Internal Auditing Standards Overview
Internal Auditing Standards Overview
• Attribute Standards address the attributes of organizations and individuals performing internal auditing.
• The Performance Standards describe the nature of internal auditing and provide quality criteria against which the performance of these services can be measured.
• Implementation Standards are also provided to expand upon the Attribute and Performance standards, by providing the requirements applicable to assurance or consulting activities
© NIRMALA (UITM SEGAMAT)
Assurance services involve the internal auditor's objective assessment of evidence to provide an Consulting services are advisory in nature, and are generally performed at ETHICS
independent opinion or conclusions regarding an entity, operation, function, process, system or the specific request of an engagement client. The nature and scope of the consulting engagement
other subject matter. There are generally three parties involved in assurance services: are subject to agreement with the engagement client. Ethics in general:
[Link] person or group directly involved with the entity, operation, function, process, system, or other Consulting • Set of moral principles, values or acceptable behaviour
subject matter-the process owner services generally involve two parties • Science of morals, study of principles of human duty,
[Link] person or group making the assessment-the internal auditor [Link] person or group offering the advice-the internal auditor rules of conduct
[Link] person or group using the assessment-the user. [Link] person or group seeking and receiving the advice the engagement client. • Provide standard of conduct in daily life
Definition of ethics:
CODE OF ETHICS • A set of moral principles that distinguish between what
The purpose of The Institute's Code of Ethics is to promote an ethical culture in the profession of internal auditing. is right and what is wrong
A code of ethics is necessary and appropriate for the profession of internal auditing, founded as it is on the trust placed in its objective assurance about governance, risk management, and control. • It is a set of values that guide the conduct and the
behavior of the individuals, enabling them to
The Institute's Code of Ethics extends beyond the Definition of Internal Auditing to include two essential components: differentiate between rights and wrong, good and bad
1. Principles that are relevant to the profession and practice of internal auditing. and what should and should not be done
2. Rules of Conduct that describe behavior norms expected of internal auditors. • “Ethical behavior is not an act BUT a HABIT…”
These rules are an aid to interpreting the principles into practical applications and are intended to guide the ethical conduct of internal auditors.
EVOLUTION OF INTERNAL AUDIT IN
PRINCIPLE RULES OF CONDUCT MALAYSIA
[Link] - How internal auditors perform their [Link] Internal auditors: • In 1970, Ministry of Defence set up its internal audit unit.
work with honesty and professional courage • Shall perform their work with honesty, diligence, and responsibility. • In 1979, the Federal Government issued a circular
[Link] - An unbiased mental attitude that • Shall observe the law and make disclosures expected by the law and the profession. expanding the establishment of IA to other ministries
allows internal auditors to make professional • Shall not knowingly be a party to any illegal activity, or engage in acts that are discreditable to the profession of internal auditing or to the with a broader role which include operational audit.
judgements. organization. • In 1993, the Ministry of Finance requested all
[Link] – Internal auditors must be • Shall respect and contribute to the legitimate and ethical objectives of the organization. government-owned organizations to set up an audit
aware of and comply with any policies and [Link] Internal auditors: committee:
procedures while handling the secrecy of the • Shall not participate in any activity or relationship that may impair or be presumed to impair their unbiased assessment. This participation • To protect the government interest as a shareholder
information includes those activities or relationships that may be in conflict with the interests of the organization. • To oversee the internal audit function in these
[Link] - Internal auditors apply the • Shall not accept anything that may impair or be presumed to impair their professional judgment. organizations.
knowledge, skills, and experience needed in • Shall disclose all material facts known to them that, if not disclosed, may distort the reporting of activities under review. • Internal auditing in private sector
the performance of internal audit services. [Link] Internal auditors: • Mainly focus on evaluating the efficiency and
[Link] Due To Professional Care - The • Shall be prudent in the use and protection of information acquired in the course of their duties. effectiveness of internal control systems and
internal auditors must plan and perform the • Shall not use information for any personal gain or in any manner that would be contrary to the law or detrimental to the legitimate and ethical compliance
details of the internal auditors’ work. objectives of the organization. • Since 1993, it was mandatory for all public listed
Assessing the audit engagement following [Link] Internal auditors: organizations to establish audit committee to monitor
relevant regulations and internal audit • Shall engage only in those services for which they have the necessary knowledge, skills, and experience. accountability, governance, independence and
standards and communicating with the related • Shall perform internal audit services in accordance with the International Standards for the Professional Practice of Internal Auditing (Standards). objectivity of the internal audit department.
parties. • Shall continually improve their proficiency and the effectiveness and quality of their services • Bursa Malaysia Listing Requirements, amended in
[Link] 2008, mandated public listed organizations to set up
internal audit function.
CHP 5 - MANAGING THE INTERNAL AUDIT FUNCTION OUTSOURCING
Staffing requirement Elements affecting staffing requirements IIA COMMON BODY OF KNOWLEDGE (CBOK) OUTSOURCING ARRANGEMENTS
• competent and skilled • staffing strategies, • Internal auditors should focus on risk areas that pose the greatest threat to the organisation.
• adequate number • understanding customer needs, • Maintain good relationship with governance parties, especially the audit committee and executive management 1. FULL OUTSOURCING 3. CO-SOURCING
• adding value, • Evaluate the internal audit processes and to continuously improve the performance. • Execution of a full-scope and risk-focused internal audit plan • Execution of an internal audit plan is shared between an
• addressing risks and use of audit tools contracted to an external provider, usually from professional accounting firm and the organization. In most cases, the
accounting firms. The oversight and responsibility for the internal audit outsource d party handles specialized areas (Reporting
activity cannot be outsourced. should be made to the management and the board.
BODY OF KNOWLEDGE AND CHARACTER
• Should require the approval of the audit committee and reporting to 4. SUB-CONTRACTING
the board or other governing body. • Involves the engagement of an external party for a limited
The knowledge and skills that internal auditors should possess include: 2. PARTIAL OUTSOURCING period to undertake a specific engagement or a portion of
• Proficiency in applying internal auditing standards, procedures and techniques to perform effective and efficient internal audits. • Execution of the internal audit plan is partly done by an internal some engagement'
• Adequate knowledge on accounting principles and techniques, management principles as well as, fundamentals of law, economics, taxation, finance and other related subject matters provider on an ongoing basis. • In-house internal audit department will normally provide the
• External provider will report to the head of the internal audit management and oversight functions.
TRAINING AND PROMOTION SELECTING STAFF ATTRIBUTES OF AN EFFECTIVE INTERNAL AUDIT FUNCTION department.
BENEFIT LIMITATION
• For continuous improvements of internal audit An appropriate process for hiring to ensure that only candidates • Objective and free from undue influence
performance with the appropriate qualification and experience are selected • Aligns with strategies, objectives and risk of organisations
• Focus on core competencies • Allegiance of in-house vs external provider
• The purpose of the training is to enhance and upgrade Process can include: • Demonstrate quality and continuous improvements.
• Costs minimisation • Organisation culture hindering external provider’s performance
knowledge, skill and competencies of internal auditors • written test – for their IQ testing • Communicates effectively
• Business efficiency • Statutory requirement – Sarbanes-Oxley Act 2002
• use of key performance indicators (KPIs) for evaluation • presentation – communication skill • Provide risk-based assurance
• Enhancement of external audit • Increasing costs in the long term
procedures, • Interview – face-to-face • Insightful, proactive and future-focused
• Increase business geographical locations • External provider lack of knowledge
• orientation - adaptability • Promotes organizational improvements
coverage • Succession plan affected
• Future expectations for in-house auditor • Lack long-range development
QUALITY ASSURANCE IMPROVEMENT PROGRAMME • Increase credibility
• IPPF 2300 – Performing the Engagement. Internal auditors must identify, analyze, evaluate, and
document sufficient information to achieve the engagement’s objectives.
Standard 232 -Analysis and Evaluation states that internal
auditors must base conclusions and engagement results on CHP 6 - INTERNAL
appropriate analyses and evaluation.
• IPPF 2310 – Identifying Information Internal auditors must identify sufficient, reliable, relevant, and
useful information to achieve the engagement’s objectives. The process: AUDIT PROCESS –
PLANNING AND
• Sufficient information is factual, adequate, and convincing so that a prudent, informed person would • Review and evaluate audit evidence
reach the same conclusions as the auditor. Reliable information is the best attainable information • Formulating audit opinion
through the use of appropriate engagement techniques. Relevant information supports engagement • Formulating recommendation
observations and recommendations and is consistent with the objectives for the engagement. Useful
information helps the organization meet its goals. Opinions and Recommendations are based on the following
attributes:
FIELDWORK
AUDIT FIELDWORK – DATA COLLECTION/AUDIT EVIDENCE ANALYSING AND • Criteria: The standards, measures or expectations used in
(to determine the risks and the location to perform audit. ) EVALUATING making an evaluation and/or verification (the correct state).
• Condition: The factual evidence that the internal auditor finds in
© NIRMALA (UITM SEGAMAT)
Steps are divided into as follows: Audit Evidence [Link] the course of the examination (the current state).
i. understanding the business process flow requirement: [Link] • Cause: The reason for the difference between expected and
ii. identifying the prescribed internal controls i. Types of [Link] actual conditions.
iii. assessing the controls evidence • Effect: The risk or exposure the organization and/or others
iv. developing the audit procedures ii. Availability encounter because the condition is not consistent with the 5. COMMUNICATION RESULT
v. audit testing iii. Selection criteria (the impact of the difference). In determining the degree
vi. audit report iv. Nature of risk or exposure, internal auditors must consider the effect on
vii. engagement supervision their engagement IPPF 2400 Internal auditors must communicate the Criteria of Quality
results of engagements. Communication
DOCUMENTATION When arriving at the conclusion, auditors should consider the The Process: Quality
following: 1. Preparation of the initial draft of the report. • Accurate
Practice Advisory 2330-1: Recording Information (Working papers that document the engagement should • whether the conclusion encompasses the entire scope of an 2. Review and edit by members of the audit team. • Objective
be prepared by the internal auditor and reviewed by management of the internal audit activity.) engagement or specific aspects 3. Preparation of the revised audit report. • Clear
Purpose: • program objectives and goals 4. Review and edit by the manager of audit assignment • Concise
1. Tools for efficient Conduct And supervision • to review alignment to organization goals; whether the 5. Preparation of the second revision of the report. • Constructive
2. Support audit Conclusion And report organization's objectives and goals are being met 6. Review and edit by the head of internal audit • Complete
3. Review and Quality Control • whether the activity under review is functioning as intended department • Timely
4. Form of evidence • an overall assessment ofcontrols or area under review 7. Preparation of the third revision of the report.
• whether the scope is limited to specific controls or aspects of 8. Combined review and edit by the audit team leader,
the engagement manager, and director.
ACTIVITIES DETAIL EXAMPLES
9. Preparation of the “discussion draft” of the report for
Interviewing or conducting inquiry Discuss with payroll manager on payroll calculation. The following are factors to be considered when developing
review by auditee management.
recommendations:
Verifying or vouching Review the payroll payment instruction letter sent to the bank. 10. Review by management and response provided on
• Be specific to the problem and offer some alternatives or advice
audit findings.
Observation Observe employee clock in attendance. to solve the problem
11. Preparation of the final draft of the audit report for
• Avoid dictatorial connotations by using should, ought or must
Re-performance/Recalculation Recalculate amount of tax deduction. distribution.
• Findings must be taken seriously by the management/auditee
Questionnaires Issue survey on employee satisfaction. but not always obligated to accept the audit recommendations
• Suited to the auditee's needs and considerations
Analytical procedures Calculate ratio on total monthly tax deduction for 12 months.
Computer assisted audit tools and Using audit software to reconcile payroll file and employee master
6. FOLLOW-UP ACTIVITES
techniques (CAATTs) file.
Physical inspection Test drive the company car used by the chief executive officer to Performance Standard 2500 states that the Factors to consider in determining the nature, timing and extend of the follow up procedures:
ensure that it is in good condition CAE should establish a follow-up process to • The significance of the reported observation or recommendation.
Review of published reports or Review minutes of meeting to identify decision on bonuses for the monitor and ensure that management actions • The degree of effort and cost needed to correct the reported condition.
minutes year. have been effectively implemented or that • The impact that may result should the corrective action fail.
Confirmation Send letters to employees who took company car loan to confirm senior management has accepted the risk of • The complexity of the corrective action.
the loan balance due. not raking action. • The time period involved
REPORT DESIGN • An internal audit report is fundamentally the final product from an audit engagement that can be considered important to management.
• The reporting is compulsory based on the Performance Standard 2400
COMPONENT CONTENT
Purposes of Internal Audit Report
CHP 7 - INTERNAL
• Criteria: A report is based on the standards, measures or expectations
used in making and evaluation and/or verification.
• The purpose statement - The
purpose of engagement should be
• Developing recommendation
• Present management with control and risk issues
AUDIT PROCESS -
• Condition: Factual evidence internal auditors found during the audit
engagement.
conducted in observing identified risk
area and the expected outcome from
• Promote problems to management
• To documented the results REPORTING AND
MONITORING
• Cause: Reasons for the difference between expected (based on the the engagement. • Developing action plan
criteria and requirement) and actual conditions. Here, it is proven that • The scope statement - This part 1. The report should disclose the current internal control situation highlighting the problems discovered during the engagement. The role of an audit report is aimed
there is system deficiency whenever actual conditions do not meet the identifies the audit process and how to change or to improved internal controls.
2. The internal audit report should highlight the importance of control and risks occurred with the business objectives. Management need to determine high priority
standards, measures or expectations.
• Effect: The risk or exposure the organization and/or others encounter
because the condition is not consistent with the criteria. In determining
the work is to be performed, including
the relevant methods in audit
process pertaining to observation.
control, adequate solution and improvement tools in order to focus on their future achievement.
3. The action plan is a one step ahead of the recommendation where management will make some required changes.
© NIRMALA (UITM
4. The highlighting and promoting problem to management will make management more concerned on risk area problem and they able to plan for any action plans.
the degree of risk or exposure, internal auditors must consider the
effect their engagement observations and recommendations may have
on the organization’s operations and financial statements.
• Opinion - The opinion will be the
overall assessment on controls from
the overall audit process.
5. The internal audit report will act as a formal tool to convey audit findings to management in order to highlight the risk areas and provide opinions and
recommendations.
SEGAMAT)
• Recommendations: This will include action plans that need to be • The main body - The main body will 6. The internal audit report will assured and confirmed that problems happened in organization may have no major errors that affect the effectiveness of operation.
employed for future prevention and current correction. Correction include the background of the audit
plans need to correct past errors, and prevention plans need to be process, observations, Process of Report Writing LEGAL AND PROFFESIONAL CONSIDERATION
thoroughly looked into. recommendations and action plans. 1. Field Audit Exit Meeting - The purpose of an exit meeting is to enable auditors to discuss matters on the weaknesses of the system and the risk area discovered
during the audit. • Internal auditors should be cautious when include results
2. Draft Audit Report - The draft audit will include audit observations, audit recommendations and an audit plan. and opinions regarding law and regulatory violations and
QUALITY OF REPORT WRITING GUIDELINES ON INTERNAL AUDIT REPORT BEST PRACTICE 3. Responses from Department - The auditee itself must take into consideration for each recommendation provide by internal auditors for the purpose of improving other legal issues in the report
the business operation and to ensure the effectiveness of the system. • Internal auditor should work closely with legal counsel and
Sawyer (2012) - has suggested a report 1. The main point must be stated immediately because clients, 4. Final Audit Report- The final report will include the significant issues, action plan, recommendations, department’s responses and auditors’ conclusion. compliance officer on the sensitivity of information from
quality checklist which can be considered senior executives and audit committee members want a 5. Post Audit Survey- The purpose is to evaluate the effectiveness of the audit process, audit planning, audit performance, professionalism and knowledge of the legal consideration
the most productive. This checklist will be succinct description of the issue, its level of risk, and audit team. • Internal audit department should have policies and
one of the rule of thumb and requirement in recommended mitigation or corrective actions. 6. Follow-up Audit- Internal auditors will request for follow up information to review and report on corrective actions taken in addressing all previous significant procedures in handling matters that relate to legal and
reporting in order to ensure every information 2. Auditors need to communicate the severity of risks and explain issues. professional considerations
taken from observation will be written the risk in meaningful ways in order for management to focus
completely in internal audit report. more on recommendations.
• Factors of good quality report writing 3. The report should be written to communicate the necessary REPORT MONITORING AND FOLLOW-UP
A good quality report will enhance the ideas that focus on audit findings in order to inform the readers.
understandability by the senior 4. Auditors need to avoid using technical terms because not every MONITORING FOLLOW-UP
management. readers would understand and be familiar with accounting and
1. Readability - Message placement, auditing terminologies. The CAE should establish procedures according to Practice • The final part is the follow-up process, where internal auditors need to look through whether management has take action for each recommendation.
coherence, conciseness and the use of 5. In preparing an internal audit report, auditors need to use the Advisory 2500-1' The procedures are as follows: • A follow-up is a process by which internal auditors evaluate the adequacy, effectiveness and timeliness of actions taken by management on reported observations
graphics can help enhance the readability correct words and acceptable practice for business 1. A timeframe within which management's response to and recommendations, including those made by external auditors and others.
of a report documents. engagement observations and recommendations is
2. Clarity - Definitions are crucial in 6. Auditors need to construct sentences which consist of a noun required Types of Follow-Up
understanding concepts for each that readers can easily understand and visualize. 2. Evaluation of management's response. • Follow-Up Documentation - Referring to Performance Standard 2330, internal auditors must document relevant information to support their conclusions and
observation and audit process. 7. Each sentence must generally be short and contain no more 3. Verification of the response. engagement results as well as document follow-up procedures and results.
3. Objective Wording and Tone - The report than 24 words to ensure readability. 4. Performance for each risk area of a follow-up • Follow-Up Reporting Results - CAE should also report the results of these procedures to upper management and the board. The report preparation depends on the
must be prepared objectively when 8. Ideas in an internal audit report can be improved by simplifying engagement. organization's culture. In a formal culture, the auditor might conclude the engagement by sending written reports to upper management and the board on any open
describing the engagement, where the ideas into lists. This list will help readers to digest and process 5. A communication process that escalates unsatisfactory issues.
wording used must be fair, impartial and information in a short time. responses/actions, including the assumption of risk, to • Follow-Up Frequency - Follow-up procedures need to be conducted and performed in order to provide confidence and assurance to the CAE, upper management and
unbiased. The tone of writing has to reflect 9. The report should emphasize the possibility of failure; thus, the appropriate levels of senior management or the the board. According to Flpn (2010), the rule of thumb for follow-up performance is that it should be conducted at least twice a year.
the level of severity for each observation. auditors should point out potential improvement for each of the board.
4. Language - The level of understanding of control.
the report is dependent on good grammar, 10. Auditors must avoid using negative words because such words
punctuation and mechanics. have a high tendency to provoke rather than convince clients DISTRIBUTION OF REPORT
QUALITY OF GOOD REPORTING • The purpose of the report distribution is to assist clients / auditees to achieve the desired action.
• The control of distribution for the final engagement report is done by the Chief Audit Executive (CAE). The CAE determines who receives the report in accordance
• Accurate – Free from errorrs and distortions and is faithful to the underlying facts Key steps to effective
• Objective – Fair, impartial and unbiased and is the result of a fair-minded and communication INTERNAL COMMUNICATION COMMUNICATE WITH OUTSIDE READER DISSEMINATING INFORMATION TO OUTSIDE READER
balanced assessment of all relevant facts and circumstances. • Must make advance
• Clear – easily understand and logical, avoiding unnecessary technical language preparation when • CAE may adopt policies or The CAE may facilitate the adoption of appropriate policies if there are no preexisting In disseminating information to outside readers, there are matters to be considered:
and providing all significant and relevant information communicating bad news guidelines in communicating guidelines, which may include: • Usefulness of written agreement with intended recipients concerning information to be
• Concise – communication is to the point and avoid unnecessary elaboration, • Must focus on the setting sensitive information within and • Authorization to seek approval in reporting information outside the organization. reported and internal auditor’s responsibilities.
superfluous details, redundancy and wordiness. for the meeting outside the group of internal • Process for seeking approval to report information outside the organization. • Identification of information providers, sources, report signers, recipients and related persons
• Constructive – helpful to the engagement client and organization and leads to • Must be straightforward auditors and/or chain of command. • Guidelines for permissible and nonpermissible information to be reported. to receive report or information.
improvements where needed. and honest in their delivery • Most information communicated • Outside persons authorized to receive information and types of information they may • Identification of objectives, scope and procedures to be performed in generating applicable
• Complete – lacks nothing that is essential to the target audience and include all • Must anticipate the may exposure threats, receive. information.
significant and relevant information and observation to support responses or feedbacks uncertainties, fraud, waste and • Related privacy regulation, regulatory requirements, and legal considerations for • Nature of report or other communication including opinions, inclusions or exclusion of
recommendations and conclusion from clients mismanagement, illegal activities, reporting information outside the organization. recommendations, disclaimers, limitations and types of assurance or assertions to be
• Timely – opportune and expedient, depending on the significance of the issue, • Determining the corrective abuse of power, misconduct that • Nature of assurances, advice, recommendations, opinions, guidance and other provided.
allowing management to take appropriate corrective action actions endangers, public health or safety information that may be included in communicating information outside the • Copyright issues, intended use of information and limitations on further distribution or sharing
or other wrongdoings. organization. of information.
TECHNOLOGY
CHP 8 - IMPACT OF TECHNOLOGY TECHNOLOGY CHALLENGES TO IA IA FUNCTION IN AN IT BUSINESS IT RELATED RISK
IMPLICATIONS OF ENVIRONMENT
INFORMATION
• Business becomes more and • Issues surrounding modification of system • IA – knowledgeable about computers, IT-related risks
more dependent on IT • Poor IS management comfortable and confident with 1. System Application Error
• Set of skills required by • Unstable system and confidence erosion technology • The risk of system error might increase since the system requires to be upgraded
TECHNOLOGY ON business– technical skill &
business process knowledge
•
•
Extra cost and time to correct system
Business loses credibility
• IA must be able to visualise impact of
technology on business – good and bad
from time to time due to the expansion of business operations. Too many changes
and flaws in the system program procedures will lead to the issue of reliability of the
IT AUDIT
EVALUATION OF GENERAL & APPLICATION CONTROLS
IT audit focuses on the evaluation of an organization's TYPES OF IT AUDIT INFORMATION SYSTEM AUDIT
computer systems and network to ensure: GENERAL CONTROL – Applicable to all aspects of IT functions, for
• the effectiveness of control procedures in minimizing • Operational computer system audits Purpose – to provide assurance that an appropriate level of control over the confidentiality, example the administration of IT function, hardware or software
related technology risks • IT application audits integrity and availability of information within system acquisition and maintenance and physical and security control over
• the compliance with international or Malaysia’s • Developing system audit (SDLC) • System operation is opened to threat (e.g. virus attack), vulnerability of system (e.g. product hardware
standard operating practice, policies, procedures and • IT management audit flaw) and associated risk
related law or regulations of the regulatory body. • IT process audit • Business need to have information security policy Scope Of Audit Objectives of Audit
• Information security and control audit • Network environment – e-commerce websites reside
• Disaster contingency or disaster recovery audit • Sources of threats to network environment: network segment, application software, system Logical Access To ensure a proper control in place for
• IT strategy audit software, process integrity and physical security Controls infrastructure, applications and data.
ELEMENT OF IT AUDIT GUIDE TO CONDUCT IT AUDIT Physical Access To ensure proper control in place for physical
Controls access within IT department and its critical
1. Physical and Environmental Review – Reviews physical facilities and conditions of IT environment such as physical access, power supply, 1. The GAIT Methodology B-head areas.
air conditioning and humidity control • a guideline to assess the scope of IT general controls using a top-down and
2. System Administration Review –It includes review of security control procedures of existing operating systems and database management risk based approach. Administration of IT To ensure proper administration of people and
systems. • helps the management to identify any deficiencies in key IT general controls Function resources of the department.
3. Application Software Review – Reviews all business application software, for example, software to record accounting and finance that may result in material errors in financial statements.
transactions used by the finance department, software to process salary used by the payroll department and web-based customer order • It include four principles that form the basis for this guideline Backup and To ensure that a proper backup and
system used by the sales department. 2. GAIT for IT General Control Deficiency Assessment Contingency Plan contingency plan is in place for unexpected
4. Network Security Review – Reviews IT network's infrastructure, which includes internal and external connections to the system, perimeter • a guideline to evaluate any IT general controls deficiencies identified during emergencies such as fire, virus attack, power
security, firewall review, router access control lists' port scanning and intrusion detection assessment failure or natural disaster.
5. Business Continuity Review – Reviews control procedures in ensuring the systems and information are available when needed. 3. GAIT for Business and IT Risk
6. Data Integrity Review – Rieviews control security measures around IT operating systems and application software to ensure output • a guideline to help identify the IT controls that are critical to achieve APPLICATION CONTROL – Include control of usage of individual
produced is accurate, complete, timely and valid. business goals and objectives. transactions specific to certain software application. For example,
controls over the processing of sales
STEPS TO PERFORM IT AUDIT ISSUE IN IT AUDIT
Scope Of Objectives of Audit
1. Establish the Terms of Engagement – The CAE will determine the scope and objectives of the audit of IT functions. • Security – To ensure access to the system and its data is restricted to Audit
2. Preliminary Review – This is the process where the auditor needs to gather information on the IT department as a basis for preparing an authorized personnel only
audit plan. • Confidentiality – To ensure that sensitive information of an organization is Input Control To check the integrity of data entered into an
3. Establish Materiality and Assess Risk – The auditor needs to establish judgement on the materiality of the IT function as well as perform protected from unauthorized access or disclosure. organization application.
assessment on the auditee's business risk in order to set the scope for the audit. • Privacy – To ensure personal information of any third party such as
Processing To ensure proper control for data processing so that
4. Plan the Audit – Normally, a proper audit plan includes engagement's objectives, scope, timing and resource allocation. customers' addresses and contact numbers are treated in accordance with
Control the process is complete, accurate and authorized.
5. Consider Internal Control – The auditor has to consider the internal control of the auditee in order to begin the audit process. The the organization's business policy and protected from unauthorized access
information on internal controls could come from a variety of sources such as studies of existing internal controls, previous audit reports, or disclosure.
Output Control To ensure output results similar with input data. To
reports by regulators such as Bank Negara Malaysia, Bursa Malaysia or feedback from operating personnel. • Processing Integrity – To ensure business data are processed accurately
ensure computer output is not interrupted by or
6. Perform Audit Procedures – The auditor will perform the audit process based on the scope stated in the audit plan. The auditor will use a and completely in a timely manner with proper authorization.
shown to unauthorized users.
substantive test approach to audit IT business functions. • Availability – To ensure the operating system and its data are available at
7. Issue the Audit Report – The auditor will issue an audit report once all audit procedures have been completed and evaluated. all times to meet the needs of business operations.
AUDITING OF SYSTEM DEVELOPMENT LIFE CYCLE (SDLC) COMPUTER-ASSISTED AUDIT TOOLS (CAATs)
CHP 8 -
IMPLICATIONS OF
System Development Life Cycle (SDLC) is a series of steps used to identify the phases of an information
system development project an approach of auditing using computers. It offers FUNCTION
INFORMATION
• Process centric approach to develop and implement system - set of defined goals and timelines that sets various tools or utilities, which help the auditor to
out the completion date and associated deliverables within each phases of the life cycle select, gather, analyze and report audit findings. • Information
TECHNOLOGY ON
• Each phase (plan, analyse, design, implement) sequentially executed – allow proper evaluation and Tools/utilities to help auditor to select, gather, analyse retrieval and
resolution of problems within each phase and report audit findings. analysis
INTERNAL AUDITING
CAATs can be classified: • Fraud detection
Phase 1: Systems planning • Electronic working papers tool
During this phase, management will plan a system to meet the organization's mission and objectives. The • Information retrieval and analysis • Audit reporting
plan will include general guidelines for system development, time frame and budget.
Phase 2: Systems Analysis
© NIRMALA (UITM • Fraud detection
• Network security
function
During the second phase, a system analyst will gather the necessary information such as facts and samples • Electronic commerce and internet security
to be used in the project from the end users.
Phase 3: Conceptual Design
SEGAMAT) • Continuous monitoring
• Audit reporting
During this phase, a conceptual design is developed to include views from all respective persons involved
with the development project. AUDITING E-COMMERCE ADVANTAGES
Phase 4: Systems Selection
A system selection phase involves a process where the management together with the system analyst will Issues in E-commerce Environment • CAATs are suitable to audit large volume of transactions. It is valuable to
evaluate alternative system requirements to select the best system to meet the requirements stipulated by • Business continuity organisations with complex processes, distributed operations and high
the users as well as to fulfil the organization's objectives. • Information security and privacy transaction volumes.
Phase 5: Detail Design • The use of CAATs is important for auditors to gain access into audited data in a
• The lack of audit trails
At this level, the system analyst will develop a system based on the DFD created in phase 3, taking into much effecient way. A direct access to an organisation’s data will eventually
• Record retention reduce the time and effort spent in performing audit procedures with assured
consideration the analysis made during the selection process.
Phase 6: Programming and Testing Systems • Segregation of duties accuracy.
It will determine whether the outcome of the project is able to meet the predetermined objectives. • Legal liability • Using CAATs in performing substative testing will provide total assurance to the
Phase 7: Systems Implementation area being audited. It allows auditors to point out errors or fraud easily in order to
Management has to sign-off the user acceptance agreement before the system is made live. However, the provide effective recommendations.
process of the SDLC does not end at this stage. Management is required to perform post-implementation E-commerce Environment • CAATs provides a standard uniform practice and user-friendly interface for
evaluation on the project. • Electronic commerce (e-commerce) is the process by auditors. It allows auditors to perform various tasks, irrespective of data format or
which organisations conduct their business over the underlying operating system of an organisation.
IA Involvement in SDLC Risk Factors in SDLC electronic systems such as the Internet and other • Data could be examined faster and more accurate
• Proactive auditor’s involvement • New system does not meet business computer networks with their customers, suppliers • Practical to scrutiny large volume data
• On-the-spot advice for all phases – not wait till the requirements • Improve effectiveness and efficiency of audit
and other external business partners.
end • Failure to develop adequate/complete user • Continuous in usage once the software is available
• Threats to e-commerce environments include virus • Flexible as the parameters can be varies
• Advisory role to the project team requirements, poor understanding about the
• Independently monitor progress of project and project, lack of user involvement, infections, hacking, cybercrime and failure of the
make recommendations requirements and specifications keep system and infrastructure. DISADVANTAGES
• Independent postimplementation review changing
• Gaining better understanding about the system • Poor project management/SDLC methodology Reason for Audit e-Commerce • Audit software incompatible with other softwares
• Better position to understand the system if involved • Planned financial resources exceeded, late • To assess the effectiveness of the infrastructure and • May require considerable computer resources/capacity
in the development process completion of individual task, missed security measures of an e-commerce. • Give rise to question cost vs. benefits
• Would assist in subsequent IT audit; or in using IT deadlines, pressure to agree to impossible • To evaluate compliance of ecommerce business • Modifications to systems may render vendor’s warranty void
for audit (e.g CAAT) schedules operations with an organisation’s IT security policies • Security and validity of the system can be compromised – especially in using
• Independence of internal auditors • Inadequate change management control dummy data
as well as with the industry good practices.
• Professional relationship from consultant • Lack of systems and process to manage • Compitability issues with the existing software applications used by a company.
• To evaluate the readiness of IT functions in the event • Installation process require various computer resources or facility, for examples
perspective – advisory capacity only change
of a major failure in e-commerce business the type of processor, size of memory and storage required.
• Better risk management • Who has made the changes, what changes
• Provider of assurance and advisory services only are made, when they are made transactions. • Sensitive business data such as customers’ detail, business plan and strategy
• Better identification of risk from independent • To identify other security issues that may affect the could be compromised by irresponsible persons, if not handled properly.
perspective current infrastructure of an e-commerce model. • Too many software available – may need software specialist to support the
system
CHP 9 - INTERNAL AUDIT PROCESS – INVESTIGATION OF FRAUD © NIRMALA (UITM SEGAMAT)
FRAUD
Fraud encompasses a wide range of irregularities and illegal acts characterized by intentional deception or misrepresentation. In TYPES OF FRAUD
general, fraud is defined as an act or course of deception, an intentional concealment, omission or perversion of truth, to:
• gain unlawful or unfair advantage 1. Asset Misappropriation
• induce another to part with some valuable item or surrender a legal right • Involves stealing of cash or assets (supplies, inventories, equipment and information) from the organisation. In many cases, the perpetrator tries to conceal the theft, usually by adjusting the records.
• inflict injury in some manner. 2. Financial Statement Fraud
• Wilful fraud is a criminal offense which calls for severe penalties, and its prosecution and punishment (like that of a murder) is not • Involves misrepresenting financial statements, often by overstating assets or revenue or understating liabilities and expenses. Financial statement fraud is typically perpetrated by managers who seek to enhance
bound by the statute of limitations. the economic appearance of the organisation. Members of the organisation may benefit directly from the fraud by selling stock, receiving performance bonuses, or using the false report to conceal another fraud.
Other definition of fraud 3. Corruption
1. as an advantage gained by unfair or wrongful means, an infraction of the rules of fair trade; a false representation of fact made • Misused of entrusted power for private gain. Corruption includes bribery and other improper uses of power. Corruption is off–book fraud meaning that there is little financial evidence available to prove that the
knowingly, without belief in its truth, recklessly, not caring whether it is true or false crime occurred. Corrupt employees do not have to fraudulently change financial statements to cover up their crimes. They simply received cash payments under the table. In most cases, these crimes are
2. as a deception deliberately practiced in order to secure unfair or unlawful gain uncovered through tips or complaints from third parties. Corruption often involves the purchasing processes.
3. Intentional misinterpretations of financial information by one or more individuals among management, employees or third parties. 4. Bribery
• Is offering, giving, receiving or soliciting of anything of value to influence an outcome. Bribes may be offered to key employees or managers who are purchasing agents and who have the ability to award businesses
to vendors.
FRAUD TRIANGLE 5. Falsification of Expense Claims
• An old favourite with both senior and junior staff. Common ‘ruses’ include inflating mileage claims, entertaining friends and relatives at the company’s expense and claiming for expenses that were never incurred.
1. PRESSURE 6. Stealing Money from the Company Bank Account
• Pressure is what causes a person to commit fraud. Pressure can include almost anything including medical bills, expensive tastes, • The perpetrator having gotten away with stealing once will keep on doing it again.
addiction problems, etc. Most of the time, pressure comes from a significant financial need/problem. Often this need/ problem is 7. Manipulating Sales Figures to Reach Target and Achieve Bonuses
non-sharable in the eyes of the fraudster. That is, the person believes, for whatever reason, that their problem must be solved in • A simple version of this involves booking sales in one month then crediting them back the next, unless the perpetrator keeps this up, the overstatement in one month will naturally show as a shortfall in the next.
secret. However, some frauds are committed simply out of greed alone. 8. Falsifying Supplier Invoices
2. OPPORTUNITY • A senior manager who had renovation work carried out on his house and then arranged for the invoices to be sent to the company, booked as costs for work carried out on the company’s premises.
• Opportunity is the ability to commit fraud. Because fraudsters don't wish to be caught, they must also believe that their activities 9. Stock Theft
will not be detected. Opportunity is created by weak internal controls, poor management oversight, and/or through use of one's • A time-honoured way to make a ‘fast buck’. The perpetrator will over a period of time abscond with a number of items from the warehouse and resell them. So long as the stock losses are within tolerance, then it is
position and authority. Failure to establish adequate procedures to detect fraudulent activity also increases the opportunities possible for this to remain undetected for a significant period of time.
fraud for to occur, Of the three elements, opportunity is the leg that organizations have the most control over. It is essential that 10. Transactions That Are Not ‘Arms Length’
organizations build processes, procedures and controls that don't needlessly put employees in a position to commit fraud and that • When a company asks for tenders for a contract, they usually obtain at least three quotes from third parties. The best value quote should then be selected. When the system does not run effectively, there is an
effectively detect fraudulent activity if it occurs. opportunity for friends and relatives of the purchasing department to send in quotes that are accepted, bypassing the quotes from reputable suppliers.
3. RATIONALIZATION 11. Tax Evasion
• Rationalization is a crucial component in most frauds. Rationalization, involves a person reconciling his/her behavior (stealing) • Fraud at corporate level. Excessively complex organisational structures are created and designed to obfuscate the revenue streams to hide the reality from tax authorities.
with the commonly accepted notions of decency and trust. Some common rationalizations for committing fraud are: 12. Fictitious Invoicing
o The person believes committing fraud is justified to save a family member or loved one • Where there are poor accounting controls, fraudsters can arrange for fake invoices from connected parties to be passed for payment.
o The person believes they will lose everything-family, home, car, etc. if they don't take the money 13. Acquisition of Company Property at Less Than Market Value
o The person believes that no help is available from outside • This requires the collusion of at least two people (usually quite senior in position). Company property is ‘sold’ to one of the individuals at a bargain price approved by the other. The property is then resold at market
o The person labels the theft as "borrowing", and fully intends to pay the stolen money back at some point value and the profit is split between the two individuals.
o The person, because of job dissatisfaction (salaries, job environment, treatment by managers, etc.), believes that something is 14. Theft of Raw Materials
owed to him/her • Manufacturers should measure the quantities and costs of the raw materials used in the manufacturing process. Some processes use expensive materials such as gold. When the measurement system is
o The person is unable to understand or does not care about the consequence of their actions or of accepted notions of decency compromised or management does not investigate adverse yield variances, fraudsters have the opportunity to steal the raw material.
and trust.
• Wheeler and dealer • Medical problems — especially for a loved one • Suddenly appears to be buying more material items Brags about new
• Domineering/controlling • Unreasonable performance goals purchases
• Do not like people reviewing their work • Spouse loses a job • Starts to carry unusual amounts of cash
• Strong desire for personal gain • Divorce • Creditors/bill collectors show up at work or call frequently
• Have a ‘Beat the System Attitude’ • Starting a new business or current business is struggling • Borrows money from co-workers
• Live beyond their means • Criminal conviction • Becomes more irritable or moody
• Close relationship with customers or • Civil lawsuit • Becomes unreasonably upset when questioned
vendors • Purchase of a new home, a second home, or a home renovation • Becomes territorial over their area of responsibility
• Unable to relax • Need to maintain a certain lifestyle (‘champagne tastes’ or • Would not take vacation or sick time or only takes it in small increments
• Often have a ‘too good to be true’ work ‘keep up with the Jones’) —person (or spouse) either likes • Works unnecessary overtime
performance expensive things or feels pressure to ‘keep up with’ or out-do • Turns down promotions
• Do not take vacation or sick time or only others in regards to material possessions • Starts coming in early or staying late
take leave in small amounts • Excessive gambling • Redoes or rewrites work to ‘make it neat’
• Often work excessive overtime • Drug or alcohol addiction • May start or mentions family or financial problems
• Outwardly appear to be very trustworthy • Exhibits signs of drug or gambling addiction
• Often display some sort of drastic change • Exhibits signs of dissatisfaction
in personality or behaviour
RESPONSIBILITIES OF FRAUD PREVENTION & DETECTION
FRAUD management’s
identification of fraud risks.
• To implement anti-fraud
• To be responsible for overseeing management’s compliance with appropriate
financial reporting.
• To be responsible for preventing senior management from overriding the controls or
• Maintain discussions with investigators and legal counsel to develop controls over the
investigation process, including developing policies and procedures for effective fraud
investigations and for handling the results of investigations, reporting and communications.
measures. other inappropriate influence over the reporting process.
ROLE OF INTERNAL AUDITOR ROLE OF EXTERNAL AUDITOR ROLE OF FRAUD INVESTIGATOR ROLE OF OTHER EMPLOYEE
• To launch initial or full investigation of suspected fraud, to perform • External auditors have the • Fraud investigators are usually responsible • Employees are the eyes and ears of an
root cause analysis and control improvement recommendations, to responsibility to comply with for the detection and investigation of fraud organisation, and they should be empowered to
monitor a reporting/whistle-blowing hotline and provide ethics professional standards and to plan as well as the recovery of assets. They also maintain a workplace of integrity.
FORENSIC AUDIT training and perform audit for an have a role in fraud prevention. • Employees can report their suspicion of fraud to
• To obtain sufficient skills and competencies including knowledge of organisation’s financial statements • Senior management and the audit the employee hotline, the internal audit
• Forensic audit is defined as the application of accounting methods to the tracking and collection of forensic evidence. fraud schemes, investigation techniques and laws to obtain reasonable assurance committee need to support investigators department or a member of management.
• Financial auditing may be defined as a concentrated audit of all the transaction of the entity to find the correctness of such • To conduct proactive auditing to search for misappropriation of whether these statements are free and to let all stakeholders know that the • To deter and detect fraud and abuse, many
transactions and to report whether or not any financial benefits has been attained by way of presenting unreal picture. assets and information misrepresentation using CAAT techniques from material misstatements and if business entity is ready to respond quickly experts believe an employee hotline that is
• Forensic audit involves examination of legalities by blending the techniques of propriety (VFM audit), regularity, investigative and data mining misstatements were found, whether and appropriately to fraud risks. appropriately monitored is the single most cost-
and financial audits. The objective is to find out whether or not true business value has been reflected in financial • To employ analytical and other procedures of high-risk accounts they were caused by error or fraud. effective fraud detection and deterrence
statements and in the course of examination to ascertain if any fraud has taken place and transactions to identify potential fraud mechanism.