Computer Assisted Audit Tools (CAAT)
Computer Assisted Audit Tools (CAAT)
Computer Assisted Audit Tools (CAAT)
Introduction
? ?
?
Management
Stakeholders
Information Risk
6
The IT Audit
The IT audit function encompasses
Careers in Information Systems
Auditing
people skills
to work as a team
to interact with clients and other auditors,
to interview many people constantly for evaluation
can’t just be a technical nerd!
Careers in Information Systems
Auditing
CPTR
Auditing around the computer
Compares output with input; assumes that accurate
output verifies proper processing operations
pays little or no attention to the control
procedures within the IT environment
is generally not an effective approach to
auditing in a computerized environment.
Auditing Computerized AIS-
Auditing Through the Computer
CPTR
Test data (or test deck, named from punch card days)
can check if program edit test controls are in place and
working
can be developed using software
programs called test data generators
But may contaminate real data with fake data
Testing Computer Programs -
Integrated Test Facility
CPTR
An integrated test facility (ITF)
establishes a fictitious entity such as a
department, branch, customer, or employee,
enters transactions for that entity, and
observes how these transactions are processed.
is effective in evaluating integrated online
systems and complex programming logic, and
aims to audit an AIS in an operational setting.
May contaminate real data with fake data.
Testing Computer Programs -
Parallel Simulation CPTR
2. program comparison
guards against unauthorized program tampering
performs certain control total tests of program
authenticity
using a test of length
using a comparison program
Review of Systems Software
Data Validation: On the top menu of Excel, go to Data and then under the Data
Tools section, go to Data Validation. Use the validation tool to verify data as it
is being entered. For example, highlight the payrate range and set the data
validation decimal feature between $7.50 and $40.00. From this point on, any
data entered in the payrate range that does not fall between these two values
will be flagged.
Benford’s Law
Physicist Frank Benford figured out the probability that
certain digits form part of financial numbers. For example,
the numeral 1 should occur as the first digit in any multiple-
digit number about 31% of the time, while 9 should occur
as the first digit only 5% of the time. As you can see below,
the numbers in digit 1,2,5,6 & 7 are suspicious.
The Sarbanes-Oxley Act of 2002
Webtrust