IS6523 Chap.9 Auditing Systems, Management and Application Controls
Auditing Systems, Management and Application Controls
Four tests, and only two of them are about security
An information systems audit is part of the overall audit process and one of the facilitators of good corporate governance. The working definition is the gathering of evidence and the weighing of it, in order to establish whether a system protects assets, keeps its data intact, meets the organisation's goals and uses resources without waste.
Read that as four tests rather than as a sentence. The first two are security tests and the second two are business tests, which is the reason auditing belongs in this course at all.
Regulations then require the organisation to hold evidence of business integrity and of internal controls protecting assets of value, so good controls with no evidence of them fail the requirement as surely as no controls.
Layers outside, subsystems inside
Controls are classified on two axes at once.
By timing they are preventive, detective or corrective, which are positions relative to the event rather than degrees of strength. By framework they are management controls or application controls, and the relationship between those two is the structural idea here: management controls serve as protective layers around application controls.
Seven management functions carry the layers, from top management down through development, programming, data resource, security, operations and quality assurance, and an audit finding phrased against one of them is actionable in a way that the same finding phrased against the organisation is not.
Six places a control can sit on one transaction
The application framework follows a transaction through boundary, input, communications, processing, database and output subsystems, with the boundary subsystem differing from access control only in the role of the accessor.
Segregation of duties ensures a fraud has to involve more than one person, and supervision, accounting records, access control and independent verification accompany it. Input controls run across source documents, coding, batches, validation and error correction, and the validation layer works at field, record and file level.
The check digit is where the material becomes arithmetic, and its published limit, that it catches some transcription errors and no transpositions, is a property of addition rather than of implementation.
What this chapter covers
- 01
Four tests inside the audit definition
- 02
Evidence, independent opinion, and reporting what the evidence indicates
- 03
Internal, external and independent audits and who may read them
- 04
Preventive, detective and corrective as positions rather than strengths
- 05
Management controls as layers around application controls
- 06
Seven management functions and what each answers for
- 07
Boundary, input, communications, processing, database and output
- 08
Segregation of duties and the four accompanying controls
- 09
Transcription against transposition errors
- 10
Check digits, validation levels and audit trail controls
Show which of two keying errors the check digit survives
- 2Classify each error.
- 3Compute the check digit each wrong entry produces.
- 1State the general limitation this demonstrates.
Key terms
- Independent Opinion
- The output of an audit, rendered on internal controls after evidence has been collected and evaluated against established criteria.
- Internal Audit
- An audit an organisation performs on itself, whose findings the course says should not be shared outside the organisation.
- Corrective Control
- A control that acts only after an event, the class to which the continuity and recovery plans belong.
- Segregation of Duties
- The division of work into different tasks and incomplete responsibilities so that any fraud requires the involvement of more than one person.
- Boundary Subsystem
- The application control subsystem made up of whatever stands at the interface where a user meets the system. It differs from access control in the role of the accessor.
- Batch Control
- A control giving assurance that all records in a batch are processed, that none is processed more than once, and that an audit trail of the transactions is created.
- Reasonableness Check
- A record level validation that examines the relationship between a record's field values, catching a value that passes every field level test but is implausible in context.
- Check Digit
- An extra digit carried alongside a code so that it can be tested for integrity later. In the simplest form the code's digits are summed and the units column kept.
- Run to Run Control
- A processing control that takes the batch control figures and follows a batch from one procedure to the next, recomputing totals and checking sequence.
- Audit Trail Control
- A technique preserving the record of processing, through transaction logs, logs and listings of automatic transactions, and error listings.
Auditing Systems, Management and Application Controls FAQ
Is the point of an audit to find problems?
No. The measure of success the course gives is narrow: to report findings accurately, reporting what the evidence indicates and producing verifiable evidence. Finding problems is not the objective and neither is finding none.
That framing matters for a project, because a risk section written to demonstrate diligence by listing many findings is doing something different from an audit, which is rendering an opinion that can be relied on.
Can a team audit the controls it built and send the result to a customer?
Two things are wrong with that. Independence, because an opinion on internal controls cannot be independent when the author implemented them, which is the same principle segregation of duties applies to transactions. And audience, because the course states that internal audit findings should not be shared outside the organisation.
Assurance given to a customer falls under external or independent audit, and those exist as separate categories precisely because the reader determines who may perform the work.
Why does the session insist that application controls sit inside management controls?
Because it changes where a finding points. An application control that was never configured, never reviewed or never funded is a failure of the function responsible for that layer, and the course names seven such functions. Writing the finding against the layer makes it actionable by a named owner, whereas writing it against the application leaves a defect with no one attached to fixing the conditions that produced it.
Which validation level catches an implausible but well formed value?
Record interrogation. Field level checks test one value at a time for missing data, character type, zero values, limits, ranges and validity against known acceptable values, and a plausible-looking number passes all of them. Record level validation examines the relationship between a record's fields, which is where a reasonableness check compares a rate against the category the record itself says the subject belongs to.
File level checks handle versions and expiry instead.
Exam move
Trace one transaction you understand through all six subsystems and write down what could go wrong at each, because audit questions describe a symptom and ask you to place it. Then take any three controls from the whole course and label each preventive, detective or corrective, which is the classification that exposes a control set with no answer to failure.
Finish by computing two check digits by hand, one of them on a transposed code, so the blind spot is yours rather than remembered.
Working through Auditing Systems, Management and Application Controls in IS6523? Sia is AskSia’s AI Information Technology tutor — ask any IS6523 Auditing Systems, Management and Application Controls question and get a clear, step-by-step explanation grounded in how IS6523 is taught and assessed. Read this chapter free, then take your hardest questions to Sia.