AUD — Quick Sheet
IT Controls in Audit
Read time: ~5 minutes
One-minute revision
- ITGCs (access, change management, development, operations) support all application controls
- Weak ITGCs → cannot rely on any automated application control in that system
- Around the computer = inputs to outputs (simple systems only); Through the computer = test data, ITF, parallel simulation
- IT segregation: development ≠ operations ≠ security administration; programmer with production access = red flag
- ADAs can test 100% of a population — removes sampling risk, not nonsampling risk