11
IT Audit Challenges V.Jawahar B.Com(Hons); FCA; Grad.CWA; ISA CISA; CISSP; CISM

V.Jawahar B.Com(Hons); FCA; Grad.CWA; ISA CISA; CISSP; CISM

Embed Size (px)

Citation preview

Page 1: V.Jawahar B.Com(Hons); FCA; Grad.CWA; ISA CISA; CISSP; CISM

IT Audit ChallengesV.Jawahar

B.Com(Hons); FCA; Grad.CWA; ISACISA; CISSP; CISM

Page 2: V.Jawahar B.Com(Hons); FCA; Grad.CWA; ISA CISA; CISSP; CISM

IntroductionDeveloping an Audit Plan is one of the

weakest links in the IT audit processAssessing risks in every domain of business

should be the starting point for every audit. Don’t let others dictate what should be audited.

To develop and audit plan, it is vital to do a company wide risk assessment.

Page 3: V.Jawahar B.Com(Hons); FCA; Grad.CWA; ISA CISA; CISSP; CISM

Heightened expectations from management – high level of service and low cost.

Gain an understanding of the IT environment

Page 4: V.Jawahar B.Com(Hons); FCA; Grad.CWA; ISA CISA; CISSP; CISM

IT Audit Plan Development Process Understand the BusinessDefine IT UniversePerform Risk AssessmentFormulate Audit Plan

Page 5: V.Jawahar B.Com(Hons); FCA; Grad.CWA; ISA CISA; CISSP; CISM

Understand the BusinessOrganizational Uniqueness Operating Environment & structure IT support model �

Degree of system and geographic centralization Types of technologies deployed Degree of customization Policies and standards Degree of Regulation and Compliance Degree of outsourcing Degree of operational standardization

Page 6: V.Jawahar B.Com(Hons); FCA; Grad.CWA; ISA CISA; CISSP; CISM

Level of Reliance on Technology

Page 7: V.Jawahar B.Com(Hons); FCA; Grad.CWA; ISA CISA; CISSP; CISM

Defining IT UniverseExamining the Business ModelRole of Supporting TechnologiesAnnual Business PlansCentralised and Decentralised IT FunctionsIT Support ProcessesRegulatory CompliancesAudit Subject Areas

Page 8: V.Jawahar B.Com(Hons); FCA; Grad.CWA; ISA CISA; CISSP; CISM

Business ApplicationsAssessing Risks

Page 9: V.Jawahar B.Com(Hons); FCA; Grad.CWA; ISA CISA; CISSP; CISM

Performing Risk Assessment Risk Assessment ProcessRanking RiskLeading IT Governance Frameworks

Page 10: V.Jawahar B.Com(Hons); FCA; Grad.CWA; ISA CISA; CISSP; CISM

Formalising IT Audit PlanAudit Plan ContextStakeholders RequestsAudit FrequencyAudit Plan PrinciplesThe IT Plan ContentIntegration of the IT Audit PlansValidating the Audit planThe Dynamic Nature of the IT Audit PlanCommunicating, Gaining Executive Support,

and Obtaining Plan Approval

Page 11: V.Jawahar B.Com(Hons); FCA; Grad.CWA; ISA CISA; CISSP; CISM

Thank You