Welcome to the World of IT Auditing!
Hello there! Don't let the phrase "Computerised Systems" intimidate you. While it sounds like something only a tech genius would understand, for an auditor, it’s really just about understanding how a business uses technology to record its transactions. Since almost every business in Hong Kong—from a small tea house to a global bank—uses computers today, understanding this chapter is essential for your HKICPA QP journey.
In this chapter, we will explore how IT affects our audit planning, what can go wrong in a digital environment, and how we use tools to make our audit more efficient. Let’s dive in!
1. Why Does the IT Environment Matter to Auditors?
In the "old days," auditors looked at paper ledgers. Today, data is stored in the cloud or on servers. This changes how we audit, but not what we are looking for (which is always truth and fairness in the financial statements).
The Main Idea: If a company's computer system is unreliable, the financial data it produces is also likely to be unreliable. Therefore, we must assess the IT risks during our Audit Planning phase.
Common IT Risks to Watch Out For:
- Unauthorised access: Someone "hacking" in and changing numbers.
- Data loss: The system crashing without a backup (imagine losing all your study notes right before the exam!).
- System errors: A bug in the software calculating depreciation incorrectly for 10,000 assets at once.
- Lack of an audit trail: When transactions are deleted without leaving a "paper trail."
2. The "Two Pillars" of IT Controls
To keep things simple, auditors divide IT controls into two main buckets: General IT Controls (GITCs) and Application Controls. Understanding the difference is crucial for your exams!
A. General IT Controls (GITCs)
Think of GITCs as the "Umbrella" or the "Security Guard" at the front door of a building. They don't check specific transactions, but they ensure the entire environment is safe.
Key Areas of GITCs (Remember the mnemonic: "P.O.D.S."):
1. Program Changes: Ensuring only authorised and tested changes are made to the software.
2. Operations: Making sure the system runs smoothly and data is backed up daily.
3. Development: Ensuring new systems are bought or built correctly.
4. Security (Access): Using passwords and firewalls so only the right people can get in.
B. Application Controls
These are the "Specific Rules" built into a specific software program (like the Sales system or Payroll system). They ensure that the data entered is accurate and complete.
Example: A "Limit Check" that prevents an employee from entering a negative salary, or a "Date Check" that prevents a transaction date in the year 2099.Common Application Controls:
- Format Checks: Ensuring a phone number field only contains numbers, not letters.
- Range Checks: Ensuring a price is between $1 and $1,000.
- Check Digits: A mathematical formula to ensure account numbers are valid.
- Batch Totals: Adding up 50 invoices manually and comparing them to the system’s total to ensure none were missed.
Quick Review: If GITCs are weak (e.g., everyone knows the admin password), we cannot trust the Application Controls, even if they look good on paper!
3. Audit Approaches: Around vs. Through the Computer
When you are planning your audit approach, you have to decide how much you want to "touch" the computer system.
Approach 1: Auditing "Around" the Computer
This is like treating the computer as a "Black Box." You look at the Inputs (invoices) and the Outputs (financial reports) and see if they match. You don't really care how the computer processed them.
When to use: Only for very simple systems with lots of paper trails.
Approach 2: Auditing "Through" the Computer
This is where you "Open the Box." You test the actual logic inside the computer. This is necessary when the system is complex and there is no physical paper trail.
When to use: Most modern audits. This involves testing the controls we discussed above (GITCs and Application Controls).
4. CAATs: The Auditor’s Secret Weapons
CAATs stands for Computer-Assisted Audit Techniques. Don't worry if this seems tricky; just think of CAATs as "Auditor Software." There are two main types you need to know for the Associate Level:
Type 1: Audit Software
This is software the auditor uses to interrogate the client's data. It can perform tasks much faster than a human.
Example: Using software to scan 1,000,000 sales transactions and instantly picking out any transaction over $100,000 for testing.- What it does: Selecting samples, recalculating totals, identifying gaps in invoice numbers.
Type 2: Test Data
This is where the auditor "tricks" the client's system by entering fake data to see if the system catches the errors.
Example: The auditor enters an invoice with a date from 10 years ago. If the system accepts it, the control is weak. If the system rejects it with an error message, the control is strong.Common Mistake to Avoid: Students often confuse these two. Remember: Audit Software looks at Real Data. Test Data uses Fake Data to test the system's logic.
5. Impact on Audit Planning (The "Big Picture")
When you are planning your audit approach, the computerised system will influence three things:
1. Timing: You might need to perform tests throughout the year because digital data can be deleted or overwritten.
2. Staffing: You might need to bring in an IT Audit Specialist if the system is very complex (like an ERP system).
3. Risk Assessment: If IT controls are strong, you can reduce Control Risk and do less "manual" testing of balances at year-end.
Summary Checklist for Success
Before moving on, make sure you can answer these:
- Can I explain the difference between a GITC and an Application Control? (Hint: Umbrella vs. Specific Rule).
- Do I know the difference between Audit Software and Test Data?
- Why do I care about IT controls during the Planning stage? (Hint: It affects our risk assessment).
Key Takeaway: In a computerised audit, we don't just check the numbers; we check the system that creates the numbers. If the system is safe (GITC) and follows the rules (Application Controls), our job as auditors becomes much more efficient!