Quality Assurance for IS Audit Functions
Understand quality assurance and improvement programs for IS audit functions. Learn internal and external assessment requirements for the CISA exam.
What Is Quality Assurance in IS Auditing?
Quality assurance (QA) for IS audit functions ensures that audit work meets professional standards, delivers value, and continually improves. A formal Quality Assurance and Improvement Program (QAIP) provides both internal and external assessments of the audit function's performance. This is an important CISA exam topic that demonstrates organizational governance over the audit function itself.
Components of a QAIP
A comprehensive quality assurance program includes two types of assessments:
Internal Assessments
Internal assessments are conducted by the audit function itself on an ongoing basis. They include:
- Supervisory review of working papers: Audit managers review the work of their teams to ensure quality, completeness, and compliance with standards.
- Engagement-level quality reviews: After each audit, the engagement is reviewed to verify that objectives were met, evidence was sufficient, and findings were well-supported.
- Performance metrics: Track key indicators such as audit plan completion rates, finding closure rates, customer satisfaction scores, and resource utilization.
- Self-assessments: Periodic evaluations of the audit function's compliance with its charter, policies, and professional standards.
- Continuous improvement activities: Identifying and implementing process improvements based on lessons learned and feedback.
External Assessments
External assessments are conducted by independent parties outside the audit function. According to the IIA Standards and ISACA guidelines:
- External assessments should be performed at least once every five years.
- They may be conducted by a qualified independent assessor or an assessment team from outside the organization.
- The assessment evaluates the audit function's conformance with professional standards, the effectiveness of its processes, and its contribution to organizational governance.
- Results are reported to the audit committee or board of directors.
Key Quality Metrics
IS audit functions typically track several quality metrics:
- Audit plan completion: Percentage of planned audits completed within the period.
- Timeliness: Whether audits are completed and reports issued within established timeframes.
- Finding quality: Are findings well-structured, clearly written, and actionable?
- Stakeholder satisfaction: Feedback from audit clients on the audit process, communication, and recommendations.
- Staff development: Training hours, certifications earned, and competency assessments for audit staff.
- Follow-up effectiveness: Percentage of findings remediated within agreed timeframes.
Benefits of Quality Assurance
- Credibility: A strong QA program demonstrates that the audit function holds itself to the same standards it applies to others.
- Consistency: Ensures uniform quality across engagements and auditors.
- Improvement: Identifies areas where processes, skills, or tools can be enhanced.
- Compliance: Demonstrates conformance with professional standards and regulatory expectations.
CISA Exam Focus
For the CISA exam, know the difference between internal and external assessments and their frequency requirements. The key points to remember are: internal assessments should be ongoing, external assessments should occur at least every five years, results should be communicated to the audit committee, and the Chief Audit Executive is responsible for establishing and maintaining the QAIP. Also understand that the purpose of a QAIP is not to find fault but to drive continuous improvement in the audit function's effectiveness and efficiency.