Chapter Three IT Risks and Controls.

Slides:



Advertisements
Similar presentations
An Internal Control Overview
Advertisements

Federal Audit Executive Council (FAEC) June 2012 Bi-Monthly Meeting Heather I. Keister Doris G. Yanger June 14, 2012 Green Book Update.
Chapter 10 Accounting Information Systems and Internal Controls
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
Control and Accounting Information Systems
Control and Accounting Information Systems
Internal Control.
Chapter 10 Section 404 Audits of Internal Control and Control Risk
Security Controls – What Works
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
1 Pertemuan 6 Internal Control System Matakuliah:A0274/Pengelolaan Fungsi Audit Sistem Informasi Tahun: 2005 Versi: 1/1.
INTERNAL CONTROL. INTERNAL CONTROL DEFINED  INTERNAL CONTROL IS A PROCESS - EFFECTED BY AN ENTITY'S BOARD OF DIRECTORS, MANAGEMENT, AND OTHER PERSONNEL.
Standar Pekerjaan Lapangan: Pemahaman Memadai atas Pengendalian Intern Pertemuan 5.
Chapter 5 Risk Assessment: Internal Control Evaluation
6-1 McGraw-Hill/Irwin ©2002 by The McGraw-Hill Companies, Inc. All rights reserved. Chapter 6 Internal Control Evaluation: Assessing Control Risk.
Internal Control. COSO’s Framework Committee of Sponsoring Organizations 1992 issued a white paper on internal control Since this time, this framework.
Internal Control. COSO’s Framework Committee of Sponsoring Organizations 1992 issued a white paper on internal control Since this time, this framework.
Chapter 4 Internal Controls McGraw-Hill/Irwin
An Educational Computer Based Training Program CBTCBT.
Chapter 8 Introduction to Internal Control Systems
5-1 McGraw-Hill/Irwin ©2005 by the McGraw-Hill Companies, Inc. All rights reserved. Chapter 5 Internal Control Evaluation: Assessing Control Risk “If everything.
Fraud & Internal Control Frank M. Klaus, CPA. Fraud Definition  Fraud is the misappropriation of assets for the benefit of an individual.  “Willful.
Chapter 07 Internal Control McGraw-Hill/IrwinCopyright © 2014 by The McGraw-Hill Companies, Inc. All rights reserved.
Introduction to Internal Control Systems
Vijay V Vijayakumar.  SOX Act  Difference between IT Management and IT Governance  Internal Controls  Frameworks for Implementing SOX  COSO - Committee.
This Lecture Covers Review of Internal Control Definitions.
INTERNAL CONTROL OVER FINANCIAL REPORTING
Internal controls. Session objectives Define Internal Controls To understand components of Internal Controls, control environment and types of controls.
Chapter 5 Internal Control over Financial Reporting
Considering Internal Control
Monitoring Internal Control Systems Johann Rieser Senior Auditor, Ministry of Finance, Vienna.
Introduction In 1992, the Committee Of Sponsoring Organizations of the Treadway Commission (COSO) published Internal Control-Integrated Framework (1992.
Internal Control in a Financial Statement Audit
Chapter 7 Auditing Internal Control over Financial Reporting McGraw-Hill/Irwin ©2008 The McGraw-Hill Companies, All Rights Reserved.
9 - 1 ©2003 Prentice Hall Business Publishing, Essentials of Auditing 1/e, Arens/Elder/Beasley Internal Control and Control Risk Chapter 9.
©2003 Prentice Hall Business Publishing, Auditing and Assurance Services 9/e, Arens/Elder/Beasley Internal Control and Control Risk Chapter 10.
1 Chapter Three IT Risks and Controls. 2 The Risk Management Process Identify IT Risks Assess IT Risks Identify IT Controls Document IT Controls Monitor.
Learning Objectives LO5 Illustrate how business risk analysis is used to assess the risk of material misstatement at the financial statement level and.
Presented By Tay Un Soo Senior VP, Bank of Commerce President of ISACA - Malaysia Chapter 1999 National Accountants Conference THRIVING IN THE DIGITAL.
Risk Management. IT Controls Risk management process Risk management process IT controls IT controls IT Governance Frameworks IT Governance Frameworks.
Evaluation of Internal Control System
5-1 McGraw-Hill/Irwin ©2007 by the McGraw-Hill Companies, Inc. All rights reserved. Chapter 5 Internal Control Evaluation: Assessing Control Risk.
Richard F. Chambers, CIA, CGAP Vice President, IIA Learning Center The Institute of Internal Auditors.
Evaluation of Internal Control System. Learning Objective 1 Contrast management’s need for internal control with the auditor’s need to consider internal.
1 Chapter Nine Conducting the IT Audit Lecture Outline Audit Standards IT Audit Life Cycle Four Main Types of IT Audits Using COBIT to Perform an Audit.
Copyright © 2013 by The McGraw-Hill Companies, Inc. All rights reserved.McGraw-Hill/Irwin.
McGraw-Hill/Irwin © 2003 The McGraw-Hill Companies, Inc., All Rights Reserved. 6-1 Chapter 6 CHAPTER 6 INTERNAL CONTROL IN A FINANCIAL STATEMENT AUDIT.
Chapter 9: Introduction to Internal Control Systems
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin 7-1 Chapter Seven Auditing Internal Control over Financial Reporting.
S5: Internal controls. What is Internal Control Internal control is a process Internal control is a process Internal control is effected by people Internal.
International Security Management Standards. BS ISO/IEC 17799:2005 BS ISO/IEC 27001:2005 First edition – ISO/IEC 17799:2000 Second edition ISO/IEC 17799:2005.
Internal Control Chapter 7. McGraw-Hill/Irwin © 2006 The McGraw-Hill Companies, Inc., All Rights Reserved. 7-2 Summary of Internal Control Definition.
©2012 Prentice Hall Business Publishing, Auditing 14/e, Arens/Elder/Beasley Section 404 Audits of Internal Control and Control Risk Chapter.
Control and Security Frameworks Chapter Three Prepared by: Raval, Fichadia Raval Fichadia John Wiley & Sons, Inc
Copyright © 2007 Pearson Education Canada 9-1 Chapter 9: Internal Controls and Control Risk.
Chapter 5 Evaluating the Integrity and Effectiveness of the Client’s Control Systems.
Deck 5 Accounting Information Systems Romney and Steinbart Linda Batch February 2012.
CCC FINANCE FORUM ON INTERNAL AUDIT April 23, 2015 ICF/DIAKONIA CENTER.
©©2012 Pearson Education, Auditing 14/e, Arens/Elder/Beasley Considering Internal Control Chapter 10.
Copyright © 2014 Pearson Education, Inc. Publishing as Prentice Hall. Chapter
Lecture 5 Control and AIS Copyright © 2012 Pearson Education 7-1.
Internal Control. McGraw-Hill/Irwin © 2004 The McGraw-Hill Companies, Inc., All Rights Reserved. 7-2 Summary of Internal Control Definition A process...designed.
Chapter 6 Internal Control in a Financial Statement Audit McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
SUNY Maritime Internal Control Program. New York State Internal Control Act of 1987 Establish and maintain guidelines for a system of internal controls.
Modern Auditing: Assurance Services and the Integrity of Financial Reporting, 8th Edition William C. Boynton California Polytechnic State University at.
Internal Control Evaluation: Assessing Control Risk
Internal control objectives
A Framework for Control
COSO Internal Control s Framework
INTERNAL CONTROLS AND THE ASSESSMENT OF CONTROL RISK
Presentation transcript:

Chapter Three IT Risks and Controls

Lecture Outline Identifying IT Risks Assessing IT Risks Identifying IT Controls Documenting IT Controls Monitoring IT Risks and Controls

Types of IT Risks What is risk? Business risk Chances of negative outcomes Business risk Likelihood that an organization will not achieve its business goals and objectives Internal & external risk

Audit risk Likelihood that an organization’s external auditor makes a mistake when issuing an opinion attesting to the fairness of its financial statements or an IT auditor fails to uncover a material error of fraud.

inherent risk control risk detection risk Likelihood of material errors or fraud inherent in the business environment. control risk Likelihood that the internal control system will not prevent or detect material errors or fraud on a timely basis. detection risk Likelihood that audit procedures will not detect material errors or fraud on a timely basis.

Security risk Continuity risk Risks associated with data access and integrity. Physical or logical unauthorized access Negative outcomes Continuity risk Risks associated with an information system’s availability and backup and recovery.

Assessing IT Risk Threats and vulnerabilities Identify threats or exposures Access vulnerabilities to threats or exposures Determine acceptable risk level The expected value of risk Risk indicators and risk measurement Identify IT processes and then develop a set of risk indicators Risk indicators would point to a need for control

Identifying IT Control Once risks have been identified and accessed, specific controls need to be designed to control those risks. Most widely used internal control model COSO, Cadbury and CoCo

COSO (Committee of Sponsoring Organizations of the Treadway Commission) COSO framework Consists of a definition of internal control and identification of 5 components Internal control is broadly defined as a process, effected by an entity’s Board of Directors, management and other personnel, designed to provide reasonable assurance regarding the achievement of objectives in the following categories: effectiveness and efficiency of operations, reliability of financial reporting, and compliance with laws and regulations. Coso(Internal Control-Integrated Framework)

COSO cont.. 5 components of Internal Control (IC) Control environment Attitude of management toward internal control Risk assessment Enterprise risk framework: guidance in developing plans to identify, measure, evaluate and respond to risks. Control activities Internal control procedures and policies i.e., authorizations, approvals, passwords, and segregation of duties

COSO cont.. Information and communication Monitoring Refer to the need for organizations to make sure they obtain and communicate the information needed to carry out management strategies and objectives Monitoring Continuous monitoring of internal control system by regular audits and evaluations

International IC Standards Cadbury Stressed that internal control encompasses both financial and operational controls and the auditors should report both. CoCo (Canadian Criteria of Control Committee) Similar to COSO and Cadbury Group IC within 4 categories Purpose criteria that relate to an organization’s missions and objectives

International IC Standards cont.. Commitment criteria relate to ethics, policies, and corporate identity Capability criteria that relate to the competence of an organization Monitoring and learning criteria that concern an organization’s evolution Other country standards South Africa’s King Report France’s Vienot Report

Quality Control Standards In addition to IC, improve public conference in products and processes by adopting quality control standards ISO 9000 series – certifies that organizations comply with documented quality standards Six Sigma – an approach to process and quality improvement

Statements on Auditing Standards Issued by AICPA’s Accounting Standards Board SAS 78 Consideration of IC in a Financial Statement Audit: An Amendment to SAS No. 55 SAS 94 The Effect of IT on the Auditor’s Consideration of IC in a Financial Staetment Audit New standards related to risk assessment

ISACA’s CobiT Integrates IC with information and IT Use by managers & business owners along with auditors and information users Three dimensions: information criteria, IT processes, and IT resources Organizations must ensure their information assets satisfy the requirements of quality, fiduciary, and security

ISACA’s CobiT cont… Domains: planning and organization, acquisition and implementation, delivery and support, and monitoring Each domain consists of processes CobiT identifies a control objectives for each processes New management guidelines (new addition)

Systems Reliability Assurance American Institute of Certified Public Accountants (AICPA) + Canadian Institute of Chartered Accountants  SysTrust SysTrust Increase management, customer, supplier, and business partner confidence in the IT

Documenting It Controls Internal control narratives Text describing controls over a particular risk Flowcharts – internal control flowchart Picture are easier to understand, follow and update IC questionnaires Ask questions about IC over various applications, processes, or risks Users or administrators would complete the questionnaires with yes or no answer

Monitoring IT Risks and Controls CobiT identifies several control objectives associated with monitoring Monitoring the processes Accessing IC adequacy Obtaining independent assurance Providing independent audit Need for independent assurance and audit of IT controls