0% found this document useful (0 votes)
23 views25 pages

Defining Audit Data Analytics

This document discusses continuous auditing techniques using computer-assisted audit tools and data analytics. It describes how data analytics can help auditors more efficiently audit large volumes of data by transforming it into structured presentations. The document also outlines different types of automated evaluation techniques for continuous auditing, including systems control audit review files, snapshots, audit hooks, integrated test facilities, and continuous and intermittent simulation.

Uploaded by

Ella Grace
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
23 views25 pages

Defining Audit Data Analytics

This document discusses continuous auditing techniques using computer-assisted audit tools and data analytics. It describes how data analytics can help auditors more efficiently audit large volumes of data by transforming it into structured presentations. The document also outlines different types of automated evaluation techniques for continuous auditing, including systems control audit review files, snapshots, audit hooks, integrated test facilities, and continuous and intermittent simulation.

Uploaded by

Ella Grace
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

Members:

Giner, Steven
Guerra, Erica Joy
Esperida, Kim
Mallon, Kaye Ann
Tabor, Rodelyn
LESSON OBJECTIVES:

Learn Computer- Assisted Audit Tools and


Techniques (CAATTs) as a Continuous Online
Auditing Approach
Learn about Continuous Auditing and Monitoring
DATA ANALYTICS
The IAASB defines data analytics for audit as the
science and art of discovering and analyzing patterns,
deviations and inconsistencies, and extracting other useful
information in the data underlying or related to the subject
matter of an audit through analysis, modelling and
visualization for the purpose of planning and performing
the audit.
HOW CAN DATA ANALYTICS BE USED BY AUDIT FIRMS?

In order to lower risk and provide more value to the client, both larger audit
firms and progressively smaller enterprises include data analytics in their audit
offerings. Smaller businesses may decide to purchase an off-the-shelf
solution, whereas larger businesses frequently have the ability to build their
own data analytics platforms. These tools are typically created by specialized
employees and convey data using visual techniques like graphs to assist spot
trends and correlations.
HOW CAN DATA ANALYTICS BE USED BY AUDITORS?

The primary motivation for employing data analytics for auditors is, it
enables auditors to more efficiently audit the massive volumes of data stored
and processed in larger companies' IT systems.
Data analytics tools have the ability to transform all the data into pre-
structured forms or presentations that are clear to auditors and clients or to
provide data directly into computerized audit procedures, which enables the
auditor to reach the result more quickly.
DO MORE in
Less Time using

Data Analytics!
DEFINITION
Computer- Assisted
Audit Tools and
Techniques (CAATTs)

CATTs are the practice of using computers to automate


the IT audit processes. Typically include essential
office productivity software and more advanced
software packages involving statistical analysis and
business intelligence tools.
CAATTS AS A CONTINUOUS ONLINE
AUDIT APPROACH
“Continuous Auditing is any method Continuous auditing is an approach used by IS
used by auditors to perform audit- auditors to monitor system reliability
related activities on a more continuously and gather selective audit
continuous or continual basis.” 
evidence through the computer. A distinctive
-Institute of Internal Auditors
characteristics of constant auditing is the short
time-lapse between the fact to be audited, the
collection of evidence, and audit reporting.
DISTINCTION BETWEEN CONSTANT AUDITING AND
CONSTANT MONITORING

Continuous Auditing Continuous Monitoring


Enables an IS auditor to perform Used by an organization to
tests and assessments in real- observe the performance of one
time or near-real-time or many processes, systems, or
environment. It also enables an IS
auditor to report results on the
types of data. For example, real-
subject matter being audited within a time antivirus or IDSs may
much shorter time frame than under a operate in a continuous
traditional audit approach. monitoring fashion.
Illustration
Continuous auditing should be independent of continuous control or
monitoring activities. When both continuous monitoring and auditing occur,
ongoing assurance can be established. In practice, continuous auditing is the
precursor to management adopting continuous monitoring as a process on a
day-to-day basis. The lack of independence and objectivity inherent in
continuous monitoring should not be overlooked, and continuous monitoring
should never be considered a substitute for the audit function.
Continuous auditing efforts often incorporate new IT developments;
increased processing capabilities of current hardware, software, standards, and
Al tools; and attempts to collect and analyze data during the transaction. Data
must be gathered from different applications working within different
environments and transactions must be screened. The IT environment is a
natural enabler for the application of continuous auditing because of the intrinsic
automated nature of its underlying processes.
Continuous auditing aims to provide a more secure platform to avoid fraud and
a real-time process to ensure a high level of financial control. If applied
appropriately, these environments can output exception lists on request while
operating against actual data. Therefore, they represent an instance of
continuous auditing.
The difficulty, but significant added value, of using these features is that they
postulate a definition of what would be a "dangerous" or exception condition. For
example, whether a set of granted IS access permissions are deemed risk-free
will depend on having well-defined SOD. On the other hand, it may be much
harder to decide if a given sequence of steps to modify and maintain a database
record points to potential risk. It is vital to validate the data source used for
continuous auditing and note the possibility of manual changes.
CONTINUOUS AUDITING TECHNIQUE

Are essential IS audit tools, mainly used in time-sharing environments


that process many transactions but leave a scarce paper trail. By permitting
an IS auditor to evaluate operating controls continuously without disrupting
the organization's usual operations, continuous audit techniques improve
the security of a system. When a system is misused by someone
withdrawing money from an inoperative account, a constant audit technique
will report this withdrawal in a timely fashion to an IS auditor.
FIVE (5) TYPES OF AUTOMATED EVALUATION
TECHNIQUES APPLICABLE TO CONTINUOUS AUDITING

1. Systems Control Audit Review File and Embedded Audit Modules (SCARF/EAM) -
This technique involves embedding specially written audit software in the
organization's host application system, so the application systems are monitored on
a selective basis.
2. Snapshots - This technique involves taking what might be termed "pictures" of a
transaction's processing path from the input to the output stage. With this technique,
transactions are tagged by applying identifiers to input data and recording selected
information about what occurs for an IS auditor's subsequent review.
3. Audit Hooks – This technique involves embedding hooks in application systems to
function as red flags and induce IS security and auditors to act before an error or irregularity
gets out of hand.

4. Integrated test facility (ITF) – Dummy entities are set up and included in an auditee's
production files in this technique. An IS auditor can make the system either process live
transactions or test transactions during regular processing runs and have these transactions
update the records of the dummy entity. The operator simultaneously enters the test
transactions with the live transactions for processing. An auditor then compares the output
with the data that have been independently calculated to verify the correctness of the
computer-processed data.
5. Continuous and Intermittent Simulation (CIS) – During a transaction
process run, the computer system simulates the instruction execution of the
application. As each transaction is entered, the simulator decides whether the
transaction meets specific predetermined criteria and, if so, audits the
transaction. If not, the simulator waits until it encounters the next transaction
that meets the requirements.
The use of each of the continuous audit techniques has advantages and
disadvantages. Their selection and implementation depend primarily on the complexity
an organization's computer systems and applications. An IS auditor can understand
and evaluate the system with and without continuous audit techniques. In addition, an
IS auditor must recognize that continuous audit techniques are not a cure for all control
problems. These techniques provide only limited assurance that the information
processing systems examined are operating as they were intended to function.
Note!
 Complete continuous auditing processes must be carefully built into applications and work in
layers. The auditing tools must operate parallel to standard processing-capturing real-time
data, extracting standardized profiles or descriptors, and passing the result to the auditing
layers.

 Continuous auditing has an intrinsic edge over point-in-time or periodic auditing because it
captures internal control problems, preventing adverse effects. Implementation can also
reduce possible or ingrained audit inefficiencies such as delays, planning time, inefficiencies
of the audit process, the overhead due to work segmentation, multiple quality or supervisory
reviews, or discussions concerning the validity of findings.
References:

ACC120: Auditing in a Computerized Information


System Environment- SAS #11
[Link]
al-exams-study-resources/p7/technical-articles/[Link]

https://
[Link]/vn/en/services/consulting/[Link]

[Link]

You might also like