SimplyCPA
Quick Sheets/AUD/IT Controls in Audit

AUD — Quick Sheet

IT Controls in Audit

Read time: ~5 minutes

One-minute revision

  • ITGCs (access, change management, development, operations) support all application controls
  • Weak ITGCs → cannot rely on any automated application control in that system
  • Around the computer = inputs to outputs (simple systems only); Through the computer = test data, ITF, parallel simulation
  • IT segregation: development ≠ operations ≠ security administration; programmer with production access = red flag
  • ADAs can test 100% of a population — removes sampling risk, not nonsampling risk