5.4 CAATs, Data Analytics & Continuous Auditing

Key Takeaways

  • Audit data analytics can test a full defined population, but completeness, relevance, data quality and non-sampling risk remain.

  • Exception rules identify items for evaluation; a flagged transaction is not automatically an error or fraud.

  • Benford analysis is appropriate only for suitable naturally occurring populations and is a risk indicator, not standalone proof.

  • Continuous monitoring belongs to management, while continuous auditing is independent assurance work with controlled access and follow-up.

  • Hashes help detect whether captured bytes changed; they do not establish the source, completeness or correctness of a dataset.

Last updated: October 2026

5.4 CAATs, Data Analytics & Continuous Auditing

Computer-assisted audit techniques and audit data analytics help auditors extract, join, recalculate and examine electronic records. Their value comes from a clear audit objective and reliable data—not from the number of rows processed or the sophistication of a chart.

Define and validate the population

Before analysis, document the source systems, period, entities, fields, extraction logic, filters and expected population. Validate completeness and accuracy through suitable procedures such as record counts, control totals, ledger reconciliations, source-to-extract tests and review of rejected records. A perfect reconciliation to one ledger total may still omit records outside that ledger or preserve incorrect attributes, so use evidence responsive to the objective.

Full-population processing removes sampling risk only for the processed population and procedure. It does not remove the risk of an incomplete extract, erroneous code, misinterpreted exceptions, inaccessible off-system records or a test that does not address the assertion.

Common analytical techniques

Recalculation and rule testing apply explicit criteria—for example, duplicate identifiers, payments outside delegated authority, dates outside an eligibility period or amounts above a programme-specific approval limit. Rules should be versioned and linked to the actual legal or policy criterion.

Sequence and gap analysis identifies missing, duplicate or out-of-order identifiers. A gap can result from a cancelled record or system design, so it requires follow-up rather than a fraud label.

Exact and fuzzy matching can compare supplier names, bank accounts, invoice references, addresses and amounts. Exact matching finds identical combinations. Fuzzy matching scores near matches such as transposed digits or spelling variants. Thresholds should be tested because aggressive matching can create many false positives.

Outlier and cluster analysis identifies unusual values, timing or relationships. Auditors may use stratification, regression or visualisation, but an unusual item becomes an audit finding only after criteria, cause and evidence are evaluated.

Benford’s Law

Benford’s Law predicts a logarithmic distribution of leading digits in many naturally occurring datasets that span orders of magnitude. It is usually unsuitable for assigned numbers, fixed-price lists, narrow ranges, minimum or maximum constrained amounts, or small and heterogeneous populations.

A statistically unusual digit pattern can guide investigation; it does not prove manipulation. The auditor should test sensitivity, understand how the data are generated and inspect underlying transactions. A spike just below an internal review threshold may reflect splitting, a standard price or a lawful procurement category.

Continuous monitoring and continuous auditing

Continuous monitoring is management activity: operational or compliance teams use alerts and dashboards to manage processes and controls. Continuous auditing is independent assurance work performed at a recurring or high frequency. Independence requires that auditors do not operate the control they later assess.

Frequency alone does not create assurance. Define ownership, access, alert criteria, investigation responsibilities, evidence retention, escalation and periodic review of the analytics. Read-only access can reduce alteration risk but does not itself prove the replica is complete or current.

Digital evidence and hashing

Record extraction time, source, query or script version, parameters, operator and transfer method. Protect data with access controls and encryption appropriate to its sensitivity, and comply with applicable data-protection and retention requirements.

A cryptographic hash such as SHA-256 is a fingerprint of the captured bytes. If the file changes, the later hash should differ. Matching hashes strongly support that the compared bytes are unchanged. They do not prove who created the file, whether the original source was authentic, whether the extract was complete, or whether its data were correct. Those propositions require other evidence and a documented chain of custody.

Constructed example

Assume an organisation’s internal procurement policy requires additional review above EUR 60,000. Analytics identify a cluster of contracts just below that amount and several suppliers sharing bank accounts. The auditor validates the extract, confirms the policy and period, reviews related awards and beneficial-ownership information, and asks whether legitimate framework pricing explains the pattern. Only supported exceptions become findings. Suspected fraud is escalated through the authorised channel; the auditor does not personally declare a cartel or automatically notify every investigative body.

Reproducibility and conclusion

Retain the code, parameters, data dictionary, exception population and resolution status so another experienced auditor can reproduce the result. Reconcile changes between runs and document why exceptions were cleared. The conclusion should state what population and assertion the routine addressed, its limitations and what additional evidence supports the result.

Loading diagram...
Reliable Analytics Workflow
Test Your Knowledge

Which population is generally suitable for Benford first-digit analysis?

A

Employee identification numbers

B

A fixed-price catalogue

C

Amounts constrained to a narrow statutory band

D

Naturally occurring transaction values spanning several orders of magnitude

Test Your Knowledge

What distinguishes continuous monitoring from continuous auditing?

A

Monitoring is a management control activity, while continuous auditing is independent assurance work

B

Monitoring is annual and auditing is always real time

C

Monitoring uses data but auditing may not

D

They are identical terms

Test Your Knowledge

How does fuzzy matching differ from exact matching in duplicate-payment analysis?

A

It proves fraud without follow-up

B

It identifies near matches such as spelling variants or transposed digits using a similarity rule

C

It can use only bank-account fields

D

It removes the need to validate the source population

Test Your Knowledge

Why record and later compare a cryptographic hash of an extracted file?

A

It proves the extract contains every source record

B

It authenticates the legal owner of each transaction

C

It provides strong evidence that the compared bytes have not changed

D

It establishes that all recorded transactions are valid

Sections you finish are checked off in the contents.