Learning
objective |
Activity |
Resources |
In class Tuesday November 6 |
|
- Develop assurance
objectives for risks of information systems.
- Design assurance
procedures.
- Communicate assurance
results.
- Collaborate with
others to achieve these objectives.
|
Practice
of IT auditing
Interview auditors
from PriceWaterhouseCoopers on SOX compliance and the practice of IT audit:
Chris Bowler, Jason Li, and Zenny Bowry
-
Some starting
points:
- How has financial
auditing and IT auditing changed due to SOX?
- Are companies
getting value from SOX?
- Are SOX requirements
likely to be changed?
- What skills
does an auditor need for SOX work?
|
SOX
experiences
- Katz, D. M. 2006.
A
tough act to follow. CFO Magazine (March): 65-70.
- Shaw, H. 2006.
The
trouble with COSO. CFO Magazine (March): 75-77.
- Stuart, A. 2006.
Serenity
now! CFO Magazine (March): 79-83.
- Wagner, S., and
L. Dittmar. 2006. The
unexpected benefits of Sarbanes-Oxley. Harvard Business Review
(April): 133-140.
- O'Sullivan, K.
2006. The
case for clarity. CFO Magazine (September): 65-69.
|
|
- Develop assurance
objectives for risks of information systems.
- Design assurance
procedures.
|
Examine
the potential roles of continuous auditing
- What is continuous
auditing? Nehmer;
Vasarhelyi/Halper. What is
required to make continuous monitoring and auditing feasible?
- Why are auditor-defined
rules (heuristics)
needed for continuous monitoring and auditing?
- What would continuous
monitoring look like? Consider this example of monitoring payables with
Oversight Systems software at American
Electric Power
- What role might
continuous assurance have with respect to the Sarbanes-Oxley Act of
2002 (SOX) Section 404? Are CPAs
and IS auditors
interpreting the role of continuous assurance the same way?
- How can digital
analysis be useful in auditing?
- Internal
auditing
- Analytical
procedures
- What about continuous
auditing accounts for interest in it with respect to SOX?
- Process improvement
payoff related to Sarbanes Oxley compliance due to continuous auditing:
Business Finance Magazine Nov.
2005
- Efficiencies
required for Sarbanes Oxley and how continuous auditing will play
a role
- Business
Finance Magazine Dec.
2004
- eWeek
Aug.
5, 2005
- How could continuous
auditing be employed to avoid a rogue
trader (link replaced 11/15)?
- What about real-time
financial reporting prompts interest in continuous auditing?
- Why do continuous
monitoring and auditing require formalizability?
|
Continuous
monitoring and auditing:
- Vasarhelyi/Halper
- Nehmer
Digital analysis:
- Internal
auditing
- Analytical
procedures
Uses for continuous
monitoring:
- Monitor payables
with Oversight Systems
software: American
Electric Power
- Improve processes:
Nov.
2005
- Avoid a rogue
trader (link replaced 11/15)
- Support real-time
financial reporting
- Monitor business
processes
|
- Develop assurance
objectives for risks of information systems.
- Design assurance
procedures.
|
PC-Now
case
Consider PC-Now Company's
procure-to-pay process:
- Role of controls
- Which controls
support which financial statement assertions for cash and accounts
payable balances:
- Existence
- Completeness
- Valuation
- Rights/obligations
- Which of the
controls in 1 would be considered key controls for SOX compliance?
- Which controls
support operational effectiveness and efficiency but would not be
considered key controls for SOX compliance?
- Which controls
seem to be superfluous? Why?
- Proof of concept:
Implementation as a continuous audit
- For the non-superfluous
controls, which ones seem sufficiently formalizable for continuous
auditing?
- For the controls
in 2.1, what else is required to implement them for continuous auditing?
|
PC-Now
procure-to-pay process
Modeling internal
control:
- Krishnan
et al. 2005. On data reliability assessment in accounting information
systems. Information Systems Research 16(3): 307-326
|