What's changed: Initial version
2.5System Audit
Learn the purpose and flow of system audits (audit planning -> audit execution -> audit reporting -> follow-up), internal control (IT controls, segregation of duties), and the independence required of auditors.
System audit is the mechanism for objectively checking, from a position outside the parties directly involved, whether a system is properly managed and operated. The key points of this section are who checks, in what flow, and against what criteria.
2.5.1The purpose and flow of an audit
- System audit is the activity of evaluating, from a third-party standpoint, whether an information system is properly managed and operated from the viewpoints of reliability, safety, and efficiency, and using that to drive improvement.
- An audit proceeds through audit planning (defining the audit's purpose, scope, and schedule) -> audit execution (gathering evidence by reviewing documents, interviewing people, and on-site checks) -> audit reporting (reporting the problems found and improvement proposals to management, etc.) -> follow-up (checking at a later date whether the reported improvements were actually carried out).
2.5.2Internal control and auditor independence
- Internal control is the general term for the mechanisms and rules an organization builds internally to properly carry out its own operations. IT controls are the internal controls related to information systems (managing access privileges, keeping approval records for changes, etc.).
- Segregation of duties is a representative internal-control mechanism that splits roles among multiple people so that authority and work do not concentrate in one person. For example, separating "the person who requests a system change" from "the person who approves it" makes fraud or error harder for any single individual to cause alone.
- The independence required of an auditor means being in a position with no vested interest in the audited operations. If someone who was in charge of the audited operations audits themselves, an objective evaluation is impossible—independence is the foundation of an audit's credibility.
The staples: an audit proceeds planning -> execution -> reporting -> follow-up; follow-up checks at a later date whether improvements were actually carried out; segregation of duties splits authority among multiple people to prevent fraud or error; an auditor needs independence, with no vested interest in what is being audited.
Trace one scene of a system audit targeting access-privilege management in an accounting system. The audit department first sets audit planning: the purpose and scope for this period will be "checking whether unnecessary privileges have been left unattended in the accounting system's access controls." Next, in audit execution, the auditors review the actual list of access privileges and interview the system administrator to check whether accounts for employees who have already been transferred still remain. Suppose this process turns up a problem: "three accounts belonging to former employees still exist with active privileges." The auditor reports this as audit reporting to management and the IT department, attaching an improvement proposal such as "thoroughly enforce account-deletion procedures upon resignation or transfer." The audit is not finished there—only after later performing follow-up, confirming whether the account-deletion procedures were actually put in place and carried out as proposed, does the audit cycle truly complete. The viewpoint this audit was examining, "whether privileges have been left behind," ultimately comes down to checking whether IT controls (internal controls related to information systems) are functioning. This company also has, as part of its internal control, segregation of duties that assigns "the person who requests a system change" and "the person who approves that request" to different people, curbing the risk of one person alone pushing through an improper change. Note also: if the auditor conducting this audit were themselves the person who normally handles the accounting system's privilege settings as their day job, they would be evaluating their own work, and objectivity could not be maintained. This is why an auditor is required to have independence, with no vested interest in the audited operations.
| Step | What happens |
|---|---|
| Audit planning | Define purpose, scope, and schedule |
| Audit execution | Gather evidence via document review, interviews, on-site checks |
| Audit reporting | Report problems and improvement proposals to management |
| Follow-up | Later confirm whether improvements were carried out |
Trap: "an audit is complete once the report is submitted" is wrong—the audit cycle is only complete after follow-up, confirming whether the improvement proposals were actually carried out. Also, "it is most efficient for the person who operates the system to audit it themselves" is wrong—if the person responsible for the audited operations becomes the auditor, independence cannot be maintained and an objective evaluation is impossible. An auditor must be in a position with no vested interest in what is being audited.
2.5.3Section summary
- An audit follows audit planning -> audit execution -> audit reporting -> follow-up. It completes only when follow-up later confirms the improvements were carried out
- A representative example of internal control (including IT controls) is segregation of duties—splitting authority among multiple people to prevent fraud or error
- An auditor must have independence, with no vested interest in what is being audited
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. In a system audit, which step later confirms whether the improvement proposals stated in the audit report were actually carried out?
Q2. A mechanism that assigns the person who requests a system change and the person who approves that request to different people is a representative example of what internal control practice?
Q3. Which requirement is most strongly demanded of a person conducting a system audit?

