Chapter 5: Audit Approaches and Computer Assisted-Auditing Techniques
A. Auditing around the computer – the auditor ignores B. PROGRAM TESTING – involves the use of auditor-
bypasses the computer processing function of an entity's controlled actual or simulated data
EDP system. This approach focuses on examining source • Historical audit techniques - test the audit computer
documents the auditor ignores or input and checking the controls at a point in time
final output based on those documents.
1. Test data – a set of dummy transactions specifically
This method can only be used if all of the following conditions designed to incorporated into the processing programs.
are met: Test data shifts control over processing to the auditor by
• The source documents must be available in a form readable using the client's software to process auditor prepared
by a human. test data that includes both valid and invalid conditions. If
• The documents must be maintained in a manner that makes embedded controls are functioning properly, the client's
it possible to locate them for auditing purposes. software should detect all the exceptions planted in the
• The output must be listed in sufficient detail to enable the auditor's test data. This technique would be ineffective if
auditor to trace individual transactions from the source the client does not use the software tested.
documents to the output and vice versa.
a. Auditing through the computer – the auditor enters the
client's system and examines directly the computer and its
system and application software. The focus of this approach
is on the effectiveness of computer controls.
b. Auditing with the computer – the computer is used as an
audit tool.
2. Base case system evaluation (BCSE) – develops test data
COMPUTER ASSISTED AUDIT TOOLS/TECHNIQUES (CAATs) – that purports to test every possible condition that an
are computer programs and data the auditor uses as part of the auditor expects a client's software will confront. BCSE
audit procedures to process data of audit significance contained provides an auditor with much more assurance than test
in an entity's information systems. The data may be transaction data alone but it is expensive to develop and therefore
data on which the auditor wishes to perform tests of controls or cost-effective only in large computer systems.
substantive procedures or they may be other types of data. 3. Integrated test facility – a variation of test data whereby
simulated data and actual data are run simultaneously with
CAATs may be used in performing various auditing procedures, the client's program and computer results are compared
including the following: with auditor's predetermined results. The technique
a. Tests of details of transactions and balances. provides assurance that the software tested is actually
b. Analytical procedures. used to prepare financial reports.
c. Tests of general controls.
d. Sampling programs to extract data for audit testing.
e. Tests of application controls.
f. Reperforming calculations performed by the entity's
accounting systems.
CAATs for TEST OF CONTROLS
d. Program tracing and mapping – program tracing is a
technique in which instruction executed is listed along with 4. Parallel simulation – it involves processing of client's live
control information affecting that instruction. Program (actual) data utilizing an auditor's generalized audit
mapping identifies sections of code which may be a software. If an entity's controls have been operating
potential source of abuse. effectively, the client's software should generate the same
e. Snapshot – this technique takes a picture of the status of exceptions as the same as the auditor's software. This
program execution, intermediate results or transaction data technique should be performed on a surprise basis if
at specified processing points in the program. possible
Chapter 5: Audit Approaches and Computer Assisted-Auditing Techniques
2. System control audit review files (SCARFS) – logs that
collect transaction information for subsequent review and
analysis by the auditor.
3. Audit hooks – "exits" in an entity's computer program that
allows an auditor to insert commands for audit processing
b. Continuous audit techniques – test the audit computer
controls throughout the period.
4. Transaction tagging – a transaction record is "tagged"
5. Control reprocessing – a variation of parallel simulation and then traced through critical points in the
which involves processing of actual client data through a information system.
copy of the client's application program. 5. Extended records – this technique attaches additional
6. Generalized Audit Software (GAS) – is the most widely used audit data which would not otherwise be saved to
CAATs for IS auditing. GAS allows auditors to access regular historic records and thereby helps to provide a
electronically coded data files and perform various more complete audit trail.
operations on their contents. ACL and IDEA are currently the
leading products, but others exist with similar features. OTHER CAATS - Other techniques which an auditor can use in
The following audit tasks can be performed using GAS: the audit under a CIS environment include:
1. Footing and balancing entire files or selected data items.
2. Selecting and reporting detailed data contained on files. a. Audit software – significance from the client's accounting
3. Selecting stratified statistical samples from data files. system. computer programs used to process data of audit
4. Formatting results of tests into reports.
5. Printing confirmations in either standardized or special Package programs (also known as generalized audit software)
wording. programs that can be used in numerous clients. They can be
6. Screening data and selectively including or excluding items. designed to perform different audit tasks such as:
7. Comparing two files and identifying any differences.
8. Recalculating data fields. b. Electronic spreadsheets – contain variety of pre-defined
mathematical operations and functions that can be applied
7. Specialized Audit Software (SAS) – automates and to data contain a variety of pre-defined entered into the
streamlines auditing processes, enabling auditors to analyze cells of a spreadsheet.
data, identify anomalies, and generate reports efficiently, c. Automated work paper software – designed to generate a
ultimately improving audit quality and compliance. trial balance, lead schedules and other reports useful for
8. Embedded audit module (EAM) – techniques use one or the audit. The schedules and reports can be created once
more programmed modules embedded in a host application the auditor has either manually entered or electronically
to select, for subsequent analysis, transactions that meet imported through using the client's account balance
predetermined conditions. As the host application processes information into the system.
the selected transaction, a copy of it is stored on an audit file d. Text retrieval software – allow the user to view any text
for subsequent review. The EAM approach allows material that is available in an electronic format. The software
transactions to be captured throughout the audit period. The program allows the user to browse through text files much
auditor retrieves captured transactions at period-end or at as a user would browse through books.
any time during the period, thus significantly reducing the e. Database management systems – manage the creation,
amount of work the auditor must do to identify significant maintenance and processing of information. The data are
transactions for substantive testing. organized in the form of predefined records and the
a. Continuous audit techniques – test the audit computer database software is used to select, update, sort, display or
controls throughout the period print the records.
1. Audit modules – programmed audit routines f. Public databases – may be used to obtain accounting
incorporated into application programs that are information related to particular companies and industries.
designed to perform an audit function such as a g. Word processing software
calculation or logging activity.
Chapter 5: Audit Approaches and Computer Assisted-Auditing Techniques
Purpose-written programs (also known as special-purpose or • Greater emphasis on tests of details of transactions and
custom-designed programs) – computer programs designed for balances and analytical review procedures, which may
specific audit tasks. increase the effectiveness of certain CAATS, particularly
Utility programs – part of the systems software that performs audit software.
routine CIS tasks. They are generally, not designed for audit
purposes • The application of audit procedures to ensure the proper
functioning of the CAATs and validity of the entity's data.
USING AND CONTROLLING CAATS
Several factors are to be considered if CAATs should be used in b. In cases where smaller volumes of data are processed,
the audit including: manual methods may be more cost-effective.
a. Degree of technical competence in CIS.
b. Availability of CAATs and appropriate computer facilities. c. Adequate technical assistance may not be available to the
c. Impracticability of manual tests. auditor from the entity, thus, making the use of CAAT'S
d. Effectiveness and efficiency of CAATS. impracticable.
e. Timing of test
d. Certain audit package programs may not operate on small
Procedures to control the use of audit software may include: computers, thus, restricting the auditor's choice of CAATS.
a. Participating in the design and testing of computer However, the entity's data files may be copied and
programs. processed on another suitable computer
b. Checking the coding of the program.
c. Requesting the client's CIS personnel to review the
operating system instructions.
d. Running the audit software on small test files before
running them on main data files.
e. Ensuring that the correct files were used.
f. Obtaining evidence that, the audit software functioned as
planned.
g. Establishing appropriate security measures to safeguard
against manipulation of the entity's data files
Procedure to control the use of test data may include:
a. Controlling the sequence of submission of test data where
it spans several processing cycles.
b. Performing test runs.
c. Predicting the results of test data.
d. Confirming that the current version of the program was
used.
e. Obtaining reasonable assurance that the programs used to
process the test data were used by the entity throughout
the applicable audit period.
USING CAATS IN SMALL BUSINESS COMPUTER
ENVIRONMENTS
The general principles outlined are applicable in small business
computer environments. However, the following points should
be given special consideration in these environments:
a. The level of general CIS controls may be such that the
auditor will place less reliance on the system of internal
control resulting in: