Digital Auditing
Digital Auditing
CHAPTER 04
1. DIGITAL AUDIT
1.1 What is a Digital Audit?
Digital Audit is placing assurance on the effectiveness of the IT systems implemented in an organization.
Technology is becoming an integral part of day-to-day business operations.
1.2 Key Features of a Digital Audit
Digital audit encourages the auditee to embrace the latest technological advancements and provides
confidence to auditee to stay updated in a constantly evolving environment. A digital audit improves the
quality of opinion. This consequently leads to a more reliable audit report. Digital Audit leads to savings in
time, cost and human effort which can be utilized towards more productive tasks.
1.3 Advantages of Digital Audit
(i) Enhanced Effectiveness & Efficiency: Increased efficiency is one of the key benefits of digital audit.
With the use of tools and automation techniques, auditee can standardize the processes and routine
tasks can be automated.
(ii) Better Audit Quality: Technology can correctly evaluate massive volumes of data quickly. This can
assist auditors in determining the areas that require more testing, lowering the chance that serious
misstatements or other problems would go unnoticed.
(iii) Lower Costs: By automating processes that were previously done manually, technology can assist with
the cost of auditing.
(iv) Better Analytics: Improved analytics capabilities can aid management and auditors in seeing trends
and patterns that may be challenging to spot manually.
(v) Improved Risk Assessment: Creating a number of automations to assist with the audit process and
streamlined testing improves the risk assessment procedure. Management and auditors put their
testing efforts on sites with a higher risk of material misstatement and make informed decisions.
1.4 Consideration and Challenges of Digital Audit
Some considerations that organization should keep in mind while using digital techniques & automation:
4.2 DIGITAL AUDITING AND ASSURANCE-Summary Vol II-CHAPTER 04
❖ New activities or changes to existing processes due to new technology (e.g., new revenue streams,
changes in the roles and responsibilities of entity personnel, automation of manual tasks, changes in
staffing levels that affect an entity’s internal control environment)
❖ Changes in the way the entity’s systems are developed and maintained and whether these changes
introduce new risks and require new controls to respond to those risks
❖ The impact of the new technology as how the organization obtains or generates and uses relevant,
quality information to support the functioning of internal control.
2. AUDITING DIGITALLY
2.1 What is the concept of auditing digitally?
Auditing Digitally is using advancements in technology for conducting an effective and efficient audit. With
a rapidly growing IT environment it is essential to adapt technology in auditing practices.
It is time to digitize the way an audit is delivered through automation and innovation. There are new
technologies to help capture data, automate procedures, analyse information and focus on the real risks
of the client. The opportunity is in understanding how technology can help and then applying it to the auditing
challenges.
2.2 Key Features or Advantages of Auditing Digitally:
Following are key features or advantages of Auditing Digitally:
(i) Improved Quality of Audits: The impact on quality is evident, through automation, data analytics
techniques, we can easily move from sample auditing to full population of transactions being reviewed
or re-performed
(ii) Decreasing human dependency: Using technology minimizes the manual intervention which ultimately
results in reducing the risk of manual errors. Technology helps in streamlining the process of testing
for auditors which decreases the errors which occur from the judgement of different individuals.
(iii) Increases Transparency: With the technological advancement, transparency has been increased. New
ERPs and tools have audit trail feature available to trace the transaction end to end.
(iv) Automation and Ease: Automating tasks like recording work in repositories, extracting data and
sampling have improved the quality of audit and reduced the manual error. Using dashboards (e.g.,
Power BI) for reporting helps in understanding the position and helps the auditor to form his opinion.
(v) Improved Efficiency: What used to take weeks to learn and programme using deep experts, is now
easily available to auditors after some simple training and digital upskilling. The result may be
increased efficiency and fewer errors, but the benefits are wider reaching and personal. This also
results in improved retention of talent and confidence.
(vi) Better Risk Assessment: With usage of automation and technology in audit, auditor may focus on the
real challenges and assess the potential risk precisely. Dashboards, visual presentations and other
tools helps in understanding where the risk lies and what all areas need more attention.
2.3 Considerations in Auditing Digitally
There are few questions it is important to ask and answer – at all stages of tech journey:
2.3.1 What problems are you trying to solve?
❖ Continuously evaluate the emerging technologies and latest tools to see what can benefit the audit.
Vol II-CHAPTER 04 DIGITAL AUDITING AND ASSURANCE-Summary 4.3
❖ Think about what would make your audit easier or better and how you will measure return on your
investment.
➢ Customization in IT applications,
DIGITAL AUDITING AND ASSURANCE
Reports System generated reports are information generated by IT systems. These reports
are often used in an entity's execution of a manual control, including business
➢ Development, testing and production environments are segregated for changes to application
configurations
DIGITAL AUDITING AND ASSURANCE
Fileless Malware Fileless malware is a type of malicious activity that uses native, legitimate
tools built into a system to execute a cyber-attack. Unlike traditional
malware, fileless malware does not require an attacker to install any code on
a target’s system, making it hard to detect.
Trojan A trojan is malware that appears to be legitimate software disguised as
native operating system programs or harmless files like free downloads.
Trojans are installed through social engineering techniques such as phishing
or bait websites.
Mobile Malware Mobile malware is any type of malware designed to target mobile devices.
Mobile malware is delivered through malicious downloads, operating system
vulnerabilities, phishing, smishing, and the use of unsecured Wi-Fi.
Vol II-CHAPTER 04 DIGITAL AUDITING AND ASSURANCE-Summary 4.7
2. Denial-of Service (DoS) Attacks: A Denial-of-Service (DoS) attack is a malicious, targeted attack
that floods a network with false requests in order to disrupt business operations.
Vishing Vishing, a voice phishing attack, is the fraudulent use of phone calls and
voice messages pretending to be from a reputable organization to convince
individuals to reveal private information such as bank details and passwords.
as knowledge of business processes, company policies or other information that would help carry out
such an attack.
DIGITAL AUDITING AND ASSURANCE
7. DNS Tunnelling: DNS Tunnelling is a type of cyber attack that leverages domain name system (DNS)
queries and responses to bypass traditional security measures and transmit data and code within the
network. This tunnel gives the hacker a route to unleash malware and/or to extract data, IP or other
sensitive information by encoding it bit by bit in a series of DNS responses.
8. IoT-Based Attacks: An IoT attack is any cyber attack that targets an Internet of Things (IoT)
device or network. Once compromised, the hacker can assume control of the device, steal data, or join
a group of infected devices
5.2 Stages of Cyber Risk:
Following are 3 Stage of cyber risk
1. Stage 1 - Assessing the cyber risk: No organization is completely immune to a cyber risk. Every
organization should consider at least the common threats-
➢ Ransomware disabling their organization (including their plants and manufacturing facilities)
➢ Common criminals using email phishing and hacks for fraud and theft.
➢ Insiders committing malicious activities or accidental activities resulting in unintended discourse
of information theft and frauds.
2. Stage 2 - Impact of cyber risk: Cyber-attack can impact one, two or more types of risks. The impact
of the attack would vary from organization to organization and most importantly from an attack to
attack. Some of the indicative areas can be –
➢ Regulatory costs
➢ Business interruptions causing an operational challenge for an organization.
➢ Data loss, reputational loss and litigation.
➢ Ransomware - more common these days where entire systems are encrypted
➢ Intellectual property theft which may not only take the competitive advantage, but we may also
result in any impairment/impediment charge because of the loss of IP.
➢ Incident response cost which could be for investigations & remediation
➢ Breach of Privacy, if personal data of a consumer is hacked it could have a significant impact on
the organization.
➢ Fines and penalties
3. Stage 3- Managing the cyber risk: A strategic approach to cyber risk management can help an
organization to:
➢ Gain a understanding of the cyber risks, threats facing their organization and other financial
institutions
➢ Assess existing IT and cyber security program and capabilities against the relevant regulatory
requirements
➢ Align cyber security and IT transformation initiatives with strategic objectives and critical
risks
➢ Understand accepted risks & documented compensating controls
Vol II-CHAPTER 04 DIGITAL AUDITING AND ASSURANCE-Summary 4.9
❖ Necessary improvements – like patch upgrades, better controls, improved technology in terms of
firewall, anti-virus, tools etc. needs to be implemented to safeguard the entity.
DIGITAL AUDITING AND ASSURANCE
➢ Ensure feasibility is determining what technology may be used, if auditors and auditees have
competencies and that resources are available.
❖ Generating and preparing meaningful information from raw system data using processes, tools, and
techniques is known as Data Analytics.
❖ It involves analyzing large sets of data to find actionable insights, trends, draw conclusions and for
informed decision making.
❖ It allows auditors to more effectively audit the large amounts of data held and processed in IT systems
in larger clients.
Audit analytics helps:
❖ To discover and analyze patterns
❖ Identifying anomalies
❖ Extract other useful information in data
The data analytics methods used in an audit are known as Computer Assisted Auditing Techniques or CAATs.
Some of the popular tools used across the industry as part of CAATs are listed below:
1. ACL - Audit Command Language (ACL) Analytics is a data extraction and analysis software used for
fraud detection and prevention, and risk management. It samples large data sets to find irregularities
or patterns in transactions that could indicate control weaknesses or fraud. Example –It is used to
analyze and check complete data sets to perform Trial Balance reconciliations during the Audits. In
such case scenarios, the entity provided the General Ledger dump and system Trial Balance.
2. Alteryx - Alteryx is used to consolidate financial or operational data to assess controls.
➢ A fully transparent audit trail of every action is performed in Alteryx in form of a workflow
which makes it easier for the user to learn as no prior knowledge of coding or scripting is required.
➢ Alteryx can also be leveraged to automate analytics and perform Machine Learning to search
for patterns indicative of fraud or irregularities speed up your processes like accounting close,
tax filings, regulatory reporting, forecast creation etc.
➢ It can also be used to automate set procedures that are performed periodically like
reconciliations, consolidations, marketing workflows, system integrations, continuous audits etc.
Example-
➢ Alteryx used for logistics organization to recompute the revenue entries recorded by the system
to match with the financials that showcased the expected revenue turnover.
➢ Due to Alteryx’s processing speed and ease to implement functions, auditors could perform re-
computation for all the transactions entry and noted that the revenue was being understated as
the expected revenue was more than the actual calculated.
3. Power Bi is a business intelligence (BI) platform that provides non-technical business users with tools
for aggregating, analyzing, visualizing and sharing data. From audit perspective, such visualization
tools can be used to find the outliers in the population, it can also be used for reporting purpose
(audit reports) to the higher management.
Example-
Power BI dashboard used for checking the outliers of the apparel company. Auditors were required
to analyse the trends of the sales during the year. By the use of Power BI, the sales data provided by
the client was further converted into dashboard to analyse the trends and patterns as per the market
standards.
Vol II-CHAPTER 04 DIGITAL AUDITING AND ASSURANCE-Summary 4.13
4. CaseWare – CaseWare is a data analysis software & provide tools that helps in conducting audit and
assurance engagements quickly, accurately and consistently.
❖ The self-deploying robots can determine how much vacuuming there is to do based on a room’s size,
uses AI to scan room size, identify obstacles and remember the most efficient routes for cleaning.
DIGITAL AUDITING AND ASSURANCE
Audit Implications
❖ Focus on logical flow- Given the invisible nature of algorithms, audits must focus on the logical flow
of processes.
❖ Algorithms. - A review of AI should ascertain whether unintended bias has been added to the
algorithms. Auditors should assess the effectiveness of algorithms and whether their output is
appropriately reviewed and approved.
❖ Bugs and vulnerabilities - Because AI is built on software modules, auditors must also consider cyber
security and search for possible bugs and vulnerabilities that can be exploited to impact AI
functionality.
❖ Effect of AI- Auditors should confirm their understanding of how the use of AI affects the entity’s
flows of transactions, including the generation of reports or analytics used by management.
❖ Decision Making - Auditors also should consider whether the AI is making decisions—or being utilized
by management as part of the decision-making process.
Common risks for AI
❖ Security is one of the key risks – the more data the system uses, from more sources, the more entry
points and connections are formed and the greater the potential risks.
❖ Inappropriate configuration - AI may also be used to diagnose medical conditions. If it is badly
configured or malfunctions, it could harm people before the problem is spotted.
❖ Data privacy - The data used and shared should have the necessary explicit consent from data
providers.
7.3 Block chain
❖ Block chain is based on a decentralized and distributed ledger that is secured through encryption.
❖ Each transaction is validated by the block chain participants, creating a block of information that is
replicated and distributed to all participants.
❖ All blocks are sequenced so that any modification or deletion of a block disqualifies the information.
❖ Example- Bitcoin, crypto currency transfer application - Block chain in money transfer, block chain
smart contracts
Audit Implications
❖ Auditors should consider the appropriate governance and security transactions around the
transactions.
❖ As block chain interacts with legacy systems and business partners, concerns related to insecure
application programming interfaces (APIs), data confidentiality and privacy cannot be ignored.
❖ Weak block chain application development protocols are something auditors cannot overlook. Similarly,
data privacy laws and regulations may be area of concern as data are communicated across geographic
boundaries.
❖ Auditors must be able to determine whether the data put on block chain will expose the enterprise to
liability for noncompliance with applicable laws and regulations.
Common risks for block chain technology
The strengths of block chain can also be its weaknesses.
Vol II-CHAPTER 04 DIGITAL AUDITING AND ASSURANCE-Summary 4.15
❖ The inability to reverse transactions and to access data without the required keys make the system
secure, but also mean that organisations need specific protocols and management processes to ensure
❖ To perform substantive testing, auditors must have an understanding of the tools used to develop and
maintain RPA.
DIGITAL AUDITING AND ASSURANCE
❖ This will be helpful when auditors review logs, configuration controls, privileged access controls and the
like. General IT controls are applicable as always.
Common Risks of RPA:
i. Operational and execution risks
➢ Robots are deployed without proper operating model.
➢ Buying the wrong tool, making wrong assumptions, taking shortcuts, and jeopardizing security and
compliance.
➢ Assigning proper responsibilities, training and clearly stating about changing roles also can help
you reduce operational risk to a great extent.
ii. Change management risks: Not following the change management implementation lifecycle, improper
and incomplete testing (not covering all scenarios) leads to inaccurate results.
iii. RPA Strategy Risk: Setting wrong expectations, improper KPIs, and unrealistic business goals
creates an environment of uncertainty. Management should discuss, and analyse the complete working
characteristics, potential, and limitations of RPA before drafting a RPA.
9.1 Some of the most rapidly advancing areas, with many implications for society are -
1. Drone Technology: Using drone technology in the remote locations for stock counts. Drones have great
payload capacity for carrying sensors and cameras, thus they can photograph and physically examine
the count of large quantities of fixed assets and inventory.
Drone captured audit information can be combined with various alternative sources of information
such as QR code readers, handheld bar scanners, manual counts etc.
2. Augmented reality: The technology allows users to view the real-world environment with augmented
(added) elements, generated by digital devices.
4.18 DIGITAL AUDITING AND ASSURANCE-Summary Vol II-CHAPTER 04
One famous example was Pokémon Go, a game for mobile devices in which players chase imaginary digital
creatures (visible on their mobile phones) around physical locations.
DIGITAL AUDITING AND ASSURANCE
3. Virtual reality: VR goes a step forward and replaces the real world entirely with a simulated
environment, created through digitally generated images, sounds, and even touch and smell. Using
special equipment, such as a custom headset, the user can explore a simulated world or simulate
experiences such as flying or skydiving.
4. Metaverse: The metaverse is the emerging 3-D digital space that uses virtual reality, augmented
reality, and other advanced internet technology to allow people to have lifelike personal and business
experiences online. It represents a convergence of digital technology to combine and extend the reach
and use of Cryptocurrency, Artificial Intelligence (AI), Augmented Reality (AR) and Virtual Reality
(VR).
9.2 Case scenarios to illustrate the potential application of the metaverse in the financial domain
❖ Virtual Banking and Transactions: A forward-thinking financial institution, establishes a presence in
the metaverse to offer virtual banking services. Users can create virtual bank accounts, access
personalized financial dashboards, and perform transactions using virtual currencies.
❖ Digital Asset Management: A digital asset management company, recognizes the growing popularity of
virtual assets in the metaverse. They launch a virtual asset trading platform within the metaverse,
allowing users to buy, sell, and trade NFTs and other digital assets.
❖ Virtual Financial Education and Training: A Financial Learning Academy aims to enhance financial
literacy using the metaverse. They create a virtual classroom environment where participants can
attend interactive financial education sessions.
❖ Virtual Meetings and Conferences: For a leading industry even, an organisation hosts a virtual
conference within the metaverse. Participants from around the world can access the conference
through their virtual avatars.
❖ Data Visualization and Analytics: A company utilizes the metaverse to offer advanced data
visualization and analytics tools to financial professionals. Their virtual analytics platform allows users
to visualize complex financial data in interactive and immersive 3D environments.
Common Risks associated:
❖ Beyond their potential, these technologies also come with challenges such as public safety,
cybersecurity, data privacy, data protection, lack of standards and technical challenges.
❖ Since they often track movements and data, massive amounts of data are generated about the
whereabouts of users. It also raises questions about taxation, jurisdiction, and customer protection.
❖ Regulators and auditors have to think of the controls around privacy, data security, governance to
make it more regulated.