0 ratings0% found this document useful (0 votes) 6 views26 pagesChapter 2
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content,
claim it here.
Available Formats
Download as PDF or read online on Scribd
CHAPTER 2 Conducting an Information Systems Audit 33
Chapter Key Points
1 Usually, auditors cannot examine and evaluate all the data
processing carried out within an organization: They need
guidelines that will direct them toward those aspects of the
information systems function in which material losses or
account misstatements are most likely to occur.
Because ultimately auditors must evaluate the reliability of
controls, they need to understand the nature of controls. A
control isa system that prevents, detects, or corrects unlawful
‘events. Itis a system because all components of the control must
be in place and working for the control to function reliably.
1 Controls reduce expected losses from unlawful events by
(a) decreasing the probability of the event occurring in the first
place, or (b) limiting the losses that arise if the event occurs.
BH Auditors deal with complexity in an information systems audit
by dividing systems to be evaluated into subsystems, evaluating
the reliability of controls in each subsystem, and then
determining the implications of each subsystem’ level of
reliability for the overall reliability of the system. The objective
of factoring is to identify a set of subsystems that can be easily
understood and evaluated because they are loosely coupled
with other subsystems and internally cohesive in the sense that
they perform a single function.
I Two major sets of systems need to be factored asa basis for
‘conducting an information systems audit: Management systems
provide the stable infrastructure in which information systems
ccan be built and operated on a day-to-day basis, and application
systems undertake basic transaction processing, management
reporting, and decision support.
1 Management systems can be factored into subsystems that
perform top-level information systems management, systems
development management, programming management, data
‘administration, quality assurance, security administration, and
operations management. Application systems can be factored
{into subsystems that perform boundary, input, communication,
nig, database, and output functions. An information
systems audit involves evaluating the reliability of controls in
Each of these management and application subsystems.
1 Doring an information systems aucit, there is some risk that the
audit procedures will fail to detect material losses or account
misstatements when they exist. This risk isa function of three
factors: (a) inherent risk, which reflects the likelihood that a
‘material loss or account misstatement exists in some segment of
the audit before the reliability of internal controls is considered;
(6) control risk, which reflcts the likelihood that internal
‘controls in some segment of the audit will not prevent, detect,
for correct material losses or account misstatements that arise;
‘and (c) detection risk, which reflects that the audit procedures,
tused in some segments of the audit will ail to detect material
losses or account misstatements. Because auditors cannot
influence inherent risk or control risk, they adjust the nature§ 34 PART! Introduction
audit procedures they Carry out to ing,
INTRODUCTION
and extent Of 201 he overall level of audit risk “Se
detection tag cae types of audit procedures t0 ofa;
. oa eats ae nded, data integrity is main) Yea,
on whether 20° ertective and efient: (2) procedures, 8
and system of controls, (b) tests Of controls, (c) sy stat a
js of transactions, (4) substantive tests of gq, tive
ee fe results, and (e) analytical review rts
balance ve major steps in an audit: (a) planning
There pudtorafempts t gain an undersiancing of
wei trls used within an organization, (b) ests oy
sas sawhich the auditor tests significant controls to gy.
Cpether Bey are operating effectively: (c) tests of transactign”
siete anitor undertakes Substantive tests 10 evaluate
Sark fnateral loss or account misstatement has oo,
pnt occur (d) fess balances or overall results, in
i secks to obtain sufficient evidence to make
dgment onthe extent of 1sses OF COUNT MSs
have occurred or might occur, and (e) completion of the audit ig
wich the auditor gives an opinion on whether material losses
fecount misstatements have occurred or might occur.
5 During the tess of controls phase, one ofthe important de
that auditors make is whether to test controls by auditin
or through the computer. They might audit around the compute,
ifthe application system is simple, its inherent risk is low, and the
reliability ofthe system's intemal processing can be easily
inferred. They must audit through the computer whenever an
application's inherent risk is high and itis difficult to infer the
internal processing carried out by the system.
sions
round
Itis a sobering experience to be in charge of the information systems aacit
an organization that has several hundred programmers and analysts, mx
computers, and thousands of files. Obviously, all organizations are not this sz
Except for the smallest organizations, however, auditors usually cannot re
form a detailed check of all the data processing carried out within the informs
tion systems function. Instead, they must rely on a sample of data to determin:
pric objectives of information systems auditing are being achieved.
then, can re Baa information systems audits so that we ob
TesSonable assurance that an organization safeguards its data-processing &S**
Iainiais data integrity, and achieves system effectiveness and eticien©! ©
hares this question, this chapter provides an overview of a general Os
that e
muchot tna ¢8 {9 conduct an information systems audit, This m3!
Temainder of the book. wes
discussing some te
yen, maki
ood
‘encountered wh:
n systems. Next We
‘affect the overall PP’| a_i et
CHAPTER 2 Conducting an information Systems Audit 35 .
to an audit, and the types of audit procedures used to
of these risks. We then consider the basic steps to be undertabern
ofan information systems audi. Finally, we examine eae ne ond
must make when planning and conducting an information systems audit.
namely, how much do they need to know about the internal workings of a com. |
puter-based information system before an effective audit can be contacted?
‘assess or control the level
THE NATURE OF CONTROLS
Information systems auditors ultimately are concerned with i
f yster 7 evaluating the reli
we understand what is meant by a control. Here, then, is the definition we shall
adopt for the purposes of this book (see, also, Wand and Weber 1989):
A control is a system that prevents, detects, or corrects unlawful events
There are three key aspects to this definition. First, a control is a system. In
other words, it comprises a set of interrelated components that function to-
gether to achieve some overall purpose. Unfortunately, we tend to name con-
trols by focusing on just one feature of the control. For example, probably all of
us are familiar with a password control. A password, per se, however, is not a
control. Passwords become a control only in the context of a system that allows
secure issue of or choice of passwords, correct validation of passwords, secure
storage of passwords, follow-up on illicit use of passwords, and so on. If this
system breaks down in some way, passwords will be ineffective as a control. In
short, the term “password control” is a notation for the constellation of things
that work together to ensure only authorized people use computing resources.
When we evaluate a control, therefore, we must consider its reliability from a
systems perspective.
Second, the focus of controls is unlawful events. An unlawful event can
arise if unauthorized, inaccurate, incomplete, redundant, ineffective, or ineffi
ient input enters the system. For example, a data-entry clerk might key incom-
plete data into the system. An unlawful event can also arise if the system trans-
forms the input in an unauthorized, inaccurate, incomplete, redundant,
ineffective, or inefficient way. For example, a program could contain erroneous
instructions that result in incorrect computations being performed. Whatever
the reason, the system moves into a state that we deem to be unacceptable.
Third, controls are used to prevent, detect, or correct unlawful-events. Con-
sider some examples:
1. Preventive control: Instructions are placed on a source document to prevent
clerks from filling it out incorrectly. Note that the control works only if the in-
‘structions are sufficiently clear and the clerk is sufficiently well trained to un-
derstand the instructions. Thus, both the clerk and the instructions are compo-
nents of the system that constitutes the control. The instructions by themselves,
are not the control.
2. Detective conirol: An input program identifies incorrect data entered into a
system via a terminal. Again, the control is a system because various parts of
the program must work together to pinpoint errors. .
3. Corrective control: A program uses special codes that enable it to correct data
corrupted because of noise on a communications line. Once more, the control
is a system because various parts of the program must work together in con-
junction with the error-correcting codes to rectify the error.