5.4 CAATs, Data Analytics & Continuous Auditing
Key Takeaways
Audit data analytics can test a full defined population, but completeness, relevance, data quality and non-sampling risk remain.
Exception rules identify items for evaluation; a flagged transaction is not automatically an error or fraud.
Benford analysis is appropriate only for suitable naturally occurring populations and is a risk indicator, not standalone proof.
Continuous monitoring belongs to management, while continuous auditing is independent assurance work with controlled access and follow-up.
Hashes help detect whether captured bytes changed; they do not establish the source, completeness or correctness of a dataset.
5.4 CAATs, Data Analytics & Continuous Auditing
Computer-assisted audit techniques and audit data analytics help auditors extract, join, recalculate and examine electronic records. Their value comes from a clear audit objective and reliable data—not from the number of rows processed or the sophistication of a chart.
Define and validate the population
Before analysis, document the source systems, period, entities, fields, extraction logic, filters and expected population. Validate completeness and accuracy through suitable procedures such as record counts, control totals, ledger reconciliations, source-to-extract tests and review of rejected records. A perfect reconciliation to one ledger total may still omit records outside that ledger or preserve incorrect attributes, so use evidence responsive to the objective.
Full-population processing removes sampling risk only for the processed population and procedure. It does not remove the risk of an incomplete extract, erroneous code, misinterpreted exceptions, inaccessible off-system records or a test that does not address the assertion.
Common analytical techniques
Recalculation and rule testing apply explicit criteria—for example, duplicate identifiers, payments outside delegated authority, dates outside an eligibility period or amounts above a programme-specific approval limit. Rules should be versioned and linked to the actual legal or policy criterion.
Sequence and gap analysis identifies missing, duplicate or out-of-order identifiers. A gap can result from a cancelled record or system design, so it requires follow-up rather than a fraud label.
Exact and fuzzy matching can compare supplier names, bank accounts, invoice references, addresses and amounts. Exact matching finds identical combinations. Fuzzy matching scores near matches such as transposed digits or spelling variants. Thresholds should be tested because aggressive matching can create many false positives.
Outlier and cluster analysis identifies unusual values, timing or relationships. Auditors may use stratification, regression or visualisation, but an unusual item becomes an audit finding only after criteria, cause and evidence are evaluated.
Benford’s Law
Benford’s Law predicts a logarithmic distribution of leading digits in many naturally occurring datasets that span orders of magnitude. It is usually unsuitable for assigned numbers, fixed-price lists, narrow ranges, minimum or maximum constrained amounts, or small and heterogeneous populations.
A statistically unusual digit pattern can guide investigation; it does not prove manipulation. The auditor should test sensitivity, understand how the data are generated and inspect underlying transactions. A spike just below an internal review threshold may reflect splitting, a standard price or a lawful procurement category.
Continuous monitoring and continuous auditing
Continuous monitoring is management activity: operational or compliance teams use alerts and dashboards to manage processes and controls. Continuous auditing is independent assurance work performed at a recurring or high frequency. Independence requires that auditors do not operate the control they later assess.
Frequency alone does not create assurance. Define ownership, access, alert criteria, investigation responsibilities, evidence retention, escalation and periodic review of the analytics. Read-only access can reduce alteration risk but does not itself prove the replica is complete or current.
Digital evidence and hashing
Record extraction time, source, query or script version, parameters, operator and transfer method. Protect data with access controls and encryption appropriate to its sensitivity, and comply with applicable data-protection and retention requirements.
A cryptographic hash such as SHA-256 is a fingerprint of the captured bytes. If the file changes, the later hash should differ. Matching hashes strongly support that the compared bytes are unchanged. They do not prove who created the file, whether the original source was authentic, whether the extract was complete, or whether its data were correct. Those propositions require other evidence and a documented chain of custody.
Constructed example
Assume an organisation’s internal procurement policy requires additional review above EUR 60,000. Analytics identify a cluster of contracts just below that amount and several suppliers sharing bank accounts. The auditor validates the extract, confirms the policy and period, reviews related awards and beneficial-ownership information, and asks whether legitimate framework pricing explains the pattern. Only supported exceptions become findings. Suspected fraud is escalated through the authorised channel; the auditor does not personally declare a cartel or automatically notify every investigative body.
Reproducibility and conclusion
Retain the code, parameters, data dictionary, exception population and resolution status so another experienced auditor can reproduce the result. Reconcile changes between runs and document why exceptions were cleared. The conclusion should state what population and assertion the routine addressed, its limitations and what additional evidence supports the result.
Which population is generally suitable for Benford first-digit analysis?
Employee identification numbers
A fixed-price catalogue
Amounts constrained to a narrow statutory band
Naturally occurring transaction values spanning several orders of magnitude
What distinguishes continuous monitoring from continuous auditing?
Monitoring is a management control activity, while continuous auditing is independent assurance work
Monitoring is annual and auditing is always real time
Monitoring uses data but auditing may not
They are identical terms
How does fuzzy matching differ from exact matching in duplicate-payment analysis?
It proves fraud without follow-up
It identifies near matches such as spelling variants or transposed digits using a similarity rule
It can use only bank-account fields
It removes the need to validate the source population
Why record and later compare a cryptographic hash of an extracted file?
It proves the extract contains every source record
It authenticates the legal owner of each transaction
It provides strong evidence that the compared bytes have not changed
It establishes that all recorded transactions are valid
Sections you finish are checked off in the contents.