End-User Computing: Risks and Governance
Understand the risks of end-user computing, governance frameworks, and audit approaches for spreadsheets and user-developed applications.
Understanding End-User Computing
End-User Computing (EUC) refers to applications and tools developed by business users outside the formal IT development process. Common examples include spreadsheets, desktop databases, macros, and scripts that are used for critical business functions such as financial reporting, risk calculations, and regulatory submissions. For IS auditors, EUC represents a significant risk because these applications often lack the controls, testing, and documentation associated with formally developed IT systems.
Risks of End-User Computing
EUC applications present several categories of risk:
- Data Integrity: Spreadsheet errors, formula mistakes, and manual data entry can lead to inaccurate results. Studies have shown that a significant percentage of complex spreadsheets contain material errors.
- Lack of Version Control: Without formal version management, multiple copies of a spreadsheet may exist, creating confusion about which version contains the most current and accurate data.
- Insufficient Access Controls: EUC applications stored on shared drives or personal workstations may lack appropriate access restrictions, allowing unauthorized modifications.
- No Change Management: Changes to EUC applications are often made without testing, documentation, or approval, increasing the risk of introducing errors.
- Key Person Dependency: EUC applications are frequently developed and maintained by a single individual, creating operational risk if that person leaves the organization.
EUC Governance Framework
Organizations should establish a governance framework for EUC that includes:
- Inventory and Classification: Identifying and cataloging all EUC applications, then classifying them based on their criticality and risk level.
- Control Requirements: Defining minimum control requirements for each classification level, such as input validation, formula protection, access restrictions, and backup procedures.
- Review and Testing: Implementing periodic reviews and testing of critical EUC applications to verify their accuracy and reliability.
- Documentation Standards: Requiring documentation of EUC application logic, data sources, and assumptions.
Audit Considerations
IS auditors should identify EUC applications that support critical business processes and assess whether appropriate controls are in place. Auditors should test the accuracy of key formulas and calculations, verify that access controls prevent unauthorized changes, and evaluate whether the organization has a policy governing EUC development and use.
CISA Exam Tips
For the CISA exam, understand that EUC is a common audit finding because business users often create critical applications without adequate controls. Know that the primary risks include data integrity issues, lack of version control, and key person dependency. Questions may focus on the auditor's recommendation to establish a governance framework that includes inventory, classification, and minimum control standards for EUC applications.