23.1 Auditing in a Computer Information Systems (CIS) Environment

Key Takeaways

  • IT processing is uniform, so program errors cause systematic misstatements, and it may remove the visible audit trail and concentrate duties.

  • Test data and integrated test facility use fictitious transactions, while parallel simulation reprocesses actual client data with the auditor's own program.

  • Generalized audit software lets the auditor analyze whole populations, but the completeness and accuracy of the extracted data must be tested first.

  • Small-entity IT environments usually lack segregation of duties, so auditors rely more on substantive procedures and compensating controls.

  • Cloud providers are service organizations under PSA 402, and cybersecurity incidents can affect data integrity, disclosures, and going concern.

Last updated: September 2026

Auditing in a Computer Information Systems (CIS) Environment

Nearly every audit client in the Philippines records transactions in an accounting system, an ERP package, or a cloud platform. PSA 315 (Revised 2019) requires the auditor to understand the entity's IT environment and the risks arising from the use of IT. This section covers how IT changes the audit, the types of computer systems, audit approaches and computer-assisted audit techniques (CAATs), data analytics, and emerging technologies. General IT controls and application controls are covered under internal control.


1. How an IT Environment Changes the Audit

Characteristic of IT processingAudit implication
Uniform processing of like transactionsClerical errors largely disappear, but a program error misstates every transaction of that type (systematic errors)
Loss of visible audit trail (data may exist only electronically or for a short time)The auditor may need to test when data exist and use CAATs rather than paper vouching
Concentration of functions and reduced segregation of dutiesAccess controls and compensating controls become critical
Automatic initiation and execution of transactions (for example, automatic reorders or interest computations)Authorization is embedded in programs, so program change controls matter
Unauthorized access to data or programsRisk of undetected alteration; logical access controls are key
Dependence of other controls on ITManual reviews of system reports rely on the accuracy of those reports (information produced by the entity must be tested)

Under PSA 315 (Revised 2019), the auditor identifies the IT applications and other aspects of the IT environment that are subject to risks arising from the use of IT and then identifies the related general IT controls.


2. Types of Computer Systems

  • Batch processing: transactions are accumulated and processed in groups (for example, a weekly payroll). Batch totals and control totals are important controls.
  • Online real-time processing: transactions update master files immediately (for example, point-of-sale and online banking). Controls focus on access, input validation, and logging, because errors post instantly.
  • Database systems: many applications share one database managed by a database management system. The database administrator controls the data structure and access, so the role must be separated from programmers and users.
  • Networks and cloud computing: processing or storage may be outsourced to a cloud provider. The auditor considers the provider as a service organization (PSA 402) and may use its SOC reports.
  • Electronic commerce and EDI: transactions are exchanged electronically with customers and suppliers, which raises risks around authentication, completeness, non-repudiation, and data privacy.
  • Small-entity and stand-alone PC environments: one person may handle programming, operation, and data entry, and off-the-shelf software may lack controls. The auditor often relies more on substantive procedures and compensating controls such as owner review.

3. Audit Approaches

ApproachDescriptionWhen appropriate
Auditing around the computerCompare inputs with outputs and ignore the processing inside the systemSimple systems with good audit trails; increasingly rare
Auditing through the computerTest the programs and controls themselves (for example, with test data)When reliance is placed on programmed controls or audit trails are limited
Auditing with the computerUse the computer as an audit tool to analyze client dataLarge volumes of data; full-population testing

4. Computer-Assisted Audit Techniques (CAATs)

TechniqueHow it worksKey point
Test dataAuditor processes fictitious valid and invalid transactions through the client's program and compares results with expectationsTests controls in the program at one point in time; the auditor must confirm the program tested is the one actually in use
Integrated test facility (ITF)Fictitious entity or records are created in the live system and processed with actual transactionsTests continuously in the live environment, but test transactions must be reversed so they do not contaminate client records
Parallel simulationAuditor reprocesses the client's actual data using the auditor's own program and compares the output with the client's resultsUses real data, so it detects differences in processing logic
Generalized audit software (GAS)Programs that read client files to sort, total, recompute, stratify, select samples, and find exceptions (such as duplicates or gaps)The most common substantive CAAT; supports data analytics
Embedded audit modules and SCARFAudit routines built into the client's programs capture transactions that meet auditor-set criteriaContinuous auditing; requires cooperation during system development
Tagging and tracing, snapshot, mappingMark transactions to follow them through processing, capture images of records at points in processing, or identify program code that was never executedHelp evaluate processing logic and unused or unauthorized code

5. Data Analytics in the Audit

Audit data analytics examine entire populations rather than samples, using tools such as generalized audit software and visualization dashboards. Common uses include journal entry testing for management override (PSA 240), matching three-way documents in purchasing, identifying duplicate payments or ghost vendors, and applying Benford's law to spot unusual digit patterns. The auditor must first test the completeness and accuracy of the data extracted from the client's system, because analytics on incomplete data give false comfort.


6. Emerging Technologies and Cybersecurity

  • Cloud and outsourced IT: reliance on third-party providers makes SOC reports, contracts, and data-location issues part of risk assessment.
  • Robotic process automation (RPA): software bots perform repetitive tasks, so bot access credentials and change controls become general IT controls.
  • Blockchain and digital assets: records may be immutable, but the auditor still needs evidence on the existence, rights, and valuation of digital assets and on the controls over private keys.
  • Artificial intelligence: models used in estimates or processing require governance over data, model changes, and outputs.
  • Cybersecurity incidents: breaches can affect the integrity of financial data, trigger provisions or disclosures, and create going concern or data privacy (RA 10173) issues.
Test Your Knowledge

An auditor obtains a copy of the client's actual payroll master file and transaction data and processes them using the auditor's own program. The results are compared with the client's payroll register. Which CAAT is being used?

A

Test data

B

Embedded audit module

C

Integrated test facility

D

Parallel simulation

Test Your Knowledge

What is the main risk that an auditor must manage when using an integrated test facility?

A

The client's program may be replaced before the test

B

The auditor cannot use actual client transactions

C

Fictitious test transactions may contaminate the client's live records if they are not reversed

D

The technique cannot be used in online real-time systems

Test Your Knowledge

A small company's bookkeeper enters transactions, runs the accounting software, prepares reports, and has full access to change master files. Which audit response is most appropriate?

A

Rely fully on the software's programmed controls

B

Issue a disclaimer of opinion because segregation of duties is absent

C

Emphasize substantive procedures and evaluate compensating controls such as owner review

D

Test only general IT controls and skip substantive testing

Sections you finish are checked off in the contents.