Computer Assisted Audit Techniques

Slides:



Advertisements
Similar presentations
Copyright © 2013 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin.
Advertisements

ASYCUDA Overview … a summary of the objectives of ASYCUDA implementation projects and features of the software for the Customs computer system.
Making the System Operational
Software Quality Assurance Plan
Audit of Autonomous District Councils (in an IT environment using FAAM)
Presented to the Tallahassee ISACA Chapter
ACCOUNTING INFORMATION SYSTEMS
ITAuditing Using GAS & CAATs
Auditing Concepts.
Auditing Computer-Based Information Systems
Learning Objectives LO5 Document an accounting system to identify key controls and weaknesses in order to assess control risk. LO6 Write key control tests.
Auditing Computer-Based Information Systems
Dr Gordon Russell, Napier University Unit Data Dictionary 1 Data Dictionary Unit 5.3.
The Islamic University of Gaza
McGraw-Hill/Irwin © 2003 The McGraw-Hill Companies, Inc., All Rights Reserved. 7-1 Chapter 7 CHAPTER 7 THE EFFECT OF INFORMATION TECHNOLOGY ON THE AUDIT.
CAATTs for Data Extraction and Analysis
1 Output Controls Ensure that system output is not lost, misdirected, or corrupted and that privacy is not violated. Exposures of this sort can cause serious.
Pertemuan 7-8 Matakuliah: A0214/Audit Sistem Informasi Tahun: 2007.
5-1 McGraw-Hill/Irwin ©2002 by The McGraw-Hill Companies, Inc. All rights reserved. Chapter 5 Audit Planning.
Concurrent Auditing Techniques
AUDITING INFORMATION TECHNOLOGY USING COMPUTER ASSISTED AUDIT TOOLS AND TECHNIQUES.
Advanced Accounting Information Systems
Pertemuan Matakuliah: A0214/Audit Sistem Informasi Tahun: 2007.
Auditing Auditing & Automated Systems Chapter 22 Auditing & Automated Systems Chapter 22.
Software Quality Assurance For Software Engineering && Architecture and Design.
Chapter 1 Introduction to Databases
Design, Implementation and Maintenance
Chapter 13 Auditing Information Technology
1 Performance Auditing  In IT Environment  Evidence Gathering & Analysis Techniques  Computer Assisted Techniques  Use of IDEA.
SOFTWARE QUALITY ASSURANCE Asst. Prof. Dr. Selim BAYRAKLI Maltepe University Faculty of Engineering SE 410.
Chapter 9.4 & 11.4 Paper F8 Audit and Assurance (International) ations/student_accountant/archive/sa_aug09_byrn.
Auditing & Assurance Services, 6e
Chapter 12/2 Audit Software Techniques
Auditing Systems Development, Acquisition and Maintenance
Auditing Computerized Information Systems
Chapter 17: Computer Audits ACCT620 Internal Accounting Otto Chang Professor of Accounting.
Computers & Employment By Andrew Attard and Stephen Calleja.
The Islamic University of Gaza
(SIA) 14 Internal Audit in an Information Technology Environment Standard should be read in the conjunction with the “Preface to the Standards on Internal.
Auditing Complex EDP Systems
S7: Audit Planning. Session Objectives To explain the need for planning To explain the need for planning To outline the essential elements of planning.
Auditing Information Systems (AIS)
Audit Planning. Session Objectives To explain the need for planning To outline the essential elements of planning process To finalise the audit approach.
Understanding the IT environment of the entity. Session objectives Defining contours of financial accounting in an IT environment and its characteristics.
S4: Understanding the IT environment of the entity.
Database Analysis and the DreamHome Case Study
CE Operating Systems Lecture 3 Overview of OS functions and structure.
1 Internal Audit. 2 Definition Is an independent activity established by management to examine and evaluate the organization’s risk management processes.
AUDIT IN COMPUTERIZED ENVIRONMENT
1 Welcome : To the third learning sequence “ DB ACTORS “ Present learning: We shall explore the following topics: - DB limitations. - DB actors. - DB Administrator.
Module 4: Systems Development Chapter 14: Design And Implementation.
 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 1 Chapter 13 Auditing Information Technology.
Auditing Data Management Systems Chapter 3 with added info.
IS 630 : Accounting Information Systems Auditing Computer-based Information Systems Lecture 10.
Hall, Accounting Information Systems, 8e ©2013 Cengage Learning. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly.
Chapter 8-1 Chapter 8 Accounting Information Systems Information Technology Auditing Dr. Hisham madi.
Chapter 3-Auditing Computer-based Information Systems.
ICAJ/PAB - Improving Compliance with International Standards on Auditing Planning an audit of financial statements 19 July 2014.
Welcome. Contents: 1.Organization’s Policies & Procedure 2.Internal Controls 3.Manager’s Financial Role 4.Procurement Process 5.Monthly Financial Report.
McGraw-Hill/Irwin © The McGraw-Hill Companies 2010 Internal Control in a Financial Statement Audit Chapter Six.
Auditing Concepts.
Internal Audit & Accounting Systems Review
Internal Control Principles
Auditing Information Technology
Deck 12 Accounting Information Systems Romney and Steinbart
Auditing & Investigations I
Types of CAATs Session 3.
CHAPTER 15 AUDITING EDP SYSTEMS.
Audit Execution Session 5.
Internal Control Internal control is the process designed and affected by owners, management, and other personnel. It is implemented to address business.
Presentation transcript:

Computer Assisted Audit Techniques CAATs

Computer Assisted Audit Techniques CAATs WinIDEA solely 1). 2). Some or most of us have been using this technique one way or the other It could be very simple 3).

Computer Assisted Audit Techniques CAATs is Computer Assisted Audit Techniques meaning We use computer to perform part of our auditing functions

Computer Assisted Audit Techniques Prime objective should be to assist in performing audit in the most effective and efficient manner They are tools to be used by the examiners, NOT a means to an end Need to first identify the objectives of audit then look at best method of achieving it

Computer Assisted Audit Techniques Considerations Importance of the system to the organisation Whether the review is a one-off or a continuing one Time and cost to set up the technique Time and cost to maintain the technique Level of audit assurance required Expected life of the system

Computer Assisted Audit Techniques Types of CAATs Interogation Software Embedded Audit Module Parallel simulation Test Data Integrated Test Facility Specialised audit software Commercial Software Using the auditee’s system & resources

Computer Assisted Audit Techniques Interogation Software Definition An audit interrogation program extracts data for subsequent audit review Examples: Easytrieve ACL IDEA Impromptu/PowerPlay

Computer Assisted Audit Techniques Generalised audit software comes in a variety of forms. It may either be a software package available commercially or one developed by an auditing firm. In most cases the purpose of the software package is to interrogate client’s computer files and extract information therefrom.

Computer Assisted Audit Techniques This type of software may be used to gather evidence in relation to both the effectiveness of operations of a programmed controll procedure and the extent of misstatements in accounts and underlying classes of transactions. In other words, this software may be used as either a test of control or as a substantive procedure.

Computer Assisted Audit Techniques Stages of Interogation File Define the file to be interrogated Field Determine the fields of interest Selection How data is to be collected Criteria Calc. Optional Output Most important aspect must get output right to meet objectives

Computer Assisted Audit Techniques Interogation Software (cont.) Advantages Independence form the IT department More effective use of audit time More Effective auditing Training Cost to set up and process Flexibility through the use of parameters

Computer Assisted Audit Techniques Interogation Software (cont.) Disadvantages Cost to purchase package Inexperience Does not review system controls

Computer Assisted Audit Techniques Embedded Audit Module Definition An audit program which is embedded in the application system to extract live data for subsequent audit review * Automating part of the the audit function

Computer Assisted Audit Techniques Embedded Audit Module (cont.) It is a CAAT in which code prepared by the auditor is embedded in the client’s software. The code may be designed, for example, to replicate specific aspect of control procedure, or to record details of certain transactions in a file accessible only to the auditor. Thus, it may be used as both a test of control* or as a substantive procedure

Computer Assisted Audit Techniques Advantages Concurrent auditing Continuous monitoring of transaction Reduces need for separate audit runs Particularly useful for very large files Extracts unusual transactions for subsequent audit checking

Computer Assisted Audit Techniques Disadvantages Must be included at system specification time Loss of independence as usually programmed by IT staff High set up and maintenance costs Program maintenance difficult, needs regular review Processing overheads may be high To be effective must assign audit staff to follow up Knowledge of testinging criteria may lead to circumvention

Computer Assisted Audit Techniques Parallel simulation Definition Live data is processed through the application system and checked to pre-determined results. lnvolves auditors developing either part or all the system and then processing data through to compare with output from original system.

Computer Assisted Audit Techniques Parallel simulation (cont.) Alternatively, actual client data is processed using a copy of the client’s software that has undergone program code analysis by the auditor and is under the control of the auditor. It provides evidence as to the effectiveness of design of program control procedures.

Computer Assisted Audit Techniques Advantages Simple and positive verification of specific programs and program controls Simple verification fo the integrity of data Uses live data files but does not corrupt them Repeatable test Can check all or part of a system

Computer Assisted Audit Techniques Disadvantages May require considerable programming knowledge Need detailed knowledge of application system Expensive to maintain Need good application documentation Are error caused by faults in live or parallel system?

Computer Assisted Audit Techniques Test Data Definition Test data is processed through the application system and checked to pre-determined results. INTEGRATED TEST FACILITY is an enhanced form of this May use TEST DATA GENERATOR Pansophic’s PANAUDIT.

Computer Assisted Audit Techniques Test data is a CAAT in which test data prepared by the auditor is processed on the current production version of the client’s software, but separately form the client’s normal input data. The test data that is processed updates the auditor’s copies of the client’s data files. It is typically used to gather evidences as to the effectiveness of design of programmed control procedures.

Computer Assisted Audit Techniques Advantages Does not interfere with live processing Enables the auditor to carry out more exhaustive testing

Computer Assisted Audit Techniques Disadvantages Computer staff assistance required Additional computer resources required No assurance that the test data followed normal processing procedures

Computer Assisted Audit Techniques Integrated Test Facility ITF is a facility forming part of the client’s software that enables the auditor’s test data to be integrated with the client’s live input data and then processed using the client’s current production version of the software. The facility ensures that the test data updates special dummy files, rather than actual operating files. This procedure provides evidence of the effectiveness of design of programmed control procedures.

Computer Assisted Audit Techniques Specialised audit software It is software designed to perform specific tasks in specific circumstances, such as comparison of source and object code, the analysis of unexecuted code and the generation of test data. It is used to gather evidence as to the design effectiveness of client’s software.

Standard software to audit operating software or applications Webtrend Security module

Computer Assisted Audit Techniques Commercial Software Such as Microsoft Excel, .., may be used by the auditor for analysing data imported from client files, writing audit program, etc. e.g. Stress Test is perform on Excel Breakeven Test (RWCR & NPL)

Computer Assisted Audit Techniques Using the auditee’s system & resources Its application system Its query tools Its programmer

Computer Assisted Audit Techniques Using the auditee’s application system Need to ask for a user-id with “read only” capability Need to understand the product Need to understand the system (command) Need system documentation Start with login & exit the application

Computer Assisted Audit Techniques Using the auditee’s query tools (very much like WinIdea) Need to ask for a user-id with “read only” capability & full assess to query tool Need to understand the query tool e.g Query/400, SQL, Crystal report,... Need system documentation Start with login & exit the application Begin extraction with the simplest query

Computer Assisted Audit Techniques Using their programmer (smart partnership) Need co-operation Must understand system flows & file structure Must know what you want & clearly communicated to the programmer Should review source code (program) Could submit/run the subsequent requests by yourself.