0% found this document useful (0 votes)
10 views46 pages

IT Concepts and Controls Overview

The document discusses concepts related to information technology and controls. It covers topics like manual and computerized systems, software, auditing approaches, basic computer elements, computer system elements, data structures, file organization, and input/processing/output methods. It also discusses general controls and application controls.

Uploaded by

andre
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPT, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
10 views46 pages

IT Concepts and Controls Overview

The document discusses concepts related to information technology and controls. It covers topics like manual and computerized systems, software, auditing approaches, basic computer elements, computer system elements, data structures, file organization, and input/processing/output methods. It also discusses general controls and application controls.

Uploaded by

andre
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPT, PDF, TXT or read online on Scribd

Chapter 2

Information technology –
concepts and controls

1
Concepts
 Manual systems
 Computerised systems
o Internal processing and storage
o Modifications
o Audit trail
o Artificial intelligence
o Data transmission
o Linked systems
(continued)
2
Concepts (cont’d)
 Software:
o Application software
o System software (operating system)

 Changes in auditing:
o Auditing around the computer
o Auditing with the computer
o Auditing through the computer
(continued)

3
Concepts (cont’d)
 Impact on internal audit:
o Same objectives, new environment
o Knowledge about IT systems and controls needed

 Basic elements of a computer:


o CPU
o Secondary storage
o Input devices
o Output devices
o Input/output control units
o Input/output channels
(continued)

4
Concepts (cont’d)
 Elements of a computer system:
o Hardware
o System software
o Application software
o Procedures
o Personnel
 Sequence of actions in a system:
o Input
o Processing
o Output
(continued)

5
Concepts (cont’d)
 Input:
o Data capturing
o Batch data preparation
o Data entry
o Or a combination of the above
(continued)

6
Concepts (cont’d)
 Processing:
o Validation
o Calculations
o Comparison
o Summarisation
o File updating
o File maintenance
o Sequencing
o Inquiry
(continued)

7
Concepts (cont’d)
 Output:
o Electronic and/or hard copies
o Apart from normal management and
accounting reports, the internal auditor will be
interested in:
 Exception reports; and
 Error reports
(continued)

8
Concepts (cont’d)
 Data structures:
o Character
o Field
o Record
o File
o Database
 Primary key for each record
 Master and variable information
 Fixed or variable field lengths
(continued)

9
Concepts (cont’d)
 File organisation:
o Sequential
o Indexed sequential
o Direct
 Input and processing methods:
o Batch input/batch processing
o On-line input/batch processing
o On-line input/real-time processing
(continued)

10
Concepts (cont’d)

 Distributed data processing:


o LAN
o WAN

 Configurations:
o Star
o Ring
o Multidrop
(continued)
11
Concepts (cont’d)
 Effect on internal control:
o Less segregation of duties
o Less documentation
o Computer processing and storage
o Limited human involvement
o Consistency in errors
o Transactions automatically generated and
processed
o Specialised knowledge
o Involvement in systems development
o Smaller systems
(continued)
12
Concepts (cont’d)
 Additional controls in an IT environment:
o General controls:
 Overarching controls that should be presents in
any computerised environment
o Application controls:
 Controls that are built into a specific system that
relate to the objectives of the system

13
General controls
3.1 Organisational structure and personnel
o Organisational structure:
 Three main functional areas to be segregated,
and also within each area as far as possible
o Personnel:
 Human resource management for IT staff
o Operating controls:
 Includes scheduling, console logs, housekeeping
and file controls
(continued)

14
General controls (cont’d)
3.2 Facilities and hardware
o Facilities:
 Risks
 Preventative controls include location,
construction and access of facilities
 Detective controls include detection devices and
continuous identification
 Corrective controls include fire extinguishers,
insurance, bypass procedures and a documented
recovery plan
(continued)
15
General controls (cont’d)
3.2 Facilities and hardware
o Hardware:
 Risks: Faulty hardware and/or data communication
devices
 Hardware controls:
• Parity checks
• Duplicate processing
• Equipment checks
• Echo tests
• Validity checks
• Operational controls (Logs, UPS etc.)
(continued)

16
General controls (cont’d)

3.2 Facilities and hardware


o Back-up plan for facilities and hardware:
 Hot site
 Cold site
o Leasing hardware from vendors
(continued)

17
General controls (cont’d)
3.3 Software, data and documentation
o Software
 Permanent set of instructions
 Controls:
• Safeguarding of files (Internal file labels, boundary
protection, memory clean-ups)
• Security protection (logs, analysis and passwords)
• Self protection (SDLC, program change controls
and hardwiring)
(continued)

18
General controls (cont’d)
3.3 Software, data and documentation
o Access to data
 Physical security
 Authorised terminals
 Authorised users
 Monitoring of system usage
 Encryption
(continued)

19
General controls (cont’d)

3.3 Software, data and documentation


o Documentation
 To be kept up-to-date
 Update whenever a change is made to the
program
 Library and back-up copies off-site for
documents, data and master copies of software
(continued)

20
General controls (cont’d)
3.4 System development and program change
controls
o SDLC
 Planning
 Development (including five types of systems
testing and four types of user testing)
 Implementation
o Program changes
 Make change to a test copy first!
(continued)

21
Application controls
 Both manual and computerised controls, but
relate to one application or transaction type

 Dependent on effective general controls

 Application controls are selected based on


the specific system and the objectives to be
achieved
(continued)

22
Application controls (cont’d)

 Divided into:
o Preventative application controls
o Detective application controls
o Corrective application controls
(continued)

23
Application controls (cont’d)
 Applied to each phase:

Data Batch data Batch data


capture preparation input

Processing Output

Data On-line
capture input
(continued)
24
Application controls (cont’d)
 Format per phase
o Definition
o Risks
o Preventative controls
o Detective controls
o Corrective controls
o Audit trail
(continued)

25
Application controls (cont’d)

 Data capturing
o Usually a manual action on a document, but can
also be electronic in an on-line/real time system
o Risks
(continued)

26
Application controls (cont’d)

 Data capturing
o Preventative controls
 Manuals
 Document design
 Security over forms
 Personnel practices
(continued)

27
Application controls (cont’d)
 Data capturing
o Detective controls
 Review and authorisation
o Corrective controls
 Error and resubmission procedures
o Audit trail
 Source document
 Transaction list
(continued)

28
Application controls (cont’d)

 Batch data preparation and input


o Preparation: Collection and coding of documents
(where applicable)
o Input: Machine readable format to primary storage
for processing
 Risks
(continued)

29
Application controls (cont’d)
 Batch data preparation and input
o Preventative controls
 Batch controls:
 Batch numbers, smaller batches, log book and
batch totals ̶
• Record/document count
• Financial/other total
• Hash total
(continued)

30
Application controls (cont’d)

 Batch data preparation and input


o Preventative controls
 Transmission documents
 Written instructions
 Low-error environment
 Drop-down menus
 Review at break-points
(continued)

31
Application controls (cont’d)

 Batch data preparation and input


o Detective controls
 Review batch totals
 Transmittal slips
 Input validation tests for entry:
(continued)

32
Application controls (cont’d)

33
Application controls (cont’d)
 Batch data preparation and input
o Limit test
o Field presence test
o Invalid data combination test
o Control/Check digit
o Sequence test
o Key verification/batch total recalculated by
system
(continued)

34
Application controls (cont’d)
 Batch data preparation and input
o Corrective controls
 Three approaches to resubmission
o Audit trail
 Printouts per batch
 Printout of rejected transactions
 Error log (manual)
 Transaction files
(continued)

35
Application controls (cont’d)
 Processing
o Internal computer function where calculations etc.
are effected on data, according to instructions
o Risks
o Preventative controls
 General controls and input controls
(continued)

36
Application controls (cont’d)
 Processing
o Detective controls
 Processing activity report
 Validation test for data:
• File label check
• Record identification
• Transaction code test
• Anticipation control
 Processing errors (arithmetic, reasonableness,
cross-footing)
 Subsystem balancing
(continued)

37
Application controls (cont’d)
 Processing
o Corrective controls
 Suspense account
 Removed (not processed further)
 Error log (if processed)
o Audit trail
 Processing activity report
 Program documentation
 File activity data
 Break points
(continued)
38
Application controls (cont’d)

 Output
o Storing of processed results (electronic or hard
copy)
o Risks
(continued)

39
Application controls (cont’d)
 Output
o Preventative controls
 Distribution checklists
 Transmittal sheets
 Terminal display controls
o Detective controls
 Control group
 User procedures
(continued)

40
Application controls (cont’d)

 Output
o Corrective controls
 Source errors (user)
 Processing errors (technical)
 Error log for resubmission
o Audit trail
 Printouts and reports
(continued)

41
Application controls (cont’d)
 On-line input
o Input of individual transactions directly onto the
system through a terminal. High dependence on
programmed controls
o Risks
o Preventative controls
 Written instruction
 Computer-assisted procedures (layout and
dialogue)
(continued)

42
Application controls (cont’d)
 On-line input
o Detective controls
 One-way transmission:
• Transaction codes
• Input validation tests
• Data echo test
 Extraction/two-way communication:
• Record confirmation check (descriptive echo)
• Verification of data
• Approval test
(continued)

43
Application controls (cont’d)
 On-line input
o Corrective controls
 Error message on-screen
 Error-handling procedures
o Audit trail
 Transaction identification number
 Transaction list
o Master files

44
Specific environments

o EDI, EFT and e-Commerce


o ERP
o Databases

45
IT governance

 King III
o Chapter 5 of King III
 Seven principles listed on page 49 of textbook

46

You might also like