0% found this document useful (0 votes)
15 views24 pages

Computer Audit and Internal Control Guide

The document outlines the fundamentals of computer auditing, defining it as a process to evaluate information systems for safeguarding assets, data integrity, and compliance with regulations. It distinguishes between internal and external audits, discusses the objectives and benefits of IT audits, and emphasizes the importance of control mechanisms in preventing and detecting fraud. The document also details the steps involved in conducting an information systems audit, including establishing engagement terms, understanding control structures, assessing control risks, and testing controls.

Uploaded by

bmakaya76977
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
15 views24 pages

Computer Audit and Internal Control Guide

The document outlines the fundamentals of computer auditing, defining it as a process to evaluate information systems for safeguarding assets, data integrity, and compliance with regulations. It distinguishes between internal and external audits, discusses the objectives and benefits of IT audits, and emphasizes the importance of control mechanisms in preventing and detecting fraud. The document also details the steps involved in conducting an information systems audit, including establishing engagement terms, understanding control structures, assessing control risks, and testing controls.

Uploaded by

bmakaya76977
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

COMPB 4113-COMPUTER SYSTEMS AUDIT AND INTERNAL CONTROL

LECTURE 1 & 2

Introduction to Computer Auditing


Definition
One of the most important factors to consider when discussing computer
audit is that the term “computer audit” can mean many different things to
different people. What may be regarded as computer auditing in one
organization, and business auditors in another similar organization may
undertake very much the realm of the specialist computer auditor.
For example, computer audit may be restricted to auditing systems software
in one organization, whilst areas such as auditing systems under
development may be the responsibility of the business auditor. Similarly, in
some organizations, it is not uncommon for the role of computer audit to be
extended to include the review of clerical procedures and the production of
compliance-based audit work programmer for field auditors, thereby
providing a wider systems audit service.

There are no hard and fast rules as to what constitutes computer audit.
Often, similar sized organizations operating in the same sector may have
different approaches to computer audit.
What is Computer audit?
Computer audit is a process carried out by specially trained professionals to
carry out a thorough audit, which consists of collecting, grouping and
evaluating evidence to determine if an information system safeguards the
business assets, maintains the integrity of the data, works effectively to
carry out the purposes of the organization, efficiently use resources, and
comply with established laws and regulations, also allow to systematically
detect the use of resources and information flows within an organization and
determine what information is critical to the fulfillment of its mission and
objectives, identifying needs, duplicities, costs, value and barriers that hinder
efficient information flows.

1
COMPB 4113-COMPUTER SYSTEMS AUDIT AND INTERNAL CONTROL
LECTURE 1 & 2

The IT audit has 2 types which are:

Internal Audit: is one that is done inside the company without hiring
outsiders.

External Audit: as the name says it is one in which the company hires people
from outside to do the audit in your company.

Auditing consists mainly of studying the control mechanisms that are


implemented in a company or organization, determining if they are adequate
and meet certain objectives or strategies, establishing the changes that
should be made to achieve them. The control mechanisms can be directive,
preventive, detection, corrective or recovery before a contingency.

objectives of IT audit

 The analysis of the efficiency of the Computer Systems


 Verification of compliance with the Regulations in this area
 The review of the effective management of computing resources.

Benefits of IT audit

 Improve the public image.


 Trust in users about security and control of IT services.
 Optimizes internal relationships and the work climate.
 Lowers the costs of poor quality (rework, rejections, claims, among others).
 Generates a balance of IT risks.
 It controls the investment in an IT environment, often unpredictable.

The audit, in general, serves to improve certain characteristics in the


company before the market, for example, the following attributes that give
better value to the company as:

2
COMPB 4113-COMPUTER SYSTEMS AUDIT AND INTERNAL CONTROL
LECTURE 1 & 2

 Performance TIME
 Reliability CORRECTNESS
 Effectiveness
 Cost-effectiveness
 Security
 Privacy

In general, audits help to improve the processes in a company and


consequently this improves the company itself, which gives more value to
the company and its processes and therefore has better prestige in the
market.

Origin of Computer Audit


The absence of a common definition of computer audit may, in part, be due
to the relative newness of computer audit. The history of traditional auditing
or inspection can be traced back many hundreds of years. In contrast,
computer audit is a relatively recent development. It was not until the late
1970’s that the majority of major organizations in the UK established a
computer audit capability for the first time.

The use of IT in business is also a relatively recent development. The father


of modern-day computing is generally regarded as being Charles Babbage,
who produced his Difference Calculator in 1833. It was not until the outbreak
of the Second World War and the widespread development of valve
technology, that the 1st Generation computers were used. Even then, it was
many years later that they became commonplace in business.

Nature of Computer Audit

3
COMPB 4113-COMPUTER SYSTEMS AUDIT AND INTERNAL CONTROL
LECTURE 1 & 2

Although an IT system may achieve the same end result as a manual


system, the way in which it does so, and hence the level of security and
control required, can differ considerably. There are a number of significant
risks associated with the processing of IT systems. It is important, therefore,
that high standards of security and control are maintained to minimize the
potential impact on the organization.
Computer fraud and abuse can have a detrimental effect on an
organization.
Periodic surveys undertaken by organizations such as the NCC (National
Computing Centre) and the Audit Commission indicate the following common
instances of computer fraud and abuse:
• Unauthorized disclosure of confidential information unavailability of key IT
systems
• Unauthorized modification/destruction of software
• Unauthorized modification/destruction of data
• Theft of IT hardware and software
• Use of IT facilities for personal business

When considering computer audit, it should be noted that the basic control
objectives and principles do not change. The manner in which those
objectives are achieved, however, does change fundamentally.
Specifically, there is a need for greater preventative controls rather than a
reliance on the more detective
and corrective control mechanisms which would usually be found in manual
systems. The development of on-line real time systems, where the
immediacy of processing can result in millions of pounds being transferred
away in a funds transfer system, requires a robust level of security.

Conducting an Information Systems Audit


Introduction

4
COMPB 4113-COMPUTER SYSTEMS AUDIT AND INTERNAL CONTROL
LECTURE 1 & 2

It is a sobering experience to be in charge of the information systems audit


of an organization that has several hundred programmers and analysts,
many computers, and thousands of files. Obviously, not all organizations are
with the same size.

Except for the smallest organizations, however, auditors usually cannot


perform a detailed check of all the data processing carried out within the
information systems function. Instead, they must rely on a sample of data to
determine whether the objectives of information system auditing are being
achieved. How, then, can we perform information systems audit so that we
obtain reasonable assurance that an organization safeguards its data-
processing assets, maintains data integrity, and achieves system
effectiveness and efficiency?

1, we start by examining the nature of controls and discussing some


techniques for simplifying and providing order to the complexity encountered
when making evaluation judgments on computer-based information systems.
2. Next, we consider some of the basic risks auditors face, how these risks
affect the overall approach to an audit and the types of audit procedures
used to assess or control the level these risks.
3, we then consider the basic steps to be undertaken in the conduct of an
information systems audit.
4. Finally, we examine a major decision auditor must make when planning
and conducting an information system audit namely, how much do they need
to know about the internal workings of a computer-based information system
before an effective audit can be conducted?
The Nature of Controls
Information systems auditors ultimately are concerned with evaluating the
reliability or operating effectiveness of controls. It is important, therefore,
that we understand what is meant by a control.

5
COMPB 4113-COMPUTER SYSTEMS AUDIT AND INTERNAL CONTROL
LECTURE 1 & 2

A control is a system that prevents, detects, or corrects unlawful events.


There are three key aspects to this definition.
First, a control is a system. In other words, it comprises a set of interrelated
components that function together to achieve some overall purpose.
Second, the focus of controls is unlawful events. An unlawful event can arise
if unauthorized inaccurate, incomplete, redundant, ineffective or inefficient
input enters the system.

For example, a data-entry clerk might key incomplete data into the system.
An unlawful event can also arise if the system transforms the input in an
unauthorized, inaccurate, incomplete, redundant, ineffective or inefficient
way. Third, controls are used to prevent, detect, or correct unlawful events.
Consider some examples:

1. Preventive control
Instructions are placed on a source document to prevent clerks from
filling it out incorrectly. Note that the control works only if the instructions
are sufficiently clear and the clerk is sufficiently well trained to
understand the instructions. Thus, both the clerk and the instructions are
components of the system that constitutes the control. The instructions
by themselves are not the control.

2. Detective control

An input program identifies incorrect data entered into a system via a


terminal. Again, the control is a system because various parts of the
program must work together to pinpoint errors.
6
COMPB 4113-COMPUTER SYSTEMS AUDIT AND INTERNAL CONTROL
LECTURE 1 & 2

3. Corrective control
A program uses special codes that enable it to correct data corrupted
because of noise on a communications line. Once more, the control is a
system because various parts of the program must work together in
conjunction with the error-correcting codes to rectify the error.

The auditor's task is to determine whether controls are in place and working
to prevent the unlawful events that might occur within a system. Auditors
must be concerned to see that at least one control exists to cover each
unlawful event that might occur. Usually, some unlawful events in a system
will not be covered because a cost-effective control cannot be found. Even if
an unlawful event is covered by a control, however, auditors must evaluate
whether the control is operating effectively.

Dealing with Complexity

Conducting an information systems audit is an exercise in dealing with


complexity. Because complexity is a root cause of the problems faced by
many professionals (e.g. engineers, architects), researchers have attempted
to develop guidelines that reduce complexity.

In the following subsections we consider two major guidelines that underline


the approach taken when conducting an information systems audit:

1. Given the purposes of the information systems audit, factor the system
to be evaluated into subsystems.
2. Determine the reliability of each subsystem and the implications of each
subsystem's level of reliability for the overall level of reliability in the
system.

Subsystem Factoring

7
COMPB 4113-COMPUTER SYSTEMS AUDIT AND INTERNAL CONTROL
LECTURE 1 & 2

The first step in understanding a complex system is breaking it up into


subsystems. A subsystem is a component of a system that performs some
basic function needed by the overall system to enable it to attain its
fundamental objectives. Subsystems are logical components rather than
physical, components, In other words, you cannot "touch" a subsystem. It
exists only in the eye of the beholder. For example, we cannot see the input
subsystem in a computer system. Instead, we see such things as terminals
and data-entry clerks that function to get data into the system, hut these
things are components of the input subsystem and not the subsystem itself.

Second, each subsystem should be internally cohesive. All the activities


performed by the subsystem should be directed toward accomplishing a
single function. If this objective can be achieved, it will be easier for auditors
to understand and evaluate the activities carried out by the subsystem

An understanding of complex systems can only be obtained if each of their


parts can be studied relatively independently and the activities performed by
each part are clear. When we decompose a system into subsystems,
therefore, we should evaluate the extent of coupling and cohesion in the
subsystems we choose. If the subsystems are not loosely coupled and
internally cohesive, we should attempt a different factoring. If no factoring
seems to delineate subsystems that possess these characteristics, we will
have difficulty evaluating the reliability of the system because its activities
are too convoluted. Indeed, auditors have long recognized that some
systems cannot be audited. The theory of coupling and cohesion provides
the underlying rationale for this conclusion when such systems are
encountered.

Assessing Subsystem Reliability


After we have identified the lowest-level sub-systems in our level structure of
subsystems, we can evaluate the reliability of controls. Beginning with the

8
COMPB 4113-COMPUTER SYSTEMS AUDIT AND INTERNAL CONTROL
LECTURE 1 & 2

lowest-level subsystems, we first attempt to identify all the different types of


events that might occur in these sub-systems. We must be mindful of both
the lawful events and the unlawful events that can occur.
A basis for identifying lawful and unlawful events in management
subsystems, we focus on the major functions each subsystem performs. We
consider how each function should be undertaken and then evaluate how
well a subsystem complies with our normative views.

To identify all the events that might arise in an application system as a result
of a transaction, we must understand how the system is likely to process the
transaction. Historically, auditors have used walk-through techniques to
accomplish this objective. They consider a particular transaction, identify the
particular components in the system that process the transaction and then
try to understand each processing step that each component executes. They
also consider any errors or irregularities (unlawful events) that might occur
along the way.

Steps in Information System Audit

1. Establish the Terms of the Engagement


This will allow the auditor to set the scope and objectives of the relationship
between the auditor and the organization. The engagement letter should
address the responsibility (scope, independence, deliverables), authority
(right of access to information), and accountability (auditee rights, agreed
completion date) of the auditor.

2. Preliminary Review
This phase of the audit allows the auditor to gather organizational
information as a basis for creating their audit plan. The preliminary review
will identify an organization’s strategy and responsibilities for managing and
controlling computer applications. An auditor can provide an in-depth

9
COMPB 4113-COMPUTER SYSTEMS AUDIT AND INTERNAL CONTROL
LECTURE 1 & 2

overview of an organization’s accounting system to establish which


applications are financially significant at this phase. Obtaining general data
about the company, identifying financial application areas, and preparing an
audit plan can achieve this.

3. Obtain understanding of control structure


Understanding control structure in an organization involves examining both
management controls and application controls. An internal control system
should be designed and operated to provide reasonable assurance (the
concept of reasonable assurance) that an organization’s objectives are
being achieved in the following categories: effectiveness and efficiency of
operations, reliability of financial reporting, and compliance with applicable
laws and regulations.
To develop their understanding of internal controls, the auditor should
consider information from previous audits, the assessment of inherent risk,
judgments about materiality, and the complexity of the organization’s
operations and systems.
Once the auditor develops their understanding of an organization’s internal
controls, they will be able to assess the level of their control risk (the risk a
material weakness will not be prevented or detected by internal controls).

4. Assess control risk


After obtaining satisfactory understanding of internal controls, auditor must
assess the level of control risk. Auditors assess control risk in terms of each
major assertion that management should be prepared to make about
material items in financial statements

Existence Assets, liabilities included in financial statements


actually exist

10
COMPB 4113-COMPUTER SYSTEMS AUDIT AND INTERNAL CONTROL
LECTURE 1 & 2

Occurrence All transactions represent events that have actually


occurred
Completeness All transitions have been recorded and presented
Rights and obligations Assets are rights and liabilities are obligations of the
organization at balance sheet date
Valuation or allocation Asset, liabilities, equity, reserves are been recorded at
correct amount
Presentation and disclosure All items of financial statements have been properly
classified described and disclosed

After auditors obtain understanding of internal controls they must determine


control risk in relation to each assertion.
1. If auditors assess controls at less than maximum level, they go to next
step and test the controls to evaluate whether they are operating
effectively.
2. If auditors assess control risk at higher than maximum level, they will
not test controls at all, and carry out detailed substantive check
procedures.
5. Test of controls
In this step the auditors will test controls to ascertain whether they are
operating effectively or not. Auditors will carry out testing of both application
and management controls. This phase usually begins by focusing on
management controls. If testing shows that control to expectations,
management controls are not operating reliably, there may be little point in
testing application controls, in such case auditors may qualify their opinion
or carry out substantive tests in detail.

6. Reassess controls

11
COMPB 4113-COMPUTER SYSTEMS AUDIT AND INTERNAL CONTROL
LECTURE 1 & 2

After auditors have completed tests of controls, they again assess the control
risk. In light of test results, they might revise the anticipated control risk
upward or downward. In other words, auditor may conclude that internal
controls are stronger or weaker than anticipated. They may also conclude
that it is worthwhile to perform more tests to further reduce substantive
testing.

7. Completion of audit
In the final phase of audit, Audit procedures are developed based on the
auditor understands of the organization and its environment. A substantive
audit approach is used when auditing an organization’s information system.
Once audit procedures have been performed and results have been
evaluated, the auditor will issue either an unqualified or qualified audit report
based on their findings.

Audit risks

We know that information systems auditors are concerned with four


objectives: asset safeguarding, data integrity, system effectiveness and
system efficiency. Both external and internal auditors are concerned with
whether errors or irregularities cause material Josses to an organization or
material misstatements in the financial information prepared by the
organization. If you are an internal auditor, it is likely you will also be
concerned with material losses that have occurred or might occur through
ineffective or inefficient operations.

External auditors, too, might be concerned when ineffective or inefficient


operations threaten to undermine the organization. Moreover~ many
external auditors report such problems as part of their professional services
to the management of an organization.

12
COMPB 4113-COMPUTER SYSTEMS AUDIT AND INTERNAL CONTROL
LECTURE 1 & 2

To assess whether an organization achieves the asset safeguarding, data


integrity, system effectiveness, and system efficiency objectives, auditors
collect evidence. Because of the test nature of auditing, auditors might fail to
detect real or potential material losses or account misstatements.
The risk of an auditor failing to detect actual or potential material
losses or account misstatements at the conclusion of the audit is
called the audit risk. Auditors choose an audit approach and design audit
procedures in an attempt to reduce this risk to a level deemed acceptable.

As a basis for determining the level of desired audit risk, some professional
bodies of auditors have adopted the following audit risk model for the
external audit function:

DAR= IR X CR X DR

In this model, DAR is the desired audit risk. IR is the inherent risk, which
reflects the likelihood that a material loss or account misstatement exists in
some segment of the audit before the reliability of internal controls is
considered.

CR is the control risk, which reflects the likelihood that internal controls in
some segment of the audit will not prevent, detect, or correct material losses
or account misstatements that arise.

DR is the detection risk, which reflects that the audit procedures used in
some segment of the audit will fail to detect material losses or account
misstatements.

13
COMPB 4113-COMPUTER SYSTEMS AUDIT AND INTERNAL CONTROL
LECTURE 1 & 2

To apply the model, auditors first choose their level of desired audit risk. In
addition, they assess the short and long-run consequences for their
organizations if they fail to detect real or potential material losses from
ineffective or inefficient operations.

Next auditors consider the level of inherent risk. Initially auditors consider
general factors such as the nature of the organization (e.g. Is it a high
flyer?), the nature of industry in which it operates (e.g. Is the industry subject
to rapid change?), the characteristics of management (e.g. Is management
aggressive and autocratic?).

Auditors then consider the inherent risk associated with different segments
of the audit. To assess the level of control risk associated with a segment of
the audit, auditors consider the reliability of both management & and
application controls, Auditors Management controls constitute protective
layers of "onion skins" around applications.

Forces that erode asset safeguarding, data integrity, system effectiveness


and system efficiency must penetrate each layer to undermine a lower layer.
To the extent the outer layers of controls are intact the inner layers of
controls are more likely to be intact.

Next auditors calculate the level of detection risk they must attain to achieve
their desired audit risk. They then design evidence collection procedures in
an attempt to achieve this level of detection risk.

In summary, the whole point to our considering the audit risk model is that
audit efforts should be focused where they will have the highest payoffs. In
most cases, auditors cannot collect evidence to the extent they would like.
Accordingly, they must be astute in terms of where they apply their audit
procedures and how they interpret the evidence, they collect. Throughout

14
COMPB 4113-COMPUTER SYSTEMS AUDIT AND INTERNAL CONTROL
LECTURE 1 & 2

the audit, they must continuously make decisions on what to do next. Their
notions of materiality and audit risk guide them in making this decision.

Types of Audit Procedures

When external auditors gather evidence to det6rmine whether material


losses have occurred or financial information has been materially misstated,
they use five types of procedures:

a) Procedures to obtain an understanding of controls


Inquiries, inspections, and observations call be used to gain all
understanding of what controls supposedly exist, bow well they have
been designed and whether they have been placed in operation.

b) Tests of controls
Inquiries, inspections, observations, and reperformance of control
procedures can he used to evaluate whether controls are operating
effectively.

c) Substantive tests of details of transactions


These tests are designed to detect dollar errors or irregularities in
transactions that would affect the financial statements. For example, an
external auditor might verify that purchase and disbursement
transactions are correctly recorded in journals and ledgers.

d) Substantive tests of details of account balances


These tests focus on the ending general ledger balances in the balance
sheet and income statement. For example, an external auditor might
circularize a sample of customers to test the existence and valuation of
the debtor’s balance.

15
COMPB 4113-COMPUTER SYSTEMS AUDIT AND INTERNAL CONTROL
LECTURE 1 & 2

e) Analytical review procedures


These tests focus on relationships among data items with the objective of
identifying areas that require further audit work. For example, an
external auditor might examine the level of sales revenue across time to
determine whether a material fluctuation that requires further
investigation has occurred in the current year.

As a modern-day auditor, the idea of auditing in computer-


based environment should no longer be alien to you. In fact, I suggest you
become proficient in conducting an AIS audit as this will broaden your
horizon as an auditor – internal or external.

Auditing through computer and auditing around computer are two different
approaches to conducting audits in the context of information technology
and computer systems. These approaches have distinct purposes and
methods:

Auditing Through Computer (Computer-Assisted Audit Techniques –


CAATs)

At the very least, you must fully grasp the rudiments and purpose of the two
terminologies involved in computer-based auditing.

Auditing through computer involves using computer-assisted audit


techniques (CAATs) to perform audit procedures with the help of business
technologies. The primary purpose is to enhance the efficiency and
effectiveness of the audit process by leveraging technology. Auditors
evaluate client’s software and hardware to determine whether to rely on the
system for operations that are not visible to human eyes or not.

16
COMPB 4113-COMPUTER SYSTEMS AUDIT AND INTERNAL CONTROL
LECTURE 1 & 2

Auditing through the computer methodology

Data analysis: Auditors use specialized software to analyse large volumes


of data quickly and accurately, identifying anomalies, trends, and potential
risks.

Automated testing: Audit procedures, such as reconciliation, validation,


and compliance testing, are automated using software tools.

Continuous monitoring: Computer systems can be set up to continuously


monitor transactions and processes, providing real-time insights into
potential issues.

Data extraction: Auditors can extract data from various systems and
databases for analysis without manual data entry.

Advantages of auditing through the computer

Auditing through computer allows for more comprehensive and timely audits,
reduces the risk of human error, and provides deeper insights into an
organization’s financial and operational activities.

Auditing Around Computer

Auditing around computer, on the other hand, refers to the traditional audit
approach where auditors rely primarily on manual methods and do not
heavily use computer-based tools. The purpose is to assess an organization’s
financial statements and internal controls without significant reliance on
automated systems. It could be as simple as selecting sample documents
and verify the correspondence of input and output.

Auditing around the computer methodology

17
COMPB 4113-COMPUTER SYSTEMS AUDIT AND INTERNAL CONTROL
LECTURE 1 & 2

Manual sampling: Auditors select a sample of transactions or documents


manually for examination, which may not be as comprehensive as data
analysis performed through computer-assisted techniques.

Manual testing: Audit procedures are performed manually, such as


counting physical inventory or inspecting paper documents.

Limited use of technology: Auditors may use computers


for administrative tasks like document management and communication but
do not heavily rely on technology for substantive audit procedures.

Advantages of auditing around the computer

Auditing around computer is often used when auditors have limited access to
an organization’s computer systems or when they want to
maintain independence from automated processes. It provides a more
traditional and conservative approach to auditing.

Similarities between auditing through the computer and auditing


around the computer

In as much as the two approaches are distinct, they have certain things in
common as discussed below.

Audit Objectives
Both approaches aim to achieve the same primary objectives of auditing,
which include assessing the accuracy and reliability of financial statements,
evaluating internal controls, and detecting fraud or irregularities.
Compliance
Both approaches must adhere to auditing standards and regulations, such as
Generally Accepted Auditing Standards (GAAS) and International Standards
on Auditing (ISA), to ensure the quality and integrity of the audit process.

18
COMPB 4113-COMPUTER SYSTEMS AUDIT AND INTERNAL CONTROL
LECTURE 1 & 2

Audit Planning

In both approaches, auditors must plan their procedures, assess risks, and
determine the scope of the audit based on the audit objectives and the
characteristics of the audited entity.

Documentation
Auditors, regardless of the approach used, are required to maintain thorough
documentation of their work, including audit plans, procedures, findings, and
conclusions.

Differences between auditing through the computer and auditing


around the computer

That they have commonalities does not mean that they don’t differences.
Some of the differences are briefly discussed below.

Use of Technology
The most significant difference is the extent to which technology is
employed. Auditing through computer relies heavily on computer-assisted
audit techniques (CAATs) and technology for data analysis, testing, and
continuous monitoring. Auditing around computer, in contrast, primarily
uses manual audit methods with limited reliance on technology.
Efficiency
Auditing through computer is generally more efficient due to automation,
which allows for faster and more comprehensive data analysis and testing.
Auditing around computer may be less efficient as it relies
on manual sampling and testing methods.

19
COMPB 4113-COMPUTER SYSTEMS AUDIT AND INTERNAL CONTROL
LECTURE 1 & 2

Data Analysis
Auditing through computer involves sophisticated data analysis techniques,
including data mining, statistical analysis, and automated testing. Auditing
around computer relies on manual sampling and manual testing, which may
not uncover all potential issues.
Access to Systems
Auditing through computer requires auditors to have access to an
organization’s computer systems and data. Auditing around computer may
not require extensive access to computer systems, making it suitable for
situations where such access is restricted or not feasible.
Independence
Auditing around computer may be seen as a more independent approach
since it does not rely heavily on an organization’s automated systems.
Auditing through computer may involve a closer connection to and reliance
on the organization’s technology infrastructure.

Risk Assessment
Auditing through computer allows for more comprehensive risk
assessment by analyzing large datasets and identifying anomalies and
trends automatically. Auditing around computer may have a more limited
ability to assess risks comprehensively.
 Auditing Around or Through the Computer

When auditors come to the controls testing phase of an information systems


audit, one of the major decisions they must make is whether to test controls
by auditing around or through the computer. The phrases "auditing around
the computer" and "auditing through the computer" are carryovers
from the past. They arose during the period when auditors were debating
how much technical knowledge was required to audit computer systems.
Some argued that little knowledge was needed because auditors could
evaluate computer systems simply by checking their input and output.

20
COMPB 4113-COMPUTER SYSTEMS AUDIT AND INTERNAL CONTROL
LECTURE 1 & 2

Others contended audits could not be conducted properly unless the internal
workings of computer systems were examined and evaluated. Unfortunately,
the arguments of the former group were sometimes motivated by their lack
of technical knowledge about computers. Today we recognize that the two
approaches each have their merits and limitations and that each must be
considered carefully in the context of planning and executing the most cost-
effective audit.

Auditing Around the Computer


Auditing around the computer involves arriving at an audit opinion through
examining and evaluating management controls and then input and output
only for application systems. Based on the quality of an application system's
input and output, auditors infer the quality of the application system's
processing. The application system's processing is not examined directly.
Instead, auditors view the computer as a black box.
Auditors should audit around the computer when it is the most cost-effective
way to undertake the audit. This circumstance often arises when an
application system has three characteristics.

First, the system is simple and batch oriented.

Second, often it is cost-effective to audit around the computer when an


application system uses a generalized package as its software platform. If
the package has been provided by a reputable vendor, has received
widespread use, and appears error free, auditors might decide not to test the
processing aspects of the system directly.

Instead they might seek to ensure (1) the organization has not modified the
package in any way; (2) adequate controls exist over the source code, object
code and documentation to prevent unauthorized modification of the
package; and (3) high-quality controls exist over input to and output from
the package.

21
COMPB 4113-COMPUTER SYSTEMS AUDIT AND INTERNAL CONTROL
LECTURE 1 & 2

Third, auditors might audit around the computer when a high reliance is
placed on user rather than computer controls to safeguard assets, maintain
data integrity and attain effectiveness and efficiency objectives. In testing,
the focus is on the reliability of user controls rather than the reliability of
computer controls.
Usually auditing around the computer is a simple approach to the conduct of
the audit and it can be performed by auditors who have little technical
knowledge of computers. The audit should be managed, however, by
someone who has expertise in information systems auditing.

The approach has two major limitations

First, the type of computer system in which it is applicable is very restricted.


It should not be used when systems are complex. Otherwise, auditors might
fail to understand some aspect of a system that could have a significant
effect on the audit approach.

Second, it does not provide information about the system's ability to cope
with change. Systems can be designed and programs can be written in
certain ways to inhibit their degradation when user requirements change.

Auditing Through the Computer


While auditing through the computer, the auditors use the computer to test
(1) the processing logic and controls existing within the system and (2) the
records produced by the system. Depending on the complexity of the
application system, the task of auditing through the computer might be fairly
simple or it might require extensive technical competence on the part of the
auditor.

Auditing through the computer must be used in the following cases:

22
COMPB 4113-COMPUTER SYSTEMS AUDIT AND INTERNAL CONTROL
LECTURE 1 & 2

i. The inherent risk associated with the application system is high.


ii. The application system processes large volumes of input and produces
large volumes of output that make extensive, direct examination of the
validity of input and output difficult to undertake.
iii. Significant parts of the internal control system are embodied in the
computer system, For example, in an online banking system, a
computer program might batch transactions for individual tellers to
provide control totals for reconciliation at the end of the day's
processing.
iv. The processing logic embedded within the application system is
complex.
Moreover, large portions of system code are intended to facilitate use
of the system or efficient processing.
v. Because of cost-benefit considerations, substantial gaps in the visible
audit trail are common in the system.

The primary advantage of auditing through the computer is that auditors


have increased power to test an application system effectively. They can
expand the range and capability of tests they can perform and thus increase
their confidence in the reliability of the evidence collection and evaluation.
Furthermore, by directly examining the processing logic embedded within an
application system, auditors are better able to assess the system's ability to
cope with change and the likelihood of losses or account misstatements
arising in the future.

The approach has two disadvantages


First, it can sometimes be costly, especially in terms of the labor hours that
must be expended to understand the internal workings of an application
system.

23
COMPB 4113-COMPUTER SYSTEMS AUDIT AND INTERNAL CONTROL
LECTURE 1 & 2

Second, in some cases we will need extensive technical expertise, if we are


to understand how the system works.

24

Common questions

Powered by AI

Materiality in the audit process influences which errors or deviations it regards as significant enough to warrant attention, affecting decisions on audit scope, risk, and evidence collection. It is crucial for auditors to define materiality clearly as it helps in focusing audit efforts on areas of greater risk or importance, ensuring that the audit results in meaningful insights for decision-making by stakeholders .

The primary difference between auditing 'through the computer' and 'around the computer' is the extent of technology use. Auditing through the computer relies on computer-assisted audit techniques (CAATs) and is more efficient and data-intensive, suitable for complex systems and when a high inherent risk is associated. Auditing around the computer uses manual methods and is more independent, applicable when systems are simple, batch-oriented, or when access to computer systems is limited. Each approach is chosen based on the cost-effectiveness and complexity of the system .

Auditing around the computer has limitations, namely that it is applicable only to simple systems and does not examine the system’s processing directly, potentially missing how systems cope with changes. This could lead to auditors not understanding critical aspects of the system, affecting their audit strategy and possibly leading to an audit that doesn’t fully address risk areas or provide a complete view of system reliability and effectiveness .

Auditors might choose not to test internal controls if they assess control risk at a higher than maximum level, indicating that internal controls are not reliable enough to prevent or detect material misstatements. In such cases, it may be more efficient to proceed directly to detailed substantive testing procedures rather than spending resources on testing ineffective controls .

The audit risk model is significant as it guides auditors in focusing their efforts where they will have the highest payoffs, helping them design audit procedures that minimize the risk of not detecting material losses or misstatements. The model includes the following components: DAR (desired audit risk), IR (inherent risk), CR (control risk), and DR (detection risk). Auditors use this model to choose the level of desired audit risk and assess risks related to the organization's operations, industry, and management characteristics .

The primary purpose of conducting a preliminary review in a computer systems audit is to gather organizational information as a basis for creating an audit plan. This involves identifying an organization’s strategy, responsibilities for managing and controlling computer applications, and determining which applications are financially significant. This step helps auditors prepare an informed audit plan .

To achieve the desired level of audit risk, auditors can employ strategies such as clearly defining acceptable levels of inherent, control, and detection risks, methodically assessing these risks for different audit segments, and designing audit procedures that effectively target potential areas of misstatement. Using the audit risk model, auditors can adjust their procedures dynamically throughout the audit to ensure they effectively address risk areas where the audit payoff is the highest .

The four audit objectives an information systems auditor focuses on are asset safeguarding, data integrity, system effectiveness, and system efficiency. External auditors might focus more on whether errors or irregularities cause material losses to an organization or material misstatements in financial information. Internal auditors may also be concerned with material losses from ineffective or inefficient operations, reflecting a broader scope within the organization .

A high detection risk implies that the audit procedures may fail to detect material losses or misstatements. To mitigate this risk, auditors might enhance the rigor of their evidence collection procedures, applying more extensive tests or increasing sample sizes to achieve the desired audit risk level. It influences audit procedures by necessitating more thorough analysis and testing, ensuring adequate audit scope and depth .

Auditors assess control risk by evaluating the effectiveness of internal controls in terms of each major assertion that management might make about material items in financial statements. The major assertions include existence, occurrence, completeness, rights and obligations, valuation or allocation, and presentation and disclosure. Auditors determine control risk by examining whether these assertions hold true, and may choose to test controls for effectiveness or focus on substantive check procedures depending on the control risk assessment .

You might also like