Instiq
Chapter 5 · Management·v1.0.0·Updated 7/9/2026·~16 min

What's changed: Initial version (chapter 5, s1-s3)

5.3System Audit and Internal Control

Key points

Learn the audit process (audit planning, execution, reporting, follow-up), audit evidence (sufficiency and appropriateness) and audit techniques (interviews, document review, on-site inspection, CAAT), internal control (IT controls--IT general controls and application controls--and segregation of duties), auditability, and auditor independence.

A system audit is the activity of evaluating, from an independent third-party standpoint, whether an information system is properly controlled in line with an organization's objectives. On the AP exam, the role of each stage of the audit process, internal control (especially the distinction between IT general controls and application controls, and segregation of duties), and auditor independence (the prohibition on self-audits) are recurring topics tested for understanding.

5.3.1The audit process and audit evidence/techniques

  • The system audit process proceeds through four stages: audit planning (defining scope, audit items, and schedule) -> execution (gathering and evaluating evidence) -> reporting (reporting findings and improvement recommendations to management) -> follow-up (confirming afterward whether findings were corrected). The key point is that the audit cycle is only complete once follow-up is included.
  • Audit evidence must satisfy both sufficiency (quantity--an adequate volume of support) and appropriateness (quality--high quality as evidence, meaning relevance and reliability). A large volume of low-quality evidence alone is not adequate grounds for an audit opinion. Audit techniques--interviews (questioning people), document review (examining regulations and records), on-site inspection (physical inspection of the site), and CAAT (Computer-Assisted Audit Techniques) (mechanically analyzing logs/data with tools or software)--are combined as fits the purpose.

5.3.2Internal control: IT general controls, application controls, and segregation of duties

  • Internal control is the overall set of mechanisms an organization builds and operates itself so that its operations are conducted properly (aimed at fraud prevention, operational effectiveness, reliable financial reporting, legal compliance, and so on). IT controls are the IT-related part of this, broadly divided into IT general controls and application controls (IT application controls).
  • IT general controls are controls that support the entire IT environment across the board, not limited to any specific business process (access management, system development/change management, operations management, outsourcing management, and so on). Application controls (IT application controls) are controls built into an individual business application (input checks, approval functions, error detection, the accuracy of automated calculations, and so on). Understand the hierarchical relationship--general controls are the foundation for application controls--such that if IT general controls are not functioning effectively, the very premise of reliability for individual application controls is undermined.
  • Segregation of duties is a representative example of internal control that splits work across multiple people or roles so authority and tasks do not concentrate in one person (for example, making the requester and approver different people). Its main purpose is avoiding concentrated authority to prevent fraud and error; operational efficiency, if anything, can arise as a trade-off cost.
Exam point

The staples: the audit process = planning -> execution -> reporting -> follow-up; audit evidence needs both sufficiency (quantity) and appropriateness (quality); IT general controls span the whole IT environment, application controls are built into an individual application; segregation of duties prevents fraud/error by splitting authority (efficiency is not the main purpose). A classic wrong-answer pattern confuses the scope of IT general controls and application controls (cross-cutting vs. individual).

Take the system audit of a company's expense reimbursement system as an example of how the process and internal control connect. At the audit planning stage, the auditor sets "whether fraud-prevention controls function in the expense approval process" as an audit item and decides the scope and schedule. What matters here is who is selected as auditor: if the very engineer who developed this system became the auditor, that would be a self-audit, undermining independence, so a different person uninvolved in development or operations is chosen instead. At the execution stage, multiple audit techniques are combined to gather evidence. First, document review checks the expense approval regulations to confirm the rule "the requester and approver must be different people"--segregation of duties--is written into the regulations. Next, an interview with expense-accounting staff asks whether operations actually follow the regulations as written. Further, CAAT analyzes the system's logs, mechanically detecting "transactions where the requester and approver are the same person." Suppose the investigation turns up a number of transactions, during one period, that were processed with the approver field left blank--this becomes a serious finding indicating that the application control (the control built into the approval function) had become hollowed out. Digging further, suppose it turns out that this system's change management (part of IT general controls) had been lax, and a fix to make the approver field mandatory had been left unaddressed for a long time--this reveals a structure in which the root cause of the individual application control's deficiency lies in a weakness in the higher-level IT general controls. In this case, the problem could be detected precisely because the log accurately recorded and made traceable the requester, approver, and timestamp of every transaction--a reflection of the system's high auditability. At the reporting stage, this finding and an improvement recommendation (such as the system change making the approver field mandatory) are reported to management, and at the follow-up stage, whether the change was actually made and segregation of duties restored to functioning is confirmed afterward, completing the audit cycle.

Type of controlScopeExample
IT general controlsSpans the entire IT environmentAccess management, change management, operations management
Application controlsBuilt into an individual applicationInput checks, approval functions, accuracy of automated calculations
Warning

Trap: "it is most efficient and desirable for the engineer who built a system to audit that same system" is wrong--a developer becoming the auditor is a self-audit that undermines independence and should be avoided. Also, "the main purpose of segregation of duties is to make operations more efficient" is wrong--its main purpose is avoiding concentrated authority to prevent fraud and error; efficiency, if anything, can arise as a trade-off cost. Furthermore, "application controls span the entire IT environment while IT general controls are built into an individual application" is wrong--the scope is reversed: correctly, IT general controls are cross-cutting and application controls are built into an individual application.

Audit process, internal control, independence.
Audit and internal control mechanisms

5.3.3Section summary

  • System audit process = planning -> execution -> reporting -> follow-up. Audit evidence needs both sufficiency (quantity) and appropriateness (quality)
  • IT general controls support the entire IT environment across the board; application controls are built into an individual application. A hierarchical relationship: general controls are the foundation for application controls
  • Segregation of duties = splitting authority/tasks to prevent fraud/error (efficiency is not the main purpose). Auditor independence = an objective standpoint independent from the audited target (self-audit is not allowed)

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. Engineer B, who developed the company's own expense reimbursement system, is set to serve as the auditor for that system's system audit. What is the most appropriate concern about this arrangement?

Q2. In a system audit, you want to distinguish controls that cross-cuttingly support the entire IT environment--such as access management, change management, and operations management--from controls built into an individual business application, such as the approval function of an expense reimbursement application. Which term refers to the former?

Q3. A system auditor used a dedicated tool to mechanically analyze the access logs of the audited system and detect transactions processed with the approver field left blank. Which audit technique does this evidence-gathering method correspond to?

Check your understandingPractice questions for Chapter 5: Management

Keep track of your progress

The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.