12/1/2023
How Information Technologies
Chapter 5 Enhance Internal Control
Computer controls replace manual controls
The Impact of Information Higher-quality information is available
Technology on the Audit
Process
Assessing Risks of
Risks to Hardware and Data
Information Technologies
Risks to hardware and data Reliance on the functioning capabilities
of hardware and software
Reduced audit trail
Systematic versus random errors
Need for IT experience and
separation of IT duties Unauthorized access
Loss of data
3 4
Need for IT Experience and
Reduced Audit Trail
Separation of Duties
Visibility of audit trail Reduced separation of duties
Reduced human involvement Need for IT experience
Lack of traditional authorization
5 6
1
12/1/2023
Internal Controls Specific to Relationship Between General
Information Technology and Application Controls
General controls Risk of unauthorized change
to application software Risk of system crash
• apply to all aspects of the IT function,
Application controls Cash receipts
application
• typically operate at the business process controls
level and apply to processing transactions Sales Payroll
application application
controls controls
Other cycle
application
controls
Risk of unauthorized GENERAL CONTROLS Risk of unauthorized
master file update processing
7 8
General Controls Administration of the IT Function
Administration of the IT function The perceived importance of IT within an
organization is often dictated by the attitude of
Separation of IT duties the board of directors and senior management.
Systems development
Physical and online security
Backup and contingency planning
Hardware controls
9 10
Segregation of IT Duties Systems Development
Chief Information Officer or IT Manager Typical test
strategies
Security Administrator
Pilot testing Parallel testing
Systems Data
Operations
Development Control
11 12
2
12/1/2023
Backup and Contingency
Physical and Online Security
Planning
Physical Controls: Online Controls: One key to a backup and contingency plan
Keypad entrances User ID control is to make sure that all critical copies of
Badge-entry systems Password control software and data files are backed up
Security cameras Separate add-on and stored off the premises.
Security personnel security software
13 14
Hardware Controls Application Controls
These controls are built into computer Input controls
equipment by the manufacturer to
detect and report equipment failures. Processing controls
Output controls
15 16
Input Controls Batch Input Controls
These controls are designed by an Financial total
organization to ensure that the
information being processed is Hash total
authorized, accurate, and complete.
Record count
17 18
3
12/1/2023
Processing Controls Output Controls
Validation test These controls focus on detecting errors
after processing is completed rather
Sequence test than on preventing errors.
Arithmetic accuracy test
Data reasonableness test
Completeness test
19 20
Impact of Information Technology
on the Audit Process
Effects of General Controls on System-
Effects of general controls on control risk wide Applications
Effects of IT controls on control risk and • Ineffective general controls create the
substantive tests potential for material misstatements across all
system applications, regardless of the quality of
Auditing in less complex IT environments individual application controls.
Auditing in more complex IT environments Relating IT Controls to Transaction-
Related Audit Objectives
• Auditors do not normally link controls and
deficiencies in general controls to specific
transaction related audit objectives.
21 22
Test Data Approach Test Data Approach
1. Test data should include all relevant Input test
transactions to test
conditions that the auditor wants tested. key control
procedures
2. Application programs tested by the
auditors’ test data must be the same as Application programs Transaction files
those the client used throughout the year. Master files (assume batch system) (contaminated?)
3. Test data must be eliminated from the
client’s records. Control test
Contaminated results
master files
23 24
4
12/1/2023
Test Data Approach Parallel Simulation
Control test The auditor uses auditor-controlled software
results
to perform parallel operations to the client’s
software by using the same data files.
Auditor-predicted results
Auditor makes of key control procedures
comparisons based on an understanding
of internal control
Differences between
actual outcome and
predicted result
25 26
Parallel Simulation Embedded Audit Module
Approach
Production Master
transactions file Auditor inserts an audit module in the
client’s application system to identify
Auditor-prepared Client application specific types of transactions.
program system programs
Auditor Client
results results
Auditor makes comparisons between Exception report
client’s application system output and noting differences
the auditor-prepared program output
27 28
Issues for Different IT
Environments
Issues for network environments
Issues for database management systems End of Chapter 5
Issues for e-commerce systems
Issues when clients outsource IT
29