Welcome to the World of Computerised Business Systems!

Hello there! Today, we are diving into a crucial part of the HKICPA QP Business Assurance curriculum: Computerised Business Systems. If you feel a bit intimidated by "IT stuff," don't worry—you are not alone! Many students find this chapter technical, but at its heart, it’s just about how businesses use technology to process financial data and how we, as auditors, make sure that technology doesn't "lie" to us. Think of it as auditing the "digital brain" of a company.

1. The IT Environment: Why Do We Care?

In the old days, auditors looked at paper ledgers. Today, almost every transaction is recorded, processed, and stored electronically. Because the IT environment is where the numbers live, if the system is weak, the financial statements might be wrong.

Quick Review: Why IT matters in Audit:

1. Speed and Volume: Systems handle millions of transactions that humans couldn't possibly check manually.
2. Consistency: Computers do exactly what they are told. If the logic is right, it's always right. If the logic is wrong, it's consistently wrong.
3. Risk of Data Loss: Digital files can be deleted or altered without leaving a physical "paper trail" unless proper controls are in place.

2. The Two Pillars: ITGC vs. Application Controls

This is the most important distinction in the chapter. Imagine a high-security bank vault. IT General Controls (ITGC) are the security guards at the front door and the cameras in the hallway. Application Controls are the specific locks and codes on the individual safety deposit boxes inside.

A. IT General Controls (ITGC)

These are controls that apply to all systems. They ensure the whole IT department is running reliably. We usually categorize them into four areas (use the mnemonic "A.C.D.O" to remember them!):

1. Access to Programs and Data: Who can get in? This includes passwords, multi-factor authentication (MFA), and removing access for employees who quit.
2. Change Management: Who is changing the code? You don't want a programmer to change the system so that all "cents" in a transaction go to their private bank account! Changes must be tested and authorized.
3. Development of Systems: How was the system built? Ensuring new software is bought or built properly and works as intended before it goes "live."
4. Operations: Is the "engine" running? This includes daily backups, disaster recovery plans, and monitoring for system crashes.

B. Application Controls

These are specific to one software (like the payroll system or the sales system). They focus on the integrity of the data being entered and processed.

Example: When you try to buy a flight and enter "32" as the day of the month, the website stops you. That is an Application Control (specifically, a Range Check).

Common Application Controls:
- Limit/Range Check: Only allows numbers within a certain range (e.g., no negative salaries).
- Existence/Validity Check: Ensures the customer ID actually exists in the database.
- Batch Totals: If you enter 50 invoices, the system adds up the total value to make sure nothing was missed during data entry.

Key Takeaway: If ITGCs are weak (e.g., anyone can guess the admin password), we cannot trust the Application Controls because someone could have just gone into the "back end" and changed the rules.

3. Evaluating IT Risks

When we "Evaluate and Advise," we are looking for things that could go wrong. Here are some classic IT risks:

- Unauthorized Access: Hackers or disgruntled employees stealing or changing data.
- System Failure: If the server crashes and there is no backup, the company loses its accounting records.
- Interface Failures: When the sales system doesn't "talk" correctly to the accounting system, and data gets garbled in transit.

Did you know? Some of the biggest financial frauds in history didn't involve stealing cash—they involved someone with "Superuser" access changing the digital records to hide losses!

4. Auditing "Around" vs. "Through" the Computer

Don't worry if this seems tricky at first—it's just a fancy way of saying "how much do we look at the software?"

1. Auditing Around the Computer: You look at the Inputs (invoices) and the Outputs (financial reports) and see if they match. You treat the computer like a "Black Box" and ignore what's happening inside. This is only okay for very simple systems.
2. Auditing Through the Computer: You actually test the system's logic. You check the ITGCs and the Application Controls. In the modern HKICPA environment, this is usually the required approach because systems are too complex to ignore.

5. Working with Service Organizations (Outsourcing)

Many Hong Kong companies use "The Cloud" (like AWS or Microsoft Azure) or outsource their payroll to a third party. This creates a problem: How do we audit a system that isn't even in the client's office?

We look for Service Auditor Reports (based on HKSA 402):
- Type 1 Report: Describes the system and tells us if the controls are designed properly at a specific date.
- Type 2 Report: Much better! It tells us if the controls were actually operating effectively over a period of time.

Exam Tip: If a case study mentions the client uses a third-party data center, always check if the auditor has obtained a Type 2 Report!

6. Summary and Quick Review

Key Terms to Remember:
- General Controls (ITGC): The "Umbrella" (Access, Change, Ops).
- Application Controls: The "Specifics" (Input, Process, Output).
- CAATs (Computer Assisted Audit Techniques): Using software to perform the audit (e.g., using Excel or specialized audit tools to re-calculate depreciation for 10,000 assets at once).
- Segregation of Duties (SoD): Ensuring the person who writes the code isn't the same person who uses the code to process payments.

Common Mistakes to Avoid:
- Mistake: Thinking that if the ITGCs are good, we don't need to test transactions. Correction: We still need to do some substantive testing, but we can do less if controls are strong.
- Mistake: Confusing a password (ITGC) with a limit check (Application Control). Remember: ITGC is about the environment; Application is about the data entry.

Key Takeaway Checklist:

- [ ] Do I understand the difference between ITGC and Application Controls?
- [ ] Can I name 3 risks of a computerized system?
- [ ] Do I know why a Type 2 SOC report is better than a Type 1?
- [ ] Can I explain why "Auditing Through the Computer" is the modern standard?

Great job! You've just simplified one of the most technical chapters in the Business Assurance module. Keep going—you've got this!