Integrated Auditing: Combining Financial and IT
Understand integrated auditing approaches that combine financial and IT audit disciplines to provide comprehensive assurance over organizational processes.
The Case for Integrated Auditing
Integrated auditing combines financial auditing and IT auditing into a unified approach that examines both the business processes and the technology supporting them. As organizations become increasingly dependent on information systems, separating financial controls from IT controls creates gaps in audit coverage and understanding.
Why Integration Matters
Traditional audit approaches often create silos where financial auditors test business controls without fully understanding the underlying technology, and IT auditors examine technical controls without appreciating their business impact. Integrated auditing bridges this gap by considering both dimensions simultaneously.
- Comprehensive risk assessment considers both financial and technology risks together
- Reduced duplication eliminates overlapping testing between separate audit teams
- Better context helps auditors understand how IT controls affect financial reporting
- Improved recommendations address root causes rather than symptoms
Framework for Integrated Auditing
Planning Phase
During planning, the integrated audit team identifies key business processes and maps the technology components that support them. This includes understanding data flows, automated controls, manual controls dependent on IT, and the interfaces between systems. Risk assessment considers both inherent business risks and technology risks.
Execution Phase
Test procedures are designed to evaluate both business process controls and the IT controls that support them. For example, when auditing revenue recognition, an integrated approach tests not only the accounting entries but also the system configurations that automate revenue calculations, the access controls protecting pricing data, and the interfaces between order management and financial systems.
Reporting Phase
Integrated audit reports present findings in a business context, explaining how technology control weaknesses affect business objectives. This approach helps management understand the full impact of identified issues and prioritize remediation efforts appropriately.
Skills Required for Integrated Auditing
Integrated auditors need a blend of financial and technical competencies. They must understand accounting principles, business processes, IT infrastructure, application controls, and data management. While deep specialization in both areas is uncommon, auditors should have enough knowledge to identify risks across both domains and collaborate effectively with specialists.
CISA Exam Considerations
The CISA exam may present scenarios requiring candidates to identify how IT control weaknesses affect business processes. Understand that application controls such as input validation, processing controls, and output controls directly impact data integrity in financial systems. Know that general IT controls including access management, change management, and operations management provide the foundation for reliable application controls.