D1IS Auditing Process

IS Auditing Process: Common Mistakes

Assuming the IS auditor should fix control weaknesses directly.

The auditor's role is to evaluate and report, not to implement controls. Fixing issues creates a self-review threat and compromises independence. ISACA standards require auditors to maintain objectivity throughout the engagement.

Correct approach: The auditor should report findings and recommend corrective actions. Management is responsible for implementing the fixes.

Selecting audit areas based solely on management requests.

A risk-based audit approach requires that audit resources be allocated to the areas of highest risk. Relying only on management requests may ignore critical risk areas and violate professional standards. ISACA mandates risk-based audit planning.

Correct approach: Use a formal risk assessment to prioritize audit areas. Management requests should be one input among several, not the sole driver.

Treating all audit evidence as equally reliable.

Evidence varies in reliability depending on its source and nature. Evidence obtained directly by the auditor (such as observation or re-performance) is more reliable than evidence provided by the auditee. Documentary evidence from external sources is generally stronger than internal documents.

Correct approach: Evaluate evidence based on its source, nature, and independence. Prioritize evidence gathered firsthand or from independent third parties.

Believing that compliance testing alone is sufficient to evaluate controls.

Compliance (adherence) testing confirms that controls exist and are being followed, but it does not assess whether the controls are effective at mitigating risk. Substantive testing is needed to verify the integrity of actual data and transactions.

Correct approach: Combine compliance testing with substantive testing. Compliance testing checks adherence to procedures; substantive testing verifies the accuracy and completeness of outcomes.

Issuing audit findings without providing supporting evidence.

Audit findings must be documented with sufficient, relevant, and reliable evidence. Without proper documentation, findings can be challenged by management and may not hold up under review. ISACA standards require that conclusions be based on appropriate evidence.

Correct approach: Document all findings with supporting evidence, including workpapers, screenshots, logs, and test results. Evidence should be organized and traceable.

Confusing inherent risk with residual risk.

Inherent risk is the risk level before any controls are applied. Residual risk is the risk that remains after controls are in place. Confusing these leads to incorrect risk assessments and inappropriate audit conclusions.

Correct approach: Assess inherent risk first, then evaluate the effectiveness of existing controls to determine residual risk. Residual risk should fall within the organization's risk appetite.

Skipping the follow-up phase after issuing audit recommendations.

Without follow-up, there is no assurance that management has implemented corrective actions. Unresolved findings may leave the organization exposed to the same risks. Follow-up is a required part of the audit lifecycle.

Correct approach: Schedule and perform follow-up reviews to verify that management has implemented agreed-upon corrective actions within the committed timeframe.

Assuming that a signed audit charter is optional.

The audit charter formally defines the authority, scope, and responsibility of the IS audit function. Without it, the audit team lacks organizational backing and may face resistance. ISACA standards require a documented and approved charter.

Correct approach: Ensure the audit charter is approved by senior management or the board. It should clearly define the audit function's authority, independence, and reporting lines.

Relying on automated tools without validating their output.

Computer-assisted audit techniques (CAATs) and other tools can produce incorrect results if configured improperly or if the underlying data is flawed. Blindly trusting tool output introduces the risk of drawing incorrect conclusions.

Correct approach: Validate the accuracy of automated tool output through independent verification. Test tools on known data sets before relying on their results for audit conclusions.

Reporting only negative findings and ignoring positive observations.

A balanced audit report that includes areas of strength provides a more accurate picture of the control environment. Reporting only weaknesses can damage relationships with management and reduce the credibility of the audit function.

Correct approach: Include both positive observations and areas for improvement in audit reports. Acknowledge effective controls alongside identified weaknesses.