case study 4-5 Pages + charts
Accounting Information Systems
Fourteenth Edition
Chapter 11
Auditing Computer-Based Information Systems
Copyright © 2018 Pearson Education, Inc. All Rights Reserved
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
If this PowerPoint presentation contains mathematical equations, you may need to check that your computer has the following installed:
1) MathType Plugin
2) Math Player (free versions available)
3) NVDA Reader (free versions available)
1
Learning Objectives
Describe the nature, scope, and objectives of audit work, and identify the major steps in the audit process.
Identify the six objectives of an information system audit, and describe how the risk-based audit approach can be used to accomplish these objectives.
Describe computer audit software, and explain how it is used in the audit of an AIS.
Describe the nature and scope of an operational audit.
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
Auditing
The process of obtaining and evaluating evidence regarding assertions about economic actions and events in order to determine how well they correspond with established criteria.
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
Let’s break down the definition of auditing to see what this really means:
1. an economic event or action has occurred (e.g., financial transaction)
2. what established criteria exists for this event? (is it government compliance or regulation? e.g., Generally Accepted Accounting Principles)
3. how well does this evidence fit with the criteria? (e.g., if it’s a sales event, does the evidence (sales contract) show that the sale was recorded according to GAAP?)
This chapter focuses on the perspective of the internal auditor. An internal auditor is someone who works for the organization but is expected to be independent and objective in their evaluation of the organization. Internal auditors are able to add value to their organization in helping to achieve the goals of the organization by conducting different internal audits:
Financial—examines the reliability and integrity of financial transactions, accounting records, and financial statements
Information systems, or internal control—reviews control policies and procedures of an AIS (input, processing, output, storage)
Operational—focus on efficient use of resources and the accomplishment of established organizational goals and objectives
Compliance—determines if organization is complying with applicable laws, regulations, policies, and procedures
Investigative—examines possible incidents of fraud, misappropriation, waste and abuse, or improper government activities
The other type of auditor is an external auditor. The external auditor is not an employee of the organization. However, external auditors may be hired by an organization to audit the financial statements. This is required for companies that are publicly held. In addition, if a company has a bank loan, the bank may require that the company hire external auditors to do a financial audit.
3
Major Steps in the Auditing Process
Audit planning
Why, how, when, and who
Establish scope and objectives of the audit; identify risk
Collection of audit evidence
Evaluation of evidence
Communication of results
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
There are four major steps in the auditing process:
Audit planning organizes what you need to do, how you are going to do the audit, and who will be doing the audit. This is done by first identifying the risks, then you can adequately understand the scope and objectives of the audit and what will be required to perform the audit. The majority of the audit work will focus on the areas with the highest amount of risk.
There are three types of audit risk:
Inherent risk: risk of control problems in absence of internal controls
Control risk: risk of material misstatement that will get through the internal control structure
Detection risk: risk that auditors and procedures will not detect material misstatement or error
2. Collection of evidence can be conducted in a variety of ways:
Observation
Reviewing documentation
Interviews, discussions, and questionnaires
Physical examination (e.g., inventory counts)
Confirmation with third parties
Reperforming calculations (e.g., estimates such as depreciation or bad debt expense calculations)
Vouching supporting documents (e.g., customer sales order, shipping documents, sales invoice, customer payment)
Analytical review (examining trends and patterns both within organization and their industry)
Audit sampling
3. Evaluation of evidence involves the auditors conclusion that the evidence supports or does not support the assertion.
4. Communication of results is in the form of a written report and often includes recommendations to management.
4
Risk-Based Audit Approach
Determine the threats (fraud and errors) facing the company
Identify control procedures (prevent, detect, correct the threats)
Evaluate control procedures
Review to see if control exists and is in place
Test controls to see if they work as intended
Determine effect of control weaknesses
Compensating controls
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
The risk-based audit approach is a framework for conducting audits.
These four basic areas of the risk-based framework can be applied to an information system audit objectives.
5
Information Systems Audit
Using the risk-based framework for an information systems audit allows the auditor to review and evaluate internal controls that protect the system to meet each of the following objectives:
Protect overall system security (includes computer equipment, programs, and data)
Program development and acquisition occur under management authorization
Program modifications occur under management authorization
Accurate and complete processing of transactions, records, files, and reports
Prevent, detect, or correct inaccurate or unauthorized source data
Accurate, complete, and confidential data files
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
Basically, the risk-based approach (identify, evaluate, review, and test) are applied for each specific objective. The chapter text breaks these out individually for each objective in Tables 11-1 through 11-6. Another way you can think about this is to have a large spreadsheet with the six objectives at the top of the spreadsheet in the columns and the framework along the left-hand side. Then you could see how these six tables focus on the framework. However, because it is so much information, the text does a nice job in breaking this out by specific objective.
6
1. Overall Information System Security
Threats
Controls
Theft of hardware
Damage of hardware (accidental and intentional)
Loss, theft, unauthorized access to
Programs
Data
Other system resources
Unauthorized modification or use of programs and data files
Loss, theft, or unauthorized disclosure of confidential data
Interruption of crucial business activities
Information security/protection plan
Limit physical access to computer equipment
Limit logical access to system using authentication and authorization controls
Data storage and transmission controls
Virus protection and firewalls
File backup and recovery procedures
Fault tolerant systems design
Disaster recovery plan
Preventive maintenance
Firewalls
Casualty and Business Interruption Insurance
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
2. Program Development and Acquisition
Threat
Controls
Inadvertent programming errors
Unauthorized program code
Review software license agreements
Management authorization for:
Program development
Software acquisition
Management and user approval of programming specifications
Testing and user acceptance of new programs
Systems documentation
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
3. Program Modification
Threat
Controls
Inadvertent programming errors
Unauthorized program code
List program components to be modified
Management authorization and approval for modifications
User approval for program change specifications
Test changes to program
System documentation of changes
Changes by personnel independent of users and programmers
Logical access controls
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
4. Computer Processing
Threats
Controls
Failure to detect incorrect, incomplete, or unauthorized input data
Failure to correct errors identified from data editing procedures
Introduction of errors into files or databases during updating
Improper distribution of output
Inaccuracies in reporting
Data editing routines
Proper use of internal and external file labels
Reconciliation of batch totals
Error correction procedures
Understandable documentation
Competent supervision
Effective handling of data input and output by data control personnel
File change listings and summaries for user department review
Maintenance of proper environmental conditions in computer facility
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
5. Source Data
Threat
Controls
Inaccurate source data
Unauthorized source data
User authorization of source data input
Batch control totals
Log receipt, movement, and disposition of source data input
Turnaround documents
Check digit and key verification
Data editing routines
User department review of file change listings and summaries
Effective procedures for correcting and resubmitting erroneous data
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
11
6. Data Files
Threats
Controls
Destruction of stored data from
Errors
Hardware and software malfunctions
Sabotage
Unauthorized modification or disclosure of stored data
Secure storage of data and restrict physical access
Logical access controls
Write-protection and proper file labels
Concurrent update controls
Data encryption
Virus protection
Backup of data files (offsite)
System recovery procedures
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
12
Audit Techniques Used to Test Programs
Integrated Test Facility (ITF)
Uses fictitious inputs
Snapshot Technique
Master files before and after update are stored for specially marked transactions
System Control Audit Review File (SCARF)
Continuous monitoring and storing of transactions that meet pre-specifications
Audit Hooks
Notify auditors of questionable transactions
Continuous and Intermittent Simulation (CIS)
Similar to SCARF for DBMS
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
These are audit techniques used for objectives two and three.
13
Software Tools Used to Test Program Logic
Automated flowcharting program
Interprets source code and generates flowchart
Automated decision table program
Interprets source code and generates a decision table
Scanning routines
Searches program for specified items
Mapping programs
Identifies unexecuted code
Program tracing
Prints program steps with regular output to observe sequence of program execution events
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
These are software tools used for objectives two and three.
14
Computer Audit Software
Computer assisted audit software that can perform audit tasks on a copy of a company’s data. Can be used to:
Query data files and retrieve records based upon specified criteria
Create, update, compare, download, and merge files
Summarize, sort, and filter data
Access data in different formats and convert to common format
Select records using statistical sampling techniques
Perform analytical tests
Perform calculations and statistical tests
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
There are two popularly used computer audit software:
Audit Control Language (ACL) www.acl.com
Interactive Data Extraction and Analysis (IDEA)
15
Operational Audits
Purpose is to evaluate effectiveness, efficiency, and goal achievement. Although the basic audit steps are the same, the specific activities of evidence collection are focused toward operations such as:
Review operating policies and documentation
Confirm procedures with management and operating personnel
Observe operating functions and activities
Examine financial and operating plans and reports
Test accuracy of operating information
Test operational controls
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
Key Terms (1 of 2)
Auditing
Internal auditing
Financial audit
Information systems (internal control) audit
Operational audit
Compliance audit
Investigative audit
Inherent risk
Control risk
Detection risk
Confirmation
Reperformance
Vouching
Analytical review
Materiality
Reasonable assurance
Systems review
Test of controls
Compensating controls
Source code comparison program
Reprocessing
Parallel simulation
Test data generator
Concurrent audit techniques
Embedded audit modules
Integrated test facility (ITF)
Snapshot technique
System control audit review file (SCARF)
Audit log
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
Key Terms (2 of 2)
Audit hooks
Continuous and intermittent simulation (CIS)
Automated flowcharting program
Automated decision table program
Scanning routines
Mapping programs
Program tracing
Input controls matrix
Computer-assisted audit techniques (CAAT)
Generalized audit software (GAS)
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
19