An information systems (IS) auditor gives other people confidence that information systems are controlled. That confidence is only worth something if the audit is done to a recognized standard by someone who is honest, competent and independent. ISACA publishes the IT Audit Framework (ITAF), which contains mandatory standards, guidelines that explain how to apply them, and tools and techniques that give practical help. The Certified Information Systems Auditor (CISA) exam expects you to think like someone who follows these standards by default, so many questions are really asking 'what would a standards-compliant auditor do next?'
The standards fall into three groups. General standards set the ground rules for the audit function and the auditor: the audit charter, organizational independence, auditor objectivity, reasonable expectation that the engagement can be completed, due professional care, proficiency, assertions and the criteria the subject matter is measured against. Performance standards govern how the work is done: risk assessment in planning, audit scheduling, performance and supervision, materiality, evidence, using the work of other experts, and irregularities and illegal acts. Reporting standards cover the report itself and follow-up activities. Standards are mandatory. Guidelines are not, but an auditor who departs from them should be able to justify and document why.
The audit charter is the starting point in practice. It is a document approved by the board or audit committee that states the audit function's purpose, authority, responsibility and accountability, including unrestricted access to records, systems and people. When an auditee later refuses access, the charter is what gives the auditor the right to escalate. An engagement letter plays a similar role for an external or one-off engagement, but the charter is the ongoing mandate for internal audit.
Independence has two parts, and the exam tests the difference. Organizational independence means the audit function reports to a level, usually the audit committee of the board, that lets it work without interference; a function that reports only to the chief information officer (CIO) whose area it audits is not independent. Independence in fact and appearance means the individual auditor has no conflicting interest or role, and that a reasonable outsider would not doubt their objectivity. Typical threats are self-review (auditing a control you designed), management participation (making decisions that belong to management), familiarity (long, close relationships with the auditee) and personal interest. Auditors may advise on controls, but the decision and the implementation stay with management. When independence is impaired, the auditor discloses the impairment to the appropriate parties rather than quietly carrying on.
The ISACA Code of Professional Ethics asks members to support the implementation of, and encourage compliance with, appropriate standards and controls; perform duties objectively, with due diligence and professional care; serve stakeholders lawfully while maintaining high standards of conduct and not discrediting the profession; maintain the privacy and confidentiality of information obtained in the course of work unless disclosure is required by legal authority; maintain competence and undertake only work they can reasonably complete; inform appropriate parties of the results of work, revealing all significant facts known; and support the professional education of stakeholders. Failure to comply can lead to an investigation and disciplinary action, including losing the certification.
Consider a worked example. You are an internal IS auditor assigned to review the identity and access management platform. Last year, before joining audit, you were the engineer who designed its role model. That is a self-review threat. The standards-compliant response is to tell the audit manager before fieldwork starts, document the issue, and either have someone else perform the review or, if that is impossible, disclose the impairment in the report. Later in the same audit, the CIO asks you to leave out a finding about shared administrator accounts because 'it will be fixed soon'. Due professional care and the ethics requirement to reveal all significant facts mean the finding stays in the report, with management's response and planned date recorded beside it.
Common mistakes: treating guidelines as mandatory or standards as optional; believing that disclosing an impairment is optional if you are confident you can stay objective; thinking confidentiality means never sharing findings (it means not disclosing outside proper channels, while still reporting results to those entitled to them); and assuming that giving advice always breaks independence. Advice is fine; taking ownership of the decision or operating the control is what crosses the line. Another trap is assuming the auditor must detect all fraud. The standards require the auditor to consider the risk of irregularities and report indicators, not to guarantee detection.
Exam questions are usually short scenarios. 'The auditor previously designed the system' or 'the auditor's spouse manages the area' points to an independence impairment, and the answer is to disclose it to audit management or the audit committee. 'Management asks the auditor to omit a finding' points to reporting honestly with management's response included. 'Which document gives the audit function its authority?' is the audit charter. 'Must an auditor follow this guideline?' calls for recognizing that departures are allowed but must be justified. When in doubt, choose the option that reports honestly through the proper channel and preserves objectivity.
Key terms
- ITAF
- ISACA's IT Audit Framework: mandatory standards, supporting guidelines, and tools and techniques for IS audit and assurance work.
- Audit charter
- A board- or audit committee-approved document that sets out the audit function's purpose, authority, responsibility and access rights.
- Organizational independence
- A reporting line for the audit function, usually to the audit committee, that lets it work without interference from the areas it audits.
- Independence in appearance
- The absence of circumstances that would lead a reasonable third party to doubt the auditor's objectivity.
- Due professional care
- Applying the skill and diligence that a prudent, competent auditor would use in the same circumstances.
- Self-review threat
- The risk that an auditor will not critically evaluate work they performed or designed themselves.
- Code of Professional Ethics
- ISACA's set of conduct principles that members and certification holders agree to follow, enforced through disciplinary procedures.
A bank's internal audit team is asked to review a new payments platform. One team member helped select the vendor and configure its approval workflow. The audit manager records the self-review threat, assigns that person to a different engagement and staffs the review with auditors who had no role in the project. The audit charter, approved by the audit committee, is cited when the vendor initially refuses to share its administrator logs, and access is granted after escalation.
Check yourself
Which ITAF element is mandatory: standards, guidelines, or tools and techniques?
Standards are mandatory; guidelines explain how to apply them and departures must be justified, and tools and techniques are practical aids.
An auditor discovers that they designed a control they are now testing. What should they do?
Disclose the self-review threat to audit management so the work can be reassigned or the impairment disclosed, because independence in fact and appearance is at risk.
What document grants the internal audit function its authority and access rights?
The audit charter, approved by the board or audit committee.
Does the Code of Ethics allow an auditor to drop a significant finding at management's request?
No; the code requires informing appropriate parties of the results and revealing all significant facts, so the finding stays with management's response.