0% found this document useful (0 votes)
33 views34 pages

Intro To CIS

The document outlines the importance of Computer Information System (CIS) audits in managing accounting records and ensuring data integrity. It details the major components of information systems, their functions, and the auditor's responsibilities in assessing internal controls within IT environments. Additionally, it discusses various control activities necessary for maintaining effective application controls and general IT controls to mitigate risks associated with data processing and access.

Uploaded by

raven
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
33 views34 pages

Intro To CIS

The document outlines the importance of Computer Information System (CIS) audits in managing accounting records and ensuring data integrity. It details the major components of information systems, their functions, and the auditor's responsibilities in assessing internal controls within IT environments. Additionally, it discusses various control activities necessary for maintaining effective application controls and general IT controls to mitigate risks associated with data processing and access.

Uploaded by

raven
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Introduction to the Computer

Information System Audit


John Carlo Balino, CPA
What is the relevance of the CIS to Daily Operations?

As Management process voluminous data, they heavily relies on Computer to process


and safekeep their accounting records. What if the following occurs:

-The system is not configured to process accurately.

-Inappropriate individuals can access and make changes to the accounting information

-Changes in system can be made without sufficient approval


Nature of IT and its Capabilities

Information Technology generally refers to a wide variety of computer hardware and


software technology that are used to manage and control information, when it is
organized to perform task or organizational process, an information system is created.
Major Components of Information System

A typical information system records, process, stores and disseminates information that
consists of the methods and records an entity’s transactions and to maintain
accountability for the related assets, liabilities and equity.
Major Components of Information System

The Major components are the following:


a. Hardware- Refers to the computer and peripheral equipment for input, output and
storage of data.
b. Software- Refers to the series of programs that provide instructions for operating
the computer.
i. System Software- which controls the operations of the computer itself
ii. Application Software- designed to perform specific task
c. Data- Refers to the inputs and outputs of the computer system. Most accounting
information systems are structured to store in data in a database, which is
organized collection of data.
Major Components of Information System

The Major components are the following:

d. People- Refers to the users and the information system professionals

e. Procedures- These are the policies and practices within a company for operating and
maintaining the information system.

f. Networks- These are specialized hardware and software that allow different IT devices
to connect with each other to share data, software, and other hardware resources.
Function of the Information Systems

Regardless of the information system components used, the architecture or the business
task undertaken, information systems perform the five fundamental functions:

a. Capture Input- Inputs are the data needed by the system. An information system
must provide a mechanism to capture input.
b. Process- The transformation of input into output is called Processing. Performing
the calculations, validating information, updating records, and tracking raw
materials are example of processing.
c. Convey Output- Outputs are the result of processing data.
Function of the Information Systems

Regardless of the information system components used, the architecture or the business
task undertaken, information systems perform the five fundamental functions:

d. Collect Feedback- In order to determine whether the system is working as planned


feedback- data about the performance of the system is collected.

e. Controls- Refers to the process and procedures that restrict and monitor the inputs,
processing and output to provide reasonable assurance and that organizational
objectives are met.
Characteristics of various type of IT-based Systems

● Batch processing- A system which like transactions are processed periodically as a


group. This does not provide up-to-time or real time transaction information.
● Real-time processing- A system that allows immediate update or access data or
instantaneous analysis of data
● Online Transaction Processing (OTP)- is a processing method in which the IT
systems process data immediately after it is captured and provide information to
the users on a timely basis.
● Designing support system- Combine models and data to attempt to solve non-
structured problems with extensive user involvement
Characteristics of various type of IT-based Systems

● Expert System- Guides decision process with a well defined area and allows the
making of decision compared to expert
● Centralized Processing System- Performed by one computer or by a cluster of
coupled computer in a single location. Data are often input and reports printed
using workstations.
● Decentralized Processing System- Computers are in different location. Although
data may be transmitted between computers periodically, such system involves
only limited communication among systems.
● Client Server Architecture (IT Architecture)- Network system which multiple
computers (clients) share memory and other capabilities of a larger computer.
Characteristics of various type of IT-based Systems

● Local Area Network (LAN)- Communication network that interconnects computer


within a limited area
● Wide Area Network (WAN)- a Communication network that interconnects within
a large geographical area network
● Cloud Computing- a model for enabling on demand user network access to a
shared pool of computing resources
● Virtualized Client/Server Infrastructure- Software-based IT infrastructure being
hosted on another physical infrastructure.
● Electronic Data Infrastructure (EDI)- Data are exchanged electronically between
the computers of different companies. In an EDI systems, source documents are
placed with electronic transactions created in standard format.
Auditor’s Responsibilities

To obtain an understanding adequate to:

a) Aid in Planning the remainder of the audit and;


b) Assess Control Risk
Auditor’s Responsibilities

Factors that may affect the study of internal control in the computer systems includes:
a. Results in transaction trails that exist for a short period of time or only in computer
readable form
b. Program error that cause uniform mishandling of transactions- clinical error
becomes less frequent;
c. Computer controls that need to be relied upon instead of segregation of functions
d. Increased difficulty in detecting an authorized access;
e. Allow increased Management supervisory potential resulting from more timely
reports.
f. Less documentation of initiation and execution of transactions.
g. Computer controls that may affect the effectiveness of related manual control
procedures that use computer output
Internal Control for IT Environment

a. General Control Activities


b. Application Control activities
c. User control activities
Internal Control for IT Environment: General Control Activities

In an IT environment, GENERAL CONTROLS are those that Affect multiple


application systems. In accordance of AICPA, the general controls are as follows:

a) Organization and Operation


b) Systems development documentation controls
c) Hardware and systems software controls
d) Access controls
e) Data and Procedural controls
General Control Activities: Organizational and Operational Control

Controls:

- Segregate functions between the IT Department and User Department


- Do not allow IT department to initiate or authorize transactions
- Segregate functions within the IT department
General Control Activities: Organizational and Operational Control

Key Functions in the IT department are:


a. System analyst
b. Applications Programmer
c. Systems Programmer
d. Operator
e. Data Librarian
f. Quality assurance
g. Control Group
h. Data Security
i. Database Administrator
j. Network technician
General Control Activities: Organizational and Operational Control

In an ideal IT set-up, the IT functions shall be separated but this is not the case for many
small company. However, 2 key functions that are segregated are the applications
programmer and operator. When these functions are not segregated, irregularities in
the IT can be penetrated and concealed and auditor cannot rely on the IT controls.

The Auditor test of controls shall include inquiry, observation, discussion and review of
the appropriate organizing chart, responsibility for initiating and authorizing
transactions, discrepancies should be reported and the appropriate controls are
recommended.
General Control Activities: Systems development documentation controls

Controls:
- User department must participate in systems design
- Each system must have written specification, which are reviewed and approved by
Management
- Both user and IT personnel must test the new system
- Management, users, and IT must approve new systems before they are placed into
operation
- All master and conversion file should be controlled to prevent unauthorized changed
- After the new system is operating there should be a proper approval of all program
change
- Proper documentation standards should exist to assure continuity of the system.
General Control Activities: Systems development documentation controls

Two Common Controls over system change are:

- Design Methodology
- Change control process
General Control Activities: Hardware and Software controls

Controls

- The auditor shall be aware of control features inherent in the computer hardware,
operating system and other supporting software and ensure that they are utilized to
the maximum possible extent
- System software should be subjected to the same control procedures as issue
applied to the installation of and changes to application programs.
General Control Activities: Hardware and Software controls

Controls built to detect and prevent equipment failures:

- Parity check
- Echo check
- Diagnostic routines
- Boundary protection
- Periodic Maintenance
General Control Activities: Access Controls

Controls

- Access to program documentation should be limited to those persons who require


it in the performance of their duties
- Access to data files and programs should be limited to those individuals such
computer operators and their supervisors.
- Access to computer hardware should be limited to authorized individuals such as
computer operators and their supervisors
General Control Activities: Access Controls

Access to IT Environment

a) Physical controls
i) Limited Physical access
ii) Visitor Entry Logs
b) Electronic Access Controls
i) Access control software (user identification)
ii) Call back
iii) Encryption boards
General Control Activities: Data Procedural Controls

Controls
- A control group should:
- Receive all data processed
- Ensure data are recorded
- Follow-up in errors during processing and determine transactions are corrected and resubmitted by
the proper use
- Verify the proper distribution of output
- Written Manual of systems and procedures should be prepared for all the
computer operations and should provide for Management’s general or specific
authorization to process transactions
- Internal Auditors should review and evaluate proposed systems at critical stages of
development and review and test computer procedures.
General Control Activities: Access Controls

Specific Controls

a. Operations Run Manual


b. Back-up and Recovery
c. Contingency Processing
d. Processing Controls
e. File Protection ring
f. Internal and External labels
Internal Control for IT Environment: Application Control activities

Application controls are related to specific application. Each accounting application that
is processed within IT includes: Input, Process and Output.
Application Control activities: Input

Controls:

a. Data should be authorized and approved


b. System should verify all significant data fields used to record information
c. Conversion of data into machine-readable form should be controlled and verified
for accuracy.
d. Movement of data between processing steps and departments should be controlled
e. Correction of errors and resubmission of corrected transactions should be reviewed
and controlled.
Application Control activities: Input

Example of Input controls


a. Preprinted form
b. Checker Digit
c. Control batch
d. Hash Total
e. Record Count
f. Reasonableness and Limit test
g. Menu Driven Input
h. Field Checks
i. Validity checks
j. Missing data check
k. Field size check
l. Logic check
Application Control activities: Processing

Controls:

a. Control totals should be produced and reconciled with input total control
b. Control should prevent processing the wrong file and detect errors in file
manipulation
c. Limit and reasonableness check should be incorporated in programs
d. Run to run totals should be verified at appropriate points in processing cycle.
Application Control activities: Processing

Example of Processing controls

a. Checkpoint/ Restart Capacity


b. Error resolution Procedure
Application Control activities: Output

Visual review of output should be done by the user or an independent control group:

a. Output control totals should be reconciled with input and processing control totals
b. Output should be scanned and tested by comparison to original source documents
c. System output should be distributed only to authorized users
Application Control activities: Output

Example of Output controls

a. Control Total
b. Limiting the Quantity of Output and total processing time
c. Error message and resolution
Reference

-Auditing Theory by Cabrera

-AASC issuances

You might also like