Reasons for Accountant and Auditor
CHAPTER 5: Systems
Involvement in SDLC – essentially
Development and touches financial aspects of the
development process itself, which
Program Change affects financial reporting, just
Activities like any manufacturing process that
CPAs are concerned about; and the
PARTICIPANTS IN SYSTEMS information system relating to
DEVELOPMENT accounting, and its integrity. Below
are the breakdowns of how these two
are affected.
Group Role &
Responsibilities
Reason Explanation
Systems Include systems
1. Financial Systems development
Professional analysts, engineers,
Oversight involves significant
s and programmers. They
financial
design and build the
transactions, similar
system by analyzing
to a manufacturing
problems and creating
process. Accountants
solutions.
ensure these are
properly planned,
End Users Individuals who use the authorized, and
system—such as controlled.
managers, operations
staff, accountants,
2. Expertise Accountants and
and auditors. They help
in Controls auditors have
define system
specialized knowledge
requirements.
in financial
integrity, controls,
Stakeholders People with an interest and compliance, making
in the system but not them valuable
direct users—e.g., contributors to system
internal/external design.
auditors, steering
committees.
3. Quality The SDLC produces
of AIS Accounting Information
Accountants/ Focus on controls, Output Systems (AIS).
Auditors accounting, and Accountants ensure
auditing aspects. these systems follow
Includes internal and proper accounting
IT auditors. External rules and have adequate
auditors are controls.
restricted by SOX from
direct involvement.
Reason Explanation Role Description
4. Risk Poorly developed is limited by
Mitigation systems can lead to professional ethics and
errors or fraud in independence standards.
financial records.
Accountants help
prevent such risks by 3. As Accountants ensure
ensuring robust system Auditors systems are auditable.
controls. They influence system
design to include audit
features, security, and
5. External auditors are controls. Early
Compliance restricted by SOX involvement helps ensure
(Sarbanes-Oxley Act) compliance and
from direct reliability of
involvement in their accounting information
audit clients’ system systems (AIS).
development, but
internal auditors play
a key role.
INFORMATION SYSTEMS
Accountant Roles in SDLC
ACQUISITION METHODS
Role Description Organizations acquire systems
in two main ways:
1. As Accountants use systems
Users that process financial
1. In-House Development
transactions. They help
• Custom-built systems
define system
requirements such as tailored to unique
accounting methods, organizational needs.
internal controls (e.g.,
audit trails), and • Requires a dedicated team
financial algorithms. of analysts and
programmers.
2. As Team Accountants may join • Offers full control over
Members development teams, even
design and functionality.
for systems not directly
handling financial data.
2. Commercial Systems
They provide insights on
accounting data usage and • Purchased from software
assess internal control
vendors.
risks. Their involvement
• Management must evaluate Types of Commercial Systems
and choose the best-fit
system. Type Description
• Often more cost-effective
and quicker to implement. Turnkey Fully developed
Systems and tested
Trends Driving Commercial systems ready for
Software Adoption immediate use.
1. Lower Cost: General Limited
commercial software is customization
cheaper than custom-built unless source
solutions. code is
purchased. Often
2. Industry-Specific used for general
Solutions: Vendors offer or industry-
tailored software for specific
specific business types. purposes.
3. Small Business Demand: General
Smaller firms often lack Accounting,
resources for in-house Special-Purpose,
development. and Office
Automation which
4. Organizational are discussed
Downsizing: Distributed next are
data processing makes essentially
commercial software more under this type
attractive, even for of commercial
larger firms. system.
Types of Commercial Software
Packages: Turnkey Systems: General Modular systems
Ready-to-use with minimal Accounting designed for
customization; Backbone Systems broad accounting
Systems: Core systems that needs (e.g.,
require additional modules or payroll,
customization; Vendor- inventory,
Supported Systems: Ongoing general ledger).
support and updates provided Cost-effective
by the vendor. and widely used.
Type Description Type Description
Special- Tailored for in industries
Purpose specific like healthcare
Systems industries like and legal
healthcare, services. Uses
banking, or reusable modules
government, to reduce cost.
addressing
unique rules and Advantages of Commercial
procedures. Software
Advantage Explanation
Office Tools that
Automation enhance office
Systems productivity, Quick Can be deployed
such as word Implementation immediately,
processors, avoiding long
spreadsheets, development
and database delays typical
software. of in-house
systems.
Backbone Provide a
Systems foundational Lower Cost Shared
structure with development
customizable costs across
modules (e.g., many users
ERP systems). reduce the
Highly flexible price
but expensive and significantly
time-consuming compared to
to implement. custom
systems.
Vendor- Hybrid approach
Supported where vendors High Thoroughly
Systems develop and Reliability tested before
maintain custom release;
systems for errors are
clients. Common quickly
Advantage Explanation Systems Development
Life Cycle (SDLC)
identified and Organizations can use both in-
corrected by house
vendors or development and commercial
users. software, and the SDLC
framework applies to both—
Disadvantages of Commercial especially in the early stages
Software like needs analysis and system
specification.
Disadvantage Explanation
Purpose of SDLC:
Vendor Organizations • Provides a structured,
Dependence rely on vendors best-practice approach to
for maintenance system development.
and support;
• Ensures consistency,
risk if vendor
quality, and auditability
discontinues
of systems.
service.
• Focuses on both new
Limited May not meet system
Customization unique or development and ongoing
complex needs; maintenance.
less flexible Key Points:
than custom-
• SDLC is widely accepted
built systems.
in the systems community.
Maintenance Difficult to • Models may vary in the
Challenges modify if number of phases (from 4
business needs to 14), but the substance
change; in- and consistent
house systems application are what
offer more matter most.
control over • The SDLC typically
updates. includes eight phases,
grouped into two major
stages:
• New Systems
Development (first 7
phases)
• Systems
Maintenance (8th
phase)
New Systems Development
Phases:
1. Problem Identification
2. Needs Analysis
3. Alternative Solutions
4. Solution Selection
5. System Design
6. System Implementation
7. System Testing &
Evaluation
Systems Maintenance: Systems Planning (Phase
• Begins after I)
implementation.
Purpose Align system
• Involves ongoing updates, projects with
fixes, and enhancements. the strategic
• Ensures the system goals of the
remains effective and organization.
secure over time.
Key Points:
• Systems planning ensures
that IT initiatives
support the business
plan.
• The IT strategic plan is
derived from and aligned
with the organization’s
business plan.
• Projects must systems planning and
be congruent with development.
strategic objectives to
Typical Members:
avoid misalignment and
inefficiency. • Chief Executive Officer
(CEO)
• Effective planning
promotes goal • Chief Financial Officer
congruence between (CFO)
technology and business
• Chief Information Officer
direction.
(CIO)
• Senior management from
user departments
• Internal auditor
• Senior IT/computer
services managers
• External consultants or
auditors (optional)
Key Responsibilities:
• Resolve conflicts related
to new systems
• Review and prioritize
system projects
• Allocate budgets for
development
• Monitor project progress
• Decide whether to
continue or terminate
Who Should Do Systems projects at SDLC
Planning? checkpoints
1. Systems Steering Committee
Most organizations form
a systems steering
committee (a cross-functional
team) to oversee and guide
Levels of Systems Planning • Avoids excessive detail;
focuses on guiding
Level Focus informed decisions.
Resources Planned:
Strategic Long-term,
• Employees (e.g., number
Systems organization-wide
Planning resource of systems professionals)
allocation and • Hardware (e.g.,
alignment with workstations, servers)
business goals
• Software (e.g., project
funding, maintenance)
Project Short-term,
Planning application- • Telecommunications (e.g.
specific planning , networking, EDI)
including Why Perform Strategic Systems
proposals and Planning?
schedules
1. Direction & Flexibility
Even if plans change,
Strategic Systems Planning having a roadmap is
better than none.
Definition:
2. Crisis Prevention
Strategic systems planning is Helps identify and
the long-term allocation of IT prioritize needs early,
resources (3–5 years) to align reducing reactive
with the organization’s problem-solving.
overall business strategy. It
focuses on high-level 3. Authorization Control
decisions about staffing, Ensures system
hardware, software, and development aligns with
telecommunications. business goals and avoids
misaligned investments.
Key Characteristics:
4. Cost Management
• Not part of the SDLC Proven to be a cost-
(which focuses on effective way to manage
specific applications). IT projects and
• Similar to budgeting for development.
other strategic areas
like R&D or marketing.
Project Planning Document Purpose
Purpose:
To allocate resources to management’s
specific system applications commitment.
within the framework of the
strategic plan. Project Team:
• Composed of systems
Key Activities:
professionals, end users,
• Identify user needs accountants, and internal
• Prepare and evaluate auditors.
project proposals • Team competence and
dedication are critical
• Assess feasibility and
to project success.
alignment with business
goals Auditor’s Role:
• Prioritize projects • Auditors (internal and
• Schedule development external) review the
tasks planning phase to ensure
systems are necessary,
Main Outputs: efficient, and well-
controlled.
Document Purpose
• Proper planning reduces
the risk of developing
Project Recommends a new
ineffective or fraudulent
Proposal or modified
systems.
system, showing
how it aligns
with business
and IT strategic Systems Analysis
goals. (Phase II)
Purpose:
Project Outlines time
Schedule and cost To thoroughly understand the
estimates for current system and identify
all SDLC phases; user needs to design an
reflects effective solution.
Key Activities:
1. Survey of the Current To examine the existing
System system and determine which
components should be retained,
• Examine how the
improved, or replaced in the
existing system
new system.
operates.
Key Activities:
• Identify problems,
inefficiencies, and • Conduct a detailed
limitations. review of the current
system and procedures.
2. User Needs Analysis
• Gather initial facts to
• Gather detailed
understand system
requirements from
performance and
users.
limitations.
• Understand business
• Refine questions and
problems and
collect additional
expectations.
data through multiple
Importance: iterations.
• Forms the foundation for • Assess the strengths and
all subsequent SDLC weaknesses of the current
phases. system.
• A flawed analysis leads Outcome:
to flawed system design
• A comprehensive
and implementation.
understanding of the
Deliverable: current system.
• Systems Analysis Report • A foundation for
identifying user needs
• Documents findings
and designing an improved
and recommendations.
solution.
• Serves as a basis
for designing the
new or improved
system.
Survey Step Overview
Purpose:
Disadvantages of Surveying the
current system Benefit Explanation
Issue Explanation knowing what to
retain or discard.
Current Analysts may get
Physical overwhelmed and stuck Identify Root Helps distinguish
Tar Pit analyzing outdated Causes between system-
systems. related issues and
broader
organizational
problems, avoiding
Thinking Focusing too much on unnecessary
Inside the the old system may limit redesigns.
Box creativity and lead to
incremental
improvements instead of
innovative solutions.
Fact-Gathering Overview
The survey of the current
Advantages of Surveying the system involves collecting
Current System detailed information to
understand how the system
operates and identify areas
for improvement.
Benefit Explanation
Key Fact Categories:
• Data Sources: Internal
Preserve Helps identify departments and external
Valuable functional parts of entities (e.g.,
Components the old system worth customers, vendors).
keeping or
modifying. • Users: Managers and
operational staff who
interact with the system.
Understand Enables analysts to • Data Stores: Files,
System for plan a smooth databases, and documents
Conversion transition by used.
• Processes: Manual or
Technique Purpose &
automated tasks triggered
Description
by information.
• Data Flows: Movement of operations
data between sources, to
stores, processes, and understand
users. tasks,
• Controls: Manual and roles, and
automated accounting or timing.
operational safeguards.
• Transaction Volumes: Task Analyst
Quantity and growth rate Participatio actively
of system transactions. n performs
user tasks
• Error Rates: Frequency of to gain
transaction errors, often firsthand
linked to system experience
capacity. and identify
• Resource Costs: Labor, issues.
materials, and overhead;
escapable costs are Personal Used to
considered benefits in Interviews gather user
cost-benefit analysis. insights and
system
• Bottlenecks &
requirements
Redundancies: Points of
:
delay or inefficiency
that should be avoided in
• Open-ended questions for
the new system.
broad feedback
Fact-Gathering Techniques
• Questionnaires for
specific, measurable data
Technique Purpose &
| | Document Review |
Description
Analyst examines
organizational documents
Observation Analyst (e.g., charts, reports,
passively flowcharts) to understand
watches structure, procedures,
system and performance.
These techniques help analysts
build a clear picture of the
current system, which is later
documented using tools like
flowcharts and data flow
diagrams.
Analysis Step Overview
• Purpose: To interpret
gathered facts and define
user needs and system
requirements.
• Process: Analysis occurs
alongside fact-gathering;
understanding the problem
implies knowing the
desired state.
• Outcome: A formal Systems Auditor’s Role:
Analysis Report.
• Auditors
Systems Analysis Report (internal/external)
Includes: should be involved early
to ensure the system
• Findings from the system
supports audit features
survey
and controls.
• Identified problems in
• Some audit tools must be
the current system
embedded during system
• User needs and system design and can't be added
requirements later.
• High-level objectives Conceptual Systems
(what the system must do,
not how) Design (Phase III)
• Details on data sources, Purpose:
users, processes, data To develop
flows, controls, and multiple alternative system
capacity designs that meet the
requirements identified during
systems analysis.
broad overview and refining
into detailed components.
Key Points:
Key Features:
• Prevents premature
commitment to a single • Begins with a high-level
solution. view of the system.
• Users evaluate and select • Uses Data Flow Diagrams
the most suitable (DFDs) and Structure
conceptual design. Diagrams to break down
processes into manageable
• Selected design moves to
parts.
the systems
selection phase for cost- • Focuses on inputs,
benefit analysis. outputs, processes, and
special features to
Design Approaches:
distinguish design
alternatives.
Approach Description
• Avoids premature
technical details (e.g.,
Structured Top-down
database structures,
Design method; builds
control techniques).
systems from
scratch. Example Comparison:
• Option A: Traditional
Object- Bottom-up batch purchasing system—
Oriented method; simple, cost-effective,
Design assembles but requires inventory.
(OOD) reusable
modules. Often • Option B: EDI-based
used in system—more efficient,
iterative reduces inventory, but
development. requires advanced
resources.
Goal:
Structured Design Approach To present plausible system
Purpose: alternatives for user
evaluation before detailed
To develop systems from design and implementation.
the top down, starting with a
Object-Oriented Design (OOD) • Auditability depends on
Approach system structure, which
is defined during
Purpose:
conceptual design.
To build systems
using reusable standard
components (objects), similar System Evaluation and
to assembling a car from pre-
made parts.
Selection (Phase IV)
Key Features: This phase involves choosing
the best system design from
• Promotes modularity and several alternatives to
reusability. proceed to detailed design. It
• Reduces development time, aims to reduce uncertainty and
cost, and maintenance. risk through a structured
decision-making process,
• Supports flexibility by consisting of:
allowing components to be
mixed and matched. 1. Detailed Feasibility
Study – Evaluates each
• Often used in iterative system using
development, where small the TELOS framework:
modules are built and
• Technical: Can the
refined quickly.
system be built with
Benefits: current or new
technology?
• Faster system development
• Economic: Is funding
• Lower testing and
available, and is
maintenance effort
the project
• Easier user support financially viable?
• Creation of a module • Legal: Does the
library for future use system comply with
laws and
Auditor’s Role:
regulations?
• Auditors must be involved
• Operational: Can the
early to ensure audit
organization adapt
features are integrated
its procedures and
into the system design.
train staff?
• Schedule: Can the • Personnel
system be training
implemented within
• Recurring Costs:
the required
timeframe? • Hardware &
software
2. Cost-Benefit Analysis –
maintenance
Compares the costs and
benefits of each feasible • Insurance
system to identify the
• Supplies
most cost-effective
option. • Personnel
salaries
Cost–Benefit Analysis Overview
2. Identify Benefits
Used to assess whether
the benefits of a proposed • Includes improved
system outweigh its costs, efficiency,
despite challenges in accuracy, decision-
quantifying intangible making, and
elements. It complements strategic advantages
feasibility studies and helps (not detailed in the
compare competing designs. original text but
typically
Three Key Steps:
considered).
1. Identify Costs
3. Compare Costs and
• One-Time Costs: Benefits
• Hardware • Weigh total costs
acquisition against expected
benefits to
• Site
determine financial
preparation
viability and select
• Software the most cost-
acquisition effective system.
• Systems design Identify Benefits Overview
• Programming & Benefits of a proposed system
testing can be:
• Data conversion 1. Tangible Benefits
• Revenue-Increasing: e.g., • Calculates the present
higher sales from value of benefits minus
improved customer the present value of
service. costs.
• Cost-Reducing: e.g., • A positive NPV indicates
lower inventory carrying economic feasibility.
costs.
• Among competing designs,
• Only escapable the one with the higher
costs (those eliminated NPV offers greater net
if the system is removed) benefit.
should be included to
2. Break-Even Analysis
avoid flawed analysis.
• Identifies the point
2. Intangible Benefits
where total benefits
• Hard to quantify but equal total costs.
often critical.
• Useful for understanding
• Examples: improved how long it takes for a
customer satisfaction, system to become
better decision-making, profitable.
enhanced employee morale.
Systems Selection Report
• Estimation techniques
A formal document that
include surveys,
includes:
statistical models, and
simulations. • Revised feasibility study
• Risk of political misuse— • Cost–benefit analysis
benefits may be
• Explanation of intangible
overstated or understated
benefits for each design
to influence decisions.
It guides the steering
Compare Costs and Benefits
committee in selecting the
This final step evaluates system to proceed to detailed
whether a system’s benefits design.
outweigh its costs using
Auditor’s Role
financial metrics:
Auditors ensure the economic
1. Net Present Value (NPV)
feasibility is accurately
Method
assessed by verifying:
1. Only escapable costs are • Process logic
used (flowcharts,
pseudocode)
2. Reasonable interest
rates are applied • Updated data
dictionary
3. All costs are complete
and accurate System Design Walkthrough
4. Useful life estimates are • Conducted by a quality
realistic assurance group to detect
design errors before
5. Intangible benefits are
coding.
fairly valued
• Helps prevent costly
Errors in these areas can lead
reprogramming by catching
to flawed decisions.
issues early.
Documentation Review
Detailed Design (Phase • QA team reviews all
V) design documents.
Purpose • Errors are recorded and
categorized:
Create a complete, precise
blueprint of the proposed • Accepted
system that aligns with • Accepted with minor
requirements and conceptual fixes
design.
• Rejected due to
Key Activities major flaws
• Specify all system Outcome
components: user
interfaces, database If approved, the design report
tables, processes, and guides programmers and
controls. database designers in building
the physical system in the next
• Produce a Detailed Design phase: Systems Implementation.
Report including:
• Input/output formats
• Database structures
(ER diagrams,
normalized tables)
Application 3. Control: Limits
errors and fraud to
Programming and individual modules.
Testing (Phase VI)
Test the Application Software
Programming the Application
Purpose
• Select a suitable
Ensure all program modules
programming language
function correctly before
based on system needs and
deployment.
standards:
Key Concepts
• Procedural (e.g.,
COBOL): Executes • Structured Testing
logic in a defined Methodology:
sequence.
• Use hypothetical
• Event-Driven (e.g., master and
Visual Basic): transaction files.
Executes based on
• Compare actual
user actions.
results with
• Object-Oriented expected outcomes to
(e.g., Java, C++): detect logic errors.
Uses objects and
• Offline Testing First:
classes; more
flexible but harder • Always test
to learn. systems offline bef
ore going live to
Modular Programming Approach
avoid critical
• Breaks system into small, failures.
independent modules.
• Test Data Creation:
• Benefits:
• Time-consuming but
1. Efficiency: Parallel valuable for future
development speeds audits and system
up coding. updates.
2. Maintainability: • Retain test data and
Easier to update and results for audit
debug. reference and contr
ol validation.
System Implementation included in operator
documentation to maintain
(Phase VII) segregation of duties
Purpose between programmers and
operators.
Deploy the system by building
databases, installing User Documentation
equipment, training users, and • Tailored to user skill
documenting the system. levels:
Key Activities • Novices: Need
• System-wide Testing: detailed training
Combine and test all and documentation.
modules using • Occasional Users:
hypothetical data; Require refresher
results must match guidance.
expected outputs.
• Frequent Light
• User Acceptance: Formal Users: Need help
sign-off confirms the with unfamiliar
system meets tasks.
requirements.
• Frequent Power
System Documentation Users: Prefer
Supports future maintenance concise, advanced
and auditing: references.
• For • User Handbook includes:
Designers/Programmers: • System overview
Flowcharts, ER diagrams,
pseudocode, and program • Step-by-step
listings. instructions
• For Operators: Run • Input/output
manuals detailing examples
schedules, hardware, file • Error messages
requirements, error
handling, and contacts. • Command reference
Security & Control • Glossary and support
info
• System flowcharts, logic
diagrams, and code • Online Documentation:
listings should not be
• Tutorials for Auditor’s Role
training
• Internal auditors support
• Help features (basic design and implementation
or context- by:
sensitive)
• Ensuring compliance
Database Conversion with financial
regulations (GAAP,
• Transfers data to new
GAAS, SEC, IRS).
formats or systems.
• Specifying
• Precautions:
documentation
1. Validation: Ensure standards.
old data is accurate
• Verifying control
and relevant.
adequacy and SOX
2. Reconciliation: compliance.
Compare old and new
Post-Implementation Review
data for
consistency. Conducted months after launch
to assess system success and
3. Backup: Retain
guide future improvements.
original files to
recover from Key Focus Areas:
discrepancies.
• System Design Adequacy:
System Cutover Approaches Output quality,
usability, data
1. Cold Turkey (Big Bang):
integrity, and
Immediate switch; high
documentation.
risk, low cost.
• Accuracy of Estimates:
2. Phased: Gradual module-
Compare actual vs.
by-module rollout;
budgeted time, cost, and
reduces risk but may
benefits.
cause compatibility
issues. • User Satisfaction:
Evaluate if expected
3. Parallel: Run old and new
benefits are realized.
systems simultaneously;
safest but most resource-
intensive.
Systems Maintenance Controlling and
(Phase VIII) Auditing SDLC
Systems Maintenance—Final Audit Relevance of the SDLC
Phase
• The accuracy of financial
• Involves updating data depends on the
application programs to integrity of the systems
meet evolving user needs. that process it.
• Changes range from minor • A flawed application can
(e.g., report formatting) lead to misstated
to major (e.g., logic or financial statements.
interface redesign).
Audit Strategy
• Maintenance can last 5+
• If SDLC
years, depending on
processes (development
business environment.
and maintenance) are
• In competitive well-controlled:
industries, system
• Auditors can reduce
lifespans are shorter.
application and
Cost Impact substantive testing.
• Maintenance is resource- • If SDLC controls are
intensive. weak:
• Can account for 80–90% of • Auditors must expand
total system costs over testing scope to
its lifetime. ensure data
reliability.
Key Audit Objectives
• Ensure systems are:
• Properly specified
• Secure and
controlled
• Thoroughly tested
• Maintained with
integrity
Controllable Activities in Audit Procedures
Systems Development
• Review completed projects
1. Systems Authorization: for:
Formal approval ensures
• Proper authorization
economic justification.
and feasibility
2. User Specification: Users analysis
define system needs;
• Accurate user needs
documentation must
and design
reflect their
documentation
perspective.
• Valid cost–benefit
3. Technical Design:
analysis
Converts user needs into
detailed specifications; • Thorough testing and
quality documentation is issue resolution
key.
• Compliance with
4. Internal Audit documentation
Participation: Auditors standards
guide design, ensure
Controlling Systems
compliance, and support
Maintenance
users.
Importance of Maintenance
5. User Testing &
Controls
Acceptance: Final
validation by users; • Maintenance is
formal acceptance is a the longest and costliest
critical control. phase of the SDLC.
Audit Objectives • Uncontrolled changes can
lead to errors, system
• Confirm consistent
failures, or fraud.
application of SDLC
policies. • Auditors must
ensure application
• Ensure systems are free
integrity remains intact
from material errors and
over time.
justified at each phase.
Key Maintenance Controls
• Verify completeness and
accuracy of 1. Formal Authorization: All
documentation. changes must be approved.
2. Technical Specifications: Essential Control Features
Changes must be clearly
• Password Control: Limits
defined.
access to programs; risk
3. Retesting: Modified increases with shared
systems must be passwords.
thoroughly tested.
• Separate Test Libraries:
4. Documentation Updates: Programmers work in
All changes must be isolated, password-
recorded. protected directories.
Source Program Library (SPL) • Naming Conventions:
Controls Distinguish test vs.
production programs to
• SPL stores source code;
prevent accidental
changes here affect
deployment.
system integrity.
• Audit Trails & Reports:
• Without controls:
Track all program
• Unauthorized changes; verify against
access is possible. authorized requests.
• Program integrity • Version Numbers:
cannot be verified. Automatically incremented
to detect unauthorized
• Proper SPL controls are
modifications.
essential to
balance security and • Restricted Maintenance
operational flexibility. Commands: Password-
protected; access limited
A Controlled Source Program
to authorized personnel.
Library (SPL) Environment:
These controls help
SPL Management System (SPLMS)
preserve program integrity,
Controls key functions: support auditing, and
balance security with
1. Store programs
operational flexibility.
2. Retrieve for maintenance
3. Delete obsolete code
4. Document changes for
audit trails
Audit Objectives and • Review test results for
each change.
Procedures Related to
• Retest programs to
System Maintenance:
confirm integrity.
Audit Objectives
3. Test Access to Libraries
1. Detect unauthorized
• Review programmer
program changes that may
authority tables for
cause errors or fraud.
proper access rights.
2. Ensure:
• Simulate access
• Maintenance attempts to ensure
procedures protect unauthorized access is
applications from blocked.
unauthorized
These procedures help auditors
changes.
ensure system integrity and
• Applications compliance throughout the
are free from maintenance phase.
material errors.
• Program libraries
are secure from
unauthorized access.
Audit Procedures
1. Identify Unauthorized
Changes
• Reconcile version
numbers with
authorization documents.
• Verify maintenance
approvals with signatures
and change details.
2. Identify Application Errors
• Reconcile source
code with documented
changes.