Systems Auditor ExaminationStudy guide
AU (Systems Auditor): Japan’s top-tier national certification for systems audit. This course targets the multiple-choice morning exam, centered on the AU-specific Part-A-II specialty (audit fundamentals, audit planning, audit execution and techniques, IT governance and internal control, control evaluation, and reporting and follow-up). The common Part-A-I builds on the AP course; the descriptive/essay afternoon exam is out of scope.
About Systems Auditor Examination (AU)
Systems Auditor Examination (AU) is a Professional / Expert-level certification from IPA(情報処理技術者試験). This page organizes the exam scope into a 6-chapter, 25-section study guide and lets you check your understanding with exam-style practice questions. A good flow is to read the chapters below in order, then test yourself via "Practice questions."
Exam domains (approximate weighting)
- Audit fundamentals & framework~16%
- Audit planning~16%
- Audit execution & techniques~18%
- IT governance & internal control~18%
- Control evaluation~18%
- Reporting & follow-up~14%
Weights are approximate guidance for the live exam. Each domain is covered in detail in the chapters and sections below.
Official exam information: https://www.ipa.go.jp/shiken/kubun/au.html
1Audit fundamentals & framework
- 1.1Purpose and framework of systems auditing
Covers how a systems audit evaluates an information system's reliability, safety, efficiency, effectiveness, and compliance from an independent position and makes recommendations for improvement; the difference between an internal audit and an external audit; and the judgment skill of working backward from the audit objective (what one wants to assure) to the audit perspective to apply.
- 1.2System Audit Standards and System Management Standards
Covers the difference in role between the Ministry of Economy, Trade and Industry's System Audit Standards (the auditor's code of conduct: general standards, execution standards, reporting standards) and its System Management Standards (the ideal state of information-system management on the audited side), and how to use each as the auditor's yardstick.
- 1.3Auditor independence, professional ethics, and objectivity
Covers the difference between the independence in mind (an objective, fair, unbiased attitude) and the independence in appearance (being seen as independent by a third party) that a systems auditor must possess; why someone who was personally involved in the audited work lacks independence; and the judgment skill of spotting situations that impair independence while maintaining objectivity, professional ethics, and due professional care.
- 1.4Assurance-type and advisory-type audits
Covers the differences in objective, deliverable, and independence requirements between an assurance-type audit that expresses a degree of assurance, and an advisory-type (consulting) audit whose primary purpose is recommendations for improvement, and the skill of discerning "does the requester want assurance or advice" to judge the audit type and mode of engagement.
2Audit planning
- 2.1Risk-based approach & audit risk
Covers the risk-based approach, which concentrates limited audit resources on high-risk areas, and the relationship audit risk = inherent risk x control risk x detection risk. Inherent and control risk are givens the auditor assesses, while only detection risk is what the auditor controls through audit procedures; the section covers how to lower detection risk to hold audit risk to an acceptable level in areas of high inherent and control risk.
- 2.2Formulating the audit plan
Covers the three-tier hierarchy of the audit plan—the medium-to-long-term plan that sets multi-year audit policy, the annual audit plan that sets that year's audit targets and resource allocation, and the individual audit plan that sets the concrete procedures and schedule for each engagement—and the judgment of how risk-assessment results cascade from higher to lower plans.
- 2.3Materiality, audit scope & objectives
Covers the core planning judgments of materiality (how much a problem or deficiency affects decision-making and reliability), the setting of the audit scope that allocates audit resources on that basis, and the setting of the audit objective that defines "what to evaluate and what to establish." The key link is that the higher the materiality of an area, the wider the audit scope and the greater the depth.
- 2.4Preparing the audit program
Covers the role and preparation of the audit program, which concretely sets "who, when, what, by which audit technique, and what evidence to obtain" in order to achieve the audit objective, its mapping to the audit objective, and its significance in ensuring the uniformity, completeness, and reviewability of the audit. The key point is that the program is designed so one can logically trace from the audit objective to the evidence.
3Audit execution & techniques
- 3.1Audit evidence and the audit trail
Covers the two requirements that audit evidence must meet—sufficiency (quantity) and appropriateness (probative force = relevance and reliability)—the hierarchy that evidence obtained by the auditor directly or from an independent external source is more reliable, and the role of the audit trail in tracing the history of processing, together with judging which evidence to gather to support an opinion.
- 3.2Audit techniques
Covers the main audit techniques for gathering evidence—document review to scrutinize records, interviews to hear the situation from staff, the checklist method that systematizes items to confirm, reconciliation/matching that cross-checks two independent records, and on-site inspection (walkthrough/observation) to verify the field directly—and building the judgment to choose (or combine) them according to the audit objective, understanding the evidence each excels at and its limits.
- 3.3Choosing among CAATs (computer-assisted audit techniques)
Precisely distinguishes the five CAAT techniques that verify computer processing itself—test data method (verify processing with auditor-prepared data), parallel simulation (re-process with the auditor's own program and compare), ITF (integrated test facility) (run dummy audit data through production), embedded audit module (build audit functions into the production program), and generalized audit software (extract and reconcile all production data)—and judges which to choose against the audit objective and evidence sufficiency, such as the exhaustive verification of mass transactions.
- 3.4Preparing, reviewing, and retaining audit working papers
Covers the requirements that audit working papers—the record of audit execution that backs the basis for conclusions—must meet (that a third party can trace and reproduce the procedures performed, evidence obtained, and conclusions reached), how review by a superior secures audit quality, and the need for retention for a set period and for confidentiality—viewing the working papers as determining the evidential force of the audit itself.
- 3.5Sampling (statistical / non-statistical)
Covers the difference between testing (sampling) that examines part of a population and a complete examination that examines every item, the difference between statistical sampling (probabilistically inferring the population's state from the sample result) and non-statistical sampling (selected by auditor judgment), and sampling risk (the risk that a sample does not represent the population and leads to a wrong conclusion)—alongside judging how to choose testing vs. complete examination and statistical methods according to risk and materiality.
4IT governance & internal control
- 4.1IT governance and COBIT
Covers IT governance (the responsibility of executive management, and alignment of IT strategy with business strategy), which ties the use of IT to business goals and controls it, and COBIT, the framework that organizes its control objectives, building the judgment an auditor needs to decide from which viewpoint to evaluate whether IT governance is functioning.
- 4.2The six components of internal control and COSO
Covers the six basic components of internal control (control environment, risk assessment and response, control activities, information and communication, monitoring, and response to IT) and their relationship to the COSO framework (which has five components—it does not include response to IT), building the judgment to diagnose which component's absence a control deficiency stems from.
- 4.3J-SOX (the internal control reporting system)
Covers the internal control reporting system (J-SOX) under the Financial Instruments and Exchange Act—the mechanism in which management self-assesses the effectiveness of internal control over financial reporting, prepares and submits an internal control report, and an auditor audits it—building the judgment to diagnose scope narrowing (a top-down, risk-based approach) and deficiency classification (a material weakness that should be disclosed).
- 4.4IT controls (IT general controls and IT application controls)
Covers the difference between IT general controls (ITGC) (access management, program change management, development/deployment, operations management), which control the IT foundation, and IT application controls (input/processing/output controls), which safeguard the accuracy, completeness, and validity of individual business processing, plus the dependency that ★if ITGC is not effective, IT application controls cannot be relied on either, building the judgment to diagnose how a control deficiency propagates.
5Control evaluation
- 5.1Evaluating planning and development controls
Covers how a systems auditor evaluates the design and operating effectiveness of preventive and detective controls in project management, requirements definition, testing, migration, and production release, and diagnoses design deficiencies such as a lack of segregation of duties between development and operations.
- 5.2Evaluating operations and maintenance controls
Covers how an auditor evaluates the design and operating effectiveness of controls over job management, change management, configuration management, incident management, and backups, and diagnoses deficiencies such as uncontrolled emergency changes.
- 5.3Information security and business continuity controls
Covers how an auditor evaluates the design and operating effectiveness of security controls such as access management, encryption, and log monitoring, together with BCP and disaster-recovery controls, and diagnoses deficiencies such as deviations from least privilege and an untested BCP.
- 5.4Evaluating outsourcing and cloud controls
Covers how an auditor gains assurance over outsourced and cloud services they cannot directly access—through vendor management, subcontracting, SLAs, the right to audit (audit response), and the division of responsibility—including the use of a third-party assurance report (SOC report).
6Reporting & follow-up
- 6.1Audit report and recommendations for improvement
Covers the structure of the audit report that conveys results, how to build each finding on the four points of fact (current state), cause, impact (risk), and recommendation, the principle that the auditor recommends but does not implement the fix themselves (preserving independence), and the judgment of making recommendations feasible and prioritized to match the significance of the risk.
- 6.2Reporting to management and the audit opinion
Covers how to choose the reporting destination (management, or a superior who can maintain independence), the problem of reporting directly to the head of the audited department, the difference between the audit opinion of an assurance engagement (a conclusion giving a level of assurance) and the proposals of an advisory engagement (improvement proposals as the main aim), and the principle that an opinion is expressed within the scope of the audit evidence obtained.
- 6.3Follow-up and audit quality management
Covers the follow-up that tracks whether recommendations were carried out, verifying the effectiveness of remediation (confirming the effect, not merely formal completion), the principle of confirming even in follow-up with objective evidence (not taking oral answers at face value), and audit quality management (review of working papers, supervision, internal evaluation) that keeps the quality of the audit work itself.
- 6.4Related laws and guidelines
Covers the related laws (the Personal Information Protection Act, the Act on Prohibition of Unauthorized Computer Access) on which a systems auditor bases their judgment, and various guidelines such as the Systems Audit Standards and Systems Management Standards that frame the audit and the Information Security Management Standards that serve as the yardstick for control evaluation—from the applied audit viewpoint of against which standard or law a deficiency is evaluated.

