Second part of article on making IT Audits more effective and value-added ….
The next area that will need to be address by CAEs is ensuring that risk-based audit plans are relevant and that selected audits provide maximum value to senior management. Today’s business environment changes rapidly to adjust to market conditions, evolving legislation and economic forces; and the risk-based audit plan must keep pace with this rapid change if it is to properly identify and assess emerging risks that can impact the achievement of business objectives.
ISACA standards state that appropriate risk assessments approach should be used when developing the overall IS audit plan. Risk should also guide IT auditors in determining priorities for the allocation of resources to provide assurance regarding the state of the IT control processes. This means that risk should drive the IT audit plan and the focus of IT audit resources. IT audit should use a top-down approach that starts with the identification of the business objectives. The next step should be the identification of the key controls required, in both the application system and the business process, to provide assurance for the business objectives. Finally, IT audit should identify the applications where the IT controls need to be tested in order to focus IT audit effort where it is needed most.
IT audit plans also need to lay the groundwork for integrating IT audit expertise within non-IT auditor to ensure that the risks associated with the IT systems are considered when assessing the overall risk in a business process. Conversely, you should also be looking at the risks in the business processes and determining the IT controls that are mitigating these risks.