case study 4-5 Pages + charts

profileMbab4
romney_ais14_inppt_11.pptx

Accounting Information Systems

Fourteenth Edition

Chapter 11

Auditing Computer-Based Information Systems

Copyright © 2018 Pearson Education, Inc. All Rights Reserved

Copyright © 2018 Pearson Education, Inc.

Chapter 11: Auditing Computer-Based Information Systems

Slide 1 - ‹#›

If this PowerPoint presentation contains mathematical equations, you may need to check that your computer has the following installed:

1) MathType Plugin

2) Math Player (free versions available)

3) NVDA Reader (free versions available)

1

Learning Objectives

Describe the nature, scope, and objectives of audit work, and identify the major steps in the audit process.

Identify the six objectives of an information system audit, and describe how the risk-based audit approach can be used to accomplish these objectives.

Describe computer audit software, and explain how it is used in the audit of an AIS.

Describe the nature and scope of an operational audit.

Copyright © 2018 Pearson Education, Inc.

Chapter 11: Auditing Computer-Based Information Systems

Slide 1 - ‹#›

Auditing

The process of obtaining and evaluating evidence regarding assertions about economic actions and events in order to determine how well they correspond with established criteria.

Copyright © 2018 Pearson Education, Inc.

Chapter 11: Auditing Computer-Based Information Systems

Slide 1 - ‹#›

Let’s break down the definition of auditing to see what this really means:

1. an economic event or action has occurred (e.g., financial transaction)

2. what established criteria exists for this event? (is it government compliance or regulation? e.g., Generally Accepted Accounting Principles)

3. how well does this evidence fit with the criteria? (e.g., if it’s a sales event, does the evidence (sales contract) show that the sale was recorded according to GAAP?)

This chapter focuses on the perspective of the internal auditor. An internal auditor is someone who works for the organization but is expected to be independent and objective in their evaluation of the organization. Internal auditors are able to add value to their organization in helping to achieve the goals of the organization by conducting different internal audits:

Financial—examines the reliability and integrity of financial transactions, accounting records, and financial statements

Information systems, or internal control—reviews control policies and procedures of an AIS (input, processing, output, storage)

Operational—focus on efficient use of resources and the accomplishment of established organizational goals and objectives

Compliance—determines if organization is complying with applicable laws, regulations, policies, and procedures

Investigative—examines possible incidents of fraud, misappropriation, waste and abuse, or improper government activities

The other type of auditor is an external auditor. The external auditor is not an employee of the organization. However, external auditors may be hired by an organization to audit the financial statements. This is required for companies that are publicly held. In addition, if a company has a bank loan, the bank may require that the company hire external auditors to do a financial audit.

3

Major Steps in the Auditing Process

Audit planning

Why, how, when, and who

Establish scope and objectives of the audit; identify risk

Collection of audit evidence

Evaluation of evidence

Communication of results

Copyright © 2018 Pearson Education, Inc.

Chapter 11: Auditing Computer-Based Information Systems

Slide 1 - ‹#›

There are four major steps in the auditing process:

Audit planning organizes what you need to do, how you are going to do the audit, and who will be doing the audit. This is done by first identifying the risks, then you can adequately understand the scope and objectives of the audit and what will be required to perform the audit. The majority of the audit work will focus on the areas with the highest amount of risk.

There are three types of audit risk:

Inherent risk: risk of control problems in absence of internal controls

Control risk: risk of material misstatement that will get through the internal control structure

Detection risk: risk that auditors and procedures will not detect material misstatement or error

2. Collection of evidence can be conducted in a variety of ways:

Observation

Reviewing documentation

Interviews, discussions, and questionnaires

Physical examination (e.g., inventory counts)

Confirmation with third parties

Reperforming calculations (e.g., estimates such as depreciation or bad debt expense calculations)

Vouching supporting documents (e.g., customer sales order, shipping documents, sales invoice, customer payment)

Analytical review (examining trends and patterns both within organization and their industry)

Audit sampling

3. Evaluation of evidence involves the auditors conclusion that the evidence supports or does not support the assertion.

4. Communication of results is in the form of a written report and often includes recommendations to management.

4

Risk-Based Audit Approach

Determine the threats (fraud and errors) facing the company

Identify control procedures (prevent, detect, correct the threats)

Evaluate control procedures

Review to see if control exists and is in place

Test controls to see if they work as intended

Determine effect of control weaknesses

Compensating controls

Copyright © 2018 Pearson Education, Inc.

Chapter 11: Auditing Computer-Based Information Systems

Slide 1 - ‹#›

The risk-based audit approach is a framework for conducting audits.

These four basic areas of the risk-based framework can be applied to an information system audit objectives.

5

Information Systems Audit

Using the risk-based framework for an information systems audit allows the auditor to review and evaluate internal controls that protect the system to meet each of the following objectives:

Protect overall system security (includes computer equipment, programs, and data)

Program development and acquisition occur under management authorization

Program modifications occur under management authorization

Accurate and complete processing of transactions, records, files, and reports

Prevent, detect, or correct inaccurate or unauthorized source data

Accurate, complete, and confidential data files

Copyright © 2018 Pearson Education, Inc.

Chapter 11: Auditing Computer-Based Information Systems

Slide 1 - ‹#›

Basically, the risk-based approach (identify, evaluate, review, and test) are applied for each specific objective. The chapter text breaks these out individually for each objective in Tables 11-1 through 11-6. Another way you can think about this is to have a large spreadsheet with the six objectives at the top of the spreadsheet in the columns and the framework along the left-hand side. Then you could see how these six tables focus on the framework. However, because it is so much information, the text does a nice job in breaking this out by specific objective.

6

1. Overall Information System Security

Threats

Controls

Theft of hardware

Damage of hardware (accidental and intentional)

Loss, theft, unauthorized access to

Programs

Data

Other system resources

Unauthorized modification or use of programs and data files

Loss, theft, or unauthorized disclosure of confidential data

Interruption of crucial business activities

Information security/protection plan

Limit physical access to computer equipment

Limit logical access to system using authentication and authorization controls

Data storage and transmission controls

Virus protection and firewalls

File backup and recovery procedures

Fault tolerant systems design

Disaster recovery plan

Preventive maintenance

Firewalls

Casualty and Business Interruption Insurance

Copyright © 2018 Pearson Education, Inc.

Chapter 11: Auditing Computer-Based Information Systems

Slide 1 - ‹#›

2. Program Development and Acquisition

Threat

Controls

Inadvertent programming errors

Unauthorized program code

Review software license agreements

Management authorization for:

Program development

Software acquisition

Management and user approval of programming specifications

Testing and user acceptance of new programs

Systems documentation

Copyright © 2018 Pearson Education, Inc.

Chapter 11: Auditing Computer-Based Information Systems

Slide 1 - ‹#›

3. Program Modification

Threat

Controls

Inadvertent programming errors

Unauthorized program code

List program components to be modified

Management authorization and approval for modifications

User approval for program change specifications

Test changes to program

System documentation of changes

Changes by personnel independent of users and programmers

Logical access controls

Copyright © 2018 Pearson Education, Inc.

Chapter 11: Auditing Computer-Based Information Systems

Slide 1 - ‹#›

4. Computer Processing

Threats

Controls

Failure to detect incorrect, incomplete, or unauthorized input data

Failure to correct errors identified from data editing procedures

Introduction of errors into files or databases during updating

Improper distribution of output

Inaccuracies in reporting

Data editing routines

Proper use of internal and external file labels

Reconciliation of batch totals

Error correction procedures

Understandable documentation

Competent supervision

Effective handling of data input and output by data control personnel

File change listings and summaries for user department review

Maintenance of proper environmental conditions in computer facility

Copyright © 2018 Pearson Education, Inc.

Chapter 11: Auditing Computer-Based Information Systems

Slide 1 - ‹#›

5. Source Data

Threat

Controls

Inaccurate source data

Unauthorized source data

User authorization of source data input

Batch control totals

Log receipt, movement, and disposition of source data input

Turnaround documents

Check digit and key verification

Data editing routines

User department review of file change listings and summaries

Effective procedures for correcting and resubmitting erroneous data

Copyright © 2018 Pearson Education, Inc.

Chapter 11: Auditing Computer-Based Information Systems

Slide 1 - ‹#›

11

6. Data Files

Threats

Controls

Destruction of stored data from

Errors

Hardware and software malfunctions

Sabotage

Unauthorized modification or disclosure of stored data

Secure storage of data and restrict physical access

Logical access controls

Write-protection and proper file labels

Concurrent update controls

Data encryption

Virus protection

Backup of data files (offsite)

System recovery procedures

Copyright © 2018 Pearson Education, Inc.

Chapter 11: Auditing Computer-Based Information Systems

Slide 1 - ‹#›

12

Audit Techniques Used to Test Programs

Integrated Test Facility (ITF)

Uses fictitious inputs

Snapshot Technique

Master files before and after update are stored for specially marked transactions

System Control Audit Review File (SCARF)

Continuous monitoring and storing of transactions that meet pre-specifications

Audit Hooks

Notify auditors of questionable transactions

Continuous and Intermittent Simulation (CIS)

Similar to SCARF for DBMS

Copyright © 2018 Pearson Education, Inc.

Chapter 11: Auditing Computer-Based Information Systems

Slide 1 - ‹#›

These are audit techniques used for objectives two and three.

13

Software Tools Used to Test Program Logic

Automated flowcharting program

Interprets source code and generates flowchart

Automated decision table program

Interprets source code and generates a decision table

Scanning routines

Searches program for specified items

Mapping programs

Identifies unexecuted code

Program tracing

Prints program steps with regular output to observe sequence of program execution events

Copyright © 2018 Pearson Education, Inc.

Chapter 11: Auditing Computer-Based Information Systems

Slide 1 - ‹#›

These are software tools used for objectives two and three.

14

Computer Audit Software

Computer assisted audit software that can perform audit tasks on a copy of a company’s data. Can be used to:

Query data files and retrieve records based upon specified criteria

Create, update, compare, download, and merge files

Summarize, sort, and filter data

Access data in different formats and convert to common format

Select records using statistical sampling techniques

Perform analytical tests

Perform calculations and statistical tests

Copyright © 2018 Pearson Education, Inc.

Chapter 11: Auditing Computer-Based Information Systems

Slide 1 - ‹#›

There are two popularly used computer audit software:

Audit Control Language (ACL) www.acl.com

Interactive Data Extraction and Analysis (IDEA)

15

Operational Audits

Purpose is to evaluate effectiveness, efficiency, and goal achievement. Although the basic audit steps are the same, the specific activities of evidence collection are focused toward operations such as:

Review operating policies and documentation

Confirm procedures with management and operating personnel

Observe operating functions and activities

Examine financial and operating plans and reports

Test accuracy of operating information

Test operational controls

Copyright © 2018 Pearson Education, Inc.

Chapter 11: Auditing Computer-Based Information Systems

Slide 1 - ‹#›

Key Terms (1 of 2)

Auditing

Internal auditing

Financial audit

Information systems (internal control) audit

Operational audit

Compliance audit

Investigative audit

Inherent risk

Control risk

Detection risk

Confirmation

Reperformance

Vouching

Analytical review

Materiality

Reasonable assurance

Systems review

Test of controls

Compensating controls

Source code comparison program

Reprocessing

Parallel simulation

Test data generator

Concurrent audit techniques

Embedded audit modules

Integrated test facility (ITF)

Snapshot technique

System control audit review file (SCARF)

Audit log

Copyright © 2018 Pearson Education, Inc.

Chapter 11: Auditing Computer-Based Information Systems

Slide 1 - ‹#›

Key Terms (2 of 2)

Audit hooks

Continuous and intermittent simulation (CIS)

Automated flowcharting program

Automated decision table program

Scanning routines

Mapping programs

Program tracing

Input controls matrix

Computer-assisted audit techniques (CAAT)

Generalized audit software (GAS)

Copyright © 2018 Pearson Education, Inc.

Chapter 11: Auditing Computer-Based Information Systems

Slide 1 - ‹#›

Copyright © 2018 Pearson Education, Inc.

Chapter 11: Auditing Computer-Based Information Systems

Slide 1 - ‹#›

19