Module 2: Auditing IT
Governance Controls
Detailed Review of IT
Governance Structures, Controls,
Risks, Audit Objectives, and
Disaster Recovery Planning
Engage: Discussion
Questions
1. How does IT governance support reliable
financial reporting and compliance?
2. What risks arise when IT functions are
poorly structured or inadequately
controlled?
3. Why is segregation of duties more complex
in an IT environment than in manual
systems?
4. How can failures in disaster recovery
planning threaten organizational survival?
5. What additional audit risks arise when IT
services are outsourced?
Learning Objectives
Understand risks associated with
incompatible IT functions and
improper IT structure
Identify controls required to protect
computer facilities and IT resources
Explain the key elements and purpose
of a disaster recovery plan (DRP)
Recognize benefits, risks, and audit
issues related to IT outsourcing
Introduction to IT
Governance
IT governance is a subset of
corporate governance focused on
managing IT resources
Ensures IT investments support
organizational strategy and
objectives
Aims to reduce IT-related risk while
maximizing business value
IT Governance and Regulatory
Oversight
Sarbanes-Oxley (SOX) increased
accountability for IT-related
controls
IT systems directly impact
financial reporting accuracy
Boards, executives, and users must
participate in IT governance
decisions
Purpose of IT Governance
Controls
Provide structure for decision-
making related to IT investments
Ensure compliance with laws,
regulations, and internal policies
Support reliability, security, and
availability of information systems
Key IT Governance Areas
Addressed by Auditors
Organizational structure of the IT
function
Computer center operations and
physical security
Disaster recovery planning
Structure of the IT Function
Defines how IT responsibilities and
authority are assigned
Directly affects segregation of
duties and control effectiveness
Common models include
centralized, distributed, and hybrid
structures
Centralized Data
Processing Model
All data processing activities occur
at a central computer facility
IT resources are shared across the
organization
IT function typically operates as a
cost center
Advantages of Centralized
Processing
Improved control over data and
systems
Standardized hardware, software,
and procedures
Economies of scale and simplified
security management
Database Administration
(DBA)
DBA manages centralized
organizational databases
Responsible for data integrity,
security, and access permissions
Function must be independent
from programming and operations
Data Processing Function
Handles routine transaction
processing activities
Includes data conversion,
computer operations, and data
library
Operates systems according to
predefined procedures
Data Conversion
The data conversion function transcribes
transaction data from hard-copy source
documents into computer input.
For example, data conversion could
involve keystroking sales orders into a
sale order application in modern systems,
or transcribing data into magnetic media
(tape or disk) suitable for computer
processing in legacy type systems.
Computer Operations
The electronic files produced in data
conversion are later processed by the
central computer, which is managed
by the computer operations groups.
Accounting applications are usually
executed according to a strict
schedule that is controlled by the
central computer’s operating system.
Data Library Function
Provides secure storage for
backup and operational data files
Controls access to sensitive data
and software
Maintains custody of original
software and licenses
Systems Development
Function
Responsible for analyzing user
needs and designing new systems
Involves systems analysts,
programmers, users, and
stakeholders
Produces applications that support
business processes
Systems Maintenance
Function
Updates and modifies systems
after implementation
Accounts for the majority of a
system’s lifetime cost
Requires thorough documentation
and controlled access
Importance of Segregation of
IT Duties
Prevents individuals from
controlling all phases of a
transaction
Reduces opportunities for fraud
and unauthorized changes
Critical internal control principle in
IT environments
Separating Development from
Operations
Programmers should not run or
operate systems
Operators should not modify or
design applications
Prevents unauthorized changes
during program execution
Separating DBA from Other IT
Functions
DBA controls database access and
structure
Independence prevents data
manipulation or concealment
Supports data accuracy and
system security
Separating Development from
Maintenance
Original developers should not
maintain their own programs
Improves documentation quality
Reduces risk of concealed program
fraud
Program Fraud Risks
Fraudulent code may be embedded
within legitimate programs
Original programmers may conceal
unauthorized logic
Difficult to detect without strong
access and review controls
Distributed Data
Processing (DDP)
IT resources are distributed to end-
user departments
End users control their own
computing environments
Central IT function may be reduced
or eliminated
Advantages of DDP
Reduced hardware and processing
costs
Improved responsiveness to user
needs
Greater flexibility in backup and
recovery options
Risks Associated with DDP
Inefficient use of IT resources
Increased difficulty maintaining
audit trails
Inadequate segregation of duties
in small units
Controlling the DDP
Environment
Implement a small corporate IT
oversight function
Establish organization-wide
standards and policies
Provide technical guidance and
support to users
The Computer Center
Central location for critical IT
infrastructure
Directly affects system availability
and data integrity
Major focus area for auditors
Physical Location and
Construction Controls
Facility should avoid flood zones
and hazard-prone areas
Fire-resistant construction and
secure utilities required
Windows sealed and proper
drainage provided
Access and Environmental
Controls
Restricted access using locks,
cards, or biometrics
Temperature and humidity
maintained within safe ranges
Continuous monitoring of
environmental conditions
Fire Suppression and Fault
Tolerance
Automatic detection and
appropriate fire suppression
systems
RAID and redundant components
reduce system failure risk
Backup power ensures controlled
shutdowns
Audit Objectives and
Procedures
Evaluate adequacy of physical and
environmental controls
Verify insurance coverage for IT
assets
Test access controls, fire systems,
and backup power
Audit Procedures
Audit Procedures
Audit Procedures
Disaster Recovery Planning
(DRP)
Formal plan for responding to
catastrophic events
Focuses on restoring critical
systems quickly
Essential for organizational survival
Key Elements of a Disaster
Recovery Plan
Identification of critical
applications
Creation of a disaster recovery
team
Second-site backup and off-site
storage procedures
Identifying Critical
Applications
Applications essential to short-
term survival
Typically support cash flow and
legal obligations
Must be reviewed and updated
regularly
Conclusion and Audit
Implications
Strong IT governance supports
reliable financial reporting
Auditors assess structure, controls,
and recovery planning
Effective governance reduces risk
and supports compliance