IS Audit Function Knowledge

Slides:



Advertisements
Similar presentations
PRESENTATION ON MONDAY 7 TH AUGUST, 2006 BY SUDHIR VARMA FCA; CIA(USA) FOR THE INSTITUTE OF INTERNAL AUDITORS – INDIA, DELHI CHAPTER.
Advertisements

Internal Audit Documentation and Working Papers
QUALITY ASSURANCE AND IMPROVEMENT PROGRAM (QAIP)
ACCOUNTING ETHICS Lect. Victor-Octavian Müller, Ph.D.
Discussion on SA-500 – AUDIT EVIDENCE
Institute of Municipal Finance Officers & Related Professions
18- 1 © 2006 The McGraw-Hill Companies, Inc., All Rights Reserved. Chapter 18 Integrated Audits of Internal Control (For Public Companies Under Sarbanes-Oxley.
Quality evaluation and improvement for Internal Audit
SAFA- IFAC Regional SMP Forum
Purpose of the Standards
ISA 220 – Quality Control for Audits of Historical Financial Information
How can projects be controlled?
Protection Against Occupational Exposure
Auditing Standards IFTA\IRP Audit Guidance Government Auditing Standards (GAO) Generally Accepted Auditing Standards (GAAS) International Standards on.
Auditing & Assurance Services, 6e
Learning Objectives LO1 Describe the role of professional judgment in achieving the overall objectives of the independent auditor in conducting an audit.
Elements of Internal Controls Preventing Fraud, Waste, and Abuse in Urban and Rural Transit Systems.
Control environment and control activities. Day II Session III and IV.
Internal Auditing and Outsourcing
D-1 McGraw-Hill/Irwin ©2005 by the McGraw-Hill Companies, Inc. All rights reserved. Module D Internal, Governmental, and Fraud Audits “I predict that audit.
Audit objectives, Planning The Audit
IAEA International Atomic Energy Agency Reviewing Management System and the Interface with Nuclear Security (IRRS Modules 4 and 12) BASIC IRRS TRAINING.
Considering Internal Control
Audit Planning & Audit Evidence
NO FRAUD LEFT BEHIND The Effect of New Risk Assessment Auditing Standards on Schools Runyon Kersteen Ouellette.
©2003 Prentice Hall Business Publishing, Auditing and Assurance Services 9/e, Arens/Elder/Beasley Internal Control and Control Risk Chapter 10.
11 STANDARD ON QUALITY CONTROL (SQC) The Institute of Chartered Accountants of India has recently in the month of October 2007 has issued new standard.
S7: Audit Planning. Session Objectives To explain the need for planning To explain the need for planning To outline the essential elements of planning.
Standards and Guidelines for IS Auditing (ISACA).
Evaluation of Internal Control System
Audit Planning. Session Objectives To explain the need for planning To outline the essential elements of planning process To finalise the audit approach.
Private & Confidential1 (SIA) 13 Enterprise Risk Management The Standard should be read in the conjunction with the "Preface to the Standards on Internal.
Understanding the IT environment of the entity. Session objectives Defining contours of financial accounting in an IT environment and its characteristics.
1 Kingsley Karunaratne, Department of Accounting, University of Sri Jayewardenepura, Colombo - Sri Lanka Practice Management.
S4: Understanding the IT environment of the entity.
Evaluation of Internal Control System. Learning Objective 1 Contrast management’s need for internal control with the auditor’s need to consider internal.
Practice Management Quality Control
Copyright © 2007 Pearson Education Canada 1 Chapter 24: Assurance Services: Internal Auditing and Government Auditing.
1 Internal Audit. 2 Definition Is an independent activity established by management to examine and evaluate the organization’s risk management processes.
[Hayes, Dassen, Schilder and Wallage, Principles of Auditing An Introduction to ISAs, edition 2.1] © Pearson Education Limited 2007 Slide 4.1 An Auditor’s.
Audit Planning Process
Risk Management & Corporate Governance 1. What is Risk?  Risk arises from uncertainty; but all uncertainties do not carry risk.  Possibility of an unfavorable.
FACILITATOR Prof. Dr. Mohammad Majid Mahmood Art of Leadership & Motivation HRM – 760 Lecture - 25.
Copyright © 2013 by The McGraw-Hill Companies, Inc. All rights reserved.McGraw-Hill/Irwin.
International Security Management Standards. BS ISO/IEC 17799:2005 BS ISO/IEC 27001:2005 First edition – ISO/IEC 17799:2000 Second edition ISO/IEC 17799:2005.
1 Performance Auditing ICAS & IRAS Officers NAAA 21 Jan 2016.
©2012 Prentice Hall Business Publishing, Auditing 14/e, Arens/Elder/Beasley Section 404 Audits of Internal Control and Control Risk Chapter.
Copyright © 2007 Pearson Education Canada 9-1 Chapter 9: Internal Controls and Control Risk.
Copyright © 2015 McGraw-Hill Education. All rights reserved. No reproduction or distribution without the prior written consent of McGraw-Hill Education.
ICAJ/PAB - Improving Compliance with International Standards on Auditing Planning an audit of financial statements 19 July 2014.
©©2012 Pearson Education, Auditing 14/e, Arens/Elder/Beasley Considering Internal Control Chapter 10.
Copyright © 2014 Pearson Education, Inc. Publishing as Prentice Hall. Chapter
Internal Audit Quality Assessment Guide
Improving Compliance with ISAs Presenters: Al Johnson & Pat Hayle.
Introduction to Compliance Auditing
McGraw-Hill/Irwin © The McGraw-Hill Companies 2010 Internal Control in a Financial Statement Audit Chapter Six.
AUDIT STAFF TRAINING WORKSHOP 13 TH – 14 TH NOVEMBER 2014, HILTON HOTEL NAIROBI AUDIT PLANNING 1.
 Planning an audit of cost statements, records and other related documents is considered necessary to ensure achievement of audit objectives with available.
©2005 Prentice Hall Business Publishing, Auditing and Assurance Services 10/e, Arens/Elder/Beasley Internal Control and Control Risk Chapter 10.
An exposure to COMPLIANCE AUDIT By- Vishal Chawre DAG(A/c & VLC) O/o AG(A&E), Nagpur.
Audit Planning, Understanding the Client, Assessing Risks and Responding Chapter 6.
PLANNING, MATERIALITY AND ASSESSING THE RISK OF MISSTATEMENT
ACCOUNTING ETHICS Conf.univ.dr. Victor-Octavian Müller.
ACCOUNTING ETHICS Conf.univ.dr. Victor-Octavian Müller.
Taking the STANDARDS Seriously
ACCOUNTING ETHICS Conf.univ.dr. Victor-Octavian Müller.
ACCOUNTING ETHICS Conf.univ.dr. Victor-Octavian Müller.
ACCOUNTING ETHICS Lect. Victor-Octavian Müller, Ph.D.
Internal Audit’s Role in Preventing Fraud and Corruption
Internal Control Internal control is the process designed and affected by owners, management, and other personnel. It is implemented to address business.
Presentation transcript:

IS Audit Function Knowledge

Tasks Develop and implement a risk based IS audit strategy for the organization in compliance with IS audit standards, guidelines and best practices Plan specific audits to ensure that IT and business systems are protected and controlled Conduct audits in accordance with IS audit standards, guidelines and best practices to meet planned audit objectives Communicate emerging issues, potential risks and audit results to key stakeholders Advise on the implementation of risk management and control practices within the organization while maintaining independence

Knowledge Risk assessment in an audit context IS ISACA Auditing Standards, Guidelines and Procedures and Code of Professional Ethics IS auditing practices and techniques Techniques to gather information and preserve evidence (e.g. observation, inquiry, interview, computer-assisted audit techniques (CAATs), electronic media) The evidence life cycle (e.g., the collection, protection, chain of custody) Control objectives and control related to IS (e.g., COBIT) Risk assessment in an audit context Audit planning and management techniques Reporting and communication techniques (e.g. facilitation, negotiation, conflict resolution) Control self assessment (CSA) Continuous audit techniques

Organization The role of the IS audit function should be established by an audit charter. IS audit is most likely to be a part of internal audit; therefore, the audit charter may include other audit function This charter should state clearly management's responsibility and objectives for, and delegation of authority to, the IS audit function This document should outline the overall authority, scope and responsibilities of the audit function The highest level of management and the audit committee, if available, should approve this charter. Once established, this charter should be changed only if the change can be and is thoroughly justifies

Audit Charter (G5) Detail of Audit Charter Mandate Content Communication Service Level Agreements

Detail of Audit Charter Should be detailed enough to communicate Purpose Responsibility Authority and accountability Limitations of the audit function or audit assgnment Should be prpared for ongoing activities The audit charter should be subject to an annual review or more often if the responsibilities are varied or changed

Mandate The IS auditor should have a clear mandate to perform the IS audit function This mandate is ordinarily documented in an audit charter that should be formally accepted Where an audit charter exists for the audit function as a whole, wherever possible the IS audit mandate should be incoporated

Content Responsibility Authority Accountability

Responsibility Mission statement Aims/goals Scope Objectives Independence Relationship with external audit Auditee requirements Critical success factors Key performance indicators Other measures of performance

Authority Risk assessment Right of access to information, personnel, locations and systems relevant to the performance of audits Scope or any limitations of scope Functions to be audited Auditee expectations Organizational structure, including reporting lines to board and senior management Grading of IS audit staff

Accountability Responsibility lines to senior management Assignment performance appraisals Personnel Performace appraisals Staffing / career development Auditee's rights Independent quality reviews Assessment of compliance with standards Benchmarking performance and functions Assessment of completion of the audit plan Comparison of budget to actual costs Agreed actions; e.g. penalties when either party fails to carry out their responsibilities

Communication Describing the service, its scope, its availability and timeliness of delivery Providing cost estimates or budgets if they are available Describing problems and possible resolutions for them Providing adequate and readily accessible facilities for effective communication Determining the relationship between the service offered and the needs of the auditee

Service Level Agreements Availability for unplanned work Delivery of reports Costs REsponse to auditee complaints Quality of service Review of performance Communication with auditees Needs assessment Control risk self assessment Agreement of terms of reference for audits Reporting process Agreement of finding

Engagement Letter (G5) Purpose - Engagement letters are often used for individual assignments or for setting the scope and objectives of a relationship between external IS Audit and an organization Content Authority Accountability

Content Responsibility Scope Objective Independence Risk Assessment Specific auditee requirement Deliverable

Authority Right of access to information, personnel, locations and systems relevant to the performance of the assignment Scope or any limitations of scope Evidence of agreement to the terms and conditions of the engagement

Accountability Intended recipients of reports Auditees rights Quality reviews Agreed completion dates

Responsibility To the Profession To the Auditee (Organisation) To the Stakeholders Statutory and Regulatory To Society

Authority Rights of IS Auditors Limitations

Rights of IS Auditors The IS auditor has the right to have an engagement letter or audit charter specifying the scope, objective and terms of reference of the audit The IS auditor has the right to access appropriate information and resources to effectively and efficiently complete the audit The IS auditor has the right to believe that management has established appropriate controls to prevent, deter and deter fraud unless the tests and evaluation carried on by the IS auditor prove otherwise The IS auditor has the right to call for such information and explanations deemed necessary and appropriate to permit objective completion of the audit The IS auditor has the right to retain the working files, documents, audit evidences, etc., obtained during the course of the audit, in support of his/her conclusions and to use the same as the basis of reference in case of any issues or contradictions

Limitations The IS auditor should have sufficient knowledge to identify the indicators of fraud but may not be expected to have the expertise of the person whose primary responsibility is detecting and investigating fraud The IS auditor should be alert to the significant risks that might affect objectives, operations or resources. However, assurance procedures alone, even when performed with due professional care, do not guarantee that all significant risks will be identified

Limitations Where the IS auditor is not able to obtain required information, is restricted from accessing resources or is in any way restrained from carrying out his/her function, the IS auditor should escalate his/her concerns to appropriate senior levels in management. The IS auditor should conduct the audit in a professional manner Where the IS auditor has utilized the services of an external expert, the IS auditor should evaluate the usefulness and sufficiency of work performed by such external expert and also perform appropriate testing to confirm the findings of the external expert The IS auditor is not responsibility for implementing corrective actions

Accountability Professional Accountability Professional Negligence Restrictions

Effect of laws and Regulation on IS Audit Planning Establishment of the regulatory requirements Organization of the regulatory requirements Responsibilities assigned to the corresponding entities Correlation to financial, operational and IT audit functions

Major Concern Legal requirements placed on IS audit Legal requirements placed on the auditee