Sunday, February 8, 2009

Auditing Services:


1. Internal Audit
2. External Audit
3. Vat Audit
4. Consultancy services
5. Others


Contact:
Mr. Binod Dhakal
Tel: 9841959522
E-mail: justbinod2000@gmail.com
URL: auditNepal.blogspot.com

stages

Stage One: Planning
Our planning for our work across the University is based on a five-year cycle and within this period we cover all activities of the institution at least once. Some areas that are considered to be high risk or high priority are often covered more than once in this period. This five-year plan is broken down into annual plans that identify audit reviews for each financial year. Prior to the start of each year we will contact your department or school to notify you about the audit and to schedule a time during the year that is most convenient for the audit to take place.
Nearer the start of the audit we will arrange a meeting with you to discuss the scope and objectives of the audit. Your input at this stage is important to us as it helps us establish areas of risk that should be included in the scope of the work. This is also your opportunity to raise any issues or areas of special concern that could be covered as part of the audit. We use this meeting, to establish information about the area being reviewed and this typically includes personnel, finance and other relevant information. One specific aspect of this meeting is identifying your unit’s strategic objectives and a discussion of the risks on your local risk register. From this we determine the possible risks that exist that may affect the achievement of your objectives and how best you can manage them through the use of internal controls.
It is helpful to us at this point if you can identify staff who can assist us in our work and any information that we are likely to need access to. We have found that in the past, a nominated audit contact is a useful way of managing the audit jointly between you and us so that issues can be raised and cleared on an ongoing basis with you as the audit progresses. This also allows you to pick up early indications of the sort of areas we will be reporting on.
The information we have gained from our initial planning meeting (above) is used in conjunction with other relevant information about your unit in order to obtain a general overview of operations. This may include information on budgets and strategic plans as well as past audit reports. There are certain risks that we will always review to ensure that they are being adequately controlled and managed - these include financial transactions, local risk management and business continuity planning.
All of this information is then used to make a preliminary assessment of the risks and controls for your unit. In the interests of quality and consistency, the Head of Internal Audit reviews this work and agrees the scope of work to be carried out. We then confirm the arrangements discussed at the meeting in a scope letter.
We use this preparatory work to produce an Audit Programme – this is an internal document that specifies detailed work that needs to be undertaken as part of the fieldwork.
Stage Two: Fieldwork
Our fieldwork concentrates on determining how well your unit is managing the risks identified at the planning stage and what controls are operating to help you do this. This can take a variety of forms that includes interviews and detailed testing / analysis of documents or transactions. When we have completed the fieldwork stage, we usually have a list of significant findings that we use to prepare a draft audit report.
However, prior to this we will usually have arranged to discuss any key issues with our audit contact before completion of the fieldwork (see above). We encourage this aspect of the audit as our contact can offer insights and work with us to determine the best method of resolving any issues that arise. Usually these communications are oral. However, sometimes, they are written in order to ensure full understanding by you and us: we aim for a no surprises approach!
Stage Three: Reporting
When we have finished our fieldwork, we draft a report. The Head of Internal Audit reviews the fieldwork and the draft in line with the professional auditing standards. Once this stage has been completed, we hold a feedback meeting to summarise the audit findings, conclusions, and recommendations necessary for us to publish a draft version of the report. We use this meeting, to listen to your comments on our findings and to reach an agreement on any recommendations that we have identified.
We then produce a formal draft report, taking into account any revisions resulting from the feedback meeting and any other subsequent work we have done in light of it. The Head of Internal Audit also reviews this work. The formal draft is then sent to you so that you have the opportunity to respond to the audit findings prior to the final report being published. We also use your response to include any further, relevant observations that you have into our final report. Included with our draft is an action plan that identifies the recommendations made in the report and as part of your response we ask you to complete the action plan. This involves explaining how the recommendations will be implemented, by whom and within what time scale. We ask that you respond to us within two weeks of receiving the draft report and action plan. This is because, like you, we don’t want the audit review process to become drawn-out and protracted and need a timely response so that we can finalise the report as quickly as possible.
We distribute copies of the final report to the operational managers of your unit and to the Director of Finance and the Registrar and Secretary. The University’s Audit Committee also receives summary reports of our work for each audit undertaken, and a copy of the completed action plan.
Finally, as part of Internal Audit's self-evaluation program, we ask you to comment on our performance. This feedback has proven to be very helpful to us, and we have made changes in our procedures as a result of the suggestions we have received. This is a short questionnaire that only takes a few minutes to complete but is important as it benefits both you and us for future audits; we also summarise the results of these questionnaires to report periodically to the Audit Committee.
Stage Four: Follow-up
Each year we select a sample of previous audits for a follow-up review. The purpose of the reviews is to check progress on the recommendations made from the last audit. During these reviews we use the completed action plan as a basis for the work to be undertaken and examine the progress on the agreed recommendations.
The reporting process for follow-up work follows a similar pattern to that of the routine reporting processes (see stage three) and you have the opportunity to respond to the audit findings prior to issue of the final report.
In addition, whenever we start a planned audit review from our agreed audit schedule of work, we will also review any key recommendations from past audits as part of our programme of work.
There is often the perception that contact with Internal Audit need not be maintained until the next audit. However, having worked with managers on audits, we are in a position to gain a good understanding of your unit's operations. To this end, we encourage an ongoing dialogue of advice and consultancy in the periods between audits to ensure that you are in a better position to manage the risks associated with your unit.

The Audit Process

The internal audit process is something that most people that are audited are often only aware of when the auditors are on site and this can often give a limited picture of our whole cycle of work. The Internal Audit Service at the University of Birmingham is committed to providing a service that includes constructive involvement and communication between you (our audit client) and us. The step-by-step guide provided below identifies the stages of an audit and highlights the potential for you to become involved in the process. We have found that things work best when unit managers and Internal Audit develop a good working relationship based on clear and continuing communication.
Most audits follow a fairly well-established pattern that consist of:
Planning
Fieldwork
Reporting
Follow-up
Your involvement is crucial to us at each of the four stages identified above. Specifically, audits are often viewed as something that happens to a section or service but you do have a significant input and influence upon the whole process. As a result, this does mean a small amount of time may be diverted from your usual routines. However, we are committed to minimising the impact of this and any disruption to your activities.

Defination

sequential order of steps followed by the auditor in the examination of client records. The audit process may vary depending upon the nature of the engagement, its objectives, and type of audit assurance desired. The process includes understanding the particular client's environment, conducting the auditing procedures and tests, appraising the audit results, and communicating the resultsto interested parties.

Auditing detail process and way:

IT Audit Process Overview
The auditor must plan and conduct the audit to ensure their audit risk (the risk of reaching an incorrect conclusion based on the audit findings) will be limited to an acceptable level. To eliminate the possibility of assessing audit risk too low the auditor should perform the following steps:
Obtain an Understanding of the Organization and its Environment: The understanding of the organization and its environment is used to assess the risk of material misstatement/weakness and to set the scope of the audit. The auditor’s understanding should include information on the nature of the entity, management, governance, objectives and strategies, and business processes.
Identify Risks that May Result in Material Misstatements: The auditor must evaluate an organization’s business risks (threats to the organization’s ability to achieve its objectives). An organization’s business risks can arise or change due to new personnel, new or restructured information systems, corporate restructuring, and rapid growth to name a few.
Evaluate the Organization’s Response to those Risks: Once the auditor has evaluated the organization’s response to the assessed risks, the auditor should then obtain evidence of management’s actions toward those risks. The organization’s response (or lack thereof) to any business risks will impact the auditor’s assessed level of audit risk.
Assess the Risk of Material Misstatement: Based on the knowledge obtained in evaluating the organization’s responses to business risks, the auditor then assesses the risk of material misstatements and determines specific audit procedures that are necessary based on that risk assessment.
Evaluate Results and Issue Audit Report: At this level, the auditor should determine if the assessments of risks were appropriate and whether sufficient evidence was obtained. The auditor will issue either an unqualified or qualified audit report based on their findings.

Phases of an IT Audit
The audit process can be broken down into the following audit phases:

Establish the Terms of the Engagement
This will allow the auditor to set the scope and objectives of the relationship between the auditor and the organization. The engagement letter should address the responsibility (scope, independence, deliverables), authority (right of access to information), and accountability (auditees’ rights, agreed completion date) of the auditor.

Preliminary Review
This phase of the audit allows the auditor to gather organizational information as a basis for creating their audit plan. The preliminary review will identify an organization’s strategy and responsibilities for managing and controlling computer applications. An auditor can provide an in depth overview of an organization’s accounting system to establish which applications are financially significant at this phase. Obtaining general data about the company, identifying financial application areas, and preparing an audit plan can achieve this.

Establish Materiality and Assess Risks
In order to plan the audit, a preliminary judgment about materiality and assessment of the client’s business risks are made to set the scope of the audit.

Plan the Audit
Proper planning of the audit will ensure the audit is conducted in an effective and efficient manner. When developing the audit plan, the auditor should take into consideration the results of their understanding of the organization and the results of the risk assessment process.

IT Audit Process Overview
The auditor must plan and conduct the audit to ensure their audit risk (the risk of reaching an incorrect conclusion based on the audit findings) will be limited to an acceptable level. To eliminate the possibility of assessing audit risk too low the auditor should perform the following steps:
Obtain an Understanding of the Organization and its Environment: The understanding of the organization and its environment is used to assess the risk of material misstatement/weakness and to set the scope of the audit. The auditor’s understanding should include information on the nature of the entity, management, governance, objectives and strategies, and business processes.
Identify Risks that May Result in Material Misstatements: The auditor must evaluate an organization’s business risks (threats to the organization’s ability to achieve its objectives). An organization’s business risks can arise or change due to new personnel, new or restructured information systems, corporate restructuring, and rapid growth to name a few.
Evaluate the Organization’s Response to those Risks: Once the auditor has evaluated the organization’s response to the assessed risks, the auditor should then obtain evidence of management’s actions toward those risks. The organization’s response (or lack thereof) to any business risks will impact the auditor’s assessed level of audit risk.
Assess the Risk of Material Misstatement: Based on the knowledge obtained in evaluating the organization’s responses to business risks, the auditor then assesses the risk of material misstatements and determines specific audit procedures that are necessary based on that risk assessment.
Evaluate Results and Issue Audit Report: At this level, the auditor should determine if the assessments of risks were appropriate and whether sufficient evidence was obtained. The auditor will issue either an unqualified or qualified audit report based on their findings.

Phases of an IT Audit
The audit process can be broken down into the following audit phases:

Establish the Terms of the Engagement
This will allow the auditor to set the scope and objectives of the relationship between the auditor and the organization. The engagement letter should address the responsibility (scope, independence, deliverables), authority (right of access to information), and accountability (auditees’ rights, agreed completion date) of the auditor.

Preliminary Review
This phase of the audit allows the auditor to gather organizational information as a basis for creating their audit plan. The preliminary review will identify an organization’s strategy and responsibilities for managing and controlling computer applications. An auditor can provide an in depth overview of an organization’s accounting system to establish which applications are financially significant at this phase. Obtaining general data about the company, identifying financial application areas, and preparing an audit plan can achieve this.

Establish Materiality and Assess Risks
In order to plan the audit, a preliminary judgment about materiality and assessment of the client’s business risks are made to set the scope of the audit.

Plan the Audit
Proper planning of the audit will ensure the audit is conducted in an effective and efficient manner. When developing the audit plan, the auditor should take into consideration the results of their understanding of the organization and the results of the risk assessment process.

Consider Internal Control
An internal control system should be designed and operated to provide reasonable assurance that an organization’s objectives are being achieved in the following categories: effectiveness and efficiency of operations, reliability of financial reporting, and compliance with applicable laws and regulations.
To develop their understanding of internal controls, the auditor should consider information from previous audits, the assessment of inherent risk, judgments about materiality, and the complexity of the organization’s operations and systems.
Once the auditor develops their understanding of an organization’s internal controls, they will be able to assess the level of their control risk (the risk a material weakness will not be prevented or detected by internal controls).

Perform Audit Procedures
Audit procedures are developed based on the auditor’s understanding of the organization and its environment. A substantive audit approach is used when auditing an organization’s information system.

Issue the Audit Report
Once audit procedures have been performed and results have been evaluated, the auditor will issue either an unqualified or qualified audit report based on their findings.

Planning the Audit
IS Standard 050 (Planning) states, “The IT auditor should plan the information systems audit coverage to address the audit objectives and comply with applicable laws and professional auditing standards.”
One of the first tasks an auditor must do when planning the audit is to develop a working budget. The IT audit manager must know the capabilities of the audit staff assigned to the project. In addition to budgeted time needed to perform the audit, the IT audit manager should also budget time needed to train the audit staff (if needed) and allow time for any error correction purposes.
While planning the audit, the auditor decides what level of audit risk (the risk of reaching an incorrect conclusion based on the audit findings) he or she is willing to accept. The more effective and extensive the audit work is, the less the risk that a weakness will go undetected and the auditor will issue an inappropriate report. Audit risk is dependent on the auditors assessed levels of inherent risk (the susceptibility of an audit area to error which could be material, assuming there are no related internal controls), control risk (the risk a material weakness will not be prevented or detected by internal controls), and detection risk (the risk substantive tests will not detect an error which could be material). These risks are determined when the auditor performs a risk assessment of the organization.
Additionally, in order to evaluate whether an IT audit has been successful, the auditor must first identify the intended scope and objectives of the audit to test management’s assertions on their information systems. To meet the audit objectives, and to ensure that audit resources will be used efficiently, the auditor will need to establish levels of materiality. The auditor should consider both qualitative and quantitative aspects in determining materiality. An assessment of risk should be made to provide reasonable assurance that all material items will be adequately covered during the audit work. This assessment should identify areas with relatively high risk of existence of material problems.

[edit] Materiality
In assessing materiality, the IT auditor should consider:
The aggregate level of error acceptable to management, the IT auditor, and appropriate regulatory agencies.
The potential for the cumulative effect of small errors or weaknesses to become material.
While establishing materiality, the auditor may audit non-financial items such as physical access controls, logical access controls, and systems for personnel management, manufacturing control, design, quality control, and password generation.
While planning the audit work to meet the audit objectives, the auditor should identify relevant control objectives and determine, based on materiality, which controls should be examined. Internal control objectives are placed by management and identifies what the management strives to achieve through their internal controls.
Where financial transactions are not processed, the following identifies some measures the auditor should consider when assessing materiality:
Criticality of the business processes supported by the system or operation.
Cost of the system or operation (hardware, software, third-party services)
Potential cost of errors.
Number of accesses/transactions/inquiries processed per period.
Penalties for failure to comply with legal and contractual requirements.

[edit] Risk Assessment
A risk is any event or action, generated internally or externally, which prevents an organization from achieving its goals and/or objectives. Risks affect control objectives in the areas of data integrity and accuracy, timeliness of the information for decision making, ability to access the system, and confidentiality/privacy of information, to name a few. Risk assessment allows the auditor to determine the scope of the audit and assess the level of audit risk and error risk (the risk of errors occurring in the area being audited). Additionally, risk assessment will aid in planning decisions such as:
The nature, extent, and timing of audit procedures.
The areas or business functions to be audited.
The amount of time and resources to be allocated to an audit.

[edit] Documentation of Risk Assessment
Once the assessed level of risk has been determined, the auditor should document the following in their work papers:
A description of the risk assessment technique used.
The identification of significant risks.
The risks the audit is going to address.
The audit evidence used to support the IS auditor’s assessment of risk.

[edit] The Audit Plan
The audit plan details the audit objectives and steps the auditor must take to ensure all of the important issues in the audit are covered. The audit plan includes:
The auditor’s understanding of the client.
Potential audit risks.
A basic framework for how the audit resources (budgeted audit hours) are to be allocated throughout the audit.
Audit procedures to be performed.
The objective of the audit plan is to assist the auditor in conducting an effective and efficient audit.

[edit] Planning Memo
A planning memo outlines for the auditee the tone and course of action the IT audit manager plans to take. The memo outlines for the auditee the areas within the audit the auditor is planning to spend most of their time, and it gives the auditee the opportunity to voice any concerns.

[edit] Evaluation of Internal Controls
COSO defines internal control as, “a process, influenced by an entity’s board of directors, management, and other personnel, that is designed to provide reasonable assurance in the effectiveness and efficiency of operations, reliability of financial reporting, and the compliance of applicable laws and regulations”. The auditor evaluates the organization’s control structure by understanding the organization’s five interrelated control components. They include:
Control Environment Provides the foundation for the other components. Encompasses such factors as management’s philosophy and operating style.
Risk Assessment Consists of risk identification and analysis.
Control Activities Consists of the policies and procedures that ensure employees carry out management’s directions. Types of control activities an organization must implement are preventative controls (controls intended to stop an error from occurring), detective controls (controls intended to detect if an error has occurred), and mitigating controls (control activities that can mitigate the risks associated with a key control not operating effectively).
Information and Communication Ensures the organization obtains pertinent information, and then communicates it throughout the organization.
Monitoring Reviewing the output generated by control activities and conducting special evaluations.
In addition to understanding the organization’s control components, the auditor must also evaluate the organization’s General and Application controls.

[edit] General Controls
General controls relate to the overall information-processing environment and has a large effect on the organization’s computer operations. Types of general controls include:
Organizational Controls - includes segregation of duties controls.
Data Center and Network Operations Controls – ensures the proper entry of data into an application system and proper oversight of error correction.
Hardware & Software Acquisition and Maintenance Controls – includes controls to compare data for accuracy when it is input twice by two separate components.
Access Security Controls – ensures the physical protection of computer equipment, software, and data, and is concerned with the loss of assets and information through theft or unauthorized use.
Application System Acquisition, Development, and Maintenance Controls - ensures the reliability of information processing.
Managerial controls- To ensure that there is no unauthorised access to IT assets.

[edit] Application Controls
Application controls apply to the processing of individual accounting applications and help ensure the completeness and accuracy of transaction processing, authorization, and validity. Types of application controls include:
Data Capture Controls – ensures that all transactions are recorded in the application system, transactions are recorded only once, and rejected transactions are identified, controlled, corrected, and reentered into the system.
Data Validation Controls – ensures that all transactions are properly valued.
Processing Controls – ensures the proper processing of transactions.
Output Controls – ensures that computer output is not distributed or displayed to unauthorized users.
Error Controls – ensures that errors are corrected and resubmitted to the application system at the correct point in processing.
Application controls may be compromised by the following application risks:
Weak security
Unauthorized access to data and unauthorized remote access
Inaccurate information and erroneous or falsified data input
Misuse by authorized end users
Incomplete processing and/or duplicate transactions
Untimely processing
Communication system failure
Inadequate training and support

[edit] Tests of Controls
Tests of controls are audit procedures performed to evaluate the effectiveness of either the design or the operation of an internal control. Tests of controls directed toward the design of the control focuses on evaluating whether the control is suitably designed to prevent material weaknesses. Tests of controls directed toward the operation of the control focuses on assessing how the control was applied, the consistency with which it was applied, and who applied it. In addition to inquiring with appropriate personnel and observation of the application of the control, an IT auditor’s main focus when testing the controls is to do a re-performance of the application of the control themselves.

[edit] Audit Procedures
Audit procedures are specific tasks (audit tests) performed by the auditor to gather evidence to determine if specific audit objectives are being met. IS Auditing Standard 060 (Performance of Audit Work) states, “During the course of the audit, the IT auditor should obtain sufficient, reliable, and relevant evidence to achieve the audit objectives. The audit findings and conclusions are to be supported by appropriate analysis and interpretation of this evidence.”
An auditor must design, select, evaluate, and document sample evidence in order to meet the requirements of “sufficient, reliable, and relevant evidence” and “supported by appropriate analysis”.

[edit] Audit Sampling
Audit sampling is the application of an audit procedure to less than 100% of the population to enable the IT auditor to evaluate audit evidence within a class of transactions for the purpose of forming a conclusion concerning the population. When designing the size and structure of an audit sample, the IT auditor should consider the audit objectives determined when planning the audit, the nature of the population, and the sampling and selection methods.

[edit] Selecting the Sample
The auditor should select the sample items in such a way that they are representative of the population. The most commonly used sampling selection methods are:
Statistical Sampling Methods
Random Sampling – ensures that all combinations of sampling units in the population have an equal chance of selection.
Systematic Sampling – involves selecting sampling units using a fixed interval between selections with the first interval having a random start.
Non-Statistical Sampling Methods
Haphazard Sampling – the auditor selects the sample without following a structured technique.
Judgmental Sampling – the auditor places a bias on the sample. For example, selecting only sampling units over a certain value.
The selection of the sample size is affected by the level of sampling risk that the IT auditor is willing to accept. Sampling risk is the risk the auditor’s conclusion may be different from the conclusion that would be reached if the entire population were subjected to the same audit procedure. The two types of sampling risk are:
The Risk of Incorrect Acceptance – the risk that a material misstatement is assessed as unlikely, when in fact the population is materially misstated.
The Risk of Incorrect Rejection – the risk that a material misstatement is assessed as likely, when in fact the population is not materially misstated.
Once the sample items have been selected to be tested, the auditor can begin audit tests using Computer Assisted Auditing Techniques (CAATs), which will be discussed shortly.

[edit] Evaluation and Documentation of Samples
The performance and evaluation of a sample must address the following issues:
The effect of not being able to apply a planned procedure to a sample item.
A projection of the sample results to the population being tested, then comparing those results with the planned amounts.
Appropriate consideration to the assessed level of sampling risk must be performed.
SAS 39 requires the auditor to adequately consider qualitative aspects of misstatements, such as the nature and cause of the misstatement and the possible relationship of the misstatements to other phases of the audit.
The auditor must document in their work papers the sampling objectives and the sampling process used. The work papers should include the source of the population, the sampling method used, sampling parameters, items selected, details of audit tests performed, and conclusions reached.

[edit] Computer Assisted Auditing Techniques (CAATs)
Further information: Data analysis (information technology)
CAATs are used to test application controls as well as perform substantive tests on sample items. Types of CAATs include:
Generalized Audit Software (GAS) – allows the auditor to perform tests on computer files and databases.
Custom Audit Software (CAS) – generally written by auditors for specific audit tasks. CAS is necessary when the organization’s computer system is not compatible with the auditor’s GAS or when the auditor wants to conduct some testing that may not be possible with the GAS.
Test Data – the auditor uses test data for testing the application controls in the client’s computer programs. The auditor includes simulated valid and invalid test data, used to test the accuracy of the computer system’s operations. This technique can be used to check data validation controls and error detection routines, processing logic controls, and arithmetic calculations, to name a few.
Parallel Simulation – the auditor must construct a computer simulation that mimics the client’s production programs.
Integrated Test Facility – the auditor enters test data along with actual data in a normal application run.

[edit] Evidence
Through the use of CAATs, the auditor will be able to obtain evidence to support their final conclusions developed on the audit. Audit evidence should be sufficient, reliable, relevant, and useful in order for the auditor to form an opinion and to support their findings and conclusions. If the auditor cannot form an opinion based on the audit evidence obtained, the auditor should then obtain additional audit evidence. Procedures used to gather audit evidence varies depending on the information system being audited. The auditor should select the most appropriate procedure for the audit objective. The following procedures should be considered:
Inquiry and/or Observation
Inspection
Reperformance
Monitoring
The audit evidence gathered by the auditor should be documented and organized to support the auditor’s findings and conclusions. Finally, when an auditor believes that sufficient audit evidence cannot be obtained, the auditor should disclose this fact as a scope limitation within the audit report.

[edit] Completing the Audit
Before choosing the appropriate audit report, the auditor must consider the following issues:
Review for Subsequent Events – two types of subsequent events require an evaluation by the auditor. They include:
Type I events – events that provide additional evidence about the conditions that existed at the date of the balance sheet.
Type II events – events that provide evidence about conditions that did not exist at the date of the balance sheet, but arose after that date.
Audit procedures used to review for subsequent events include asking management whether any unusual adjustments to their information systems have been made during the subsequent events period (after the completion of the audit, but before the audit report is issued), or obtaining a representation letter from management.
Final Evidential Evaluation Processes – audit steps performed by the auditor in this phase to determine the most appropriate audit report includes obtaining a representation letter, reviewing work papers, final assessment of audit results and obtaining an independent review of the engagement.
Communications with the Audit Committee and Management – communications should include significant audit adjustments, the auditor’s judgments about the quality of the entity’s accounting principles, disagreements with management, major issues discussed with management before the auditor was retained, difficulties encountered during the audit, and fraud involving senior management. Also, the auditor should discuss the draft of the audit report with management to give management the chance to correct any weaknesses or deficiencies before they are reported and released to the public. The auditor may decide to do this in the form of a Management Comment Letter.
Subsequent Discovery of Facts Existing at the Date of the Auditor’s Report – Auditing standards 561 provides guidance for auditors when facts have come to the auditor’s attention about the organization’s processes that might have affected the report had they known about them.
The auditor’s conclusion and findings, which are based on documented evidence, must be objective, measurable, complete, and relevant. The findings are disclosed to management in formal statements, typically an audit report. Any recommendations must be provided for each audit finding for the report to be useful to management.

[edit] Reporting
IS Auditing Standard 070 (Reporting) states, “The IT auditor should provide a report in an appropriate form, upon the completion of the audit. The report should state the scope, objectives, period of coverage, and the nature, timing, and extent of the audit work performed. The report should state the findings, conclusions, and recommendations and any reservations, qualifications or limitations of scope that IT auditor has with respect to the audit.”

[edit] Types of Reports
Unqualified Audit Report
This type of report is used when the auditor has gathered sufficient evidence, the audit was performed in accordance with GAAS, and no scope limitations were encountered.
Unqualified Audit Report with Explanation
This type of audit report is required when the auditor’s wording needs to be modified possibly due to an emphasis of a matter or an organization’s lack of consistency when processing information.
Qualified Report
The auditor’s opinion will be qualified due to a scope limitation or an organization’s departure from GAAP, even though the overall financial statements having been fairly presented.
Qualified Report with Disclaimer
The auditor disclaims an opinion because there is insufficient competent evidence to form an opinion or because there is a lack of independence.
Qualified Report with an Adverse Opinion
The auditor issues this report because the organization’s financial statements are not presented fairly and were not developed in conformance with GAAP.

[edit] Audit Documentation
Working papers (audit documentation) is the formal collection of auditors notes, documents, flowcharts, correspondence, results of observations, plans and results of tests, the audit plan, minutes of meetings, computerized records, data files or application results, and evaluations that document the auditor activity for the entire audit period. The audit report is also included in the work papers. Work papers are essential to support the auditor’s findings and recommendations as stated in the audit report.

[edit] Follow Up Activities
Once the auditor has reported their findings and recommendations to management, the IT auditor should request and evaluate relevant information to conclude whether appropriate action was taken by management in a timely manner. The nature, timing, and extent of the follow-up activities should take into account the importance of the reported findings and the impact on the organization if corrective action has not been taken. Depending on the scope of the audit, the IT auditor may rely on an internal auditor to perform the follow-up activities.

[edit] Assessing the Audit
The audit and working papers should be evaluated based on the following criteria by a partner or senior manager:
Completeness – An audit must cover every element of the audit subject.
Pertinence – The audit should be free of extraneous or unnecessary elements.
Accuracy – All elements of the audit must be precise and error-free.
Appropriate Conclusions, Findings and Recommendations – The audit must present appropriate conclusions and findings that lead to recommendations reflecting workable and timely solutions to audit objectives.
Follow-up to Findings and Recommendations – The value of the audit must be assessed to assure that the findings and recommendations, reflecting workable and timely solution have been achieved to some quantifiable degree and have provided value to the organization.
An internal control system should be designed and operated to provide reasonable assurance that an organization’s objectives are being achieved in the following categories: effectiveness and efficiency of operations, reliability of financial reporting, and compliance with applicable laws and regulations.
To develop their understanding of internal controls, the auditor should consider information from previous audits, the assessment of inherent risk, judgments about materiality, and the complexity of the organization’s operations and systems.
Once the auditor develops their understanding of an organization’s internal controls, they will be able to assess the level of their control risk (the risk a material weakness will not be prevented or detected by internal controls).
Perform Audit Procedures
Audit procedures are developed based on the auditor’s understanding of the organization and its environment. A substantive audit approach is used when auditing an organization’s information system.

Issue the Audit Report
Once audit procedures have been performed and results have been evaluated, the auditor will issue either an unqualified or qualified audit report based on their findings.

Planning the Audit
IS Standard 050 (Planning) states, “The IT auditor should plan the information systems audit coverage to address the audit objectives and comply with applicable laws and professional auditing standards.”
One of the first tasks an auditor must do when planning the audit is to develop a working budget. The IT audit manager must know the capabilities of the audit staff assigned to the project. In addition to budgeted time needed to perform the audit, the IT audit manager should also budget time needed to train the audit staff (if needed) and allow time for any error correction purposes.
While planning the audit, the auditor decides what level of audit risk (the risk of reaching an incorrect conclusion based on the audit findings) he or she is willing to accept. The more effective and extensive the audit work is, the less the risk that a weakness will go undetected and the auditor will issue an inappropriate report. Audit risk is dependent on the auditors assessed levels of inherent risk (the susceptibility of an audit area to error which could be material, assuming there are no related internal controls), control risk (the risk a material weakness will not be prevented or detected by internal controls), and detection risk (the risk substantive tests will not detect an error which could be material). These risks are determined when the auditor performs a risk assessment of the organization.
Additionally, in order to evaluate whether an IT audit has been successful, the auditor must first identify the intended scope and objectives of the audit to test management’s assertions on their information systems. To meet the audit objectives, and to ensure that audit resources will be used efficiently, the auditor will need to establish levels of materiality. The auditor should consider both qualitative and quantitative aspects in determining materiality. An assessment of risk should be made to provide reasonable assurance that all material items will be adequately covered during the audit work. This assessment should identify areas with relatively high risk of existence of material problems.

Materiality
In assessing materiality, the IT auditor should consider:
The aggregate level of error acceptable to management, the IT auditor, and appropriate regulatory agencies.
The potential for the cumulative effect of small errors or weaknesses to become material.
While establishing materiality, the auditor may audit non-financial items such as physical access controls, logical access controls, and systems for personnel management, manufacturing control, design, quality control, and password generation.
While planning the audit work to meet the audit objectives, the auditor should identify relevant control objectives and determine, based on materiality, which controls should be examined. Internal control objectives are placed by management and identifies what the management strives to achieve through their internal controls.
Where financial transactions are not processed, the following identifies some measures the auditor should consider when assessing materiality:
Criticality of the business processes supported by the system or operation.
Cost of the system or operation (hardware, software, third-party services)
Potential cost of errors.
Number of accesses/transactions/inquiries processed per period.
Penalties for failure to comply with legal and contractual requirements.

Risk Assessment
A risk is any event or action, generated internally or externally, which prevents an organization from achieving its goals and/or objectives. Risks affect control objectives in the areas of data integrity and accuracy, timeliness of the information for decision making, ability to access the system, and confidentiality/privacy of information, to name a few. Risk assessment allows the auditor to determine the scope of the audit and assess the level of audit risk and error risk (the risk of errors occurring in the area being audited). Additionally, risk assessment will aid in planning decisions such as:
The nature, extent, and timing of audit procedures.
The areas or business functions to be audited.
The amount of time and resources to be allocated to an audit.

Documentation of Risk Assessment
Once the assessed level of risk has been determined, the auditor should document the following in their work papers:
A description of the risk assessment technique used.
The identification of significant risks.
The risks the audit is going to address.
The audit evidence used to support the IS auditor’s assessment of risk.

The Audit Plan
The audit plan details the audit objectives and steps the auditor must take to ensure all of the important issues in the audit are covered. The audit plan includes:
The auditor’s understanding of the client.
Potential audit risks.
A basic framework for how the audit resources (budgeted audit hours) are to be allocated throughout the audit.
Audit procedures to be performed.
The objective of the audit plan is to assist the auditor in conducting an effective and efficient audit.

Planning Memo
A planning memo outlines for the auditee the tone and course of action the IT audit manager plans to take. The memo outlines for the auditee the areas within the audit the auditor is planning to spend most of their time, and it gives the auditee the opportunity to voice any concerns.

Evaluation of Internal Controls
COSO defines internal control as, “a process, influenced by an entity’s board of directors, management, and other personnel, that is designed to provide reasonable assurance in the effectiveness and efficiency of operations, reliability of financial reporting, and the compliance of applicable laws and regulations”. The auditor evaluates the organization’s control structure by understanding the organization’s five interrelated control components. They include:
Control Environment Provides the foundation for the other components. Encompasses such factors as management’s philosophy and operating style.
Risk Assessment Consists of risk identification and analysis.
Control Activities Consists of the policies and procedures that ensure employees carry out management’s directions. Types of control activities an organization must implement are preventative controls (controls intended to stop an error from occurring), detective controls (controls intended to detect if an error has occurred), and mitigating controls (control activities that can mitigate the risks associated with a key control not operating effectively).
Information and Communication Ensures the organization obtains pertinent information, and then communicates it throughout the organization.
Monitoring Reviewing the output generated by control activities and conducting special evaluations.
In addition to understanding the organization’s control components, the auditor must also evaluate the organization’s General and Application controls.

General Controls
General controls relate to the overall information-processing environment and has a large effect on the organization’s computer operations. Types of general controls include:
Organizational Controls - includes segregation of duties controls.
Data Center and Network Operations Controls – ensures the proper entry of data into an application system and proper oversight of error correction.
Hardware & Software Acquisition and Maintenance Controls – includes controls to compare data for accuracy when it is input twice by two separate components.
Access Security Controls – ensures the physical protection of computer equipment, software, and data, and is concerned with the loss of assets and information through theft or unauthorized use.
Application System Acquisition, Development, and Maintenance Controls - ensures the reliability of information processing.
Managerial controls- To ensure that there is no unauthorised access to IT assets.

Application Controls
Application controls apply to the processing of individual accounting applications and help ensure the completeness and accuracy of transaction processing, authorization, and validity. Types of application controls include:
Data Capture Controls – ensures that all transactions are recorded in the application system, transactions are recorded only once, and rejected transactions are identified, controlled, corrected, and reentered into the system.
Data Validation Controls – ensures that all transactions are properly valued.
Processing Controls – ensures the proper processing of transactions.
Output Controls – ensures that computer output is not distributed or displayed to unauthorized users.
Error Controls – ensures that errors are corrected and resubmitted to the application system at the correct point in processing.
Application controls may be compromised by the following application risks:
Weak security
Unauthorized access to data and unauthorized remote access
Inaccurate information and erroneous or falsified data input
Misuse by authorized end users
Incomplete processing and/or duplicate transactions
Untimely processing
Communication system failure
Inadequate training and support

Tests of Controls
Tests of controls are audit procedures performed to evaluate the effectiveness of either the design or the operation of an internal control. Tests of controls directed toward the design of the control focuses on evaluating whether the control is suitably designed to prevent material weaknesses. Tests of controls directed toward the operation of the control focuses on assessing how the control was applied, the consistency with which it was applied, and who applied it. In addition to inquiring with appropriate personnel and observation of the application of the control, an IT auditor’s main focus when testing the controls is to do a re-performance of the application of the control themselves.

Audit Procedures
Audit procedures are specific tasks (audit tests) performed by the auditor to gather evidence to determine if specific audit objectives are being met. IS Auditing Standard 060 (Performance of Audit Work) states, “During the course of the audit, the IT auditor should obtain sufficient, reliable, and relevant evidence to achieve the audit objectives. The audit findings and conclusions are to be supported by appropriate analysis and interpretation of this evidence.”
An auditor must design, select, evaluate, and document sample evidence in order to meet the requirements of “sufficient, reliable, and relevant evidence” and “supported by appropriate analysis”.

Audit Sampling
Audit sampling is the application of an audit procedure to less than 100% of the population to enable the IT auditor to evaluate audit evidence within a class of transactions for the purpose of forming a conclusion concerning the population. When designing the size and structure of an audit sample, the IT auditor should consider the audit objectives determined when planning the audit, the nature of the population, and the sampling and selection methods.

Selecting the Sample
The auditor should select the sample items in such a way that they are representative of the population. The most commonly used sampling selection methods are:
Statistical Sampling Methods
Random Sampling – ensures that all combinations of sampling units in the population have an equal chance of selection.
Systematic Sampling – involves selecting sampling units using a fixed interval between selections with the first interval having a random start.
Non-Statistical Sampling Methods
Haphazard Sampling – the auditor selects the sample without following a structured technique.
Judgmental Sampling – the auditor places a bias on the sample. For example, selecting only sampling units over a certain value.
The selection of the sample size is affected by the level of sampling risk that the IT auditor is willing to accept. Sampling risk is the risk the auditor’s conclusion may be different from the conclusion that would be reached if the entire population were subjected to the same audit procedure. The two types of sampling risk are:
The Risk of Incorrect Acceptance – the risk that a material misstatement is assessed as unlikely, when in fact the population is materially misstated.
The Risk of Incorrect Rejection – the risk that a material misstatement is assessed as likely, when in fact the population is not materially misstated.
Once the sample items have been selected to be tested, the auditor can begin audit tests using Computer Assisted Auditing Techniques (CAATs), which will be discussed shortly.

Evaluation and Documentation of Samples
The performance and evaluation of a sample must address the following issues:
The effect of not being able to apply a planned procedure to a sample item.
A projection of the sample results to the population being tested, then comparing those results with the planned amounts.
Appropriate consideration to the assessed level of sampling risk must be performed.
SAS 39 requires the auditor to adequately consider qualitative aspects of misstatements, such as the nature and cause of the misstatement and the possible relationship of the misstatements to other phases of the audit.
The auditor must document in their work papers the sampling objectives and the sampling process used. The work papers should include the source of the population, the sampling method used, sampling parameters, items selected, details of audit tests performed, and conclusions reached.

Computer Assisted Auditing Techniques (CAATs)
Further information: Data analysis (information technology)
CAATs are used to test application controls as well as perform substantive tests on sample items. Types of CAATs include:
Generalized Audit Software (GAS) – allows the auditor to perform tests on computer files and databases.
Custom Audit Software (CAS) – generally written by auditors for specific audit tasks. CAS is necessary when the organization’s computer system is not compatible with the auditor’s GAS or when the auditor wants to conduct some testing that may not be possible with the GAS.
Test Data – the auditor uses test data for testing the application controls in the client’s computer programs. The auditor includes simulated valid and invalid test data, used to test the accuracy of the computer system’s operations. This technique can be used to check data validation controls and error detection routines, processing logic controls, and arithmetic calculations, to name a few.
Parallel Simulation – the auditor must construct a computer simulation that mimics the client’s production programs.
Integrated Test Facility – the auditor enters test data along with actual data in a normal application run.

Evidence
Through the use of CAATs, the auditor will be able to obtain evidence to support their final conclusions developed on the audit. Audit evidence should be sufficient, reliable, relevant, and useful in order for the auditor to form an opinion and to support their findings and conclusions. If the auditor cannot form an opinion based on the audit evidence obtained, the auditor should then obtain additional audit evidence. Procedures used to gather audit evidence varies depending on the information system being audited. The auditor should select the most appropriate procedure for the audit objective. The following procedures should be considered:
Inquiry and/or Observation
Inspection
Reperformance
Monitoring
The audit evidence gathered by the auditor should be documented and organized to support the auditor’s findings and conclusions. Finally, when an auditor believes that sufficient audit evidence cannot be obtained, the auditor should disclose this fact as a scope limitation within the audit report.

Completing the Audit
Before choosing the appropriate audit report, the auditor must consider the following issues:
Review for Subsequent Events – two types of subsequent events require an evaluation by the auditor. They include:
Type I events – events that provide additional evidence about the conditions that existed at the date of the balance sheet.
Type II events – events that provide evidence about conditions that did not exist at the date of the balance sheet, but arose after that date.
Audit procedures used to review for subsequent events include asking management whether any unusual adjustments to their information systems have been made during the subsequent events period (after the completion of the audit, but before the audit report is issued), or obtaining a representation letter from management.
Final Evidential Evaluation Processes – audit steps performed by the auditor in this phase to determine the most appropriate audit report includes obtaining a representation letter, reviewing work papers, final assessment of audit results and obtaining an independent review of the engagement.
Communications with the Audit Committee and Management – communications should include significant audit adjustments, the auditor’s judgments about the quality of the entity’s accounting principles, disagreements with management, major issues discussed with management before the auditor was retained, difficulties encountered during the audit, and fraud involving senior management. Also, the auditor should discuss the draft of the audit report with management to give management the chance to correct any weaknesses or deficiencies before they are reported and released to the public. The auditor may decide to do this in the form of a Management Comment Letter.
Subsequent Discovery of Facts Existing at the Date of the Auditor’s Report – Auditing standards 561 provides guidance for auditors when facts have come to the auditor’s attention about the organization’s processes that might have affected the report had they known about them.
The auditor’s conclusion and findings, which are based on documented evidence, must be objective, measurable, complete, and relevant. The findings are disclosed to management in formal statements, typically an audit report. Any recommendations must be provided for each audit finding for the report to be useful to management.

Reporting
IS Auditing Standard 070 (Reporting) states, “The IT auditor should provide a report in an appropriate form, upon the completion of the audit. The report should state the scope, objectives, period of coverage, and the nature, timing, and extent of the audit work performed. The report should state the findings, conclusions, and recommendations and any reservations, qualifications or limitations of scope that IT auditor has with respect to the audit.”

Types of Reports
Unqualified Audit Report
This type of report is used when the auditor has gathered sufficient evidence, the audit was performed in accordance with GAAS, and no scope limitations were encountered.
Unqualified Audit Report with Explanation
This type of audit report is required when the auditor’s wording needs to be modified possibly due to an emphasis of a matter or an organization’s lack of consistency when processing information.
Qualified Report
The auditor’s opinion will be qualified due to a scope limitation or an organization’s departure from GAAP, even though the overall financial statements having been fairly presented.
Qualified Report with Disclaimer
The auditor disclaims an opinion because there is insufficient competent evidence to form an opinion or because there is a lack of independence.
Qualified Report with an Adverse Opinion
The auditor issues this report because the organization’s financial statements are not presented fairly and were not developed in conformance with GAAP.

Audit Documentation
Working papers (audit documentation) is the formal collection of auditors notes, documents, flowcharts, correspondence, results of observations, plans and results of tests, the audit plan, minutes of meetings, computerized records, data files or application results, and evaluations that document the auditor activity for the entire audit period. The audit report is also included in the work papers. Work papers are essential to support the auditor’s findings and recommendations as stated in the audit report.

Follow Up Activities
Once the auditor has reported their findings and recommendations to management, the IT auditor should request and evaluate relevant information to conclude whether appropriate action was taken by management in a timely manner. The nature, timing, and extent of the follow-up activities should take into account the importance of the reported findings and the impact on the organization if corrective action has not been taken. Depending on the scope of the audit, the IT auditor may rely on an internal auditor to perform the follow-up activities.

Assessing the Audit
The audit and working papers should be evaluated based on the following criteria by a partner or senior manager:
Completeness – An audit must cover every element of the audit subject.
Pertinence – The audit should be free of extraneous or unnecessary elements.
Accuracy – All elements of the audit must be precise and error-free.
Appropriate Conclusions, Findings and Recommendations – The audit must present appropriate conclusions and findings that lead to recommendations reflecting workable and timely solutions to audit objectives.
Follow-up to Findings and Recommendations – The value of the audit must be assessed to assure that the findings and recommendations, reflecting workable and timely solution have been achieved to some quantifiable degree and have provided value to the organization.

The IS Audit Process

Information systems audit is a part of the overall audit process, which is one of the facilitators for good corporate governance. While there is no single universal definition of IS audit, Ron Weber has defined it (EDP auditing--as it was previously called) as "the process of collecting and evaluating evidence to determine whether a computer system (information system) safeguards assets, maintains data integrity, achieves organizational goals effectively and consumes resources efficiently."1
Information systems are the lifeblood of any large business. As in years past, computer systems do not merely record business transactions, but actually drive the key business processes of the enterprise. In such a scenario, senior management and business managers do have concerns about information systems. The purpose of IS audit is to review and provide feedback, assurances and suggestions. These concerns can be grouped under three broad heads:
Availability: Will the information systems on which the business is heavily dependent be available for the business at all times when required? Are the systems well protected against all types of losses and disasters?
Confidentiality: Will the information in the systems be disclosed only to those who have a need to see and use it and not to anyone else?
Integrity: Will the information provided by the systems always be accurate, reliable and timely? What ensures that no unauthorized modification can be made to the data or the software in the systems?
[Author's note: Of course there are other concerns that IS audit should look at, such as effectiveness, efficiency, value for money, return on investment, culture and people related issues. Such concerns will be addressed in IT Audit Basics columns in future issues of the Journal in 2002.]
Elements of IS Audit
An information system is not just a computer. Today's information systems are complex and have many components that piece together to make a business solution. Assurances about an information system can be obtained only if all the components are evaluated and secured. The proverbial weakest link is the total strength of the chain. The major elements of IS audit can be broadly classified:
Physical and environmental review--This includes physical security, power supply, air conditioning, humidity control and other environmental factors.
System administration review--This includes security review of the operating systems, database management systems, all system administration procedures and compliance.
Application software review--The business application could be payroll, invoicing, a web-based customer order processing system or an enterprise resource planning system that actually runs the business. Review of such application software includes access control and authorizations, validations, error and exception handling, business process flows within the application software and complementary manual controls and procedures. Additionally, a review of the system development lifecycle should be completed.
Network security review--Review of internal and external connections to the system, perimeter security, firewall review, router access control lists, port scanning and intrusion detection are some typical areas of coverage.
Business continuity review--This includes existence and maintenance of fault tolerant and redundant hardware, backup procedures and storage, and documented and tested disaster recovery/business continuity plan.
Data integrity review--The purpose of this is scrutiny of live data to verify adequacy of controls and impact of weaknesses, as noticed from any of the above reviews. Such substantive testing can be done using generalized audit software (e.g., computer assisted audit techniques).
All these elements need to be addressed to present to management a clear assessment of the system. For example, application software may be well designed and implemented with all the security features, but the default super-user password in the operating system used on the server may not have been changed, thereby allowing someone to access the data files directly. Such a situation negates whatever security is built into the application. Likewise, firewalls and technical system security may have been implemented very well, but the role definitions and access controls within the application software may have been so poorly designed and implemented that by using their user IDs, employees may get to see critical and sensitive information far beyond their roles.
It is important to understand that each audit may consist of these elements in varying measures; some audits may scrutinize only one of these elements or drop some of these elements. While the fact remains that it is necessary to do all of them, it is not mandatory to do all of them in one assignment. The skill sets required for each of these are different. The results of each audit need to be seen in relation to the other. This will enable the auditor and management to get the total view of the issues and problems. This overview is critical.
Risk-based Approach
Every organization uses a number of information systems. There may be different applications for different functions and activities and there may be a number of computer installations at different geographical locations.
The auditor is faced with the questions of what to audit, when and how frequently. The answer to this is to adopt a risk-based approach.
While there are risks inherent to information systems, these risks impact different systems in different ways. The risk of nonavailability even for an hour can be serious for a billing system at a busy retail store. The risk of unauthorized modification can be a source of frauds and potential losses to an online banking system. A batch processing system or a data consolidation system may be relatively less vulnerable to some of these risks. The technical environments on which the systems run also may affect the risk associated with the systems.
The steps that can be followed for a risk-based approach to making an audit plan are:
Inventory the information systems in use in the organization and categorize them.
Determine which of the systems impact critical functions or assets, such as money, materials, customers, decision making, and how close to real time they operate.
Assess what risks affect these systems and the severity of impact on the business.
Rank the systems based on the above assessment and decide the audit priority, resources, schedule and frequency.
The auditor then can draw up a yearly audit plan that lists the audits that will be performed during the year, as per a schedule, as well as the resources required.
The Audit Process
The preparation before commencing an audit involves collecting background information and assessing the resources and skills required to perform the audit. This enables staff with the right kind of skills to be allotted to the right assignment.
It always is a good practice to have a formal audit commencement meeting with the senior management responsible for the area under audit to finalize the scope, understand the special concerns, if any, schedule the dates and explain the methodology for the audit. Such meetings get senior management involved, allow people to meet each other, clarify issues and underlying business concerns, and help the audit to be conducted smoothly.
Similarly, after the audit scrutiny is completed, it is better to communicate the audit findings and suggestions for corrective action to senior management in a formal meeting using a presentation. This will ensure better understanding and increase buy-in of audit recommendations. It also gives auditees an opportunity to express their viewpoints on the issues raised. Writing a report after such a meeting where agreements are reached on all audit issues can greatly enhance audit effectiveness.
Key Challenge
IS audit often involves finding and recording observations that are highly technical. Such technical depth is required to perform effective IS audits. At the same time it is necessary to translate audit findings into vulnerabilities and businesses impacts to which operating managers and senior management can relate. Therein lies a main challenge of IS audit.

Auditing solutions

Auditing Services:


Contact:
Mr. Binod
Tel: 9841959522
E-mail: justbinod2000@gmail.com
URL: auditNepal.blogspot.com