Building an Audit Program from Scratch
Learn how to establish an IS audit program from the ground up. Comprehensive guide covering charter, planning, and execution for the CISA exam.
Starting an IS Audit Program
Building an IS audit program from scratch requires careful planning, organizational support, and a systematic approach. For CISA candidates, understanding how to establish an audit program is important because it demonstrates comprehensive knowledge of audit governance, planning, and execution, all of which are tested on the exam.
Step 1: Establish the Audit Charter
The audit charter is the foundational document that authorizes the audit function:
- Purpose and mission: Define the audit function's purpose, typically to provide independent assurance that IT controls are adequate and effective.
- Authority: Document the authority granted to the audit function, including unrestricted access to systems, records, personnel, and physical locations.
- Reporting structure: Define the reporting relationship, ideally to the audit committee or board of directors to ensure independence from management.
- Scope: Describe the scope of audit activities, including all IT systems, processes, and third-party relationships.
- Independence: Affirm the audit function's independence from the areas it audits.
- Responsibilities: Detail the audit function's responsibilities including planning, execution, reporting, and follow-up.
Step 2: Conduct Risk Assessment
A comprehensive risk assessment drives audit planning:
- Identify the audit universe: Catalog all auditable areas including applications, infrastructure, processes, vendors, and business units.
- Assess risks: Evaluate each area based on business impact, data sensitivity, regulatory requirements, complexity, change frequency, and prior audit history.
- Rank and prioritize: Score and rank auditable areas to determine which should receive attention first.
Step 3: Develop the Audit Plan
The risk assessment informs a multi-year audit plan:
- Annual audit plan: Define specific audit engagements for the current year, including objectives, scope, timing, and resource requirements.
- Multi-year plan: Outline planned coverage over three to five years to ensure all significant risk areas are audited on a reasonable cycle.
- Resource allocation: Determine staffing needs including skills requirements, and identify where external expertise may be needed.
Step 4: Build the Team
An effective audit team requires a mix of skills and experience. Consider the technical skills needed to audit IT environments (networks, databases, applications, cloud), industry knowledge relevant to the organization, and certifications such as CISA, CISSP, and CIA that demonstrate competency. Develop training plans to build and maintain team capabilities.
Step 5: Establish Methodology and Standards
Define the audit methodology that will guide all engagements, including engagement planning procedures (scope, objectives, risk assessment), fieldwork standards (evidence collection, testing approaches, documentation requirements), reporting templates and review processes, quality assurance procedures, and follow-up and issue tracking processes. Align the methodology with ISACA standards and any applicable regulatory requirements.
Step 6: Implement Tools and Technology
Select and implement tools that support audit operations including audit management software for planning, scheduling, and tracking, data analytics tools for automated testing and analysis, working paper management for documenting evidence and findings, and issue tracking systems for managing audit findings and remediation.
Step 7: Execute and Improve
Execute the audit plan and continuously improve. After each engagement, conduct quality reviews, gather feedback, and refine processes. Periodically assess the overall audit program's effectiveness through self-assessments and external quality reviews.
CISA Exam Focus
For the CISA exam, understand the key components of an IS audit program, the importance of the audit charter, risk-based planning, and the relationship between the audit function and governance bodies. Questions may present scenarios involving audit program establishment and ask about the appropriate sequence of steps or key requirements.