is-auditing8 min read

Evaluating Audit Evidence Reliability and Sufficiency

Learn how to evaluate the reliability and sufficiency of audit evidence in IS auditing, a critical skill for CISA exam success and professional practice.

CISAPractice|

Audit Evidence Fundamentals

Audit evidence forms the basis for audit conclusions and opinions. For CISA candidates, understanding what constitutes sufficient and appropriate evidence is essential. The quality of audit evidence directly determines the credibility and defensibility of audit findings.

Characteristics of Good Audit Evidence

Audit evidence must be both sufficient and appropriate. Sufficiency relates to the quantity of evidence needed to support conclusions. Appropriateness addresses the quality, relevance, and reliability of the evidence gathered. Both dimensions must be satisfied for evidence to adequately support audit findings.

Evidence Reliability Hierarchy

Not all evidence carries equal weight. The reliability of audit evidence depends on its source, nature, and the circumstances under which it is obtained.

  • Evidence from independent external sources is generally more reliable than internally generated evidence
  • Evidence generated internally with strong controls is more reliable than evidence from weak control environments
  • Evidence obtained directly by the auditor through observation, inspection, or recalculation is more reliable than evidence obtained indirectly
  • Documentary evidence in original form is more reliable than photocopies or verbal representations
  • Electronic evidence with proper integrity controls is reliable when audit trails and access controls are adequate

Types of Audit Evidence in IS Auditing

IS auditors gather various types of evidence including system configurations and screenshots, access control lists, change management records, log files and audit trails, policy and procedure documents, and results from automated testing tools. Each type has different reliability characteristics that must be considered.

Evaluating Sufficiency

Determining whether enough evidence has been gathered requires professional judgment. Factors influencing sufficiency include the risk level of the area being audited, the quality of individual evidence items, the consistency of evidence from different sources, and the materiality of potential findings. Higher risk areas and more significant findings require more evidence.

Corroborating Evidence

Relying on a single piece of evidence is generally insufficient for significant findings. Auditors should seek corroborating evidence from different sources and of different types. When multiple independent sources point to the same conclusion, the overall evidence is more persuasive and reliable.

Documentation Requirements

All evidence must be properly documented in audit workpapers. Documentation should include the source of evidence, the date obtained, the method of collection, and the conclusions drawn. This documentation enables supervisory review and supports the defensibility of audit findings.

Key Exam Points

For the CISA exam, remember that evidence reliability depends on its source, nature, and the conditions under which it was obtained. Independent evidence is more reliable than internal evidence. Direct evidence is more reliable than indirect evidence. The auditor must exercise professional judgment in determining both the sufficiency and appropriateness of evidence gathered during the audit.

Related Tags

Audit EvidenceEvidence ReliabilityAudit Quality

Ready to practice?

Put this knowledge to work with scenario-based practice questions.

Start Free