Digital Auditing: Enhancing IT Assurance
Digital Auditing: Enhancing IT Assurance
AND ASSURANCE
DIGITAL AUDIT
When using digital techniques and automation, organizations should consider the following:
1|Page
Ensure processes are standardized and functioning correctly before automating, as bots
cannot easily adapt to process changes.
Be aware that automation introduces new challenges for organizations.
Do not neglect governance and data security in risk management.
New activities or changes in processes due to technology (e.g., new revenue streams,
automation of manual tasks, staff changes) may impact internal controls.
Changes in system development and maintenance might introduce new risks, requiring
new controls.
New technology may affect how an organization generates or uses information to support
internal control.
This section focuses on how digital auditing impacts professional ethics, how it changes
auditing methods, and the role of technology in improving auditing practices.
AUDITING DIGITALLY
Auditing Digitally uses technology advancements for efficient and effective audits. With the
growing IT environment, adapting technology in audits is essential. It helps capture data,
automate procedures, analyze information, and focus on real risks. For example, AI tools can
identify patterns in financial data. Auditors need to understand how technology can aid in
auditing challenges.
Audit teams should involve experts in software and technology. Having knowledge in
technologies like RPA, AI, and blockchain helps auditors deliver high-quality audits.
Investing in upskilling is key for quality audits. Automation tools like data analytics are
improving audit quality, and advanced technologies such as AI and drones can bring even
more impact.
Improved Quality of Audits: Automation and data analytics allow auditors to move from
sample auditing to reviewing all transactions. This frees up time to analyze information
and understand the business better. However, initial investment and resource allocation
are necessary.
Decreasing Human Dependency: Using technology reduces manual intervention,
minimizing the risk of human error. For example, automation can streamline testing,
reducing errors from human judgment.
Increased Transparency: Technology increases transparency, as modern ERPs have audit
trails to trace transactions. For instance, auditors can see when a change occurred, who
made it, and what was changed.
Automation and Ease: Automating tasks like data extraction and sampling reduces
manual errors. Using tools like dashboards (e.g., Power BI) for reporting helps auditors
form opinions based on clear visual data.
Improved Efficiency: Technology simplifies processes that once required experts,
increasing efficiency with fewer errors. For example, simple training can help auditors
use complex tools. This leads to higher talent retention and confidence in audit results.
2|Page
Better Risk Assessment: Automation allows auditors to focus on real challenges and
assess risks more accurately. For example, tools like dashboards help identify areas
needing more attention, enabling auditors to make informed decisions.
While industries are impacted by emerging technologies, auditors must assess their unique
needs. There are a few critical questions to ask at each stage of digital technology adoption.
Evaluate emerging technologies and tools to identify what will benefit the audit. Think about
how technology can make auditing easier and improve outcomes, then measure the return on
investment.
There are various tools for data acquisition, manipulation, and visualization. Consider how
these solutions will integrate into current processes and identify potential issues early.
HOW WILL YOU UPSKILL YOUR PEOPLE TO MAKE BEST USE OF THE
TECHNOLOGY AVAILABLE?
Technology is only effective if the team can use it properly. Continuous training and
development are vital for teams to understand the tools and their purpose. For example,
helping staff adjust to AI tools can improve audit outcomes.
There are various automation solutions ranging from basic to advanced, helping standardize
tasks and optimize efforts. Some examples include:
Understanding how an entity uses IT helps auditors identify potential risks in the IT
environment (as per SA 315). This involves knowing how IT supports the business. For
example, an auditor may look into how a company uses SAP for transactions.
Understanding how IT is used helps identify controls over the entity's IT processes, making
audits more thorough. For example, understanding the ERP system can reveal controls for
financial transactions.
The applications used by the company: Understanding which software and systems are
utilized, such as SAP or custom-built applications.
Details of the IT infrastructure for each application: This includes the servers, storage
systems, and operating systems used by the applications. For example, SAP might use
Oracle 19c as its database.
The organization structure and governance: How the IT systems are managed within the
company, such as the roles of IT teams.
The policies, procedures, and processes followed: Identifying how IT policies are
implemented to ensure proper controls and management of IT systems.
Extent of IT integration and use of service organizations: Whether the company integrates
IT systems across departments or relies on third-party service providers.
IT risks and controls: Assessing potential risks from IT systems, such as data breaches,
and how these risks are controlled within the company.
An example of how auditors document details of an automated environment might look like:
The auditor should understand how transactions flow through IT applications and systems.
Changes in how transactions flow, such as database updates, can affect the audit. For
example, if a company updates its billing system, it might change how transactions are
processed.
The auditor identifies key IT applications and systems that handle significant transactions and
account balances. For example, a company may use SAP for financial transactions and
inventory management.
An entity may use both manual and automated controls in its IT environment. Auditors need
to assess how both types of controls work to prevent errors or fraud. For example, automated
tools may validate financial data, while manual controls may oversee financial approvals.
Auditors must understand emerging technologies like blockchain or AI that are being used in
financial reporting and information processing. The use of these technologies may introduce
new risks. For example, cryptocurrency exchanges using blockchain may involve different
risks than traditional transactions.
The complexity of the IT environment varies across applications. Auditors assess this
complexity based on factors such as automation, reliance on system-generated reports,
customization, and use of emerging technologies. For example, a business using robotics for
inventory management would have a more complex IT environment than one using simple
spreadsheets.
4|Page
IDENTIFYING THE RISKS ARISING FROM USAGE OF IT
To identify risks from IT usage, auditors examine the nature of IT applications used by the
company. Risks may also relate to cybersecurity. High volume or complex automated
applications increase IT risk. For example, a company relying heavily on automated financial
reports may face higher risks if the controls fail.
Risks arising from the use of IT include cybersecurity threats. The more complex and
automated the application controls, the greater the risk. For instance, if an organization relies
on IT to process transactions without robust security, unauthorized data changes or fraud can
occur.
Unauthorized access to data: Risks include data destruction or unauthorized changes, such
as recording non-existent transactions. A shared database increases this risk. For example,
multiple employees accessing the same financial data could lead to errors.
Excessive access privileges for IT personnel: IT staff gaining access beyond their role
could break segregation of duties. For instance, an IT employee with both development
and production access could make unauthorized changes to critical data.
Unauthorized changes to IT applications or environment: Changes to IT systems that are
not approved could cause data inaccuracies or disrupt operations. For example, an
unapproved update to an accounting system might lead to incorrect financial reports.
Failure to update IT systems: If IT applications aren’t updated regularly, vulnerabilities
can arise, allowing cyberattacks. For example, outdated antivirus software can lead to a
system breach.
Inappropriate manual intervention: Manual interventions in automated systems might
bypass controls and lead to errors or fraud. For instance, altering transaction records
manually might lead to incorrect financial reporting.
Data loss or corruption: Data can be lost or corrupted if proper cybersecurity controls
aren’t in place. Hackers might encrypt data or steal it. For example, a ransomware attack
can lead to loss of sensitive customer data.
System downtime: Hardware failures, cyberattacks, or power outages can cause systems
to be unavailable, which can disrupt business operations. For instance, a server crash
might halt all customer orders on an e-commerce platform.
System integration and compatibility risks: Problems arise when different IT systems or
versions don’t work well together. For example, a company using an outdated version of
its financial software might face integration issues with a new payroll system.
Compliance risks: Changes in laws and regulations can impact the business and its costs.
For instance, new data protection laws may require changes in how customer data is
handled and increase compliance costs.
Performance issues: Heavy data loads or poor network performance can affect system
responsiveness. For example, slow response times when processing customer orders
during peak hours may require additional hardware resources.
5|Page
Identifying IT dependencies helps auditors understand how the business relies on IT, the
integration of IT into business operations, and potential risks. It also helps develop an
efficient audit approach, ensuring IT risks are addressed. For example, knowing that a
company depends on automated invoicing will guide the auditor in testing relevant controls.
TYPES OF IT DEPENDENCIES
Automated Controls: Controls embedded in the IT system to enforce business rules. For
example, a system may automatically flag duplicate customer numbers during data entry.
Reports: System-generated reports are used for testing and decision-making. For instance,
a vendor master report might help auditors confirm supplier transactions during an audit.
Calculations: IT systems perform calculations instead of humans, like calculating
depreciation on assets. For example, an accounting system will calculate asset
depreciation based on predefined formulas.
Security: Security controls, including segregation of duties, are managed by the IT system
to ensure restricted access. For example, an access control system may ensure only
authorized employees can modify financial data.
Interfaces: Interfaces transfer data from one IT system to another. For example, a payroll
system may send data to the general ledger for financial reporting.
IT dependencies impact how entity controls are designed and how they function. Auditors
must consider IT dependencies and evaluate risks accordingly. If controls are not functioning
as expected, the auditor may not rely on them and will need to perform manual testing.
Examples of ITGCs include ensuring access to programs and data is authorized and changes
to applications are properly tested and approved. For example, a company should have
procedures to ensure only authorized personnel can make changes to financial software.
6|Page
A cyber-attack is an attempt to gain unauthorized access to a system to cause harm, steal, or
destroy data. Regulators are focusing on cyber risk management, especially for financial
institutions, to assess and enhance cybersecurity. Common types of cyber-attacks include:
Common Cyber-Attacks
Denial-of-Service (DoS) Attacks - Floods a network with fake requests to disrupt operations.
While data loss may not occur, it costs time and resources to restore services.
Phishing - Attacks using email, phone, or social media to steal sensitive information or install
malware.
Spoofing - Cybercriminals impersonate trusted sources to steal data, install malware, or extort
money.
Insider Threats - Current or former employees who have access to sensitive data and can
cause harm.
DNS Tunneling - Uses DNS queries to bypass security and transmit malicious data.
IoT-Based Attacks - Targets Internet of Things (IoT) devices, stealing data or taking control
of devices.
Stage 2 - Impact of Cyber Risk - The impact varies depending on the type of attack. Some
possible effects include:
Stage 3 - Managing Cyber Risk - A strategic approach helps understand and mitigate cyber
risks, including:
The auditor should determine if the organization’s risk assessment process includes
cybersecurity risks.
The entity must conduct a periodic risk assessment and create a strategy for identifying
cybersecurity risks, including IT system failures, unauthorized access, or loss of data.
The organization should maintain an inventory of information assets (e.g., patents, trade
secrets) and prioritize their protection.
The organization should review how cybersecurity risks impact internal controls over
financial reporting, such as the impact on revenue recognition and financial data
recoverability.
The entity should establish clear roles and responsibilities for cybersecurity (e.g., CISO,
CIO).
The entity must safeguard its assets from cyber risks by monitoring unauthorized access and
implementing data security controls.
The entity should have processes to identify and protect critical digital assets, such as
intellectual property, from cybersecurity threats.
The entity should have controls to detect cybersecurity risks and incidents, assess their
impact, and make timely disclosures.
In the case of a cybersecurity or data breach, the entity should document the nature of the
incident, assess its impact, and communicate the information to responsible parties and
governance.
8|Page
The entity should have a security incident response plan to mitigate damage and prepare for
potential litigation and regulatory investigations.
The organization should take necessary steps to recover from cyber-attacks, restoring
business operations and minimizing impact.
The recovery plan should involve improvements like patch upgrades, better controls, and
enhanced technology tools (e.g., firewalls, anti-virus).
Management should have strong internal controls, along with cybersecurity policies and
frameworks, to protect against cyber risks.
Vendor Setup and Modifications: Cyber schemes may request changes to vendor
information via phishing emails, causing inappropriate funds transfer.
Who is responsible for vendor data changes? Is the process centralized or decentralized?
Are communication channels like email used for vendor data changes? Is multi-factor
authentication in place for emails?
What systems are used to process changes to vendor data?
Are there authentication protocols, such as callback procedures, for verifying changes to
vendor data?
Electronic Transfer of Funds: Phishing scams may also request wire transfers or funds
from customer accounts.
REMOTE AUDIT
Remote audits involve using electronic means to gather audit evidence, either partially or
completely virtual. Planning is crucial, especially considering how the COVID-19 pandemic
changed the business landscape.
Feasibility and Planning: Agreement on audit timelines, platforms (Zoom, Teams, Google
Meet), and data exchange methods are necessary. Consider technology availability and
competency of both auditors and auditees.
Confidentiality and Security: To ensure data privacy, access to document sharing
platforms should be restricted and encrypted. Compliance with relevant regulations is
crucial, and auditees' consent is needed before capturing any screenshots.
9|Page
Auditors should use a VPN (Virtual Private Network) when accessing auditee’s IT
systems to ensure security and privacy.
Risk Assessment: Clear communication is critical. Auditors must assess if remote audits
will meet audit objectives.
Advantages:
• Cost and Time Efficient: No travel expenses, auditors work from home.
• Flexibility: Auditors can conduct audits remotely, saving time and costs.
Disadvantages:
• Limited Physical Presence: Cannot observe organization culture or auditee’s body language.
• Increased Risk of Security Violations: Remote audits may lead to increased potential for
security breaches.
• Limited Physical Verification: Physical verification of assets and stock taking cannot be
performed remotely.
Remote audits provide assurance during times like COVID-19, offering cost savings and
operational flexibility. Management must ensure secure systems (e.g., VPN access), and
auditors should follow stringent security protocols when conducting remote audits.
Emerging technologies like Data Analytics, Artificial Intelligence (AI), Robotic Process
Automation, and Blockchain are changing the way audits are conducted. These technologies
are transforming business processes, and auditors are adopting them to enhance their own
processes.
Data Analytics in auditing involves analyzing large sets of data to identify patterns, trends,
and anomalies. This helps auditors make informed decisions and improve audit quality.
10 | P a g e
Audit Analytics: This involves using data to uncover actionable insights, such as
identifying trends and anomalies in business processes. For example, auditors can analyze
sales data to detect irregularities or fraud.
Purpose of CAATs: CAATs help auditors find and analyze patterns, detect anomalies,
and extract useful information from large data sets. This minimizes the risk of missing
critical data. For example, an auditor could use CAATs to identify discrepancies in a
client’s financial records.
Auditors use various tools as part of CAATs to enhance the audit process.
ACL (Audit Command Language): ACL is a data analysis tool used to detect fraud and
control weaknesses by analyzing large data sets and identifying irregularities. For
example, ACL could help an auditor discover patterns in financial transactions that
suggest fraud.
Alteryx: Alteryx consolidates data and provides an audit trail for every action performed,
making it user-friendly even for those without coding experience. It is useful for
automating tasks such as reconciliations and tax filings. Alteryx can also apply machine
learning to identify patterns suggesting fraud. For example, it can automatically check for
discrepancies in invoices or receipts.
Power BI: Power BI is a visualization tool that helps auditors find outliers in data and
create interactive reports. It can be used to display audit findings, like a dashboard that
shows financial anomalies or trends to senior management.
CaseWare: CaseWare is a software platform for conducting audits efficiently. It helps
auditors perform tasks quickly and accurately, providing analytical insights to support
better decision-making. For example, CaseWare helps auditors streamline processes by
automating routine tasks like data extraction and report generation.
These tools are becoming increasingly essential for auditors to perform audits more
effectively, saving time and reducing the risk of missing important details.
Enterprises are rapidly adopting emerging technologies like Robotic Process Automation
(RPA), blockchain, Machine Learning (ML), Internet of Things (IoT), and Artificial
Intelligence (AI) to create synergies and enhance business operations. These technologies are
reshaping auditing, requiring auditors to adapt and perform procedures on a broader range of
systems that affect financial statements.
Automation technologies like RPA, blockchain, ML, IoT, and AI are transforming audits by
enabling auditors to analyze large datasets and complex systems. Auditors now need to
evaluate not only financial transactions but also the IT systems supporting these transactions.
11 | P a g e
INTERNET OF THINGS (IOT)
IoT refers to the network of devices connected to the internet, such as phones, appliances, and
even machines. These devices collect and analyze data, which can change business models
and strategic goals, as well as introduce new risks.
Audit Implications: Auditors must expand their scope to include IoT systems, especially
when traditional manual controls are no longer sufficient. New automated systems must
be assessed for security, efficiency, and accuracy. For example, payment systems linked
to mobile devices might introduce new risks related to transaction handling and service
providers.
Common Risks of IoT: IoT devices come with risks like hijacking, data theft, service
attacks, and breaches. For instance, hackers might gain unauthorized access to a
company's network through IoT-connected devices, posing a security threat.
AI refers to machines that learn and make decisions based on data analysis and predictive
algorithms. AI systems are used to automate tasks and enhance decision-making.
Audit Implications: Auditors need to examine AI algorithms, assess potential biases, and
review the quality of decision-making processes driven by AI. For example, if a company
uses AI to predict stock prices, auditors must ensure the AI system’s accuracy and
fairness. Additionally, cybersecurity concerns must be considered since AI relies heavily
on software modules.
Common Risks of AI: Key risks include security vulnerabilities, poor configuration, and
data privacy concerns. For example, AI used in medical diagnostics may fail if
misconfigured, potentially leading to harmful outcomes.
BLOCKCHAIN
Audit Implications: Auditors must ensure proper governance and security of blockchain
transactions, especially as they interact with legacy systems. Risks include insecure APIs,
data privacy issues, and cross-border data transmission, which could lead to
noncompliance with regulations.
Common Risks of Blockchain: Blockchain’s immutability can be both an advantage and a
drawback. The inability to reverse transactions means errors cannot be easily corrected.
Furthermore, blockchain can be susceptible to cyber-attacks, and inadequate management
processes could expose organizations to vulnerabilities.
NFTs are unique digital assets secured by blockchain, representing ownership of items like
art, music, and collectibles. Unlike cryptocurrencies, NFTs cannot be exchanged for one
another due to their unique properties.
Key Features of NFTs: NFTs are digital assets representing collectibles with a
blockchain-backed certificate of authenticity. For instance, owning an NFT could
represent exclusive ownership of a digital painting.
Challenges of NFTs: NFTs face challenges such as ownership and copyright disputes,
security risks, limited market, and the potential for online fraud. Auditors must review
12 | P a g e
NFT code, ensure data privacy, and assess the security of NFT contracts to mitigate these
risks.
RPA is the automation of repetitive tasks performed by humans using software bots that
mimic human actions. These bots work around the clock with high precision and speed.
Audit Implications: Auditors need to understand RPA processes like data extraction,
cleansing, and aggregation. They should also review the source code of RPA systems,
verify logs, and evaluate access controls. For example, an auditor might review an RPA
bot used to process payroll transactions, ensuring it operates correctly and securely.
Common Risks of RPA: RPA risks include operational issues like choosing the wrong
tool, poor execution, or failing to account for security and compliance. Additionally,
improper change management and misaligned expectations could lead to audit errors.
By incorporating auditing standards such as IND AS, IFCoFR, and Standards on Auditing
with RPA, auditors can improve financial reporting and internal controls. RPA developers
and auditors should work together to ensure that RPA workflows align with relevant
standards and improve audit accuracy and efficiency.
Emerging technologies bring many benefits but also substantial risks. Auditors need to adapt
to these changes and assess technology risks properly to ensure the accuracy of financial
statements.
Auditors must focus on key control considerations to evaluate how new technologies impact
business operations and financial reporting. This helps in assessing risks introduced by
emerging technologies such as automation or cloud systems.
13 | P a g e
Unauthorized access to data leading to data loss or changes to data, like unauthorized
transactions or modification of records. For instance, if a system allows multiple users to
access a common database, it may lead to unauthorized data changes.
IT personnel having excessive access rights that violate segregation of duties. For
example, an employee who can approve transactions and also modify the database could
exploit their position for fraudulent activity.
Unauthorized changes to master data files, which could affect key accounting information
like customer details or payment terms.
Changes to systems or programs without proper authorization, which could result in
unintended disruptions to financial reporting processes.
Failure to update systems or programs appropriately, leading to outdated or ineffective
controls, such as using an old version of accounting software that no longer meets
regulatory standards.
Inappropriate manual intervention, such as manually altering system settings that could
affect the accuracy of financial data.
Risks from using third-party providers, such as cloud services or outsourced IT services,
where their lack of security could expose the company to breaches.
Cybersecurity risks, including hacking, phishing, and other attacks that might
compromise the integrity of financial data.
As auditors understand the impact of technology on businesses, they should remember some
key steps to adapt to new technological environments while maintaining effective audits.
The Next Generation Audit is a human-led, tech-powered, and data-driven approach that
combines emerging technologies to redefine auditing practices.
The main aim of the Next Generation Audit is to improve efficiency, accuracy, and insight
through advanced technologies.
The use of emerging technologies such as drones, augmented reality (AR), virtual reality
(VR), and more are revolutionizing auditing practices.
Drones are used for stock counts and fixed asset audits in remote areas, offering great
payload capacity for sensors and cameras.
Drone technology improves audit quality and speed by combining data captured by drones
with other sources like QR codes, handheld scanners, and manual counts.
AR overlays digital elements onto real-world environments, enhancing the user experience. A
famous example is Pokémon Go, where players chase digital creatures in real-world
locations.
VR creates a simulated environment, replacing the real world. It can be used for experiences
like flying or skydiving through special equipment.
The Metaverse is an immersive 3D digital space combining VR, AR, AI, and cryptocurrency,
enabling virtual experiences and transactions.
15 | P a g e
Virtual Banking and Transactions: Financial institutions establish virtual branches in the
Metaverse to offer services such as virtual bank accounts, personalized dashboards, and
transactions with virtual currencies.
Digital Asset Management: Companies can facilitate buying and selling NFTs and virtual
assets in a decentralized platform within the Metaverse.
Virtual Financial Education: Interactive learning environments within the Metaverse for
financial literacy, including simulated investment and trading experiences.
Virtual Meetings and Conferences: Virtual conferences in the Metaverse, where
participants can interact and attend events using avatars.
Data Visualization and Analytics: The Metaverse enables financial professionals to
analyze and visualize complex data in immersive 3D environments, aiding decision-
making.
While emerging technologies provide great benefits, they also introduce new risks such as
public safety, cybersecurity, data privacy, and data protection issues.
Regulators and auditors need to address privacy, security, and governance concerns to make
digital systems more regulated and secure.
CONCLUSION
Emerging technologies bring both opportunities and risks to businesses. Auditors need to
strike a balance between technology costs and benefits while ensuring proper controls are in
place.
Though auditors do not need to be experts in every technology, they must understand its
risks, internal controls, and integration with business processes.
16 | P a g e