ITA 100 Flashcards
(248 cards)
What is the primary focus of an IT audit?
An IT audit primarily focuses on examining the management controls within an Information Technology (IT) infrastructure and business applications.
How is an IT audit different from a financial audit?
An IT audit differs from a financial audit in terms of its purpose. While a financial audit evaluates whether financial statements present an entity’s financial position accurately, an IT audit assesses the internal control design and effectiveness of IT systems.
What are the objectives of an IT audit?
The objectives of an IT audit include determining if information systems safeguard assets, maintain data integrity, and operate effectively to achieve an organization’s goals.
What are some alternative names for IT audits?
IT audits are also known as automated data processing audits (ADP audits) and computer audits. They were formerly called electronic data processing audits (EDP audits).
In what context may IT audits be performed?
IT audits may be performed in conjunction with a financial statement audit, internal audit, or other forms of attestation engagement.
What does the evaluation of evidence in an IT audit entail?
The evaluation of evidence in an IT audit determines whether information systems are meeting the goals of safeguarding assets, maintaining data integrity, and operating effectively.
What aspects does an IT audit assess in terms of internal control?
An IT audit assesses internal control design and effectiveness, including efficiency and security protocols, development processes, and IT governance or oversight.
Why are controls considered necessary but not sufficient for adequate security in IT audits?
Installing controls is deemed necessary but not sufficient for adequate security in IT audits because the overall effectiveness of security measures requires comprehensive evaluation beyond just the presence of controls.
How does the purpose of an IT audit align with organizational goals?
The purpose of an IT audit aligns with organizational goals by ensuring that information systems operate effectively to achieve the organization’s objectives.
Why do IT auditors become involved in a financial auditing process?
IT auditors get involved in a financial auditing process for several reasons, including assisting the financial audit team in understanding transaction flow, identifying relevant IT systems for financial reporting, and supporting the identification of risk points in business processes.
How do IT auditors contribute to the identification of risk points within a business’s processes?
IT auditors contribute to the identification of risk points by evaluating the design and implementation of GITCs and automated controls.
What do IT auditors do to assess the operating effectiveness of controls during a financial auditing process?
IT auditors test the operating effectiveness of both GITCs and automated controls that have been identified as relevant to the audit.
How do IT auditors support the financial audit team in financial reporting?
IT auditors assist in identifying which of the entity’s IT systems are relevant to financial reporting, ensuring a comprehensive understanding of the financial processes.
What is the significance of obtaining an understanding of the entity’s processes in IT audit?
Obtaining an understanding of the entity’s processes in IT audit is crucial for identifying risks and automated controls associated with those processes.
How does IT audit address financial statement risks related to IT?
IT audit addresses financial statement risks related to IT by identifying and assessing both financial statement level risks and assertion level risks, including those associated with fraud risks resulting from the use of IT.
How does IT audit determine the controls to test in the financial audit process?
IT audit determines the controls to test by identifying relevant IT applications for each process, including automated controls intended for reliance, and designing effective and efficient strategies for control testing.
What is the importance of identifying GITCs in IT audit?
Identifying GITCs is important in IT audit as they support the consistent operation of automated controls.
How does IT audit apply computer-assisted audit techniques (CAATs)?
IT audit applies CAATs by designing and/or using them to enhance the audit process.
What is the focus of testing reports in IT audit?
The focus of testing reports in IT audit includes controls or direct testing procedures related to the accuracy and completeness of relevant data elements.
Why is the testing of automated controls emphasized in IT audit?
Testing the design, implementation, and operating effectiveness of relevant automated controls is emphasized in IT audit to ensure their reliability and compliance with financial audit objectives.
Is IT audit involved for entities audited under PCAOB standards?
Yes, IT audit is involved for entities audited under PCAOB standards.
Does IT audit participate in integrated audits according to AU-C 940?
Yes, IT audit is involved in integrated audits when entities request audits in accordance with AU-C 940.
Are all other entities, including employee benefit plans and not-for-profit organizations, subject to IT audit?
Yes, all other entities, including employee benefit plans and not-for-profit organizations, are subject to IT audit.
Under what circumstances does IT audit get involved for other entities?
IT audit gets involved for other entities, such as employee benefit plans and not-for-profit organizations, when the entity is highly dependent on IT processes. Additionally, IT audit is required when planning to rely on the operating effectiveness of automated controls to respond to a significant risk.