10.2 Testing Methodologies for Accounting, Finance, IT, Operations, and Cybersecurity

Key Takeaways

  • CIA Part 2 A6e tests matching methodology to domain: reconciliations, cutoff, and vouching or tracing for accounting; analytics for finance; configuration, ITGCs, and access tests for IT; observation and reperformance for operations; log review, identity evidence, and vulnerability-management evidence for cybersecurity.
  • Choose the method that can answer the objective; a vulnerability scan does not prove cutoff, and a mid-year observation does not prove period-end quantity.
  • Integrated engagements combine methods in one work program rather than forcing a single method across unlike risks.
  • After you pick a method family, the work program still must state nature, timing, extent, tools, and planned evidence.
  • Part 2 expects identification of an appropriate method, not a specialist textbook on accounting, ERP administration, or exploit development.
Last updated: August 2026

CIA Part 2 objective A6e asks you to identify testing methodologies for an engagement that includes accounting, finance, IT systems, business operations, or cybersecurity. The skill is matching. You are not sitting a second information-systems, finance, or pentest exam. Choose a method family that can produce relevant, sufficient, reliable evidence for that domain's objective, then record nature, timing, and extent on the work program from Chapter 10.1.

Quick Answer: Match the method to the domain: reconciliations, cutoff tests, and vouching or tracing for accounting; analytics, ratios, and variance analysis for finance; configuration review, IT general controls (ITGCs), and access testing for IT; observation and reperformance for operations; log review, identity evidence, and vulnerability-management evidence for cybersecurity. Integrated engagements combine those families in one work program. Do not use a pentest to answer a cutoff question, and do not use a ratio to prove a firewall rule.

Match Method to Domain, Then Set Extent

A methodology is the type of work you will do. Extent is how much, where, and for which period. CIA stems fail candidates who pick a fashionable method that cannot answer the objective. Vulnerability scans do not prove revenue cutoff. A warehouse observation in July does not prove 31 December quantity. A ratio spike is a pointer, not by itself a completeness conclusion.

DomainTypical objectivesMethodologies that usually fitWhat they are not
AccountingExistence, completeness, cutoff, accuracy, classification of recorded transactions and balancesReconciliations (GL to subledger, bank, inventory); cutoff tests around period-end; vouching recorded items to source documents; tracing source documents into the records; recalculationA strategy workshop or a culture survey
FinanceReasonableness of results, budget discipline, performance reporting, working-capital movementsAnalytics: ratios, trends, variance to budget or forecast, reasonableness tests, peer or internal benchmarksRecalculating every invoice when analytics already isolate the residual risk
IT systemsITGCs, application configuration, access, change management, interfacesConfiguration reviews against approved baselines; ITGC tests of access, change, and computer operations; user-access and privileged-access tests; interface reconciliationsRewriting code or acting as system administrator
Business operationsProcess actually runs as designed; physical safeguards; cycle time at the controlObservation of the control in operation; reperformance of the control; physical inspection; limited timing studies when efficiency is in scopeA full industrial-engineering restudy of the plant
CybersecurityIdentity, logging and monitoring, vulnerability and patch handling, selected configuration hardeningLog review and monitoring evidence; identity lifecycle and privileged-access evidence; vulnerability-scan and patch-exception evidence; sampling of incident ticketsWriting exploits or certifying the entire information-security management system

Keep Chapter 9 in its lane. That chapter taught which procedure family (design, operating effectiveness, efficiency) you need. This chapter teaches which domain method you reach for once that family is chosen. Example: operating effectiveness of a three-way match plus accounting vouching of matched invoices can sit in the same task. Operating effectiveness of a privileged-access review plus cyber identity evidence can sit in another.

Accounting: Reconcile, Cut Off, Vouch

Accounting methodologies stay close to the records. Reconciliations test whether two independently maintained records tell the same story—subledger to general ledger, bank to cash book, inventory subledger to the GL control account. The auditor either reperforms the reconciliation or tests management's reconciliation for completeness of reconciling items and timely clearance.

Cutoff tests whether transactions near a period boundary landed in the correct period. Typical evidence is shipping logs, receiving reports, invoice dates, and system posting dates for a window before and after period-end. Cutoff is a timing methodology; it is not a random sample from mid-year.

Vouching starts with the recorded amount and inspects source documents (recorded to source), which primarily supports existence or occurrence. Tracing starts with the source and follows it into the records (source to recorded), which primarily supports completeness. CIA items still punish mixing those directions. Recalculation and independent confirmation appear when the objective needs mathematical accuracy or third-party corroboration. You do not need a full financial-statement audit program; you need the method that matches the accounting objective on the engagement.

Finance: Let Analytics Do the Heavy Sorting

Finance testing on Part 2 is usually analytical: ratios, trends, budget-versus-actual, flash-versus-forecast, and reasonableness models (for example, interest expense versus average debt). Analytics are strongest when they isolate where detailed testing should go, and when the objective is about the reasonableness of reported performance rather than the existence of a single invoice.

Set the expectation in the work program: which metric, which comparator, what threshold sends you to detail, and what evidence you will pull when the analytic breaks. An analytic with no threshold is a sightseeing tour. Detailed vouching of every journal when a clean variance analysis already explained the movement wastes resources (Chapter 10.3) and is the wrong methodology for a finance reasonableness objective.

IT: Configuration, ITGCs, and Access

IT methodologies ask whether the system environment can be relied on. ITGCs typically cover access, change management, and computer operations. Configuration reviews compare actual settings—approval workflows, segregation flags, password parameters, interface job schedules—to an approved baseline. Access tests examine joiner-mover-leaver evidence, recertifications, and privileged IDs.

You are evaluating controls and evidence, not administering the system. Do not volunteer to reset a production role. For CIA, it is enough to know that an ERP accounts-payable engagement with an automated three-way match usually must include ITGC, access, or configuration work on that match; ignoring the system that enforces the control is an inadequate methodology mix, not a time-saver.

Operations: Watch It and Do It Again

Operations respond to observation (watch the control operate) and reperformance (the auditor performs the control independently and compares results). Physical inspection of assets, seals, or restricted areas belongs here when existence or safeguarding is in scope. Observation is time-specific: seeing the count on the count day is not the same as reading last quarter's count memo. Reperformance is powerful for checklists, reconciliations, and calculations that a competent auditor can execute without becoming the process owner.

If efficiency is an objective, operations methods may include limited timing or exception-rate work. That is still not a consulting mandate to redesign the line. Chapter 9's efficiency procedures tell you what efficient means; this chapter tells you that you will usually observe or reperform the operational control rather than only read a procedure manual.

Cybersecurity: Logs, Identity, Vulnerability Evidence

Cyber on Part 2 is evidence about management's control, not a capture-the-flag contest. Log review inspects whether relevant events are collected, retained, reviewed, and escalated. Identity evidence covers provisioning, multi-factor or equivalent authentication, privileged-access vaulting, and recertification. Vulnerability evidence includes scan results, exception handling, and patch service levels—evaluated as a process, not re-run as an amateur pentest.

Topical Requirements may raise the floor when cybersecurity is in scope (Chapters 4 and 7). They do not turn every CIA candidate into a red-team lead. If the objective is that privileged access to the payment file is restricted, identity and log evidence fit. If the objective claims every web application is free of injection flaws, you likely need a specialist (Chapter 10.3), and the work program should say so rather than pretending a staff walk-through of the login page is enough.

Integrated Engagements Combine Methods on Purpose

Real CIA stems rarely stay in one domain. Payroll accuracy plus the HR/payroll application plus privileged access is one engagement, one work program, several methodologies:

  • Accounting: reconcile payroll subledger to GL; recalculate a sample of gross-to-net; cutoff for period-end accruals.
  • Finance: analytics on overtime, headcount versus salary cost, budget variance.
  • IT: ITGCs and configuration of pay-cycle jobs and role design.
  • Operations: observe time-entry approval on a shift; reperform a sample of supervisor approvals.
  • Cyber: privileged-access listings, joiner-leaver logs, and selected authentication evidence for accounts that can change bank details.

The failure mode is method monopoly: using only interviews, only analytics, or only a vendor pentest report for every objective. Integrated work is still one approved program (Chapter 10.1) with tasks tagged to the right method. Nature, timing, and extent remain mandatory inside each task. Choosing cyber log review without a period, system, and population is not a methodology; it is a slogan.

The illustrative hour mix in the chart below is a teaching example for one integrated procure-to-pay job, not an IIA official weighting. Use it to remember that accounting, IT, and cyber often share the stage when the process runs in an ERP.

Loading diagram...
Match testing methodology to domain, then combine on one work program
Illustrative hours by method family on one integrated procure-to-pay engagement (not official IIA weights)
Test Your Knowledge

An engagement objective is whether sales are recorded in the correct period. Which testing methodology is the best match?

A
B
C
D
Test Your Knowledge

An integrated engagement covers payroll amount accuracy, ITGCs over the payroll application, and privileged access that can change bank details. Which methodology mix is most appropriate?

A
B
C
D
Test Your Knowledge

On CIA Part 2, identifying cybersecurity testing methodologies primarily means which of the following?

A
B
C
D