Saturday, December 14, 2019
Corporate Compliance Insights
  • Home
    • Home
  • About
    • About CCI
    • Writing for CCI
    • Advertise With Us
  • Articles
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Leadership and Career
  • Industry News
  • Jobs
  • Events
    • Webinars & Events
    • Submit an Event
  • Downloads
    • eBooks
    • Whitepapers
  • Podcasts
  • Videos
  • Subscribe
No Result
View All Result
  • Home
    • Home
  • About
    • About CCI
    • Writing for CCI
    • Advertise With Us
  • Articles
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Leadership and Career
  • Industry News
  • Jobs
  • Events
    • Webinars & Events
    • Submit an Event
  • Downloads
    • eBooks
    • Whitepapers
  • Podcasts
  • Videos
  • Subscribe
No Result
View All Result
Corporate Compliance Insights

Effective Audit Programs Consider Objectives First

by Rosemary Amato
August 8, 2016
in Uncategorized
The key to an effective audit program

Thanks to excellent white papers like this one, creating audit and assurance programs can seem as easy as one, two, three, four and five! At least on the face of it. And that is where audit programs can go awry. The auditor often doesn’t take into consideration the objectives they actually want the program to accomplish as they move through the five planning phases.

Anyone can follow an audit program, but if they tailor their execution to meet the four key objectives of a world-class audit and assurance program it will be faster, more efficient and ensure that they are doing the right things to mitigate risk.

So what key objectives should an audit process have? They include:

  1. Formally documented audit procedures and sequential steps.
  2. Procedures that are repeatable and easy to use by internal or external auditors who need to perform similar audits.
  3. Documented testing methods that will be used (compliance and/or substantive).
  4. Generally accepted audit standards that relate to the planning phase in the audit process.

These objectives should be considered when preparing each of the five audit and assurance planning process steps, which include: 1) Determine audit subject, 2) Define audit objective, 3) Set audit scope, 4) Perform pre-audit planning and 5) Determine audit procedures and steps for data-gathering.

Well-documented Procedures Save Time and Money

Take the first objective—formally documenting audit procedures and sequential steps—this links to all five key planning steps because if an audit professional takes any shortcuts, they might miss what the true audit subject is and won’t have a clear understanding of the audit objective. This can cause numerous issues that adversely affect the planned audit. Its scope may be too narrow, too broad or even incorrect. It may take too much or too little time to conduct. Key steps might be missed and the right resources may not be allocated. The execution may involve unnecessary work. All of these issues impact the effectiveness of the audit and can increase its costs. Undocumented or poorly documented procedures will require partial or complete revisions, which risk incurring additional costs. Many of us have heard (or experienced ourselves) situations where charges were increased due to poorly documented procedures, which required rework by the audit team and additional charges to be incurred by the client.

Make it Repeatable

Testing and testing tools have evolved over the years as technology has improved. The use of data visualization tools like QlikView and Tableau provide the ability to do ongoing monitoring instead of just testing a particular time period. At the recent EuroCACS conference in Dublin, the IT Audit Directors Forum participants discussed data visualization and how it can be applied to, and used for, the creation of audit and assurance programs for enterprise resource planning (ERP) systems. We’re now seeing testing tools that look specifically at the concept of data visualization and how it should be considered when determining which testing tools an audit and assurance program will require.

Understand Those Audit Standards

Finally, the planning process should look at how the program will meet generally accepted audit standards around the planning phase of the audit process. If the auditor does not understand the standards they are applying, it will result in a longer-than-needed audit time, and likely a failure to select the right personnel and audit focus. The auditor also wants to make sure he/she completely understands the purpose of the particular audit being undertaken. As an aid to information systems auditors, ISACA has developed ITAF: A Professional Practices Framework for IS Audit/Assurance, which contains the necessary standards and guidelines useful in planning and conducting IS audits.

In the end, audit and assurance programs are only effective if they focus on achieving the four key objectives every audit should have. Without a single-minded emphasis on the objectives throughout the process, an audit could easily miss its mark in terms of subject, objectives, scope, planning, data-gathering and, ultimately, success.


Tags: briberyHIPAA
Previous Post

EU-U.S. Privacy Shield: A Path Forward

Next Post

Government Reach Does Not Extend to Information Stored Overseas

Rosemary Amato

Rosemary AmatoRosemary M. Amato, CISA, CMA, is a former international vice president of ISACA and is also a board member of the IMA, chairing the Performance Oversight and Audit Committee. Amato is currently a managing director in global finance at one of the Big 4 and prior to that spent more than 20 years as a finance and IT professional, with her last role being that of vice president controller for a large U.S. footwear retailer.

Related Posts

change is coming text on city background at sunset

Future-Proofing the Compliance Professional

December 13, 2019
futuristic technology projecting 2020 in white text

The Future of Data Privacy Regulation

December 12, 2019
illustration of businessmen shaking hands through smartphone screens

FINRA Reveals Top Areas of Interest: Supervision and Digital Communications Compliance Programs

December 12, 2019
new york city skyline at sunset

The Early Days: The Birth of the Independent Monitoring Concept

December 11, 2019
Next Post
recent ruling impacts consumer privacy

Government Reach Does Not Extend to Information Stored Overseas

Free Downloads

OFAC whitepaper cover
Compliance Job Interview Q&A
Reputation Risk Management Research

RSS SEC Litigation News

  • John Special, Defendant, and Michael Murphy, Relief Defendant, John Kenneth Davidson December 12, 2019
    SEC Obtains $3 Million Settlement in Insider Trading Action
  • Palm Beach Atlantic Financial Group, LLC and William A. Smith December 11, 2019
    SEC Charges Florida Resident and His Corporate Entity for Fraudulent Securities Offerings
  • Nanotech Engineering, Inc., Michael James Sweaney (also known as Michael Hatton), David Sweaney, and Jeffery Gange December 11, 2019
    SEC Obtains Asset Freeze to Halt Alleged Offering Fraud

Jump to a Topic:

anti-corruption anti-money laundering/AML Artificial Intelligence/A.I. automation banks Big Data blockchain board of directors board risk oversight bribery CCPA/California Consumer Privacy Act Cloud Compliance communications management corporate culture corporate governance culture of ethics cyber risk data analytics data breach data governance decision-making Dodd-Frank DOJ due diligence fcpa enforcement actions GDPR GRC HIPAA information security internal audit internet of things (IoT) KYC/know your customer machine learning monitoring regtech reputation risk risk assessment Sanctions SEC social media risk technology third party risk management tone at the top training whistleblowing
No Result
View All Result

Privacy Policy

Follow Us

  • Facebook
  • Twitter
  • LinkedIn
  • RSS Feed

Category

  • Audit
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • HR Compliance
  • Leadership and Career
  • News
  • Opinion
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Whitepapers

© 2019 Corporate Compliance Insights

No Result
View All Result
  • Home
  • About
  • Articles
  • News
  • Podcasts
  • Videos
  • Whitepapers
  • eBooks
  • Events
  • Jobs
  • Subscribe

© 2019 Corporate Compliance Insights