Chapter 2
Information technology –
concepts and controls
1
Concepts
Manual systems
Computerised systems
o Internal processing and storage
o Modifications
o Audit trail
o Artificial intelligence
o Data transmission
o Linked systems
(continued)
2
Concepts (cont’d)
Software:
o Application software
o System software (operating system)
Changes in auditing:
o Auditing around the computer
o Auditing with the computer
o Auditing through the computer
(continued)
3
Concepts (cont’d)
Impact on internal audit:
o Same objectives, new environment
o Knowledge about IT systems and controls needed
Basic elements of a computer:
o CPU
o Secondary storage
o Input devices
o Output devices
o Input/output control units
o Input/output channels
(continued)
4
Concepts (cont’d)
Elements of a computer system:
o Hardware
o System software
o Application software
o Procedures
o Personnel
Sequence of actions in a system:
o Input
o Processing
o Output
(continued)
5
Concepts (cont’d)
Input:
o Data capturing
o Batch data preparation
o Data entry
o Or a combination of the above
(continued)
6
Concepts (cont’d)
Processing:
o Validation
o Calculations
o Comparison
o Summarisation
o File updating
o File maintenance
o Sequencing
o Inquiry
(continued)
7
Concepts (cont’d)
Output:
o Electronic and/or hard copies
o Apart from normal management and
accounting reports, the internal auditor will be
interested in:
Exception reports; and
Error reports
(continued)
8
Concepts (cont’d)
Data structures:
o Character
o Field
o Record
o File
o Database
Primary key for each record
Master and variable information
Fixed or variable field lengths
(continued)
9
Concepts (cont’d)
File organisation:
o Sequential
o Indexed sequential
o Direct
Input and processing methods:
o Batch input/batch processing
o On-line input/batch processing
o On-line input/real-time processing
(continued)
10
Concepts (cont’d)
Distributed data processing:
o LAN
o WAN
Configurations:
o Star
o Ring
o Multidrop
(continued)
11
Concepts (cont’d)
Effect on internal control:
o Less segregation of duties
o Less documentation
o Computer processing and storage
o Limited human involvement
o Consistency in errors
o Transactions automatically generated and
processed
o Specialised knowledge
o Involvement in systems development
o Smaller systems
(continued)
12
Concepts (cont’d)
Additional controls in an IT environment:
o General controls:
Overarching controls that should be presents in
any computerised environment
o Application controls:
Controls that are built into a specific system that
relate to the objectives of the system
13
General controls
3.1 Organisational structure and personnel
o Organisational structure:
Three main functional areas to be segregated,
and also within each area as far as possible
o Personnel:
Human resource management for IT staff
o Operating controls:
Includes scheduling, console logs, housekeeping
and file controls
(continued)
14
General controls (cont’d)
3.2 Facilities and hardware
o Facilities:
Risks
Preventative controls include location,
construction and access of facilities
Detective controls include detection devices and
continuous identification
Corrective controls include fire extinguishers,
insurance, bypass procedures and a documented
recovery plan
(continued)
15
General controls (cont’d)
3.2 Facilities and hardware
o Hardware:
Risks: Faulty hardware and/or data communication
devices
Hardware controls:
• Parity checks
• Duplicate processing
• Equipment checks
• Echo tests
• Validity checks
• Operational controls (Logs, UPS etc.)
(continued)
16
General controls (cont’d)
3.2 Facilities and hardware
o Back-up plan for facilities and hardware:
Hot site
Cold site
o Leasing hardware from vendors
(continued)
17
General controls (cont’d)
3.3 Software, data and documentation
o Software
Permanent set of instructions
Controls:
• Safeguarding of files (Internal file labels, boundary
protection, memory clean-ups)
• Security protection (logs, analysis and passwords)
• Self protection (SDLC, program change controls
and hardwiring)
(continued)
18
General controls (cont’d)
3.3 Software, data and documentation
o Access to data
Physical security
Authorised terminals
Authorised users
Monitoring of system usage
Encryption
(continued)
19
General controls (cont’d)
3.3 Software, data and documentation
o Documentation
To be kept up-to-date
Update whenever a change is made to the
program
Library and back-up copies off-site for
documents, data and master copies of software
(continued)
20
General controls (cont’d)
3.4 System development and program change
controls
o SDLC
Planning
Development (including five types of systems
testing and four types of user testing)
Implementation
o Program changes
Make change to a test copy first!
(continued)
21
Application controls
Both manual and computerised controls, but
relate to one application or transaction type
Dependent on effective general controls
Application controls are selected based on
the specific system and the objectives to be
achieved
(continued)
22
Application controls (cont’d)
Divided into:
o Preventative application controls
o Detective application controls
o Corrective application controls
(continued)
23
Application controls (cont’d)
Applied to each phase:
Data Batch data Batch data
capture preparation input
Processing Output
Data On-line
capture input
(continued)
24
Application controls (cont’d)
Format per phase
o Definition
o Risks
o Preventative controls
o Detective controls
o Corrective controls
o Audit trail
(continued)
25
Application controls (cont’d)
Data capturing
o Usually a manual action on a document, but can
also be electronic in an on-line/real time system
o Risks
(continued)
26
Application controls (cont’d)
Data capturing
o Preventative controls
Manuals
Document design
Security over forms
Personnel practices
(continued)
27
Application controls (cont’d)
Data capturing
o Detective controls
Review and authorisation
o Corrective controls
Error and resubmission procedures
o Audit trail
Source document
Transaction list
(continued)
28
Application controls (cont’d)
Batch data preparation and input
o Preparation: Collection and coding of documents
(where applicable)
o Input: Machine readable format to primary storage
for processing
Risks
(continued)
29
Application controls (cont’d)
Batch data preparation and input
o Preventative controls
Batch controls:
Batch numbers, smaller batches, log book and
batch totals ̶
• Record/document count
• Financial/other total
• Hash total
(continued)
30
Application controls (cont’d)
Batch data preparation and input
o Preventative controls
Transmission documents
Written instructions
Low-error environment
Drop-down menus
Review at break-points
(continued)
31
Application controls (cont’d)
Batch data preparation and input
o Detective controls
Review batch totals
Transmittal slips
Input validation tests for entry:
(continued)
32
Application controls (cont’d)
33
Application controls (cont’d)
Batch data preparation and input
o Limit test
o Field presence test
o Invalid data combination test
o Control/Check digit
o Sequence test
o Key verification/batch total recalculated by
system
(continued)
34
Application controls (cont’d)
Batch data preparation and input
o Corrective controls
Three approaches to resubmission
o Audit trail
Printouts per batch
Printout of rejected transactions
Error log (manual)
Transaction files
(continued)
35
Application controls (cont’d)
Processing
o Internal computer function where calculations etc.
are effected on data, according to instructions
o Risks
o Preventative controls
General controls and input controls
(continued)
36
Application controls (cont’d)
Processing
o Detective controls
Processing activity report
Validation test for data:
• File label check
• Record identification
• Transaction code test
• Anticipation control
Processing errors (arithmetic, reasonableness,
cross-footing)
Subsystem balancing
(continued)
37
Application controls (cont’d)
Processing
o Corrective controls
Suspense account
Removed (not processed further)
Error log (if processed)
o Audit trail
Processing activity report
Program documentation
File activity data
Break points
(continued)
38
Application controls (cont’d)
Output
o Storing of processed results (electronic or hard
copy)
o Risks
(continued)
39
Application controls (cont’d)
Output
o Preventative controls
Distribution checklists
Transmittal sheets
Terminal display controls
o Detective controls
Control group
User procedures
(continued)
40
Application controls (cont’d)
Output
o Corrective controls
Source errors (user)
Processing errors (technical)
Error log for resubmission
o Audit trail
Printouts and reports
(continued)
41
Application controls (cont’d)
On-line input
o Input of individual transactions directly onto the
system through a terminal. High dependence on
programmed controls
o Risks
o Preventative controls
Written instruction
Computer-assisted procedures (layout and
dialogue)
(continued)
42
Application controls (cont’d)
On-line input
o Detective controls
One-way transmission:
• Transaction codes
• Input validation tests
• Data echo test
Extraction/two-way communication:
• Record confirmation check (descriptive echo)
• Verification of data
• Approval test
(continued)
43
Application controls (cont’d)
On-line input
o Corrective controls
Error message on-screen
Error-handling procedures
o Audit trail
Transaction identification number
Transaction list
o Master files
44
Specific environments
o EDI, EFT and e-Commerce
o ERP
o Databases
45
IT governance
King III
o Chapter 5 of King III
Seven principles listed on page 49 of textbook
46