Defining Objectives and Obtaining Data for Analytics (CIA Part 2: Information Gathering, Analysis and Evaluation)
Overview
Data analytics has become a core tool in modern internal auditing. In CIA Part 2 (Practice of Internal Auditing), the data analytics process appears under Information Gathering, Analysis and Evaluation. Its first two steps, defining objectives and obtaining data, decide whether every later step succeeds or fails. If an analytic answers the wrong question, or runs on incomplete or unreliable data, it produces misleading conclusions, however sophisticated the technique.
Why It Is Important
1. Relevance: Clear objectives keep the analytics linked to the engagement objectives and to the risks identified during planning. This avoids running tests simply because the data is available.
2. Efficiency: Well-defined objectives limit data requests to what is needed. This saves time for auditors and data owners and lowers the burden of storing and protecting data.
3. Sufficient, reliable, relevant and useful information: The IIA Standards require internal auditors to base conclusions on information of this quality. Data that is complete, accurate and from a trustworthy source is a prerequisite.
4. Confidentiality and security: Obtaining data responsibly protects sensitive information, such as personal data and payroll, and respects legal and organizational requirements.
5. Credibility of results: Management will challenge exceptions produced from flawed data. Validated data makes findings defensible.
What It Is
The data analytics process is commonly described in these steps:
1. Define the question / objectives
2. Obtain relevant data, including identifying sources and requesting, extracting and receiving the data
3. Clean and normalize the data
4. Analyze the data
5. Communicate the results
This topic covers the first two steps.
Step 1: Defining Objectives
Defining objectives means stating precisely what the analysis should answer. Examples include:
- Are there duplicate vendor payments?
- Are any employees also set up as vendors?
- Were purchases split to avoid approval limits?
Good objectives have these features:
- They are derived from the engagement objectives and risk assessment.
- They are specific and measurable, with clear criteria for what counts as an exception.
- They define the scope: the period, business units, systems and populations covered.
- They identify the expected output, such as an exception report, a trend, a dashboard or a population for sampling.
- They consider the type of analytics needed:
- Descriptive: what happened
- Diagnostic: why it happened
- Predictive: what is likely to happen
- Prescriptive: what should be done
Step 2: Obtaining DataObtaining data covers three activities.
Identifying data sources and owners:- Internal sources: ERP systems, general ledger, HR and payroll systems, CRM, logs, spreadsheets
- External sources: bank statements, vendor confirmations, government databases, industry data, social media
- Structured data, such as database tables, versus unstructured data, such as emails, documents and images
Understanding the data:- Obtain data dictionaries, field definitions, file layouts and record counts.
- Meet IT staff and data owners to understand how data is created, stored and changed.
Requesting and extracting the data:- Make formal data requests that specify fields, period, format and control totals.
- The auditor's own direct, read-only extraction is generally preferred over files prepared by the auditee, because it reduces the risk of manipulation.
- Use secure transfer methods and follow data privacy laws and organizational policies.
How It Works in PracticeExample: an auditor reviewing accounts payable is concerned about fraudulent or erroneous payments.
1. Objective. Identify duplicate payments, payments to unapproved vendors and vendors sharing bank accounts or addresses with employees, for the fiscal year.
2. Data needed.- Vendor master file
- Payment and disbursement history
- Invoice register
- Employee master file (address and bank fields)
3. Sources and owners.- ERP accounts payable module, owned by finance
- HR system, owned by HR
- The IT department assists with access
4. Request. Specify the fields, the date range, the file format (for example CSV) and the control totals required: record counts and total payment amounts.
5. Validation on receipt. This is critical.
- Reconcile record counts and totals to the general ledger or system reports. This tests completeness.
- Check that the dates fall within the requested period.
- Look for blanks, duplicates and format problems. This tests accuracy and integrity.
- Confirm the source is the production system, not an edited copy. This tests reliability.
- Use hash totals where appropriate.
6. Document. Record the source, extraction method, date, validation procedures and any limitations in the workpapers.
Key Concepts to Remember- Completeness: all relevant records are included.
- Accuracy: the data correctly reflects transactions.
- Validity: the data represents real, authorized events.
- Timeliness: the data covers the correct period and is current.
- Reliability of source:
- Independent external sources are generally more reliable than internal ones.
- Data obtained directly by the auditor is more reliable than data obtained indirectly.
- Data from systems with strong controls is more reliable.
- Data governance: ownership, access rights and privacy laws such as GDPR all apply to auditors too.
- Full population testing: a key benefit of analytics is examining 100% of transactions instead of a sample. This depends on obtaining the complete population.
- Garbage in, garbage out: poor-quality inputs invalidate results.
Common Pitfalls- Starting with available data instead of a defined question
- Requesting excessive data, which creates privacy and efficiency problems
- Accepting auditee-prepared extracts without reconciling them
- Ignoring how the data was defined, for example misreading what a status code means
- Not documenting the data lineage
Exam Tips: Answering Questions on Defining Objectives and Obtaining Data for Analytics1. Know the order. When asked for the FIRST step in a data analytics process, the answer is almost always
defining the objective or question. It is not obtaining data, cleaning data or choosing software. Objectives come from the engagement objectives and risks.
2. Validation follows receipt. If a question asks what the auditor should do immediately after receiving data, choose
verifying completeness and accuracy before analysis. Reconciling record counts and control totals to the source system or general ledger is the classic correct answer.
3. Prefer independent and direct sources. When asked which data is most reliable, rank:
- auditor-extracted data above client-prepared data
- external third-party data above internal data
- data from well-controlled systems above data from poorly controlled systems
4. Link to the Standards. Answers stressing
sufficient, reliable, relevant and useful information and alignment with
engagement objectives usually win over answers about speed or volume.
5. Watch for privacy and access traps. Options suggesting the auditor obtain unrestricted access, bypass data owners, or request all available data are usually wrong. Choose the option that is limited to the need, authorized, secure and compliant.
6. Distinguish the steps. Questions may describe an activity and ask which phase it belongs to:
- Removing duplicates or standardizing date formats is cleaning/normalization, not obtaining data.
- Identifying the system that holds vendor data is obtaining data.
- Deciding what fraud scenarios to test is defining objectives.
7. Scenario questions. Ask yourself: what risk is being addressed, what question answers it, what data answers that question, and how do I know the data is complete and trustworthy? The answer addressing the root step is usually correct.
8. Spot keywords.- 'Most important', 'first' or 'primary' often point to objectives or data integrity.
- 'Best evidence' points to reliability of source.
- 'Efficient' points to limiting data to what the objective requires.
9. Eliminate tool-focused answers. Choosing the analytics software or building visualizations is rarely the correct first or most important action.
10. Remember full population benefits. If asked about the advantage of analytics, testing entire populations and identifying anomalies or patterns is key. That advantage only holds if the extracted data is complete.
SummaryDefining objectives ensures analytics answer the right risk-based questions. Obtaining data ensures those questions are answered with complete, accurate, reliable and properly authorized information. In the exam, prioritize objective-setting first, validate data before analysis, favor independent and direct sources, and respect confidentiality and data governance.