IS Audit Standards: ISACA and International Guidelines
Learn about ISACA audit standards, guidelines, and international frameworks that govern IS auditing. Essential knowledge for CISA exam preparation.
Understanding IS Audit Standards
IS audit standards provide the foundation for how auditors conduct their work. For CISA exam candidates, understanding these standards is critical because they define the minimum level of acceptable performance and professional responsibilities expected of IS auditors.
ISACA IT Audit and Assurance Standards
ISACA publishes a comprehensive framework of standards, guidelines, and procedures for IS auditing. These are organized into three tiers:
- Standards: Mandatory requirements for IS auditing and reporting. Auditors must comply with these to ensure the quality and consistency of their work.
- Guidelines: Provide guidance on how to apply IS auditing standards. While not mandatory, auditors should consider them when exercising professional judgment.
- Tools and Techniques: Offer examples of procedures an auditor might follow during an engagement. These are practical resources, not requirements.
Key ISACA Standards
Several ISACA standards are particularly important for the CISA exam:
- Audit Charter: Requires that the purpose, responsibility, authority, and accountability of the IS audit function be documented in an audit charter or engagement letter.
- Independence: Mandates that auditors maintain professional and organizational independence in both attitude and appearance.
- Due Professional Care: Requires auditors to exercise due professional care, including observance of applicable professional auditing standards.
- Competence: Auditors must be competent, possessing the skills and knowledge necessary to perform audit work.
- Planning: Each IS audit engagement should be adequately planned to address audit objectives and comply with applicable standards.
- Reporting: Upon completion of audit work, auditors should provide a report that includes findings, conclusions, and recommendations.
International Standards
Beyond ISACA, several international bodies publish standards relevant to IS auditing:
- IIA (Institute of Internal Auditors): Publishes the International Professional Practices Framework (IPPF) that provides guidance for internal audit activities, including IT auditing.
- IFAC/IAASB: The International Auditing and Assurance Standards Board publishes International Standards on Auditing (ISAs) that external auditors follow.
- ISO 27001: Provides requirements for information security management systems and serves as a benchmark for security audits.
Why Standards Matter for CISA
On the CISA exam, you will encounter questions about the hierarchy of standards versus guidelines, the mandatory nature of standards, and how auditors should respond when standards conflict with organizational practices. Remember that standards are always mandatory; guidelines are recommended. Auditors who deviate from standards must be prepared to justify their departure and accept the risk that their work may be questioned.
Practical Application
When planning an IS audit, the auditor should first identify which standards apply to the engagement. This includes ISACA standards, any regulatory requirements (such as SOX or GDPR), and industry frameworks. Mapping these requirements early ensures comprehensive coverage and helps the auditor demonstrate compliance throughout the engagement.