-
3
pages
-
English
-
Documents
Description
Copyright © 2006 ISACA. All rights reserved. www.isaca.org.Optimizing Controls to Test as Part of a Risk-based Audit StrategyBy Mukul Pareek, CISA, ACA, AICWAIn a risk-based audit, controls that address specific audit cases, a particular control may be designed to take care of onlyrisks are identified and tested. The process normally begins one risk. In others, it will cover a variety of risks. Therefore, itwith the identification of what can go wrong or risk statements is possible to express the relationship between risks andthat could prevent the achievement of the desired audit controls in a matrix (see figure 1).objectives, and proceeds to listing control objectives andultimately preparing a work plan for testing the controls thatFigure 1—Risks and Controls Matrixaddress these risks.In practice, risks and controls are rarely related by simpleone-to-one relationships. Often one control may addressABCDEFmultiple risks, part of one or more risks, or any combinationthereof. In real-life situations where risks number into manyRiskshundreds with an equally intimidating number of controls withcomplex interrelationships, it becomes difficult for the auditor RnR1 R2 R3 R4 …1to decide which combination of controls to test to minimize the2 C1total audit effort required to address all the risks. With the 3 C2scope of audits and audit approaches coming under greater 4 C3scrutiny as part of external audits and internal Sarbanes-Oxley5 C4section 404 ...
-
Publié par
-
Langue
English