IT Examiner School
Audit Report Review
• Be wary of auditors who rely solely on checklists • Using only regulatory workprograms is not an audit • Absence or lack of workpapers could indicate a poorly performed audit Especially if there are no workpapers showing how ITGCs were reviewed/tested
Signs of a questionable audit:
Audit Findings Tracking and Resolution
A formal tracking system that assigns responsibility and target date for resolution
Timely and formal status reporting
Tracking and reporting of changes in target dates or proposed corrective actions to the Board or Audit Committee
Process to ensure findings are resolved
Independent validation to assess the effectiveness of corrective measures
• Issues and corrective actions from internal audits and independent testing/assessments are formally tracked to ensure procedures and control lapses are resolved in a timely manner.
Made with FlippingBook Digital Publishing Software