Download presentation
Presentation is loading. Please wait.
Published byWhitney Ross Modified over 9 years ago
1
19-April-02 The effects of auditor type and information system risk on the implementation of continuous monitoring of financial information systems. Richard Dull - Clemson University Eric Johnson - Indiana University
2
19-April-02 Today’s Presentation -- Report on the status of our project Seek advice for improvement
3
19-April-02 Continuous Monitoring/Auditing Are we operating at an acceptable level of implementation?
4
19-April-02 Why Not? “Everyone” agrees CM would assist in providing more timely information to decision-makers. It is widely accepted in non-financial settings.
5
19-April-02 Background Continuous monitoring – one of the “top five” emerging technologies The role of auditor in IS design, implementation and monitoring is key in CM deployment (Kogan et. al.) Auditor acceptance of technology may influence risk assessment for new technology (Hunton et. al.)
6
19-April-02 Research Questions Obstacles to CM/CA implementation Effects of Risk Effects of Auditor “type” –Internal –External
7
19-April-02 Addressing the Research Questions Field experiment Currently in process –Limited preliminary results –Adjusting for next round
8
19-April-02 Research Design Basic 2X2 Design –Auditor Type Internal External –IS Risk Level Low High
9
19-April-02 Research Design - Auditor Practicing IS Experienced
10
19-April-02 Research Design - Auditor Internal –Improve organizations operations (IIA) –Organization’s interest –Support CM External –Compliance of financial information system –CM is “untested” –Lower Support
11
19-April-02 Research Design – Auditor Other factors... Who developed CM modules Residence/control of modules Trust
12
19-April-02 Research Design -- Risk Manipulated by controls over passwords –Security manager –Network manager
13
19-April-02 Research Design – Risk (problems?) Manipulation too subtle? CM “untested” – does this overshadow the risk manipulation
14
19-April-02 Case Provided background on company High risk and low risk versions Solicited opinions on company
15
19-April-02 Case – Questions Security of system Access by company's IS staff Inherent risk Control risk Fraud risk Effectiveness of CA software Auditor’s qualifications to assess controls Overall knowledge of CA
16
19-April-02 Case – Questions CA General opinions regarding CA Costs/Benefits Effectiveness Staffing Timing Auditor involvement in development Relative risk
17
19-April-02 Demographics Experience IS/non-IS Company type Level Certifications
18
19-April-02 Results
19
Future Shorten survey/case Web vs. paper?
20
19-April-02 Questions/Comments? Contact: Richard Dull rdull@clemson.edu
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.