Business Information Security Officer's Point of View and Internal Auditing Best practices
Internal Audit (IA) professionals serve a high profile set of stakeholders that
include senior management, the board of directors, and external auditors. These
stakeholders expect that IA not only demonstrate a broad and deep knowledge of
the organization and the risks that it faces, but also that IA teams remain dynamic
and flexible in the face of changing business conditions, coordinate effectively with
other risk and assurance functions, and remain independent and objective while
demonstrating a high level of professional proficiency. Internal auditors also have a
requirement to work offline on a laptop.
Manage your complete audit lifecycle on one platform, from audit planning to execution and wrap-up.
- Govern audit-related activities, such as reporting to management and the audit committee.
- Integrate with other risk and control functions.
- Use a consistent, standards-driven, risk-based audit approach to drive greater efficiency in the execution of the audit plan.
- Perform risk-based prioritization of your audit universe.
- Manage resource scheduling and staffing on engagements.
- Perform audit engagements and audit testing, manage workpapers, and create audit reports.
- Track findings, remediation plans, and exception requests.
- Improve the efficiency of your audit department.
- Complete better-scoped, risk-based audits more effectively, increase reliance of work by regulators and external auditors, and decrease external audit fees.
Here are the parts of a Audit Solution that you will need to perform the audit:
- Audit Entity application
- Audit Plan application
- IA Engagement and Assessment Results application
- Plan Entity application
- Audit Engagements sub solution
- Audit Engagement application
- Audit Program Library application
- Audit Workpaper application
- Staffing Management sub solution
- Expense Reports application
- Contacts application
- Base Availability application
- Timesheet Task application
- Training application
- Degrees and Certifications application
- Schedule Management sub solution
- Appointment application
- Quality Management sub solution
- Internal Audit Customer Survey questionnaire
- Internal Audit Department Annual Review application
- Internal Audit Quality Assurance Review Checklist questionnaire
- Question Library application
Planning your Audit:
The Audit Planning sub-solution allows you to capture all audit entities that could be
the subject of audit scrutiny, risk assess them, and determine their inclusion in a
subsequent audit plan covering a given time period, such as a quarter or year.
Define your Audit Entity:
The Audit Entity application provides a single, centralized location to capture
details about each area that could be the subject of audit scrutiny, such as business
processes, organizational units (such as department), specific topics (such as a
regulation such as FFIEC), IT infrastructure and applications, or other individual
areas.
Capture Historical Data:
The IA Engagement and Assessment Results application captures historical audit
engagement and risk assessment results for the Audit Entity for purposes of
maintaining integrity, reporting, and comparing historical information.
Create a plan entity:
Once an Audit Entity is identified as a target for an audit engagement, based on
factors such as risk (from the audit entity risk assessment), regulatory scrutiny, or
strategic value, the entity is included in an Audit Plan. The Plan Entity application
allows you to associate an Audit Entity with an Audit Engagement by creating an
individual plan entity that can be edited and updated as necessary.
Create your Audit Plan:
The Audit Plan application allows you to create and manage Audit Plan records.
The Audit Plan record includes a plan name, description, and estimated start and
end date. To include items in the plan, you associate records from the Plan Entity
application. The Plan Entity record creates a link between previously defined Audit
Entity records and the Audit Plan record. The Audit Plan enables you to capture and
track other information for the Audit Plan, such as plan hours and expenses.
Manage Audit Engagement:
Audit Engagement application serves as Internal Audit's mechanism for
creating, managing, tracking, and reporting on individual audit engagements. The
application allows users to determine the audit engagement’s scope, schedule and
staff resources for the audit, create and manage workpapers, perform audit testing,
document findings and draft the audit report.
Create a Program library:
The Audit Program Library application provides a repository to create and house
audit programs and related audit procedures for use on multiple audit engagements.
When you select audit programs with corresponding audit procedures,
make copies of the audit programs and procedures for audit engagements and
creates workpapers for documenting testing and results.
Create Audit Workpapers:
Audit Workpaper application provides a method for documenting testing using
the steps outlined in audit programs and related procedures for a specific audit
engagement. The Audit Workpaper application is designed to mirror the Audit
Program Library, in that you can create project-specific versions of standard audit
programs and procedures and use them to document your testing. This approach
allows audit department management to maintain consistency of audit procedures
across engagements by leveraging the Audit Program Library while enabling
auditors to customize or add procedures to fit the needs of the engagement on which
they are working.
Manage the Staff:
The Staffing Management sub solution allows you to manage IA team member
availability and schedules (including internal and external resources, track staff
credentials), schedule audit engagements and team resources, report on staffing and
scheduling gaps and monitor utilization.
Perform Quality Management:
The Quality Management sub solution allows you to establish a quality assurance
and improvement program designed to evaluate internal audit's conformance with
the Definition of Internal Auditing and the Standards.
Maintain your question Library:
The Question Library application supports your audit management program. The
application documents assessment questions linked to authoritative sources, control
standards and risks. You can use these questions as often as you like in any type of
assessment.
Through the Question Library application, you can:
- Import your existing questions, use pre-loaded question packs from the Content Library, or enter questions manually through the application's web-based interface.
- Assign questions to categories and apply filter properties that you can later use to create question display rules.
- Assign correct answers, numeric answer values and question weighting.
- Link questions to authoritative sources and control standards in the Policy Management solution.
- Link questions to statements of risk in the Risk Management solution.
By Demetrius Fluker
Comments
Post a Comment