This topic focuses on the execution phase of IS auditing, including audit project management, testing and sampling methodologies, evidence collection techniques, audit data analytics, reporting and communication techniques, and quality assurance in the audit process.
5 minutes
5 Questions
The Information System Auditing Process - Execution phase is a critical component of the CISA methodology, occurring after audit planning and before reporting. During execution, auditors implement the audit program to gather sufficient, reliable evidence for drawing conclusions about the information system's controls.
Auditors begin by conducting entrance meetings with key stakeholders to confirm audit objectives, scope, and timing. They then deploy various evidence collection techniques including documentation review, interviews, observations, walkthroughs, and technical testing.
Specifically, auditors examine system documentation, policies, and procedures to understand design controls. They interview personnel to confirm understanding of processes and identify potential issues. Through observation, they witness actual control operation. Walkthroughs allow tracing transactions through entire processes, while technical testing may involve vulnerability assessments, configuration reviews, or code analysis.
Throughout execution, auditors document findings in working papers that connect evidence to audit objectives. They identify control weaknesses, compliance gaps, and operational inefficiencies. Evidence must be sufficient (adequate quantity), reliable (trustworthy), relevant (applicable to objectives), and useful (helps achieve audit purpose).
As issues emerge, auditors perform root cause analysis to identify underlying problems rather than merely symptoms. They evaluate findings based on risk and materiality - considering impact on confidentiality, integrity, and availability of information assets.
Auditors maintain continuous communication with auditees during execution, promptly discussing potential findings to validate accuracy and give management opportunity for clarification. They adjust audit procedures as needed when unexpected issues arise.
The execution phase concludes with preliminary findings documentation and preparation for the exit conference, where auditors present initial results before formal reporting. Throughout execution, professional skepticism and objectivity remain essential to effective information systems auditing.The Information System Auditing Process - Execution phase is a critical component of the CISA methodology, occurring after audit planning and before reporting. During execution, auditors implement the audit program to gather sufficient, reliable evidence for drawing conclusions about the informatio…