Security audits are typically conducted for the purposes of business-information security, risk management and regulatory compliance. If performed correctly, a security audit can reveal weaknesses in technologies, practices, employees and other key areas. The process can also help companies save money by finding more efficient ways to protect IT hardware and software, as well as by enabling businesses to get a better handle on the application and use of security technologies and processes. As bothersome as security audits are, business owners, executives and IT managers who truly understand them realize that periodic examinations can actually help ensure that security strategies are in sync with overall business activities and goals.
Audit Practices and Activities
There is no standard security-audit process, but auditors typically accomplish their job though personal interviews, vulnerability scans, examination of OS and security-application settings, and network analyses, as well as by studying historical data such as event logs. Auditors also focus on the business's security policies to determine what they cover, how they are used and whether they are effective at meeting ongoing and future threats.
CAATs (Computer-Assisted Audit Techniques) are often employed to help auditors gain insight into a business's IT infrastructure in order to spot potential security weaknesses. CAATs use system-generated audit reports, as well as monitoring technology, to detect and report changes to a system's files and settings. CAATs can be used with desktop computers, servers, mainframe computers, network routers and switches, and an array of other systems and devices.
While CAATs can provide definitive data on business systems, auditors must also keep an eye on activities and practices that are not easily quantifiable. Some of the key questions that an auditor must ask include:
Who is in charge of security, and who does this person report to?
Have ACLs (Access Control Lists) been placed on network devices to control who has access to shared data?
How are passwords created and managed?
Are there audit logs to record who accesses data?
Who reviews the audit logs, and how often are they examined?
Are the security settings for OSes and applications in accordance with accepted industry security practices?
Have unnecessary applications and services been purged from systems? How often does this task take place?
Are all OSes and applications updated to current levels?
How is backup media stored? Who has access to it? Is it up-to-date?
How is email security addressed?
How is Web security addressed?
How is wireless security addressed?
Are remote workers covered by security policies?
Is a disaster-recovery plan in place? Has the plan ever been rehearsed?
Have custom applications been tested for security flaws?
How are configuration and code changes documented? How often are these records reviewed?
Many other questions pertaining to the exact nature of the business's operations also must be addressed.
Auditors
An auditor's skills and affiliations depend on the nature of the audit and the audited company's business focus. An internal audit will usually draw auditors from within the business's own IT and accounting departments. Alternatively, a company may hire a security consultant to handle the job. A financial institution or other business working in a regulated industry will often find itself dealing with federal and state regulators. Auditors may also be sent to a business by private standards-setting bodies and other industry organizations.
Aftermath and Follow-Up
Shortly after the audit concludes, the auditors will usually brief a company's owners, executives and managers on what they've discovered and if any immediate remedial action is necessary. A few days or weeks later, the auditors usually issue a formal report. Stakeholders can use both the meeting and the report as opportunities to gain insight into their security practices and make improvements.
While a security audit is usually a specific event, IT security is an ongoing process. As a business designs, deploys and maintains its security policies, technologies and practices, it should strive to maintain a constant state of preparedness that will allow it to pass a security audit at any given moment.
source
Security audits are important nowadays because many accounting systems are now computerized and organizations have to protect the interests of their companies.
Showing posts with label auditing. Show all posts
Showing posts with label auditing. Show all posts
Wednesday, July 29, 2009
What is a Security Audit?
You may see the phrase "penetration test" used interchangeably with the phrase "computer security audit". They are not the same thing. A penetration test (also known as a pen-test) is a very narrowly focused attempt to look for security holes in a critical resource, such as a firewall or Web server. Penetration testers may only be looking at one service on a network resource. They usually operate from outside the firewall with minimal inside information in order to more realistically simulate the means by which a hacker would attack the site.
On the other hand, a computer security audit is a systematic, measurable technical assessment of how the organization's security policy is employed at a specific site. Computer security auditors work with the full knowledge of the organization, at times with considerable inside information, in order to understand the resources to be audited.
Security audits do not take place in a vacuum; they are part of the on-going process of defining and maintaining effective security policies. This is not just a conference room activity. It involves everyone who uses any computer resources throughout the organization. Given the dynamic nature of computer configurations and information storage, some managers may wonder if there is truly any way to check the security ledgers, so to speak. Security audits provide such a tool, a fair and measurable way to examine how secure a site really is.
Computer security auditors perform their work though personal interviews, vulnerability scans, examination of operating system settings, analyses of network shares, and historical data. They are concerned primarily with how security policies - the foundation of any effective organizational security strategy - are actually used. There are a number of key questions that security audits should attempt to answer:
Are passwords difficult to crack?
Are there access control lists (ACLs) in place on network devices to control who has access to shared data?
Are there audit logs to record who accesses data?
Are the audit logs reviewed?
Are the security settings for operating systems in accordance with accepted industry security practices?
Have all unnecessary applications and computer services been eliminated for each system?
Are these operating systems and commercial applications patched to current levels?
How is backup media stored? Who has access to it? Is it up-to-date?
Is there a disaster recovery plan? Have the participants and stakeholders ever rehearsed the disaster recovery plan?
Are there adequate cryptographic tools in place to govern data encryption, and have these tools been properly configured?
Have custom-built applications been written with security in mind?
How have these custom applications been tested for security flaws?
How are configuration and code changes documented at every level? How are these records reviewed and who conducts the review?
These are just a few of the kind of questions that can and should be assessed in a security audit. In answering these questions honestly and rigorously, an organization can realistically assess how secure its vital information is.
Security Policy Defined
As stated, a security audit is essentially an assessment of how effectively the organization's security policy is being implemented. Of course, this assumes that the organization has a security policiy in place which, unfortunately, is not always the case. Even today, it is possible to find a number of organizations where a written security policy does not exist. Security policies are a means of standardizing security practices by having them codified (in writing) and agreed to by employees who read them and sign off on them. When security practices are unwritten or informal, they may not be generally understood and practiced by all employees in the organization. Furthermore, until all employees have read and signed off on the security policy, compliance of the policy cannot be enforced. Written security policies are not about questioning the integrity and competency of employees; rather, they ensure that everyone at every level understands how to protect company data and agrees to fulfill their obligations in order to do so.
Natural tensions frequently exist between workplace culture and security policy. Even with the best of intentions, employees often choose convenience over security. For example, users may know that they should choose difficult-to-guess passwords, but they may also want those passwords to be close at hand. So every fledgling auditor knows to check for sticky notes on the monitor and to pick up the keyboard and look under it for passwords. IT staff may know that every local administrator account should have a password; yet, in the haste to build a system, they may just bypass that step, intending to set the password later, and therefore place an insecure system on the network.
The security audit should seek to measure security policy compliance and recommend solutions to deficiencies in compliance. The policy should also be subject to scrutiny. Is it a living document, accurately reflecting how the organization protects IT assets on a daily basis? Does the policy reflect industry standards for the type of IT resources in use throughout the organization?
source
Performing security audit means that one should be good at computers.
On the other hand, a computer security audit is a systematic, measurable technical assessment of how the organization's security policy is employed at a specific site. Computer security auditors work with the full knowledge of the organization, at times with considerable inside information, in order to understand the resources to be audited.
Security audits do not take place in a vacuum; they are part of the on-going process of defining and maintaining effective security policies. This is not just a conference room activity. It involves everyone who uses any computer resources throughout the organization. Given the dynamic nature of computer configurations and information storage, some managers may wonder if there is truly any way to check the security ledgers, so to speak. Security audits provide such a tool, a fair and measurable way to examine how secure a site really is.
Computer security auditors perform their work though personal interviews, vulnerability scans, examination of operating system settings, analyses of network shares, and historical data. They are concerned primarily with how security policies - the foundation of any effective organizational security strategy - are actually used. There are a number of key questions that security audits should attempt to answer:
Are passwords difficult to crack?
Are there access control lists (ACLs) in place on network devices to control who has access to shared data?
Are there audit logs to record who accesses data?
Are the audit logs reviewed?
Are the security settings for operating systems in accordance with accepted industry security practices?
Have all unnecessary applications and computer services been eliminated for each system?
Are these operating systems and commercial applications patched to current levels?
How is backup media stored? Who has access to it? Is it up-to-date?
Is there a disaster recovery plan? Have the participants and stakeholders ever rehearsed the disaster recovery plan?
Are there adequate cryptographic tools in place to govern data encryption, and have these tools been properly configured?
Have custom-built applications been written with security in mind?
How have these custom applications been tested for security flaws?
How are configuration and code changes documented at every level? How are these records reviewed and who conducts the review?
These are just a few of the kind of questions that can and should be assessed in a security audit. In answering these questions honestly and rigorously, an organization can realistically assess how secure its vital information is.
Security Policy Defined
As stated, a security audit is essentially an assessment of how effectively the organization's security policy is being implemented. Of course, this assumes that the organization has a security policiy in place which, unfortunately, is not always the case. Even today, it is possible to find a number of organizations where a written security policy does not exist. Security policies are a means of standardizing security practices by having them codified (in writing) and agreed to by employees who read them and sign off on them. When security practices are unwritten or informal, they may not be generally understood and practiced by all employees in the organization. Furthermore, until all employees have read and signed off on the security policy, compliance of the policy cannot be enforced. Written security policies are not about questioning the integrity and competency of employees; rather, they ensure that everyone at every level understands how to protect company data and agrees to fulfill their obligations in order to do so.
Natural tensions frequently exist between workplace culture and security policy. Even with the best of intentions, employees often choose convenience over security. For example, users may know that they should choose difficult-to-guess passwords, but they may also want those passwords to be close at hand. So every fledgling auditor knows to check for sticky notes on the monitor and to pick up the keyboard and look under it for passwords. IT staff may know that every local administrator account should have a password; yet, in the haste to build a system, they may just bypass that step, intending to set the password later, and therefore place an insecure system on the network.
The security audit should seek to measure security policy compliance and recommend solutions to deficiencies in compliance. The policy should also be subject to scrutiny. Is it a living document, accurately reflecting how the organization protects IT assets on a daily basis? Does the policy reflect industry standards for the type of IT resources in use throughout the organization?
source
Performing security audit means that one should be good at computers.
Arrest of COA, BIR, Customs chiefs sought
By Tina Santos, Edson C. Tandoc Jr.
Philippine Daily Inquirer
MANILA, Philippines—A lawyers’ group Wednesday asked a Manila court to order the arrest of the heads of the Commission on Audit (COA) and the customs and internal revenue bureaus for their continued disobedience of the court’s order to examine the account books of the Big 3 oil companies.
The Social Justice Society (SJS) asked Judge Silvino Pampilo Jr. to issue arrest warrants against the officials “for their deliberate, obstinate and contumacious refusal to obey the lawful order” of the court and to detain them until they comply with the order.
Pampilo earlier directed the heads of the agencies to explain within 72 hours why they should not be cited for contempt for failure to comply with his April 2009 order to open and examine the books of accounts of Chevron Philippines Inc., Petron Corp. and Pilipinas Shell Petroleum Corp..
Gov’t counsel
The judge’s July 24 order was reportedly served and received on the same day by the Office of the Solicitor General (OSG), which is acting as the counsel for the government agencies.
The SJS said the 72-hour period expired last Tuesday.
Pampilo last April directed the COA, the Bureau of Customs (BOC) and the Bureau of Internal Revenue (BIR) to form a panel that would conduct the examination of cash receipts, cash disbursement books, purchase orders on petroleum products, delivery receipts, sales invoices and other related documents on the purchases of petroleum products of the three firms from January 2003 to December 2003.
The judge’s order stemmed from a complaint filed by the SJS, which accused the oil companies of using pricing schemes grossly disadvantageous to the public.
Last July 7, the judge denied for lack of merit separate motions for reconsideration seeking to stop his order filed by the OSG and the oil firms.
The judge ruled that there was no law or jurisprudence that prohibits government entities from performing acts that would best serve the public.
At a hearing of the energy committee at the House of Representatives Wednesday, Pampanga Rep. Juan Miguel Arroyo said the committee would summon the COA, the BIR and the BOC to update the committee on the progress of their audit of the oil companies as ordered by Pampilo.
“Auditing the oil firms is the only way we will find out if prices are really overpriced or not,” said Arroyo, the committee chair.
Saying they are willing to open their books for auditing, oil companies defended their prices as being fair and reasonable before the committee.
“We have always been transparent with our financial situation. We are open to public audits as long as it is by the right agency,” said Chevron spokesperson Mark Quebral.
Some of the oil companies claimed that they actually incurred millions of pesos in losses last year.
Shell spokesperson Robert Kanapi said that compared to other industries, oil companies have been generating smaller profits. While media companies, for instance, made 12.2 percent in profits last year, oil companies only made some 2.3 percent, he said.
Industry losers
Malou Espina, corporate affairs manager of Total Phil., said the company lost P570 million last year.
Zenaida Monsada, oil industry management bureau director for the Department of Energy, told the committee that four out of nine oil companies incurred net losses last year: Total, Caltex, Petron and Pryce.
Monsada said oil price increases in Metro Manila are lower than the increases in international market prices. She said the Philippines, an oil importer, has among the lowest oil prices in Southeast Asia, its rates just slightly higher than those of Indonesia and Malaysia which both produce and subsidize oil.
But George San Mateo, secretary general of the transport group Pagkakaisa ng mga Samahan ng Tsuper at Operaytor Nationwide (Piston), said he doubted the claims that oil prices in the country are lower than international rates. He urged the committee to review the Oil Deregulation Law.
source
I believe there is no reason why COA and BIR heads should be arrested. They have not done anything wrong.
Philippine Daily Inquirer
MANILA, Philippines—A lawyers’ group Wednesday asked a Manila court to order the arrest of the heads of the Commission on Audit (COA) and the customs and internal revenue bureaus for their continued disobedience of the court’s order to examine the account books of the Big 3 oil companies.
The Social Justice Society (SJS) asked Judge Silvino Pampilo Jr. to issue arrest warrants against the officials “for their deliberate, obstinate and contumacious refusal to obey the lawful order” of the court and to detain them until they comply with the order.
Pampilo earlier directed the heads of the agencies to explain within 72 hours why they should not be cited for contempt for failure to comply with his April 2009 order to open and examine the books of accounts of Chevron Philippines Inc., Petron Corp. and Pilipinas Shell Petroleum Corp..
Gov’t counsel
The judge’s July 24 order was reportedly served and received on the same day by the Office of the Solicitor General (OSG), which is acting as the counsel for the government agencies.
The SJS said the 72-hour period expired last Tuesday.
Pampilo last April directed the COA, the Bureau of Customs (BOC) and the Bureau of Internal Revenue (BIR) to form a panel that would conduct the examination of cash receipts, cash disbursement books, purchase orders on petroleum products, delivery receipts, sales invoices and other related documents on the purchases of petroleum products of the three firms from January 2003 to December 2003.
The judge’s order stemmed from a complaint filed by the SJS, which accused the oil companies of using pricing schemes grossly disadvantageous to the public.
Last July 7, the judge denied for lack of merit separate motions for reconsideration seeking to stop his order filed by the OSG and the oil firms.
The judge ruled that there was no law or jurisprudence that prohibits government entities from performing acts that would best serve the public.
At a hearing of the energy committee at the House of Representatives Wednesday, Pampanga Rep. Juan Miguel Arroyo said the committee would summon the COA, the BIR and the BOC to update the committee on the progress of their audit of the oil companies as ordered by Pampilo.
“Auditing the oil firms is the only way we will find out if prices are really overpriced or not,” said Arroyo, the committee chair.
Saying they are willing to open their books for auditing, oil companies defended their prices as being fair and reasonable before the committee.
“We have always been transparent with our financial situation. We are open to public audits as long as it is by the right agency,” said Chevron spokesperson Mark Quebral.
Some of the oil companies claimed that they actually incurred millions of pesos in losses last year.
Shell spokesperson Robert Kanapi said that compared to other industries, oil companies have been generating smaller profits. While media companies, for instance, made 12.2 percent in profits last year, oil companies only made some 2.3 percent, he said.
Industry losers
Malou Espina, corporate affairs manager of Total Phil., said the company lost P570 million last year.
Zenaida Monsada, oil industry management bureau director for the Department of Energy, told the committee that four out of nine oil companies incurred net losses last year: Total, Caltex, Petron and Pryce.
Monsada said oil price increases in Metro Manila are lower than the increases in international market prices. She said the Philippines, an oil importer, has among the lowest oil prices in Southeast Asia, its rates just slightly higher than those of Indonesia and Malaysia which both produce and subsidize oil.
But George San Mateo, secretary general of the transport group Pagkakaisa ng mga Samahan ng Tsuper at Operaytor Nationwide (Piston), said he doubted the claims that oil prices in the country are lower than international rates. He urged the committee to review the Oil Deregulation Law.
source
I believe there is no reason why COA and BIR heads should be arrested. They have not done anything wrong.
Labels:
Accountancy,
auditing,
coa audit,
coa auditing,
coa news
Thursday, July 23, 2009
THE BENEFITS OF COMPUTER AUDIT
In today's fast changing world, computer audit is very important. Hereunder are the benefits of computer audit:
Business efficiency – companies are required by company law to safeguard assets by instituting effective internal controls. Computer audit would not only meet this requirement but would give you the facts you need to make important decisions.
Security – computer audit would reinforce your company’s attitude to risk. Thousand of pounds are invested in computers (PCs, workstations, laptops, scanners, etc) it pays to be prudent by mitigating loss, whether by theft, fire or otherwise.
The fact that your company has a computer audit policy and that it is taken seriously acts as a deterrent. This is further reinforced when security measures, such as “electronic tagging”, bar coding, permanent fixing or similar measures are employed.
Having documented records of your computer assets aid your claim for loss under your company’s insurance policy. The existence of reliable records aids the process.
Standardisation – a computer audit promotes a standardised purchasing policy. What could be more practical than applying a purchasing policy that not only saves money but also reinforces values, such as brand, efficiency and time?
Don’t assume that all computer equipment comes with quality parts and that they are subject to the same quality control standards. Likewise, not all retailers give the same guarantee! This is where a computer audit could provide valuable information.
Asset tracking – at the point where computer equipment arrives in the company they should be tagged to aid tracking, accounting and ultimately, control against loss. If these assets are not tracked or traceable, they could easily disappear from the company. A computer audit would capture all computing equipment, whether they are included on the asset register or not.
Asset replacement policy – computer audit assists your replacement policy by identifying ageing assets that present potential operational risk to your business. Your accounting policy may provide for non-capitalisation or write off over two to four years, however computers will be used until they are incapable of being sustained.
Such a policy does not help your company in maximising efficiency and productivity. This plays into your competitor’s hands, surrendering to them your competitive advantage. If your business relies on latest technology, it’s imperative that obsolete computers are systematically identified and replaced.
Accounting – computer audit will ensure the completeness of your fixed asset register and the accounting transactions that are processed in your ledgers.
Cost control – computer audit aids the budgeting and timely replacement of computer equipment. It reduces substantially the guesswork in constructing the relevant capital expenditure budget.
Competitive advantage – whether being the quickest to market, having the latest technology or efficient processes is what sets you apart from your competitors it is essential that you make computer audit an essential company tool. Factors that contribute to maintaining competitive advantage cannot be ignored and a Finance Director or IT Manager would be grossly negligent in failing to have answers on this important matter.
source
Business efficiency – companies are required by company law to safeguard assets by instituting effective internal controls. Computer audit would not only meet this requirement but would give you the facts you need to make important decisions.
Security – computer audit would reinforce your company’s attitude to risk. Thousand of pounds are invested in computers (PCs, workstations, laptops, scanners, etc) it pays to be prudent by mitigating loss, whether by theft, fire or otherwise.
The fact that your company has a computer audit policy and that it is taken seriously acts as a deterrent. This is further reinforced when security measures, such as “electronic tagging”, bar coding, permanent fixing or similar measures are employed.
Having documented records of your computer assets aid your claim for loss under your company’s insurance policy. The existence of reliable records aids the process.
Standardisation – a computer audit promotes a standardised purchasing policy. What could be more practical than applying a purchasing policy that not only saves money but also reinforces values, such as brand, efficiency and time?
Don’t assume that all computer equipment comes with quality parts and that they are subject to the same quality control standards. Likewise, not all retailers give the same guarantee! This is where a computer audit could provide valuable information.
Asset tracking – at the point where computer equipment arrives in the company they should be tagged to aid tracking, accounting and ultimately, control against loss. If these assets are not tracked or traceable, they could easily disappear from the company. A computer audit would capture all computing equipment, whether they are included on the asset register or not.
Asset replacement policy – computer audit assists your replacement policy by identifying ageing assets that present potential operational risk to your business. Your accounting policy may provide for non-capitalisation or write off over two to four years, however computers will be used until they are incapable of being sustained.
Such a policy does not help your company in maximising efficiency and productivity. This plays into your competitor’s hands, surrendering to them your competitive advantage. If your business relies on latest technology, it’s imperative that obsolete computers are systematically identified and replaced.
Accounting – computer audit will ensure the completeness of your fixed asset register and the accounting transactions that are processed in your ledgers.
Cost control – computer audit aids the budgeting and timely replacement of computer equipment. It reduces substantially the guesswork in constructing the relevant capital expenditure budget.
Competitive advantage – whether being the quickest to market, having the latest technology or efficient processes is what sets you apart from your competitors it is essential that you make computer audit an essential company tool. Factors that contribute to maintaining competitive advantage cannot be ignored and a Finance Director or IT Manager would be grossly negligent in failing to have answers on this important matter.
source
Wednesday, July 15, 2009
Audit Program for Accounts Payable
Accounts Payable should also be properly taken care of to ensure that they actually exist. The audit program for payables are shown below:
Audit Objectives:
To determine that all existing liabilities are properly recorded and shown in the balance sheet
To determine that all the recorded liabilities are existing liabilities of the agency as of balance sheet date
To determine that payees are valid claimants
To ascertain that transactions are duly approved and complete with supporting documents
Test of details of transactions and balances:
1. Vouch recorded accounts payable transactions to supporting documentation.
2. Vouch credits to supporting vouchers, vendor invoices, receiving reports, and purchase orders and other supporting information.
3. Vouch debits to cash disbursements or purchase returns memoranda.
4. Perform purchases cut-off test.
Select sample of recorded purchase transactions from several days before and after year-end and examine supporting vouchers, invoices, etc. to determine that purchases were recorded in the proper period.
Observe the number of the last receiving report issued on the last business day of the audit period and trace sample of lower- and higher-numbered receiving reports to related purchase documents and determine that transactions were recorded in the proper period.
Perform cash disbursements cut-off.
Observe the number of last check issued and trace to the accounting records to verify accuracy of cut-off, or trace dates of paid checks returned with year-end cut-off bank statements to dates recorded.
Confirm accounts payable. On a sample basis, send confirmation requests to vendors with large balances. Investigate and reconcile differences.
Determine that payables are properly identified and classified.
Audit Objectives:
To determine that all existing liabilities are properly recorded and shown in the balance sheet
To determine that all the recorded liabilities are existing liabilities of the agency as of balance sheet date
To determine that payees are valid claimants
To ascertain that transactions are duly approved and complete with supporting documents
Test of details of transactions and balances:
1. Vouch recorded accounts payable transactions to supporting documentation.
2. Vouch credits to supporting vouchers, vendor invoices, receiving reports, and purchase orders and other supporting information.
3. Vouch debits to cash disbursements or purchase returns memoranda.
4. Perform purchases cut-off test.
Select sample of recorded purchase transactions from several days before and after year-end and examine supporting vouchers, invoices, etc. to determine that purchases were recorded in the proper period.
Observe the number of the last receiving report issued on the last business day of the audit period and trace sample of lower- and higher-numbered receiving reports to related purchase documents and determine that transactions were recorded in the proper period.
Perform cash disbursements cut-off.
Observe the number of last check issued and trace to the accounting records to verify accuracy of cut-off, or trace dates of paid checks returned with year-end cut-off bank statements to dates recorded.
Confirm accounts payable. On a sample basis, send confirmation requests to vendors with large balances. Investigate and reconcile differences.
Determine that payables are properly identified and classified.
Audit Program for PROPERTY, PLANT AND EQUIPMENT
PROPERTY, PLANT AND EQUIPMENT (PPE) are very important assets of an organization and hereunder is an audit program in the examination of such assets:
Audit Objectives:
To establish the existence and ownership by the client of property, plant and equipment.
To ascertain that the basis at which property accounts are stated is acceptable and consistent with that of the preceding year
To determine that additions during the audit period are recorded and valued properly
To make certain that all dispositions of property whether transferred without cost or disposed have been properly authorized and recorded in the books
To ascertain that all properties in the hands of end-users are properly identified and handled or managed and corresponding Memorandum Receipts (MRs) are on file and acknowledged by them
To ascertain that totals per inventory report tally with balances appearing in the Balance Sheet
To ascertain whether all PPE are stated at cost less accumulated depreciation, and to determine whether depreciation of these assets had been properly and accurately computed.
Test of details of transactions and balances:
1. Vouch PPE additions to supporting documentation.
2. Vouch PPE disposals to supporting documentation.
3. Review entries to repairs and maintenance expenses.
4. Inspect PPE and additions thereto. Be alert to evidence of additions and disposals not included on agency’s schedules and to conditions that bear on the proper valuation and classification of the PPE.
5. Examine title documents and pertinent papers.
6. Evaluate fair presentation of depreciation expense by evaluating the appropriateness of useful lives and estimated salvage values set by the Commission on Audit.
7. Determine that PPE and related expenses, gains, and losses are properly identified and classified in the financial statements.
8. Determine the appropriateness of disclosures related to the cost, book value, depreciation methods and useful lives.
Audit Objectives:
To establish the existence and ownership by the client of property, plant and equipment.
To ascertain that the basis at which property accounts are stated is acceptable and consistent with that of the preceding year
To determine that additions during the audit period are recorded and valued properly
To make certain that all dispositions of property whether transferred without cost or disposed have been properly authorized and recorded in the books
To ascertain that all properties in the hands of end-users are properly identified and handled or managed and corresponding Memorandum Receipts (MRs) are on file and acknowledged by them
To ascertain that totals per inventory report tally with balances appearing in the Balance Sheet
To ascertain whether all PPE are stated at cost less accumulated depreciation, and to determine whether depreciation of these assets had been properly and accurately computed.
Test of details of transactions and balances:
1. Vouch PPE additions to supporting documentation.
2. Vouch PPE disposals to supporting documentation.
3. Review entries to repairs and maintenance expenses.
4. Inspect PPE and additions thereto. Be alert to evidence of additions and disposals not included on agency’s schedules and to conditions that bear on the proper valuation and classification of the PPE.
5. Examine title documents and pertinent papers.
6. Evaluate fair presentation of depreciation expense by evaluating the appropriateness of useful lives and estimated salvage values set by the Commission on Audit.
7. Determine that PPE and related expenses, gains, and losses are properly identified and classified in the financial statements.
8. Determine the appropriateness of disclosures related to the cost, book value, depreciation methods and useful lives.
Audit Program for Inventories
Here is an audit program for inventories which is very useful for auditors:
Audit Objectives:
To ascertain the physical existence of the items appearing in the balance sheet and to be satisfied of the reasonable accuracy of quantities
To ascertain whether all recorded procurements and utilization occurred during the current year.
To test whether the inventories are properly valued using the moving average method of costing.
Analytical Procedure:
Compare inventory balances to anticipated need as well as to last year’s inventory balances.
Test of details of transactions:
1. Vouch entries in inventory accounts to supporting documentation (e.g. invoices, requisition and issue slips, etc.)
2. Trace data from purchases, supply card, subsidiary ledgers to inventory accounts.
3. See if the asset method of accounting is applied.
4. Test cut-off of purchases and issuances.
Test of details of balances:
5. Observe agency’s physical count and verify inventory quantities:
review the client’s inventory instructions, if any, Determine whether the procedures outlined will result in reasonably accurate inventory.
- Observe the inventory-taking and make sufficient test counts to determine whether inventory instructions are carried out, counts are accurate and properly recorded, and quality and condition of goods are considered
- Obtain proper cut-off
- Note existence of obsolete, slow-moving or damaged goods
- Test check extension and footings of Inventory List
- Check against Memorandum Receipts
- Assist in the inventory-taking personally or by representative
- Conduct inquiry/personal observation to satisfy oneself as to
effectiveness of methods of inventory-taking and as to reliability of
client’s representations
- Prepare reports as to results of inventory-taking observed
Obtain copy of final inventory lists, trace test of inventory
quantities
- compare final inventory list with the inventory balances
appearing in the Supplies Ledger cards maintained by the
Accounting Division as well as the inventory balances indicated
in the stock cards of the Supply Office. Note down differences.
6. Verify inventory valuation-test check basis of prices from
purchase orders/delivery receipts. See whether ending balances were arrived at using the moving average method of valuation.
Reconcile inventory report balances with balances appearing in
the balance sheet
Audit Objectives:
To ascertain the physical existence of the items appearing in the balance sheet and to be satisfied of the reasonable accuracy of quantities
To ascertain whether all recorded procurements and utilization occurred during the current year.
To test whether the inventories are properly valued using the moving average method of costing.
Analytical Procedure:
Compare inventory balances to anticipated need as well as to last year’s inventory balances.
Test of details of transactions:
1. Vouch entries in inventory accounts to supporting documentation (e.g. invoices, requisition and issue slips, etc.)
2. Trace data from purchases, supply card, subsidiary ledgers to inventory accounts.
3. See if the asset method of accounting is applied.
4. Test cut-off of purchases and issuances.
Test of details of balances:
5. Observe agency’s physical count and verify inventory quantities:
review the client’s inventory instructions, if any, Determine whether the procedures outlined will result in reasonably accurate inventory.
- Observe the inventory-taking and make sufficient test counts to determine whether inventory instructions are carried out, counts are accurate and properly recorded, and quality and condition of goods are considered
- Obtain proper cut-off
- Note existence of obsolete, slow-moving or damaged goods
- Test check extension and footings of Inventory List
- Check against Memorandum Receipts
- Assist in the inventory-taking personally or by representative
- Conduct inquiry/personal observation to satisfy oneself as to
effectiveness of methods of inventory-taking and as to reliability of
client’s representations
- Prepare reports as to results of inventory-taking observed
Obtain copy of final inventory lists, trace test of inventory
quantities
- compare final inventory list with the inventory balances
appearing in the Supplies Ledger cards maintained by the
Accounting Division as well as the inventory balances indicated
in the stock cards of the Supply Office. Note down differences.
6. Verify inventory valuation-test check basis of prices from
purchase orders/delivery receipts. See whether ending balances were arrived at using the moving average method of valuation.
Reconcile inventory report balances with balances appearing in
the balance sheet
Audit Program for Receivables
Audit Objective: To establish the validity and collectibility of the receivables and the fairness of the description and classification of these receivables in the Balance Sheet
Analytical Review:
Compare last year’s Accounts Receivable with the current period receivables. Segregating them as to kind or nature of the receivable. Take note of significant increases/decreases. Know the causes of such significant differences.
Test of Details of Balances and Transactions:
1. Obtain/prepare a schedule of receivables w/ the ff:
name
address
balance of account
age of account balance
2. Pay particular attention to Receivables in the nature of advances to employees
for traveling expenses.
3. Foot the schedule and trace totals to GL
4. Compare balances in SL and test accuracy of
aging
5. Verify collections made after balance sheet date
6. Ascertain that AR represent valid claims against
existing debtors
7. Determine validity of AR
8. Determine collectibility of AR.
9. Confirm receivables
-write positive or negative confirmation letter
-jot down details and items that need to be
clarified
10. For receivables in the nature of traveling advances, prepare demand letters for
their liquidation in accordance with pertinent regulations.
11. Make an evaluation of results of work done
12. Prepare working paper and report
Receivables are also important element in financial statements so it must be examined carefully by an auditor.
Analytical Review:
Compare last year’s Accounts Receivable with the current period receivables. Segregating them as to kind or nature of the receivable. Take note of significant increases/decreases. Know the causes of such significant differences.
Test of Details of Balances and Transactions:
1. Obtain/prepare a schedule of receivables w/ the ff:
name
address
balance of account
age of account balance
2. Pay particular attention to Receivables in the nature of advances to employees
for traveling expenses.
3. Foot the schedule and trace totals to GL
4. Compare balances in SL and test accuracy of
aging
5. Verify collections made after balance sheet date
6. Ascertain that AR represent valid claims against
existing debtors
7. Determine validity of AR
8. Determine collectibility of AR.
9. Confirm receivables
-write positive or negative confirmation letter
-jot down details and items that need to be
clarified
10. For receivables in the nature of traveling advances, prepare demand letters for
their liquidation in accordance with pertinent regulations.
11. Make an evaluation of results of work done
12. Prepare working paper and report
Receivables are also important element in financial statements so it must be examined carefully by an auditor.
AUDIT PROGRAM for Cash Receipts Transactions and Cash Balances
Hereunder is a useful audit program for auditing Cash Receipts Transactions and Cash Balances:
Audit Objective: To determine whether cash balances at month-end/year-end are valid and actually exist.
Analytical Procedures:
1. Compare cash accounts with those of prior years and investigate additions or deletions of accounts;
2. Compare cash receipts from miscellaneous sources with those of prior year and account for major changes.
Other Procedures:
3. Count and list cash on hand at year-end and trace to cash receipts record and bank statement.
4. Vouch significant cash receipts from sources other than customers and trace to deposit slips and bank statements on a test basis.
5. Confirm bank balances directly with bank and BTr. Compare replies and investigate differences, if any.
6. Reconcile bank accounts as of year-end.
7. Obtain cutoff bank statement(s) directly from banks and trace reconciling items from bank reconciliation to cut-off statement.
8. Inquire as to status of inactive bank accounts.
9. Review GL account balances and trace postings from the underlying receipts and supporting documents to the reports and journals.
10. Prepare/obtain schedule of collections and deposits per bank account as of month-end/year-end.
11. Compare schedule with SL accounts. Examine the schedule footings and compare totals with the GL.
12. Review/verify bank reconciliation statements.
13. Note differences between bank and book balances and verify whether reconciling items are properly recorded in the books of accounts.
14. Prepare draft AO and discuss with management officials concerned before issuance.
Audit Objective: To determine whether cash balances at month-end/year-end are valid and actually exist.
Analytical Procedures:
1. Compare cash accounts with those of prior years and investigate additions or deletions of accounts;
2. Compare cash receipts from miscellaneous sources with those of prior year and account for major changes.
Other Procedures:
3. Count and list cash on hand at year-end and trace to cash receipts record and bank statement.
4. Vouch significant cash receipts from sources other than customers and trace to deposit slips and bank statements on a test basis.
5. Confirm bank balances directly with bank and BTr. Compare replies and investigate differences, if any.
6. Reconcile bank accounts as of year-end.
7. Obtain cutoff bank statement(s) directly from banks and trace reconciling items from bank reconciliation to cut-off statement.
8. Inquire as to status of inactive bank accounts.
9. Review GL account balances and trace postings from the underlying receipts and supporting documents to the reports and journals.
10. Prepare/obtain schedule of collections and deposits per bank account as of month-end/year-end.
11. Compare schedule with SL accounts. Examine the schedule footings and compare totals with the GL.
12. Review/verify bank reconciliation statements.
13. Note differences between bank and book balances and verify whether reconciling items are properly recorded in the books of accounts.
14. Prepare draft AO and discuss with management officials concerned before issuance.
Sunday, July 12, 2009
Generally Accepted Auditing Standards
Generally Accepted Auditing Standards, or GAAS, are ten auditing standards, developed by the AICPA, consisting of general standards, standards of field work, and standards of reporting, along with interpretations. They were developed by the AICPA in 1947 and have undergone minor changes since then.
General Standards
1. The auditor must have adequate technical training and proficiency to perform the audit
2. The auditor must maintain independence in mental attitude in all matters related to the audit.
3. The auditor must use due professional care during the performance of the audit and the preparation of the report.
Standards of Field Work
1. The auditor must adequately plan the work and must properly supervise any assistants.
2. The auditor must obtain a sufficient understanding of the entity and its environment, including its internal control, to assess the risk of material misstatement of the financial statements whether due to error or fraud, and to design the nature, timing, and extent of further audit procedures.
3. The auditor must obtain sufficient appropriate audit evidence by performing audit procedures to afford a reasonable basis for an opinion regarding the financial statements under audit.
The new standards are in effect for audits of financial statements for periods beginning on or after December 15, 2006.
Standards of Reporting
1. The auditor must state in the auditor's report whether the financial statements are in accordance with generally accepted accounting principles (GAAP).
2. The auditor must identify in the auditor's report those circumstances in which such principles have not been consistently observed in the current period in relation to the preceding period.
3. When the auditor determines that informative disclosures are not reasonably adequate, the auditor must so state in the auditor's report.
4. The auditor must either express an opinion regarding the financial statements, taken as a whole, or state that such an opinion cannot be expressed in the auditors report. When the auditor cannot express an overall opinion, the auditor should state the reasons therefore in the auditor's report. In all cases where the auditor's name is associated with the financial statements, the auditor should clearly indicate the character of the auditor's work, if any, and the degree of responsibility the auditor is taking, in the auditor's report.
source
Generally Accepted Auditing Standards should be properly observed by an auditor.
General Standards
1. The auditor must have adequate technical training and proficiency to perform the audit
2. The auditor must maintain independence in mental attitude in all matters related to the audit.
3. The auditor must use due professional care during the performance of the audit and the preparation of the report.
Standards of Field Work
1. The auditor must adequately plan the work and must properly supervise any assistants.
2. The auditor must obtain a sufficient understanding of the entity and its environment, including its internal control, to assess the risk of material misstatement of the financial statements whether due to error or fraud, and to design the nature, timing, and extent of further audit procedures.
3. The auditor must obtain sufficient appropriate audit evidence by performing audit procedures to afford a reasonable basis for an opinion regarding the financial statements under audit.
The new standards are in effect for audits of financial statements for periods beginning on or after December 15, 2006.
Standards of Reporting
1. The auditor must state in the auditor's report whether the financial statements are in accordance with generally accepted accounting principles (GAAP).
2. The auditor must identify in the auditor's report those circumstances in which such principles have not been consistently observed in the current period in relation to the preceding period.
3. When the auditor determines that informative disclosures are not reasonably adequate, the auditor must so state in the auditor's report.
4. The auditor must either express an opinion regarding the financial statements, taken as a whole, or state that such an opinion cannot be expressed in the auditors report. When the auditor cannot express an overall opinion, the auditor should state the reasons therefore in the auditor's report. In all cases where the auditor's name is associated with the financial statements, the auditor should clearly indicate the character of the auditor's work, if any, and the degree of responsibility the auditor is taking, in the auditor's report.
source
Generally Accepted Auditing Standards should be properly observed by an auditor.
Saturday, July 11, 2009
Strategic Audits
Strategic audits are examinations and evaluations of strategic management processes including measuring corporate performance against the corporate strategy. Whenever a deficiency is noted or performance of an organization is sub-par, the organization may elect to perform a strategic audit. This may be done with in-house auditors, or an audit firm may be contracted to perform the audit.
The auditors will audit performance of the organization against the current corporate strategy and seek to identify problems within the current strategy that may be tied or can be traced to poor performance. Upon completion of the audit, a report will be created regarding the auditing firm or group’s findings and submit the report with recommended remedies to the management of the organization. The organization will then seek to implement the proposed remedies with hopes of increasing organizational performance.
source
In government auditing, strategic audits refers to performance audit or value for money audit.
The auditors will audit performance of the organization against the current corporate strategy and seek to identify problems within the current strategy that may be tied or can be traced to poor performance. Upon completion of the audit, a report will be created regarding the auditing firm or group’s findings and submit the report with recommended remedies to the management of the organization. The organization will then seek to implement the proposed remedies with hopes of increasing organizational performance.
source
In government auditing, strategic audits refers to performance audit or value for money audit.
Operational Audits
Operational audits are performed within an organization to ensure the highest level of organizational, departmental, and process performance, and conformity with organizational policies and budgetary outlays. An operational audit can uncover inefficiencies in process, workflow, and manufacturing processes by identifying flaws in the processes, areas where slow-downs occur, and areas where costs or wastes are too high.
An operational audit may also identify business risks by finding areas of non-compliance within any given business unit, finding business areas where environmental issues, job hazards and employee safety and health are at risk, and identify areas where assets, cash-flow, intellectual properties and other ownerships contain an unacceptable exposure to risk. These audits are generally performed by internal auditors on a recurrent basis within an organization who give resultant reports to management along with recommendations to improve found inefficiencies, reduce these exposures to risk, and suggest other necessary improvements.
source
Operational audit is the actual examination of the books of accounts and operations of an organization.
An operational audit may also identify business risks by finding areas of non-compliance within any given business unit, finding business areas where environmental issues, job hazards and employee safety and health are at risk, and identify areas where assets, cash-flow, intellectual properties and other ownerships contain an unacceptable exposure to risk. These audits are generally performed by internal auditors on a recurrent basis within an organization who give resultant reports to management along with recommendations to improve found inefficiencies, reduce these exposures to risk, and suggest other necessary improvements.
source
Operational audit is the actual examination of the books of accounts and operations of an organization.
Auditing Process
The audit process is unique among every organization due to differing needs, however the basics remain constant. The audit process begins with a preliminary review at which time the auditor collects information about the organization, reviews internal controls, and designs the audit program. Once the review process is completed and an approach to the audit has been designed, the auditor will conduct the fieldwork required to complete the audit.
Transaction testing will be completed and any problems or flaws in processes in place will be discussed with the organization. A summary of the auditor's findings will be completed with recommendations for organizational improvement will be completed. The summary will be used to prepare the discussion draft for the final audit report. The discussion draft will be submitted for review to the organization being audited. Once the organization has reviewed the discussion draft, the auditors will meet with management to discuss their findings. A formal draft will then be prepared including findings concluded from the discussion taking into account any revisions to the report, and then reviewed again by the audit management team and the organization being audited.
The final report will then be submitted to all required recipients. Approximately one year after the audit, the auditing group will then usually follow up with the organization to review change implementation resulting from the audit and submit a report showing the organizational changes as a result of the audit results, also highlighting any procedures that should have changed but did not. This completes the audit process until the next audit cycle.
source
Auditing process should be carefully planned and executed during the conduct of audit and examination of an organization.
Transaction testing will be completed and any problems or flaws in processes in place will be discussed with the organization. A summary of the auditor's findings will be completed with recommendations for organizational improvement will be completed. The summary will be used to prepare the discussion draft for the final audit report. The discussion draft will be submitted for review to the organization being audited. Once the organization has reviewed the discussion draft, the auditors will meet with management to discuss their findings. A formal draft will then be prepared including findings concluded from the discussion taking into account any revisions to the report, and then reviewed again by the audit management team and the organization being audited.
The final report will then be submitted to all required recipients. Approximately one year after the audit, the auditing group will then usually follow up with the organization to review change implementation resulting from the audit and submit a report showing the organizational changes as a result of the audit results, also highlighting any procedures that should have changed but did not. This completes the audit process until the next audit cycle.
source
Auditing process should be carefully planned and executed during the conduct of audit and examination of an organization.
What is Auditing Technique?
Auditing technique is defined as any technique used by auditors to determine deviations from actual accounting and controls established by a business or organization as well as uncovering problems in established processes and controls. Auditing techniques can be used to aid organizations by uncovering errors in business practices and providing a means of correction. Some businesses have used irregular accounting methods to hide certain monetary transactions and non-compliant behavior which has been uncovered by the use of varied auditing techniques. Other businesses have found new ways to save money and streamline business practices through various auditing techniques which have found waste in certain processes.
Auditing techniques can be used to uncover these issues in order to ensure ethical business practices and to minimize waste or possible oversights within an organization. The applied techniques can determine if any income is hidden or improperly categorized or reported; transactions are being completed between the organization and regulated or prohibited persons, groups, or countries; uncovering of environmental waste discrepancies; finding of data inconsistencies; or any other business practice that can be considered as a process error, oversight, or violation of ethics, regulations, and laws.
source
Auditing techniques are important to auditors in uncovering fraud in an organization.
Auditing techniques can be used to uncover these issues in order to ensure ethical business practices and to minimize waste or possible oversights within an organization. The applied techniques can determine if any income is hidden or improperly categorized or reported; transactions are being completed between the organization and regulated or prohibited persons, groups, or countries; uncovering of environmental waste discrepancies; finding of data inconsistencies; or any other business practice that can be considered as a process error, oversight, or violation of ethics, regulations, and laws.
source
Auditing techniques are important to auditors in uncovering fraud in an organization.
Thursday, July 9, 2009
Financial, Operational & Compliance Audits & Reviews of Harvard University Financial Administration
The Financial, Operational & Compliance Audit Group is responsible for assuring that financial and operational controls are in place and working properly throughout the University. Our audit engagements range from audits of small departments to large schools, as well audits of specific departmental and University-wide processes. Our goal is to provide a beneficial service to each of our clients by identifying inefficiencies and control weaknesses and recommending ways to correct them. Our evaluations are objective and professional. In addition to the standard audit, we offer the following services:
Financial and Operational Control Audits
We will provide an objective and professional evaluation of an area, department or functional operation's system of internal controls. We will advise on control weaknesses and opportunities for improvement to ensure efficiency and effectiveness of operations. If you are looking for information regarding prepartion for an audit please see our FAQs. If you are looking for tools that may be helpful in preparing for an audit or at any time see our Tools You Can Use.
Integrated Audits
We can combine a financial and operational control audit of an area with an audit of the information systems that support that particular area. In doing an integrated audit, we can assess whether the business objectives are linked to the information systems that are in place. See also Information Systems.
Business Process Reviews
We will review and evaluate business processes and assess need for new business processes. We will advise on aspects of policies, process enhancements and procedures.
Management Reviews
We will perform a limited review of an area at the request of a department head or senior management. It is usually short-term in nature and is intended to provide insight into the operations from a controls and/or efficiency perspective. Distribution of the report is limited to a need-to-know list as determined by the person/s requesting the review.
Operations Self-Assessment
Local units may use this tool to self-evaluate their operations or may engage us to conduct an interview with staff. To review or use the operations self-assessment (OSA), please see the OSA.
Construction
We will review potential changes to the Harvard contract boilerplate documents under consideration during a project’s pre-construction period, assist in the negotiation of labor burden rates and their related components, provide support on issues for projects below the Corporation/JCI threshold for independent cost audits ($5 Million) and share knowledge University-wide on audit issues that may have multi-project or University-wide potential impacts. We will respond to stakeholder requests for information and services related to project accounting and controls.
Harvard University uses Risk Management in its Auditing Services. All areas are covered and I believe that said organization is employing effective auditing techniques and practices.
Source
Financial and Operational Control Audits
We will provide an objective and professional evaluation of an area, department or functional operation's system of internal controls. We will advise on control weaknesses and opportunities for improvement to ensure efficiency and effectiveness of operations. If you are looking for information regarding prepartion for an audit please see our FAQs. If you are looking for tools that may be helpful in preparing for an audit or at any time see our Tools You Can Use.
Integrated Audits
We can combine a financial and operational control audit of an area with an audit of the information systems that support that particular area. In doing an integrated audit, we can assess whether the business objectives are linked to the information systems that are in place. See also Information Systems.
Business Process Reviews
We will review and evaluate business processes and assess need for new business processes. We will advise on aspects of policies, process enhancements and procedures.
Management Reviews
We will perform a limited review of an area at the request of a department head or senior management. It is usually short-term in nature and is intended to provide insight into the operations from a controls and/or efficiency perspective. Distribution of the report is limited to a need-to-know list as determined by the person/s requesting the review.
Operations Self-Assessment
Local units may use this tool to self-evaluate their operations or may engage us to conduct an interview with staff. To review or use the operations self-assessment (OSA), please see the OSA.
Construction
We will review potential changes to the Harvard contract boilerplate documents under consideration during a project’s pre-construction period, assist in the negotiation of labor burden rates and their related components, provide support on issues for projects below the Corporation/JCI threshold for independent cost audits ($5 Million) and share knowledge University-wide on audit issues that may have multi-project or University-wide potential impacts. We will respond to stakeholder requests for information and services related to project accounting and controls.
Harvard University uses Risk Management in its Auditing Services. All areas are covered and I believe that said organization is employing effective auditing techniques and practices.
Source
Wednesday, July 8, 2009
Roles of an Auditor
Auditors as representatives of the Commission. - The Auditors shall exercise such powers and functions as may be authorized by the Commission in the examination, audit and settlement of the accounts, funds, financial transactions, and resources of the agencies under their respective audit jurisdiction.
Role of the Auditor. - The Auditor shall maintain complete independence and exercise professional care and be guided by applicable laws, regulations and the generally accepted principles of auditing and accounting in the performance of the audit work as well as in the preparation of audit and financial reports.
Responsibility to Accumulate Sufficient Evidence. - The Auditor shall obtain, accumulate, and safeguard sufficient evidence to provide an appropriate factual bases for his opinions, conclusions,judgments recommendations. Evidence needed to support his findings may be (1) physical evidence obtained by observation, photograph, ocular inspection, or similar means, (2) testimonial evidence obtained by interviewing and taking sworn statements from witnesses, (3) documentary evidence consisting of letters, contracts, reports, extracts from books of accounts, invoices, receipts and computer print-outs and (4) analytical evidence such as analysis sheets/working papers prepared.
The technicalities of law and the rules governing the admissibility and sufficiency of evidence obtaining in the courts of law shall not strictly apply.
Report, Certificate of Settlement and Balances, Notice of Disallowances and Charges, Order or Decision of the Auditor. - The result of the audit work of the Auditor may be in the form of a report, Certificate of Settlement and Balances, notice of disallowances and charges, audit observation, order or decision which shall clearly and distinctly state his findings of fact, conclusions, recommendations and dispositions. The factual findings shall be adequately established by evidence and the conclusions, recommendations or dispositions shall be supported by applicable laws, regulations, jurisprudence and the generally accepted accounting and auditing principles on which the report, Certificate of Settlement and Balances, notice of disallowances and charges and order or decision are based.
The roles of an auditor are quite difficult but it must be strictly observed for the outstanding performance of the auditor of his duties and responsibilities.
Source
Role of the Auditor. - The Auditor shall maintain complete independence and exercise professional care and be guided by applicable laws, regulations and the generally accepted principles of auditing and accounting in the performance of the audit work as well as in the preparation of audit and financial reports.
Responsibility to Accumulate Sufficient Evidence. - The Auditor shall obtain, accumulate, and safeguard sufficient evidence to provide an appropriate factual bases for his opinions, conclusions,judgments recommendations. Evidence needed to support his findings may be (1) physical evidence obtained by observation, photograph, ocular inspection, or similar means, (2) testimonial evidence obtained by interviewing and taking sworn statements from witnesses, (3) documentary evidence consisting of letters, contracts, reports, extracts from books of accounts, invoices, receipts and computer print-outs and (4) analytical evidence such as analysis sheets/working papers prepared.
The technicalities of law and the rules governing the admissibility and sufficiency of evidence obtaining in the courts of law shall not strictly apply.
Report, Certificate of Settlement and Balances, Notice of Disallowances and Charges, Order or Decision of the Auditor. - The result of the audit work of the Auditor may be in the form of a report, Certificate of Settlement and Balances, notice of disallowances and charges, audit observation, order or decision which shall clearly and distinctly state his findings of fact, conclusions, recommendations and dispositions. The factual findings shall be adequately established by evidence and the conclusions, recommendations or dispositions shall be supported by applicable laws, regulations, jurisprudence and the generally accepted accounting and auditing principles on which the report, Certificate of Settlement and Balances, notice of disallowances and charges and order or decision are based.
The roles of an auditor are quite difficult but it must be strictly observed for the outstanding performance of the auditor of his duties and responsibilities.
Source
Labels:
audit ideas,
auditing,
coa auditing,
roles of an auditor
Monday, June 22, 2009
Selective Pre-audit on Government Transactions
Starting July 1, 2009, the Commission on Audit through COA Circular no. 2009-002 dated May 18, 2009, is reinstituting selective pre-audit on government transactions. This is because of recent developments which gave rise to incidents of irregular, illegal, wasteful and anomalous disbursements of huge amounts of public funds and disposal of public property. Indeed corruption is everywhere nowadays, you can see or hear it in the news everyday pointing to the need to consider restoring pre-audit as a deterrent against resurgence of the observed maladies. For a full text of COA Circular no. 2009-002, please click below:
COA Circular No. 2009-002
COA Circular No. 2009-002
Subscribe to:
Posts (Atom)