Progress Report on proposed GUID on Information TECHNOLOGY Audit

Slides:



Advertisements
Similar presentations
1 Revision of ISSAI 30 – Code of Ethics Project proposal to the Steering Committee of the INTOSAI Professional Standards Committee Bahrain, May 2014.
Advertisements

Agenda item 5 ISSAI 200 and ISSAI Changes to the ISSAIs.
Due Process – ISSAIs and INTOSAI GOVs Roberto José Domínguez Moro Superior Audit Office of Mexico INTOSAI Working Group on Public Debt October, 2009.
The 22 nd meeting of the INTOSAI Working Group on IT Audit (WGITA) KPI Project Final Report — Key Performance Indicators Methodology for Auditing IT Programs.
Development of ISSAI 5300 on IT AUDIT
Conducting the IT Audit
PSC INTOSAI Professional Standards Committee Harmonisation of ISSAIs – Revision of the Fundamental Auditing Principles.
Revision of ISSAI 30 INTOSAI Code of Ethics
Progress Report to the PSC Steering Committee INTOSAI PSC Subcommittee on Internal Control Standards SAI of Poland (NIK) June 2011, Wellington.
INTOSAI Working Group on Public Debt Progress Report on Updating of ISSAI 5410, 5430, and 5440 Dawn Simpson, U.S. Government Accountability Office INTOSAI.
Progress Report on the activities of the INTOSAI Working Group on IT Audit Chair: SAI India Comptroller and Auditor General of India1.
PSC meeting - Beijing - October The INTOSAI Compliance Audit Guidelines Presentation of Exposure Drafts ISSAIs 4000, 4100 and 4200.
Performance Audit Subcommittee PSC-SC meeting – Manama standards/performance-audit-subcommittee.html.
Harmonization Project FAS Meeting Harmonization project and ISSAI 200 Purpose and scope of the project The purpose is to provide a conceptual basis.
Working Group on Public Debt Progress Report 7th Meeting of the Steering Committee of the INTOSAI Committee on the Knowledge Sharing and Knowledge Services.
PSC INTOSAI Professional Standards Committee The auditing function of Supreme Audit Institutions A systematic mapping of the auditing assignments of selected.
INTOSAI Financial Audit Guidelines (ISSAI )
Brasilia June Compliance Audit Subcommittee (CAS) Presentation to the PSC Steering Committee.
Due Process – ISSAIs and INTOSAI GOVs Roberto José Domínguez Moro Superior Audit Office of Mexico INTOSAI Working Group on Public Debt October, 2009.
Due Process – ISSAIs and INTOSAI GOVs Roberto José Domínguez Moro Superior Audit Office of Mexico INTOSAI Working Group on Public Debt June 14, 2010.
Updating ISSAI Project Proposal SAI India Comptroller and Auditor General of India1.
SAI-India.  The Working Group on IT Audit (WGITA) was created at the XIII INCOSAI in Berlin in  WGITA is chaired by SAI-India and represented.
Introducing the ISSAIs and INTOSAI GOVs 1 PSC The Professional Standards Committee.
Agenda Item No. 12 Progress Report on the activities of the INTOSAI Working Group on IT Audit Chair: SAI India Comptroller and Auditor General of India1.
Agenda Item No. 25 INTOSAI Strategic Plan ( ) Strategic objectives and goals of KSC (Goal 3) SAI-India Comptroller and Auditor General of India1.
What are ISSAIs? 1. ISSAIs I -International S - Standards – (of) S -Supreme A -Audit I -Institutions 2.
Revised ISSAI 30 Endorsement Version Steering Committee of the Professional Standards Committee Copenhagen, 27 May 2016 Jacek Jezierski, Supreme Audit.
Presentation to the PSC Steering Committee, May 2016, Copenhagen The proposed INTOSAI Framework of Professional Pronouncements (IFPP) Forum for the INTOSAI.
25th Meeting of the INTOSAI Working Group on IT Audit Brasilia, Brazil, April 25 – 26, 2016 Madhav Panwar - US, GAO Report on WGITA IDI Handbook on IT.
ISSAI 100 Presentation to CAS Vilnius September 2012
process and procedures for assessments
Comptroller and Auditor General of India
Strategic Development Plan (for INTOSAI professional pronouncements)
7th KSC Steering Committee Meeting
Vilnius CAS meeting sept , 2012
Sources for formulation of Work Plan
CAS Annual Meeting New Delhi 20th February 2017.
Developments in Standards of GRAP 12 July 2016
INTOSAI Financial Audit Guidelines Subcommittee
Revision of ISSAI 30 INTOSAI Code of Ethics
Alignment of WGEA’s documents into IFPP
WGITA Work Plan NOTE: To change the image on this slide, select the picture and delete it. Then click the Pictures icon in the placeholder to.
CBC Steering Committee Meeting
Comptroller and Auditor General of India
Structure–Feedback on Structure ED-2 and Task Force Proposals
Progress Report on proposed GUID on Information System Security Audit
of the Russian Federation
of the Russian Federation
Performance Audit Subcommittee Project for ISSAI Level 4 review 66th INTOSAI Governing Board Meeting Vienna, November 5-7, 2014.
Documentation Requirements of an IT Audit including Audit Management System (Area: Audit Process) A presentation by SAIs AFROSAI-E, Bangladesh, China,
9th Meeting of KSC Steering Committee
Harmonisation Activity Progress report
Quality Assurance of non-IFPP documents
Comptroller and Auditor General of India
Presentation by SAI Pakistan
17 April 2018 Progress report ccc General capacity requirements for SAIs for conducting IT audits.
May 2010 Intosai PSC Steering Committee
Reporting Dashboard of WGITA
INTOSAI Strategic Plan & Role of KSC
What is IT audit? An examination of how IT systems where implemented to ensure that they meet the organization’s business needs without compromising.
Changes in INTOSAI Standard Setting Process.
Working Group on IT Audit
INTOSAI WORKING GROUP ON KEY NATIONAL INDICATORS
Progress Report GUID on Information System Security Audit
The Next Strategic Development Plan for IFPP
Presentation by SAI Pakistan
Progress Report GUID on Information Systems Audit
Office of the Auditor General of Norway
Implementation of the SDP
3. Status of SDP implementation
Presentation transcript:

Progress Report on proposed GUID on Information TECHNOLOGY Audit A presentation by SAI India for 27th INTOSAI WGITA

Introduction - background New project taken due to FIPP directions Revise ISSAI 5300 as GUID on Information Technology Audit as part of SDP 2.8 - Consolidating and aligning guidance on IT Audit Project now titled - Guidelines on Information Technology Audit in support of Financial, Performance and Compliance Audits Project Progress Report on Revising GUID on IT Audit – Presentation by SAI India

Introduction - background Recommended numbering in 5100 - 5109 series (reserved for guidance on IT Audit) Approved Project Duration: 10.10.2017 to 30.09.2019 (24 months) in line with FIPP deadline Members of Project Team Lead: India Members: Australia, Poland, Russia, USA Project Progress Report on Revising GUID on IT Audit – Presentation by SAI India

Revising GUID on IT Audit Project Objectives Draw upon existing Standards (ISACA), guidelines and frameworks (COBIT) and similar material related to IT audit Align with ISSAI 100 and ISSAIs viz. ISSAI 200, 300 and 400 Consult material contained in GUID 5450 and other guidance To be overarching, general principles GUID on IT Audit and provide basis for GUIDs on IT related specific subject matter Require alignment with ongoing WGITA Project for revising ISSAI 5310 on IT Security Audit Revising GUID on IT Audit

Rationale for revision ISSAI 5300, with detailed sections on macro- and micro-level planning of IT Audits, gave an impression that IT Audit was distinct type of audit ‘Requirements’ portion made it appear like a Standard While content of ISSAI 5300 would be preserved, update needed to define, elaborate, and harmonize how Information Technology (IT) Audits relate to and support Financial, Performance, and Compliance Audits Revising GUID on IT Audit

Proposed Timelines and Progress Achieved Stages Due process milestones Project Proposal Start Date End Date Expected time in total Comments   10.10.2017 30.11.2017 50 Days Project proposal and detailed outline approved Exposure draft 01.03.2018 31.07.2018 5 months  In progress Exposure period 01.11.2018 31.01.2019 90 Days  Yet to commence Endorsement Version 01.02.2019 30.04.2019 3 months Final pronouncement 01.08.2019 30.09.2019 60 days Revising GUID on IT Audit

FIPP requirements on Project Proposal Revised GUID will need to ensure alignment with ISSAIs 100, 200, 300 and 400 Need for more clarity on project scope with reference to IT audit being treated as specific subject matter and for proposing inclusion of high level principles of IT audit GUID should make high level references to subjects like Information Security Audit and Cyber Security STATUS: Detailed outline focusses on FIPP requirements Revising GUID on IT Audit

Revising GUID on IT Audit Current Status Following FIPP’s approval of detailed outline: Finalising Exposure Draft of GUID is in progress Detailed comments on proposed sections of GUID have been requested from all Team Members by April 30, 2018 Revising GUID on IT Audit

Revising GUID on IT Audit Proposal before WGITA WGITA members are requested to take note of Progress Report Project Schedule Detailed Outline of GUID (circulated) Suggested that the guidance may be renamed as Guidance on Auditing Information Systems Revising GUID on IT Audit

Revising GUID on IT Audit Thanks… Revising GUID on IT Audit