Instiq

Systems Auditor Examination — knowledge map

The 62 core concepts of Systems Auditor Examination and how they connect. Click a node in the map above to explore related terms and prerequisites; the list below indexes every concept with its definition and links to its prerequisites and related concepts.

Concepts (62)

  • Internal control

    The mechanisms and structures a company builds into its own business processes so that operations are carried out appropriately and efficiently. It aims to prevent fraud and ensure reliable financial reporting, and responsibility for establishing and operating it rests with management.

  • Audit procedure

    The general term for the specific techniques and steps an auditor performs to obtain audit evidence. Based on the audit plan, the auditor selects and combines techniques—such as document review, interviews, on-site observation, and CAAT—according to the audit objective, and records the results in the audit working papers.

    Prerequisites: Audit planDocument review methodInterview methodOn-site observation (inspection)

    Related: Audit working papers and review

  • System audit

    An activity in which an independent auditor verifies and evaluates, from a third-party standpoint, whether an information system is operated safely and efficiently, and advises on improvements. Independence from the audited department is a precondition for the audit's credibility.

  • Risk-based audit approach

    An approach to planning and executing an audit that, given finite audit resources, concentrates effort on the areas of highest risk and materiality rather than examining every process or system to a uniform depth. Based on the assessed inherent and control risk, the auditor selects focus areas and applies more extensive procedures to higher-risk areas to make the audit more effective. This corresponds to the audit-risk framework (audit risk = inherent risk x control risk x detection risk): based on the assessed inherent and control risk, the auditor sets the nature, timing, and extent of procedures so as to hold detection risk to an acceptable level.

    Prerequisites: Audit planAudit riskControl riskDetection risk

  • Audit evidence (sufficiency and appropriateness)

    The information a systems auditor relies on to form an audit opinion. Sufficiency refers to the quantity of evidence, while appropriateness refers to its persuasive power (relevance and reliability); both must be satisfied to reasonably support an opinion. Evidence obtained directly by the auditor, or from sources external to the audited department, is generally considered more reliable than evidence obtained indirectly through the auditee.

    Related: Audit opinion

  • Audit opinion

    The conclusion an auditor states, in an assurance-type systems audit, on the adequacy or effectiveness of the audited internal controls or system, based on the audit evidence obtained. The opinion must be expressed strictly within the scope of the evidence actually gathered; the auditor must not assert conclusions unsupported by, or exceeding the scope of, that evidence. Opinion types include unqualified, qualified, adverse, and disclaimer of opinion, chosen according to evidence limitations and the presence of material deficiencies.

    Prerequisites: Internal controlSystem audit

    Related: Audit evidence (sufficiency and appropriateness)

  • Audit plan

    A plan prepared before conducting a system audit, defining the audit's objectives, scope, timing, procedures, and organization. To allocate audit resources effectively, it is often split into a medium/long-term basic plan that prioritizes higher-risk areas and a detailed individual audit plan for each specific audit.

    Prerequisites: System audit

  • Control risk

    The risk that a material error or fraud will not be prevented or detected even though internal controls exist. The auditor assesses the design and operating effectiveness of controls to gauge this risk, and applies more extensive substantive testing where control risk is judged high. Like inherent risk, it is a condition the auditor assesses rather than directly manages.

    Prerequisites: Inherent riskInternal control

  • Inherent risk

    The risk inherent to a business process or system by its very nature, assuming no internal controls exist. It stems from factors such as transaction complexity, monetary significance, or technological novelty, and is assessed by the auditor independently of whether controls are in place. Areas with high inherent risk receive a greater share of audit resources.

    Prerequisites: Internal control

  • Audit working papers and review

    Audit working papers are documents recording the audit procedures performed and the audit evidence obtained by the auditor. They are the critical record supporting the basis for the audit opinion and must be retained for a specified period after the audit concludes. Review refers to a senior person, other than the preparer, checking the adequacy and completeness of the working papers, one of the mechanisms that assures audit quality.

    Prerequisites: Audit evidence (sufficiency and appropriateness)Audit opinion

    Related: Audit procedure

  • Audit report

    The document reporting the results of a systems audit to the requester (e.g., management). It records the audit's objective and scope, the procedures performed, findings, improvement recommendations, and the audit opinion. The auditor must clearly distinguish fact-based findings from the scope of procedures actually performed.

    Prerequisites: Audit opinionAudit procedureImprovement recommendation (audit finding)System audit

  • Audit scope and audit objectives

    The audit objective states what the audit is meant to confirm — for example, the adequacy of availability controls or the effectiveness of internal controls — while the audit scope defines the boundaries of what is covered, such as the systems, processes, period, and locations included. The auditor first clarifies the objective, then delimits a scope sufficient and necessary to achieve it before planning procedures. A scope misaligned with the objective leaves conclusions inadequately supported.

    Prerequisites: Audit planInternal control

  • CAAT (computer-assisted audit techniques)

    An umbrella term for audit techniques that use computers to obtain and analyze audit evidence. It encompasses the test data method, parallel simulation, ITF (integrated test facility), embedded audit modules, and full-population verification with generalized audit software, enabling verification of large data volumes and of program processing logic itself that manual methods cannot practically achieve.

    Prerequisites: Audit evidence (sufficiency and appropriateness)

    Related: Generalized audit softwareITF (integrated test facility)Parallel simulation methodTest data methodEmbedded audit module method

  • Detection risk

    The risk that the auditor's own procedures fail to detect a material misstatement or weakness. Unlike inherent and control risk, which the auditor merely assesses, detection risk is the one component the auditor can actively manage by adjusting the nature, extent, and timing of procedures (for example, how much sampling versus full examination to use). Where inherent and control risk are high, the auditor must drive detection risk lower.

    Prerequisites: Audit procedureControl riskInherent riskSampling (statistical vs. non-statistical; test check vs. detailed check)

  • Response to IT (internal control component)

    The sixth internal control component added by Japan's J-SOX implementation standards on top of COSO's five. It refers to an organization appropriately addressing the IT environment (IT infrastructure, application controls, and IT general controls) used in its operations to achieve internal control objectives. Auditors evaluate both IT general controls (access management, change management, etc.) and application controls.

    Prerequisites: IT general controls and IT application controlsChange management controls (program change management)COSO frameworkJ-SOX (internal control reporting system)

  • Audit program

    A planning document that specifies which audit procedures will be performed, in what order and manner, to achieve the stated audit objectives. It serves as a practical guide that maintains consistent audit quality even if the assigned auditor changes, and the results of executing it are recorded in audit working papers. The program is built directly from the defined audit scope and objectives.

    Prerequisites: Audit procedureAudit scope and audit objectivesAudit working papers and review

  • Audit risk

    The risk that an auditor issues an incorrect conclusion because a material weakness goes undetected. It is modeled as the product of inherent risk, control risk, and detection risk; the auditor adjusts the scope and depth of procedures — thereby the level of detection risk — based on the assessed inherent and control risk so that overall audit risk stays within an acceptable level.

    Prerequisites: Audit procedureControl riskDetection riskInherent risk

  • Change management controls (program change management)

    Controls over the request, approval, testing, migration to production, and recording of each stage of program or system configuration changes. It is a core component of IT general controls, preventing failures or fraud arising from unauthorized changes or insufficient testing. Auditors verify that approval and segregation of duties are embedded throughout the process from change request to production deployment.

    Related: IT general controls and IT application controls

  • J-SOX (internal control reporting system)

    A system under Japan's Financial Instruments and Exchange Act requiring listed companies' management to self-assess the effectiveness of internal control over financial reporting, prepare an internal control report, and undergo audit by a certified public accountant. Management scopes the assessment using a top-down risk approach, prioritizing items of high financial materiality; auditors verify the validity of management's assessment.

    Prerequisites: MaterialityRisk-based audit approachInternal control

  • Six components of internal control (J-SOX implementation standards)

    The internal control components defined by Japan's J-SOX implementation standards. It extends COSO's five components (control environment, risk assessment and response, control activities, information and communication, monitoring) by adding "response to IT" as a sixth, independent component. Auditors evaluate the design and operation of internal control over financial reporting against these six components.

    Prerequisites: COSO frameworkResponse to IT (internal control component)J-SOX (internal control reporting system)Internal control

  • Materiality

    The degree to which a matter could influence the judgments or conclusions reached in an audit. It encompasses not only quantitative magnitude, such as monetary amount, but also qualitative significance, such as operational impact or legal and regulatory implications. The auditor uses materiality judgments to set the scope and depth of procedures, avoiding overinvestment of audit resources in trivial matters.

    Prerequisites: Audit scope and audit objectives

  • On-site observation (inspection)

    An audit technique in which the auditor personally visits the workplace or system operation site to directly observe the actual conditions. It captures realities that documents or interviews alone cannot reveal, such as adherence to work procedures or the actual state of physical access controls, and because the auditor obtains the evidence firsthand, it carries high reliability.

    Prerequisites: Design review (walkthrough, inspection)

  • Sampling (statistical vs. non-statistical; test check vs. detailed check)

    A test-check technique for obtaining audit evidence by examining a subset of a population. Statistical sampling draws the sample using objective, probability-based criteria and allows results to be generalized to the whole population, whereas non-statistical sampling relies on the auditor's experience and judgment. A test check (examining only part of the population) is distinguished from a detailed check (examining every item), and the choice between them depends on the level of risk and the availability of tools such as generalized audit software.

    Prerequisites: Audit evidence (sufficiency and appropriateness)

    Related: Generalized audit software

  • System Audit Standards

    A code of conduct issued by Japan's Ministry of Economy, Trade and Industry that governs how a systems auditor plans, performs, and reports an audit. It comprises general standards (auditor qualifications and independence), performance standards (planning and execution), and reporting standards, ensuring consistent audit quality. Auditors continually check their own procedures against this benchmark.

    Prerequisites: Audit planAudit procedureSystem audit

  • Risk assessment

    The process of identifying, analyzing, and evaluating risk by surveying the threats and vulnerabilities affecting information assets. It quantifies risk magnitude (likelihood times impact) as the basis for subsequent risk treatment decisions, forming the core of the Plan phase in the ISMS PDCA cycle.

    Related: Risk treatment (reduction, avoidance, transfer, acceptance)Information asset

  • Auditor independence

    The principle that a system auditor must remain free of interests in the audited department or the system under audit, in order to judge fairly and objectively. It requires both independence in appearance (a position free of any perceived bias to third parties) and independence in mind (a mindset that keeps one's professional judgment free from external influence).

    Prerequisites: Independence in fact and independence in appearanceSystem audit

  • IT general controls and IT application controls

    Among IT controls, IT general controls cover system-wide foundations such as access management, change management, and operations management, while IT application controls ensure the accuracy of input, processing, and output within individual business systems (input checks, reconciliation, approvals). If IT general controls are not effective, the reliability of individual IT application controls is also undermined.

    Related: Change management controls (program change management)

  • Audit quality control

    A mechanism for ensuring the quality of the audit engagement itself. Through review of audit working papers, an independent quality review, and confirmation of compliance with auditing standards, it ensures that audit procedures are appropriate and that the basis for the audit opinion is sufficient. It helps limit variability in individual auditors' judgment.

    Prerequisites: Audit opinionAudit procedureAudit working papers and review

  • COSO framework

    A framework published by the Committee of Sponsoring Organizations of the Treadway Commission (COSO cube). It consists of five components: control environment, risk assessment, control activities, information and communication, and monitoring, supporting the objectives of operational effectiveness/efficiency, reliable financial reporting, and compliance. Auditors assess the design of internal control against these five components.

    Prerequisites: Internal controlRisk assessment

  • Embedded audit module method

    A CAAT technique in which audit-specific functionality (such as extracting and logging exception transactions that meet certain conditions) is built directly into the production program, continuously collecting audit evidence while the system operates. It enables real-time, ongoing monitoring, but because it requires modifying the production program, the cost and control of implementation and maintenance become key considerations.

    Prerequisites: Audit evidence (sufficiency and appropriateness)

    Related: CAAT (computer-assisted audit techniques)

  • Follow-up

    An activity that later confirms how far the audited department has addressed issues raised in a systems audit. The auditor must not simply accept the audited department's self-reported improvements at face value, but should verify the effectiveness of the improvement using actual audit evidence such as records and operational status.

    Prerequisites: Audit evidence (sufficiency and appropriateness)System audit

  • Generalized audit software

    A general-purpose CAAT tool that lets the auditor read production data directly and perform full-population extraction, sorting, aggregation, and matching. It is well suited to exhaustive, whole-population verification, and is used to comprehensively detect outliers and exception patterns that sampling might miss. Its defining feature is versatility independent of any specific business application.

    Related: Sampling (statistical vs. non-statistical; test check vs. detailed check)CAAT (computer-assisted audit techniques)

  • Improvement recommendation (audit finding)

    A proposal by which the auditor, having identified the facts, causes, and impact (risk) of an internal control deficiency, urges the audited department to make improvements. The auditor only recommends; designing and implementing the actual control remains the responsibility of the audited department. If the auditor were to implement the corrective measures themselves, it would impair independence and must be avoided.

    Prerequisites: Internal control

  • Advisory-type audit

    A form of audit whose primary purpose is to evaluate the audited area and offer concrete recommendations for improvement, rather than to express a formal assurance conclusion. The auditor is expected to go beyond pointing out deficiencies and propose practical remedies. Because this collaborative style brings the auditor closer to the audited unit than an assurance-type audit, extra care is needed to preserve independence.

    Related: Assurance-type audit

  • Checklist method

    An audit technique in which the auditor works through a predefined list of check items aligned with the audit objective, verifying each one in turn. It helps prevent omissions and reduces variability between auditors, ensuring coverage and consistency, though it may fail to surface issues not anticipated in the list.

  • Control types (preventive, detective, corrective)

    A functional classification of internal controls into three types. Preventive controls stop errors or fraud before they occur (authorization limits, segregation of duties, access controls); detective controls identify errors or fraud that have occurred (document matching, log monitoring, exception reporting); corrective controls remediate identified problems and prevent recurrence. Auditors assess the combination and coverage of these control types.

    Prerequisites: Internal control

  • Parallel simulation method

    A CAAT technique in which the auditor runs the actual input data used by the production system through an independently prepared verification program, then compares the results against the production system's actual output. Unlike the test data method, it uses real production data, allowing verification of the accuracy of processing results under actual operating conditions.

    Prerequisites: Test data method

    Related: CAAT (computer-assisted audit techniques)

  • System Management Standards

    A practice framework issued by Japan's Ministry of Economy, Trade and Industry describing how an organization should govern the planning, development, operation, and maintenance of information systems. It sets the benchmark that the audited organization is expected to meet, and the systems auditor uses it as the yardstick for judging observed practice. It must not be confused with the System Audit Standards, which govern the auditor's own conduct.

    Prerequisites: System Audit StandardsSystem audit

  • Test data method

    A CAAT technique in which the auditor prepares test data with predetermined expected results, has it processed by the target program (or a copy of it) in a test environment separate from live data, and compares the output against the expected results to verify the correctness of the program logic. It focuses primarily on validating the program itself, and is normally run in a test environment to avoid contaminating live data—unlike the ITF method, which injects audit data into live production processing.

    Related: CAAT (computer-assisted audit techniques)

  • Availability rate

    The proportion of time a system operates correctly. Availability = MTBF ÷ (MTBF + MTTR); it rises as time-between-failures grows and repair time shrinks. A core availability metric, also used as an agreed SLA target (e.g., 99.9%).

    Prerequisites: MTBF (mean time between failures)

  • Risk treatment (reduction, avoidance, transfer, acceptance)

    Four response strategies chosen based on risk assessment results. Reduction lowers likelihood or impact through controls; avoidance stops the activity causing the risk; transfer shifts the risk to a third party via insurance or outsourcing; acceptance tolerates the risk without further action when it falls within an acceptable range. The choice balances cost against effect.

    Related: Risk assessment

  • Change types (standard, normal, emergency)

    Three categories of change in service management, distinguished by approval route and risk. A standard change is a pre-authorized, low-risk, repeatable change that needs no per-instance approval; a normal change is assessed and approved by the CAB for risk, impact, and schedule; an emergency change addresses an urgent situation such as an outage and is approved quickly by the ECAB, then documented afterward. The IT service manager decides which category each change belongs to, expanding the set of standard changes to reduce approval delay and assessment cost while keeping control.

    Related: CAB (change advisory board) and ECAB

  • Assurance-type audit

    A form of audit whose purpose is to express a level of assurance — a conclusion or opinion — on whether the audited system or internal controls conform to a predetermined criterion. The auditor gathers sufficient and appropriate evidence and reports a clear conclusion on conformity. It differs from an advisory-type audit in that issuing improvement recommendations is not the primary goal.

    Prerequisites: Internal control

    Related: Advisory-type audit

  • Audit trail

    A chronological chain of records that allows a transaction or system process to be traced from its origin to its final result, and back again. Logs, document numbers, and similar linkages let an auditor follow processing bidirectionally—from input to aggregated output or vice versa—to investigate errors or irregularities and confirm the legitimacy of processing.

  • Interview method

    An audit technique in which the auditor questions personnel or managers in the audited department to gather information and evidence about actual operations or system practices. It provides direct explanations from those involved, but statements alone carry limited evidential weight and must be corroborated with other procedures such as record review or on-site observation.

    Prerequisites: On-site observation (inspection)

  • MTBF (mean time between failures)

    For a repairable system, the average operating time from one failure to the next. A larger value means fewer failures and higher reliability. Computed as total operating time ÷ number of failures.

  • MTTR (mean time to repair)

    The average time from a failure until recovery. A smaller value means faster recovery and better maintainability. Computed as total repair time ÷ number of failures; it is part of the denominator in availability = MTBF ÷ (MTBF + MTTR), assessed together with MTBF (mean time between failures) for reliability and maintainability.

    Prerequisites: Availability rateMTBF (mean time between failures)

  • Design review (walkthrough, inspection)

    An activity in which stakeholders verify design artifacts to find errors and problems early. A walkthrough is an informal review in which the author leads by explaining the artifact while participants point out issues, with light preparation. An inspection is a formal review led by a moderator with roles assigned to participants, systematically detecting and recording defects against a checklist, giving high detection power. The architect chooses the review form by the importance of the target to prevent defects leaking into later phases.

    Prerequisites: Checklist method

  • Evaluation of access controls

    In a systems audit, the auditor's assessment of the design and operation of access controls, including authentication, authorization, the principle of least privilege, and management of privileged (administrator) IDs. The auditor verifies whether granted permissions are proportionate to job duties and whether periodic access reviews are performed.

    Prerequisites: System audit

  • Application controls (IT process controls)

    Controls embedded in an individual business system to ensure the accuracy, completeness, and validity of input, processing, and output. Examples include check digits to detect input errors, batch controls (reconciling counts and amounts), input data validation, and error reprocessing management. Auditors assess whether the automated and manual controls built into the business process adequately address the relevant risks.

    Prerequisites: IT general controls and IT application controls

  • COBIT

    An IT governance and management framework developed by ISACA that organizes control objectives systematically. Systems auditors use it as a benchmark to judge whether the design and operation of controls at an audited entity are adequate.

    Prerequisites: System audit

  • Document review method

    An audit technique in which the auditor examines documents such as policies, manuals, design specifications, minutes, and records to confirm both the design of controls (whether rules are properly established) and their operation (whether records are actually created and retained). It can verify consistency on paper, but whether practice matches documentation must be corroborated with other procedures.

  • ITF (integrated test facility)

    A CAAT technique in which a fictitious audit entity (a dummy department, business partner, or account) is established within the production environment, and auditor-prepared verification data is processed alongside real production transactions, with the results then examined. It allows continuous verification of processing accuracy in parallel with live operations, but requires safeguards to prevent contamination of actual production data.

    Related: CAAT (computer-assisted audit techniques)

  • Independence in fact and independence in appearance

    Independence in fact (mental independence) refers to the auditor's inner objectivity — forming judgments free of bias or self-interest. Independence in appearance refers to how the auditor is perceived by third parties: as having no special relationship or conflicting interest with the audited party. Auditing work one personally performed or a system one personally designed should be avoided, since even a fair judgment would damage independence in appearance.

  • ITIL

    A framework summarizing best practices in IT service management, systematizing approaches such as incident management and change management. The latest edition, ITIL 4 (2019), is reorganized around the value-co-creation-centric Service Value System (SVS) and 34 practices (the former processes are carried forward as practices).

    Prerequisites: Change management controls (program change management)

  • Segregation of duties

    A basic internal-control principle that prevents fraud and error by dividing a sequence of duties — such as approval, execution, recording, and custody — among multiple people rather than concentrating them in one person.

    Prerequisites: Internal control

  • SLA and SLM

    An SLA (service level agreement) is a document agreed between a service provider and its users specifying quality targets such as uptime and response time. SLM (service level management) is the ongoing activity of monitoring and reviewing that agreement.

    Prerequisites: Availability rate

  • Information asset

    Information that has value to an organization and is subject to risk assessment, together with the systems that handle it. It covers not only the data itself — such as customer records or design documents — but also the equipment (servers, PCs) that stores or processes it, and related business processes. Building an inventory and rating importance (confidentiality, integrity, availability) is the starting point of asset management.

    Related: Risk assessment

  • Privileged ID management

    A framework that separates privileged IDs holding system-administrator rights (root/Administrator, etc.) from ordinary user IDs and strictly manages their request, approval, issuance, usage logging (audit trail), and return. Privileged access management products automate password rotation or one-time issuance to reduce the risk of shared or permanently held credentials.

    Prerequisites: Audit trail

  • Residual risk

    The risk that remains after risk treatment (reduction, avoidance, transfer) has been applied. Because risk can never be reduced to zero, management must judge whether the remaining level is acceptable and formally approve accepting it.

    Prerequisites: Risk treatment (reduction, avoidance, transfer, acceptance)

  • Statement of Applicability (SoA)

    A document that specifies, for each control listed in Annex A of ISO/IEC 27001, whether it is applied or excluded in the organization and the rationale for that decision. It is drawn up based on risk assessment results and is a central artifact examined during ISMS certification audits.

    Prerequisites: Risk assessment

  • CAB (change advisory board) and ECAB

    The CAB (change advisory board) is a standing body that assesses the risk, impact, and schedule of normal changes and advises whether to proceed, bringing together technical, business, and user perspectives to support decisions. The ECAB (emergency change advisory board) is a small, fast-acting formation of just the few authorities needed to approve emergency changes when there is no time to convene the full CAB. The IT service manager designs the CAB agenda criteria and membership and switches to the ECAB in emergencies to balance assessment quality against speed.

    Related: Change types (standard, normal, emergency)