Nature of IT Based Systems

Slides:



Advertisements
Similar presentations
©2008 Prentice Hall Business Publishing, Auditing 12/e, Arens/Beasley/Elder The Impact of Information Technology on the Audit Process Chapter 12.
Advertisements

ITAuditing Using GAS & CAATs
Auditing Concepts.
Auditing Computer-Based Information Systems
Learning Objectives LO5 Document an accounting system to identify key controls and weaknesses in order to assess control risk. LO6 Write key control tests.
McGraw-Hill/Irwin © 2003 The McGraw-Hill Companies, Inc., All Rights Reserved. 7-1 Chapter 7 CHAPTER 7 THE EFFECT OF INFORMATION TECHNOLOGY ON THE AUDIT.
Consideration of Internal Control in an IT Environment.
©2006 Prentice Hall Business Publishing, Auditing 11/e, Arens/Beasley/Elder The Impact of Information Technology on the Audit Process Chapter 12.
MODERN AUDITING 7th Edition
Chapter 14 System Controls. A Quote “The factory of the future will have only two employees, a man and a dog. The man will be there to feed the dog. The.
4-1 McGraw-Hill/Irwin ©2002 by The McGraw-Hill Companies, Inc. All rights reserved. Chapter 4 Materiality and Risk.
Chapter 12 Auditing the Human Resource Management Process McGraw-Hill/Irwin ©2008 The McGraw-Hill Companies, All Rights Reserved.
Auditing Auditing & Automated Systems Chapter 22 Auditing & Automated Systems Chapter 22.
©2003 Prentice Hall Business Publishing, Auditing and Assurance Services 9/e, Arens/Elder/Beasley The Impact of Information Technology on the Audit.
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin 12-1 Chapter Twelve Auditing the Human Resource Management Process.
Chapter 13 Prepared by Richard J. Campbell Copyright 2011, Wiley and Sons Auditing Human Resources Processes: Personnel and Payroll in Service Industries.
CHAPTER 6 ELECTRONIC DATA PROCESSING SYSTEMS
Copyright © 2013 by The McGraw-Hill Companies, Inc. All rights reserved.McGraw-Hill/Irwin.
Copyright © 2003 by Prentice Hall Computers: Tools for an Information Age Chapter 14 Systems Analysis and Design: The Big Picture.
Computer Based Information Systems Control UAA – ACCT 316 – Fall 2003 Accounting Information Systems Dr. Fred Barbee.
Computers Are Your Future Tenth Edition Chapter 12: Databases & Information Systems Copyright © 2009 Pearson Education, Inc. Publishing as Prentice Hall1.
Overview of Transaction Processing and Enterprise Resource Planning Systems Chapter 2.
Transaction Processing System  Business Transactions are certain events that occur routinely in a business firm.  A transaction is a set of activities.
(SIA) 14 Internal Audit in an Information Technology Environment Standard should be read in the conjunction with the “Preface to the Standards on Internal.
Chapter 07 Internal Control McGraw-Hill/IrwinCopyright © 2014 by The McGraw-Hill Companies, Inc. All rights reserved.
Chapter 5 Internal Control over Financial Reporting
Considering Internal Control
Auditing Complex EDP Systems
Implications of Information Technology for the Audit Process
Internal Control in a Financial Statement Audit
1 Chapter Three IT Risks and Controls. 2 The Risk Management Process Identify IT Risks Assess IT Risks Identify IT Controls Document IT Controls Monitor.
IT Service Delivery And Support Week Eleven – Auditing Application Control IT Auditing and Cyber Security Spring 2014 Instructor: Liang Yao (MBA MS CIA.
Copyright © 2007 Pearson Education Canada 1 Chapter 13: Audit of the Sales and Collection Cycle: Tests of Controls.
Understanding the IT environment of the entity. Session objectives Defining contours of financial accounting in an IT environment and its characteristics.
S4: Understanding the IT environment of the entity.
Copyright © 2013 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin.
 2001 Prentice Hall Business Publishing, Accounting Information Systems, 8/E, Bodnar/Hopwood Chapter 10 Electronic Data Processing Systems.
Chapter 12 Inventories and Cost of Goods Sold McGraw-Hill/Irwin
McGraw-Hill/Irwin © 2003 The McGraw-Hill Companies, Inc., All Rights Reserved. 6-1 Chapter 6 CHAPTER 6 INTERNAL CONTROL IN A FINANCIAL STATEMENT AUDIT.
AUDIT IN COMPUTERIZED ENVIRONMENT
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin 6-1 Chapter Six Internal Control in a Financial Statement Audit.
 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 1 Chapter 13 Auditing Information Technology.
CHAPTER 2 TYPES OF BUSINESS INFORMATION SYSTEM. INTRODUCTION Information System support business operations by processing data related to business operation.
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin 7-1 Chapter Seven Auditing Internal Control over Financial Reporting.
APA – Fundamentals of Payroll Chapter 2 – Payroll Systems March 10, 2012.
Copyright©2001 by Houghton Mifflin Company. All rights reserved. 1 Financial Accounting Belverd E. Needles, Jr. Marian Powers Multimedia.
Copyright © 2007 Pearson Education Canada 23-1 Chapter 23: Using Advanced Skills.
8-1 Copyright © 2016 McGraw-Hill Education. All rights reserved. No reproduction or distribution without the prior written consent of McGraw-Hill Education.
Statement of Auditing Standard No. 94 The Effect of Information Technology on the Auditor’s Consideration of Internal Control in a Financial Statement.
The Impact of Information Technology on the Audit Process
Copyright © 2014 Pearson Education, Inc. Publishing as Prentice Hall. Chapter
McGraw-Hill/Irwin © The McGraw-Hill Companies 2010 Internal Control in a Financial Statement Audit Chapter Six.
Internal Control Chapter 7. McGraw-Hill/Irwin © 2008 The McGraw-Hill Companies, Inc., All Rights Reserved. 7-2 Summary of Internal Control Definition.
Auditing Concepts.
Audit of the Acquisition and Payment Cycle
Chapter 08 Consideration of
Electronic Data Processing Systems Chapter 6.
Auditing Information Technology
Chapter 4 The Revenue Cycle 1.
Controlling Computer-Based Information Systems, Part II
TRANSACTION PROCESSING
Part I: Purchases and Cash Disbursements Procedures
The Impact of Information Technology on the Audit Process
Computer-Based Processing: Developing an Audit Assessment Approach
The Impact of Information Technology on the Audit Process
Payroll and Production
Purchases and Cash Disbursements Procedures
CHAPTER 15 AUDITING EDP SYSTEMS.
CHAPTER 6 ELECTRONIC DATA PROCESSING SYSTEMS
Internal Control Internal control is the process designed and affected by owners, management, and other personnel. It is implemented to address business.
Presentation transcript:

Nature of IT Based Systems Many systems have developed away from centralized systems with one main frame computer using user developed software to a combination of smaller computers using commercially available software Less expensive software Electronic checkbooks (e.g., Quicken) Moderate system Basic general ledger system (e.g.., Quickbooks) Expensive ERP systems (e.g., SAP)

Nature of IT Systems Usually consists of: Hardware Digital computer and peripheral equipment Software Various programs and routines for operating the system

Computer Hardware Card Readers Arithmetic Unit Magnetic Disks Input/Output Devices Central Processing Unit Auxiliary Storage Card Readers Arithmetic Unit Magnetic Disks Terminals Control Unit Magnetic Drums Electronic Cash Primary Storage Magnetic Tapes Registers Optical Compact Optical Scanners Disks Magnetic Tape Drives Magnetic Disk Drives Optical Compact Disks 2 2

Software Two Types: Systems software Application software Programs that control and coordinate hardware components and provide support to application software Operating system (Examples: Unix, Windows) Application software Programs designed to perform a specific data processing task Written in programming language (Example: Java)

System Characteristics Regardless of size, system possesses one or more of the following elements Batch processing On-line capabilities Database storage IT networks End user computing 3

Batch Processing Input data gathered and processed periodically in groups Example: Accumulate all of a day’s sales transactions and process them as a batch at end of day Often more efficient than other types of systems but does not provide up-to-minute information

Online Capabilities Online systems allow users direct access to data stored in the system Two types (a company may use both) Online transaction processing (OLTP) Individual transactions entered from remote locations Online real time (Example: Bank balance at ATM) Online analytical processing (OLAP) Enables user to query a system for analysis Example: Data warehouse, decision support systems, expert systems

Database Storage In traditional-IT systems, each computer application maintains separate master files Redundant information stored in several files Database system allows users to access same integrated database file Eliminates data redundancy Creates need for data administrator for security against improper access

IT Networks Networks Computers linked together through telecommunication links that enable computers to communicate information back and forth WAN, LAN Internet, intranet, extranet Electronic commerce Involves electronic processing and transmission of data between customer and client Electronic Data Interchange (EDI)

End User Computing User departments are responsible for the development and execution of certain IT applications Involves a decentralized processing system IT department generally not involved Controls needed to prevent unauthorized access

Internal Control in IT Importance of internal control not diminished in computerized environment Separation of duties Clearly defined responsibilities Augmented by controls written into computer programs

Audit Trail Impact In a traditional manual system, hard-copy documentation available for accounting cycle In computerized environment, audit trail ordinarily still exists, but often not in printed form Can affect audit procedures Consulting auditors during design stage of IT-based system helps ultimate auditability

Responsibilities (1 of 2) Information systems management Supervise the operation of the department and report to vice president of finance Systems analysis Responsible for designing the system Application programming Design flowcharts and write programming code Database administration Responsible for planning and administering the company database Data Entry Prepare and verify input data for processing

Responsibilities (2 of 2) IT Operations Run and monitor central computers Program and file library Protect computer programs, master files and other records from loss, damage and unauthorized use Data Control Reviews and tests all input procedures, monitors processes and reviews IT logs Telecommunications Specialists Responsible for maintaining and enhancing IT networks Systems Programming Responsible for troubleshooting the operating system

Computer-Based Fraud History shows the person responsible for frauds in many situations set up the system and controlled its modifications Segregation of duties Programming separate from controlling data entry Computer operator from custody or detailed knowledge of programs If segregation not possible need: Compensating controls like batch totals Organizational controls not effective in mitigating collusion

Internal Auditing in IT Interested in evaluating the overall efficiency and effectiveness of information systems operations and related controls throughout the company Should participate in design of IT-based system Perform tests to ensure no unauthorized changes, adequate documentation, control activities functioning and data group performing duties.

IT Control Activities General Control Activities Developing new programs and systems Changing existing programs and systems Access to programs and data IT operations controls 3 4

Application Control Activities Programmed Control Activities Input validation checks Limit test Validity test Self-checking number Batch controls Item count Control total Hash total Processing controls Input controls plus file labels Manual Follow-up Activities Exception reports follow-up 5

User Control Activities Designed to test the completeness and accuracy of IT-processed transactions Designed to ensure reliability Reconciliation of control totals generated by system to totals developed at input phase Example: Sales invoices generated by IT-based system tested for clerical accuracy and pricing by the accounting clerk

Control in Decentralized and Single Workstation Systems Involves use of one or more user operated workstations to process data Needed controls Train users Document computer processing procedures Backup files stored away from originals Authorization controls Prohibit use of unauthorized programs Use antivirus software

Steps 1 and 2 of audit--Plan audit and Obtain an Understanding Step 1 – Consider IT system in planning Step 2 – Obtain an understanding of the client and its environment Documentation of client’s IT-based system depends on complexity of system Narrative Systems flowchart Program flowchart Internal control questionnaires

Step 3 of Audit: Assess the Risks of Material Misstatement Identify risks Relate the identified risks to what can go wrong at the relevant assertion level Consider whether the risks are of a magnitude that could result in a material misstatement Consider the likelihood that the risks could result in a material misstatement Evaluate effectiveness of related controls in mitigating risks Test of controls over IT-based systems

Techniques for Testing Application Controls Auditing Around the Computer--Manually processing selected transactions and comparing results to computer output Manual Tests of Computer Controls--Inspection of computer control reports and evidence of manual follow-up on exceptions Auditing Through the Computer--Computer assisted techniques Test Data Integrated Test Facility Controlled Programs Program Analysis Techniques Tagging and Tracing Transactions Generalized audit software – parallel simulation 4 6

Using Generalized Audit Software to Perform Substantive Procedures In general, using client data and generalized audit software Examine client’s records for overall quality, completeness and valid conditions Rearrange data and perform analyses Select audit samples Compare data on separate files Compare results of audit procedures with client’s records

Typical Inventory Audit Procedures Using Generalized Audit Software

Service Organizations Computer service centers provide processing services to customers who decide not to invest in their own processing of particular data Outsourcing companies run computer centers and provide a range of computer processing services to companies

Service Organizations Auditor concerned if service provided are part of the client’s information system. Part of system if service organization affect: How client’s transactions are initiated The accounting records, supporting information The accounting processes from initiation to inclusion in financial statements The financial reporting process Can obtain service auditors’ report SAS 70 report