-
29
pages
-
English
-
Documents
Description
INFORMATION SYSTEMS RISK FACTORS, RISK ASSESSMENTS, AND AUDIT PLANNING DECISIONS Jean C. Bedard Cynthia Jackson Both at: College of Business Administration 404 Hayden Hall Northeastern University Boston, MA 02115 Lynford Graham Director of Audit Policy BDO Seidman LLP 330 Madison Avenue 10th Floor New York, NY 10017 Acknowledgments: The authors thank the public accounting firms providing advice and the time of their personnel in support of this research. We also appreciate helpful comments from Kathy Hurtt, Ganesh Krishnamoorthy, and Margarita Lenk. INFORMATION SYSTEMS RISK FACTORS, RISK ASSESSMENTS, AND AUDIT PLANNING DECISIONS ABSTRACT In this study, we examine systems risk factors identified by external auditors for a sample of their actual audit clients. Specifically, we study two important areas of information systems risk: the risk of breaches in system security and the risk that the information provided by the system is inadequate. To perform the study, we examine the nature of systems risk factors identified, and relate those risk factors to the auditors’ systems risk assessments and audit test plans. We find that systems risk factors are identified for a high proportion of clients, most frequently including issues of management style and competence, maintaining system currency, and adequacy of documentation. Risk assessments are significantly associated with the number of risk factors ...
-
Publié par
-
Langue
English