0% found this document useful (0 votes)
10 views16 pages

Digital Auditing: Enhancing IT Assurance

A Digital Audit evaluates the effectiveness of IT systems in organizations, ensuring compliance and identifying risks while enhancing audit quality and efficiency through automation. Key advantages include improved risk assessment, lower costs, and better analytics, although challenges such as governance and data security must be addressed. Auditors are encouraged to embrace technology, upskill their teams, and understand IT dependencies to effectively manage cyber risks and enhance auditing practices.

Uploaded by

umvishnu.97
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
10 views16 pages

Digital Auditing: Enhancing IT Assurance

A Digital Audit evaluates the effectiveness of IT systems in organizations, ensuring compliance and identifying risks while enhancing audit quality and efficiency through automation. Key advantages include improved risk assessment, lower costs, and better analytics, although challenges such as governance and data security must be addressed. Auditors are encouraged to embrace technology, upskill their teams, and understand IT dependencies to effectively manage cyber risks and enhance auditing practices.

Uploaded by

umvishnu.97
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

CHAPTER 12: DIGITAL AUDITING

AND ASSURANCE
DIGITAL AUDIT

WHAT IS A DIGITAL AUDIT?

A Digital Audit ensures the effectiveness of IT systems within an organization. As


technology is crucial to daily operations, organizations need to review their technology-
related controls to spot gaps and risks, ensuring continuous improvement and regulatory
compliance. A strong control position helps build trust with stakeholders.

KEY FEATURES OF A DIGITAL AUDIT

 Digital audit encourages embracing technological advancements, ensuring auditees stay


updated in a rapidly evolving environment.
 It improves the quality of the audit opinion, leading to more reliable audit reports.
 Digital Audit saves time, cost, and human effort, allowing more productive tasks. It helps
automate processes that operate 24/7, handling real-time transactions.
 It standardizes processes and implements controls to mitigate risks.
 Digital audit gives a comprehensive overview of end-to-end processes, showing how
technologies are utilized, controlled, and optimized against set standards.
 It helps create a future digital strategy and facilitates adopting technologies like AI,
robotics, analytics, and automation.
 It aids the auditee in making informed decisions.

DIGITAL AUDITING AND ASSURANCE

ADVANTAGES OF DIGITAL AUDIT

 Enhanced Effectiveness & Efficiency: Digital audit increases efficiency by automating


routine tasks (e.g., automating reconciliation), saving time and costs.
 Better Audit Quality: Technology enables auditors to process large data volumes quickly,
helping them focus on areas needing more attention, reducing the chance of
misstatements or overlooked issues.
 Lower Costs: Automation reduces the time and effort spent on manual tasks, decreasing
the overall cost of auditing.
 Better Analytics: Advanced analytics helps detect trends and patterns, like AI spotting
possible fraud in financial data, which is difficult to identify manually.
 Improved Risk Assessment: Automations assist in identifying risks and help focus testing
on high-risk areas, enhancing informed decision-making.

CONSIDERATIONS AND CHALLENGES OF DIGITAL AUDIT

When using digital techniques and automation, organizations should consider the following:

 Understand the business benefits expected from automation.


 Prioritize people and acknowledge that change can be difficult.
 Target the right processes for automation to ensure success.
 Automation should be part of a broader digitalization strategy, not a standalone solution.

1|Page
 Ensure processes are standardized and functioning correctly before automating, as bots
cannot easily adapt to process changes.
 Be aware that automation introduces new challenges for organizations.
 Do not neglect governance and data security in risk management.

Some additional points to consider are:

 New activities or changes in processes due to technology (e.g., new revenue streams,
automation of manual tasks, staff changes) may impact internal controls.
 Changes in system development and maintenance might introduce new risks, requiring
new controls.
 New technology may affect how an organization generates or uses information to support
internal control.

ADVANCED AUDITING, ASSURANCE AND PROFESSIONAL ETHICS

This section focuses on how digital auditing impacts professional ethics, how it changes
auditing methods, and the role of technology in improving auditing practices.

AUDITING DIGITALLY

WHAT IS THE CONCEPT OF AUDITING DIGITALLY?

Auditing Digitally uses technology advancements for efficient and effective audits. With the
growing IT environment, adapting technology in audits is essential. It helps capture data,
automate procedures, analyze information, and focus on real risks. For example, AI tools can
identify patterns in financial data. Auditors need to understand how technology can aid in
auditing challenges.

EXPECTATIONS FROM AN AUDITOR

Audit teams should involve experts in software and technology. Having knowledge in
technologies like RPA, AI, and blockchain helps auditors deliver high-quality audits.
Investing in upskilling is key for quality audits. Automation tools like data analytics are
improving audit quality, and advanced technologies such as AI and drones can bring even
more impact.

KEY FEATURES OR ADVANTAGES OF AUDITING DIGITALLY

 Improved Quality of Audits: Automation and data analytics allow auditors to move from
sample auditing to reviewing all transactions. This frees up time to analyze information
and understand the business better. However, initial investment and resource allocation
are necessary.
 Decreasing Human Dependency: Using technology reduces manual intervention,
minimizing the risk of human error. For example, automation can streamline testing,
reducing errors from human judgment.
 Increased Transparency: Technology increases transparency, as modern ERPs have audit
trails to trace transactions. For instance, auditors can see when a change occurred, who
made it, and what was changed.
 Automation and Ease: Automating tasks like data extraction and sampling reduces
manual errors. Using tools like dashboards (e.g., Power BI) for reporting helps auditors
form opinions based on clear visual data.
 Improved Efficiency: Technology simplifies processes that once required experts,
increasing efficiency with fewer errors. For example, simple training can help auditors
use complex tools. This leads to higher talent retention and confidence in audit results.
2|Page
 Better Risk Assessment: Automation allows auditors to focus on real challenges and
assess risks more accurately. For example, tools like dashboards help identify areas
needing more attention, enabling auditors to make informed decisions.

CONSIDERATIONS IN AUDITING DIGITALLY

While industries are impacted by emerging technologies, auditors must assess their unique
needs. There are a few critical questions to ask at each stage of digital technology adoption.

WHAT PROBLEMS ARE YOU TRYING TO SOLVE?

Evaluate emerging technologies and tools to identify what will benefit the audit. Think about
how technology can make auditing easier and improve outcomes, then measure the return on
investment.

WHICH TECHNOLOGY CAN HELP YOU?

There are various tools for data acquisition, manipulation, and visualization. Consider how
these solutions will integrate into current processes and identify potential issues early.

HOW WILL YOU UPSKILL YOUR PEOPLE TO MAKE BEST USE OF THE
TECHNOLOGY AVAILABLE?

Technology is only effective if the team can use it properly. Continuous training and
development are vital for teams to understand the tools and their purpose. For example,
helping staff adjust to AI tools can improve audit outcomes.

RANGE OF AUTOMATED SOLUTIONS

There are various automation solutions ranging from basic to advanced, helping standardize
tasks and optimize efforts. Some examples include:

 Macros and Scripts: Rules-based automation within specific applications.


 Business Process Automation (BPA): Reengineering business processes, like workflows,
to improve efficiency.
 Robotic Process Automation (RPA): Automating labor-intensive, repetitive tasks across
systems and interfaces.
 Intelligent Process Automation (IPA): Combining RPA with AI to identify patterns, learn
over time, and optimize workflows.

UNDERSTAND THE IT ENVIRONMENT

Understanding how an entity uses IT helps auditors identify potential risks in the IT
environment (as per SA 315). This involves knowing how IT supports the business. For
example, an auditor may look into how a company uses SAP for transactions.

Understanding how IT is used helps identify controls over the entity's IT processes, making
audits more thorough. For example, understanding the ERP system can reveal controls for
financial transactions.

DIGITAL AUDITING AND ASSURANCE

Assessing the IT environment's complexity helps auditors decide if IT specialists or experts


are needed during the audit. For instance, a highly automated system might require
specialized knowledge during auditing.
3|Page
THE AUDITOR’S UNDERSTANDING OF THE AUTOMATED
ENVIRONMENT SHOULD INCLUDE THE FOLLOWING

 The applications used by the company: Understanding which software and systems are
utilized, such as SAP or custom-built applications.
 Details of the IT infrastructure for each application: This includes the servers, storage
systems, and operating systems used by the applications. For example, SAP might use
Oracle 19c as its database.
 The organization structure and governance: How the IT systems are managed within the
company, such as the roles of IT teams.
 The policies, procedures, and processes followed: Identifying how IT policies are
implemented to ensure proper controls and management of IT systems.
 Extent of IT integration and use of service organizations: Whether the company integrates
IT systems across departments or relies on third-party service providers.
 IT risks and controls: Assessing potential risks from IT systems, such as data breaches,
and how these risks are controlled within the company.

An example of how auditors document details of an automated environment might look like:

KEY AREAS FOR AN AUDITOR TO UNDERSTAND IT


ENVIRONMENT

1. UNDERSTAND THE FLOW OF TRANSACTION

The auditor should understand how transactions flow through IT applications and systems.
Changes in how transactions flow, such as database updates, can affect the audit. For
example, if a company updates its billing system, it might change how transactions are
processed.

2. IDENTIFICATION OF SIGNIFICANT SYSTEMS

The auditor identifies key IT applications and systems that handle significant transactions and
account balances. For example, a company may use SAP for financial transactions and
inventory management.

3. IDENTIFICATION OF MANUAL AND AUTOMATED CONTROLS

An entity may use both manual and automated controls in its IT environment. Auditors need
to assess how both types of controls work to prevent errors or fraud. For example, automated
tools may validate financial data, while manual controls may oversee financial approvals.

4. IDENTIFICATION OF THE TECHNOLOGIES USED

Auditors must understand emerging technologies like blockchain or AI that are being used in
financial reporting and information processing. The use of these technologies may introduce
new risks. For example, cryptocurrency exchanges using blockchain may involve different
risks than traditional transactions.

5. ASSESSING THE COMPLEXITY OF THE IT ENVIRONMENT

The complexity of the IT environment varies across applications. Auditors assess this
complexity based on factors such as automation, reliance on system-generated reports,
customization, and use of emerging technologies. For example, a business using robotics for
inventory management would have a more complex IT environment than one using simple
spreadsheets.

4|Page
IDENTIFYING THE RISKS ARISING FROM USAGE OF IT

To identify risks from IT usage, auditors examine the nature of IT applications used by the
company. Risks may also relate to cybersecurity. High volume or complex automated
applications increase IT risk. For example, a company relying heavily on automated financial
reports may face higher risks if the controls fail.

HOW TO IDENTIFY THE IT RISKS?

Risks arising from the use of IT include cybersecurity threats. The more complex and
automated the application controls, the greater the risk. For instance, if an organization relies
on IT to process transactions without robust security, unauthorized data changes or fraud can
occur.

RISKS ARISING FROM USE OF IT

 Unauthorized access to data: Risks include data destruction or unauthorized changes, such
as recording non-existent transactions. A shared database increases this risk. For example,
multiple employees accessing the same financial data could lead to errors.
 Excessive access privileges for IT personnel: IT staff gaining access beyond their role
could break segregation of duties. For instance, an IT employee with both development
and production access could make unauthorized changes to critical data.
 Unauthorized changes to IT applications or environment: Changes to IT systems that are
not approved could cause data inaccuracies or disrupt operations. For example, an
unapproved update to an accounting system might lead to incorrect financial reports.
 Failure to update IT systems: If IT applications aren’t updated regularly, vulnerabilities
can arise, allowing cyberattacks. For example, outdated antivirus software can lead to a
system breach.
 Inappropriate manual intervention: Manual interventions in automated systems might
bypass controls and lead to errors or fraud. For instance, altering transaction records
manually might lead to incorrect financial reporting.
 Data loss or corruption: Data can be lost or corrupted if proper cybersecurity controls
aren’t in place. Hackers might encrypt data or steal it. For example, a ransomware attack
can lead to loss of sensitive customer data.
 System downtime: Hardware failures, cyberattacks, or power outages can cause systems
to be unavailable, which can disrupt business operations. For instance, a server crash
might halt all customer orders on an e-commerce platform.
 System integration and compatibility risks: Problems arise when different IT systems or
versions don’t work well together. For example, a company using an outdated version of
its financial software might face integration issues with a new payroll system.
 Compliance risks: Changes in laws and regulations can impact the business and its costs.
For instance, new data protection laws may require changes in how customer data is
handled and increase compliance costs.
 Performance issues: Heavy data loads or poor network performance can affect system
responsiveness. For example, slow response times when processing customer orders
during peak hours may require additional hardware resources.

KNOW HOW TO IDENTIFY THE IT DEPENDENCIES IMPACTING


THE AUDIT

WHY IS IT IMPORTANT TO IDENTIFY IT DEPENDENCIES?

5|Page
Identifying IT dependencies helps auditors understand how the business relies on IT, the
integration of IT into business operations, and potential risks. It also helps develop an
efficient audit approach, ensuring IT risks are addressed. For example, knowing that a
company depends on automated invoicing will guide the auditor in testing relevant controls.

HOW IT DEPENDENCIES ARISE?

IT dependencies arise when IT is used to initiate, authorize, record, process, or report


transactions. For example, when a company uses an IT system to calculate payroll and update
financial records, it creates an IT dependency.

TYPES OF IT DEPENDENCIES

There are five main types of IT dependencies:

 Automated Controls: Controls embedded in the IT system to enforce business rules. For
example, a system may automatically flag duplicate customer numbers during data entry.
 Reports: System-generated reports are used for testing and decision-making. For instance,
a vendor master report might help auditors confirm supplier transactions during an audit.
 Calculations: IT systems perform calculations instead of humans, like calculating
depreciation on assets. For example, an accounting system will calculate asset
depreciation based on predefined formulas.
 Security: Security controls, including segregation of duties, are managed by the IT system
to ensure restricted access. For example, an access control system may ensure only
authorized employees can modify financial data.
 Interfaces: Interfaces transfer data from one IT system to another. For example, a payroll
system may send data to the general ledger for financial reporting.

UNDERSTANDING AND RESPONDING TO IT DEPENDENCIES RISKS

Auditors need to understand how management responds to risks arising from IT


dependencies, such as implementing IT General Controls (ITGCs). If ITGCs are not properly
implemented, the auditor cannot rely on IT dependencies. For example, if the system for
managing employee access rights is not properly tested, the auditor may need to perform
additional testing.

DIGITAL AUDITING AND ASSURANCE

IT dependencies impact how entity controls are designed and how they function. Auditors
must consider IT dependencies and evaluate risks accordingly. If controls are not functioning
as expected, the auditor may not rely on them and will need to perform manual testing.

GENERAL IT CONTROLS (ITGCS)

Examples of ITGCs include ensuring access to programs and data is authorized and changes
to applications are properly tested and approved. For example, a company should have
procedures to ensure only authorized personnel can make changes to financial software.

ASSESSING CYBER RISKS (INCLUDING REMOTE AUDIT)

WHAT IS CYBER RISK

6|Page
A cyber-attack is an attempt to gain unauthorized access to a system to cause harm, steal, or
destroy data. Regulators are focusing on cyber risk management, especially for financial
institutions, to assess and enhance cybersecurity. Common types of cyber-attacks include:

Common Cyber-Attacks

 Ransomware - Encrypts data and demands payment for decryption.


 Fileless Malware - Uses system tools for attack, no installation needed.
 Trojan - Disguises itself as legitimate software to deceive users.
 Mobile Malware - Targets mobile devices via malicious downloads, phishing, or
unsecured Wi-Fi.

Denial-of-Service (DoS) Attacks - Floods a network with fake requests to disrupt operations.
While data loss may not occur, it costs time and resources to restore services.

Phishing - Attacks using email, phone, or social media to steal sensitive information or install
malware.

 Spear Phishing - Targets specific individuals or organizations for information theft.


 Whaling - Targets senior executives for sensitive data or system access.
 Smishing - Uses SMS to trick victims into revealing personal info.
 Vishing - Uses phone calls to deceive individuals into providing personal information.

Spoofing - Cybercriminals impersonate trusted sources to steal data, install malware, or extort
money.

 Domain Spoofing - Fake domain names to impersonate businesses or individuals.


 Email Spoofing - Forged sender addresses in emails to deceive recipients.

Identity-Based Attacks - Cybercriminals use compromised credentials to impersonate users.

Insider Threats - Current or former employees who have access to sensitive data and can
cause harm.

DNS Tunneling - Uses DNS queries to bypass security and transmit malicious data.

IoT-Based Attacks - Targets Internet of Things (IoT) devices, stealing data or taking control
of devices.

STAGES OF CYBER RISKS

Stage 1 - Assessing Cyber Risk - No organization is immune to cyber risks. Every


organization has different levels of risk. Common threats include:

 Ransomware attacks affecting manufacturing facilities.


 Email phishing and fraud by common criminals.
 Insiders causing unintentional or malicious data theft.

Stage 2 - Impact of Cyber Risk - The impact varies depending on the type of attack. Some
possible effects include:

 Regulatory costs and fines.


 Business interruptions affecting daily operations.
 Data and reputational loss.
 Ransomware leading to encrypted systems.
 Theft of intellectual property (IP) causing loss of competitive advantage.
 Incident response costs for investigation and remediation.
7|Page
 Privacy breach impacting consumer data.

Stage 3 - Managing Cyber Risk - A strategic approach helps understand and mitigate cyber
risks, including:

 Gaining a clear understanding of risks faced by organizations.


 Assessing existing cybersecurity programs and capabilities.
 Aligning cybersecurity with strategic objectives.
 Understanding accepted risks and compensating controls.

CYBER SECURITY FRAMEWORK

A cybersecurity framework helps an organization identify, protect, detect, respond, and


recover from cyber risks.

IDENTIFY THE RISK

The auditor should determine if the organization’s risk assessment process includes
cybersecurity risks.

The entity must conduct a periodic risk assessment and create a strategy for identifying
cybersecurity risks, including IT system failures, unauthorized access, or loss of data.

The organization should maintain an inventory of information assets (e.g., patents, trade
secrets) and prioritize their protection.

The organization should review how cybersecurity risks impact internal controls over
financial reporting, such as the impact on revenue recognition and financial data
recoverability.

The entity should establish clear roles and responsibilities for cybersecurity (e.g., CISO,
CIO).

PROTECT THE RISK

The entity must safeguard its assets from cyber risks by monitoring unauthorized access and
implementing data security controls.

Formal training should be conducted to educate teams on cybersecurity risks.

The entity should have processes to identify and protect critical digital assets, such as
intellectual property, from cybersecurity threats.

DETECT THE RISK

The entity should have controls to detect cybersecurity risks and incidents, assess their
impact, and make timely disclosures.

Continuous monitoring is required to detect security breaches or incidents (e.g., anti-virus,


firewall logs).

RESPOND TO THE RISK

In the case of a cybersecurity or data breach, the entity should document the nature of the
incident, assess its impact, and communicate the information to responsible parties and
governance.

8|Page
The entity should have a security incident response plan to mitigate damage and prepare for
potential litigation and regulatory investigations.

RECOVER FROM RISK

The organization should take necessary steps to recover from cyber-attacks, restoring
business operations and minimizing impact.

The recovery plan should involve improvements like patch upgrades, better controls, and
enhanced technology tools (e.g., firewalls, anti-virus).

CONTROL CONSIDERATIONS FOR CYBER RISKS

Management should have strong internal controls, along with cybersecurity policies and
frameworks, to protect against cyber risks.

 Vendor Setup and Modifications: Cyber schemes may request changes to vendor
information via phishing emails, causing inappropriate funds transfer.

Some control questions to consider:

 Who is responsible for vendor data changes? Is the process centralized or decentralized?
 Are communication channels like email used for vendor data changes? Is multi-factor
authentication in place for emails?
 What systems are used to process changes to vendor data?
 Are there authentication protocols, such as callback procedures, for verifying changes to
vendor data?
 Electronic Transfer of Funds: Phishing scams may also request wire transfers or funds
from customer accounts.

Some control questions to consider:

 Are personnel educated about phishing risks related to wire transfers?


 Are dual-authentication or callback procedures used to verify wire transfer requests?
 What systems are used to request and authorize wire transfers?
 Patch Management: Cyberattacks often exploit unpatched vulnerabilities, causing
damage.

Control questions to consider:

 Does the entity have a patch management program in place?


 Does the entity run vulnerability scans for missing patches?
 How is the entity notified of necessary patches from external vendors (e.g., Microsoft)?

REMOTE AUDIT

Remote audits involve using electronic means to gather audit evidence, either partially or
completely virtual. Planning is crucial, especially considering how the COVID-19 pandemic
changed the business landscape.

 Feasibility and Planning: Agreement on audit timelines, platforms (Zoom, Teams, Google
Meet), and data exchange methods are necessary. Consider technology availability and
competency of both auditors and auditees.
 Confidentiality and Security: To ensure data privacy, access to document sharing
platforms should be restricted and encrypted. Compliance with relevant regulations is
crucial, and auditees' consent is needed before capturing any screenshots.

9|Page
 Auditors should use a VPN (Virtual Private Network) when accessing auditee’s IT
systems to ensure security and privacy.
 Risk Assessment: Clear communication is critical. Auditors must assess if remote audits
will meet audit objectives.

ADVANTAGES AND DISADVANTAGES OF REMOTE AUDIT

Remote audits offer several benefits, but also face challenges.

 Advantages:

• Cost and Time Efficient: No travel expenses, auditors work from home.

• Flexibility: Auditors can conduct audits remotely, saving time and costs.

• Global Network: Can involve auditors from anywhere in the world.

 Disadvantages:

• Network Interruptions: Interviews may be affected by technical issues.

• Limited Physical Presence: Cannot observe organization culture or auditee’s body language.

• Time Zone Challenges: Different time zones can impact efficiency.

• Increased Risk of Security Violations: Remote audits may lead to increased potential for
security breaches.

• Difficulty in Verifying Documents: Remote audits increase the chances of doctored


documents being presented.

• Limited Physical Verification: Physical verification of assets and stock taking cannot be
performed remotely.

CONCLUSION ON REMOTE AUDITS

Remote audits provide assurance during times like COVID-19, offering cost savings and
operational flexibility. Management must ensure secure systems (e.g., VPN access), and
auditors should follow stringent security protocols when conducting remote audits.

EMERGING TECHNOLOGIES IN AUDIT

INTRODUCTION TO EMERGING TECHNOLOGIES

Emerging technologies like Data Analytics, Artificial Intelligence (AI), Robotic Process
Automation, and Blockchain are changing the way audits are conducted. These technologies
are transforming business processes, and auditors are adopting them to enhance their own
processes.

DATA ANALYTICS TECHNIQUES

Data Analytics in auditing involves analyzing large sets of data to identify patterns, trends,
and anomalies. This helps auditors make informed decisions and improve audit quality.

10 | P a g e
 Audit Analytics: This involves using data to uncover actionable insights, such as
identifying trends and anomalies in business processes. For example, auditors can analyze
sales data to detect irregularities or fraud.

CAATs (Computer-Assisted Auditing Techniques) are techniques used in audit analytics to


analyze data through specialized software tools. These tools help auditors examine vast
amounts of data more efficiently, increasing the audit quality.

 Purpose of CAATs: CAATs help auditors find and analyze patterns, detect anomalies,
and extract useful information from large data sets. This minimizes the risk of missing
critical data. For example, an auditor could use CAATs to identify discrepancies in a
client’s financial records.

Auditors use various tools as part of CAATs to enhance the audit process.

TOOLS USED IN AUDIT ANALYTICS (CAATS)

Some of the most popular tools used in audit analytics are:

 ACL (Audit Command Language): ACL is a data analysis tool used to detect fraud and
control weaknesses by analyzing large data sets and identifying irregularities. For
example, ACL could help an auditor discover patterns in financial transactions that
suggest fraud.
 Alteryx: Alteryx consolidates data and provides an audit trail for every action performed,
making it user-friendly even for those without coding experience. It is useful for
automating tasks such as reconciliations and tax filings. Alteryx can also apply machine
learning to identify patterns suggesting fraud. For example, it can automatically check for
discrepancies in invoices or receipts.
 Power BI: Power BI is a visualization tool that helps auditors find outliers in data and
create interactive reports. It can be used to display audit findings, like a dashboard that
shows financial anomalies or trends to senior management.
 CaseWare: CaseWare is a software platform for conducting audits efficiently. It helps
auditors perform tasks quickly and accurately, providing analytical insights to support
better decision-making. For example, CaseWare helps auditors streamline processes by
automating routine tasks like data extraction and report generation.

These tools are becoming increasingly essential for auditors to perform audits more
effectively, saving time and reducing the risk of missing important details.

AUTOMATED TOOLS IN AUDIT

INTRODUCTION TO EMERGING TECHNOLOGIES IN AUDITING

Enterprises are rapidly adopting emerging technologies like Robotic Process Automation
(RPA), blockchain, Machine Learning (ML), Internet of Things (IoT), and Artificial
Intelligence (AI) to create synergies and enhance business operations. These technologies are
reshaping auditing, requiring auditors to adapt and perform procedures on a broader range of
systems that affect financial statements.

DIGITAL AUDITING AND ASSURANCE

Automation technologies like RPA, blockchain, ML, IoT, and AI are transforming audits by
enabling auditors to analyze large datasets and complex systems. Auditors now need to
evaluate not only financial transactions but also the IT systems supporting these transactions.

11 | P a g e
INTERNET OF THINGS (IOT)

IoT refers to the network of devices connected to the internet, such as phones, appliances, and
even machines. These devices collect and analyze data, which can change business models
and strategic goals, as well as introduce new risks.

 Audit Implications: Auditors must expand their scope to include IoT systems, especially
when traditional manual controls are no longer sufficient. New automated systems must
be assessed for security, efficiency, and accuracy. For example, payment systems linked
to mobile devices might introduce new risks related to transaction handling and service
providers.
 Common Risks of IoT: IoT devices come with risks like hijacking, data theft, service
attacks, and breaches. For instance, hackers might gain unauthorized access to a
company's network through IoT-connected devices, posing a security threat.

ARTIFICIAL INTELLIGENCE (AI)

AI refers to machines that learn and make decisions based on data analysis and predictive
algorithms. AI systems are used to automate tasks and enhance decision-making.

 Audit Implications: Auditors need to examine AI algorithms, assess potential biases, and
review the quality of decision-making processes driven by AI. For example, if a company
uses AI to predict stock prices, auditors must ensure the AI system’s accuracy and
fairness. Additionally, cybersecurity concerns must be considered since AI relies heavily
on software modules.
 Common Risks of AI: Key risks include security vulnerabilities, poor configuration, and
data privacy concerns. For example, AI used in medical diagnostics may fail if
misconfigured, potentially leading to harmful outcomes.

BLOCKCHAIN

Blockchain is a decentralized ledger that ensures secure transactions through encryption.


Each transaction is validated and distributed across all participants, making it nearly
impossible to modify or delete data once it’s recorded.

 Audit Implications: Auditors must ensure proper governance and security of blockchain
transactions, especially as they interact with legacy systems. Risks include insecure APIs,
data privacy issues, and cross-border data transmission, which could lead to
noncompliance with regulations.
 Common Risks of Blockchain: Blockchain’s immutability can be both an advantage and a
drawback. The inability to reverse transactions means errors cannot be easily corrected.
Furthermore, blockchain can be susceptible to cyber-attacks, and inadequate management
processes could expose organizations to vulnerabilities.

NON-FUNGIBLE TOKENS (NFT)

NFTs are unique digital assets secured by blockchain, representing ownership of items like
art, music, and collectibles. Unlike cryptocurrencies, NFTs cannot be exchanged for one
another due to their unique properties.

 Key Features of NFTs: NFTs are digital assets representing collectibles with a
blockchain-backed certificate of authenticity. For instance, owning an NFT could
represent exclusive ownership of a digital painting.
 Challenges of NFTs: NFTs face challenges such as ownership and copyright disputes,
security risks, limited market, and the potential for online fraud. Auditors must review

12 | P a g e
NFT code, ensure data privacy, and assess the security of NFT contracts to mitigate these
risks.

ROBOTIC PROCESS AUTOMATION (RPA)

RPA is the automation of repetitive tasks performed by humans using software bots that
mimic human actions. These bots work around the clock with high precision and speed.

 Audit Implications: Auditors need to understand RPA processes like data extraction,
cleansing, and aggregation. They should also review the source code of RPA systems,
verify logs, and evaluate access controls. For example, an auditor might review an RPA
bot used to process payroll transactions, ensuring it operates correctly and securely.
 Common Risks of RPA: RPA risks include operational issues like choosing the wrong
tool, poor execution, or failing to account for security and compliance. Additionally,
improper change management and misaligned expectations could lead to audit errors.

INCORPORATING RPA WITH STANDARDS AND FRAMEWORKS

By incorporating auditing standards such as IND AS, IFCoFR, and Standards on Auditing
with RPA, auditors can improve financial reporting and internal controls. RPA developers
and auditors should work together to ensure that RPA workflows align with relevant
standards and improve audit accuracy and efficiency.

CONTROL CONSIDERATIONS OR OBJECTIVES OF AUDITING


DIGITALLY

EMERGING TECHNOLOGIES IN AUDITING

Emerging technologies bring many benefits but also substantial risks. Auditors need to adapt
to these changes and assess technology risks properly to ensure the accuracy of financial
statements.

CONTROL CONSIDERATIONS FOR AUDITORS

Auditors must focus on key control considerations to evaluate how new technologies impact
business operations and financial reporting. This helps in assessing risks introduced by
emerging technologies such as automation or cloud systems.

 Gain a holistic understanding of changes in the industry and IT environment to assess


management’s processes for recording transactions effectively. For example, auditors
should understand how a company’s use of cloud computing or AI could affect their
transaction recording systems.
 Consider the risks from new technologies, including differences from traditional systems.
For instance, the risks introduced by using AI or blockchain in financial reporting are
different from the risks in using older systems, so auditors must evaluate new risks that
may arise.
 Assess the need for digital upskilling or specialists to evaluate new technologies’ impact.
For example, auditors might need to consult cybersecurity experts or IT specialists to
assess the effectiveness of controls around new systems.
 Test controls for digital systems to ensure accuracy and security. Examples include:
 Reliance on systems that process inaccurate data or do not process data correctly, which
may lead to incorrect financial reporting. For example, an ERP system might incorrectly
calculate inventory, affecting the financial statement.

13 | P a g e
 Unauthorized access to data leading to data loss or changes to data, like unauthorized
transactions or modification of records. For instance, if a system allows multiple users to
access a common database, it may lead to unauthorized data changes.
 IT personnel having excessive access rights that violate segregation of duties. For
example, an employee who can approve transactions and also modify the database could
exploit their position for fraudulent activity.
 Unauthorized changes to master data files, which could affect key accounting information
like customer details or payment terms.
 Changes to systems or programs without proper authorization, which could result in
unintended disruptions to financial reporting processes.
 Failure to update systems or programs appropriately, leading to outdated or ineffective
controls, such as using an old version of accounting software that no longer meets
regulatory standards.
 Inappropriate manual intervention, such as manually altering system settings that could
affect the accuracy of financial data.
 Risks from using third-party providers, such as cloud services or outsourced IT services,
where their lack of security could expose the company to breaches.
 Cybersecurity risks, including hacking, phishing, and other attacks that might
compromise the integrity of financial data.

KEY STEPS FOR AUDITORS IN A CHANGING TECHNOLOGY


ENVIRONMENT

As auditors understand the impact of technology on businesses, they should remember some
key steps to adapt to new technological environments while maintaining effective audits.

 Maintain professional skepticism when reviewing management’s risk assessments,


especially for new systems that could introduce new risks. For example, an auditor might
question management’s assumption that a new cloud-based system has adequate security.
 Understand the direct and indirect effects of technology on financial reporting and adjust
the audit approach. For example, if a company introduces AI for financial forecasting,
auditors need to understand how it impacts the transaction flow and the risk of errors.
 Evaluate how technology impacts the flow of transactions, ensuring internal control over
financial reporting remains complete and robust. For instance, auditors must assess
whether blockchain integration introduces vulnerabilities in tracking financial
transactions.
 Review the appropriateness of management’s processes for selecting, developing, and
operating technology controls, ensuring the organization maintains effective risk
management procedures. For example, auditors should evaluate whether the company has
an adequate process for maintaining cybersecurity protocols for its new digital platforms.

NEXT GENERATION AUDIT

The Next Generation Audit is a human-led, tech-powered, and data-driven approach that
combines emerging technologies to redefine auditing practices.

KEY OBJECTIVES OF NEXT GENERATION AUDIT

The main aim of the Next Generation Audit is to improve efficiency, accuracy, and insight
through advanced technologies.

TRANSFORMATIONS IN AUDITING: FROM → TO

 Sampling populations → Full population analysis: Instead of selecting a small sample,


auditors now analyze the entire population of transactions.
14 | P a g e
 Multiple datasets → One data set: Consolidating various data sets into one unified system
for better integration and analysis.
 Disconnected tools → Integrated ecosystem services: Using connected tools and systems
for seamless data processing.
 Manual risk assessments → Dynamic, data-driven risk assessment: Risk assessments are
now based on real-time data analysis, instead of manual evaluations.
 Separated communication → Embedded communication: Auditors can now communicate
directly within the audit tools, reducing communication gaps.
 Repetitive tasks → High value work and capacity for growth: Automating routine tasks
allows auditors to focus on more strategic, value-added activities.
 Manual work → Automation: Replacing manual labor with automated processes for
speed and accuracy.
 Ad hoc insights → Insights from a broader audit: Moving from isolated observations to
comprehensive, data-driven insights across all areas of the audit.

TECHNOLOGIES IMPACTING THE NEXT GENERATION AUDIT

The use of emerging technologies such as drones, augmented reality (AR), virtual reality
(VR), and more are revolutionizing auditing practices.

DRONE TECHNOLOGY IN AUDITING

Drones are used for stock counts and fixed asset audits in remote areas, offering great
payload capacity for sensors and cameras.

Drone technology improves audit quality and speed by combining data captured by drones
with other sources like QR codes, handheld scanners, and manual counts.

DIGITAL AUDITING AND ASSURANCE

Emerging technologies in digital auditing are transforming traditional audit methods.

AUGMENTED REALITY (AR)

AR overlays digital elements onto real-world environments, enhancing the user experience. A
famous example is Pokémon Go, where players chase digital creatures in real-world
locations.

VIRTUAL REALITY (VR)

VR creates a simulated environment, replacing the real world. It can be used for experiences
like flying or skydiving through special equipment.

In businesses like architecture and engineering, AR and VR allow professionals to visualize


their projects before actual construction begins.

METAVERSE IN BUSINESS AND FINANCE

The Metaverse is an immersive 3D digital space combining VR, AR, AI, and cryptocurrency,
enabling virtual experiences and transactions.

Examples of Metaverse applications in finance include virtual banking, digital asset


management, financial education, and virtual meetings.

15 | P a g e
 Virtual Banking and Transactions: Financial institutions establish virtual branches in the
Metaverse to offer services such as virtual bank accounts, personalized dashboards, and
transactions with virtual currencies.
 Digital Asset Management: Companies can facilitate buying and selling NFTs and virtual
assets in a decentralized platform within the Metaverse.
 Virtual Financial Education: Interactive learning environments within the Metaverse for
financial literacy, including simulated investment and trading experiences.
 Virtual Meetings and Conferences: Virtual conferences in the Metaverse, where
participants can interact and attend events using avatars.
 Data Visualization and Analytics: The Metaverse enables financial professionals to
analyze and visualize complex data in immersive 3D environments, aiding decision-
making.

COMMON RISKS AND CHALLENGES OF EMERGING TECHNOLOGIES

While emerging technologies provide great benefits, they also introduce new risks such as
public safety, cybersecurity, data privacy, and data protection issues.

Regulators and auditors need to address privacy, security, and governance concerns to make
digital systems more regulated and secure.

CONCLUSION

Emerging technologies bring both opportunities and risks to businesses. Auditors need to
strike a balance between technology costs and benefits while ensuring proper controls are in
place.

Though auditors do not need to be experts in every technology, they must understand its
risks, internal controls, and integration with business processes.

16 | P a g e

You might also like