Example: barber

External ITGC Audits – An Internal Auditor’s …

External itgc Audits AnInternal Auditor s Opportunity These slides are incomplete without the benefit of the commentsmade at the session. Theinformation and considerations presented herein do not constitute legal or any other type ofprofessional 2, 2009 Presented to: The Dallas Chapter of the Institute of Internal AuditorsPage2 PricewaterhouseCoopersExternal itgc Audits An Internal Auditor s OpportunityToday s Agenda Brief Overview of ITGCs Impact on Application Controls and System Generated Data Linkage to the Financial Audit Internal Audit Involvement in the itgc Audit Life Cycle Additional Opportunities Final ThoughtsPage3 PricewaterhouseCoopersExternal itgc Audits An Internal Auditor s OpportunityQuestions to contemplate Have I contemplated Internal Audit s role in driving efficiencies in the External itgc audit?

PricewaterhouseCoopers Page 3 External ITGC Audits – An Internal Auditor’s Opportunity Questions to contemplate Have I contemplated Internal Audit’s role in driving efficiencies in the external ITGC

Tags:

  Roles, Auditors, Itgc

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Transcription of External ITGC Audits – An Internal Auditor’s …

1 External itgc Audits AnInternal Auditor s Opportunity These slides are incomplete without the benefit of the commentsmade at the session. Theinformation and considerations presented herein do not constitute legal or any other type ofprofessional 2, 2009 Presented to: The Dallas Chapter of the Institute of Internal AuditorsPage2 PricewaterhouseCoopersExternal itgc Audits An Internal Auditor s OpportunityToday s Agenda Brief Overview of ITGCs Impact on Application Controls and System Generated Data Linkage to the Financial Audit Internal Audit Involvement in the itgc Audit Life Cycle Additional Opportunities Final ThoughtsPage3 PricewaterhouseCoopersExternal itgc Audits An Internal Auditor s OpportunityQuestions to contemplate Have I contemplated Internal Audit s role in driving efficiencies in the External itgc audit?

2 Does the External auditor s itgc budget seem high given the amount of workrequired? Am I doing everything I can to ensure the External auditors perform an efficient andeffective itgc audit? Have I been consistently interfacing with the External auditorsduring the planning,fieldwork and wrap up phases of the itgc audit? Do the External auditors realize the maximum amount of relianceon my work? If not,what needs to happen to achieve maximum reliance? What else can I do to drive an efficient and effective itgc audit?Brief Overview of ITGCsPage5 PricewaterhouseCoopersExternal itgc Audits An Internal Auditor s OpportunityEntity Level Controls Over IT Relate to the softer COSO components ELCs should reflect how management approaches information technology needs and shouldserve to promote ongoing effectiveness of ITGCs Examples include: IT Policies Employee training Communication Adequacy of IT Team External Audit will assess the overall tone at the top to decideif the nature or extent ofprocedures should be modified.

3 When past Audits have indicated deficiencies in the control environment or relevant ITGCs andremediation efforts have been insufficient, the audit plan willbe developed in consideration ofthe potential inability to rely on impacted automated over IT Set the Tone for controls in the itgc Audits An Internal Auditor s OpportunityITGCs- What s Relevant for Testing Access to programs and data Program changes Program development Computer operationsBoth of these domains are almost alwaysrelevant, but their complexity and the extentof audit evidence needed can vary greatlyby only if needed to directly address assertions oversignificant accounts (more common in high transactionvolume industries with complex systems, such as banking)

4 Or to address specific only where new system implementations willimpact ICFR and the risk of material generally not required if no impact on currentyear financial statements and auditors will generallyconsiderrisks in each ofthese areas, even if little or no testing is itgc Audits An Internal Auditor s OpportunityITGCs- Access to Programs and Data Areas for consideration: Importance of restricted access to: Segregation of duties objectives Fraud risk Risk of inadvertent errors Company s approach to application security and the securityinfrastructure Access (user and administrative)

5 At the application, operating systemand database levels It is usually not necessary to test perimeter security and anti-hackingcontrols, such as firewalls and intrusion detection systems, unless materialfinancial reporting risks exist that are not adequately addressed byapplication-level security closer you get to financial data, the greater the risk tomaterial itgc Audits An Internal Auditor s OpportunityDBAPPOSINFI nfrastructure (INF)Operating System (OS)Application (APP)Database (DB)Increasing Level of RiskLayers of the Application Architecture and their Relative RiskPage9 PricewaterhouseCoopersExternal itgc Audits An Internal Auditor s OpportunityITGCs- Program Changes Areas for consideration.

6 In house developed versus third party application Ownership of source code Volume / frequency of changes Complexity of changes Ownership of changes to key reports (business versus IT) Where accountability sits in the organization for identifying changesimpacting ICFR Degree of finance and IT interactionForms the basis for relying on the ongoing operatingeffectiveness of application controlsPage10 PricewaterhouseCoopersExternal itgc Audits An Internal Auditor s OpportunityITGCs- Program Development Areas for consideration: Methodology for implementing projects Business involvement and buy-in on requirements and design Contemplation of Internal Controls in design phase Nature and extent of quality assurance (unit, regression, integrationtesting) Accuracy and completeness of converted data Go-live approvalsNot required to be tested unless there are specific dataconversions or system implementations that impact the riskof material misstatementPage11 PricewaterhouseCoopersExternal itgc Audits An Internal Auditor s OpportunityITGCs Computer Operations Areas for consideration.

7 Job maintenance and monitoring (specific to financial jobs) Backup and recovery procedures (in an unstable environment) Operating system patch maintenance Anti-virus controls Environmental controls Computer Operations controls, otherwise not included in scope for thefinancial audit, are sometimes included in scope for the purposes of astatutory present operational risk, not ICFR risk, depending onthe specific circumstancesImpact on Application Controls includingSystem Generated DataPage13 PricewaterhouseCoopersExternal itgc Audits An Internal Auditor s OpportunityApplication Control vs.

8 An IT General Control? itgc Scoping ITGCs-Activities that ensure thecontinuedeffective operation of applicationcontrols, automated accountingprocedures that depend on computerprocesses and manual controls thatuse application-generated information /reports-Some ITGCs may also serve asApplication Controls, passwordcontrols-ITGCs are pervasive, and thereforeoften do not directly support financialstatement assertions Application controls-Think in terms of does this directlyrelate to the input, processing oroutput of financial transactions -Directly support CAVR(Completeness, Accuracy.)

9 Validity andRestricted Access), therebycontributing to comfort over financialstatement assertionsPage14 PricewaterhouseCoopersExternal itgc Audits An Internal Auditor s OpportunityApplication controls Programmed or configured automated controls Reports or data generated from the system and used in manual controls oraccounting procedures Automated calculations or data processing routines programmed into theapplication Restricted access to transaction processing capabilities Restricted access to programs and data ITGCs that directly address relevant financial statement assertionsPage15

10 PricewaterhouseCoopersExternal itgc Audits An Internal Auditor s OpportunityAutomated Controls- Baselining ApproachThe ability to rely on the proper and consistent operation ofapplication controls usually depends on the effectiveoperation of related ITGCs. A baseline test provides evidence that an automated control is functioningas intendedat a point in time. ITGCs support a baselining approach: If ITGCs are effective and continue to be tested AND an automatedcontrol hasn t changed since the last time it was tested We can conclude the automated control continues to be itgc Audits An Internal Auditor s OpportunitySystem Generated DataThe ability to rely on the proper and consistent operation ofapplication controls usually depends on the effectiveoperation of related ITGCs.


Related search queries