City University of Hong Kong · FACULTY OF INFORMATION TECHNOLOGY

IS6523 Chap.9 Auditing Systems, Management and Application Controls

- one subject, every graph, every model, every mark
10 Chapters6-page Bible
Our own words - no uploaded lecturer files
Updated for this semester
Chapter 9 of 10 · IS6523

Auditing Systems, Management and Application Controls

Four tests, and only two of them are about security

An information systems audit is part of the overall audit process and one of the facilitators of good corporate governance. The working definition is the gathering of evidence and the weighing of it, in order to establish whether a system protects assets, keeps its data intact, meets the organisation's goals and uses resources without waste.

Read that as four tests rather than as a sentence. The first two are security tests and the second two are business tests, which is the reason auditing belongs in this course at all.

Regulations then require the organisation to hold evidence of business integrity and of internal controls protecting assets of value, so good controls with no evidence of them fail the requirement as surely as no controls.

Layers outside, subsystems inside

Controls are classified on two axes at once.

By timing they are preventive, detective or corrective, which are positions relative to the event rather than degrees of strength. By framework they are management controls or application controls, and the relationship between those two is the structural idea here: management controls serve as protective layers around application controls.

Seven management functions carry the layers, from top management down through development, programming, data resource, security, operations and quality assurance, and an audit finding phrased against one of them is actionable in a way that the same finding phrased against the organisation is not.

Six places a control can sit on one transaction

The application framework follows a transaction through boundary, input, communications, processing, database and output subsystems, with the boundary subsystem differing from access control only in the role of the accessor.

Segregation of duties ensures a fraud has to involve more than one person, and supervision, accounting records, access control and independent verification accompany it. Input controls run across source documents, coding, batches, validation and error correction, and the validation layer works at field, record and file level.

The check digit is where the material becomes arithmetic, and its published limit, that it catches some transcription errors and no transpositions, is a property of addition rather than of implementation.

In this chapter

What this chapter covers

  • 01

    Four tests inside the audit definition

  • 02

    Evidence, independent opinion, and reporting what the evidence indicates

  • 03

    Internal, external and independent audits and who may read them

  • 04

    Preventive, detective and corrective as positions rather than strengths

  • 05

    Management controls as layers around application controls

  • 06

    Seven management functions and what each answers for

  • 07

    Boundary, input, communications, processing, database and output

  • 08

    Segregation of duties and the four accompanying controls

  • 09

    Transcription against transposition errors

  • 10

    Check digits, validation levels and audit trail controls

Worked example · free

Show which of two keying errors the check digit survives

Q [6 marks]. AskSia-authored practice, with AskSia-authored figures. A supplier account code is four digits plus a check digit formed by summing the digits and keeping the units column, so account 4816 carries the digit 9. A clerk enters two orders wrongly, one as 8416 and one as 4616. Which does the check digit catch? The marks shown are an AskSia study allocation, not a University marking scheme.
  • 2Classify each error.
  • 3Compute the check digit each wrong entry produces.
  • 1State the general limitation this demonstrates.
The first is a transposition, with eight and four swapped, and the second is a transcription error of the substitution kind, with an eight become a six. For the first, the digits still sum to nineteen, so the check digit remains nine and the record passes undetected. For the second the sum falls to seventeen, the expected digit becomes seven, and the mismatch rejects the record. The general limitation is that a check formed by addition is blind to any error that preserves the set of digits, which is why the course states that the technique detects some transcription errors but no transposition errors, and why it is one validation control among five rather than the validation control.
Sia tip — Write an audit finding against a named management function rather than against the organisation. Top management, development, programming, data resource, security, operations or quality assurance: a finding with no owner attached cannot be actioned and does not score as a finding.
Glossary

Key terms

Independent Opinion
The output of an audit, rendered on internal controls after evidence has been collected and evaluated against established criteria.
Internal Audit
An audit an organisation performs on itself, whose findings the course says should not be shared outside the organisation.
Corrective Control
A control that acts only after an event, the class to which the continuity and recovery plans belong.
Segregation of Duties
The division of work into different tasks and incomplete responsibilities so that any fraud requires the involvement of more than one person.
Boundary Subsystem
The application control subsystem made up of whatever stands at the interface where a user meets the system. It differs from access control in the role of the accessor.
Batch Control
A control giving assurance that all records in a batch are processed, that none is processed more than once, and that an audit trail of the transactions is created.
Reasonableness Check
A record level validation that examines the relationship between a record's field values, catching a value that passes every field level test but is implausible in context.
Check Digit
An extra digit carried alongside a code so that it can be tested for integrity later. In the simplest form the code's digits are summed and the units column kept.
Run to Run Control
A processing control that takes the batch control figures and follows a batch from one procedure to the next, recomputing totals and checking sequence.
Audit Trail Control
A technique preserving the record of processing, through transaction logs, logs and listings of automatic transactions, and error listings.
FAQ

Auditing Systems, Management and Application Controls FAQ

Is the point of an audit to find problems?

No. The measure of success the course gives is narrow: to report findings accurately, reporting what the evidence indicates and producing verifiable evidence. Finding problems is not the objective and neither is finding none.

That framing matters for a project, because a risk section written to demonstrate diligence by listing many findings is doing something different from an audit, which is rendering an opinion that can be relied on.

Can a team audit the controls it built and send the result to a customer?

Two things are wrong with that. Independence, because an opinion on internal controls cannot be independent when the author implemented them, which is the same principle segregation of duties applies to transactions. And audience, because the course states that internal audit findings should not be shared outside the organisation.

Assurance given to a customer falls under external or independent audit, and those exist as separate categories precisely because the reader determines who may perform the work.

Why does the session insist that application controls sit inside management controls?

Because it changes where a finding points. An application control that was never configured, never reviewed or never funded is a failure of the function responsible for that layer, and the course names seven such functions. Writing the finding against the layer makes it actionable by a named owner, whereas writing it against the application leaves a defect with no one attached to fixing the conditions that produced it.

Which validation level catches an implausible but well formed value?

Record interrogation. Field level checks test one value at a time for missing data, character type, zero values, limits, ranges and validity against known acceptable values, and a plausible-looking number passes all of them. Record level validation examines the relationship between a record's fields, which is where a reasonableness check compares a rate against the category the record itself says the subject belongs to.

File level checks handle versions and expiry instead.

Study strategy

Exam move

Trace one transaction you understand through all six subsystems and write down what could go wrong at each, because audit questions describe a symptom and ask you to place it. Then take any three controls from the whole course and label each preventive, detective or corrective, which is the classification that exposes a control set with no answer to failure.

Finish by computing two check digits by hand, one of them on a transposed code, so the blind spot is yours rather than remembered.

Working through Auditing Systems, Management and Application Controls in IS6523? Sia is AskSia’s AI Information Technology tutor — ask any IS6523 Auditing Systems, Management and Application Controls question and get a clear, step-by-step explanation grounded in how IS6523 is taught and assessed. Read this chapter free, then take your hardest questions to Sia.

A+Everything unlocked
Unlocks this Bible + all 6 of your City University of Hong Kong subjects - and 1,000+ Bibles across every Australian university.
Sia - your IS6523 tutor, unlimited, worked the way the exam marks it
The full 6-page Bible + practice bank with worked solutions
Chrome extension - sync your LMS so Sia knows your deadlines
Bilingual EN / Chinese on every Bible and every Sia answer
$0.99 Trial
30-day money-back · cancel in one tap · how it works