Advanced Accounting Information Systems Day 18 IT Auditing Wrap-up / Control Frameworks Introduction October 5, 2009.

Slides:



Advertisements
Similar presentations
OPERATING EFFECTIVELY AT WESD. What is Internal Control? A process designed to provide reasonable assurance the organizations objectives are achieved.
Advertisements

Computer Fraud Chapter 5.
Computer Fraud Chapter 5.
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
Control and Accounting Information Systems
Control and Accounting Information Systems
Auditing Concepts.
Auditing Computer-Based Information Systems
Auditing Computer Systems
Auditing Computer-Based Information Systems
Sarbanes-Oxley Compliance Process Automation
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
Institute of Municipal Finance Officers & Related Professions
©2006 Prentice Hall Business Publishing, Auditing 11/e, Arens/Beasley/Elder The Impact of Information Technology on the Audit Process Chapter 12.
Accounting Information Systems Chapter Outlines
INTERNAL CONTROL. INTERNAL CONTROL DEFINED  INTERNAL CONTROL IS A PROCESS - EFFECTED BY AN ENTITY'S BOARD OF DIRECTORS, MANAGEMENT, AND OTHER PERSONNEL.
1 Sarbanes-Oxley IT Audits. 2 Sarbanes-Oxley 2002 Recommended “audit firms place a high priority on enhancing the overall effectiveness of auditors’ work.
©2003 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, Romney/Steinbart 18-1 Accounting Information Systems 9 th Edition Marshall.
COSO Framework A company should include IT in all five COSO components: –Control Environment –Risk Assessment –Control activities –Information and communication.
Advanced Accounting Information Systems
Internal Control. COSO’s Framework Committee of Sponsoring Organizations 1992 issued a white paper on internal control Since this time, this framework.
Internal Control. COSO’s Framework Committee of Sponsoring Organizations 1992 issued a white paper on internal control Since this time, this framework.
©2003 Prentice Hall Business Publishing, Auditing and Assurance Services 9/e, Arens/Elder/Beasley The Impact of Information Technology on the Audit.
Chapter 13 Auditing Information Technology
“The Impact of Sarbanes Oxley, An Evolving Best Practice” Ellen C. Wolf Senior Vice President & Chief Financial Officer American Water National Association.
Information Technology Audit
Auditing Computerized Information Systems
Auditing Information Systems (AIS)
Fraud & Internal Control Frank M. Klaus, CPA. Fraud Definition  Fraud is the misappropriation of assets for the benefit of an individual.  “Willful.
The Islamic University of Gaza
Update from Business Week Number of Net Fraud Complaints – 2002 – 48,252 – 2004 – 207,449.
Karen Evans, national director of the U.S. Cyber Challenge and former Office of Management and Budget administrator Auditor Responsibility?
Auditing Internal Control over Financial Reporting
Chapter 07 Internal Control McGraw-Hill/IrwinCopyright © 2014 by The McGraw-Hill Companies, Inc. All rights reserved.
Chapter Three IT Risks and Controls.
Chapter 5 Internal Control over Financial Reporting
Page 1 Internal Audit Outsourcing The Moss Adams Approach to Internal Audit Outsourcing Proposed SOX 404 Changes.
Chapter 2 Conflict of interest. SEC guiding principles not in book Independence in fact Independence in appearance Auditors are not independent if relationships.
Monitoring Internal Control Systems Johann Rieser Senior Auditor, Ministry of Finance, Vienna.
Everyone’s Been Hacked Now What?. OakRidge What happened?
Chapter 7 Auditing Internal Control over Financial Reporting McGraw-Hill/Irwin ©2008 The McGraw-Hill Companies, All Rights Reserved.
Implications of Information Technology for the Audit Process
Learning Objectives LO5 Illustrate how business risk analysis is used to assess the risk of material misstatement at the financial statement level and.
Everyone’s Been Hacked Now What?. OakRidge What happened?
Chapter 14: Information Technology Auditing
Advanced Accounting Information Systems Day 19 Control and Security Frameworks October 7, 2009.
IT Controls Global Technology Auditing Guide 1.
A Guide for Management. Overview Benefits of entity-level controls Nature of entity-level controls Types of entity-level controls, control objectives,
Assessing Financial Statement Risks and Internal Controls
Copyright © 2007 Pearson Education Canada 23-1 Chapter 23: Using Advanced Skills.
IS 630 : Accounting Information Systems Auditing Computer-based Information Systems Lecture 10.
Auditing of CBIS Chapter Ten. IIA Vs. AICPA IIA Audit Scope –Reliability and integrity –Complies with operating parameters –Review IC to safeguard assets.
This Lecture Covers Roles of –Management –IT Personnel –Users –Internal Auditors –External Auditors.
Statement of Auditing Standard No. 94 The Effect of Information Technology on the Auditor’s Consideration of Internal Control in a Financial Statement.
The Impact of Information Technology on the Audit Process
Chapter 3-Auditing Computer-based Information Systems.
Deck 5 Accounting Information Systems Romney and Steinbart Linda Batch February 2012.
Collaboration Process 1. IC Objectives and Risk Tolerances Define, document, and implement top-down internal control objectives and risk tolerances: 
Corporate Governance and Financial Reporting Research Discussion of “Fraud type and auditor litigation: An analysis of SEC accounting and auditing enforcement.
8 INTERNAL CONTROL. Definition Duty  mgt (CEO)  Board  Internal auditor  Employee  External person.
Modern Auditing: Assurance Services and the Integrity of Financial Reporting, 8th Edition William C. Boynton California Polytechnic State University at.
Auditing Concepts.
Internal control objectives
Deck 12 Accounting Information Systems Romney and Steinbart
The Impact of Information Technology on the Audit Process
The Impact of Information Technology on the Audit Process
OAUG SOX Panel Scott Tang, Project Manager
Audit Execution Session 5.
Internal Control Internal control is the process designed and affected by owners, management, and other personnel. It is implemented to address business.
Information Technology Auditing
Presentation transcript:

Advanced Accounting Information Systems Day 18 IT Auditing Wrap-up / Control Frameworks Introduction October 5, 2009

Announcements –Revised syllabus –Assignment 3 –Assignment 4

Outline for today Continuous auditing example Hot dog cart case

Validating Computer Programs Tests of programs change controls –responsibility system of computer program development and maintenance Program comparison –Control total tests Review of systems software –Operating system software –Utility programs that do basic ‘housekeeping’ chores such as sorting and copying –Program library software that controls and monitors storage of programs –Access control software that controls logical access to programs and data files Validating users and access privileges Continuous auditing –Embedded audit modules or audit hooks (SCARF) –Exception reporting –Transaction tagging –Snapshot technique –Continuous and intermittent simulation

IT Auditing Today Component of IT governance –Process of using IT resources effectively to meet organizational objectives –Two objectives Focus on use of IT strategically to fulfill the organizational mission and to compete effectively Making sure that organization’s IT resources are managed effectively and that management controls IT related risks

Fraud triangle (SAS 99) Incentive / pressure Opportunity rationalization

SOX Section 201 – services outside scope of practice of auditors Section 302 – corporate responsibility for financial reports Section 404 – management assessment of IC –Small companies must now comply – see SEC press releasesee SEC press release

Continuous Auditing In groups of two to three, answer the following questions: –List two definitions of continuous auditing in the paper and explain how they differ –Develop your own definition of continuous auditing –Approximately what year did continuous auditing start in?

Continuous Auditing In groups of two to three, answer the following questions: –Identify factors influencing whether internal auditing can be appraised as attaining continuous auditing status –How does continuous auditing differ from continuous monitoring?

Continuous Auditing – American Electric Power In groups of two to three, answer the following questions: –How does American Electric Power implement continuous auditing? –What technology does American Electronic Power internal auditing use to implement continuous auditing –What is a safety audit?

Continuous Auditing - Microsoft In groups of two to three, answer the following questions: –What factors did Microsoft expect when it developed its continuous auditing program? –What problems did it actually encounter? –Is Microsoft using continuous auditing or continuous monitoring (or both) today? Explain.. –How does Microsoft internal audit monitor is business activities for possible fraud?

Continuous Auditing – Hospital Corporation of America In groups of two to three, answer the following questions: –How does Hospital Corporation of America (HCA) determine which automated audits to implement? –Give examples of variables HCA monitors. –How does HCA reduce the threat that senior management could manipulate their financial statements?

Hot Dog Cart Case What business objectives do you expect your new employee to achieve? What operational and financial risks do you face with allowing an employee to run your hot dog cart?

Hot Dog Cart Case How can the problem of lack of segregation of duties be addressed when you are away from the business?

Hot Dog Cart Case What controls could you develop to mitigate (notice I did NOT say completely eliminate) the operational and financial risks identified above while achieving your business objectives?

Hot Dog Cart Case How can we organize the controls identified above to ensure that our business objective is achieved?

Questions for Wednesday Identify two control frameworks discussed in our textbook and determine if either framework would be useful if you were considering expanding your hot dog cart business