Jump to content

Recommended Posts

Posted

Hi All,

 

Has anyone been through a full finance audit since ISA 315 was updated with regard to IT processes and their impact?

 

We've been handed a 'questionnaire' by our auditors, which isn't actually a questionnaire but a blank table with some examples. They are suggesting that we need to complete the table, listing all IT processes, risk assessments and what system they relate too. And to do this for all systems we use across the School. So essentially looking at every system from the POV of permissions, user access, authentication methods, risk mitigation, security, backups etc. I've questioned whether this should only be for systems relating to the production of financial statements (as my research online would suggest) but the auditors have said it needs to be everything, giving examples such as "teacher laptops, next of kin information and online student attendance recording".

 

I just wondered if anyone had any experience of this yet, as to produce that for all of our systems and processes would be a large time commitment, and I wonder if the auditors themselves have got the wrong end of the stick. I've read ISA 315 appendix 5 and to me it reads that it only covers processes relating to the production of financial statements. We've asked for an example of a completed questionnaire but they say they can't find one (?!) and have instead just given us a one line example of a single IT process for one system.

 

Appreciate any pointers - if it has to be done with all systems in scope, then it has to be done, but don't want to do it unnecessarily!

  • 2 weeks later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...