IMPLICATIONS OF IT RISKS AND CONTROLS ON INTERNAL AUDITING

Autori

  • Mile Stanišić Univerzitet Singidunum, Beograd

DOI:

https://doi.org/10.5937/Rev2090061S

Ključne reči:

interal IT audit, IT risks, IT controls, GTAG guides, standards of internal auditing

Apstrakt

The implications of IT for internal auditors were addressed. IT has significantly changed the competencies internal auditors must possess and how they conduct their work. An internal audit function’s capacity to provide valueadding assurance and consulting services is highly dependent on its IT expertise. All internal auditors need to have a baseline of technology knowledge and skills. This includes automated workpaper systems, data analytics, and IT terminology. The internal audit function can provide insights as to how the organization can best leverage advances in IT.

Internal audit functions need to understand their organizations’ information systems and the IT risks that threaten the achievement of their organizations’ business objectives. They also must be proficient in assessing their organizations’ IT governance, risk management, and control processes and be able to effectively apply technology based audit techniques.

Reference

The Institute of Internal Auditors (IIA), International standards for the professional practice of internal auditing (Standards), IIA, USA, 2017, 11

GAIT Methodology, A risk-based approach to assessing the scope of IT general controls, The Institute of Internal Auditors, 2007, 18

Global Technology Audit Guide, Information Technology Risk and Controls, The Institute of Internal Auditors, 2012, 10-12

Global Technology Audit Guide, IT Essentials for Internal Auditors, The Institute of Internal Auditors, 2020, 11-21

Global Technology Audit Guide, Management of IT Auditing, The Institute of Internal Auditors, 2013, 8-9

Global Technology Audit Guide, Developing the IT Audit Plan, The Institute of Internal Auditors, 2008, 12-15

Global Technology Audit Guide, Auditing IT Projects, The Institute of Internal Auditors, 2009, 3-7, 14, 16-17

Global Technology Audit Guide, Auditing User-developed Applications, The Institute of Internal Auditors, 2010, 6-11

Global Technology Audit Guide, Business Continuity Management, The Institute of Internal Auditors, 2008, 5, 8-11.

Global Technology Audit Guide, Assessing Cybersecurity Risk, The Institute of Internal Auditors, 2008, 2-22

Global Technology Audit Guide, Identity and Access Management, The Institute of Internal Auditors, 2007, 1-2, 4, 12-16

Global Technology Audit Guide, Auditing Application Controls, The Institute of Internal Auditors, 2007, 4-10

The IIA Practice Guide, Auditing Privacy Risks, The Institute of Internal Auditors, 2012, 2, 5-6, 9-10, 13-21

Global Technology Audit Guide, Fraud Prevention and Detection in an Automated World, The Institute of Internal Auditors, 2009, 2-8, 11-13, 16-17

Global Technology Audit Guide, Information Technology Risk and Controls, The Institute of Internal Auditors, 2012, 16

Global Technology Audit Guide, Continuous Auditing: Implications for Assurance, Monitoring, and Risk Assessment, The Institute of Internal Auditors, 2005, 7

##submission.downloads##

Objavljeno

2020-06-30

Broj časopisa

Sekcija

Pregledni naučni rad