0% found this document useful (0 votes)
7 views18 pages

Digital Auditing

The document discusses Digital Auditing and Assurance, emphasizing the importance of technology in enhancing audit effectiveness, efficiency, and quality. It outlines the advantages of digital audits, including cost savings, improved analytics, and better risk assessment, while also addressing considerations and challenges organizations face when adopting digital techniques. Additionally, it highlights the need for auditors to understand the IT environment, identify IT risks, and assess cyber risks to ensure robust auditing practices.

Uploaded by

Prapti Dutta Roy
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
7 views18 pages

Digital Auditing

The document discusses Digital Auditing and Assurance, emphasizing the importance of technology in enhancing audit effectiveness, efficiency, and quality. It outlines the advantages of digital audits, including cost savings, improved analytics, and better risk assessment, while also addressing considerations and challenges organizations face when adopting digital techniques. Additionally, it highlights the need for auditors to understand the IT environment, identify IT risks, and assess cyber risks to ensure robust auditing practices.

Uploaded by

Prapti Dutta Roy
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Vol II-CHAPTER 04 DIGITAL AUDITING AND ASSURANCE-Summary 4.

CHAPTER 04

DIGITAL AUDITING AND ASSURANCE


DIGITAL AUDITING AND ASSURANCE

1. DIGITAL AUDIT
1.1 What is a Digital Audit?
Digital Audit is placing assurance on the effectiveness of the IT systems implemented in an organization.
Technology is becoming an integral part of day-to-day business operations.
1.2 Key Features of a Digital Audit
Digital audit encourages the auditee to embrace the latest technological advancements and provides
confidence to auditee to stay updated in a constantly evolving environment. A digital audit improves the
quality of opinion. This consequently leads to a more reliable audit report. Digital Audit leads to savings in
time, cost and human effort which can be utilized towards more productive tasks.
1.3 Advantages of Digital Audit
(i) Enhanced Effectiveness & Efficiency: Increased efficiency is one of the key benefits of digital audit.
With the use of tools and automation techniques, auditee can standardize the processes and routine
tasks can be automated.
(ii) Better Audit Quality: Technology can correctly evaluate massive volumes of data quickly. This can
assist auditors in determining the areas that require more testing, lowering the chance that serious
misstatements or other problems would go unnoticed.
(iii) Lower Costs: By automating processes that were previously done manually, technology can assist with
the cost of auditing.
(iv) Better Analytics: Improved analytics capabilities can aid management and auditors in seeing trends
and patterns that may be challenging to spot manually.
(v) Improved Risk Assessment: Creating a number of automations to assist with the audit process and
streamlined testing improves the risk assessment procedure. Management and auditors put their
testing efforts on sites with a higher risk of material misstatement and make informed decisions.
1.4 Consideration and Challenges of Digital Audit
Some considerations that organization should keep in mind while using digital techniques & automation:
4.2 DIGITAL AUDITING AND ASSURANCE-Summary Vol II-CHAPTER 04

Areas of focus could include understanding of the following:


DIGITAL AUDITING AND ASSURANCE

❖ New activities or changes to existing processes due to new technology (e.g., new revenue streams,
changes in the roles and responsibilities of entity personnel, automation of manual tasks, changes in
staffing levels that affect an entity’s internal control environment)
❖ Changes in the way the entity’s systems are developed and maintained and whether these changes
introduce new risks and require new controls to respond to those risks
❖ The impact of the new technology as how the organization obtains or generates and uses relevant,
quality information to support the functioning of internal control.

2. AUDITING DIGITALLY
2.1 What is the concept of auditing digitally?
Auditing Digitally is using advancements in technology for conducting an effective and efficient audit. With
a rapidly growing IT environment it is essential to adapt technology in auditing practices.
It is time to digitize the way an audit is delivered through automation and innovation. There are new
technologies to help capture data, automate procedures, analyse information and focus on the real risks
of the client. The opportunity is in understanding how technology can help and then applying it to the auditing
challenges.
2.2 Key Features or Advantages of Auditing Digitally:
Following are key features or advantages of Auditing Digitally:
(i) Improved Quality of Audits: The impact on quality is evident, through automation, data analytics
techniques, we can easily move from sample auditing to full population of transactions being reviewed
or re-performed
(ii) Decreasing human dependency: Using technology minimizes the manual intervention which ultimately
results in reducing the risk of manual errors. Technology helps in streamlining the process of testing
for auditors which decreases the errors which occur from the judgement of different individuals.
(iii) Increases Transparency: With the technological advancement, transparency has been increased. New
ERPs and tools have audit trail feature available to trace the transaction end to end.
(iv) Automation and Ease: Automating tasks like recording work in repositories, extracting data and
sampling have improved the quality of audit and reduced the manual error. Using dashboards (e.g.,
Power BI) for reporting helps in understanding the position and helps the auditor to form his opinion.
(v) Improved Efficiency: What used to take weeks to learn and programme using deep experts, is now
easily available to auditors after some simple training and digital upskilling. The result may be
increased efficiency and fewer errors, but the benefits are wider reaching and personal. This also
results in improved retention of talent and confidence.
(vi) Better Risk Assessment: With usage of automation and technology in audit, auditor may focus on the
real challenges and assess the potential risk precisely. Dashboards, visual presentations and other
tools helps in understanding where the risk lies and what all areas need more attention.
2.3 Considerations in Auditing Digitally
There are few questions it is important to ask and answer – at all stages of tech journey:
2.3.1 What problems are you trying to solve?
❖ Continuously evaluate the emerging technologies and latest tools to see what can benefit the audit.
Vol II-CHAPTER 04 DIGITAL AUDITING AND ASSURANCE-Summary 4.3

❖ Think about what would make your audit easier or better and how you will measure return on your
investment.

DIGITAL AUDITING AND ASSURANCE


2.3.2 Which technology can help you?
❖ There are a number of tools available and many vendors and start-ups using data acquisition,
manipulation and visualization tools. Consider how comfortably these solutions will integrate into your
current processes and flag any potential implementation issues early on.
2.3.3 How will you upskill your people to make best use of the technology available?
❖ Technology is only as good as the people using it. Training and development are critical to ensure teams
understand how and why they are using the technology. Reluctance to change is obvious, however
continuous training help them to get better.
2.3.4 Range of automated solutions:
❖ There is a range of automation solutions, from low to high sophistication, which helps to standardize
the repeatable tasks and optimize the efforts resulting in doing better. Some of the techniques are
using robotics and automation for data gathering activities, use of data analytics for planning and
budgeting and reporting by dashboards.

3. UNDERSTAND THE IT ENVIRONMENT


3.1 Key Areas for an Auditor to Understand IT Environment
Key Areas for an Auditor to Understand IT Environment are as follows:
1. Understand the flow of transaction: The auditor's understanding of the IT environment may focus
on identifying and understanding the nature and number of the specific IT applications and other
aspects of the IT environment that are relevant to the flows of transactions and processing of
information in the information system
2. Identification of Significant Systems: The auditor may identify the IT applications and supporting
IT infrastructure concurrently with the auditor's understanding of how information relating to
significant classes of transactions, account balances and disclosures flows into, through and out the
entity's information system.
3. Identification of Manual and Automated Controls: An entity's system of internal control contains
manual elements and automated elements. These are relevant to the auditor's identification and
assessment of the risks of material misstatement.
4. Identification of the technologies used : The need to understand the emerging technologies
implemented and the role they play in the entity's information processing or other financial reporting
activities and consider whether there are risks arising from their use.
Some examples of emerging technologies are:
➢ Block chain, including crypto currency businesses (e.g., token issuers, custodial services,
exchanges, miners, investors),Robotics, Artificial Intelligence, Internet of Things, Biometrics,
Drone
5. Assessing the complexity of the IT environment: Not all applications of the IT environment have the
same level of complexity. The level of complexity for individual characteristics differs across
applications.
Complexity is based on the following factors
➢ Automation used in the organization,
➢ Entity’s reliance on system generated reports,
4.4 DIGITAL AUDITING AND ASSURANCE-Summary Vol II-CHAPTER 04

➢ Customization in IT applications,
DIGITAL AUDITING AND ASSURANCE

➢ Business model of the entity,


➢ Any significant changes done during the year and implementation of emerging technologies.

4. IDENTIFYING THE RISKS ARISING FROM USAGE OF IT


4.1 How to identify the IT Risks?
In identifying the risks arising from the use of IT, the auditor may consider
❖ the nature of the identified IT application.
❖ Applicable risks arising from the use of IT may also be identified related to cyber security.
❖ It is more likely that there will be more risks arising from the use of IT when the volume or complexity
of automated application controls is higher, and management is placing greater reliance on those
controls for effective processing of transactions.
4.2 Risks arising from use of IT
❖ Unauthorized access to data that may result in destruction of data or improper changes to data,
including the recording of unauthorized or non-existent transactions, or inaccurate recording of
transactions. Particular risks may arise where multiple users access a common database.
❖ Unauthorized changes to IT applications or other aspects of the IT environment.
❖ Failure to make necessary update to IT applications or other aspects of the IT environment.
❖ Inappropriate manual intervention.
❖ Data loss or data corruption is a major risk which arises from use of IT. If appropriate cyber security
controls and protocols not followed it may lead to loss of sensitive data, hackers might encrypt your
system or illegally break into your system.
4.3 Know how to identify the IT dependencies impacting the Audit?
4.3.1 Why is it important to identify IT dependencies?
❖ Identifying and documenting the entity's IT dependencies in a consistent, clear manner helps to
identify the entity's reliance upon IT
❖ Understand how IT is integrated into the entity's business model,
❖ Identify potential risks arising from the use of IT,
❖ Identify related IT General Controls and enables us to develop an effective and efficient audit
approach.
4.3.2 How IT dependencies arise and types of IT dependencies.
IT Dependencies are created when IT is used to initiate, authorize, record, process, or report
transactions or other financial data for inclusion in financial statements.
There are five types of IT dependencies as described below:
Type Description
Automated Automated controls are designed into the IT environment to enforce business rules.
Controls For example,
Purchase order approval via workflow or format checks (e.g., only a particular date
format is accepted), existence checks (e.g., Duplicate customer number cannot exist),
and/or reasonableness checks (e.g., maximum payment amount) when a transaction is
entered.
Vol II-CHAPTER 04 DIGITAL AUDITING AND ASSURANCE-Summary 4.5

Reports System generated reports are information generated by IT systems. These reports
are often used in an entity's execution of a manual control, including business

DIGITAL AUDITING AND ASSURANCE


performance reviews, or may be the source of entity information used by us when
selecting items for testing, performing substantive tests of details or performing a
substantive analytical procedure. E.g. (Vendor master report, customer ageing
report)
Calculations Calculations are accounting procedures that are performed by an IT system instead
of a person. For example, the system will apply the 'straight-line' depreciation
formula to calculate depreciation of an asset (i.e., cost of the asset, less the residual
value of the asset at the end of its useful life divided by the useful life of the asset)
or the system will calculate the value of the amount invoiced to a customer by
multiplying the item price times the quantity shipped.
Security Security including segregation of duties is enabled by the IT environment to restrict
access to information and to determine the separation of roles and responsibilities
that could allow an employee to perpetrate and conceal errors or fraud, or to process
errors that go undetected.
Interfaces Interfaces are programmed logic that transfer data from one IT system to
another. For example, an interface may be programmed to transfer data from a
payroll sub- ledger to the general ledger.
4.3.3 Understanding and responding to risks arising from IT dependencies
When auditors identify IT dependencies that are relevant to the entity's flow of transactions and processing
of financial information, they need to understand how management responds to the associated risks that may
arise from them.
Management may implement information technology general controls (ITGCs) to address risks related to IT
dependencies.
4.3.4 The illustration below is an overview of the Control Objectives and controls for each area of
General IT Controls:
1. Access Security
Objective: To ensure that access to programs and data is authenticated and authorized to meet
financial reporting objectives.
Activities:
➢ Access requests to the application are properly reviewed and authorized by management
➢ Access of terminated user is removed on a timely basis
➢ Access rights to applications are periodically monitored for appropriateness
➢ Transactions of administrative and sensitive generic IDs are monitored
➢ Security policies and procedures are maintained
➢ Access to operating system and database is restricted.
2. Program Change
Objective:
To ensure modified systems continue to meet financial reporting objectives
Activities:
➢ Change Management policy and procedures are maintained.
4.6 DIGITAL AUDITING AND ASSURANCE-Summary Vol II-CHAPTER 04

➢ Development, testing and production environments are segregated for changes to application
configurations
DIGITAL AUDITING AND ASSURANCE

➢ Changes are adequately tracked and recorded.


➢ Changes to application configurations are adequately tested and approved before being migrated
into production
➢ Emergency changes are approved.
➢ Segregation of duties is maintained between developer and implementor.
3. Data Centre and network operations
Objective : To ensure production systems are appropriately backed up to meet financial reporting
objectives
Activities:
➢ Policies and procedures for data backup and recovery is maintained.
➢ Data is appropriately backed up and recoverable
➢ Restoration testing is performed
➢ Monitoring and compliance of service level agreements.
➢ Batch job scheduled are monitored for failures and access is restricted.

5. ASSESSING CYBER RISKS (INCLUDING REMOTE AUDIT)


5.1 What is Cyber Risk:
A cyber-attack is an attempt to gain unauthorized access to a computing system or network with the
intent to cause damage, steal, expose, alter, disable, or destroy data.
Most common types of cyber- attacks are:
1. Malware: Malware or malicious software is any program or code that is created with the intent to do
harm to a computer, network or server. Malware is the most common type of cyberattack, its subsets
are ransomware, fileless Malware trojans, viruses etc.
Type Description
Ransomware In a ransomware attack, an adversary encrypts a victim’s data and offers to
provide a decryption key in exchange for a payment. Ransomware attacks are
usually launched through malicious links delivered via phishing emails, but
unpatched vulnerabilities and policy misconfigurations are used as well.

Fileless Malware Fileless malware is a type of malicious activity that uses native, legitimate
tools built into a system to execute a cyber-attack. Unlike traditional
malware, fileless malware does not require an attacker to install any code on
a target’s system, making it hard to detect.
Trojan A trojan is malware that appears to be legitimate software disguised as
native operating system programs or harmless files like free downloads.
Trojans are installed through social engineering techniques such as phishing
or bait websites.
Mobile Malware Mobile malware is any type of malware designed to target mobile devices.
Mobile malware is delivered through malicious downloads, operating system
vulnerabilities, phishing, smishing, and the use of unsecured Wi-Fi.
Vol II-CHAPTER 04 DIGITAL AUDITING AND ASSURANCE-Summary 4.7

2. Denial-of Service (DoS) Attacks: A Denial-of-Service (DoS) attack is a malicious, targeted attack
that floods a network with false requests in order to disrupt business operations.

DIGITAL AUDITING AND ASSURANCE


In a DoS attack, users are unable to perform routine and necessary tasks, such as accessing email,
websites, online accounts or other resources that are operated by a compromised computer or network.
While most DoS attacks do not result in lost data and are typically resolved without paying a ransom,
they cost the organization time, money and other resources in order to restore critical business
operations.
3. Phishing: Phishing is a type of cyber attack that uses email, SMS, phone, social media, and social
engineering techniques to entice a victim to share sensitive information — such as passwords or
account numbers — or to download a malicious file that will install viruses on their computer or phone.
Type Description
Spear Phishing Spear-phishing is a type of phishing attack that targets specific individuals
or organizations typically through malicious emails. The goal of spear phishing
is to steal sensitive information such as login credentials or infect the
targets’ device with malware.
Whaling A whaling attack is a type of social engineering attack specifically targeting
senior or C-level executive employees with the purpose of stealing money or
information or gaining access to the person’s computer in order to execute
further cyber attacks.
Smishing Smishing is a type of fraudulent practice of sending text messages
purporting to be from reputable companies in order to induce individuals to
reveal personal information, such as passwords or credit card numbers.

Vishing Vishing, a voice phishing attack, is the fraudulent use of phone calls and
voice messages pretending to be from a reputable organization to convince
individuals to reveal private information such as bank details and passwords.

4. Spoofing: Spoofing is a technique through which a cybercriminal disguises themselves as a known or


trusted source. In so doing, the adversary is able to engage with the target and access their systems
or devices with the ultimate goal of stealing information, extorting money or installing malware or other
harmful software on the device.
Type Description
Domain Spoofing Domain spoofing is a form of phishing where an attacker impersonates a
known business or person with fake website or email domain to fool
people into the trusting them. Typically, the domain appears to be
legitimate at first glance, but a closer look will reveal subtle differences.
Email Spoofing Email spoofing is a type of cyberattack that targets the businesses by
using emails with forged sender addresses. Because the recipient trusts
the alleged sender, they are more likely to open the email and interact with
its contents, such as a malicious link or attachment.
5. Identity-Based Attacks: When a valid user’s credentials have been compromised and an adversary
is pretend to be that user. For e.g., people often use the same user ID and password across multiple
accounts. Therefore, possessing the credentials for one account may be able to grant access to other,
unrelated account.
6. Insider Threats: When current or former employees that pose danger to an organization because
they have direct access to the company network, sensitive data, and intellectual property (IP), as well
4.8 DIGITAL AUDITING AND ASSURANCE-Summary Vol II-CHAPTER 04

as knowledge of business processes, company policies or other information that would help carry out
such an attack.
DIGITAL AUDITING AND ASSURANCE

7. DNS Tunnelling: DNS Tunnelling is a type of cyber attack that leverages domain name system (DNS)
queries and responses to bypass traditional security measures and transmit data and code within the
network. This tunnel gives the hacker a route to unleash malware and/or to extract data, IP or other
sensitive information by encoding it bit by bit in a series of DNS responses.
8. IoT-Based Attacks: An IoT attack is any cyber attack that targets an Internet of Things (IoT)
device or network. Once compromised, the hacker can assume control of the device, steal data, or join
a group of infected devices
5.2 Stages of Cyber Risk:
Following are 3 Stage of cyber risk
1. Stage 1 - Assessing the cyber risk: No organization is completely immune to a cyber risk. Every
organization should consider at least the common threats-
➢ Ransomware disabling their organization (including their plants and manufacturing facilities)
➢ Common criminals using email phishing and hacks for fraud and theft.
➢ Insiders committing malicious activities or accidental activities resulting in unintended discourse
of information theft and frauds.
2. Stage 2 - Impact of cyber risk: Cyber-attack can impact one, two or more types of risks. The impact
of the attack would vary from organization to organization and most importantly from an attack to
attack. Some of the indicative areas can be –
➢ Regulatory costs
➢ Business interruptions causing an operational challenge for an organization.
➢ Data loss, reputational loss and litigation.
➢ Ransomware - more common these days where entire systems are encrypted
➢ Intellectual property theft which may not only take the competitive advantage, but we may also
result in any impairment/impediment charge because of the loss of IP.
➢ Incident response cost which could be for investigations & remediation
➢ Breach of Privacy, if personal data of a consumer is hacked it could have a significant impact on
the organization.
➢ Fines and penalties
3. Stage 3- Managing the cyber risk: A strategic approach to cyber risk management can help an
organization to:
➢ Gain a understanding of the cyber risks, threats facing their organization and other financial
institutions
➢ Assess existing IT and cyber security program and capabilities against the relevant regulatory
requirements
➢ Align cyber security and IT transformation initiatives with strategic objectives and critical
risks
➢ Understand accepted risks & documented compensating controls
Vol II-CHAPTER 04 DIGITAL AUDITING AND ASSURANCE-Summary 4.9

5.3 Cyber Security Framework

DIGITAL AUDITING AND ASSURANCE


Cyber security framework includes how management is identifying the risk, protecting and safeguarding its
assets (including electronic assets) from the risk. Management preparedness to detect the attacks, anomalies
and responsiveness to the adverse event.
5.3.1 Identify the risk:
Auditor has to determine whether the entity's risk assessment process considers cyber security risks.
❖ Entity should conduct a periodic risk assessment & develop a management strategy which identifies
cyber security risks around IT system.
❖ The entity should maintain and periodically reviews an inventory of their information assets- i.e.,
Asset Management (e.g., intellectual property, patents, copyrighted material, trade secrets and other
intangibles).
❖ From the governance perspective, management should review how cyber security risks affect internal
controls over financial reporting. In case of adverse attack how management is going to assess the
impact on the recoverability of financial data and impact on revenue recognition.
❖ To determine overall responsibility for cyber security in the business environment, entity should
establish roles and responsibilities over cyber security (CISO, CIO).
5.3.2 Protect the risk
❖ Obtained an understanding of the entity's processes for safeguarding of assets subject to cyber
security.
❖ Entity monitors whether there has been unauthorized access to electronic assets and any related
impact on financial reporting.
❖ Formal training should be conducted to make the teams aware of the risk associated with cyber-
attacks.
❖ Entity should implement effective controls for data security.
❖ Entity should have a process & procedures in place for identifying material digital/electronic assets on
the balance sheet subject to cyber security risk (e.g., intellectual property, patents, copyrighted
material, trade secrets) and prioritizing their protection based on criticality.
5.3.3 Detect The risk
❖ Entity should have controls and procedures that enable it to identify cyber security risks and
incidents and to assess and analyses their impact on the entity’s business.
❖ Evaluate the significance associated with such risks and incidents, and consider timely disclosures.
5.3.4 Respond to the risk
❖ In case of material cyber security or data breach has been identified management should capture the
details of nature of incident.
❖ Management should assess Litigation costs, Regulatory investigation costs and Remediation costs as
a part of mitigation process and improvement.
❖ Management should assess the future action plans that needs to be taken to safeguard the organisation
from such attacks.
5.3.5 Recover from risk
❖ Once the impact evaluated and communicated with the regulators, the recovery plan needs to be
implemented to overcome the impact.
4.10 DIGITAL AUDITING AND ASSURANCE-Summary Vol II-CHAPTER 04

❖ Necessary improvements – like patch upgrades, better controls, improved technology in terms of
firewall, anti-virus, tools etc. needs to be implemented to safeguard the entity.
DIGITAL AUDITING AND ASSURANCE

5.4 Control considerations for Cyber Risks:


1) Controls around vendor setup and modifications:
Certain cyber schemes exist in which changes to bank account or other critical vendor information are
requested through email phishing scams by individuals purporting to be authorized vendor personnel.
➢ Who is responsible for making changes to vendor master data? Is the process centralized or
decentralized?
➢ Are other communication channels, such as email, used to request changes to vendor master data?
(If yes, consider if multi-factor authentication is enabled for email).
➢ What systems and technologies are used to initiate, authorize and process requests related to
changes to vendor master data?
➢ Are authentication protocols defined to verify modifications to vendor master data (e.g., call
back procedures, multi-factor authentication)?
2) Controls around electronic transfer of funds:
➢ Are personnel responsible for wire transfers educated on the relevant threats and information
related to common phishing scams associated with fraudulent requests for wire transfers?
➢ Are authentication protocols defined to verify wire transfer requests (e.g., call back procedures,
dual-authentication procedures)?
➢ What systems and technologies are used to facilitate the request/initiation, authorization and
release of wire transfers?
3) Controls around patch management:
Cyber and ransomware attacks exploit known security vulnerabilities resulting in the manipulation or
the destruction of data. Exploitations of known security vulnerabilities are often caused by unapplied
patches or upgrades.
➢ Does the entity have a patch management program?
➢ Does the entity run periodic vulnerability scans to identify missing/unapplied patches?
➢ How is the entity notified of patches by external vendors (e.g., Microsoft for Windows patches)?
5.5 Remote Audit
Remote audit or virtual audit is when the auditor uses the online or electronic means to conduct the
audit. It could be partially or completely virtual, auditor engages using technology to obtain the audit
evidence or to perform documentation review with the participation of the auditee.
The COVID-19 pandemic has changed the entire business landscape and processes have been adjusted to this
new situation, where remote audit is appreciated by clients as well.
5.5.1 Considerations for remote audit:
Auditors must develop tailored strategies to ensure the remote audit meets the requirements and deliver
results equivalent to traditional onsite audits.
1. Feasibility and Planning
➢ Planning should involve agreeing on audit timelines, meeting platform (Zoom calls/ Microsoft
Teams/Google Meet) to be used for audit sessions, data exchange mechanisms, any access
authorization requests.
Vol II-CHAPTER 04 DIGITAL AUDITING AND ASSURANCE-Summary 4.11

➢ Ensure feasibility is determining what technology may be used, if auditors and auditees have
competencies and that resources are available.

DIGITAL AUDITING AND ASSURANCE


➢ The execution phases of a remote audit involve video/tele conferencing with auditees.
➢ The documentation for audit evidence should be transferred through a document sharing
platform.
2. Confidentiality, Security and Data Protection
➢ To ensure data security and confidentiality, access to document sharing platform should be
sufficiently restricted and secured by encrypting the data that is sent across the network.
➢ The information, once reviewed and documented by auditor, is removed from the platform, and
stored according to applicable archiving standards and data protection requirements.
➢ Consider legislation and regulations, which may require additional agreements from both sides
(e.g., there will be no recording of sound and images, or authorizations to using people’s images).
➢ Auditors should not take screenshots of auditees as audit evidence. Any screenshots of
documents or records or other kind of evidence should be previously authorized by the audited
organization.
➢ In case of accessing the auditee’s IT system auditor should use VPN (Virtual private
network). VPN is a service which creates safe and encrypted online connection. It prevents
unauthorized users to enter into network and allows the users to perform work remotely.
3. Risk assessment
The assessment if remote audit would be sufficient to achieve the audit objectives should be done and
documented for each audit involving all members of the audit team and the audited organization
representative.
5.5.2 Advantages and Disadvantages of remote audit:
ADVANTAGES DISADVANTAGES
Cost and time effective: No travel time and Due to network issues, interviews and meetings can
travel costs involved. be interrupted.
Comfort and flexibility to the audit team as they Limited or no ability to visualize facility, culture of
would be working from home environment, the organization, and the body language of the
auditees. Time zone issues could also affect the
efficiency of remote audit session
Time required to gather evidence can spread over The opportunity to present doctored documents and
several weeks, instead of concentrated into a to omit relevant information is increased. This may
small period that takes personnel from their daily call for additional planning, some additional/different
activities. audit procedures, security and confidentiality
violation.
Auditor can get first-hand evidence directly Remote access to sensitive IT systems may not be
from the IT system as direct access may be allowed. Security aspects related to remote access
provided. and privacy needs to be assessed
Widens the selection of auditors from global Cultural challenges for the auditor. Lack of
network of experts. knowledge for local laws and regulations could impact
audit. Audit procedures like physical verification of
assets and stock taking cannot be performed.

6. EMERGING TECHNOLOGIES IN AUDIT


4.12 DIGITAL AUDITING AND ASSURANCE-Summary Vol II-CHAPTER 04

Data Analytic Techniques


DIGITAL AUDITING AND ASSURANCE

❖ Generating and preparing meaningful information from raw system data using processes, tools, and
techniques is known as Data Analytics.
❖ It involves analyzing large sets of data to find actionable insights, trends, draw conclusions and for
informed decision making.
❖ It allows auditors to more effectively audit the large amounts of data held and processed in IT systems
in larger clients.
Audit analytics helps:
❖ To discover and analyze patterns
❖ Identifying anomalies
❖ Extract other useful information in data
The data analytics methods used in an audit are known as Computer Assisted Auditing Techniques or CAATs.
Some of the popular tools used across the industry as part of CAATs are listed below:
1. ACL - Audit Command Language (ACL) Analytics is a data extraction and analysis software used for
fraud detection and prevention, and risk management. It samples large data sets to find irregularities
or patterns in transactions that could indicate control weaknesses or fraud. Example –It is used to
analyze and check complete data sets to perform Trial Balance reconciliations during the Audits. In
such case scenarios, the entity provided the General Ledger dump and system Trial Balance.
2. Alteryx - Alteryx is used to consolidate financial or operational data to assess controls.
➢ A fully transparent audit trail of every action is performed in Alteryx in form of a workflow
which makes it easier for the user to learn as no prior knowledge of coding or scripting is required.
➢ Alteryx can also be leveraged to automate analytics and perform Machine Learning to search
for patterns indicative of fraud or irregularities speed up your processes like accounting close,
tax filings, regulatory reporting, forecast creation etc.
➢ It can also be used to automate set procedures that are performed periodically like
reconciliations, consolidations, marketing workflows, system integrations, continuous audits etc.
Example-
➢ Alteryx used for logistics organization to recompute the revenue entries recorded by the system
to match with the financials that showcased the expected revenue turnover.
➢ Due to Alteryx’s processing speed and ease to implement functions, auditors could perform re-
computation for all the transactions entry and noted that the revenue was being understated as
the expected revenue was more than the actual calculated.
3. Power Bi is a business intelligence (BI) platform that provides non-technical business users with tools
for aggregating, analyzing, visualizing and sharing data. From audit perspective, such visualization
tools can be used to find the outliers in the population, it can also be used for reporting purpose
(audit reports) to the higher management.
Example-
Power BI dashboard used for checking the outliers of the apparel company. Auditors were required
to analyse the trends of the sales during the year. By the use of Power BI, the sales data provided by
the client was further converted into dashboard to analyse the trends and patterns as per the market
standards.
Vol II-CHAPTER 04 DIGITAL AUDITING AND ASSURANCE-Summary 4.13

4. CaseWare – CaseWare is a data analysis software & provide tools that helps in conducting audit and
assurance engagements quickly, accurately and consistently.

DIGITAL AUDITING AND ASSURANCE


➢ It shares analytical insights which help in taking better informed decisions.
➢ It helps in streamlining processes and eliminating the routine tasks.
➢ Used by accounting firms, governments and corporations worldwide, this trusted platform
integrates everything you need to conduct assurance and reporting engagements.
Example- It provides the solutions to build accounting software which turns any document, including
financial statements into cost effective client ready report.
It automatically links to client data and securely communicate with the client in real time. Regardless
of location, all authorized users have access to the same documents. Consistency of data is ensured.

7. AUTOMATED TOOLS IN AUDIT

7.1 Internet of Things


❖ IoT is the concept of connecting any device (cell phones, coffee makers, washing machines, and so on)
to the internet.
❖ Key components of IoT are data collection, analytics, connectivity, and people and process.
❖ IoT not only changes the business model, but also affects the strategic objectives of the organization.
❖ The risk profile of the entity changes with exposure to new laws and regulations.
Audit Implications
❖ A shift to connected devices and systems may result in auditors not being able to rely only on manual
controls. Instead, auditors may need to scope new systems into their audit.
❖ Audit firms may need to train and upskill auditors to evaluate the design and operating effectiveness
of automated controls.
❖ Consumer-facing tools that connect to business environments in new ways can impact the flow of
transactions and introduce new risks for management and auditors to consider. Example- Consider
payment processing tools that allow users to pay via credit card at a retail location through a mobile
device.
❖ Auditors would need to consider the volume of those transactions and the processes and controls
related to it.
Common risks of IoT:
The key risks associated with IoT, including, device hijacking, data siphoning, denial of service attacks,
data breaches and device theft.
7.2 AI (Artificial intelligence)
Artificial intelligence (AI) refers to a system or a machine that can think and learn. AI systems utilize
data analysis and algorithms to make decisions based on predictive methods. Complex algorithms are
developed to propose decisions based on a pattern or behavior learned over time.
Examples-
❖ Self-driving cars, manufacturing robots, smart assistants, marketing chatbots, virtual travel booking
agent.
4.14 DIGITAL AUDITING AND ASSURANCE-Summary Vol II-CHAPTER 04

❖ The self-deploying robots can determine how much vacuuming there is to do based on a room’s size,
uses AI to scan room size, identify obstacles and remember the most efficient routes for cleaning.
DIGITAL AUDITING AND ASSURANCE

Audit Implications
❖ Focus on logical flow- Given the invisible nature of algorithms, audits must focus on the logical flow
of processes.
❖ Algorithms. - A review of AI should ascertain whether unintended bias has been added to the
algorithms. Auditors should assess the effectiveness of algorithms and whether their output is
appropriately reviewed and approved.
❖ Bugs and vulnerabilities - Because AI is built on software modules, auditors must also consider cyber
security and search for possible bugs and vulnerabilities that can be exploited to impact AI
functionality.
❖ Effect of AI- Auditors should confirm their understanding of how the use of AI affects the entity’s
flows of transactions, including the generation of reports or analytics used by management.
❖ Decision Making - Auditors also should consider whether the AI is making decisions—or being utilized
by management as part of the decision-making process.
Common risks for AI
❖ Security is one of the key risks – the more data the system uses, from more sources, the more entry
points and connections are formed and the greater the potential risks.
❖ Inappropriate configuration - AI may also be used to diagnose medical conditions. If it is badly
configured or malfunctions, it could harm people before the problem is spotted.
❖ Data privacy - The data used and shared should have the necessary explicit consent from data
providers.
7.3 Block chain
❖ Block chain is based on a decentralized and distributed ledger that is secured through encryption.
❖ Each transaction is validated by the block chain participants, creating a block of information that is
replicated and distributed to all participants.
❖ All blocks are sequenced so that any modification or deletion of a block disqualifies the information.
❖ Example- Bitcoin, crypto currency transfer application - Block chain in money transfer, block chain
smart contracts
Audit Implications
❖ Auditors should consider the appropriate governance and security transactions around the
transactions.
❖ As block chain interacts with legacy systems and business partners, concerns related to insecure
application programming interfaces (APIs), data confidentiality and privacy cannot be ignored.
❖ Weak block chain application development protocols are something auditors cannot overlook. Similarly,
data privacy laws and regulations may be area of concern as data are communicated across geographic
boundaries.
❖ Auditors must be able to determine whether the data put on block chain will expose the enterprise to
liability for noncompliance with applicable laws and regulations.
Common risks for block chain technology
The strengths of block chain can also be its weaknesses.
Vol II-CHAPTER 04 DIGITAL AUDITING AND ASSURANCE-Summary 4.15

❖ The inability to reverse transactions and to access data without the required keys make the system
secure, but also mean that organisations need specific protocols and management processes to ensure

DIGITAL AUDITING AND ASSURANCE


that they are not locked out and have clear contingency plans.
❖ Operating through network nodes could also expose the organisation to cyber-attacks and data hacks,
so security issues are important.
❖ Auditors should also ensure that the organisation has the necessary data management processes and
complies with regulations. The regulatory landscape is still evolving for block chain, so audit teams
should check that compliance managers are following developments constantly and adapting processes
accordingly.
7.3.1 NFT (Non-Fungible Token)
❖ NFT means something is unique and cannot be replaced.
❖ Physical money and crypto currencies are fungible (means they can be traded or exchanged for one
another) NFTs are non-fungible tokens. NFTs contains the digital signature which make them unique.
NFTs are digital assets, e.g., photos, videos, artwork, sports collectibles etc.
❖ NFTs are tokens used to represent ownership of unique items. NFTs allow their creators to tokenize
things like art, collectibles, or even real estate.
❖ They are secured by the block chain and can only have one official owner at a time. No one can
change the record of ownership or copy/paste a new NFT into existence.
Key Features of NFT-
❖ Digital Asset - NFT is a digital asset that represents Internet collectibles like art, music, and games
with an authentic certificate created by block chain technology that underlies Crypto currency.
❖ Unique - It cannot be forged or otherwise manipulated.
❖ Exchange - NFT exchanges take place with crypto currencies such as Bitcoin on specialist sites.
Challenges of NFT–
❖ NFTs has its own challenges like ownership and copyright concerns, security risks, market is not
that wide, online frauds etc.
❖ NFT audit considerations includes comprehensive code review for verifying the safety of a token,
valid contract, data privacy and potential cyber threat.
7.4 Robotic Process Automation
❖ RPA is the automation of the repetitive processes performed by users.
❖ It is a software technology that emulate humans’ actions interacting with digital systems and software.
❖ Process efficiency, customer experience and control effectiveness contributed to RPA.
❖ Robotic Process Automation software bots can interact with any application or system the same way
people do—except that RPA bots can operate around the clock, nonstop, much faster and with 100%
reliability and precision.
Audit Implications:
❖ It is of utmost importance for auditors to understand RPA processes, which include data extraction,
aggregation, sanitization and cleansing. Unless auditors understand these processes, they will not be in
a position to initiate an audit.
❖ A comprehensive assurance process might demand review of the source code.
4.16 DIGITAL AUDITING AND ASSURANCE-Summary Vol II-CHAPTER 04

❖ To perform substantive testing, auditors must have an understanding of the tools used to develop and
maintain RPA.
DIGITAL AUDITING AND ASSURANCE

❖ This will be helpful when auditors review logs, configuration controls, privileged access controls and the
like. General IT controls are applicable as always.
Common Risks of RPA:
i. Operational and execution risks
➢ Robots are deployed without proper operating model.
➢ Buying the wrong tool, making wrong assumptions, taking shortcuts, and jeopardizing security and
compliance.
➢ Assigning proper responsibilities, training and clearly stating about changing roles also can help
you reduce operational risk to a great extent.
ii. Change management risks: Not following the change management implementation lifecycle, improper
and incomplete testing (not covering all scenarios) leads to inaccurate results.
iii. RPA Strategy Risk: Setting wrong expectations, improper KPIs, and unrealistic business goals
creates an environment of uncertainty. Management should discuss, and analyse the complete working
characteristics, potential, and limitations of RPA before drafting a RPA.

8. CONTROL CONSIDERATIONS OR OBJECTIVES OF AUDITING DIGITALLY


Emerging technologies can bring great benefits, but they also come with a varied set of substantial risks.
The strength of the auditing profession is the assessment of risks and controls. As they address the
challenge of assessing technology risk, auditors can and should focus on the following control
considerations:
1. Auditors should gain a holistic understanding of changes in the industry and the information
technology environment to effectively evaluate management’s process for initiating, processing, and
recording transactions and then design appropriate auditing procedures.
2. Auditors should consider risks resulting from the implementation of new technologies and how those
risks may differ from those that arise from more traditional, legacy systems.
3. Auditors should consider whether digital upskilling or specialists are necessary to determine the
impact of new technologies and to assist in the risk assessment and understanding of the design,
implementation, and operating effectiveness of controls. E.g., cybersecurity control experts, IT
specialists in the team etc.
8.1 Some examples of technology risks where auditors should test the appropriate controls for relying
on the digital systems
❖ Reliance on systems or programs that are inaccurately processing data, processing inaccurate data,
or both
❖ Unauthorized access to data that might result in destruction of data or improper changes to data,
including the recording of unauthorized or non-existent transactions or inaccurate recording of
transactions (specific risks might arise when multiple users access a common database)
❖ The possibility of information technology personnel gaining access privileges beyond those necessary
to perform their assigned duties, thereby leading to insufficient segregation of duties
❖ Unauthorized or erroneous changes to data in master files
❖ Unauthorized changes to systems or programs
Vol II-CHAPTER 04 DIGITAL AUDITING AND ASSURANCE-Summary 4.17

❖ Failure to make necessary or appropriate changes to systems or programs

DIGITAL AUDITING AND ASSURANCE


❖ Inappropriate manual intervention
❖ Potential loss of data or inability to access data as required
❖ Risks introduced when using third-party service providers
❖ Cyber security risks
8.2 Key Steps for Auditors in a Changing Technology Environment
As auditors obtain an understanding of the impact of technology on a company’s business, its systems of
internal control, and its financial reporting, some important reminders include the following:
❖ Maintain sufficient professional skepticism when reviewing management’s risk assessment for new
systems.
❖ Understand the direct and indirect effects of new technology and determine how its use by the
entity impacts the auditor’s overall risk assessment.
❖ Understand how the technologies impact the flow of transactions, assess the completeness of the
in-scope ICFR systems, and design a sufficient and appropriate audit response.
❖ Assess the appropriateness of management’s processes to select, develop, operate, and maintain
controls related to the organization’s technology based on the extent the technology is used.

9. NEXT GENERATION AUDIT


The Next Generation Audit is human-led, tech-powered and data-driven. It is based on combining emerging
technologies to redefine how audits are performed.
Next Generation Audit aims to the following:

9.1 Some of the most rapidly advancing areas, with many implications for society are -
1. Drone Technology: Using drone technology in the remote locations for stock counts. Drones have great
payload capacity for carrying sensors and cameras, thus they can photograph and physically examine
the count of large quantities of fixed assets and inventory.
Drone captured audit information can be combined with various alternative sources of information
such as QR code readers, handheld bar scanners, manual counts etc.
2. Augmented reality: The technology allows users to view the real-world environment with augmented
(added) elements, generated by digital devices.
4.18 DIGITAL AUDITING AND ASSURANCE-Summary Vol II-CHAPTER 04

One famous example was Pokémon Go, a game for mobile devices in which players chase imaginary digital
creatures (visible on their mobile phones) around physical locations.
DIGITAL AUDITING AND ASSURANCE

3. Virtual reality: VR goes a step forward and replaces the real world entirely with a simulated
environment, created through digitally generated images, sounds, and even touch and smell. Using
special equipment, such as a custom headset, the user can explore a simulated world or simulate
experiences such as flying or skydiving.
4. Metaverse: The metaverse is the emerging 3-D digital space that uses virtual reality, augmented
reality, and other advanced internet technology to allow people to have lifelike personal and business
experiences online. It represents a convergence of digital technology to combine and extend the reach
and use of Cryptocurrency, Artificial Intelligence (AI), Augmented Reality (AR) and Virtual Reality
(VR).
9.2 Case scenarios to illustrate the potential application of the metaverse in the financial domain
❖ Virtual Banking and Transactions: A forward-thinking financial institution, establishes a presence in
the metaverse to offer virtual banking services. Users can create virtual bank accounts, access
personalized financial dashboards, and perform transactions using virtual currencies.
❖ Digital Asset Management: A digital asset management company, recognizes the growing popularity of
virtual assets in the metaverse. They launch a virtual asset trading platform within the metaverse,
allowing users to buy, sell, and trade NFTs and other digital assets.
❖ Virtual Financial Education and Training: A Financial Learning Academy aims to enhance financial
literacy using the metaverse. They create a virtual classroom environment where participants can
attend interactive financial education sessions.
❖ Virtual Meetings and Conferences: For a leading industry even, an organisation hosts a virtual
conference within the metaverse. Participants from around the world can access the conference
through their virtual avatars.
❖ Data Visualization and Analytics: A company utilizes the metaverse to offer advanced data
visualization and analytics tools to financial professionals. Their virtual analytics platform allows users
to visualize complex financial data in interactive and immersive 3D environments.
Common Risks associated:
❖ Beyond their potential, these technologies also come with challenges such as public safety,
cybersecurity, data privacy, data protection, lack of standards and technical challenges.
❖ Since they often track movements and data, massive amounts of data are generated about the
whereabouts of users. It also raises questions about taxation, jurisdiction, and customer protection.
❖ Regulators and auditors have to think of the controls around privacy, data security, governance to
make it more regulated.

You might also like