Preview

Process Control and Audit Guidelines

Powerful Essays
Open Document
Open Document
52875 Words
Grammar
Grammar
Plagiarism
Plagiarism
Writing
Writing
Score
Score
Process Control and Audit Guidelines
AUDIT GUIDELINES
Level 1 General IT audit approach
COBIT Framework Audit Process Requirements Control Observations Generic Audit Guideline

Level 2 Process audit guidelines Level 3 Audit attention points to complement detailed control objectives

J Detailed Audit Guidelines

J Local Conditions

sector specific criteria industry standards platform specific elements detailed control techniques used

AUDIT PROCESS REQUIREMENTS
Having defined what we are going to audit and provide assurance on, we have to determine the most appropriate approach or strategy for carrying out our audit work. First we need to determine the correct scope of our audit. To achieve this we need to investigate, analyse and define: • the business processes concerned • the platforms and information systems which are supporting the business process as well as interconnectivity with other platforms or systems • the IT roles and responsibilities defined, including what has been in- or out-sourced • associated business risks and strategic choices

The next step is to identify the information requirements which are of particular relevance with respect to the business processes. Then we will need to identify the inherent IT risks as well as overall level of control which can be associated with the business process. To achieve this we identify: • recent changes in the business environment having an IT impact • recent changes to the IT environment, new developments, etc. • recent incidents relevant to the controls and business environment • IT monitoring controls applied by management • recent audit and/or certification reports • recent results of self assessments

22

IT GOVERNANCE INSTITUTE

AUDIT GUIDELINES
On the basis of the information obtained, we can now select the relevant COBIT processes as well as the resources that apply to them. This could require that certain COBIT processes will need to be audited several times, each time for a different platform or system. One

You May Also Find These Documents Helpful

  • Good Essays

    Information technology and financial audits primary objectives are to ensure data integrity, safety, secure and operational effectiveness for Kudler’s business processes. Internal audit will provide an opinion on the accuracy and fairness of the financial statements. “This fairness evaluation is conducted in the context of generally accepted accounting principles (GAAP) and requires application of generalized auditing standards” (Bargranoff, 2008).…

    • 986 Words
    • 4 Pages
    Good Essays
  • Good Essays

    Sr-Rm-022 Part 2

    • 839 Words
    • 3 Pages

    TIBCO Software Inc. (2001). Business process. (pp. 10-15). Palo Alto, CA: Global Headquarters. Retrieved from htts://www.tibco.com/multimedia/business-process-design_tcm8-2399.pdf…

    • 839 Words
    • 3 Pages
    Good Essays
  • Powerful Essays

    ACCT 601 Final Draft

    • 4036 Words
    • 12 Pages

    During this meeting the information about important processes within the company will be gathered; the organization mangers discuss existing controls, and how to approach the additional steps remaining to this audit. Then the audit committee would need to concentrate on informal communication and testing the transaction procedures. When the auditors conduct fieldwork; the main goal is to determine whether controls identified in the preliminary review are working properly, in the manner which the client described. To complete the fieldwork, they should develop a list of finding to be discussed in the audit report. During this report the auditor will conclude all audit findings and give any…

    • 4036 Words
    • 12 Pages
    Powerful Essays
  • Good Essays

    Before any strategy takes place, an auditor must determine the end result desired from the Information Technology being used as well as the type of technology being dealt with. The most important thing is security thus it is vital to know this technology in and out to be able to determine its strengths and weaknesses. This allows for proper compensation to combat such attacks whether they are fraudulent or accidental in nature. It is necessary to be familiar with different types of proven viable internal control setups to properly test and gage an IT’s internal control system. There are three different strategies use when testing internal controls. First includes assessing the controls using user control information. In this strategy, an auditor would gather computer-generated reports and compare those to all documentation on specific transactions. This process is also known as auditing around the computer because it deals with more hard copy documents. The next strategy entails using application controls to determine the level of risk…

    • 627 Words
    • 3 Pages
    Good Essays
  • Satisfactory Essays

    The purpose of this audit work program is to assess, at a high level, and validate key controls in place for Information and Communication. Inadequate or ineffective controls in this area may give rise to financial and operational risks.…

    • 948 Words
    • 4 Pages
    Satisfactory Essays
  • Good Essays

    The COBIT framework is an ever evolving process designed to organize Information Technology governance objectives and best practices in a global business environment. As new technologies are introduced in the business environment, the requirements for unified guidelines must also be addressed. COBIT is working to help research, promote and publish up-to-date set of control objectives that will be generally accepted by the international…

    • 361 Words
    • 2 Pages
    Good Essays
  • Powerful Essays

    Nt1310 Unit 1 Assignment 1

    • 1434 Words
    • 6 Pages

    A popular saying is, “inspect what you expect,” and this is definitely true in the area of IT information security auditing. The goal should not be to catch rule breakers, but rather to work with IT and the business to ensure nothing slips through the cracks and that solid practices are always followed. Doing this will go a long way to ensuring and maintaining the expected information security policy of the…

    • 1434 Words
    • 6 Pages
    Powerful Essays
  • Good Essays

    It is required for an audit team to assess control risk below the maximum level to identify specific control procedures and policies relevant to specific assertions that will detect and prevent material misstatement regarding those assertions. It is required also to perform control tests in order to evaluate the operating patterns and effectiveness of the internal control procedures.…

    • 1065 Words
    • 5 Pages
    Good Essays
  • Powerful Essays

    Unit 4

    • 1878 Words
    • 8 Pages

    To be well defined and timely, an auditing strategy must provide useful tracking data on an organization's most important resources, critical behaviors, and potential risks. In a growing number of organizations, it must also provide absolute proof that IT operations comply with corporate and regulatory requirements.…

    • 1878 Words
    • 8 Pages
    Powerful Essays
  • Powerful Essays

    The Internal Audit department lacks the needed oversight and monitoring of Alchemy Inc. due to their limited scope and experience. The Audit Committee Policy indicates that the Internal Audit department should report to the Audit Committee. Furthermore, the Audit Committee is required to determine compensation and monitor the internal audit plan. Currently, the Internal Audit…

    • 1978 Words
    • 8 Pages
    Powerful Essays
  • Powerful Essays

    Nt1330 Unit 9 Final Paper

    • 1645 Words
    • 7 Pages

    Organizations, information systems and business processes are the most crucial enablers of the organization growth and works harmoniously in a dynamic relationship to come up with satisfying outcomes. For the business processes there are three types which are the management, operational and supporting processes. Business processes are directly related to the information systems as any changes in the organizations and the business processing needs a drastic change in the information systems. (4)…

    • 1645 Words
    • 7 Pages
    Powerful Essays
  • Good Essays

    Providian Trust case memo

    • 729 Words
    • 3 Pages

    To revise business processes based on effectively using technology as an enabling mechanism and propose how the software would streamline information flow for each of the 17 processes…

    • 729 Words
    • 3 Pages
    Good Essays
  • Powerful Essays

    The purpose of this audit work program is to assess, at a high level, and validate key controls in place for the Control Environment. Inadequate or ineffective controls in this area may give rise to financial and operational risks.…

    • 1911 Words
    • 10 Pages
    Powerful Essays
  • Best Essays

    This report focuses on the design and evaluation of a Management Control System for the Auditing division of “Pierre & Silva” (P&S), a hypothetical established second-tier, industry-specialised accounting firm operating in competition with the Big 4 and other second-tier accounting firms.…

    • 3740 Words
    • 15 Pages
    Best Essays
  • Powerful Essays

    Operations Audit

    • 1362 Words
    • 6 Pages

    This step is considered the basic stage in which the procedures or departments whose operations are to be audited are selected, which significantly affects all subsequent steps of the auditing process. This is accomplished by using the following criteria:  The audit added value: it refers to the impact that will result from improving the implementation of the procedure…

    • 1362 Words
    • 6 Pages
    Powerful Essays