ISACA ITAF (General Standards/Guidelines) Flashcards
Standards: Audit Charter (1001)
- 1) The IT audit and assurance function shall document the audit function appropriately in an audit charter, indicating purpose, responsibility, authority and accountability.
- 2) The IT audit and assurance function shall have the audit charter agreed upon and formally approved by those charged with governance and oversight of the audit function, e.g., the board of directors and/or the audit committee.
- 3) The IT audit and assurance function shall communicate the audit charter to executive/senior management. Also, relevant elements of the audit charter shall be shared with groups being audited at entrance meetings and/or through engagement letters.
- 4) Through review of the audit charter on a periodic basis, the audit and assurance function’s responsibilities, as reflected in the audit charter, shall remain aligned with the enterprise’s mission and strategies. Immediate review of the audit charter is warranted should the enterprise’s mission or strategies change, or if the audit function’s responsibilities change.
Guidelines: Audit Charter (1001) - What should an Audit Charter document?
An audit charter shall document the IT audit and assurance function’s:
- Independence, code of ethics and standards
- Purpose, responsibility, authority and accountability
- Protocols that the IT audit and assurance practitioner will follow in the performance of engagements, including but not limited to communication and escalation
- Roles and responsibilities of the auditee during the IT audit or assurance engagement
- The IT audit and assurance function’s role in reporting irregularities and illegal acts
Guidelines: Audit Charter (1001) - What is the Purpose of the Audit Function?
The purpose of the audit function is to:
Evaluate and test the design and execution of controls implemented by management.
Guidelines: Audit Charter (1001) - What is the Responsibility of the Audit Function?
The responsibility of the audit function is to:
Add value to the enterprise, ensuring that organizational perspectives such as strategy, mission and regulatory/compliance expectations are integrated in its work, and to abide by professional expectations (e.g., ethics, professional development).
Guidelines: Audit Charter (1001) - The Audit Charter should contain the following sections to facilitate the Audit Function’s Responsibilities..
- Independence: Independence requirement for the audit function and practitioners. Independence should be assessed periodically (at least annually). Results of independence assessment and potential impairments of independence should be reported to Board of Directors and/or Audit Committee.
**Should also establish whether the practitioners are permitted to perform nonaudit services or roles, and the broad nature/timing/extent of such services or roles to ensure that objectivity/independence are not impaired*
- Relationship with External Audit Firms: Details the audit function’s reliance strategy with the external auditor (meeting with them to coordinate, providing access to workpapers/evidence, considering the work planned by external auditors when drafting the audit plan for the coming period)
- Auditee’s Expectations: Detail the services and deliverables the auditees can expect from the audit function and practitioners (description of identified problems/consequences/possible resolutions; may also note SLA for delivering final report to management, response to auditee complaints, reporting process, agreement with management on findings, etc.)
- Auditee Requirements: All auditees are required to make themselves available and assist the audit function in fulfilling their assigned responsibilities.
- Abide by Professional Standards
- Compliance: Compliance with standards that detail the requirements with which the audit function will adhere to.
Guidelines: Audit Charter (1001) - What is the Authority of the Audit Function?
How is this detailed in the Audit Charter?
Authority of the audit function should contain the following sections:
- Right of Access: Right of Access to relevant information, systems (including logs/activities built into the systems), personnel, and locations.
The Audit Function has authorized access to any and all records/documentation/systems/locations/etc. necessary to perform the audit engagement. Can seek assistance from Executive Management in obtaining such access.
The Audit Function has the authority to seek any information from an employee/consultant/contractor when performing the audit engagement.
- Limitations of Authority (if any)
- Processes to be Audited: Processes that the audit function is authorized to audit - i.e., the audit function is free to determine that processes it will audit, based on the risk-based audit plan.
Guidelines: Audit Charter (1001) - What is the Accountability of the Audit Function?
How is this detailed in the Audit Charter?
- Distributing Written Communications: i.e. distributing reports for audits (and memoranda for non-audit engagements) to the appropriate stakeholders and the Board of Directors and/or the Audit Committee.
- Monitoring and Reporting of Management’s Progress: i.e. monitoring of management’s agreed-on implementations/corrective actions.
- Reporting of the Audit Function’s Performance Metrics: i.e. reporting on performance relative to the audit plan and budget to the Board of Directors and/or the Audit Committee.
- Reporting to Those Charged with Governance/Oversight of the Audit Function: i.e. reporting on the audit function’s independence and any potential impairments.
- Quality Assurance Process: That establishes an understanding of auditee needs/expectations relevant to the audit function (i.e. interviews, surveys, etc.). These needs should be evaluated against the Audit Charter.
- Staffing Rules for Audit Engagements: Reliance on the Audit Charter permitting non-audit services (i.e. consulting) to ensure that independence and objectivity are not impaired.
Also establishes the minimum time period that must elapse before practitioners can participate on audit engagements in areas they performed non-audit/consulting services.
Penalties when the audit function fails to carry out its responsibilities.
Frequence and communication channels through which the audit function will communicate with the auditees.
Standards: Organizational Independence (1002)
- 1) The audit function shall (must) be free from conflicts of interest and undue influence (influence by which a person is induced to act otherwise than by their own free will) in all matters related to audit and assurance engagements. Any impairment of independence (in fact or appearance) is identified and disclosed to the appropriate parties.
- 2) The audit function shall (must) have a functional reporting relationship (e.g., reporting to the board of directors) that supports the function’s ability to remain free from undue influence.
- 3) The audit function shall (must) have an administrative reporting relationship that supports the function’s unhindered performance of its responsibilities (e.g., scope of engagement, fieldwork or reporting).
Functional Reporting Relationship: Shows the “chain of command” so to speak at the functional level: who makes decisions, and who executes, even if one is not the formal “boss” of the other.
Administrative Reporting Relationship: Shows the boss/subordinate relationship in its formalistic structure, without regard to function. In some organization, a person may be formally attached to a department without having anything to with them functionally.
Guidelines: Organizational Independence (1002) - What should the Audit Function’s position be in the enterprise/business?
The Audit Function must have a position in the business that allows it to perform its responsibilities without interference.
This can be achieved by:
- In the Audit Charter, establishing in the audit function as an independent function/department outside of operational departments. The Audit Function should not be assigned any operational responsibilities/activities.
- Ensuring that the Audit Function reports to a level within the business that allows it to achieve organization independence (i.e. NOT reporting to the head of an operational department).
Guidelines: Organizational Independence (1002) - What roles should the Audit Function avoid performing in the enterprise/business?
- The Audit Function should avoid performing non-audit roles in IT initiatives that require assumption of management’s responsibilities (because it could impair future independence).
- The Audit Function’s independence could be impaired if an auditor is scheduled to plan/participate on an engagement in an area in which the auditor previously had direct management responsibility (if the defined acceptable timeframe has not yet passed).
Guidelines: Organizational Independence (1002) - Who should the Audit Function report to in the enterprise/business?
WHAT should the Audit Function report to those charged with governance for input/approval?
The Audit Function should report to a level that allows it to act with complete organizational independence.
Independence should be defined in the Audit Charter and confirmed by the Board of Directors and those charged with governance on a regular basis (at least annually.)
To ensure organizational independence, the following should be reported to those charged with governance (i.e. Board of Directors) for their input and/or approval:
- Audit resource plan & budget
- Risk-based audit plan
- Performance follow-up performed by the Audit Function on audit activity
- Follow-up of significant scope/resource limitations
Standards: Auditor Objectivity (1003)
IT audit and assurance practitioners shall be objective in all matters related to audit and assurance engagements.
Practitioners (Auditors) are required to identify, evaluate, and address potential threats to objectivity or independence.
Guidelines: Auditor Objectivity (1003) - What should an auditor do when appropriate safeguards are not available/cannot be applied to eliminate objectivity threats or reduce threats to an acceptable level?
The practitioner (auditor) should either (1) eliminate the circumstance or relationship creating the threats, or (2) decline or terminate the audit or assurance engagement.
If the auditor cannot decline or terminate the engagement, appropriate disclosure of the impairment to objectivity or independence must be made to those charged with governance (i.e. Board of Directors), and included in any report resulting from the engagement.
Guidelines: Auditor Objectivity (1003) - What factors/situations may create a threat to an auditor’s objectivity?
1) Self-Interest: i.e. financial interest influences the auditor’s professional judgement.
2) Self-Review: The threat that auditors will not appropriately evaluate results of previous judgements made/service performed, which the auditor relies upon when forming judgements in the current engagement.
3) Advocacy: Auditor promotes an auditee’s (i.e. operational team member’s) position to the point that professional objectivity is compromised.
4) Familiarity: Due to a long or close relationship with an auditee (auditor becomes too sympathetic to the interest of the auditee and is then too accepting of their work/views/arguments).
5) Intimidation: Actual and/or perceived pressures (including auditee attempts to exercise undue influence on auditors).
6) Bias: Political, ideological, social, psychological, other convictions
7) Management Participation: Resulting from the auditor taking on the role of management/performing management functions on behalf of the entity undergoing an audit or assurance engagement.
Guidelines: Auditor Objectivity (1003) - When should an auditor specifically NOT perform non-audit services?
An auditor should not perform nonaudit services or roles in areas where it is likely that a current or future audit or assurance engagement is planned and would likely be performed by the same
auditor.
If the entity has no other recourse (i.e., engaging an alternative internal or external
resource), the auditor’s involvement in the non-audit service should be approved by the chief audit executive (or VP/director of audit) and by those formally charged with governance and oversight of the audit function (e.g., the board of directors and/or the audit committee).
Guidelines: Auditor Objectivity (1003) - What safeguards can be implemented to reduce threats to objectivity?
Examples of safeguards that can be considered by practitioners in response to identified threats are:
Internal procedures within the enterprise and audit function that ensure objective choices in assigning engagements, (e.g., the practitioner does not audit an area over which the practitioner previously had direct management responsibilities)
Assigning management and staff from outside the audit function, such as borrowing staff from another function, division or external organization to supplement practitioners
Periodic rotation in IT audit assignments, reducing the practitioner’s familiarity with people in the assigned areas
Adequate hiring practices, such as background screening and vetting, to improve the likelihood that practitioners are free from bias or conflicts of interest (i.e., competing professional or personal interests)
Removing an individual from an engagement should that individual’s interests or relationships pose a threat to objectivity
Appropriate documentation and reporting requirements, ensuring that assessment of professional independence is documented in the work papers and consistently reported in deliverables
Assigning an independent resource—from within the audit function or other sources referenced previously—to carry out a peer review or to act as an independent observer during planning, fieldwork and reporting
Having an external review of the reports, communications or information produced by practitioners by a recognized third party, e.g., accepted authority in the field or independent specialist