Premium Essay

Auditing It Governance

In:

Submitted By 116278
Words 10762
Pages 44
Global Technology Audit Guide

Auditing IT
Governance

Global Technology Audit Guide (GTAG®) 17
Auditing IT Governance

July 2012

GTAG — Table of Contents
Executive Summary......................................................................................................................................... 1
1. Introduction................................................................................................................................................ 2
2. IT Governance Risks................................................................................................................................... 7
3. Aligning the Organization and IT — Key Considerations................................................................ 12
4. The Role of Internal Audit in IT Governance............................................................................ 15
Conclusion....................................................................................................................................................... 18
Authors and Reviewers.............................................................................................................................. 18
Appendix — IT Governance Risk Assessment/Engagement Planning Considerations............................................. 19

iv

GTAG — Executive Summary
Executive Summary

To support the heightened importance of IT governance and the mandatory nature of the International Standards for the Professional Practice of Internal Auditing (Standards), this
GTAG provides internal auditors with the foundational knowledge necessary to fulfill their responsibilities in providing both assurance and consulting services, applicable in the public and private sector. Some of the key areas of IT governance internal auditors should address are:

As defined by The Institute of Internal Auditors’ (IIA’s)

Similar Documents

Premium Essay

Corporate Governance and Auditing

...Corporate governance and Auditing Introduction Corporate governance is a method that the proprietors and financial providers of a business exercises power and necessitate accountability for the assets that is trusted to the business. The proprietors choose a board of directors to be responsible for overseeing the business’s actions and accountability to interested parties. Many parties have a stake in the quality of an organization’s corporate governance. In this assignment, I will discuss two principles that surround corporate governance and how they tie into the recent legislation that was introduced to resolve ethical difficulties and changes. The three main parts of an audit will also be described, as well as the role of the audit committee. The oversight and primary responsibilities of the audit committee will be compared and contrasted. I will also attempt to explain the impact on the auditing profession by Sarbanes-Oxley Act. Two Principles Proprietors want disclosures from organization that are correct and empirically provable. Management has the responsibility to provide financial reports in certain incidences on internal control effectiveness. Management always have the key obligation for the correctness and comprehensiveness of an business’s financial statements. They must select which accounting principles best represent the economic material of the business transactions. Management also have the obligation to apply a system of internal control that reassures...

Words: 1926 - Pages: 8

Free Essay

Zara Corporate Governance & Internal Auditing

...LES 1. Praktijkopdracht 2. Corporate governance & internal auditing Corporate Governance wordt uitvoerig besproken in het jaarverslag van 2012 van Inditex. ZARA is onderdeel van deze organisatie. Zo kent de Inditex Groep een ‘duurzaamheidsstrategie’. ZARA streeft naar het bevorderen van duurzame ontwikkeling in de samenleving en omgeving en heeft deze aspecten dan ook in haar bedrijfsmodel geïntegreerd. Interne auditafdeling Audit & Control Committee In onderstaand figuur is de plaats van de interne audit te zien in de organisatie van Inditex, waar ZARA onderdeel van uitmaakt. ZARA kent een Audit and Control Committee die de auditafdeling aanstuurt. Deze committee bestaat uit een voorzitter, secretaris en 5 bestuursleden. De hoofdactiviteiten van de audit & control committee zijn als volgt weergeven: * Periodieke financiële informatie, jaarrekening en accountantsverklaring De audit & control committee herziet de financiele en economische informatie, voorafgaande aan de goedkeuring door het Raad van Bestuur. Hiermee overlegt zij met het managementteam en de externe accountant. * Efficiëntie en onafhankelijkheid van de accountants * Interne & externe audit De directeur van de interne (en externe) auditafdeling zijn aanwezig bij de vergaderingen die de Audit & Control Committee houdt. In deze vergaderingen dient het committee naar behoren geinformeerd te worden door de interne auditafdeling. De audit en control committee overziet...

Words: 1187 - Pages: 5

Free Essay

Role of Auditors

...the role of the ethics in the auditing profession which basically is integrity and objectivity for the auditors. This essay addresses dimension of the ethics in the profession of auditing main demands for them in the profession is to assess the integrity and the ethical value of their customers or clients. This is indeed very difficult task for the auditors in practice and demands a deep and robust understanding the value of ethics, ethical infrastructure with their products. According to roger D, martin auditors face ethics issues from two perspectives among which one is well known and other being known and appreciated by the people who are familiar with auditors knowing their work and responsibility. The prospective of this is to deal among the ethical foundation of the auditing profession and to show the integrity and get appreciated with the job they do. This indicates ethics prospective as seeking within their profession on how to manage and achieve their targets with no difficulty. The other prospective, which the auditors face, is to understand and get the solution for the current and new clients. This is generally referred as an assessment, which demands a complete attention and understanding of ethics, ethical infrastructure and the solution of that infrastructure. This essay will give a complete picture on why ethics is important to the auditors and how significant is the contribution of auditors is to the effective corporate governance of large Uk companies. According...

Words: 1470 - Pages: 6

Premium Essay

Pengauditan Sistem Informasi

...INFORMATION SYSTEMS AUDITING Haryono, MCom, Ak 1 Why study Information Systems and Information Technology? • Vital component of successful businesses • Helps businesses expand and compete • Businesses use IS and IT: To improve efficiency and effectiveness of business processes For managerial decision making For workgroup collaboration  IS and IT change the business process dramatically 2 IT Inside Organization 3 SIMASTERGAMA Case study: UGM UNIVERSITY ENTERPRISE SYSTEM Informasi untuk Eksekutif (Rektor, Wakil REktor, Direktur) Informasi untuk Manajer (Ka Adm, Kabag/Kasi) Academics MO DUL /AP LIK AS HR Payroll Library Accounting Informasi untuk Operasional (Front Office) I dll. Fakultas Biologi Fakultas Ekonomika dan Bisnis Fakultas ISIPOL Fakultas Farmasi Fakultas Kedokteran Fakultas Pertanian TAS KUL FA Transition of IS Governance Poor IS Governance Good IS Governance 5 Need for Audit of Information Systems 6 Information System Auditing “IS Auditing is the process of collecting and evaluating evidence to determine whether a computer system safeguards assets, maintains data integrity, allows organizational goals to be achieved effectively, and uses resources efficiently” (Weber, 1999) 7 Objectives of IS Auditing Evaluate and Improved of… asset safeguarding system efficiency IS Auditing system effectiveness data integrity 8 Information Technology Auditing IT audits: provide...

Words: 647 - Pages: 3

Premium Essay

Earning Management

...Academic Year: 2014/15 Module code: P13505, Level 3 Autumn Semester Module Outline: Auditing, Governance and Scandals (AGS) |Module Convenor |Dr. Kevin Dow, AB474 | |Lectures |Dr. Kevin Dow | | |TH 4:00-5:30, TB 329 | |Additional Staff |Cass Lai, AB247 | |E-mail addresses |kevin.dow@nottingham.edu.cn | | |cass.lai@nottingham.edu.cn | |Office Hours |Dr. Kevin Dow: Th, 2:00 pm - 4:00 pm, every Thursday until Exams (except December 11 and 25) | | |Cass Lai: Th, 2:00 pm - 4:00 pm | KEY POINTS • This is a Level 3, 10 credit module; • Assessment basis: a one and a half hour Examination (100%); • Keywords: Audit; Governance; Corporate Scandals; Audit Theory and Practice; Accountability; • Pre-requisite module: P12307 Financial Reporting. MODULE AIMS To use a mix of textual and...

Words: 1810 - Pages: 8

Premium Essay

Corporate Governance

...CORPORATE GOVERNANCE 1 CORPORATE GOVERNANCE We can attribute societies demand for improved corporate governance on the number of recent financial scandals that have occurred in both the United States and abroad in the past decade. For many organizations, the way to rebuild shareholder confidence was to implement a fundamental framework of procedures that would ensure scandals like Enron, WorldCom and Tyco would not occur in the future. It is precisely these scandals that made corporate governance the focus of organizations worldwide. Corporate governance is defined as the principles and processes that provide the strategies on how an organization directs and obtains its goals, the oversight process for implementing effective accountability from its directors and managers (Rittenberg, Johnstone, & Gramling, 2012). What are two of the principles that surround corporate governance? How do they tie into the recent legislation that was put into place to resolve ethical challenges and changes within the last decade? Two principles that surround corporate governance include “successful management and ethical corporate culture and independence and objectivity” (Creel, 2013). It is management’s responsibility to create a culture of “integrity and ethical behavior” (Rittenberg, Johnstone, & Gramling, 2012). In addition, it is imperative for board members to maintain their objectivity and their judgment must remain independent and in the best interest of its stakeholders. Corporate...

Words: 1286 - Pages: 6

Premium Essay

Enron Case

...Accounting 1370 Accounting Ethics Session 6 Governance, Accounting, and Auditing, Post-Enron Group 1: Student Name__Seven Autrey_____________________________________ Student Name__Duc Nguyen_____________________________________ Telling the Enron Story Name five ethical problems and the existing conditions that caused the Enron fiasco. Explain each. 1. Fiduciary Failure – the board of directors failed to safeguard the companies from many inappropriate practices. 2. High Risk Accounting – Enron allowed high risk accounting in that the partnerships with Chewco and LJM1 and LJM2 did not conform with accounting rules 3. Enron had extensive undisclosed off-the-books activity. There were billions of dollars in off-the-book assets and liabilities. 4. Excessive Compensation – There was a cash drain caused by the 2000 annual bonus and performance unit plan. 5. Lack of Independence – There were financial ties between Enron and board members. Arthur Anderson provided internal auditing services as well as consulting services. Accounting 1370 Accounting Ethics Session 6 Governance, Accounting, and Auditing, Post-Enron Group 1: Student Name__Carol Cates_____________________________________ Student Name__Brenda Bohm____________________________________ Telling the Enron Story Name five ethical problems and the existing conditions that caused the Enron fiasco. Explain each. 1. At Enron, a lack of integrity was built into the foundation...

Words: 8085 - Pages: 33

Premium Essay

Flat

...Internal audit Internal auditing is an independent, objective assurance and consulting activity designed to add value and improve an organization's operations. It helps an organization accomplish its objectives by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of risk management, control, and governance processes.[1] Internal auditing is a catalyst for improving an organization's governance, risk management and management controls by providing insight and recommendations based on analyses and assessments of data and business processes. With commitment to integrity and accountability, internal auditing provides value to governing bodies and senior management as an objective source of independent advice. Professionals called internal auditors are employed by organizations to perform the internal auditing activity. The scope of internal auditing within an organization is broad and may involve topics such as an organization's governance, risk management and management controls over: efficiency/effectiveness of operations (including safeguarding of assets), the reliability of financial and management reporting, and compliance with laws and regulations. Internal auditing may also involve conducting proactive fraud audits to identify potentially fraudulent acts; participating in fraud investigations under the direction of fraud investigation professionals, and conducting post investigation fraud audits to identify control breakdowns and establish...

Words: 3415 - Pages: 14

Free Essay

Transparency and It Governance

...Transparency and IT Governance James Anthony Quilty Keller Graduate School of Management May 16, 2010 SE592ON_A – IT Governance MAY10 – Sec A Professor William Uminowicz Transparency and IT Governance I. Table of Contents…………………………………………………………2 II. Why Transparency?.…...………………………………………………...3 III. Transparencies relation to IT Governance..……………………………3 IV. COBIT Framework Provides for Internal Audit and Corrective Action……………………………………………………………………..4 V. Summary..………………………………………………………………...4 VI. References………………………………………………………………...5 II. Why Transparency? Due to many of the scandals that have arisen in recent years; Enron, AOL Time Warner, Adelphia Communications and other corporations according to Forbes (2002, Patsuris). Due to these scandals, the United States government stepped in and started making regulatory changes such as disclosure requirements and better detailed reporting of off-balance sheet financing. If any of these reports are found to be purposely misreported then penalties to the executives will be ensued. This why it is important for transparency to be a part of the IT governance. So, Sarbanes_Oxley (Sox) was adopted for all companies to comply with a standard (2007, Hermalin & Weisbach). III. Transparencies relation to IT Governance Transparency within the IT Governance creates a standard where everyone involved can participate on any given project and obtain a higher level of competency. Transparency can...

Words: 701 - Pages: 3

Premium Essay

Enron Corporation Case Study

...instability and the compromising factor of accounting profession itself. Out of the many parties in the league and the major force behind the debacle of Enron concern Andersen's, the accounting and auditing firm that once deserved name in the industry for its conscience in accounting professional services and auditing. As the case relates to, accounting audit for Enron is attended by Andersen's since long enough. However, the interesting feature is that some compromise in the profession of accounting services by Andersen's was notable, given that there are noteworthy feature of stock manipulation, especially in financial statements of Enron attended and audited by Andersen's. The statement and restatement of Enron also gives some probable indication for manipulation of accounting, where debate and counter debate in that regard from the prying eye of the media was a common feature. Thus, the involvement of Andersen's in Enron consultancy and professional auditing makes it rather more imploded for the direct involvement of Andersen's that also successively ushered the debacle and bankruptcy of Enron for the entire sheer element attached to it. Moreover, the accounting scandal involving Enron have been subject to criticism from many quarters. However, insiders who testify against the auditing firm make it the biggest party of the fall out and bankruptcy of Enron...

Words: 2622 - Pages: 11

Premium Essay

Internal Auditing

...Internal auditing is an independent, objective assurance and consulting activity designed to add value and improve an organization's operations. It helps an organization accomplish its objectives by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of risk management, control, and governance processes.[1] Internal auditing is a catalyst for improving an organization's governance, risk management and management controls by providing insight and recommendations based on analyses and assessments of data and business processes. With commitment to integrity and accountability, internal auditing provides value to governing bodies and senior management as an objective source of independent advice. Professionals called internal auditors are employed by organizations to perform the internal auditing activity. The scope of internal auditing within an organization is broad and may involve topics such as an organization's governance, risk management and management controls over: efficiency/effectiveness of operations (including safeguarding of assets), the reliability of financial and management reporting, and compliance with laws and regulations. Internal auditing may also involve conducting proactive fraud audits to identify potentially fraudulent acts; participating in fraud investigations under the direction of fraud investigation professionals, and conducting post investigation fraud audits to identify control breakdowns and establish financial...

Words: 405 - Pages: 2

Premium Essay

It Certification

...Executive Summary The need for auditors with technology skills have increased, this is why the IT auditing profession has become very important. Information Technology auditors analyze the information technology structure, operations, and software of an organization. They are in charge of identifying better ways in which the organization’s systems can meet their needs in a better and more reliable way. IT auditors can basically design new systems by configuring hardware and software programs and they also test the systems to make sure they are working properly. Most IT auditors work in offices, obviously with computer systems. Some IT auditors work with the same company for years making sure the information systems and internal controls work properly. Some other IT auditors work for CPA firms that provide auditing services, and are required to travel to evaluate the information systems of clients. For the most part IT auditors work independently, but when they are assigned to larger and/or complicated projects, they use the collaboration of other peers. James Reinhard, CPA, CIA, CISA, manager of Simon Property Group Inc. who has more than 20 years’ experience in IT and integrated auditing states that “The ideal IT auditor should be able to discuss IP routing with the network folks in one hour and financial statement disclosures with the controller in the next” (Scharf, 2008). To become the ideal IT auditor IT audit certifications are the best option. IT audit...

Words: 5614 - Pages: 23

Premium Essay

Esp Charter

...ESP CHARTER INTERNAL AUDITING DEPARTMENT Published By: ESP CHARTER INTERNAL AUDITING DEPARTMENT INTRODUCTION: Internal auditing is an independent, objective assurance and consulting activity designed to add value and improve ESP operations. It helps ESP to accomplish its objectives by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of risk management, control, and governance processes. ROLE: The Internal Auditing Department is established by ESP’s governing body and the purpose, authority, and responsibility of the internal audit activity are defined in an internal audit charter, consistent with the Definition of Internal Auditing, the Code of Ethics, and the Standards. The chief audit executive must periodically review the internal audit charter and present it to ESP’s senior management and the governing body for approval. PROFESSIONAL STANDARDS: The Internal Auditing Staff shall govern themselves by adherence to the Institute of Internal Auditor’s “Code of Ethics.” The Institute’s “Standards for the Professional Practice of Internal Auditing” shall constitute the operating procedures for the department. These two documents constitute an addendum to their charter. The Institute of Internal Auditor’s “Practice Advisories” will be adhered to as applicable. In addition, Internal Auditing will adhere to ESP policies and procedures and Internal Auditing’s Standard Operating Procedures Manual. If inconsistencies exist between...

Words: 1170 - Pages: 5

Premium Essay

Auditing

...Corporate governance heavily refers to the whole structure of rights, processes and controls established internally and externally over the management of a business entity with the objective of protecting the interests of its stakeholders from any type of loses incurring. To begin with, firstly there are three types of auditors in the corporate governances, internal, external and government auditors. The role of the internal auditors in the corporate governance is to evaluates corporate activities, controls or procedures and ensures that they are adequate and in compliance with senior management's recommendations and human resources guidelines. An internal audit also helps a firm adhere with regulatory standards and industry practices.An internal auditor evaluates a firm's processes, "controls" and mechanisms to ensure that they are "adequate" and "functional". A control is a group of instructions that top management puts into place to avoid losses due to human error, technology breakdowns or fraud. A "functional" control provides corrections to internal problems. A control is "adequate" when it clarifies instructions for job performance and problem reporting. An auditor also ensures that a firm's activities and controls abide by government mandates or industry regulations. (Codjia, 2013) Moreover the role and responsibility of an external auditor is to provide assurance to the general public regarding the truth and fairness of the information presented in the audited reports...

Words: 2531 - Pages: 11

Premium Essay

Accounting Information Systems Research Paper

...monitor effective internal controls over financial reporting. The cost of implementing an effective internal control structure are onerous, and SOX inflicts opportunity costs upon an enterprise as executives have become more risk adverse due to fears of incrimination. The Public Company Accounting Oversight Board (PCAOB) was created by SOX to oversee the accounting process and dictate independence requirements for auditors and auditing committees. The PCAOB proposed regulations must be approved by the SEC before they are enacted. Since the passage of SOX, the IT department has become critical in designing and implementing the internal controls in company accounting information systems. The Information Technology Governance Institute (ITGI) created a framework called Control Objectives for Information and Related Technology (COBIT) to provide guidance for companies to implement and monitor IT governance. Accounting Information Systems Research Paper The Sarbanes-Oxley Act of 2002 changed the landscape of corporate financial reporting and auditing. In the wake of corporate reporting scandals, Congress decided the accounting profession was unable to self-regulate, and The Sarbanes-Oxley Act of 2002 was signed into law. The law addresses corporate greed and dishonesty by requiring companies to implement extensive internal control procedures to deter fraud and hold corporate...

Words: 3250 - Pages: 13