Instiq
Chapter 1 · Audit fundamentals & framework·v1.0.0·Updated 7/11/2026·~14 min

What's changed: Initial version

1.1Purpose and framework of systems auditing

Key points

Covers how a systems audit evaluates an information system's reliability, safety, efficiency, effectiveness, and compliance from an independent position and makes recommendations for improvement; the difference between an internal audit and an external audit; and the judgment skill of working backward from the audit objective (what one wants to assure) to the audit perspective to apply.

AU's exam A-2 specialty does not test rote definitions such as "what is a systems audit"; it tests the ability to judge, under constraints of risk and materiality, which evaluation perspective (reliability, safety, efficiency, effectiveness, compliance) to hold the information system against, what to verify, and how to recommend improvement. A systems audit is the activity in which an independent, professional systems auditor inspects and evaluates an information system and its management arrangements, points out problems, and prompts improvement; its essence is that the auditor is neither the party that builds the system nor the party that operates it, but rather the party that evaluates from the outside whether those are appropriate.

1.1.1The five evaluation perspectives of a systems audit

  • Reliability means the information system operates stably without error and provides correct, consistent results even on failure. Safety means confidentiality, integrity, and availability are secured, protecting assets and information from unauthorized access, disasters, and accidents.
  • Efficiency means management resources (people, assets, money, information, time) are used without waste, operating at a cost and performance commensurate with cost-effectiveness. Effectiveness means the information system actually contributes to achieving business goals and requirements (a system that was built but is unused has low effectiveness).
  • Compliance means the information system and its management adhere to laws, internal rules, contracts, and various standards (such as the System Audit Standards and System Management Standards). From these five perspectives, the auditor selects and prioritizes the ones important in light of the objective of that particular audit.

1.1.2Internal vs. external audit, and the position of the audit

  • An internal audit is an audit in which an internal audit department the organization itself has established inspects and evaluates its own information systems. It is expected to report directly to management and be independent of the audited departments. An external audit is conducted by an independent auditor outside the organization (an audit firm, a consulting firm, etc.), where objectivity and independence as a third party are more structurally assured.
  • A systems audit is not an activity that produces value in itself, but an "evaluation and advice" activity that supports the achievement of business goals from the information-systems side. The auditor's responsibility does not stop at findings (discovering problems) but extends to making recommendations leading to improvement and later confirming the state of that improvement (follow-up).
Exam point

Most-tested: the purpose of a systems audit is evaluating and recommending improvement of reliability, safety, efficiency, effectiveness, and compliance; effectiveness is contribution to achieving business goals (merely being built is not effective); and the auditor is the evaluating party, not the building or operating party. Practice being able to judge which of the five perspectives to prioritize according to the audit objective.

Suppose you are a systems auditor in an internal audit department, asked to audit a core business system. Management's concern is that "we invested heavily in this system, yet we don't feel it has led to improvement in frontline work." If you carelessly finish after only checking "whether the system runs correctly (reliability)" or "whether security is fine (safety)," you cannot answer the question management truly wants answered: whether the information system they invested in actually helps achieve business goals and requirements. The perspective to prioritize in this audit is effectiveness, and rather than "does the system operate as specified," the auditor verifies "are the original objectives (shortening work time, reducing errors, etc.) actually being achieved," "are the user departments truly making use of it," and "are there unused features or hollowed-out procedures" by means of usage-record data, frontline interviews, and reconciliation against the original investment plan. If the investigation reveals that "the system runs technically without problems, but the input procedure is cumbersome, so the frontline keeps a separate duplicate Excel ledger," the auditor points out a lack of effectiveness rather than reliability, and recommends improvement together with the business process (simplifying the UI, reviewing operations). The starting point of a systems audit is the procedure of "first discern which of the five perspectives this audit's objective is asking about, then design the facts and evidence to verify from there."

Evaluation perspectiveWhat it verifiesMain question
ReliabilityWhether it runs stably without error and yields correct resultsCan it process consistently even on failure?
SafetyWhether confidentiality, integrity, availability are protectedCan it protect assets from unauthorized access and disaster?
EfficiencyWhether resources are used without waste, cost-effectivelyAre there excessive costs or idle resources?
EffectivenessWhether it helps achieve business goals and requirementsAre the original objectives actually being achieved?
ComplianceWhether it follows laws, rules, standards, contractsDoes it comply with internal rules and relevant laws?
Warning

Trap: "As long as the system runs technically correctly, the purpose of a systems audit is achieved" is wrong—even if technical reliability is confirmed, if the system does not help achieve business goals there is a problem from the effectiveness perspective, which can become a finding depending on the audit objective. Also wrong: "a systems auditor's role is to fix system defects"—the auditor is in a position to evaluate and recommend improvement, and getting involved in fixing (building, operating) it would impair independence; the role differs.

Five evaluation axes.
Assessing IT from many angles

1.1.3Section summary

  • A systems audit evaluates an information system's reliability, safety, efficiency, effectiveness, and compliance from an independent position and recommends improvement
  • Effectiveness asks about "contribution to achieving business goals" and is a separate axis from merely running technically (reliability)
  • The auditor is the evaluating party, not the building or operating party, and judges which of the five perspectives to prioritize according to the audit objective

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. Management has requested confirmation of "whether the core business system, in which a large sum was invested, truly leads to improvement in frontline work." Which evaluation perspective should the systems auditor prioritize most in this audit?

Q2. At a company, the information systems department is about to conduct a systems audit. From the perspective of audit independence and objectivity, which statement about the systems auditor's role is most appropriate?

Q3. In an internal audit where an internal audit department audits its own organization's information systems, which arrangement is most appropriate for securing independence?

Check your understandingPractice questions for Chapter 1: Audit fundamentals & framework