Study Notes on ICT in Internal Auditing
Subject: Information and Communications Technology (ICT)
Facilitators: Ms. M. Mogale, Ms. M. Mamabolo, Mr. T. Lebese
Level: Auditing 3A (IAA316D)
Learning Outcomes
Understand main changes in hardware, software, and audit approach in ICT, focusing on the transition from traditional to digital processing systems.
Familiarize with main terminology and concepts in an ICT environment to effectively communicate and engage in audits.
Explain ICT's impact on control systems, detailing how technological advancements influence the effectiveness and efficiency of internal controls.
Identify general controls in ICT, including physical controls, access controls, and application controls.
Assess weaknesses in general control activities and recommend improvements to mitigate risks associated with those weaknesses.
Describe application control activities: risks, preventive, detective, corrective controls, and audit trails for batch and online systems, with examples of each type of control.
Gain knowledge in specific ICT environments and governance frameworks, such as COBIT and ITIL, to understand how they dictate best practices and compliance.
Introduction to ICT
Reliance on ICT systems for processing and storage of information is pivotal in modern organizations due to the need for accuracy, speed, and efficiency in data handling.
Definition of ICT: Integrated system of devices, networks, communication links, and data that facilitate electronic interaction in the digital world. This encompasses hardware (computers, servers), software (applications, operating systems), and networks (LAN, WAN).
Internal Audit Approach
Audit objectives remain unchanged; however, execution processes are influenced by the ICT environment, necessitating auditors to embrace technology in their methodologies.
Auditors must adapt to the ever-evolving ICT landscape by staying updated on the latest technologies, trends, and threats in the cyber environment, enhancing their ability to perform risk assessments and audits effectively.
Manual vs ICT Systems
Manual Systems:
Follow the accounting cycle manually, which allows for clear audit trails and detailed documentation.
Vulnerable to risks such as data loss from natural disasters, human errors, and inefficiencies in processing.
ICT Systems:
Enable fast processing of large data volumes with automation, resulting in faster decision-making processes and reduced operational costs.
Present challenges for tracking audit trails, as many transactions are automated and lack human oversight, which can lead to difficulties in identifying and mitigating errors or fraud.
Risks include data manipulation, data loss, and system vulnerabilities due to malicious attacks or hacking attempts, necessitating robust cyber security measures.
Software Types
Application Software: Performs specific tasks tailored for user needs, such as word processing, spreadsheets, or databases (e.g., Microsoft Word, Excel, and Access).
System Software: Operating systems that manage computer hardware and allow application software to function efficiently (e.g., Windows, macOS, and Linux).
Internal Audit Approaches in ICT
Auditing Around the Computer: Tracing source documents to computer outputs; ensures that audit trails exist by verifying the output against original source documentation and performing substantive testing.
Auditing With the Computer: Utilizing ICT tools such as data analytics and automated reporting to conduct internal audit engagements more efficiently.
Auditing Through the Computer: Testing the ICT system's consistency and accuracy using dummy data to simulate real transactions, ensuring that the system performs as expected under various conditions and loads.
Internal Auditor's Knowledge and Skills
Understand auditing concepts and risks associated with ICT systems, including risks specific to technology such as system failures, data breaches, and fraud.
Familiarity with ICT components like hardware, software, data structures, and security protocols ensures that auditors can identify pertinent issues during audits and recommend appropriate solutions.
Concepts in ICT Environment
Core ICT Components:
Central Processing Unit (CPU): Executes processing commands and manages data.
Secondary Storage: Stores data for long-term access; examples include USB drives, hard disks, and cloud storage services.
Input Devices: Facilitate data entry and user interaction with systems (e.g., barcode scanners, keyboards, and mice).
Output Devices: Present processed data to users in a usable format (e.g., monitors, printers, and speakers).
Control Units: Manage input/output operations and coordinate the execution of various processing tasks to ensure smooth operation across all components.
Processing and Data Structures
Processing Steps: In-depth processing steps include input, data capturing, batch preparation, data entry, processing, validations, calculations, comparisons, summarizations, and inquiries to ensure accurate and timely reporting.
Data Structure Hierarchy: Character → Field → Record → File → Database, highlighting the organization and relationships between different data types.
File Types: Understanding of master files (containing stable, long-term information) and transaction files (holding dynamic, frequently changing data) is crucial for managing and auditing data effectively.
Input and Processing Methods
Batch Input: Accumulates transactions and processes them periodically, enhancing auditability due to the presence of tangible supporting documents.
On-line Input with Batch Processing: Allows for immediate data entry but employs periodic system updates, raising concerns over segregation of duties and potential control weaknesses.
On-line Input/Real-time Processing: Involves immediate transaction processing, which benefits from instant validation but poses risks due to fewer safeguards and potential for unchecked errors or fraud.
Distributed Data Processing
Organization of data processing across different locations and users. This includes Local Area Networks (LAN) for small geographic areas and Wide Area Networks (WAN) for larger distances, affecting how data integrity and security are managed.
Effects of ICT on Internal Control Systems
Reduced Segregation of Duties: Centralization of activities within ICT systems can lead to increased risks of fraud and errors, as fewer individuals monitor operations.
Less Documentation: The elimination of traditional paper trails in favor of digital records can complicate audits if systems lack robust tracking and logging.
Reliance on Program Accuracy: Errors can be consistently repeated due to programmed operations, necessitating diligent routine testing and error-checking protocols.
Limited Human Oversight: Reduced roles and responsibilities can lead to unchecked automation risks, highlighting the importance of regular reviews of automated processes.
Next Steps
Upcoming session will cover general controls in ICT algorithms and their weaknesses along with corrective recommendations to enhance security and integrity. We will also delve into application control activities related to identifying risks and maintaining thorough audit trails, emphasizing their critical role in effective internal auditing.
Conclusion: Awareness of the ICT environment is critical for effective internal auditing. Familiarity with both manual and automated systems, along with the unique challenges they pose, prepares auditors to identify, assess, and recommend controls that fortify organizational operations against risks, ensuring compliance and integrity in financial reporting.
Subject: Information and Communications Technology (ICT)
Facilitators: Ms. M. Mogale, Ms. M. Mamabolo, Mr. T. Lebese
Level: Auditing 3A (IAA316D)
Learning Outcomes
Understand main changes in hardware, software, and audit approach in ICT, focusing on the transition from traditional to digital processing systems, which has involved a shift from manual methods reliant on paper documentation to fully automated processes powered by software applications and hardware systems.
Familiarize with main terminology and concepts in an ICT environment to effectively communicate and engage in audits; essential terms include network topologies, data privacy regulations, and system architectures.
Explain ICT's impact on control systems, detailing how technological advancements, such as cloud computing and big data analytics, influence the effectiveness and efficiency of internal controls, providing deeper insights into process automation and risk management.
Identify general controls in ICT, including physical controls (e.g., securing hardware and facilities), access controls (e.g., user authentication measures), and application controls (ensuring the accuracy and completeness of data input).
Assess weaknesses in general control activities and recommend improvements to mitigate risks associated with those weaknesses, which may involve implementing enhanced user training programs or adopting more robust technology solutions.
Describe application control activities: risks, preventive, detective, corrective controls, and audit trails for batch and online systems, with examples of each type of control to illustrate the importance of such measures in maintaining data integrity and confidentiality.
Gain knowledge in specific ICT environments and governance frameworks, such as COBIT and ITIL, to understand how they dictate best practices and compliance requirements in the realm of IT governance and service management.
Introduction to ICT
Reliance on ICT systems for processing and storage of information is pivotal in modern organizations due to the need for accuracy, speed, and efficiency in data handling. These systems support decision-making processes and enhance operational workflows across departments.
Definition of ICT: Integrated system of devices, networks, communication links, and data that facilitate electronic interaction in the digital world. This encompasses hardware (computers, servers, and networking equipment), software (applications, operating systems, and middleware), and networks (Local Area Networks (LAN), Wide Area Networks (WAN), and the internet).
Internal Audit Approach
Audit objectives remain unchanged; however, execution processes are influenced by the ICT environment, necessitating auditors to embrace technology in their methodologies. The digital transformation has led to the evolution of auditing methods to incorporate data analytics tools and continuous auditing practices. Auditors must adapt to the ever-evolving ICT landscape by staying updated on the latest technologies, trends, and threats in the cyber environment, enhancing their ability to perform risk assessments and audits effectively.
Manual vs ICT Systems
Manual Systems: Follow the accounting cycle manually, which allows for clear audit trails and detailed documentation that can be easily reviewed. However, they are vulnerable to risks such as data loss from natural disasters, human errors in data entry, and inefficiencies in processing that can lead to delayed reporting and decision-making.
ICT Systems: Enable fast processing of large data volumes with automation, resulting in faster decision-making processes and reduced operational costs. Although ICT systems bring benefits, they present challenges for tracking audit trails, as many transactions are automated and lack human oversight, which can lead to difficulties in identifying and mitigating errors or fraud. Risks include data manipulation, data loss, and system vulnerabilities due to malicious attacks or hacking attempts, necessitating robust cyber security measures tailored to the specific ICT environment.
Software Types
Application Software: Performs specific tasks tailored for user needs, such as word processing, spreadsheets, or databases (e.g., Microsoft Word, Excel, and Access). These applications often include additional functionalities such as collaborative tools and cloud storage integration.
System Software: Operating systems that manage computer hardware and allow application software to function efficiently (e.g., Windows, macOS, and Linux). These systems also include device drivers and utility software that maintain system performance and security.
Internal Audit Approaches in ICT
Auditing Around the Computer: Tracing source documents to computer outputs; ensures that audit trails exist by verifying the output against original source documentation and performing substantive testing to confirm data accuracy.
Auditing With the Computer: Utilizing ICT tools such as data analytics and automated reporting to conduct internal audit engagements more efficiently. This approach enables auditors to analyze large datasets for anomalies or trends that may indicate risks or irregularities.
Auditing Through the Computer: Testing the ICT system's consistency and accuracy using dummy data to simulate real transactions, ensuring that the system performs as expected under various conditions and loads, allowing auditors to evaluate system robustness and operational efficacy.
Internal Auditor's Knowledge and Skills
Understanding auditing concepts and risks associated with ICT systems, including risks specific to technology such as system failures, data breaches, and fraud. Familiarity with ICT components like hardware, software, data structures, and security protocols ensures that auditors can identify pertinent issues during audits