Audit Evidence: Types, Collection, and Evaluation
Understand the types of audit evidence, how to collect it effectively, and how to evaluate its sufficiency and reliability for the CISA exam.
The Role of Audit Evidence
Audit evidence is the information gathered by auditors to support their findings, conclusions, and recommendations. The quality and quantity of evidence directly affect the credibility of audit results. For CISA exam candidates, understanding evidence types and evaluation criteria is essential.
Types of Audit Evidence
Audit evidence can take many forms, each with different levels of reliability:
- Physical evidence: Direct observation of assets, processes, or conditions. Examples include observing a data center's physical security controls or watching a backup procedure being performed.
- Documentary evidence: Written or electronic records such as policies, procedures, system logs, configuration files, and contracts.
- Testimonial evidence: Statements obtained through interviews with personnel. This is generally the least reliable type of evidence unless corroborated.
- Analytical evidence: Results from data analysis, comparisons, trend evaluations, and computations performed by the auditor.
- Electronic evidence: Data stored or transmitted electronically, including database records, email communications, and system-generated reports.
Reliability of Evidence
Not all evidence carries the same weight. Several factors influence reliability:
- Evidence obtained directly by the auditor is more reliable than evidence provided by the auditee.
- Evidence from independent external sources is more reliable than evidence generated internally.
- Documentary evidence is generally more reliable than oral testimony.
- Original documents are more reliable than copies.
- Evidence from systems with strong internal controls is more reliable than evidence from poorly controlled systems.
Collecting Evidence
Auditors use several techniques to gather evidence:
- Inquiry: Asking questions of knowledgeable personnel through interviews or questionnaires.
- Observation: Watching processes and activities as they occur.
- Inspection: Examining documents, records, and physical assets.
- Re-performance: Independently executing a control or procedure to verify it produces the expected result.
- Computer-assisted audit techniques: Using software tools to extract and analyze data from information systems.
Evaluating Evidence
Auditors evaluate evidence based on two primary criteria:
- Sufficiency: Is there enough evidence to support the findings? Sufficiency is a measure of quantity. The auditor must gather enough evidence to convince a reasonable person that the finding is valid.
- Appropriateness: Is the evidence relevant and reliable? Appropriateness is a measure of quality. Evidence must be directly related to the audit objective and must come from trustworthy sources.
CISA Exam Focus
The CISA exam tests your ability to determine whether evidence is sufficient and appropriate for a given finding. Remember that auditors should use multiple types of evidence to corroborate findings (this is called corroborative evidence). When evidence conflicts, the auditor should gather additional evidence to resolve the discrepancy rather than relying on a single source. Additionally, auditors must maintain a clear chain of custody for evidence, especially when findings may lead to disciplinary or legal actions.