How to survive an Audit



Similar documents
Managing the Auditor/Client Relationship

February Audit committee performance evaluation

AUDIT COMMITTEE BEST PRACTICES CHECKLIST

Annual Assessment of the External Auditor

Module 2 IS Assurance Services

The Firewall Audit Checklist Six Best Practices for Simplifying Firewall Compliance and Risk Mitigation

Achieve. Performance objectives

Audit programs. Audit program are lists of audit procedures to be performed by audit staff in order to obtain sufficient appropriate evidence.

INTERNATIONAL STANDARD ON ASSURANCE ENGAGEMENTS 3000 ASSURANCE ENGAGEMENTS OTHER THAN AUDITS OR REVIEWS OF HISTORICAL FINANCIAL INFORMATION CONTENTS

SESSION 3 AUDIT PLANNING

LSE Internal Audit procedures (to be read in conjunction with the attached flowchart)

2. Auditing Objective and Structure What Is Auditing?

OBSERVATIONS FROM 2010 INSPECTIONS OF DOMESTIC ANNUALLY INSPECTED FIRMS REGARDING DEFICIENCIES IN AUDITS OF INTERNAL CONTROL OVER FINANCIAL REPORTING

COMPANY LEVEL CONTROLS A PRACTICAL FRAMEWORK

October 20, Sincerely. Anthony Chavez, CIA, CGAP, CRMA Director, Internal Audit Division

INTERNATIONAL STANDARD ON REVIEW ENGAGEMENTS 2410 REVIEW OF INTERIM FINANCIAL INFORMATION PERFORMED BY THE INDEPENDENT AUDITOR OF THE ENTITY CONTENTS

RELEVANT TO ACCA QUALIFICATION PAPER P7 AND PERFORMANCE OBJECTIVES 17 AND 18. Completing the audit

Audit Quality Thematic Review

Risk Management Advisory Services, LLC Capital markets audit and control

Special Purpose Reports on the Effectiveness of Control Procedures

IT audit updates. Current hot topics and key considerations. IT risk assessment leading practices

Managing risks in a Salesforce environment

How Non-profit Boards can Effectively Utilize Committees

3 Terms and definitions 3.5 client organization whose management system is being audited for certification purposes

PIONEER NATURAL RESOURCES COMPANY AUDIT COMMITTEE OF THE BOARD OF DIRECTORS CHARTER

The Value of Vulnerability Management*

Data Analytics Working Group Update

4 Testing General and Automated Controls

Review of an SMSF audit engagement questionnaire

ALLEGIANT TRAVEL COMPANY AUDIT COMMITTEE CHARTER

Division of Insurance Internal Control Questionnaire For the period July 1, 2013 through June 30, 2014

CHARTER OF THE AUDIT COMMITTEE OF THE BOARD OF DIRECTORS OF INTERCONTINENTAL EXCHANGE, INC.

INTERNATIONAL FRAMEWORK FOR ASSURANCE ENGAGEMENTS CONTENTS

LeadingAge Maryland. QAPI: Quality Assurance Performance Improvement

Data Analytics Working Group Update

Compliance Department No. COMP Title: EFFECTIVE SYSTEM FOR ROUTINE MONITORING, AUDITING, AND IDENTIFICATION OF COMPLIANCE RISKS (ELEMENT 6)

Western Australian Auditor General s Report. Information Systems Audit Report

Checklist for Customer Protection Management

EXAM PREPARATION GUIDE

Control Environment Questionnaire

FIRST CITIZENS BANCSHARES, INC. FIRST-CITIZENS BANK & TRUST COMPANY CHARTER OF THE JOINT AUDIT COMMITTEE

Charter of the Audit Committee of the Board of Directors

Chapter 5. Planning the Audit Engagement

Audit Evidence. AU Section 326. Introduction. Concept of Audit Evidence AU

Report on Inspection of PricewaterhouseCoopers LLP. Public Company Accounting Oversight Board

Audit Committee Internal Regulations

Internal Auditing & Controls. Examination phase of the internal audit Module 5. Course Name: Internal Auditing & Controls

Compliance, Audits and Fire Drills: In the Way of Real Security?

J-SOX Compliance Approach Best Practices for Foreign Subsidiaries November 8, 2007

OF CPAB INSPECTION FINDINGS

Sarbanes-Oxley Control Transformation Through Automation

RELEVANT TO FOUNDATION LEVEL PAPER FAU / ACCA QUALIFICATION PAPER F8

How To Write An Impactful Audit Report

EXAM PREPARATION GUIDE

Assuria Auditor The Configuration Assurance, Vulnerability Assessment, Change Detection and Policy Compliance Reporting Solution for Enterprise

Risk committee performance evaluation

Service Organizations and the Internal Audit function conference Institute of Internal Auditors in Israel

INTEGRATED SILICON SOLUTION, INC. CORPORATE GOVERNANCE PRINCIPLES. Effective January 9, 2015

Spillemyndigheden s change management programme. Version of 1 July 2012

Insurance Inspection Manual

Quest InTrust. Change auditing and policy compliance for the secure enterprise. May Copyright 2006 Quest Software

SECURITY RISK MANAGEMENT

The Role of the Board in Enterprise Risk Management

Statement of responsibilities of auditors and audited bodies: Local authorities, NHS bodies and small authorities.

Protection & Compliance are you capturing what s going on? Alistair Holmes. Senior Systems Consultant

Supporting New Data Sources in SIEM Solutions: Key Challenges and How to Deal with Them

Frequently Asked Questions in Identifying and Assessing Prospective Risks

IT Security & Compliance. On Time. On Budget. On Demand.

COMPETENCY FRAMEWORK Trainee Actuary /Actuarial Technician / HEO / SEO

Employee Performance Review

Quality Assurance. Policy P7

Table of Contents. Chapter 3: ESTABLISH A COMMUNICATION PLAN Discussion Questions Documenting the Communication Element...

Securing the Microsoft Cloud

Virginia Commonwealth University School of Medicine Information Security Standard

Weighing in on the Benefits of a SAS 70 Audit for Third Party Data Centers

Abu Dhabi EHSMS Regulatory Framework (AD EHSMS RF)

Lauren Sundararajan, CFE, Internal Audit Manager

Office of Inspector General Department of Defense FY 2012 FY 2017 Strategic Plan

Material Transfers and Material Management and Accounting System (MMAS)

WHITEPAPER. Compliance: what it means for databases

Reporting on Control Procedures at Outsourcing Entities

Auditing Standard 5- Effective and Efficient SOX Compliance

MARLIN MIDSTREAM GP, LLC AUDIT COMMITTEE CHARTER

Performing Audit Procedures in Response to Assessed Risks and Evaluating the Audit Evidence Obtained

Audit Quality Thematic Review

Hunter Hall International Limited

EU Project N MARKT/2007/15/F LOT 2

Post-accreditation monitoring report: The Chartered Institute of Personnel and Development. June 2007 QCA/07/3407

February Sample audit committee charter

The principal purposes of the Audit Committee ( Committee ) of the Board of Directors ( Board ) of CSRA Inc. (the Company ) are to:

ENTERPRISE RISK MANAGEMENT FRAMEWORK

1/21/2014. Agenda. Audit Testing. The Basics of Internal Auditing January 23-24, 2014

The Importance of IT Controls to Sarbanes-Oxley Compliance

Transcription:

How to survive an Audit Eric Tan PwC Harshul Joshi PwC

Objectives Preparation - You can never prepare enough; Mock audit - Running a mock audit Documentation to prove the processes and controls - Documentation is king Is email documentation? How much information to volunteer? - Respond to the point More is more? Liaison between your internal technical folks and the auditor Developing a internal quality program - Peer reviews Collaborating with your external auditors Believe it or not, everybody wants to do the right thing? The devil is in the details - Know when to get the right experts involved. Ensuring objectives and scope are clearly defined.

Type of Audits External Audit (SOX requirements) Internal Audit Compliance and Regulatory based audits (PCI, SOX, FISMA, Vendor based) Technical Assessments (Configuration reviews, Server hardening)

So what s the point? Resource mapping before execution Having the right resources available for the auditors Having the right context and scope Methodologies and Tools

Scoping Technology Areas

Case Study - PCI What are the requirements Preparation Going through the audit Findings Sustaining PCI

Case Study ISO 27001 / 2 What are the requirements Preparation Going through the audit Findings Sustaining

Backing up the procedures How to produce auditable proof? What is a auditable process?

Ensure Sufficient Planning Ensure that scope and objectives are clearly define Avoid scope creep. Schedule and allow time for sufficient involvement, feedback, input and audit team leader and manager Budget sufficient time for execution of audit, allowing time to: Prepare to research and to design tailored questions Plan the meeting to allow sufficient time so that the meeting is not rushed Document findings as soon as possible after the meeting Debrief and plan to corroborate findings and/or perform additional testing Ensure timing with client contacts considering their busy season is likely not yours

Basic Ground Rules for Meetings Ensure meetings are prepared well ahead of time; agenda, meeting objectives, specific detailed questions you want to ask. Learn to always apply professional skepticism and, whenever possible, support the explanations given to us by asking the our clients to show us reports and procedure manuals or other documents used in, or generated by, the performance of the controls. Team composition is critical. Don t go at it on your own. Spread responsibility over the team (e.g. security, ERP, data management). Where appropriate, involve technical specialist involving them as needed during planning, execution and delivering results Document timely, clearly and concisely.

Always Be On The Alert Healthy skepticism means that we do not necessarily assume the honesty of management Be alert to fraud risk indicators and perform specific required fraud inquiries, as necessary Do not rely solely on management representations - corroborate them or use observation, examination and reperformance of evidence of the control so that we do not simply audit by conversation Recognize conflicting information (e.g., contradictory representations from different entity personnel or information that is inconsistent with our own views based on our analytical procedures)

Learn to Ask Probing Questions We should ensure that our inquiries of management are sufficiently detailed. For example, asking a security manager if he reviews a security violation report is insufficient. We need to validate that the control is effective by evaluating corrective actions taken. In this example, appropriate questions might include the following: How is the report reviewed? Is every report reviewed? How long does the review take? How are the items investigated? Are there particular situations to which the manager's attention is directed? Is there a record of the investigation and results? Are those problems being eliminated? Are the resolutions documented? What do you do when you find an error or what are you looking? What kinds of errors have been found? What happened as a result of finding the errors? Are the reports ever not produced, or do reports ever have no entries on them? Has anything ever occurred to suggest the report is not reliable?

Discussing and Presenting Issues Determine where to have your discussions. For example closing meetings vs. during field work. Carefully consider participants in your closing discussions (e.g. executive or managers) are present Determine method of delivery of observations e.g. sharing ahead of time vs. working through the details together. Take into account the behavior of the individual and culture of the client. Consider if this is the first time the individual is undergoing and audit? How is he / she measured on the results? Consider the size and complexity of the client and systems.

Having Successful Meetings Effective interviewing technique includes using open, closed and probing questions, and avoids jargon Generally aim to keep to the agreed time; if you need more time, arrange a new appointment with the client immediately It is important to direct the meeting to avoid unnecessary topics and prevent wasted time Keep focused on what evidence you expect to get (relating to the "show me" meeting agenda) Do not leave follow-up and verification to another meeting Summarize at the end of the meeting to confirm your understanding

Documentation Considerations Ensure sufficient footprint of team leader s review in the audit Audit risks, focus areas and related controls Nature, timing and extent of testing performed (and thus whether we need to perform further testing) Consider whether we have recorded sufficient information where an independent reviewer can follow the thought process taken for the audit. Avoid delegating note-taking responsibilities to junior staff without giving them sufficient briefing beforehand Do not attempting to write up everything that was discussed during the meeting

Case Study 404 Sarbanes Oxley Have all systems supporting financially significant process been identified? Have reports supporting both internal controls and financial statements been identified, tested for completeness and accuracy? How much test testing do we really need to do when an exception or error is found? Have we considered mitigating controls?

Audit approach Internal Controls The relationship with the Audit Approach Weak Evidence obtained during testing Control Environment, Risk Assessment, Information and Communication and Monitoring of Controls Strong Higher Evidence required during testing control activities Lower Weak Evidence obtained during testing Control Activities Strong Higher Substantive audit evidence required Lower

Case Study System Implementation Assessments $300m implementation of supermarket system. Have all areas in scope been identified and risk ranked? Ensuring continuous buy-in from various stakeholders is critical to the success of an audit. Have we validated inquiry procedures with evidence of execution controls? What is the basis of our assessment? Work-program? Framework utilized?

Have all procedures in the step been addressed? Final Consideration Critical Self Review Were the audit objectives of the planned and executed procedures achieved? If exceptions were noted during testing, has an appropriate management letter comment been provided? Has consideration been given to how findings in a particular area impact the company? Are there any issues or questions that need to be discussed with a more senior team member immediately?