Accounting Essay 2 pages must answer all questions
Accounting Information Systems
Fourteenth Edition
Chapter 11
Auditing Computer-Based Information Systems
Copyright © 2018 Pearson Education, Inc. All Rights Reserved
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
If this PowerPoint presentation contains mathematical equations, you may need to check that your computer has the following installed:
1) MathType Plugin
2) Math Player (free versions available)
3) NVDA Reader (free versions available)
1
Learning Objectives
Describe the nature, scope, and objectives of audit work, and identify the major steps in the audit process.
Identify the six objectives of an information system audit, and describe how the risk-based audit approach can be used to accomplish these objectives.
Describe computer audit software, and explain how it is used in the audit of an AIS.
Describe the nature and scope of an operational audit.
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
Auditing
The process of obtaining and evaluating evidence regarding assertions about economic actions and events in order to determine how well they correspond with established criteria.
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
3
Major Steps in the Auditing Process
Audit planning
Why, how, when, and who
Establish scope and objectives of the audit; identify risk
Collection of audit evidence
Evaluation of evidence
Communication of results
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
4
Risk-Based Audit Approach
Determine the threats (fraud and errors) facing the company
Identify control procedures (prevent, detect, correct the threats)
Evaluate control procedures
Review to see if control exists and is in place
Test controls to see if they work as intended
Determine effect of control weaknesses
Compensating controls
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
5
Information Systems Audit
Using the risk-based framework for an information systems audit allows the auditor to review and evaluate internal controls that protect the system to meet each of the following objectives:
Protect overall system security (includes computer equipment, programs, and data)
Program development and acquisition occur under management authorization
Program modifications occur under management authorization
Accurate and complete processing of transactions, records, files, and reports
Prevent, detect, or correct inaccurate or unauthorized source data
Accurate, complete, and confidential data files
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
6
1. Overall Information System Security
Threats
Controls
Theft of hardware
Damage of hardware (accidental and intentional)
Loss, theft, unauthorized access to
Programs
Data
Other system resources
Unauthorized modification or use of programs and data files
Loss, theft, or unauthorized disclosure of confidential data
Interruption of crucial business activities
Information security/protection plan
Limit physical access to computer equipment
Limit logical access to system using authentication and authorization controls
Data storage and transmission controls
Virus protection and firewalls
File backup and recovery procedures
Fault tolerant systems design
Disaster recovery plan
Preventive maintenance
Firewalls
Casualty and Business Interruption Insurance
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
2. Program Development and Acquisition
Threat
Controls
Inadvertent programming errors
Unauthorized program code
Review software license agreements
Management authorization for:
Program development
Software acquisition
Management and user approval of programming specifications
Testing and user acceptance of new programs
Systems documentation
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
3. Program Modification
Threat
Controls
Inadvertent programming errors
Unauthorized program code
List program components to be modified
Management authorization and approval for modifications
User approval for program change specifications
Test changes to program
System documentation of changes
Changes by personnel independent of users and programmers
Logical access controls
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
4. Computer Processing
Threats
Controls
Failure to detect incorrect, incomplete, or unauthorized input data
Failure to correct errors identified from data editing procedures
Introduction of errors into files or databases during updating
Improper distribution of output
Inaccuracies in reporting
Data editing routines
Proper use of internal and external file labels
Reconciliation of batch totals
Error correction procedures
Understandable documentation
Competent supervision
Effective handling of data input and output by data control personnel
File change listings and summaries for user department review
Maintenance of proper environmental conditions in computer facility
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
5. Source Data
Threat
Controls
Inaccurate source data
Unauthorized source data
User authorization of source data input
Batch control totals
Log receipt, movement, and disposition of source data input
Turnaround documents
Check digit and key verification
Data editing routines
User department review of file change listings and summaries
Effective procedures for correcting and resubmitting erroneous data
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
11
6. Data Files
Threats
Controls
Destruction of stored data from
Errors
Hardware and software malfunctions
Sabotage
Unauthorized modification or disclosure of stored data
Secure storage of data and restrict physical access
Logical access controls
Write-protection and proper file labels
Concurrent update controls
Data encryption
Virus protection
Backup of data files (offsite)
System recovery procedures
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
12
Audit Techniques Used to Test Programs
Integrated Test Facility (ITF)
Uses fictitious inputs
Snapshot Technique
Master files before and after update are stored for specially marked transactions
System Control Audit Review File (SCARF)
Continuous monitoring and storing of transactions that meet pre-specifications
Audit Hooks
Notify auditors of questionable transactions
Continuous and Intermittent Simulation (CIS)
Similar to SCARF for DBMS
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
13
Software Tools Used to Test Program Logic
Automated flowcharting program
Interprets source code and generates flowchart
Automated decision table program
Interprets source code and generates a decision table
Scanning routines
Searches program for specified items
Mapping programs
Identifies unexecuted code
Program tracing
Prints program steps with regular output to observe sequence of program execution events
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
14
Computer Audit Software
Computer assisted audit software that can perform audit tasks on a copy of a company’s data. Can be used to:
Query data files and retrieve records based upon specified criteria
Create, update, compare, download, and merge files
Summarize, sort, and filter data
Access data in different formats and convert to common format
Select records using statistical sampling techniques
Perform analytical tests
Perform calculations and statistical tests
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
15
Operational Audits
Purpose is to evaluate effectiveness, efficiency, and goal achievement. Although the basic audit steps are the same, the specific activities of evidence collection are focused toward operations such as:
Review operating policies and documentation
Confirm procedures with management and operating personnel
Observe operating functions and activities
Examine financial and operating plans and reports
Test accuracy of operating information
Test operational controls
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
Key Terms (1 of 2)
Auditing
Internal auditing
Financial audit
Information systems (internal control) audit
Operational audit
Compliance audit
Investigative audit
Inherent risk
Control risk
Detection risk
Confirmation
Reperformance
Vouching
Analytical review
Materiality
Reasonable assurance
Systems review
Test of controls
Compensating controls
Source code comparison program
Reprocessing
Parallel simulation
Test data generator
Concurrent audit techniques
Embedded audit modules
Integrated test facility (ITF)
Snapshot technique
System control audit review file (SCARF)
Audit log
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
Key Terms (2 of 2)
Audit hooks
Continuous and intermittent simulation (CIS)
Automated flowcharting program
Automated decision table program
Scanning routines
Mapping programs
Program tracing
Input controls matrix
Computer-assisted audit techniques (CAAT)
Generalized audit software (GAS)
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
Copyright © 2018 Pearson Education, Inc.
Chapter 11: Auditing Computer-Based Information Systems
Slide 1 - ‹#›
19