Systems Audit Policy
1. Objectives of Systems Audit
The objective of periodical system audit is to confirm the effectiveness of our system risk
management activities and compliance with applicable laws and regulations.
2. Responsibility and Authority
The designated auditor shall have necessary authority to require all the departments to submit
materials, to explain the facts or to report matters necessary for conducting the audit. The
audited department must not refuse the request with no legitimate reason.
3. Scope of Systems Audit
The scope of this policy includes all personnel who have access to any [company name]
facility, [company name] network, or any non-public [company name] information.
4. Planning Systems Audit
The Internal Audit Division must prepare the systems audit plan and submit to the CEO and
CCO for approval.
5. Performing Systems Audit
Prior to the beginning of the systems audit, manager of the audited business unit must be
notified about the schedule and the focused areas of the systems audit
Audit is conducted by inquiry, document inspection, observation, or a combination of the
above.
The Internal Audit Division must create working papers that include the result of the audit,
supporting evidences and related materials.
The Internal Audit Division must have discussions with the audited department to explain the
results of the audit and to agree on the identified issues.
6. Report to Management
After the systems audit, manager of the Internal Audit Division must promptly create the
audit report and submit it to the CEO and CCO.
Upon the approval of the audit report by the CEO and CCO, manager of the Internal Audit
Division notifies the results of the audit to the manager of the audited department.
The CEO must direct the manager of the audited department to address the identified issues
in a timely manner.
The Internal Audit Division must evaluate the status of the remediation and report to the CEO
and CCO.
7. Review Process
We will review this policy at least annually.
1
Systems Audit Policy
8. Revision History
Date of Change Responsible Summary of Change
xxx xxx xxx
9. Revision Approval History
Date of Approval Approved By Approval Artifacts
10. Approved Exceptions
Date of Approval Approved By Description of Exception & Artifacts
none