|
1 Introduction: Objectives, Focus and Description of the Text |
|
|
1 | (8) |
|
Part I Corporate Governance and the Audit Process |
|
|
|
2 Responsibilities, Regulations, Control Frameworks |
|
|
9 | (22) |
|
Responsibility of External Audit Firms |
|
|
10 | (6) |
|
|
11 | (1) |
|
|
12 | (1) |
|
|
13 | (1) |
|
|
13 | (1) |
|
|
14 | (1) |
|
|
14 | (2) |
|
Responsibilities of the PCAOB |
|
|
16 | (1) |
|
Responsibilities of the Board of Directors (BOD) |
|
|
16 | (1) |
|
Responsibilities of the Audit Committee |
|
|
16 | (2) |
|
Responsibilities of Senior Management |
|
|
18 | (1) |
|
Internal Auditor Responsibilities |
|
|
18 | (3) |
|
Responsibilities of First Line Managers |
|
|
21 | (2) |
|
|
23 | (1) |
|
|
24 | (3) |
|
|
27 | (1) |
|
|
28 | (1) |
|
|
28 | (1) |
|
|
28 | (2) |
|
|
30 | (1) |
|
|
31 | (12) |
|
|
32 | (1) |
|
|
33 | (2) |
|
|
35 | (2) |
|
|
37 | (1) |
|
|
37 | (1) |
|
|
38 | (1) |
|
|
39 | (4) |
|
|
43 | (16) |
|
|
44 | (2) |
|
|
46 | (3) |
|
|
49 | (2) |
|
|
51 | (1) |
|
|
52 | (1) |
|
|
53 | (1) |
|
|
54 | (1) |
|
|
54 | (5) |
|
|
59 | (14) |
|
|
59 | (2) |
|
Recommendation and Responses |
|
|
61 | (2) |
|
|
63 | (2) |
|
|
65 | (1) |
|
|
66 | (1) |
|
|
67 | (1) |
|
|
68 | (1) |
|
|
68 | (5) |
|
Part II Controls Overview |
|
|
|
6 Types of Audits and Controls |
|
|
73 | (24) |
|
|
73 | (3) |
|
|
76 | (3) |
|
|
79 | (2) |
|
|
81 | (1) |
|
|
82 | (5) |
|
|
87 | (1) |
|
|
88 | (1) |
|
|
89 | (1) |
|
|
89 | (1) |
|
|
90 | (1) |
|
|
90 | (1) |
|
|
91 | (1) |
|
|
92 | (1) |
|
|
92 | (1) |
|
|
93 | (2) |
|
|
95 | (2) |
|
7 Administration Controls |
|
|
97 | (18) |
|
|
97 | (6) |
|
|
103 | (3) |
|
|
103 | (1) |
|
Definitions and Abbreviations |
|
|
103 | (1) |
|
|
104 | (1) |
|
|
104 | (1) |
|
Examples of Client Responsibilities |
|
|
104 | (1) |
|
Examples of Service Provider Responsibilities |
|
|
104 | (1) |
|
|
105 | (1) |
|
|
105 | (1) |
|
Version Details and Document Change History |
|
|
105 | (1) |
|
|
106 | (1) |
|
Password Controls and User ID Administration |
|
|
106 | (1) |
|
|
107 | (1) |
|
|
108 | (1) |
|
|
109 | (2) |
|
|
111 | (1) |
|
|
111 | (1) |
|
|
112 | (2) |
|
|
114 | (1) |
|
|
115 | (16) |
|
|
116 | (1) |
|
|
117 | (2) |
|
|
119 | (4) |
|
Proprietary, Confidential, and Personal Information |
|
|
123 | (2) |
|
|
125 | (2) |
|
|
127 | (1) |
|
|
127 | (1) |
|
|
128 | (1) |
|
|
128 | (2) |
|
|
130 | (1) |
|
9 System and Application Access Controls |
|
|
131 | (22) |
|
|
131 | (5) |
|
|
136 | (3) |
|
|
139 | (7) |
|
|
146 | (1) |
|
|
147 | (1) |
|
|
148 | (1) |
|
|
148 | (3) |
|
|
151 | (2) |
|
|
153 | (18) |
|
|
154 | (2) |
|
|
156 | (2) |
|
|
158 | (4) |
|
|
162 | (1) |
|
Business Recovery and Continuity |
|
|
163 | (2) |
|
|
165 | (1) |
|
|
166 | (1) |
|
|
167 | (1) |
|
|
168 | (1) |
|
|
169 | (2) |
|
|
171 | (36) |
|
|
173 | (1) |
|
|
173 | (2) |
|
Separation of Duties in IT |
|
|
175 | (6) |
|
IT Separation of Duties Matrix |
|
|
181 | (3) |
|
Accounting Separation of Duties |
|
|
184 | (3) |
|
|
184 | (3) |
|
Example I of Segregation of Duties Matrix for Revenue and Accounts Receivable |
|
|
187 | (1) |
|
Example II-Segregation of Duties Matrix for Revenue and Accounts Receivable |
|
|
188 | (3) |
|
Purchasing and Accounts Payable |
|
|
188 | (3) |
|
Example I-Segregation of Duties Matrix for Purchasing and Accounts Payable |
|
|
191 | (1) |
|
Example II-Segregation of Duties Matrix for Purchasing and Accounts Payable |
|
|
192 | (1) |
|
Human Resources Separation of Duties |
|
|
192 | (2) |
|
Payroll Separation of Duties Matrix |
|
|
194 | (1) |
|
|
195 | (2) |
|
Inventory Managment Separation of Duties |
|
|
197 | (1) |
|
Financial Functions Separation of Duties |
|
|
197 | (4) |
|
|
200 | (1) |
|
|
201 | (1) |
|
|
202 | (1) |
|
|
203 | (1) |
|
|
203 | (2) |
|
|
205 | (2) |
|
|
207 | (22) |
|
|
209 | (3) |
|
|
210 | (2) |
|
|
212 | (1) |
|
Input/Output/Interface Controls |
|
|
213 | (3) |
|
Editing and Auditing Data |
|
|
215 | (1) |
|
|
215 | (1) |
|
|
216 | (7) |
|
Balancing/Database Reconciliation |
|
|
217 | (2) |
|
|
219 | (3) |
|
Backup and Restart Procedures |
|
|
222 | (1) |
|
|
223 | (1) |
|
|
224 | (1) |
|
|
225 | (1) |
|
|
226 | (3) |
|
|
229 | (22) |
|
|
229 | (4) |
|
|
233 | (4) |
|
|
235 | (2) |
|
|
237 | (4) |
|
Health Insurance Portability and Accountability Act (HIPAA) |
|
|
241 | (2) |
|
|
243 | (1) |
|
|
244 | (1) |
|
|
244 | (1) |
|
|
245 | (1) |
|
|
246 | (5) |
|
Part III Pro-active Measures |
|
|
|
14 Identification of Exposures and Issues |
|
|
251 | (28) |
|
Processes, Procedures, and Control Documentation |
|
|
252 | (8) |
|
|
254 | (1) |
|
|
255 | (2) |
|
Process Flow Diagrams and Control Points |
|
|
257 | (1) |
|
Narrative of Issues Management Flow Diagram with Control Points |
|
|
258 | (2) |
|
|
260 | (3) |
|
|
260 | (3) |
|
|
263 | (1) |
|
|
264 | (5) |
|
|
269 | (1) |
|
|
270 | (1) |
|
|
271 | (1) |
|
|
272 | (1) |
|
|
273 | (1) |
|
|
274 | (1) |
|
|
275 | (4) |
|
|
279 | (14) |
|
Issues Management Process |
|
|
281 | (2) |
|
|
283 | (2) |
|
|
285 | (1) |
|
|
285 | (3) |
|
|
288 | (1) |
|
|
288 | (1) |
|
|
289 | (1) |
|
|
289 | (1) |
|
|
290 | (1) |
|
|
291 | (2) |
|
|
293 | (12) |
|
|
294 | (1) |
|
|
295 | (1) |
|
|
296 | (1) |
|
|
296 | (1) |
|
|
296 | (1) |
|
|
296 | (1) |
|
|
297 | (1) |
|
|
297 | (1) |
|
|
298 | (1) |
|
|
298 | (1) |
|
|
299 | (1) |
|
|
300 | (1) |
|
|
300 | (1) |
|
|
301 | (4) |
|
|
|
17 Preparation for Mock Audits |
|
|
305 | (4) |
|
Auditor's Preparation (If You Are Assigned to This Role) |
|
|
306 | (1) |
|
Audit Client's Preparation (If You Are Assigned to This Role) |
|
|
306 | (1) |
|
|
307 | (1) |
|
Guidelines for the Mock Audit Preparation |
|
|
308 | (1) |
|
|
309 | (34) |
|
Writing Announcement Letters |
|
|
309 | (5) |
|
|
314 | (1) |
|
|
315 | (23) |
|
|
326 | (2) |
|
|
328 | (7) |
|
First IT Billing System Interview |
|
|
335 | (2) |
|
Second IT Billing System Interview |
|
|
337 | (1) |
|
|
338 | (2) |
|
|
340 | (1) |
|
|
341 | (2) |
|
19 Writing and Presenting Mock Audit Reports |
|
|
343 | (10) |
|
|
344 | (2) |
|
Examples of Audit Reports |
|
|
346 | (4) |
|
Presenting the Audit Report |
|
|
350 | (1) |
|
|
350 | (1) |
|
|
351 | (1) |
|
|
352 | (1) |
|
|
352 | (1) |
Conclusion |
|
353 | (2) |
Index |
|
355 | |