lOMoARcPSD|51817568
TOPIC 1: INTRODUCTION TO AUDITING IN A COMPUTER INFORMATION
SYSTEMS (CIS) ENVIRONMENT
Learning Objectives:
At the end of the lesson, you should be able to:
1. identify what is an IT/CIS Audit;
2. identify the structure of the IT audit; and,
3. identify the internal controls and their objectives.
In a computerized environment, managements are often faced with relatively high
responsibility towards maintaining a reliable information system. Per regulation-based,
these systems undergo auditing to ensure effective and faithful representation of inputs,
processes and outputs of such systems. To achieve these, managements are then
obliged in designing, implementing, and monitoring internal controls to achieve a
reliable information system whether it is a computerized system or a manual system.
As an information systems auditor, it is very important to understand how these internal
control works to effectively design audit procedures and whether to test these controls
or not. This lesson then focuses on understanding internal controls and its objectives
as well as the key features of a computer environment.
I. WHAT IS AN IT AUDIT
➢ An IT audit focuses on the computer-based aspect of an organization’s information
system. This audit includes assessing the proper implementation, operation, and
control of computer resources. Because most modern systems employ information
technology, the IT audit is typically a significant component of all external and
internal audits.
II. UNDERSTANDING THE IT ENVIRONMENT
In an IT environment, as compared to manual systems, it complicates the design of
effective internal controls. First, there is a concentration of data on information
systems. Combined with the number of access connections, remote access, and
linkages to other systems or computers, the modern IT environment exacerbates the
design of effective controls. For example, all users are connected to the same system
where the database is located, which holds all data, and is thus a risk for
unauthorized access, theft or destruction. In effect, there are thousands of control
points with multiple controls needed. Next, there has been an increase in the
malicious activities initiated against systems, data, and assets. Finally, it is easy for
management to override internal controls, and that can lead to financial fraud.
lOMoARcPSD|51817568
III. THE STRUCTURE OF AN IT AUDIT
The IT audit is generally divided into 3 phases; audit planning, test of controls,
and substantive testing. This is illustrated in the figure below:
Substantive Testing
Audit Planning Phase Test of Control Phase
Phase
Review
START
organization’s Perform
policies, Perform test substantive
practices, and of controls tests
structure
Review general
controls and Evaluate test Evaluate results
application results and issue
controls auditor’s report
Plan tests of
Determine
controls and
degree of Audit Report
substantive
reliance on
testing
controls
procedures
1. Audit Planning
This is the first step in the It audit. Before the auditor can determine the nature and
extent of tests to perform, he must gain a thorough understanding of the client’s
business. A major part of this phase is the analysis of the audit risk (to be discussed
in audit theory). The auditor’s objective is to obtain sufficient information about the
firm to plan the other phases of the audit. The risk analysis incorporates an overview
of the organization’s internal controls.
During the review of controls, the auditor attempts to understand the organization’s
policies, practices, and structure. In this phase of the audit, the auditor also
identifies the financially significant applications and attempts to understand the
controls over the primary transactions that are processes by these applications.
The techniques for gathering evidence at this phase include conducting
questionnaires, interviewing management, reviewing systems documentation, and
observing activities. During this process, the IT auditor must identify the principal
exposures and controls that attempt to reduce these exposures. Having done so, the
auditor proceeds to the next phase, where he tests the controls for compliance with
pre-established standards.
2. Tests of controls
The objective of the tests of controls phase is to determine whether adequate internal
controls are in place and functioning properly. To accomplish this, the auditor
performs various tests of controls. The evidence-gathering techniques used in this
phase may include both manual techniques and specialized computer audit
techniques. These techniques used the system-based approach to IT audit, which
focuses on controls and the system as a whole.
lOMoARcPSD|51817568
At the conclusion of the tests of control phase, the auditor must assess the quality
of internal controls. The degree of reliance the auditor can ascribe to internal controls
affects the nature and extent of substantive testing that needs to be performed.
3. Substantive testing
The third phase of audit process focuses on financial data. This phase involves a
detailed investigation of specific account balances and transactions through
substantive tests. For example, a customer confirmation is a substantive test
sometimes used to verify account balances. The auditor selects a sample of accounts
receivable balances and traces these back to their source-the customers—to
determine if the amount stated is in fact owned by a bona fide customer. By doing
so, the auditor can verify the accuracy of each account in the sample. Based on such
findings, the auditor is able to draw conclusion about the fair value of the entire
account receivable asset.
In an IT environment, the information needed to perform substantive tests (such as
account balances, names and addresses of individual customers) is contains in data
files that often must be extracted using Computer-Assisted Audit Tools and
Techniques (CAATTs) software. The database approach to IT audits uses CAATTs
and substantive testing to investigate the integrity of the data. In other words, IT
auditors use CAATTs to get the data to tell them about the data’s integrity and
reliability. Later in this subject, we will examine the role of CAATTs in performing
traditional substantive tests and other data analysis and reporting tasks.
Note: Discussed above is the overview of the IT audit, as part of the first phase, audit
planning, IT auditors are required to have sufficient understanding of their client’s
internal control. Related to this, the following discussion concentrates more on
discussing about internal controls and their objectives.
IV. INTERNAL CONTROL
Organization management is required by law to establish and maintain adequate
system of internal control. The internal control system comprises policies,
practices, and procedures employed by the organization to achieve four broad
objectives:
1. To safeguard assets of the firm
2. To ensure the accuracy and reliability of accounting records and information
3. To promote efficiency in the firm’s operations
4. To measure compliance with management’s prescribed policies and
procedures.
A. Modifying Assumptions
1. Management responsibility
This concept holds that the establishment and maintenance od a system of
internal control is a management responsibility.
2. Reasonable assurance
The internal control system should provide reasonable assurance that the
four broad objectives of internal control are met. This reasonable assurance
means that non system of internal control is perfect and the cost of achieving
improved control should not outweigh its benefits.
lOMoARcPSD|51817568
3. Methods of data collection
The internal control system should achieve the four broad objectives
regardless of the data processing method used (e.g., paper-based, computer-
based, web-based). However, the specific techniques used to achieve these
objectives will vary with different types of technology.
4. Limitations
Every system of internal control has limitations on its effectiveness. These
include the possibility of error- no system is perfect, circumvention-personnel
may circumvent the system through collusion or other means, management
override- management is in a position to override control procedures by
personally distorting transactions or by directing a subordinate to do so, and
changing conditions- conditions may change over time so that existing
effective controls may become ineffectual.
V. COMPONENTS OF INTERNAL CONTROL
1. The control environment
The control environment sets the tone for the organization and influences the
control awareness of its management and employees. It has several important
elements:
• The integrity and ethical values of management
• The structure of the organization
• The participation of the organization’s board of directors and the audit
committee, if one exists
• Management philosophy and operating style
• The procedures for delegating responsibility and authority
• Management’s method of assessing performance
• External influences, such as examinations by regulatory agencies
• The organization’s policies and practices for managing its human resources
Auditors should obtain sufficient knowledge to assess the attitude and awareness
of the organization’s management, board of directors, and owners regarding
internal control.
2. Risk assessment
Organizations must perform a risk assessment to9 identify, analyze, and manage
risks relevant to financial reporting. Risks can arise out of changes in
circumstances, such as the following:
• Changes in operating environment that imposes new competitive pressures
on the firm
• New or reengineered information systems that affect transaction processing
• The implementation of new technology into the production process or
information system that impacts transaction processing. Etc.
Auditors are required to obtain sufficient knowledge on the organization’s risk
assessment procedures to understand how management identifies, prioritizes,
and manages the risk related to financial reporting.
3. Information and Communication
An effective accounting information system will do the following:
• Identify and record all valid financial transactions
• Provide timely information about transactions in sufficient detail to permit
proper classification and financial reporting
lOMoARcPSD|51817568
• Accurately measure the financial value of transactions so their effects can be
recorded in financial statements
• Accurately records transactions in the time period in which they occur
Auditors are required to obtain sufficient knowledge of the organization’s
information system to understand these aspects:
• The classes of transactions that are material to the financial statements and
how these transactions are initiated
• The accounting records and accounts that are used in the processing of
material transactions
• The transaction processing steps involved from the initiation of an economic
event to its inclusion in the financial statements
• The financial reporting process used to prepare financial statements,
disclosures, and accounting estimates.
4. Monitoring
Management must determine that internal controls are functioning as intended.
5. Control Activities
Control activities are the policies and procedures used to ensure that appropriate
actions are taken to deal with the organization’s identified risks. Control activities
can be grouped into two distinct categories: computer controls and physical
controls.
a. Computer controls
Computer controls relate specifically to the IT environment and IT auditing. It
has two broad groups:
1) General controls
✓ Pertain to entity-wide concerns such as controls over the data center,
organization databases, system access, systems development, and
program maintenance.
2) Application controls
✓ Ensure the integrity of specific systems such as sales order, processing,
accounts payable, and payroll applications. Later in this subject, we
will discuss general and application controls in detail and the risk in
which they relate.
b. Physical controls
Relate primarily to traditional accounting systems that employ manual
procedures. However, an understanding of these control concepts also gives
insights to the risks and control concerns associated with the IT environment.
We will be concentrating more in the IT implications. Implications in the
manual system will be discussed in Auditing theory.
1) Independent verification
✓ Verification procedures are independent checks of the accounting
system to identify errors and misrepresentations. Independent
verification control is needed in the manual environment because
employees sometimes make mistakes or forget to perform necessary
tasks.
✓ In an IT environment, computer programs perform many routine tasks.
Most of our concerns rest with application integrity. For example, after
data have been entered into the system, check programs can be run to
lOMoARcPSD|51817568
look for anomalies such as blank fields, values out of range, or missing
foreign keys. The report from this check program can therefore be used
to verify data integrity after keypunching (i.e., after the application has
run).
✓ In the IT environment, IT auditors perform an independent verification
function by evaluating controls over systems development and
maintenance activities and occasionally by reviewing the internal logic
of programs.
2) Transaction authorization
✓ The purpose of transaction authorization is to ensure that all material
transactions processed by the information systems are valid and in
accordance with management’s objective.
✓ In an IT environment, transaction authorization may consist of coded
rules embedded within computer programs. For example, a program
module in a purchase system will determine when, how much, and
from which vendor inventory items are recorded. Such transactions
may be initiated automatically and without human involvement.
Within this setting, it may be difficult for auditors to assess whether
these transactions are in compliance with management’s objectives.
For instance, is the organization buying inventory only when it is
needed? Are correct quantities being purchased only from approved
vendors? Because automated authorization procedures are unobserved
by management, control failure may go unnoticed until the firm
experiences some adverse symptoms. In the case of purchases
authorization, symptoms of a problem may take the form of an
inventory stock out or an excessive buildup of inventory. Controls may
also be circumvented to perpetrate fraud. Unfortunately, by the time
the problem is recognized, the firm may have incurred substantial
financial losses.
✓ In an IT environment, the responsibility for achieving the control
objectives of transaction authorization rests directly on the accuracy
and consistency (integrity) of the computer programs that perform
these tasks.
3) Segregation of duties
✓ One of the most important control activities is segregation of employee
duties to minimize incompatible functions.
✓ In an IT environment, segregation of duties is not identical to that of
manual environment. Computer programs typically perform tasks that
are deemed incompatible in manual system. For example, a program
may be solely responsible for authorizing a purchase, processing the
purchase order, and recording the accounts payable. When the
suppliers invoice arrives, the computer will also determine the timing
and amount of the payment to be made. In manual system, segregation
is necessary to avoid human mistakes or fraud. However, in a
computerized system, computers do not commit mistakes or perpetrate
fraud not unless there is error in programming which is a human error
still.
lOMoARcPSD|51817568
✓ Segregation of duties still plays a role in the IT environment. However,
the IT auditor’s attention must be redirected to those activities that
threaten application integrity. For example, once the proper
functioning of a program is established at system implementation, its
integrity must be preserved throughout the application’s life cycle. The
activities of program development, program operations, and program
maintenance are critical It functions that must be adequately
separated.
4) Supervision
✓ Segregation of duties in manual system is not always applicable to
small entities. Hence, the management must compensate for the
absence of segregation controls with close supervision.
✓ In an IT environment, supervisory control must be more elaborate than
in manual system for three reasons. Fist is the problem of attracting
competent employees. I this field of expertise, there is very high
turnover of employees resulting to staffing complications which
frustrates management’s ability to assess the competence of
prospective employees. Second reason reflects the management’s
concern over the trustworthiness of the data processing personnel in
high risk areas. Some systems professionals serve in positions of
authority that permit direct and unrestricted access to the
organization’s programs and data. The combination of technical skills
and opportunity in the hands of an individual who may be mischievous
or corrupt, represents a significant risk to the organization. Third
reason is management’s inability to adequately observe employees in
an IT environment. The activities of employees engaged in data
processing are frequently hidden from management’s direct
observation. Supervisory controls must therefore be designed into the
computer system to compensate for the lack of direct supervision.
5) Accounting records
✓ The traditional accounting records of an organization consist of source
documents, journals, and ledgers. These records capture the economic
essence of transactions and provide an audit trail of economic events.
The audit trails enables the auditor to trace any transaction through
all phases of its processing from the initiation of the event to the
financial statements.
✓ The obligation to maintain an audit trail exists in an IT environment
just as it does in a manual setting. However, automated accounting
records and audit trails are very different from those in manual
systems. Some computer systems maintain no physical source
documents. Journals and ledgers often do not exist in the traditional
sense. Instead, records of transactions and economic events are
fragmented across several normalized database tables. Audit trails may
take the form of pointers, hashing techniques, indexes, or embedded
keys that link record fragments between and among the database
tables. To meet their responsibilities, auditors must understand the
operational principles of the database management systems in use and
the effects on accounting records and audit trails of alternative file
structures.
lOMoARcPSD|51817568
✓ In the IT environment, part or all of the audit trail is in digital form.
Because it resides on computers in files, if at all, it is basically invisible
to auditors. Therefore, it is imperative in the IT environment that
programmers and analysts understand the importance of logs, and
how to capture a sufficient amount of data for audit trail purposes. For
example, in file maintenance programs, the programmer should
capture the values and data prior to the changes, and the new values
after the changes, a reason for the changes (keyed by the operator), the
operator’s identification (user id, IP address, etc.), and a date-time
stamp. Such information builds an effective audit trail that with a
CAAT or query can be printed for the benefit of the IT auditors.
6) Access controls
✓ The purpose of access control is to ensure that only authorized
personnel have access to the firm’s assets.
✓ In the IT environment, accounting records are often concentrated
within the data processing center on mass storage devices. Data
consolidation exposes the organization to two forms of threat: the
computer fraud and losses from disaster. Fraud occurs when
individual with proper skills and unrestricted access perpetrate
fraud. It is easily done because often times the records are in one
location and the perpetrator does not need to gain access to several
places and more likely to be achieved without detection. Disasters
such as fires also may cause firms to lose files.
✓ Access control in an IT environment covers many levels of risk.
Controls that address these risks include techniques designed to
limit personnel access authority, restrict access to computer
programs, provide physical security for the data processing center,
ensure adequate back up for data files, and provide disaster
recovery capability. Some access controls are technological
procedures and devices, while others are physical barriers
implemented through organizational segregation of duties.