CISA · Domain 1
Information Systems Auditing Process
About 18% of the exam
Audit charter and mandate
- Charter grants authority, scope, responsibility
- Approved by audit committee or board
- Engagement letter covers one specific audit
- Audit function reports to the audit committee
- Independence: organizational and individual
- Disclose conflicts before the engagement starts
- Prior operational role can impair independence
Charter is permanent and organization-wide; the engagement letter is one audit at a time
ISACA standards and ethics
- Standards
- mandatory requirements for auditors
- Guidelines
- help apply the standards
- Tools and techniques
- examples, procedures, not mandatory
- Code of ethics
- binding on every member
- Due professional care
- diligence a prudent auditor shows
- Professional skepticism
- question, corroborate, never assume
- Quality assurance review
- external assessment every five years
Risk-based audit planning
- Annual plan built on a risk assessment
- Highest risk areas are audited first
- Understand the business before the systems
- Consider regulatory change, volume, complexity
- Scoring model for many diverse entities
- Plan is reviewed as risk shifts
- Auditee cannot dictate scope exclusions
Audit risk model
- Inherent risk
- exposure before any controls
- Control risk
- controls fail to prevent or detect
- Detection risk
- auditor procedures miss the error
- Audit risk
- wrong opinion on the whole
- Materiality
- size that changes a decision
- Sampling risk
- sample misrepresents the population
Inherent and control risk belong to the auditee; only detection risk is the auditor's lever
The audit engagement
- Plan
- Fieldwork
- Evaluate
- Report
- Follow up
- Planning
- objectives, scope, criteria, resources
- Fieldwork
- gather evidence, test controls
- Evaluation
- weigh findings against criteria
- Reporting
- findings, impact, recommendations, opinion
- Follow up
- confirm management remediated
- Workpapers
- support every conclusion reached
Scope can widen when a control gap is found; it never narrows just because the auditee asks
Control types
- Preventive
- stop the error before it happens
- Detective
- find it after it happens
- Corrective
- fix it and restore
- Compensating
- covers for a control that is missing
- General controls
- environment shared by all systems
- Application controls
- specific to one business process
Weak general controls undermine reliance on every application control above them
Compliance vs substantive
- Compliance test
- is the control operating
- Substantive test
- is the data actually correct
- Test of one
- enough for an automated control
- Strong controls
- less substantive work needed
- Weak controls
- extend substantive procedures
- Reperformance
- auditor redoes the process
Test controls first; the outcome decides how much substantive testing follows
Sampling
Approach
- Statistical
- random, quantifies sampling risk
- Judgmental
- auditor picks, cannot extrapolate
- Stratified
- split population, sample each layer
Purpose
- Attribute
- rate of occurrence, yes or no
- Variable
- dollar or quantity estimates
- Stop or go
- few errors expected, stop early
- Discovery
- hunting one instance of fraud
Attribute sampling tests controls; variable sampling tests balances. Sample size grows with expected error and confidence
Evidence
- Sufficient, reliable, relevant, useful
- External confirmation beats internal documents
- Auditor-generated beats auditee-provided
- Direct observation beats interview
- Original documents beat photocopies
- Corroborate oral statements with records
- Test the control, do not just read it
- Absence of exceptions can itself be suspicious
Most reliable: independent third party. Least reliable: an unsupported statement from the auditee
CAATs and data analytics
- Test 100% of transactions, not a sample
- Verify source data integrity first
- Generalized audit software, embedded modules
- Test data: dummy transactions, live logic
- Integrated test facility: fictitious entity
- Parallel simulation reruns the logic
- Duplicate payment matching with fuzzy logic
- Document the tool, version and parameters
Reporting and follow up
- Lead with business impact and risk
- Aggregate small weaknesses that combine
- Agree facts with management before issue
- Auditor recommends, management owns the fix
- Report regulatory exposure to audit committee
- Accepted risk is still documented
- Follow up confirms remediation actually happened
CSA and continuous auditing
- Control self-assessment
- process owners rate their controls
- CSA benefit
- ownership, early detection, awareness
- CSA limit
- does not replace independent audit
- Continuous auditing
- audit function, gives assurance
- Continuous monitoring
- management function, runs controls
- Integrated audit
- financial and IS scope together
- Agile audit
- checkpoints inside the CI/CD pipeline
Key formulas
- Audit risk
- inherent x control x detection
- Lower detection risk
- more substantive testing
- Sample size up
- confidence up, tolerable error down
- Precision
- acceptable range around the estimate
- Confidence level
- certainty the sample is right
- Expected error
- estimated before sizing the sample
High inherent, medium control: push detection risk low with extensive substantive work
Know the order
- Charter
- Risk assessment
- Annual plan
- Engagement letter
- Fieldwork
- Report
- Follow up
- Evidence: confirm, observe, inspect, inquire
- Testing: compliance first, then substantive
- Forensics: image, hash, chain of custody
- Independence: disclose, assess, recuse
Reference strip: standards, controls, sampling, evidence, reports
ISACA framework
- IS Audit and Assurance Standards, mandatory
- Guidelines interpret the standards
- ITAF ties them together
- Code of Professional Ethics
- COBIT as the control criteria
Control classification
- Preventive, detective, corrective, compensating
- Manual, automated, IT dependent manual
- General controls vs application controls
- Key control vs secondary control
Sampling types
- Statistical: random, systematic, stratified
- Judgmental: haphazard, block
- Attribute for controls, variable for values
- Stop or go, discovery for fraud
Evidence hierarchy
- External confirmation, auditor reperformance
- Direct observation, system extraction
- Internal documents, screenshots
- Auditee interview, lowest weight
Report elements
- Scope, objectives, period, methodology
- Finding: condition, criteria, cause, effect
- Recommendation and management response
- Overall opinion, restrictions on use
- Follow up date and owner
Quick exam traps
- Trap: The engagement letter grants the audit function its authority
- Trap: The auditor can lower inherent risk by testing more
- Trap: Judgmental sampling results can be projected to the population
- Trap: A signed management statement is the strongest evidence
- Trap: Twelve clean months of an automated control removes all substantive testing
- Trap: Continuous monitoring is performed by the audit function
- Trap: The auditor is responsible for implementing the recommendations
- Trap: Excluding a system at the auditee's request is a scope decision for the auditee
cybercertprep.com · original revision sheet written from the public body of knowledge