Michael Romeu-Lugo MBA, CISA March 27, 2017

Slides:



Advertisements
Similar presentations
Copyright © 2013 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin.
Advertisements

Audit of Autonomous District Councils (in an IT environment using FAAM)
Learning and Development Evidence Collection Planning January 2015.
Financial Statements Audit
Discussion on SA-500 – AUDIT EVIDENCE
S17: Field work. Session Objectives  To explain the manner in which field audit is carried out.  To explain the nature of evidence and the different.
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
IS Audit Function Knowledge
5-1 McGraw-Hill/Irwin ©2002 by The McGraw-Hill Companies, Inc. All rights reserved. Chapter 5 Audit Planning.
Internal Control in a Financial Statement Audit
The Information Systems Audit Process
Audit Planning and Documentation
Internal Control. COSO’s Framework Committee of Sponsoring Organizations 1992 issued a white paper on internal control Since this time, this framework.
Mª ANGELA JIMENEZ 1 UNIT 4. EXTERNAL AUDIT BASIS CONCEPTS.
Purpose of the Standards
Audit Programme. Audit Assertions  As part of the planning stage, auditors need to prepare audit tests to test the account areas.  To assist the auditors.
Lecture 7 Audit Documentation
Auditing Standards IFTA\IRP Audit Guidance Government Auditing Standards (GAO) Generally Accepted Auditing Standards (GAAS) International Standards on.
Auditing & Assurance Services, 6e
Auditing Internal Control over Financial Reporting
Session 3 & 4. Institute of Internal Auditors Inc (IIA) was created for internal auditors in 1941 Generally accepted criteria of a profession are: –Adopting.
7 - 1 Copyright  2003 Pearson Education Canada Inc. CHAPTER 7 Audit Planning and Documentation.
Chapter 7 Preparation for the Audit ACCT620 Internal Auditing Otto Chang Professor of Accounting.
Internal Control in a Financial Statement Audit
Chapter 7 Auditing Internal Control over Financial Reporting McGraw-Hill/Irwin ©2008 The McGraw-Hill Companies, All Rights Reserved.
Evidence and Documentation
Internal Control in a Financial Statement Audit
Appendix E – Checklist for Review of Performance Audits Presented by: Ashton Coleman Department of Defense Office of the Inspector General August 16, 2012.
Evaluation of Internal Control System
QUALITY OF EVIDENCE FRCC Compliance Workshop September/October 2008.
Understanding the IT environment of the entity. Session objectives Defining contours of financial accounting in an IT environment and its characteristics.
S4: Understanding the IT environment of the entity.
Copyright © 2007 Pearson Education Canada 1 Chapter 1: The Demand for Auditing and Assurance Services.
State of the Art Audit Evidence
College Reviews An Overview Presented by Howard Lutwak, CIA Director of Internal Audit January 2004.
[Hayes, Dassen, Schilder and Wallage, Principles of Auditing An Introduction to ISAs, edition 2.1] © Pearson Education Limited 2007 Slide 7.1 Internal.
McGraw-Hill/Irwin © 2003 The McGraw-Hill Companies, Inc., All Rights Reserved. 6-1 Chapter 6 CHAPTER 6 INTERNAL CONTROL IN A FINANCIAL STATEMENT AUDIT.
 Definition of a quality Audit  Types of audit  Qualifications of quality auditors  The audit process.
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin 6-1 Chapter Six Internal Control in a Financial Statement Audit.
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin 7-1 Chapter Seven Auditing Internal Control over Financial Reporting.
Chapter 4 Audit Evidence and Audit Documentation McGraw-Hill/Irwin Copyright © 2008 by The McGraw-Hill Companies, Inc. All rights reserved.
IS 630 : Accounting Information Systems Auditing Computer-based Information Systems Lecture 10.
Chapter 5 Evidence and Documentation McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
Audit Evidence Process
Lecture 9 Audit Evidence
ICAJ/PAB - Improving Compliance with International Standards on Auditing Planning an audit of financial statements 19 July 2014.
AUDIT QUALITY AND ASSURANCE 2 ND AND 3 RD OCTOBER 2014 HILTON HOTEL ANALYTICAL PROCEDURES 1.
F8: Audit and Assurance. 2 Designed to give you knowledge and application of: Section A: Audit Framework and Regulation Section B: Internal audit Section.
McGraw-Hill/Irwin © The McGraw-Hill Companies 2010 Internal Control in a Financial Statement Audit Chapter Six.
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin 4-1 Chapter Four Audit Evidence and Audit Documentation Chapter.
Chapter 6 Internal Control in a Financial Statement Audit McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
 Planning an audit of cost statements, records and other related documents is considered necessary to ensure achievement of audit objectives with available.
Internal Control Chapter 7. McGraw-Hill/Irwin © 2008 The McGraw-Hill Companies, Inc., All Rights Reserved. 7-2 Summary of Internal Control Definition.
Jean-Pierre Garitte Budapest 29 March 2017
Audit Documentation.
MODULE 8: GOVERNANCE AUDIT EVIDENCE AND REVIEW
Internal Control in a Financial Statement Audit
AUDIT LECTURE 6 AUDIT EVIDENCE HOLY KPORTORGBI
CHAPTER 7 Audit Planning and Documentation
BASIC AUDITING CONCEPTS: MATERIALITY, RISK ASSESSMENT, AND EVIDENCE
Internal and Governmental Financial Auditing and Operational Auditing
SYSTEMS ANALYSIS Chapter-2.
LATIHAN MID SEMINAR AUDIT hiday.
MODULE 2 INTRODUCTION TO GOVERNANCE AUDIT
INTRODUCTION TO Compliance audit METHODOLGY and CAM
Evidence and Documentation
AUDIT TESTS.
Jean-Pierre Garitte Skopje 8 April 2019
Tools and Techniques for the Auditor: Fieldwork
Presentation transcript:

Michael Romeu-Lugo MBA, CISA March 27, 2017 IT Audit Process Michael Romeu-Lugo MBA, CISA March 27, 2017

Agenda Audit Planning Evidence References: PS 1203 / PG 2203 ITAF 3rd Edition Information Systems Auditing: Tools and Techniques – Creating Audit Programs

Performance Standard 1203 – Performance and Supervision ITAF 3rd Edition, page 10 Statements - “IS audit and assurance professionals shall…” 1203.1 Conduct the work in accordance with the approved IS audit plan to cover identified risk and within the agreed-on schedule. 1203.2 Provide supervision to IS audit staff for whom they have supervisory responsibility, to accomplish audit objectives and meet applicable professional audit standards. 1203.3 Accept only tasks that are within their knowledge and skills or for which they have a reasonable expectation of either acquiring the skills during the engagement or achieving the task under supervision. 1203.4 Obtain sufficient and appropriate evidence to achieve the audit objectives. The audit findings and conclusions shall be supported by appropriate analysis and interpretation of this evidence. 1203.5 Document the audit process, describing the audit work and the audit evidence that supports findings and conclusions. 1203.6 Identify and conclude on findings.

Performance Guideline 2203 – Performance and Supervision ITAF 3rd Edition, Page 95 Planning and risk assessment 1201 Engagement Planning 1202 Risk Assessment in Planning Identifying controls Assessing controls and gathering evidence Design effectiveness Operational effectiveness Documenting work performed and identifying findings Confirming findings and following up on corrective actions Confirm with Auditee If corrected before end of engagement auditor should mention original findings and document actions taken Drawing conclusions and reporting 1204 Reporting Draw conclusions and report about impact of finding on audit objectives MAIN TASKS

Performance Guideline 2203 – Performance and Supervision ITAF 3rd Edition, Page 98 Documenting Professionals should prepare sufficient, appropriate and relevant documentation in a timely manner that provides a basis for the conclusion and contains evidence of the review performed. Sufficient, appropriate and relevant documentation should enable a prudent and informed person, with no previous connection to the audit engagement, to re-perform the tasks performed during the audit engagement and reach the same conclusion. Documentation should include: Audit engagement objectives and scope of work Audit engagement project plan Audit work programme Audit steps performed Evidence gathered Conclusions and recommendations MAIN TASKS

Audit Work Programme* “Work Programme” = “Audit Program” Procedures and instructions Test controls Evaluate results Obtain suitable evidence to form an opinion Report findings to stakeholders Include: Areas to be audited High-level objectives Tools and techniques for testing controls * Information Systems Auditing: Tools and Techniques – Creating Audit Programs

Audit Program – Planning Phase

Audit Program – Planning Steps Examples Sources of information 1. Define audit subject ERP system Data Center BYOD Security Annual audit plan Risk assessment Organizational change plans Legal / regulatory changes Mergers and Acquisitions 2. Define audit objective ERP Inventory management DC environmental controls iOS devices Audit management Executive management Previous audit reports Internal policies, standards and procedures Risk assessments Legislation or regulations applicable to enterprise. 3. Set audit scope Assuring compliance with SOX SAP MM – Inventory Management Data Center Temperature and Humidity Controls iOS data protection and encryption Legislation or regulations applicable to enterprise Previous audit results SLA and compliance issues Problem and Incident tickets

Audit Program – Planning (continued) Steps Examples Sources of information 4. Perform preaudit planning Location of IT functions supporting SAP MM, location of supply operations personnel. Philadelphia Distribution Center: 2017 Broad Street, Philadelphia PA Mobile Management organization Organization charts Previous audit reports Process maps and flow diagrams Vendor contracts Network maps

Audit Program – Planning: Step 5 Develop Procedure Activity Example Identify and obtain departmental policies, standards and guidelines for review Information security policies Segregation of duties (SoD) policies Purchasing policies Authorization matrix Industry standards or guidelines Compliance requirements Identify a list of individuals to interview Accounts payable clerks Subject matter experts (SME) Supervisors and Managers Identify methods (including tools) to perform the evaluation. Compliance Testing Substantive Testing Tools Questionnaires Checklists Spreadsheets Computer Assisted Auditing Tools (CAATs)

Audit Program – Planning: Step 5 Develop Procedure Activity Develop tools and methodology to test and verify controls. See the previous step: “Identify methods (including tools)…” Identify criteria for evaluating the tests (similar to a test script for the auditor to use in conducting the evaluation). Organization Structure Review Policies, standards and procedures review Documentation review (user manuals, training material, …) Interviews with key personnel Observation of procedures as they are performed Reperformance Walk-Throughs Data analysis Define a methodology to evaluate that the testing and its results are accurate (and repeatable if necessary). Refer to standard 1205 – Evidence

Performance Standard 1205 - Evidence Statements 1205.1 IS audit and assurance professionals shall obtain sufficient and appropriate evidence to draw reasonable conclusions on which to base the engagement results. 1205.2 IS audit and assurance professionals shall evaluate the sufficiency of evidence obtained to support conclusions and achieve engagement objectives. Evidence must be: Relevant – consistent with audit objectives and supports audit findings and recommendations. Reliable – accurate, verifiable and from objective sources. Sufficient – factual, adequate and convincing such that a prudent person would reach the same conclusions as the auditor. Must be relevant? Is consistent with audit objectives and supports audit findings and recommendations. Must be reliable? Accurate, verifiable and from objective sources. Must be sufficient? Factual, adequate and convincing such that a prudent person would reach the same conclusions as the auditor.

Evidence-Gathering Procedures Comments Inquiry and Confirmation Least reliable. Consists of interviews usually driven by checklists. Inspection of Records Paper, computer printouts, plans and reports, etc. Originals are better than copies; system-generated; gathered by auditor. Inspection of Assets Existence and condition. Verify/record ID, serial#, etc. Observation Watching a person or system execute the process or transaction Re-performance Executing again and recording how it happens, not how it should happen. Re-calculation Carrying out calculations manually or by other independent means recording the results. Scanning Looking for things that do not belong or do not follow a pattern. Use the most appropriate of these. Inquiry and Confirmation – password complexity example

Other Evidence Considerations Source, nature and authenticity Written rather than oral From independent sources Obtained professionally rather than by auditee Certified Kept by an independent party The results of inspection and observation Identify, cross-reference and catalogue Retention, availability and disposal Protect from unauthorized disclosure or modification

Coming Soon – Next Week Sampling Testing Techniques Sampling Types Sampling Techniques Testing Techniques