Evidence Collection: Evidence Is not just Evidence
There are three techniques used by auditors in collecting evidence that allows them to understand an organization and its application systems:
Make a judgment about the levels of inherent risk associated with an organization's management and its application systems.
Obtain an understanding of an organization's controls sufficient to make a judgment about the types and levels of controls in the applications system.
Design and perform tests of the existence and reliability of controls on which the organization can depend.
Auditors commonly use the evidence collecting techniques of interviews, questionnaires, and flowcharts to complete their audits.
Interviews
Auditors use interviews to obtain qualitative and quantitative information during their evidence collection efforts. Their objectives are to elicit candid, complete and honest answers from the interviewees. At this point, it is important to differentiate between interviews and interrogations. The reason behind an interrogation is to elicit information about some wrongdoing. Inherently, it is an intrusive method of obtaining information using accusatory language and demeanor. Interviewing is a technique eliciting information from someone who has more information than the interviewer who is requesting a response from a fellow professional. It is a kinder, gentler approach to eliciting information than an interrogation.
Auditors must conduct effective interviews, but first, they must understand the interviewee's motivation for answering the auditor's questions. Usually, the respondent's motivation to reply to questions asked during the interview is a function of how they perceive the interview to be a means of reaching their goals or something the respondent wants. For example, if a respondent sees the audit as a process in assisting them in attaining their performance goals, they will likely answer questions frankly and directly. However, if the interviewee views the auditor's interview as a process hindering their work, it is possible their answers will be evasive, incomplete, and even antagonistic. Wise auditors ask themselves, "What's in the interview for the respondent?"
Interview Preparation
Auditors may control the amount of interview stress by limiting the number of difficult questions asked. In this fashion, more stressful interviews should be shorter. Experienced auditors take sufficient steps to alleviate any respondent fears before the interview begins. Interviewers should be aware of the interviewee's desire to pursue topics that interest them if they perceive the auditor to be a responsible person. The auditor's task is one of establishing a professional rapport as quickly and effectively as possible. This is another one of those good judgment areas for auditors. Adept auditors clearly communicate the purpose and intent of the interview at the outset to show empathy, professional and responsible demeanor, and promote mutual trust and respect.
Doing Your Homework
Before beginning an interview, auditors should be mindful that the information they require is not available from anywhere else. Frankly, if interviewees perceive the interview is a waste of their time, they may become disinterested and less than forthright. Doing their homework involves auditors identifying those employees who can provide them with the best information on a particular topic. Organizational charts are usually the first source.
Another good source of information is the organization's line-of-authority documentation and brief job descriptions. Through senior managers, auditors may obtain an idea as to the division of business units and corresponding employee responsibilities. Additionally, senior managers may wish to make introductions between their employees and the auditors. Senior managers can be very helpful in locating facilities for performing interviews where the atmosphere is not disruptive and scheduling mutually convenient times.
Interview content must be thoroughly prepared before beginning the interview. Nothing will leave a respondent colder than an auditor who has no idea about what they want to do during the interview. Auditors should make a list of goals they wish to achieve during the interview. Some auditors go so far as having a script of questions they want to ask divided by specific topic area.
Auditors may use open or closed questions in their interviews. Closed questions merely require a yes or no answer. Open questions usually begin with the words: how, why, when, who, or what. Open questions may be asked at the beginning of topic areas followed by closed questions where more clarification is needed. For example, "What are the types of controls you have over the entry of data from credit card applications?" This question might be followed by "Do you have manual or automated data input quality inspections?"
Auditors : Subsystem Interaction and Reliability
Auditors usually begin their analysis with the lowest level of subsystem activity attempting to identify all the different types of events that occur in these subsystems. Through this effort, the auditor begins to build a vision of what happens in the organization's business processes. Auditors must be mindful of two levels of prohibited events, prohibited events that are presently occurring and prohibited events that might occur in the future. In this vein, it is important for the auditor to focus her attention on the major process functions and how each subsystem supports the process's mission. One of the most important aspects of identifying permissible events in management subsystems is the determination of how a particular function should be performed within the subsystem. After the auditor performs research in the management subsystem, it should be clear how the management subsystems vary between circumstances in each relevant business unit.
A valid basis for identifying events in applications subsystems, attention must be placed on the transactions that occur as data is input to the subsystem. Events in an application subsystem cause changes in the application's state when the data is received in the form of input. More events take place as the application processes the transaction. Permitted events occur if the transaction and processing are authorized, complete, accurate, and not redundant. If anything otherwise occurs, a prohibited event occurred.
Risks Affecting Auditors
Information technology auditors must be concerned with four essential goals:
All auditors must consider that errors or irregularities will cause financial losses to the organization. Auditors collect evidence to achieve their goals, but there are inherent risks in these efforts. There is a risk that auditors may fail to detect actual or potential misstatements or process errors through the course of the audit. Experienced auditors approach and design their audit programs in such a fashion as they can fully articulate and document their efforts to minimize audit risks. If they fail to adequately address audit risk, audit results will not be valid and will not represent the true state of the system.
Assessing the levels of control risk associated within an audit segment, auditors consider the reliability of, and implementation of management and application controls. It is important to remember that management controls are fundamental controls in that they govern all application systems. In this hierarchical view, the absence of some or all management controls is a serious matter and reason for immediate action on the part of senior managers.
Once auditors have evaluated a management control and it is discovered that it spans the business unit's operation, it should function in relevant subsystem applications. For example, if an auditor reviews an adequate sample and discovers that an organization enforces high documentation standards of software development, it is likely these standards are enforced throughout the software development unit. Therefore, it is unlikely the auditor will review all documentation in all software development projects. Rather, she will select a representative amount ensuring that adequate documentation standards are observed thereby addressing any audit risk.
Experienced auditors estimate the level of detection risk they might achieve within a given set of audit procedures. They develop a good understanding of the probability these procedures have in detecting material loss or misstatements. It is very important that auditors choose audit procedures that provide the organization with an acceptable level of detection risk. In light of deadlines and limited resources, addressing audit risks must be focused on areas where they can deliver the highest payoffs.
Frequently, auditors cannot collect evidence to the extent they would prefer because they must spread their abilities among so many demands. They must be careful in the terms of where they apply their audit practice and how they interpret the evidence they collect. Throughout the audit, they must continuously make decisions based on their experience and training. It is their knowledge of audit methodology, material evidence collection and acceptable risks that guides them in making decisions as to what should be reported, to whom, and when.
Generally Accepted Government Auditing Standards (GAGAS)
According to GAGAS 4.21, auditors should obtain a sufficient understanding of internal control to plan the audit and determine the nature, timing, and extent of tests to be performed. According to GAGAS 4.21.1, auditors must consider the following when conducting an audit:
Audit Procedures
Auditors generally use five types of procedures in collecting evidence for their audits:
A valid basis for identifying events in applications subsystems, attention must be placed on the transactions that occur as data is input to the subsystem. Events in an application subsystem cause changes in the application's state when the data is received in the form of input. More events take place as the application processes the transaction. Permitted events occur if the transaction and processing are authorized, complete, accurate, and not redundant. If anything otherwise occurs, a prohibited event occurred.
Risks Affecting Auditors
Information technology auditors must be concerned with four essential goals:
Safeguarding critical assets Data integrity System effectiveness System efficiency
All auditors must consider that errors or irregularities will cause financial losses to the organization. Auditors collect evidence to achieve their goals, but there are inherent risks in these efforts. There is a risk that auditors may fail to detect actual or potential misstatements or process errors through the course of the audit. Experienced auditors approach and design their audit programs in such a fashion as they can fully articulate and document their efforts to minimize audit risks. If they fail to adequately address audit risk, audit results will not be valid and will not represent the true state of the system.
Assessing the levels of control risk associated within an audit segment, auditors consider the reliability of, and implementation of management and application controls. It is important to remember that management controls are fundamental controls in that they govern all application systems. In this hierarchical view, the absence of some or all management controls is a serious matter and reason for immediate action on the part of senior managers.
Once auditors have evaluated a management control and it is discovered that it spans the business unit's operation, it should function in relevant subsystem applications. For example, if an auditor reviews an adequate sample and discovers that an organization enforces high documentation standards of software development, it is likely these standards are enforced throughout the software development unit. Therefore, it is unlikely the auditor will review all documentation in all software development projects. Rather, she will select a representative amount ensuring that adequate documentation standards are observed thereby addressing any audit risk.
Experienced auditors estimate the level of detection risk they might achieve within a given set of audit procedures. They develop a good understanding of the probability these procedures have in detecting material loss or misstatements. It is very important that auditors choose audit procedures that provide the organization with an acceptable level of detection risk. In light of deadlines and limited resources, addressing audit risks must be focused on areas where they can deliver the highest payoffs.
Frequently, auditors cannot collect evidence to the extent they would prefer because they must spread their abilities among so many demands. They must be careful in the terms of where they apply their audit practice and how they interpret the evidence they collect. Throughout the audit, they must continuously make decisions based on their experience and training. It is their knowledge of audit methodology, material evidence collection and acceptable risks that guides them in making decisions as to what should be reported, to whom, and when.
Generally Accepted Government Auditing Standards (GAGAS)
According to GAGAS 4.21, auditors should obtain a sufficient understanding of internal control to plan the audit and determine the nature, timing, and extent of tests to be performed. According to GAGAS 4.21.1, auditors must consider the following when conducting an audit:
The extent to which computer processing is used in each significant accounting application The complexity of the entity's computer operations The organizational structure of the computer processing activities The kinds and competence of available evidential matter in electronic and paper formats to achieve audit objectives
Audit Procedures
Auditors generally use five types of procedures in collecting evidence for their audits:
Procedures in obtaining an understanding of system controls. Auditors will make inquiries, inspections, and observations to obtain an understanding of the controls that exist, the design of the controls, and whether the controls have been implemented. Inquiries, inspections, and observations can be used in obtaining an understanding of the controls affecting the company's asset safeguards. It is important to remember the three critical asset pillars: human resources, data, and physical facilities.
Tests of controls. Auditors will make inquiries, inspections, observations, and reperformance of control procedures to determine whether controls are operating effectively and efficiently. These tests deal with whether controls have been designed and whether they are effectively operating. For example, the auditors will determine if the operations manager reviews system response times and what substantive steps she has taken to address unacceptable system response times.
Transactions tests. These tests are designed by the auditors to detect errors or irregularities in system transactions that affect the organization. For example, an auditor would verify that accounts payable transactions are correctly posted in the business' financial journals and ledgers. Auditors must evaluate the limits of transaction effectiveness and efficiency. For example, auditors sample system response times for individual transactions attempting to determine if they are within acceptable limits.
Analytical review. Tests of an analytical nature look at relationships between data items in identifying areas. For example, an auditor examines two years of inventory levels to determine if there are substantive levels of fluctuation requiring further investigation. Auditors may employ similar procedures in evaluating the effectiveness and efficiency of an organization's operation: These are comparisons between two related procedures concerning effectiveness and efficiency. For example, auditors will design a model where the amount of document processing by the system is evaluated and compared with the previous two years.
Tests of system results. These are tests of management's assertions regarding effectiveness and efficiency. For example, senior IT management may assert that system response time over the past two years is three seconds. Auditors will design a sampling technique where a survey of system users is made to determine the validity of this assertion for the applicable period.
Auditors : Code of Ethics and Conduct
Auditors must subscribe to a formalized, universal code of ethics. For example, a code of ethics for holders of the Certified Information Systems Auditor (CISA) certification has been established by the Information Systems Audit and Control Association (ISACA).
Free and Independent
External auditing is often called independent auditing as qualified individuals outside the organization being audited do the audit. External auditors represent the interests of third-party stakeholders such as creditors, government agencies, and stockholders.
Internal auditors operate as independent appraisers established within an organization examining and evaluating activities as a service to the organization itself. Internal auditors perform a wide variety of tasks including assessing compliance with legal obligations, assessing operational efficiency, detecting and pursuing fraud and system vulnerabilities. External auditors are distinguished from internal auditors in that they represent outside constituents, while internal auditors represent the interests of the organization. Their efforts are not necessarily exclusive, internal auditors often cooperate and assist external auditors in performing audits achieving efficiency and reducing audit fees. External auditors depend on the independence and competence of internal auditors in relying on their work. Independent internal auditors add value to business processes. Internal auditors often collect evidence throughout the fiscal period that can be used at year end to conduct more-efficient, less-costly external audits.
In auditing and all related matters, auditors must be free from personal and external impairments to their independence. Auditors must be organizationally independent and should maintain an independent attitude and appearance.
Auditors must consider not only if they are independent with their attitudes and beliefs, but also whether there is anything about their situation that might lead others to question their independence. All situations must be considered, as it is essential that auditors consider themselves to be impartial and that knowledgeable third parties consider them to be independent.
For auditors, there are essentially three very general types of impairments to independence: organizational, personal, and external. If any of these impairments affect their ability to do their work and report their findings impartially, the auditors must decline the engagement.
Organizational Impairments
Internal auditors may be affected by their job-placement within the structure of the business entity where they are employed. Auditors must be sufficiently removed from managerial, political, and organizational pressures ensuring that they can conduct their audits independently and report their findings, opinions, recommendations, and conclusions objectively. In the case of external auditors, they may be presumed to be independent of the audited entity if there are no personal, external, or organizational impairments.
External Impairments
There may be factors external to the auditor interfering with an auditor's ability to form objective and independent opinions, recommendations, and conclusions. There may be interference or undo influence that improperly limits or modifies the scope or methodology of an audit.
Personal Impairments
Regrettably, there are circumstances in which auditors may not be impartial or perceived by knowledgeable third parties as being impartial. It is important for an auditing unit to have policies and procedures in place to determine if auditors have any personal impairment affecting their ability to conduct audits. Although the responsibility rests on the shoulders of the individual auditors, audit managers and executives need to be alert for impairments affecting the judgment and performance of their audit staff. Auditors must be responsible for notifying the appropriate official about any personal impairment. Personal impairments include, but are not limited to the following:
Codes of ethics are usually required by professional organizations and typically address the following areas of auditor conduct: Establishment and compliance with information systems controls, standards, and procedures Trustworthy service and reporting to stakeholders throughout the audit process Avoidance of participating in improper acts personally and professionally Confidentiality of observed and collected audit evidence Auditor independence Professional competence through participation in continuing professional development Due diligence when conducting audits and documentation of sufficient evidence supporting conclusions and recommendations Communication of audit results to appropriate stakeholders Education of stakeholders in the audit process to enhance understanding of systems and the audit process
Free and Independent
External auditing is often called independent auditing as qualified individuals outside the organization being audited do the audit. External auditors represent the interests of third-party stakeholders such as creditors, government agencies, and stockholders.
Internal auditors operate as independent appraisers established within an organization examining and evaluating activities as a service to the organization itself. Internal auditors perform a wide variety of tasks including assessing compliance with legal obligations, assessing operational efficiency, detecting and pursuing fraud and system vulnerabilities. External auditors are distinguished from internal auditors in that they represent outside constituents, while internal auditors represent the interests of the organization. Their efforts are not necessarily exclusive, internal auditors often cooperate and assist external auditors in performing audits achieving efficiency and reducing audit fees. External auditors depend on the independence and competence of internal auditors in relying on their work. Independent internal auditors add value to business processes. Internal auditors often collect evidence throughout the fiscal period that can be used at year end to conduct more-efficient, less-costly external audits.
In auditing and all related matters, auditors must be free from personal and external impairments to their independence. Auditors must be organizationally independent and should maintain an independent attitude and appearance.
Auditors must consider not only if they are independent with their attitudes and beliefs, but also whether there is anything about their situation that might lead others to question their independence. All situations must be considered, as it is essential that auditors consider themselves to be impartial and that knowledgeable third parties consider them to be independent.
For auditors, there are essentially three very general types of impairments to independence: organizational, personal, and external. If any of these impairments affect their ability to do their work and report their findings impartially, the auditors must decline the engagement.
Organizational Impairments
Internal auditors may be affected by their job-placement within the structure of the business entity where they are employed. Auditors must be sufficiently removed from managerial, political, and organizational pressures ensuring that they can conduct their audits independently and report their findings, opinions, recommendations, and conclusions objectively. In the case of external auditors, they may be presumed to be independent of the audited entity if there are no personal, external, or organizational impairments.
External Impairments
There may be factors external to the auditor interfering with an auditor's ability to form objective and independent opinions, recommendations, and conclusions. There may be interference or undo influence that improperly limits or modifies the scope or methodology of an audit.
Personal Impairments
Regrettably, there are circumstances in which auditors may not be impartial or perceived by knowledgeable third parties as being impartial. It is important for an auditing unit to have policies and procedures in place to determine if auditors have any personal impairment affecting their ability to conduct audits. Although the responsibility rests on the shoulders of the individual auditors, audit managers and executives need to be alert for impairments affecting the judgment and performance of their audit staff. Auditors must be responsible for notifying the appropriate official about any personal impairment. Personal impairments include, but are not limited to the following:
Official, professional, financial, or personal relationships that might cause the auditor to limit the methodology, extent of the audit inquiry, limit disclosure, or minimize or slant the audit findings in any way. Preconceived ideas toward the audit or the organization on which the audit is going to be performed; any feelings that the auditor has that could taint audit results require that the auditor is removed from the audit engagement Previous responsibility for decision making or management authority that would affect current operations of the entity to be audited is considered biasing Personal biases (including business, political, religious, or social convictions) resulting from employment or loyalty to a particular group or organization Direct or indirect financial interest in the audited entity
Subscribe to:
Posts (Atom)
Popular Posts
-
The composition of the crisis and incident response teams should reflect the personnel required to analyze and deal with any events, fro...
-
Incident and problem management processes are intended to handle problems that are raised through the service desk as well as responses t...
-
Each company will define the composition and structure of its own crisis response group dependent on the nature, size, and scope of the ...
-
Often crisis responders will initiate a crisis notification through a verbal briefing. As such, it is imperative that a clear and accurate ...
-
The first step in implementing a strategy for deploying physical scanners is to select a central location to which all scanners will re...
-
There are many ways to deploy a system, and what is needed for the operating environment will possibly affect the solution chosen. In so...
-
Nessus is a popular open-source scanner for organizations that choose not to spend the money on other proprietary products. There are s...
-
Incident Management Guidelines Office block, facility, or hotel fires can present unique risks depending on the operating region in which th...
-
Once vulnerability information has been collected, it must be categorized and evaluated. The methods of evaluation and categorization va...
-
The first step in dealing with critical incidents rests with becoming aware that an adverse event has happened. The detection of critic...