 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 1 Chapter 13 Auditing Information Technology.

Slides:



Advertisements
Similar presentations
Audit of Autonomous District Councils (in an IT environment using FAAM)
Advertisements

ACCOUNTING INFORMATION SYSTEMS
ITAuditing Using GAS & CAATs
Auditing Concepts.
Auditing Computer-Based Information Systems
Auditing Computer Systems
Auditing Computer-Based Information Systems
The Islamic University of Gaza
©2008 Prentice Hall Business Publishing, Auditing 12/e, Arens/Beasley/Elder The Demand for Audit and Other Assurance Services Chapter 1.
Internal Control Concepts Knowledge. Best Practices for IT Governance IT Governance Structure of Relationship Audit Role in IT Governance.
MSIS 110: Introduction to Computers; Instructor: S. Mathiyalakan1 Systems Design, Implementation, Maintenance, and Review Chapter 13.
Fundamentals of Information Systems, Second Edition 1 Information and Decision Support Systems Chapter 6.
Computer Assisted Audit Techniques
©2003 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, Romney/Steinbart 18-1 Accounting Information Systems 9 th Edition Marshall.
Concurrent Auditing Techniques
Computers: Tools for an Information Age
General Ledger and Reporting System
Chapter Lead Black Slide © 2001 Business & Information Systems 2/e.
Chapter 13 Auditing Information Technology
 2001 Prentice Hall Business Publishing, Accounting Information Systems, 8/E, Bodnar/Hopwood Auditing Information Technology Chapter 16 l What.
Chapter 17 Acquiring and Implementing Accounting Information Systems
Chapter 12/2 Audit Software Techniques
Chapter 12 The Impact of Information Technology on the Audit Process
Chapter 13 Prepared by Richard J. Campbell Copyright 2011, Wiley and Sons Auditing Human Resources Processes: Personnel and Payroll in Service Industries.
Copyright © 2013 by The McGraw-Hill Companies, Inc. All rights reserved.McGraw-Hill/Irwin.
Auditing Computerized Information Systems
Copyright © 2003 by Prentice Hall Computers: Tools for an Information Age Chapter 14 Systems Analysis and Design: The Big Picture.
Chapter 22 Systems Design, Implementation, and Operation Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 22-1.
Systems Analysis and Design: The Big Picture
 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 11 – 1 Chapter 11 Systems Implementation, Operation,
The Islamic University of Gaza
Update from Business Week Number of Net Fraud Complaints – 2002 – 48,252 – 2004 – 207,449.
Managing the development and purchase of information systems (Part 1)
Chapter 7 Preparation for the Audit ACCT620 Internal Auditing Otto Chang Professor of Accounting.
Auditing Internal Control over Financial Reporting
(SIA) 14 Internal Audit in an Information Technology Environment Standard should be read in the conjunction with the “Preface to the Standards on Internal.
 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 4 – 1 Transaction Processing and the Internal Control.
Chapter 7 Auditing Internal Control over Financial Reporting McGraw-Hill/Irwin ©2008 The McGraw-Hill Companies, All Rights Reserved.
5 - 5 ©2012 Prentice Hall Business Publishing, Auditing 14/e, Arens/Elder/Beasley Audit Evidence Chapter 7.
Principles of Information Systems, Sixth Edition Systems Design, Implementation, Maintenance, and Review Chapter 13.
Chapter 10 Information Systems Analysis and Design
Understanding the IT environment of the entity. Session objectives Defining contours of financial accounting in an IT environment and its characteristics.
S4: Understanding the IT environment of the entity.
 2001 Prentice Hall Business Publishing, Accounting Information Systems, 8/E, Bodnar/Hopwood Chapter 10 Electronic Data Processing Systems.
 2001 Prentice Hall Business Publishing, Accounting Information Systems, 8/E, Bodnar/Hopwood Systems Implementation, Operation, and Control Chapter.
[Hayes, Dassen, Schilder and Wallage, Principles of Auditing An Introduction to ISAs, edition 2.1] © Pearson Education Limited 2007 Slide 7.1 Internal.
AUDIT IN COMPUTERIZED ENVIRONMENT
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin 7-1 Chapter Seven Auditing Internal Control over Financial Reporting.
Principles of Information Systems, Sixth Edition 1 Systems Design, Implementation, Maintenance, and Review Chapter 13.
IS 630 : Accounting Information Systems Auditing Computer-based Information Systems Lecture 10.
©2010 Prentice Hall Business Publishing, Auditing 13/e, Arens/Elder/Beasley The Demand for Audit and Other Assurance Services Chapter 1.
Copyright © 2007 Pearson Education Canada 1 Chapter 11: Overall Audit Plan and Audit Program.
Hall, Accounting Information Systems, 8e ©2013 Cengage Learning. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly.
Chapter 8-1 Chapter 8 Accounting Information Systems Information Technology Auditing Dr. Hisham madi.
Chapter 3-Auditing Computer-based Information Systems.
McGraw-Hill/Irwin © The McGraw-Hill Companies 2010 Internal Control in a Financial Statement Audit Chapter Six.
Copyright © 2014 Pearson Education, Inc. Publishing as Prentice Hall. Chapter
Accounting Information Systems: An Overview
Introduction for the Implementation of Software Configuration Management I thought I knew it all !
Auditing Concepts.
Fundamentals of Information Systems, Sixth Edition
Auditing Information Technology
SYSTEMS ANALYSIS Chapter-2.
5 - 5 ©2012 Prentice Hall Business Publishing, Auditing 14/e, Arens/Elder/Beasley Audit Evidence Chapter 7.
Types of CAATs Session 3.
CHAPTER 15 AUDITING EDP SYSTEMS.
Audit Execution Session 5.
Internal Control Internal control is the process designed and affected by owners, management, and other personnel. It is implemented to address business.
Information Technology Auditing
Presentation transcript:

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 1 Chapter 13 Auditing Information Technology

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 2 Learning Objective 1 Distinguish between “auditing through the computer” and “auditing with the computer.”

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 3 Information Systems Auditing Concepts

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 4 Structure of a Financial Statement Audit The primary objective and responsibility of the external auditor is to attest to the fairness of a firm’s financial reports. The internal auditor serves a firm’s management. The external auditor serves outsiders.

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 5 Structure of a Financial Statement Audit Transactions Compliance testing Interim audit AccountingsystemFinancialreports Substantive testing Financial statement audit CashBank ReceivablesCustomers Confirm balances Confirm balances

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 6 Auditing Around the Computer Accounting system InputOutput In the around-the-computer approach, the processing portion is ignored. Processing

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 7 Auditing Around the Computer Totals are accumulated for accepted and rejected records. The around-the-computer approach is no longer widely used. Auditors emphasize control over rejected transactions, their correction, and then resubmission.

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 8 Auditing Through the Computer Auditing through the computer may be defined as the verification of controls in a computerized system.

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 9 Control Framework in IT Environment Internalcontrols Applicationscontrols Generalcontrols Computerapplication systems and programs Applicationsystemsdevelopment Computerservicecenter

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 10 Auditing With the Computer Auditing with the computer is the process of using information technology in auditing. The use of information technology is no longer optional.

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 11 Auditing With the Computer What are some of the potential benefits of using information systems technology in an audit? 2. Time may be saved by eliminating manual footing, cross footing, and other routine calculations. 1. Computer-generated working papers are generally more legible and consistent.

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 12 Auditing With the Computer 3. Calculations, comparisons, and other data manipulations are more accurately performed. 5. Project information may be more easily generated and analyzed. 4. Analytical review calculations may be more efficiently performed.

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 13 Auditing With the Computer 6. Standardized audit correspondence may be stored and easily modified. 7. Morale and productivity may be improved by reducing the time spent on clerical tasks.

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 14 Auditing With the Computer 8. Increased cost-effectiveness is obtained by reusing and extending existing electronic audit applications to subsequent audits. 9. Increased independence from information systems personnel is obtained.

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 15 Learning Objective 2 Describe and evaluate alternative information systems audit technologies.

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 16 Information Systems Auditing Technology Information system audit technology has evolved along with computer system development. Rather, there is a variety of tools and techniques that may be used to accomplish an audit’s objective. There is no one overall auditing technology.

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 17 Test Data Technique Test data are input containing both valid and invalid data. Payroll transactions for fictitious employees are processed concurrently with valid payroll transactions.

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 18 Test Data Approach Test data hypotheticaltransactions Computer processing using master program Error listing Auditor’sexpectedoutput Compare

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 19 Integrated-Test-Facility Technique ITF involves both the use of test data and the creation of fictitious records (vendors, employees) on the master files of a computer system. Payroll transactions for fictitious employees are processed concurrently with valid payroll transactions.

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 20 Integrated-Test-Facility Approach TransactionsITFtransactions Computerapplicationsystem Reportscontaining ITF information Reportswithout ITF data Data files ITF data

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 21 Parallel Simulation Technique Processing real data through audit programs. The simulated output and the regular output are then compared. Depreciation calculations are verified by processing the fixed-asset master file with an audit program.

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 22 Parallel Simulation TransactionsCompare Parallelsimulationprogram Report Simulationreport Computerapplicationsystem Function to be verified

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 23 Audit Software Technique Computer programs that permit the computer to be used as an auditing tool. An auditor uses a computer program to extract data records from a master file.

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 24 Generalized Audit Software (GAS) Technique GAS is audit software that has been specifically designed to allow auditors to perform audit-related data processing functions. An auditor uses GAS to search computer files for unusual items.

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 25 PC Software Technique Software that allows the auditor to use a PC to perform audit tasks. A PC spreadsheet package is used to maintain audit working papers and audit schedules.

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 26 Embedded Audit Routines Technique Special auditing routines included in regular computer programs so that transaction data can be subjected to audit analysis. Data items that are exceptions to auditor- specified edit tests included in a program are written to a special audit file.

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 27 Embedded Audit Data Collection Productiontransactions ProductioncomputerapplicationsystemEmbedded audit data collectionmodule Productionreports Auditreports

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 28 Extended Records Technique Modification of programs to collect and store data of audit interest. A payroll program is modified to collect data pertaining to overtime pay.

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 29 Snapshot Technique Modifications of programs to output data of audit interest. A payroll program is modified to output data pertaining to overtime pay.

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 30 Tracing Technique Tracing provides a detailed audit trail of the instructions executed during the program’s operation. A payroll program is traced to determine if certain edit tests are performed in the correct order.

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 31 Review of System Documentation Technique Existing system documentation as program flowcharts are reviewed for audit purposes. An auditor desk checks the processing logic of a payroll program.

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 32 Control Flowcharting Technique Analytic flowcharts or other graphic techniques are used to describe the controls in a system. An auditor prepares an analytic flowchart to review controls in the payroll application system.

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 33 Mapping Technique Special software is used to monitor the execution of a program. The execution of a program with test data as input is mapped to indicate how extensively the input tested compares with individual program statements.

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 34 Learning Objective 3 Characterize various types of information systems audits.

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 35 General Approach to an Information Systems Audit Initial review and evaluation of the area to be audited and audit plan preparation. Detailed review and evaluation of controls. Compliance testing which is followed by analysis and reporting of results.

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 36 General Approach to an Information Systems Audit The initial review phase determines the course of action the audit will take. Decisions concerning specific areas to be investigated Deployment of audit labor Audit technology to be used Development of a time and/or cost budget for the audit

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 37 General Approach to an Information Systems Audit What is an audit program? Standardized audit programs for particular audit areas have been developed and are common in all types of auditing. It is a detailed list of the audit procedures to be applied on a particular audit.

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 38 General Approach to an Information Systems Audit In the second general phase of the audit, is detailed review and evaluation. Data concerning the operation of the system are reviewed. Documentation of the application area is reviewed.

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 39 General Approach to an Information Systems Audit The third phase of the audit is testing. This phase produces evidence of compliance with procedures.

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 40 Information Systems Application Audits Application controls are divided into three general areas. InputOutput Processing

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 41 Application Systems Development Audits Systems development audits are directed at the activities of systems analysts and programmers. Controls governing the systems development process directly affect the reliability of the application programs that are developed.

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 42 Application Systems Development Audits There are three general areas of audit concern in the systems development process. Systems development standards Project management Program change control

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 43 Systems Development Standards Systems development standards are the documentation governing the design, development, and implementation of application systems.

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 44 Project Management It consists of project planning and project supervision. What is project management?

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 45 Program Change Controls It is to prevent unauthorized and potentially fraudulent changes from being introduced into previously tested and accepted programs. What is the objective of program change controls?

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 46 Computer Service Center Audits Normally, an audit of the computer service center is undertaken before any application audits to ensure the general integrity of the environment in which the application will function. What are some examples? Audits might be undertaken in several areas.

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 47 Computer Service Center Audits Environmental controls Data release, reports, and computer programs Physical security of the center Management controls

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 48 Computer Service Center Audits Audits of computer service center operations require a high degree of technical training and familiarity with systems operations.

 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 13 – 49 End of Chapter 13