Auditing Information Technology

Slides:



Advertisements
Similar presentations
Presented by: Diana Tai Ivan Chen Ronnie Lee Wilson Wong Chapter 11 DQ 35 CAAT.
Advertisements

Module 3: Business Information Systems
Software Quality Assurance Plan
Audit of Autonomous District Councils (in an IT environment using FAAM)
ACCOUNTING INFORMATION SYSTEMS
ITAuditing Using GAS & CAATs
ACCOUNTING INFORMATION SYSTEMS
Auditing Computer-Based Information Systems
Auditing Computer Systems
Auditing Computer-Based Information Systems
The Islamic University of Gaza
The Islamic University of Gaza
1 Output Controls Ensure that system output is not lost, misdirected, or corrupted and that privacy is not violated. Exposures of this sort can cause serious.
Computer Assisted Audit Techniques
Computers: Tools for an Information Age
Advanced Accounting Information Systems
Accounting Information Systems, 1st Edition
General Ledger and Reporting System
Chapter Lead Black Slide © 2001 Business & Information Systems 2/e.
Chapter 13 Auditing Information Technology
 2001 Prentice Hall Business Publishing, Accounting Information Systems, 8/E, Bodnar/Hopwood Auditing Information Technology Chapter 16 l What.
Chapter 12/2 Audit Software Techniques
Chapter 12 The Impact of Information Technology on the Audit Process
Main Types of Audit Evidence Advanced Auditing Chapter 7 Dr. Mohamed A. Hamada.
Auditing Computerized Information Systems
Copyright © 2003 by Prentice Hall Computers: Tools for an Information Age Chapter 14 Systems Analysis and Design: The Big Picture.
Chapter 22 Systems Design, Implementation, and Operation Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 22-1.
Lead Black Slide Powered by DeSiaMore1. 2 Chapter 10 Business Operations.
The Islamic University of Gaza
Update from Business Week Number of Net Fraud Complaints – 2002 – 48,252 – 2004 – 207,449.
Chapter 7 Preparation for the Audit ACCT620 Internal Auditing Otto Chang Professor of Accounting.
Auditing Internal Control over Financial Reporting
(SIA) 14 Internal Audit in an Information Technology Environment Standard should be read in the conjunction with the “Preface to the Standards on Internal.
Chapter 7 Auditing Internal Control over Financial Reporting McGraw-Hill/Irwin ©2008 The McGraw-Hill Companies, All Rights Reserved.
Copyright © 2007 Pearson Education Canada 1 Chapter 13: Audit of the Sales and Collection Cycle: Tests of Controls.
Understanding the IT environment of the entity. Session objectives Defining contours of financial accounting in an IT environment and its characteristics.
S4: Understanding the IT environment of the entity.
1 California State University, Fullerton Chapter 10 Business Operations.
Nature and Type of Audit Evidence
McGraw-Hill/Irwin © 2003 The McGraw-Hill Companies, Inc., All Rights Reserved. 6-1 Chapter 6 CHAPTER 6 INTERNAL CONTROL IN A FINANCIAL STATEMENT AUDIT.
 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 1 Chapter 13 Auditing Information Technology.
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin 7-1 Chapter Seven Auditing Internal Control over Financial Reporting.
IS 630 : Accounting Information Systems Auditing Computer-based Information Systems Lecture 10.
McGraw-Hill/Irwin © The McGraw-Hill Companies 2010 Auditing Internal Control over Financial Reporting Chapter Seven.
Copyright © 2007 Pearson Education Canada 1 Chapter 11: Overall Audit Plan and Audit Program.
Hall, Accounting Information Systems, 8e ©2013 Cengage Learning. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly.
Chapter 8-1 Chapter 8 Accounting Information Systems Information Technology Auditing Dr. Hisham madi.
Chapter 3-Auditing Computer-based Information Systems.
McGraw-Hill/Irwin © The McGraw-Hill Companies 2010 Internal Control in a Financial Statement Audit Chapter Six.
Copyright © 2014 Pearson Education, Inc. Publishing as Prentice Hall. Chapter
Chapter 6 Internal Control in a Financial Statement Audit McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
Introduction for the Implementation of Software Configuration Management I thought I knew it all !
Auditing Concepts.
Internal Control in a Financial Statement Audit
Accounting Information Systems An Introduction
TRANSACTION PROCESSING
Chapter 10: Auditing of Information Systems
SYSTEMS ANALYSIS Chapter-2.
FORMAL SYSTEM DEVELOPMENT METHODOLOGIES
Auditing & Investigations I
Defining Internal Control
Other Assurance Services
Purchases and Cash Disbursements Procedures
Types of CAATs Session 3.
CHAPTER 15 AUDITING EDP SYSTEMS.
Audit Execution Session 5.
Internal Control Internal control is the process designed and affected by owners, management, and other personnel. It is implemented to address business.
Information Technology Auditing
Presentation transcript:

Auditing Information Technology Chapter 2 Auditing Information Technology What is auditing through the computer? It is the process of reviewing and evaluating the internal controls in an electronic data processing system. What is auditing with the computer? It is the utilization of the computer by an auditor to perform some audit work that otherwise would have to be done manually.

Structure of Financial Statement Audit The primary objective and responsibility of the external auditor is to attest to the fairness of a firm’s financial reports. The external auditor serves the firm’s stockholders, the government, and the general public. The internal auditor serves a firm’s management.

Structure of Financial Statement Audit Various types of professional certifications are applicable to auditing. What are these? CPA (certified public accountant) CISA (certified information systems auditor) CIA (certified internal auditor) Audits are almost universally divided into two components.

Structure of Financial Statement Audit Transactions Accounting System Financial Reports Cash Bank Receivables Customers (Confirm balances) Compliance Testing Interim Audit Substantive Testing Financial Statement Audit

Auditing Around the Computer An accounting system is comprised of input, processing, and output. In the around-the-computer approach, the processing portion is ignored. Auditing through the computer may be defined as the verification of controls in a computerized system. Auditing with the computer is the process of using information technology in auditing.

Control Framework in IT Environment Applications Controls Computer Application Systems and Programs Internal Controls Application Systems Development General Controls Computer Service Center

Auditing with the Computer What are some of the potential benefits of using information systems technology in an audit? Computer-generated working papers are generally more legible and consistent. Time may be saved by eliminating manual footing, cross footing, and other routine calculations.

Auditing with the Computer Calculations, comparisons, and other data manipulations are more accurately performed. Analytical review calculations may be more efficiently performed. Project information may be more easily generated and analyzed.

Auditing with the Computer Standardized audit correspondence may be stored and easily modified. Morale and productivity may be improved by reducing the time spent on clerical tasks. Increased cost-effectiveness is obtained by reusing and extending existing electronic audit applications to subsequent audits. Increased independence from information systems personnel is obtained.

Information Systems Auditing Technology Technique: Test data Description: Test data are input containing both valid and invalid data. Example: Payroll transactions for fictitious employees are processed concurrently with valid payroll transactions.

Information Systems Auditing Technology Test Data Hypothetical Transactions Computer Processing Using Master Program Error Listing Auditor’s Expected Output Compare

Information Systems Auditing Technology Technique: Integrated test facility (ITF) Description: ITF involves both the use of test data and the creation of fictitious records (vendors, employees) on the master files of a computer system. Example: Payroll transactions for fictitious employees are processed concurrently with valid payroll transactions.

Information Systems Auditing Technology Transactions ITF Transactions Computer Application System Data Files ITF Data Reports Without ITF Data Reports Containing ITF Information

Information Systems Auditing Technology Technique: Parallel simulation Description: Processing real data through audit programs. The simulated output and the regular output are then compared. Example: Depreciation calculations are verified by processing the fixed- asset master file with an audit program.

Information Systems Auditing Technology Computer Application System Function to Be Verified Transactions Parallel Simulation Program Report Compare Simulation Report

Information Systems Auditing Technology Technique: Audit software Description: Computer programs that permit the computer to be used as an auditing tool. Example: An auditor uses a computer program to extract data records from a master file.

Information Systems Auditing Technology Technique: Generalized audit software (GAS) Description: GAS is audit software that has been specifically designed to allow auditors to perform audit-related data processing functions. Example: An auditor uses GAS to search computer files for unusual items.

Information Systems Auditing Technology Technique: PC software Description: Software that allows the auditor to use a PC to perform audit tasks. Example: A PC spreadsheet package is used to maintain audit working papers and audit schedules.

Information Systems Auditing Technology Deloitte & Touche AuditSystem/2™ Smart Audit Support Work Papers Access to Information Document Manager Trial Balance File Interrogation Multilocation Support MS Word MS Excel MS Access Lotus cc:mail ACL Folio VIEWS Other Applications

Information Systems Auditing Technology Technique: Embedded audit routines Description: Special auditing routines included in regular computer programs so that transaction data can be subjected to audit analysis. Example: Data items that are exceptions to auditor-specified edit tests included in a program are written to a special audit file.

Information Systems Auditing Technology Production Transactions Production Computer Application System Embedded Audit Data Collection Module Production Reports Audit Reports

Information Systems Auditing Technology Technique: Extended records Description: Modification of programs to collect and store data of audit interest. Example: A payroll program is modified to collect data pertaining to overtime pay.

Information Systems Auditing Technology Technique: Snapshot Description: Modifications of programs to output data of audit interest. Example: A payroll program is modified to output data pertaining to overtime pay.

Information Systems Auditing Technology Technique: Tracing Description: Tracing provides a detailed audit trail of the instructions executed during the program’s operation. Example: A payroll program is traced to determine if certain edit tests are performed in the correct order.

Information Systems Auditing Technology Technique: Review of system documentation Description: Existing system documentation such as program flowcharts are reviewed for audit purposes. Example: An auditor desk checks the processing logic of a payroll program.

Information Systems Auditing Technology Technique: Control flowcharting Description: Analytic flowcharts or other graphic techniques are used to describe the controls in a system. Example: An auditor prepares an analytic flowchart to review controls in the payroll application system.

Information Systems Auditing Technology Technique: Mapping Description: Special software is used to monitor the execution of a program. Example: The execution of a program with test data as input is mapped to indicate how extensively the input tested compares with individual program statements.

General Approach to an Information Systems Audit Most approaches to an information systems audit follow some variation of a three-phase structure. The first phase consists of an initial review and evaluation of the area to be audited and audit plan preparation. The second phase is a detailed review and evaluation of controls.

General Approach to an Information Systems Audit The third phase involves compliance testing and is followed by analysis and reporting of results. The initial review phase determines the course of action the audit will take. It includes the following: decisions concerning specific areas to be investigated

General Approach to an Information Systems Audit the deployment of audit labor the audit technology to be used the development of time and/or cost budget for the audit The primary control over the conduct of an information systems audit centers on documentation and review of performance.

General Approach to an Information Systems Audit What is an audit program? It is a detailed list of the audit procedures to be applied on a particular audit. Standardized audit programs for particular audit areas have been developed and are common in all types of auditing.

General Approach to an Information Systems Audit In the second general phase of the audit, effort is focused on fact-finding in the area(s) selected for audit. Documentation of the application area is reviewed. Data concerning the operation of the system are reviewed.

General Approach to an Information Systems Audit In the third phase of the audit, compliance tests are undertaken to provide reasonable assurance that internal controls exist and operate as prescribed.

Information Systems Application Audits Application controls are divided into three general areas. What are these areas? Input Processing Output

Application Systems Development Audits There are three general areas of audit concern in the systems development process. They are: Systems development standards Project management Program change control What are systems development standards?

Application Systems Development Audits Systems development standards are the documentation governing the design, development, and implementation of application systems. What is project management? It consists of project planning and project supervision.

Application Systems Development Audits What is the objective of program change controls? It is to prevent unauthorized and potentially fraudulent changes from being introduced into previously tested and accepted programs. Normally, an audit of the computer service center is undertaken before any application audits to ensure the general integrity of the environment in which the application will function.