Not every audit asks the same question. Before you plan any work, you need to know what kind of engagement it is, because that decides the objective, the criteria, the evidence you need and who will rely on the result. The CISA exam often describes an engagement in a sentence or two and expects you to recognize its type, then choose the approach that fits it.
A financial audit gives an opinion on whether financial statements are fairly presented in accordance with an accounting framework. IS auditors support it by testing the IT general controls (ITGCs) and application controls behind financial systems, because if those controls fail, the numbers cannot be trusted. A compliance audit tests whether the organization follows specific laws, regulations, contracts or internal policies, for example a payment card security standard or a data protection law; its criteria are the requirements themselves. An operational audit evaluates whether a process is efficient and effective and achieves its objectives, such as whether the service desk resolves tickets within agreed times. An IS audit evaluates the controls over information systems: general IT controls such as access, change management and operations, and application controls inside a system. An integrated audit combines financial, operational and IS work on one process so the auditor sees the whole control picture instead of disconnected slices.
A forensic audit or investigation is different in purpose. It gathers and analyzes evidence about suspected fraud, misconduct or crime in a way that could stand up in court or a disciplinary hearing. Evidence handling becomes critical: the auditor preserves original media, works on verified copies (for example, comparing hash values before and after imaging), and keeps a chain of custody that records every person who handled the evidence and when. Forensic work often involves legal counsel from the start. Specialized reviews include administrative audits, which look at the efficiency of administrative processes, and third-party or service organization reviews, such as reading a System and Organization Controls (SOC) report on a cloud provider.
Assessments and reviews are not always audits, and the difference is the level of assurance. A control self-assessment (CSA) has the process owners evaluate their own controls, usually in facilitated workshops or through questionnaires. It builds ownership, spreads control awareness and can surface risks early, but it does not replace independent audit because the people assessing are not independent. A risk assessment identifies and rates risks rather than testing controls. A review gives limited, negative-form assurance ('nothing came to our attention') rather than the reasonable assurance of an audit. An agreed-upon procedures engagement reports factual findings from specific procedures and gives no overall opinion at all.
Consider a worked example. A retailer asks internal audit for three things in one quarter. The finance director wants comfort that the enterprise resource planning (ERP) system produces reliable revenue figures for year-end; that is IS audit work supporting a financial audit, focused on ITGCs and revenue application controls. The compliance officer wants to know whether card data handling meets the card industry standard the acquiring bank requires; that is a compliance audit with the standard as criteria. Separately, a manager reports that a buyer may be steering contracts to a relative's company; that becomes a forensic investigation, run with legal counsel, where email and purchasing records are preserved and imaged before anyone is interviewed.
Common mistakes: treating a CSA as a substitute for audit; confusing operational audits (efficiency and effectiveness) with compliance audits (following rules); starting a forensic investigation by confronting the suspect or examining original disks directly, which can destroy evidence; and assuming an integrated audit simply means several separate audits on the same day. Integration means one engagement with shared objectives and a combined conclusion. Another frequent error is relying on a review report as if it gave the same assurance as an audit opinion.
Match the assurance to the need. If a board or regulator will rely on the conclusion, an independent audit with reasonable assurance is usually required. If management wants to improve awareness and ownership across many teams cheaply, CSA fits. If the goal is to prove what happened for legal action, the forensic approach with chain of custody is needed.
Exam questions often hinge on a clue word. 'Efficiency', 'effectiveness' or 'economy' points to an operational audit. 'Laws', 'regulations', 'contract' or 'policy adherence' points to compliance. 'Fairly presented financial statements' is financial. 'Combines financial and IS procedures' is integrated. 'Suspected fraud', 'admissible' or 'chain of custody' is forensic. 'Process owners evaluate their own controls' is CSA, and the correct statement about CSA is that it supplements, not replaces, independent audit.
Key terms
- Integrated audit
- An audit that combines financial, operational and IS audit work to evaluate all the controls over a process or system together.
- Control self-assessment (CSA)
- A technique in which process owners and staff evaluate their own controls, usually in facilitated workshops.
- Forensic audit
- An engagement to collect and analyze evidence about suspected fraud or crime for possible legal or disciplinary use.
- Compliance audit
- An audit that tests adherence to specific laws, regulations, contracts or internal policies.
- Operational audit
- An audit that evaluates the efficiency, effectiveness and economy of a process or function.
- Chain of custody
- A documented record of who collected, handled and stored evidence, and when, showing it was not altered.
- Reasonable assurance
- A high but not absolute level of assurance, which is the level an audit opinion provides.
A hospital's audit committee asks whether its new electronic health record system is being used securely and in line with health privacy rules. Audit plans an integrated engagement: IS auditors test access provisioning and audit logging, compliance specialists compare practices with the privacy regulation, and operational auditors check whether clinicians' workarounds, such as shared logins at nursing stations, are slowing care or bypassing controls. One report gives the committee a single view of risk across all three angles.
Check yourself
An engagement checks whether IT help desk processes are efficient and meet their objectives. What type is it?
An operational audit, because it evaluates efficiency and effectiveness rather than rule compliance or financial statements.
What is the main benefit of control self-assessment, and its main limitation?
It builds control ownership and awareness among process owners, but it is not independent, so it cannot replace independent audit.
Why is chain of custody central to a forensic audit?
Evidence may be used in legal or disciplinary proceedings, so the organization must show who handled it and that it was not altered.
What distinguishes an integrated audit from separate financial and IS audits?
It combines the work into one engagement with shared objectives, giving a single conclusion about all controls over the process.