D1IS Auditing Process

IS Auditing Process: Glossary

Analytical Review
An audit procedure that evaluates financial or operational data through analysis of plausible relationships among both financial and nonfinancial data.
Audit Charter
A document approved by senior management and the board that defines the purpose, authority, scope, and responsibility of the internal audit function.
Audit Evidence
Information collected by an auditor to support audit findings and conclusions. It should be sufficient, relevant, and reliable.
Audit Plan
A detailed outline describing the scope, objectives, timing, and resource allocation for a specific audit engagement.
Audit Risk
The risk that an auditor may issue an incorrect opinion on the subject matter being audited. It is composed of inherent risk, control risk, and detection risk.
Audit Trail
A chronological record of system activities that enables the reconstruction and examination of a sequence of events in a transaction from initiation to output.
Audit Universe
The complete list of all auditable entities within an organization, used to develop risk-based audit plans.
CAAT (Computer-Assisted Audit Techniques)
Tools and techniques such as generalized audit software, test data, and parallel simulation used by auditors to automate audit procedures.
Compliance Testing
Audit testing that gathers evidence to determine whether controls are being applied in a manner consistent with management policies and procedures.
Control Objective
A statement of the desired result or purpose to be achieved by implementing control procedures in a particular process.
Control Risk
The risk that a material error exists and will not be prevented or detected in a timely manner by internal controls.
Control Self-Assessment (CSA)
A methodology used to review key business objectives, risks, and controls. It involves business unit management and staff in assessing controls.
Corroborative Evidence
Evidence obtained from a different source that confirms or supports the initial audit findings.
Detection Risk
The risk that audit procedures will fail to detect a material error or misstatement that exists in the subject matter.
Engagement Letter
A formal document that defines the terms and scope of an audit engagement between the auditor and the auditee.
Evidence Hierarchy
The ranking of audit evidence by reliability, from most to least reliable: physical examination, confirmation, documentation, observation, and inquiry.
Follow-Up Audit
An audit conducted to verify that agreed-upon corrective actions from a prior audit have been implemented effectively.
Generalized Audit Software (GAS)
Software used by auditors to access and analyze data from various systems, perform calculations, and generate reports for audit purposes.
Inherent Risk
The risk level or exposure to a material error without considering the effect of internal controls. It is influenced by the nature of the business and the complexity of transactions.
Integrated Audit
An audit approach that combines financial, operational, and compliance audit procedures to provide a comprehensive assessment of controls.
ISACA Code of Professional Ethics
A set of principles and guidelines that ISACA members and certification holders must follow, including supporting professional standards and acting with integrity.
Materiality
The significance of an item or event in the context of the overall audit. An error is material if its knowledge would influence the decision of the audit report user.
Risk-Based Auditing
An audit methodology that focuses resources on areas of highest risk to the organization, rather than auditing all areas equally.
Sampling
The process of selecting a subset of items from a population for testing. It can be statistical (random) or judgmental (nonstatistical) and is used when testing 100% of items is impractical.
Substantive Testing
Audit procedures designed to detect material errors or misstatements in account balances, transactions, or data. These tests verify accuracy and completeness of information.
Test Data Method
An audit technique that uses dummy transactions to verify that system controls function correctly. The auditor processes fabricated data through the production system.
Variable Sampling
A statistical sampling technique used to estimate the monetary value or quantity of a population, commonly applied in substantive testing.