ICT Audit Practice Areas
The Process of
Protection of Auditing
Information Assets, Information
Systems,
Governance and
Management of IT,
Information Systems
Operations,
Maintenance and
Service
Management,
Information Systems
Acquisition,
Development and
Implementation,
1 © Copyright 2016 ISACA. All rights reserved.
Domain 1
Provide audit services to assist the
organization in protecting and controlling
information systems.
2 © Copyright 2016 ISACA. All rights reserved.
Task 1.1
Execute a risk-based IS audit to ensure
that key risk areas are audited.
3 © Copyright 2016 ISACA. All rights reserved.
Key Terms
Key Term Definition
Information systems The combination of strategic, managerial and operational
(IS) activities involved in gathering, processing, storing,
distributing and using information and its related
technologies. Information systems are distinct from
information technology (IT) in that an information system
has an IT component that interacts with the process
components.
Standard A mandatory requirement, code of practice or
specification approved by a recognized external
standards organization, such as International
Organization for Standardization (ISO).
4 © Copyright 2016 ISACA. All rights reserved.
Key Terms (cont’d)
Key Term Definition
Guideline A description of a particular way of accomplishing
something that is less prescriptive than a procedure.
Tools and Tools and techniques provide examples of processes an
techniques IS auditor might follow in an audit engagement. The tools
and techniques documents provide information on how
to meet the standards when completing IS auditing work
but do not set requirements.
5 © Copyright 2016 ISACA. All rights reserved.
IS Audit Function
IS auditing is the formal examination, interview and/or
testing of information systems to determine whether:
o Information systems are in compliance with applicable
laws, regulations, contracts and/or industry
guidelines.
o IS data and information have appropriate levels of
confidentiality, integrity and availability.
o IS operations are being accomplished efficiently, and
effectiveness targets are being met.
6 © Copyright 2016 ISACA. All rights reserved.
IS Auditor Skills
ISACA IS Audit and Assurance Standards require that
the IS auditor be technically competent (1006
Proficiency).
This is achieved through continuing education.
CISA candidates do NOT need to memorize the ISACA
IS Audit and Assurance Standards, Guidelines, and Tools
and Techniques, but they must be able to apply the
standard, guideline or ISACA Code of Professional
Ethics in a given situation.
7 © Copyright 2016 ISACA. All rights reserved.
Code of Professional Ethics
1. Support the implementation of, and encourage
compliance with, appropriate standards, procedures for
the effective governance and management of
enterprise information systems and technology,
including audit, control, security and risk management.
2. Perform their duties with objectivity, due diligence and
professional care, in accordance with professional
standards.
3. Serve in the interest of stakeholders in a lawful manner,
while maintaining high standards of conduct and
character, and not discrediting their profession or the
Association.
8 © Copyright 2016 ISACA. All rights reserved.
Code of Professional Ethics (cont’d)
4. Maintain the privacy and confidentiality of information
obtained in the course of their activities unless
disclosure is required by legal authority. Such
information shall not be used for personal benefit or
released to inappropriate parties.
5. Maintain competency in their respective fields, and
agree to undertake only those activities they can
reasonably expect to complete with the necessary
skills, knowledge and competence.
9 © Copyright 2016 ISACA. All rights reserved.
Code of Professional Ethics (cont’d)
6. Inform appropriate parties of the results of work
performed, including the disclosure of all significant
facts known to them that, if not disclosed, may distort
the reporting of the results.
7. Support the professional education of stakeholders in
enhancing their understanding of the governance and
management of enterprise information systems and
technology, including audit, control, security and risk
management.
10 © Copyright 2016 ISACA. All rights reserved.
Laws and Regulations
Certain industries, such as banks and internet service
providers (ISPs), are closely regulated. These legal
regulations may pertain to financial, operational and IS
audit functions.
There are two areas of concern that impact the audit
scope and objectives:
o Legal requirements placed on the audit
o Legal requirements placed on the auditee and its
systems, data management, reporting, etc.
11 © Copyright 2016 ISACA. All rights reserved.
Laws and Regulations (cont’d)
Examples include:
o US Health Insurance Portability and Accountability Act
(HIPAA)
o US Sarbanes-Oxley Act of 2002
o Basel Accords
o Protection of Personal Data Directives and Electronic
Commerce within the European Community
12 © Copyright 2016 ISACA. All rights reserved.
Laws and Regulations (cont’d)
To determine an organization’s level of compliance, an IS
auditor must:
o Identify those government or other relevant external
requirements dealing with:
• Electronic data, personal data, copyrights,
e-commerce, e-signatures, etc.
• Computer system practices and controls
• The manner in which computers, programs and
data are stored
• The organization or the activities of information
technology services
• IS audits
13 © Copyright 2016 ISACA. All rights reserved.
Laws and Regulations (cont’d)
Also, an IS auditor would perform these additional steps to
determine an organization’s level of compliance:
o Document applicable laws and regulations.
o Assess whether management and the IT function have
considered the relevant external requirements in their plans,
policies, standards and procedures, as well as business
application features.
o Review internal IT department/function/activity documents
that address adherence to laws applicable to the industry.
o Determine adherence to procedures that address these
requirements.
o Determine if there are procedures in place to ensure
contracts or agreements with external IT services providers
reflect any legal requirements related to responsibilities.
14 © Copyright 2016 ISACA. All rights reserved.
CSA
Control self-assessment (CSA) is an assessment of
controls made by the staff and management to assure
stakeholders, customers and other parties of the
reliability of the organization’s internal controls.
It can consist of simple questionnaires to facilitated
workshops.
Tools include:
o Management meetings
o Client workshops
o Worksheets
o Rating sheets
15 © Copyright 2016 ISACA. All rights reserved.
CSA Objectives
The primary objective is to leverage the internal audit
function by shifting some of the control monitoring
responsibilities to the functional areas.
CSA empowers workers to assess or even design the
control environment.
An IS auditor’s role is to facilitate and guide the auditees
in assessing their environment by providing insight about
the objectives of controls based on the risk assessment.
16 © Copyright 2016 ISACA. All rights reserved.
CSA Pros and Cons
Advantages Disadvantages
• Early detection of risk • Mistaken as an audit function
• More effective and improved replacement
internal controls • Regarded as an additional
• Creation of cohesive teams workload
through employee • Failure to act on improvement
involvement suggestions could damage
• Developing sense of employee morale
ownership • Lack of motivation may limit
• Increased employee effectiveness in the detection
awareness of weak controls
• Increased communication
• Improved audit rating process
• Reduction in control cost
• Assurance provided to
stakeholders and customers
17 © Copyright 2016 ISACA. All rights reserved.
Key Terms
Key Term Definition
Audit plan A plan containing the nature, timing and extent of audit
procedures to be performed by engagement team
members in order to obtain sufficient appropriate audit
evidence to form an opinion; includes the areas to be
audited, the type of work planned, the high-level
objectives and scope of the work and topics such as
budget, resource allocation, schedule dates, type of
report and its intended audience, and other general
aspects of the work
Audit risk The probability that information or financial reports may
contain material errors and that the auditor may not
detect an error that has occurred
18 © Copyright 2016 ISACA. All rights reserved.
Key Terms (cont’d)
Key Term Definition
Audit universe An inventory of audit areas that is compiled and
maintained to identify areas for audit during the audit
planning process
Reasonable A level of comfort short of a guarantee but considered
assurance adequate given the costs of the control and the likely
benefits achieved
19 © Copyright 2016 ISACA. All rights reserved.
Audit Planning
The first step in performing an IS audit is adequate
planning.
To plan an audit, the following tasks must be completed:
o List all the processes that may be considered for the
audit.
o Evaluate each process by performing a qualitative or
quantitative risk assessment. These evaluations
should be based on objective criteria.
o Define the overall risk of each process.
o Construct an audit plan to include all of the processes
that are rated “high” which would represent the ideal
annual audit plan.
20 © Copyright 2016 ISACA. All rights reserved.
When To Audit
Audit planning includes short-term and long-term
planning.
o Short-term planning involves all audit issues that will
be covered during the year.
o Long-term planning takes into account all risk-related
issues that might be affected by the organization’s IT
strategic direction.
21 © Copyright 2016 ISACA. All rights reserved.
When To Audit (cont’d)
In addition to a yearly analysis of short-term and
long-term issues, individual audits may be conducted
based on the following:
o New control issues
o Changes in risk environment, technologies and
business processes
o Enhanced evaluation techniques
22 © Copyright 2016 ISACA. All rights reserved.
Audit Planning Steps
In order to plan an audit, the IS auditor must have an
understanding of the overall environment under review.
To accomplish this task, the IS auditor should:
o Gain an understanding of the business’s mission,
objectives, purpose and processes.
o Understand changes in business environment of the
auditee.
o Review prior work papers.
o Identify stated contents, such as policies, standards
and required guidelines, procedures and organization
structure.
23 © Copyright 2016 ISACA. All rights reserved.
Audit Planning Steps (cont’d)
Also, to plan for an audit, the IS auditor should:
o Perform a risk analysis to help in designing the audit
plan.
o Set the audit scope and audit objectives.
o Develop the audit approach or audit strategy.
o Assign personnel resources to the audit.
o Address engagement logistics.
24 © Copyright 2016 ISACA. All rights reserved.
Risk Analysis
During audit planning, the IS auditor must perform or
review a risk analysis to identify risks and vulnerabilities
in order to determine the controls needed to mitigate
those risks.
The IS auditor’s role is to:
o Understand the relationship between risk and control.
o Identify and differentiate risk types and the controls
used to mitigate the risk.
o Evaluate risk assessment and management
techniques used by the organization.
o Understand that risk exists as part of the audit
process.
25 © Copyright 2016 ISACA. All rights reserved.
Risk Analysis (cont’d)
IS auditors are often focused on high-risk issues
associated with confidentiality, integrity and availability of
sensitive and critical information.
26 © Copyright 2016 ISACA. All rights reserved.
Risk-based Auditing
Gather Information and Plan
• Knowledge of business and industry • Regulatory statutes
• Prior year’s audit results • Inherent risk assessments
• Recent financial information
Obtain Understanding of Internal Control
• Control environment • Control risk assessment
• Control procedures • Equate total risk
• Detection risk assessment
Perform Compliance Tests
• Identify key controls to be tested. • Perform tests on reliability, risk
prevention and adherence to
organization policies and procedures.
Perform Substantive Tests
• Analytical procedures • Other substantive audit procedures
• Detailed tests of account balances
Conclude the Audit
• Create recommendations. • Write audit report.
Source: ISACA, CISA Review Manual 26th Edition, figure 1.8
27 © Copyright 2016 ISACA. All rights reserved.
Internal Controls
Internal controls are normally composed of policies,
procedures, practices and organizational structures that
are implemented to reduce risk to the organization.
Internal controls should address:
o What should be achieved?
o What should be avoided?
28 © Copyright 2016 ISACA. All rights reserved.
Control Classification
Class Function
Preventive • Detect problems before they arise.
• Monitor both operation and inputs.
• Attempt to predict potential problems before they occur and make
adjustments.
• Prevent an error, omission or malicious act from occurring.
• Segregate duties (deterrent factor).
• Control access to physical facilities.
• Use well-designed documents (prevent errors).
Detective • Use controls that detect and report the occurrence of an error,
omission or malicious act.
Corrective • Minimize the impact of a threat.
• Remedy problems discovered by detective controls.
• Identify the cause of a problem.
• Correct errors arising from a problem.
• Modify the processing system(s) to minimize future occurrences of
the problem.
Source: ISACA, CISA Review Manual 26th Edition, figure 1.5
29 © Copyright 2016 ISACA. All rights reserved.
IS Control Objectives
IS control objectives are statements of the desired result
achieved by implementing controls. They provide
reasonable assurance that the business objectives will
be achieved and undesired events will be prevented,
detected or corrected.
30 © Copyright 2016 ISACA. All rights reserved.
IS Control Objectives (cont’d)
IS control objectives may also include:
o Safeguarding assets
o System development life cycle (SDLC) processes are
established, in place and operating effectively
o Integrity of general operating system (OS)
environments
o Integrity of sensitive and critical application system
environments
o Appropriate identification and authentication of users
o The efficiency and effectiveness of operations
o Integrity and reliability of systems by implementing
effective change management procedures
31 © Copyright 2016 ISACA. All rights reserved.
General Controls
General controls include:
• Internal accounting controls that concern the
safeguarding of assets and reliability of financial
information
• Operational controls that concern day-to-day operations,
functions and activities
• Administrative controls that concern operational efficiency
in a functional area and adherence to management
policies
• Organizational security policies and procedures to ensure
proper usage of assets
• Overall policies for the design and use of adequate
documents and records
• Access and use procedures and practices
• Physical and logical security policies for all facilities
32 © Copyright 2016 ISACA. All rights reserved.
IT Specific Controls
Each general control can be translated into an
IS-specific control. The IS auditor should understand IS
controls and how to apply them in planning an audit.
IS control procedures include:
o Strategy and direction of the IT function
o General organization and management of the IT
function
o Access to IT resources, including data and programs
o Systems development methodologies and change
control
33 © Copyright 2016 ISACA. All rights reserved.
IS Specific Controls (cont’d)
Additional IS control procedures include:
o Operations procedures
o Systems programming and technical support
functions
o Quality assurance (QA) procedures
o Physical access controls
o Business continuity planning (BCP)/disaster recovery
planning (DRP)
o Networks and communications
o Database administration
o Protection and detective mechanisms against internal
and external attacks
34 © Copyright 2016 ISACA. All rights reserved.
Types of Audits
Type Description
Compliance Compliance audits include specific tests of controls to
audits demonstrate adherence to specific regulatory or industry
standards. Examples include Payment Card Industry Data
Security Standard (PCI DSS) audits for companies that
process credit card data and Health Insurance Portability and
Accountability Act (HIPAA) audits for companies that handle
health care data.
Financial The purpose of a financial audit is to assess the accuracy of
audits financial reporting. It often involves detailed, substantive
testing, although increasingly, auditors are placing more
emphasis on a risk- and control-based audit approach. This
kind of audit relates to financial information integrity and
reliability.
35 © Copyright 2016 ISACA. All rights reserved.
Types of Audits (cont’d)
Type Description
Operational An operational audit is designed to evaluate the internal
audits control structure in a given process or area. Examples include
IS audits of application controls or logical security systems.
Administrative These are oriented to assess issues related to the efficiency
audits of operational productivity within an organization.
IS audits This process collects and evaluates evidence to determine
whether the information systems and related resources
adequately safeguard assets, maintain data and system
integrity and availability, provide relevant and reliable
information, achieve organizational goals effectively, and
consume resources efficiently. Also, do they have, in effect,
internal controls that provide reasonable assurance that
business, operational and control objectives will be met and
that undesired events will be prevented, or detected and
corrected, in a timely manner.
36 © Copyright 2016 ISACA. All rights reserved.
Types of Audits (cont’d)
Type Description
Forensic audits Forensic auditing has been defined as auditing specialized in
discovering, disclosing and following up on fraud and crimes.
The primary purpose of such a review is the development of
evidence for review by law enforcement and judicial
authorities.
Integrated An integrated audit combines financial and operational audit
audits steps. It is performed to assess the overall objectives within
an organization, related to financial information and assets’
safeguarding, efficiency and compliance.
37 © Copyright 2016 ISACA. All rights reserved.
Integrated Audit
An integrated audit focuses
on risk. It involves a team
of auditors with different
skill sets working together
to provide a Operational Financial
Audit Audit
comprehensive report.
IS Audit
Source: ISACA, CISA Review Manual 26th Edition,
figure 1.13
38 © Copyright 2016 ISACA. All rights reserved.
Integrated Audit (cont’d)
The process typically involves:
o Identification of risk faced by
the organization for the area
being audited
o Identification of relevant key
controls Operational Financial
Audit Audit
o Review and understanding of
the design of key controls
o Testing that key controls are
supported by the IT system
o Testing that management IS Audit
controls operate effectively
o A combined report or opinion
on control risk, design and
weaknesses
Source: ISACA, CISA Review Manual 26th Edition,
figure 1.13
39 © Copyright 2016 ISACA. All rights reserved.
Continuous Auditing
Continuous auditing is characterized by the short time
lapse between the audit, the collection of evidence and
the audit reporting.
It results in better monitoring of financial issues, such as
fraud, ensuring that real-time transactions benefit from
real-time monitoring.
Continuous auditing should be independent of
continuous controls and continuous monitoring.
40 © Copyright 2016 ISACA. All rights reserved.
Continuous Auditing (cont’d)
This process must be carefully built into the business
applications and may include IT techniques such as:
o Transaction logging
o Query tools
o Statistics and data analysis (CAAT)
o Database management systems (DBMS)
o Intelligent agents
41 © Copyright 2016 ISACA. All rights reserved.
Continuous Auditing (cont’d)
For continuous auditing to succeed, it needs to have:
o A high degree of automation.
o Alarm triggers to report timely control failures.
o Implementation of highly automated audit tools that require
the IS auditor to be involved in setting up the parameters.
o The ability to quickly inform IS auditors of the results of
automated procedures, particularly when the process has
identified anomalies or errors.
o Quick and timely issuance of automated audit reports.
o Technically proficient IS auditors.
o Availability of reliable sources of evidence.
o Adherence to materiality guidelines.
42 © Copyright 2016 ISACA. All rights reserved.
Audit Phases
Audit Phase Description
Audit subject • Identify the area to be audited.
Audit objective • Identify the purpose of the audit.
Audit scope • Identify the specific systems, function or unit of the
organization to be included in the review.
Preaudit • Identify technical skills and resources needed.
planning • Identify the sources of information for test or review, such
as functional flow charts, policies, standards, procedures
and prior audit work papers.
• Identify locations or facilities to be audited.
• Develop a communication plan at the beginning of each
engagement that describes who to communicate to, when,
how often and for what purpose(s).
Source: ISACA, CISA Review Manual 26th Edition, figure 1.7
43 © Copyright 2016 ISACA. All rights reserved.
Audit Phases (cont’d)
Audit Phase Description
Audit • Identify and select the audit approach to verify and test the
procedures controls.
and steps for • Identify a list of individuals to interview.
data gathering • Identify and obtain departmental policies, standards and
guidelines for review.
• Develop audit tools and methodology to test and verify
control.
Procedures for • Identify methods (including tools) to perform the evaluation.
evaluating the • Identify criteria for evaluating the test (similar to a test
test or review script for the IS auditor to use in conducting the
results evaluation).
• Identify means and resources to confirm the evaluation
was accurate (and repeatable, if applicable).
Source: ISACA, CISA Review Manual 26th Edition, figure 1.7
44 © Copyright 2016 ISACA. All rights reserved.
Audit Phases (cont’d)
Audit Phase Description
Procedures for • Determine frequency of communication.
communication • Prepare documentation for final report.
with
management
Audit report • Disclose follow-up review procedures.
preparation • Disclose procedures to evaluate/test operational efficiency
and effectiveness.
• Disclose procedures to test controls.
• Review and evaluate the soundness of documents, policies
and procedures.
Source: ISACA, CISA Review Manual 26th Edition, figure 1.7
45 © Copyright 2016 ISACA. All rights reserved.
IS Audit Steps
Define the audit scope.
Formulate the audit objectives.
Identify the audit criteria.
Perform audit procedures.
Review and evaluate evidence.
Form audit conclusions and opinions.
Report to management after discussion with key process owners.
46 © Copyright 2016 ISACA. All rights reserved.
Audit Objectives
A key element in IS audit planning is translating basic
audit objectives into specific IS audit objectives.
Audit objectives refer to the specific goals that must be
accomplished by the audit. They are often focused on
validating that internal controls exist and are effective at
minimizing business risk.
47 © Copyright 2016 ISACA. All rights reserved.
Audit Risk
Audit risk can be defined as the risk that information may
contain a material error that may go undetected during
the course of the audit.
48 © Copyright 2016 ISACA. All rights reserved.
Audit Risk (cont’d)
Audit risk is influenced by:
o Inherent risk―the risk level or exposure of the
process/entity to be audited without taking into
account the controls that management has
implemented
o Control risk―risk that a material error exists that
would not be prevented or detected on a timely basis
by the system of internal controls
o Detection risk―risk that material errors or
misstatements have occurred that will not be detected
by the IS auditor
o Overall audit risk―probability that information may
contain material errors
49 © Copyright 2016 ISACA. All rights reserved.
Audit Risk (cont’d)
The IS auditor should have a good understanding of
audit risk when planning an audit.
Proper sampling procedures and strong quality control
processes can minimize detection risk.
50 © Copyright 2016 ISACA. All rights reserved.
Audit Programs
An audit program is a step-by-step set of audit
procedures and instructions that should be performed to
complete an audit.
Audit programs are based on the scope and objective of
the particular assignment.
It is the audit strategy and plan.
It identifies scope, audit objectives and audit procedures
to obtain sufficient, relevant and reliable evidence to
draw and support audit conclusions and opinions.
51 © Copyright 2016 ISACA. All rights reserved.
Program Procedures
Procedures for Testing and
General Audit Procedures
Evaluating IS Controls
• Obtaining and recording an • The use of generalized audit
understanding of the audit software to survey the contents of
area/subject data files (including system logs)
• A risk assessment and general • The use of specialized software to
audit plan and schedule assess the contents of OS
• Detailed audit planning database and application parameter
• Preliminary review of the audit files
area/subject • Flow-charting techniques for
• Evaluating the audit area/subject documenting automated
• Verifying and evaluating the applications and business
appropriateness of controls processes
designed to meet control objectives • The use of audit logs/reports
• Compliance testing available in operation/application
• Substantive testing systems
• Documentation review
• Reporting
• Inquiry and observation
• Follow-up
• Walk-throughs
• Reperformance of controls
52 © Copyright 2016 ISACA. All rights reserved.
Fraud Detection
The presence of internal controls does not altogether
eliminate fraud.
Legislation and regulations relating to corporate
governance cast significant responsibilities on
management, auditors and the audit committee
regarding detection and disclosure of any fraud, whether
material or not.
The IS auditor should be aware of potential legal
requirements concerning the implementation
of specific fraud detection
procedures and reporting ISACA IS Audit and Assurance
Standard 1005 Due
fraud to appropriate Professional Care
authorities.
53 © Copyright 2016 ISACA. All rights reserved.
Testing Methods
Compliance testing:
o Tests of control designed to obtain audit evidence on
both the effectiveness of the controls and their
operation during the audit period.
Substantive testing:
o Obtaining audit evidence on the completeness,
accuracy or existence of activities or transactions
during the audit period.
54 © Copyright 2016 ISACA. All rights reserved.
Testing Process
This figure shows the relationship between compliance and
substantive testing and describes the two categories of
substantive tests.
Source: ISACA, CISA Review Manual 26th Edition, figure 1.9
55 © Copyright 2016 ISACA. All rights reserved.
Evidence
Evidence is any information used by ISACA IS Audit and
the IS auditor to determine whether Assurance Standard
the entity or data being audited follows 1205 Evidence
the established criteria or objectives
and supports audit conclusions.
Some types of evidence are more reliable than others.
Reliability is determined by:
o The independence of the evidence provider
o The qualifications of the evidence provider
o The objectivity of the evidence
o The timing of the evidence
The IS auditor must focus on the objectives of the audit and not
on the nature of the evidence.
Evidence is considered competent when it is both valid and
relevant.
56 © Copyright 2016 ISACA. All rights reserved.
Evidence Gathering Techniques
Review IS Review IS
Review IS
organizational policies and
standards.
structures. procedures.
Observe
Interview
Review IS processes and
appropriate
documentation. employee
personnel.
performances.
Conduct a Conduct
reperformance. walkthroughs.
57 © Copyright 2016 ISACA. All rights reserved.
Interviews and Observations
Observing personnel in the performance of their duties
assists an IS auditor in identifying:
Actual
Actual Security Reporting
processes/
functions awareness relationships
procedures
Note that personnel may change their behavior if they
know they are being observed. Therefore, combine
observations with interviews, which can provide
adequate assurance that personnel have the required
technical skills.
58 © Copyright 2016 ISACA. All rights reserved.
CAATs
CAATs help IS auditors collect sufficient, relevant and
useful evidence that may only exist in electronic form.
They are particularly useful when auditing systems that
have different hardware and software environments,
data structures, record formats or processing functions.
59 © Copyright 2016 ISACA. All rights reserved.
CAATs (cont’d)
CAATs include many tools and techniques, such as:
o Generalized audit software (GAS)
o Utility software
o Debugging and scanning software
o Test data
o Application software tracing and
mapping
o Expert systems
60 © Copyright 2016 ISACA. All rights reserved.
CAAT Considerations
Before the use of a CAAT, consider:
o Ease of use, both for existing and future audit staff
o Training requirements
o Complexity of coding and maintenance
o Flexibility of uses
o Installation requirements
o Processing efficiencies (especially with a PC CAAT)
o Effort required to bring the source data into the CAATs for analysis
o Ensuring the integrity of imported data by safeguarding their
authenticity
o Recording the time stamp of data downloaded at critical processing
points to sustain the credibility of the review
o Obtaining permission to install the software on the auditee servers
o Reliability of the software
o Confidentiality of the data being processed
61 © Copyright 2016 ISACA. All rights reserved.
Evaluation of Controls
After gathering evidence, the IS auditor can use a control
matrix to assess the strengths and weaknesses of the
controls and determine if they are effective at meeting
the control objectives.
The IS auditor should always review for compensating
controls before reporting control weaknesses.
The IS auditor must keep the concept of materiality in
mind and judge what would be significant to different
levels of management.
62 © Copyright 2016 ISACA. All rights reserved.
Key Terms
Key Term Definition
Audit report Present the auditor’s findings and recommendations to
management.
Stakeholder Anyone who has a responsibility for, an expectation from
or some other interest in the enterprise.
63 © Copyright 2016 ISACA. All rights reserved.
Communication of Results
The IS auditor communicates the audit results in an exit
interview with management.
During the exit interview, the IS auditor should:
o Ensure that the facts presented in the report are
correct.
o Ensure that the recommendations are realistic and
cost-effective, and if not, seek alternatives through
negotiation with auditee management.
o Recommend implementation dates for agreed upon
recommendations.
The IS auditor can present the results of the audit in an
executive summary or a visual presentation.
64 © Copyright 2016 ISACA. All rights reserved.
Communication of Results (cont’d)
Before communicating results of the audit to senior
management, the IS auditor should discuss the findings
with the key process owners to gain an agreement on
the findings and develop a course of corrective action.
IS auditors should feel free to communicate issues or
concerns with senior management or the audit
committee.
65 © Copyright 2016 ISACA. All rights reserved.
Audit Report
Audit reports present the
ISACA IS Audit and
IS auditor’s findings and Assurance Standard
recommendations to 1401 Reporting
management. They are the
end product of the IS audit work.
The report should be balanced, describing not only
negative issues in terms of findings but positive
constructive comments regarding improving processes
and controls or effective controls already in place.
66 © Copyright 2016 ISACA. All rights reserved.
Audit Report Structure
The audit report format and structure is dependent on the organization’s
audit policies and procedures, but reports usually have the following
structure and content:
o An introduction to the report, including the audit objectives, limitations
and scope, the period of audit coverage, and a general statement on
the procedures conducted and processes examined during the audit,
followed by a statement on the IS audit methodology and guidelines
o Audit findings, often grouped in sections by materiality and/or
intended recipient
o The IS auditor’s overall conclusion and opinion on the adequacy of
controls and procedures, and the actual potential risk identified as a
consequence of detected deficiencies
o The IS auditor’s reservations or qualifications with respect to the audit
o Detailed audit findings and recommendations
o A variety of findings, some of which may be quite material while
others are minor in nature
67 © Copyright 2016 ISACA. All rights reserved.
Audit Documentation
Audit documentation provides the necessary evidence
that support the audit findings and conclusions.
It should be clear, complete, and easily retrievable.
It is the property of the auditing entity and should only
be accessible to authorized personnel.
All audit documentation should be:
o Dated
o Initialed
o Page-numbered ISACA IS Audit and
Assurance Guideline 2203
o Self-contained Performance and Supervision
o Properly labeled
o Kept in custody
68 © Copyright 2016 ISACA. All rights reserved.
Audit Documentation (cont’d)
Audit documentation should include, at a minimum, a
record of the following:
o Planning and preparation of the audit scope and
objectives
o Description and/or walk-throughs on the scoped audit
area
o Audit program
o Audit steps performed and audit evidence gathered
o Use of services of other auditors and experts
o Audit findings, conclusions and recommendations
o Audit documentation relation with document
identification and dates
69 © Copyright 2016 ISACA. All rights reserved.
Audit Documentation (cont’d)
Documentation must include all information required by
laws and regulations, contractual stipulations and
professional standards.
70 © Copyright 2016 ISACA. All rights reserved.
Task 1.5
Conduct audit follow-ups to determine
whether appropriate actions have been
taken by management in a timely manner.
71 © Copyright 2016 ISACA. All rights reserved.
Follow-up Activities
Auditing is an ongoing ISACA IS Audit and
process. Assurance Standard
1402 Follow-up Activities
It is the IS auditor’s
responsibility to ensure that
management has taken appropriate corrective actions.
A follow-up program should be implemented to manage
follow-up activities.
When the follow-up occurs depends on the criticality of
the audit findings.
Results of the follow-up should be communicated to the
appropriate level of management.
72 © Copyright 2016 ISACA. All rights reserved.