, respectively. The IIA Code of Ethics is founded on the
principles of integrity, objectivity, confidentiality, and competency. Similarly,
ISACA’s Code of Professional Ethics recognizes due diligence, objectivity,
competency, communication, maintaining privacy and confidentiality, and serving
in the interests of stakeholders.
The Sarbanes-Oxley Act places restrictions on auditors by limiting the types of
services they can provide for their audit clients. This is intended to promote
objectivity in the conduct of their work by prohibiting the types of services that
In fulfilling their ethical responsibilities, auditors must practice professional
skepticism, which means that they should maintain a questioning attitude and
persistent approach to evaluating evidence. This is important in order to increase
the chances of detecting fraud, which may be especially difficult to find if
perpetrated by managers who can override internal controls. Forensic audit
testing performed by certified fraud examiners (CFEs) may be used in cases
where fraud is suspected or is known to exist.
Accountants are sometimes called upon to perform a specialized type of
assurance service called forensic auditing. Forensic auditing involves audit
testing specifically for finding and preventing fraud, and is used for companies
where fraud is known or believed to exist.