23.1 Auditing in a Computer Information Systems (CIS) Environment
Key Takeaways
IT processing is uniform, so program errors cause systematic misstatements, and it may remove the visible audit trail and concentrate duties.
Test data and integrated test facility use fictitious transactions, while parallel simulation reprocesses actual client data with the auditor's own program.
Generalized audit software lets the auditor analyze whole populations, but the completeness and accuracy of the extracted data must be tested first.
Small-entity IT environments usually lack segregation of duties, so auditors rely more on substantive procedures and compensating controls.
Cloud providers are service organizations under PSA 402, and cybersecurity incidents can affect data integrity, disclosures, and going concern.
Auditing in a Computer Information Systems (CIS) Environment
Nearly every audit client in the Philippines records transactions in an accounting system, an ERP package, or a cloud platform. PSA 315 (Revised 2019) requires the auditor to understand the entity's IT environment and the risks arising from the use of IT. This section covers how IT changes the audit, the types of computer systems, audit approaches and computer-assisted audit techniques (CAATs), data analytics, and emerging technologies. General IT controls and application controls are covered under internal control.
1. How an IT Environment Changes the Audit
| Characteristic of IT processing | Audit implication |
|---|---|
| Uniform processing of like transactions | Clerical errors largely disappear, but a program error misstates every transaction of that type (systematic errors) |
| Loss of visible audit trail (data may exist only electronically or for a short time) | The auditor may need to test when data exist and use CAATs rather than paper vouching |
| Concentration of functions and reduced segregation of duties | Access controls and compensating controls become critical |
| Automatic initiation and execution of transactions (for example, automatic reorders or interest computations) | Authorization is embedded in programs, so program change controls matter |
| Unauthorized access to data or programs | Risk of undetected alteration; logical access controls are key |
| Dependence of other controls on IT | Manual reviews of system reports rely on the accuracy of those reports (information produced by the entity must be tested) |
Under PSA 315 (Revised 2019), the auditor identifies the IT applications and other aspects of the IT environment that are subject to risks arising from the use of IT and then identifies the related general IT controls.
2. Types of Computer Systems
- Batch processing: transactions are accumulated and processed in groups (for example, a weekly payroll). Batch totals and control totals are important controls.
- Online real-time processing: transactions update master files immediately (for example, point-of-sale and online banking). Controls focus on access, input validation, and logging, because errors post instantly.
- Database systems: many applications share one database managed by a database management system. The database administrator controls the data structure and access, so the role must be separated from programmers and users.
- Networks and cloud computing: processing or storage may be outsourced to a cloud provider. The auditor considers the provider as a service organization (PSA 402) and may use its SOC reports.
- Electronic commerce and EDI: transactions are exchanged electronically with customers and suppliers, which raises risks around authentication, completeness, non-repudiation, and data privacy.
- Small-entity and stand-alone PC environments: one person may handle programming, operation, and data entry, and off-the-shelf software may lack controls. The auditor often relies more on substantive procedures and compensating controls such as owner review.
3. Audit Approaches
| Approach | Description | When appropriate |
|---|---|---|
| Auditing around the computer | Compare inputs with outputs and ignore the processing inside the system | Simple systems with good audit trails; increasingly rare |
| Auditing through the computer | Test the programs and controls themselves (for example, with test data) | When reliance is placed on programmed controls or audit trails are limited |
| Auditing with the computer | Use the computer as an audit tool to analyze client data | Large volumes of data; full-population testing |
4. Computer-Assisted Audit Techniques (CAATs)
| Technique | How it works | Key point |
|---|---|---|
| Test data | Auditor processes fictitious valid and invalid transactions through the client's program and compares results with expectations | Tests controls in the program at one point in time; the auditor must confirm the program tested is the one actually in use |
| Integrated test facility (ITF) | Fictitious entity or records are created in the live system and processed with actual transactions | Tests continuously in the live environment, but test transactions must be reversed so they do not contaminate client records |
| Parallel simulation | Auditor reprocesses the client's actual data using the auditor's own program and compares the output with the client's results | Uses real data, so it detects differences in processing logic |
| Generalized audit software (GAS) | Programs that read client files to sort, total, recompute, stratify, select samples, and find exceptions (such as duplicates or gaps) | The most common substantive CAAT; supports data analytics |
| Embedded audit modules and SCARF | Audit routines built into the client's programs capture transactions that meet auditor-set criteria | Continuous auditing; requires cooperation during system development |
| Tagging and tracing, snapshot, mapping | Mark transactions to follow them through processing, capture images of records at points in processing, or identify program code that was never executed | Help evaluate processing logic and unused or unauthorized code |
5. Data Analytics in the Audit
Audit data analytics examine entire populations rather than samples, using tools such as generalized audit software and visualization dashboards. Common uses include journal entry testing for management override (PSA 240), matching three-way documents in purchasing, identifying duplicate payments or ghost vendors, and applying Benford's law to spot unusual digit patterns. The auditor must first test the completeness and accuracy of the data extracted from the client's system, because analytics on incomplete data give false comfort.
6. Emerging Technologies and Cybersecurity
- Cloud and outsourced IT: reliance on third-party providers makes SOC reports, contracts, and data-location issues part of risk assessment.
- Robotic process automation (RPA): software bots perform repetitive tasks, so bot access credentials and change controls become general IT controls.
- Blockchain and digital assets: records may be immutable, but the auditor still needs evidence on the existence, rights, and valuation of digital assets and on the controls over private keys.
- Artificial intelligence: models used in estimates or processing require governance over data, model changes, and outputs.
- Cybersecurity incidents: breaches can affect the integrity of financial data, trigger provisions or disclosures, and create going concern or data privacy (RA 10173) issues.
An auditor obtains a copy of the client's actual payroll master file and transaction data and processes them using the auditor's own program. The results are compared with the client's payroll register. Which CAAT is being used?
Test data
Embedded audit module
Integrated test facility
Parallel simulation
What is the main risk that an auditor must manage when using an integrated test facility?
The client's program may be replaced before the test
The auditor cannot use actual client transactions
Fictitious test transactions may contaminate the client's live records if they are not reversed
The technique cannot be used in online real-time systems
A small company's bookkeeper enters transactions, runs the accounting software, prepares reports, and has full access to change master files. Which audit response is most appropriate?
Rely fully on the software's programmed controls
Issue a disclaimer of opinion because segregation of duties is absent
Emphasize substantive procedures and evaluate compensating controls such as owner review
Test only general IT controls and skip substantive testing
Sections you finish are checked off in the contents.