0% found this document useful (0 votes)
13 views21 pages

Transcript Audcise g2 Finalist

The document provides an overview of auditing in computer information systems, focusing on relevant regulations such as the Sarbanes-Oxley Act and the Data Privacy Act of 2012, which establish guidelines for ethical standards and data protection. It also discusses various standards and frameworks, including ISPPIA, COSO, and COBIT, that aid auditors in evaluating internal controls and data management practices. Additionally, it outlines data collection methods, types of data storage, and the stages of the data lifecycle, emphasizing the importance of effective data management in organizational decision-making.

Uploaded by

pnghrt
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
13 views21 pages

Transcript Audcise g2 Finalist

The document provides an overview of auditing in computer information systems, focusing on relevant regulations such as the Sarbanes-Oxley Act and the Data Privacy Act of 2012, which establish guidelines for ethical standards and data protection. It also discusses various standards and frameworks, including ISPPIA, COSO, and COBIT, that aid auditors in evaluating internal controls and data management practices. Additionally, it outlines data collection methods, types of data storage, and the stages of the data lifecycle, emphasizing the importance of effective data management in organizational decision-making.

Uploaded by

pnghrt
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

BURAUEN COMMUNITY COLLEGE

Burauen Sports Complex, San Diego, District 9


Burauen, Leyte
Phone: 09760510107/09674116167
Email: localcollegebcc@[Link]

AUDITING IN COMPUTER
INFORMATION SYSTEM
ENVIRONMENT
GROUP 2

Leader
Silong, Zarah Jake C.

Members

Abas, Kem A.
Bulabon, Dayn Allison M.
Cuazon, John Rhod B.
Gatela, Jhaika
Limbo, Honeyleigh M.
Lubiano, Analiza D.
Pacheco, Jethca Jill
Serato, Clarizze Ann R.
BURAUEN COMMUNITY COLLEGE
Burauen Sports Complex, San Diego, District 9
Burauen, Leyte
Phone: 09760510107/09674116167
Email: localcollegebcc@[Link]

3. REGULATIONS, STANDARDS, AND FRAMEWORKS

3.1 SALIENT PROVISIONS OF GLOBAL AND LOCAL RELEVANT REGULATIONS (US SOX AND
DATA PRIVACY)

US SOX
Sarbanes-Oxley Act of 2002
Also known as the SOX act of 2002, a law the US Congress passed on July 30 of that year
to help protect investors from fraudulent financial reporting by corporations, such as the case
of Enron & WorldCom.
It mandated strict reforms to existing securities regulations and imposed through new
penalties on lawbreakers.

SOX REPRESENT THE FF. GUIDELINES FOR BEST PRACTICES 1. SEPARATE CEO AND CHAIRMAN
1. CEO – they have the opportunity to discuss issues without management present
2. CHAIRMAN – important in facilitating such discussions.

2. SET ETHICAL STANDARDS


The BOD should establish a code of ethical standards from which management and
staff will take direction.

3. ESTABLISH AN INDEPENDENT AUDIT COMMITTEE


The audit committee is responsible for selecting and engaging an independent auditor,
ensuring that an annual audit is conducted, reviewing the audit report and ensuring that
deficiencies are addressed.

4. COMPENSATE COMMITTEES
The compensation should not be a rubber stamp for management.

5. NOMINATING COMMITTEES
The board nominations committee should have a plan to maintain a fully staffed BOD
with capable people as it moves forward for the next several years.

6. ACCESS TO OUTSIDE PROFESSIONALS


All committees of the board should have access to attorneys and consultants other than
the corporation’s normal counsel and consultants.

DATA PRIVACY ACT OF 2012 (RA Act No. 10173)


BURAUEN COMMUNITY COLLEGE
Burauen Sports Complex, San Diego, District 9
Burauen, Leyte
Phone: 09760510107/09674116167
Email: localcollegebcc@[Link]

The Data Privacy Act of 2012 establishes a legal framework to protect personal data
processed in both public and private information systems. This law reflects a shift in Philippine
data governance toward privacy protection in digital environments.

Its salient provisions require organizations to:


 Safeguard personal and sensitive personal information throughout its lifecycle
(collection, storage, use, sharing).1,6
 Respect the rights of data subjects (e.g., access, correction, erasure).
 Implement appropriate organizational, physical, and technical security measures to
protect personal data.14

This law also created an independent National Privacy Commission (NPC) to enforce
compliance and align the Philippines with international data protection standards. Because
many CIS audits involve examination of data handling and privacy controls, RA 10173 provides
legal criteria for auditors tasked with evaluating how systems protect personal information.

3.2 OVERVIEW OF RELEVANT STANDARDS (ISPPIA, IT AUDIT AND ASSURANCE STANDARDS

ISPPIA (INTERNATIONAL STANDARDS FOR THE PROFESSIONAL PRACTICE OF INTERNAL


AUDITING)

The purpose of the Standards is to:


1.) Guide adherence with the mandatory elements of the International Professional
Practices Framework.
2.) Provide a framework for performing and promoting a broad range of value-added
internal auditing services
3.) Establish the basis for the evaluation of internal audit performance.
4.) Foster improved organizational processes and procedures.

They also have:


COSO (Committee of Sponsoring Organization) - Widely used to evaluate control
environments (especially in SOX audit contexts).

COBIT (Control Objectives for Information and Related Technologies) - An IT governance


framework that integrates control objectives and audit guidance for information systems.
BURAUEN COMMUNITY COLLEGE
Burauen Sports Complex, San Diego, District 9
Burauen, Leyte
Phone: 09760510107/09674116167
Email: localcollegebcc@[Link]

ISO 27001/27002 series - used to implement and audit information security and privacy
control sets.

These frameworks help auditors classify, assess, and benchmark IT controls within the
larger audit engagement, bridging the gap between regulatory requirements (like SOX and the
Data Privacy Act) and actual audit procedures in computerized environments.

IT AUDIT AND ASSURANCE STANDARDS


The Auditing and Assurance Standards Council (AASC) issues the official Philippine
Standards on Auditing (PSAs) and related assurance standards that are harmonized with
International Standards on Auditing (ISAs). These standards form the foundation for all audit
engagements in the Philippines, including evaluating controls and data reliability in
computerized systems. For instance, PSAs require auditors to obtain sufficient, competent
evidence and understand internal control structures, which increasingly include IT system
controls in a CIS environment.

The IT Audit and Assurance Standards are a collection of recognized, mandatory


guidelines developed by organizations like ISACA or Information System Audit and Control
Association (often via the ITAF framework) that define the minimum requirements for
conducting information systems audits. IS auditing, along with the skills and knowledge
necessary to perform an audit, ensures systematic, high-quality, and ethical IT audits by
focusing on planning, execution, and reporting, while guiding professionals to manage risks,
security, and control effectiveness.

The framework for ISACA IT audit and assurance standards have the following levels:
1.) Standards: Which are mandatory requirements for IT audit and assurance reporting.
2.) Guidelines: Provides guidance in applying IT audit and assurance standards.
3.) Procedures: Are examples of the processes that an auditor might follow.

3.3 RELEVANT FRAMEWORKS ( e.g., COSO, COBIT 2019)

COSO (Committee of Sponsoring Organizations of the Treadway Commission)


It is the standard for designing, implementing, and evaluating internal controls, primarily
focused on improving financial reporting quality, compliance, and operational effectiveness.

What Is the COSO Framework Used for?


BURAUEN COMMUNITY COLLEGE
Burauen Sports Complex, San Diego, District 9
Burauen, Leyte
Phone: 09760510107/09674116167
Email: localcollegebcc@[Link]

is used to organize internal controls that prevent the fraudulent reporting of financial
activities. It provides guiding principles for internal controls across the entire enterprise. COSO
has also published a popular framework for enterprise risk management (ERM).

Five key components of COSO:


1.) Environment - The foundation, focusing on integrity, ethical values, and structure.
2.) Risk Assessment - Identifying and analyzing risks that could affect objectives.
3.) Control Activities - Policies and procedures to mitigate risk.
4.) Information and Communication - Ensuring information flows effectively to support
internal control.
5.) Monitoring Activities - Ongoing evaluations to ensure controls are functioning.

COBIT 2019 (Control Objectives for Information and Related Technologies)


It is an ISACA-developed framework focusing on the governance and management of
enterprise information and technology (EGIT).
It bridges the gap between technical issues, business risks, and control requirements.

Comparison of Key Frameworks


Feature COSO ICIF COBIT 2019

Primary Internal Control & Financial Reporting IT Governance & Management


Focus

Scope Enterprise-wide It-related risks and processes

Approach Principle-based Process-based and detailed

Main Output Control Matrix Governance/Management Objectives

4. DATA MANAGEMENT

4.1 DATA COLLECTION METHODS AND TECHNIQUES


DATA COLLECTION METHODS AND TECHNIQUES
Data collection is the systematic process of gathering information from relevant sources
to answer research questions, test hypotheses, or support decision-making. It is essential for
ensuring the validity and reliability of research findings and can be classified by type of data,
source, or method used.
BURAUEN COMMUNITY COLLEGE
Burauen Sports Complex, San Diego, District 9
Burauen, Leyte
Phone: 09760510107/09674116167
Email: localcollegebcc@[Link]

Types of Data
Quantitative Data: Numerical and measurable, analyzed statistically. Examples include test
scores, income levels, population counts, and temperature readings.

Qualitative Data: Descriptive and non-numerical, capturing experiences, opinions, or cultural


phenomena. Examples include interview transcripts, open-ended survey responses, and
observational notes.

Common Data Collection Methods


Surveys and Questionnaires: Structured instruments to gather specific information from
participants. They can be online, paper-based, or in-person. Advantages include scalability,
cost-effectiveness, and suitability for large populations. Example: Customer satisfaction surveys.

Interviews: Direct, in-depth questioning of individuals to obtain detailed insights. Can be


structured, semi-structured, or unstructured. Advantages include flexibility and the ability to
explore complex topics. Example: Interviews with healthcare professionals about patient care
experiences.

Observations: Recording behaviors or events in their natural settings. Provides contextual and
real-time data. Example: Observing classroom interactions.

Experiments: Controlled studies where variables are manipulated to examine cause-and-effect


relationships. Advantages include high reliability and precision. Example: Testing a new drug’s
effectiveness or consumer reactions to product packaging.

4.2 TYPES OF DATA STORAGE AND DATA BASED SCHEMAS

What is data storage?


Data storage is the system that saves and preserves your files, documents, and other
digital data for ongoing and future use.

Methods of Data Storage

1. Network Attached Storage (NAS)


NAS is a single data storage device that multiple machines can share over one network.
This type of network-based storage consists of either redundant storage containers or a
redundant array of independent disks (RAID) based on a file storage system.
BURAUEN COMMUNITY COLLEGE
Burauen Sports Complex, San Diego, District 9
Burauen, Leyte
Phone: 09760510107/09674116167
Email: localcollegebcc@[Link]

2. Direct Attached Storage (DAS)


DAS attaches directly to your computer to store data transferred from your machine.
While this is a good backup system for your data, it has limited sharing with other devices or
systems. DAS storage devices include solid-state drives (SSD), hard disk drives (HDD), USB flash
drives, optical disks (like CDs and DVDs), and floppy disks.

3. Cloud Storage
Cloud-based storage uses the internet like one extensive network instead of relying on a
local area network. Data is stored in an off-site location, and authorized users can access their
data through the internet, regardless of location. Cloud storage offers easy expansion as
business grows and can have lower setup and operating costs than on-premise storage options
when dealing with vast amounts of data.

4. Storage Area Network (SAN)


is a type of network-based storage that uses a combination of storage devices, including
USB flash drive storage, SSD, cloud storage, or any method of hybrid storage. It works with fiber
channel networks, allowing for faster performance than NAS, and is ideal for multiple users. It
can be a more expensive network-based storage solution but offers unlimited expansion
abilities.

TYPES OF DATA STORAGE DEVICES

SSD and flash storage


These solid-state devices use flash memory to write and store information. SSDs have no
moving parts and offer less latency than HDDs, so they quickly transfer data between devices
and are less prone to damage. This device works well for storing current workloads or your
most critical data but may be cost-prohibitive for storing data long-term.

Cloud storage
Advances in technology have made cloud storage much more cost-effective for many
organizations. With this device, your data is stored in offsite locations instead of on-premise
and hosted on a public cloud network or service provider. Your provider maintains the
infrastructure and keeps your data secure. Cloud storage is easy to access from any internet-
connected device.

Hybrid cloud storage


BURAUEN COMMUNITY COLLEGE
Burauen Sports Complex, San Diego, District 9
Burauen, Leyte
Phone: 09760510107/09674116167
Email: localcollegebcc@[Link]

This device combines public and private cloud services to better address your needs.
You can keep compliance-regulated or highly sensitive data on a private cloud, where you have
full control of security. Then store less sensitive information on a public cloud, which is less
expensive. Some hybrid solutions also combine cloud storage with on-premise devices for
further customization.

WHAT IS A DATABASE SCHEMA?


A database schema logically describes a part or all of a database by displaying the data
structure in tables, fields, and relationships. You can think of it as a blueprint for understanding
an organization’s data resources.

Database Schema Types

Conceptual schema
A conceptual database schema is a high-level schema in a database that provides an
overall view of the entire system of databases without showing implementation details, such as
data types or constraints. They help users understand data flow within an organization and
make it easier for both technical and non-technical users.

Logical schema
The logical schema outlines the logical structure of the data in the database. It defines
how the data is organized and the relationships among the data entities without showing how it
is physically stored. This schema type maintains data consistency and integrity by specifying
data types and constraints to validate entries during the database's design phase.

Physical schema
A physical database schema describes where the data is located in a system. This can
cover file locations, indexing strategies, and storage formats for each table to ensure maximum
performance when you deal with a large amount of data.

4.3 OVERVIEW OF DATA LIFE CYCLE STAGES


What is the data lifecycle?
The data lifecycle encompasses a series of eight stages through which data passes—
from its creation to its end use in decision-making. Each stage involves specific processes and
stakeholders that ensure data is properly managed, analyzed, and utilized.
Understanding the data lifecycle helps organizations optimize their data-handling
practices. This leads to better data quality, improved security, and smarter business decisions.
BURAUEN COMMUNITY COLLEGE
Burauen Sports Complex, San Diego, District 9
Burauen, Leyte
Phone: 09760510107/09674116167
Email: localcollegebcc@[Link]

By effectively navigating these eight stages, organizations can transform raw data into
information they can truly use to drive innovation.

What are the 8 stages of the data lifecycle?


The data lifecycle can be broken down into eight distinct stages, each of which plays a
vital role in transforming raw data into valuable insights. Understanding these stages helps
organizations streamline their data processes—which helps ensure efficiency, accuracy, and
security.

1. Data generation
Data generation marks the birth of the data lifecycle. This first stage involves the
creation of data from a variety of sources, including:

 Customer interactions
 Business and financial transactions
 Social media activities
 Internet of Things (IT) devices

For example, a retail company might generate customer data from point-of-sale (POS) systems,
e-commerce shopping carts, and feedback forms.

2. Data collection
The second stage in the data lifecycle, data collection, involves the structured gathering
of relevant data from a variety of sources like:

 Surveys and questionnaires


 Web scraping
 IT sensors
 Application programming interfaces (APIs)
 Transaction records
 Social media monitoring
 Observations

This stage is critical to the process, as it ensures that the data needed for analysis is
accurately aggregated and that data loss is reduced.

3. Data processing
BURAUEN COMMUNITY COLLEGE
Burauen Sports Complex, San Diego, District 9
Burauen, Leyte
Phone: 09760510107/09674116167
Email: localcollegebcc@[Link]

Data processing is the third stage in the data lifecycle. It involves the following steps
that prepare data for analysis:

1. Data cleaning: Removing duplicate content, correcting errors, and filling in missing
values.
2. Data transformation: Converting raw or unstructured data into a suitable format or
structure.
3. Data integration: Combining data from disparate sources into a cohesive dataset.
4. Data reduction: Simplifying datasets by eliminating redundant or irrelevant data.
5. Data validation: Ensuring processed data meets organizational standards and accurately
reflects its original sources.

These steps prepare collected data for meaningful analysis, ensuring accuracy and consistency.

4. Data storage
The fourth stage of the data lifecycle, data storage, is essential for ensuring data is
accessible, safeguarded, and backed up for future use. This stage focuses on data privacy —
configuring your storage solution for privacy — by securely storing processed data in:

 Databases
 Data warehouses
 Cloud storage solutions
 Data lakes
 On-location storage (e.g., physical servers)

This stage in the data lifecycle involves choosing the right storage solution for your data
protection needs and organizing data for efficient retrieval and use.

5. Data management
Data management is the fifth stage in the data lifecycle. It encompasses the ongoing
organization and maintenance of data through:

 Data governance: Establishing standards, defining user roles, and ensuring compliance.
Setting policies for data sharing across departments.
 Data quality management: Monitoring, cleaning, and validating data.
 Data security: Implementing encryption and access controls and conducting security
audits.
 Data access and retrieval: Setting up and using indexing and cataloging techniques.
BURAUEN COMMUNITY COLLEGE
Burauen Sports Complex, San Diego, District 9
Burauen, Leyte
Phone: 09760510107/09674116167
Email: localcollegebcc@[Link]

 Data integration: Creating a unified view of data and ensuring consistency.


 Data archiving and deletion: Caching or deleting outdated or infrequently used data.

These processes ensure data remains accurate, accessible, and meets regulatory
requirements. And, most importantly, ensures privacy while data is being used.

6. Data analysis
Data analysis, the sixth stage in the data lifecycle, is where real value is discovered by
using analytical tools and techniques to identify patterns, trends, and correlations in data. The
key components involved are:

 Descriptive analytics: Summarizes past data to help organizations understand what has
happened.
 Diagnostic analytics: Examines data to determine why certain events or issues occurred.
 Predictive analytics: Uses historical data and machine learning (ML) to forecast trends
and future outcomes.
 Prescriptive analytics: Guides future actions by predicting optimal steps to reach a
specific goal.

This stage makes it possible to extract meaningful insights from data so businesses can
make more informed decisions.

7. Data Visualization
The seventh stage of the data lifecycle is data visualization. It involves representing data
graphically to communicate data insights effectively. This is the stage in which complex data
becomes more understandable through visualizations like:

 Charts and graphs


 Interactive and real-time dashboards
 Geospatial maps (e.g., heat and choropleth)
 Advanced techniques like scatter plots, histograms, and tree maps

Through graphical representations, this stage makes data understandable for


organizational stakeholders and allows them to take action confidently.

Note: Although data visualization is the 7th step in the data lifecycle, a data analyst, data
scientist, or data engineer, will likely refer to multiple types of visualizations in the exploratory
stage of their analysis and perhaps even earlier in the process.
BURAUEN COMMUNITY COLLEGE
Burauen Sports Complex, San Diego, District 9
Burauen, Leyte
Phone: 09760510107/09674116167
Email: localcollegebcc@[Link]

Who is involved in data visualization?


The main roles typically involved in data visualization include:

 Data scientists: Develop intricate visualizations to illustrate analytical models and


outcomes and ensure they accurately reflect insights and trends.
 Business analysts: Use visualizations to present findings to stakeholders in an
understandable format.

8. Data interpretation
Data interpretation is the final stage in the data lifecycle. This is the stage in which the
analyzed and visualized data is used to make informed business decisions. The key activities
involved in this stage include:

 Reviewing dashboards, charts, and graphs to identify key insights.


 Making sense of analytical results and drawing conclusions to explain business
performance.
 Suggesting actions based on data findings and providing strategic guidance on
marketing, product development, and customer engagement.
 Presenting findings and using storytelling techniques to convey the significance of data
insights.

This stage is important to an organization’s data usage practices, as it ensures that


insights derived from data analysis and visualization are effectively utilized to drive strategic
decisions and improve outcomes for an organization.

Who is involved in data interpretation?


The main roles typically involved in data interpretation include:

 Business analysts: Use visualizations to present findings to stakeholders in an


understandable format.
 Stakeholders and executives: Make tactical decisions based on data.

4.4 RELATIONAL DATABASE STRUCTURE FOR DATA RELEVANCE INTEGRITY, USE OF DATA
DICTIONARIES, AND NORMALIZATION

RELATIONAL DATABASE
BURAUEN COMMUNITY COLLEGE
Burauen Sports Complex, San Diego, District 9
Burauen, Leyte
Phone: 09760510107/09674116167
Email: localcollegebcc@[Link]

Relational database structures store data in tables composed of rows and columns,
where each table represents a specific type of information such as customers, products, or
transactions. These tables are linked to one another through keys, allowing related data to be
connected without unnecessary duplication. This structure helps organize data clearly and
makes it easier to store, retrieve, and manage information efficiently.

1. RELATIONAL DATABASE STRUCTURES FOR DATA INTEGRITY


DATA INTEGRITY – Data integrity refers to the accuracy, consistency, and reliability of data
stored in a database.

Common Ways To Ensure Data Integrity:

a. Primary Keys - primary key is a unique ID for each record in a table.


For example, a student table may use Student ID so that no two students have the same ID. This
prevents duplicate records.

b. Foreign Keys- foreign key links one table to another.


For example, an Orders table may connect to a Customers table using Customer ID. This
ensures that an order cannot exist without a valid customer.

c. Entity Integrity- this rule ensures that the primary key is never empty (null). Every record
must have a valid identity.

d. Referential Integrity- this makes sure relationships between tables stay valid.
For example, you cannot delete a customer if there are still orders connected to that customer.

e. Domain Integrity- this controls the type of data allowed in a column. For example, an Age
field should only accept numbers within a reasonable range. These structures help prevent
errors, missing data, and inconsistencies.

2. USE OF DATA DICTIONARIES


DATA DICTIONARY- is a reference document that describes the structure and meaning of data
within a database. It contains details such as table names, field names, data types, and rules for
data entry. By clearly defining each data element, a data dictionary helps users and developers
understand the database and promotes consistency in data use.

It contains important information about the data, such as:


BURAUEN COMMUNITY COLLEGE
Burauen Sports Complex, San Diego, District 9
Burauen, Leyte
Phone: 09760510107/09674116167
Email: localcollegebcc@[Link]

 Names of tables
 Names of columns
 Data types (text, number, date, etc.)
 Size limits
 Descriptions of each field
 Rules or restrictions
3. NORMALIZATION
Is the process of organizing data to reduce duplication and avoid inconsistencies. It
involves dividing large tables into smaller, related tables so that each table focuses on a single
type of information. Through normalization, data is stored efficiently, updates become easier,
and the overall accuracy and reliability of the database are improved.

Goals of normalization are:


 Remove duplicate data
 Avoid data inconsencies
 Save storage space
 Make updates easier
Normalization is done in stages called normal forms:

1. First Normal Form (1NF)- each column should contain only one value, not multiple values.
Example: Instead of listing many phone numbers in one field, create separate records.

2. Second Normal Form (2NF)- data should depend on the whole primary key, not just part of
it. This usually means separating data into new tables.

3. Third Normal Form (3NF)- remove columns that do not directly depend on the primary key.
This prevents storing unrelated information in the same table.

4.5 STANDARD SQL QUERIES FOR DATA RELEVANCE AND COMPLETENESS


In a modern computerized environment, most companies store their financial and
operational data electronically. Auditing in such environments requires auditors to examine
large volumes of data efficiently and accurately. Manual verification is often impractical due to
the large amount of data, so auditors rely on Structured Query Language (SQL) to retrieve,
filter, and analyze data.
Two critical aspects of data that auditors evaluate are relevance and completeness.
Relevant data ensures that the information examined pertains directly to the audit objectives,
while complete data ensures that no required transactions or records are missing. The use of
BURAUEN COMMUNITY COLLEGE
Burauen Sports Complex, San Diego, District 9
Burauen, Leyte
Phone: 09760510107/09674116167
Email: localcollegebcc@[Link]

SQL queries enables auditors to assess both factors effectively, ensuring accurate and reliable
audit outcomes.

DATA RELEVANCE AND SQL QUERIES


It refers to the appropriateness of the data for the audit objectives. Auditors focus on
retrieving only the information necessary for evaluation to avoid analyzing unnecessary or
unrelated records. SQL provides several tools, to achieve this:

SELECT Query – Retrieves specific data from a table.


SELECT transaction_id, amount, date
FROM sales;
Purpose: Enables auditors to access the relevant fields needed for examination.

WHERE Clause – Filters data according to specific conditions.


SELECT *
FROM sales
WHERE date BETWEEN '2025-01-01' AND '2025-12-31';
Purpose: Ensures that only transactions within the audit period are included, maintaining
relevance.

ORDER BY Clause – Organizes data in a logical sequence.


SELECT *
FROM sales
ORDER BY date DESC;
Purpose: Allows auditors to review the most recent transactions first, streamlining analysis.

DATA COMPLETENESS AND SQL QUERIES


It ensures that all transactions or records are properly recorded, with no omissions.
Several SQL queries assist auditors in verifying completeness:

COUNT() Function – Counts the number of records in a table.


SELECT COUNT(*) FROM sales;
Purpose: The total number of records can be compared with expected totals to identify missing
transactions.

NULL Value Check – Identifies incomplete records.


SELECT *
FROM sales
WHERE amount IS NULL;
BURAUEN COMMUNITY COLLEGE
Burauen Sports Complex, San Diego, District 9
Burauen, Leyte
Phone: 09760510107/09674116167
Email: localcollegebcc@[Link]

Purpose: Detects missing or incomplete data that may indicate recording errors.

Detecting Duplicate Records – Identifies repeated transactions


SELECT transaction_id, COUNT(*)
FROM sales
GROUP BY transaction_id
HAVING COUNT(*) > 1;
Purpose: Prevents overstatement or double-counting of transactions.

Comparing Related Tables – Ensures all data is properly linked.


SELECT *
FROM sales s
LEFT JOIN customers c
ON s.customer_id = c.customer_id
WHERE c.customer_id IS NULL;
Purpose: Detects transactions without valid customer records, indicating incomplete or
inconsistent data.

4.6 DATA INTEGRATION FROM VARIOUS SOURCES FOR ANALYSIS AND DECISION-MAKING
Classify the data integration from various sources for analysis and decision-making

Data integration combines heterogeneous data into a consistent, usable form for analytics and
operations.

Classification by Process Type


 ETL (Extract, Transform, Load): Data is extracted, converted in a separate staging
environment, and then loaded into a warehouse. Ideal for complex transformations,
high data quality requirements, and structured, batch-processed data.
 ELT (Extract, Load, Transform): Data is loaded raw into a modern cloud data warehouse
(e.g., Snowflake, BigQuery) and transformed inside the target. Best for large, high-
volume data sets and rapid availability.
 Data Streaming (Real-time Integration): Data is continuously moved, processed, and
loaded in real time. Crucial for applications requiring up-to-the-minute, actionable
insights.
 Change Data Capture (CDC): A specialized technique that identifies only the data that
has changed in source systems, minimizing resource load during synchronization.
Classification by Architecture
 Common Storage (Consolidation): Data is physically copied from multiple sources into a
centralized repository, such as a data warehouse or data lake. This offers high query
performance.
BURAUEN COMMUNITY COLLEGE
Burauen Sports Complex, San Diego, District 9
Burauen, Leyte
Phone: 09760510107/09674116167
Email: localcollegebcc@[Link]

 Data Virtualization (Federation): A virtual abstraction layer provides a unified view of


data without moving it from its source. It allows real-time, read-only access, ideal for
agile, heterogeneous data environments.
 Middleware-Based Integration: Middleware acts as an intermediary, managing
communication and data transformation between disparate, often legacy, systems.
 API-Based Integration: Systems are directly connected through Application
Programming Interfaces. It is effective for integrating SaaS applications but can be
fragile if API schemas change.
Classification by Scope and Usage
 Application-Based Integration: Focuses on synchronizing data between specific
applications, such as linking a CRM with an ERP.
 Manual Integration: Data is manually exported from one system and imported into
another (e.g., spreadsheets). Simple, but error-prone and unscalable.
 Master Data Management (MDM): Focuses on creating a “single source of truth” for
critical data entities (e.g., customer, product) across the enterprise.
Key Considerations for Decision-Making
 Latency: Do you need real-time (streaming/CDC) or daily batch (ETL/ELT) data?
 Data Type: Is the data structured, semi-structured, or unstructured?
 Volume & Velocity: How much data is moving, and how fast?
 Infrastructure: On-premises, cloud-native, or hybrid?

4.7 USE OF COMPUTERS – ASSISTED AUDIT TOOLS AND TECHNIQUES (CAATs)

DEFINITIONS:
Computer – Assisted Audit Techniques (CAATs)
Refers to the use of specialized software and tools by auditors to perform auditing tasks
more efficiently and effectively.

Computer – Assisted Audit Tools and Techniques (CAATTs)


Defines as the use, by an auditor, of different information technology software, tools
and techniques, to review a computerized accounting information system. They provide a wide
range of techniques and tools that help the auditor evaluating internal control, conducting
tests, collecting evidences, and so forth.

Other terms: Computer Aided (Assisted) Audit Tools (or Techniques).


CAATs and CAATTs can be used interchangeably.

2 COMMON TYPES OF CAATS

1. Audit Software
BURAUEN COMMUNITY COLLEGE
Burauen Sports Complex, San Diego, District 9
Burauen, Leyte
Phone: 09760510107/09674116167
Email: localcollegebcc@[Link]

Consists of computer programs used by the auditors, as part of their auditing


procedures, to process data of audit significance from the entity’s accounting system.

The main advantage of these programs is that they can be used to process large
volumes of data in a relatively short period, which it would be inefficient to do manually. The
programs can then present the results so that they can be investigated further.

Specific procedures they can perform include:


Extracting samples according to specified criteria, such as:
 Random;
 Over a certain amount;
 Below a certain amount;
 At certain dates;
 Calculating ratios and select indicators that fail to meet certain pre-defined criteria;
 Check arithmetical accuracy;
 Preparing reports;
 Stratification of data;
 Produce letters to send out to customers and suppliers; and
 Tracing transactions through the computerized system.

Generalized Audit Software


Allows auditors to perform tests on computer files and databases, such as reading and
extracting data from a client’s systems for further testing, selecting data that meets certain
criteria, performing arithmetic calculations on data, facilitating audit sampling, and producing
documents and reports.
Custom Audit Software
is written by auditors for specific tasks when generalized audit software cannot be used.

Audit Software: Examples of Use


 Perform calculations and comparisons in analytical procedures
 Sampling programs to extract data for audit testing (ex. select a sample of receivables
for confirmation)
 Scan a file to ensure that all documents in a series have been accounted for or to search
for large and unusual items
 Compare data elements in different files for agreement (ex. prices on sales invoices to
authorized prices in master files)

2. Test Data
BURAUEN COMMUNITY COLLEGE
Burauen Sports Complex, San Diego, District 9
Burauen, Leyte
Phone: 09760510107/09674116167
Email: localcollegebcc@[Link]

used to test specific controls in computer programs, such as online password and data
access controls. Test data involves the auditor submitting ‘dummy’ /fake data into the client’s
system to ensure that the system correctly processes it and that it prevents or detects and
corrects misstatements.

Objective:
is to test the operation of application controls within the system. To be successful, test
data should include both data with errors built into it and data without errors.

EXAMPLES OF ERRORS:
 Codes that do not exist;
 Transactions above pre-determined limits;
 Invoices with arithmetical errors; and
 Submitting data with incorrect batch control totals.

PURPOSE OF CAATS
 Efficiency: CAATs help auditors quickly process and analyze large datasets, which
improves the efficiency of the audit process.
 Accuracy: Automated tools reduce the risk of human error and increase the accuracy of
audit findings.
 Comprehensive Coverage: CAATs enable auditors to examine entire data populations,
rather than relying on samples, leading to more comprehensive audit results.
 Detection of Irregularities: These tools help identify anomalies, trends, and patterns
that may indicate fraud, errors, or other issues that require further investigation.
 Risk Management: By enabling continuous monitoring and real-time analysis, CAATs
help in identifying and mitigating risks promptly.

WHO PERFORMS CAATS?


 Auditors: Typically performed by internal and external auditors trained in the use of
CAATs and audit software.
 IT Specialists: May assist auditors in implementing and configuring CAATs, especially in
complex IT environments.
 Audit Teams: Often, CAATs are performed by a team that includes both audit and IT
professionals.

ADVANTAGES OF USING CAATs


1. Increased Efficiency – CAATs automates repetitive tasks, such as data extraction and
analysis, which saves time and reduces the risk of errors.
BURAUEN COMMUNITY COLLEGE
Burauen Sports Complex, San Diego, District 9
Burauen, Leyte
Phone: 09760510107/09674116167
Email: localcollegebcc@[Link]

2. Enhanced Accuracy – CAAT tools can perform complex calculations and data analysis
with a high level of accuracy. They can identify anomalies, patterns, and trends in large
datasets that may be difficult to detect manually.
3. Improved Audit Quality – CAATs provides auditors with access to a wide range of data
analysis techniques and tests. This enables them to perform more comprehensive and
thorough audits, leading to higher audit quality and assurance.
4. Increased Audit Coverage – CAAT allows auditors to analyze large volumes of data
quickly and efficiently. This enables to cover large sample size population audit,
providing a more comprehensive view of the organization’s operations.
5. Standardization and Consistency – CAAT tools provide a standardized approach to data
analysis and audit procedures. This ensures consistency in the audit process and
facilities comparability across different audits or audit periods.

DISADVANTAGES OF USING CAATs


1. Cost and Complexity – Implementing and maintaining CAAT tools can be costly,
especially for smaller audit firms or organizations with limited resources.
2. Data Integrity and Reliability – CAATs heavily relies on the accuracy and reliability of the
underlying data. If the data is incomplete, inaccurate, or not properly validated, it can
lead to incorrect audit conclusions and recommendations.
3. Limited Scope – CAATs tools are most effective when dealing with structured data, such
as financial transactions. They may have limitations in analyzing unstructured data, such
as emails or documents, which may require manual review.
4. Lack of Human Judgement – While CAAT tools can automate many audit procedures,
they cannot replace human judgement and professional skepticism. Auditors still need
to interpret the results, exercise professional judgement, and consider qualitative
factors that may not be captured by the tools.
5. Security and Privacy Risks – CAAT tools require access to sensitive and confidential
data. This raises concerns about data security, privacy, and compliance with relevant
regulations. Adequate controls and safeguards must be in place to protect the data and
ensure compliance.

APPLICATION OF CAATS IN THE AUDIT PROCESS


 Data Extraction: Pulling relevant data from various systems for analysis.
 Data Analysis: Analyzing extracted data for inconsistencies, trends, and anomalies.
 Test of Controls: Verifying the effectiveness of internal controls by simulating
transactions and processes.
 Substantive Testing: Conducting detailed tests on specific areas of interest, such as
financial transactions or inventory levels.
BURAUEN COMMUNITY COLLEGE
Burauen Sports Complex, San Diego, District 9
Burauen, Leyte
Phone: 09760510107/09674116167
Email: localcollegebcc@[Link]

 Reporting: Generating automated reports based on the findings of the CAATs, which can
be used to support audit conclusions.

You might also like