IT Audit and Data Analytics in Auditing
Controls
IT Audit and Data Analytics in Auditing
Syllabus tag: KASNEB CPA | Advanced Level | CA36 Advanced Auditing and Assurance
1. Why IT audit matters
Financial statements are produced by IT systems. Controls over IT directly affect the reliability of financial reporting. Key IT risks: unauthorised access to data, loss of data integrity through system errors, business disruption from system failure, and complex electronic audit trails.
2. IT general controls (GITCs)
GITCs create the environment within which application controls operate: access controls (user authentication, multi-factor authentication, least-privilege management, physical security of servers, access logging); change management (formal procedures for requesting, testing, approving, and implementing system changes); operations (backup and recovery, job scheduling, incident management); system development (controls over acquisition and development of new systems).
3. IT application controls
Embedded in specific applications: input controls (validation rules — range checks, format checks, completeness checks; batch totals); processing controls (sequence checks, edit checks, run-to-run totals); output controls (exception report review, comparison of outputs to expected results). Application controls are only reliable if the underlying GITCs are effective.
4. Computer-assisted audit techniques (CAATs)
Audit software interrogates the entity's data: selecting samples, stratifying populations, performing recalculations, identifying duplicate or missing sequences in invoices or cheques, sorting, and summarising. Tools include ACL, IDEA, and Excel-based CAATs. Test data involves entering fictitious transactions into the client's system to verify that controls operate as expected.
5. Data analytics in auditing
Advanced analytics enables: testing 100% of the population (identifying all transactions above a threshold, all duplicate payments, all journal entries posted outside business hours); anomaly detection to flag unusual transactions; predictive modelling to identify accounts behaving differently from expectations; and dashboard visualisation to communicate findings to those charged with governance.
6. Cybersecurity
The auditor considers cybersecurity risk as a business risk that may cause material misstatements (data breach liabilities, regulatory fines). The auditor assesses whether financial statement disclosures about cybersecurity risks are adequate and consistent with evidence gathered — but is not required to assess whether the entity's cybersecurity controls represent best practice.
