Audit Types and Engagement Objectives
Compliance, substantive, operational and integrated engagements ask different questions. Choosing the wrong one produces a technically correct answer to something nobody asked.
What this makes you able to do
Select the audit approach and engagement objective appropriate to the assurance being sought.
By the end you can
- Distinguish compliance testing from substantive testing by what each concludes.
- Determine when the result of compliance testing permits reduced substantive testing.
- Identify the engagement type appropriate to a stated assurance need.
Transcript
Audit types and engagement objectives. This lesson is about choosing the audit approach that matches the assurance being sought, because the wrong choice gives you a technically correct answer to a question nobody asked.
Here is how that goes wrong. Management asks for assurance over the payroll system. You test that every change had an approval, that access was granted through the correct workflow, and that the interface reconciliation ran nightly and was signed. Everything passes, and you report that payroll controls are operating effectively. Then someone points out that payroll has been overpaying a group of staff for eight months.
Nothing you tested would have found it. And that is not a mistake in your testing, it is a mistake in the type of testing. You proved the machinery ran. You never proved the machinery produced the right answer.
The first type is compliance testing. Compliance testing determines whether a control operated as prescribed throughout the period. Every change had an approval. Every leaver was deprovisioned in time. The reconciliation was performed and signed each night. It concludes on the control, not on the data.
The second type is substantive testing. Substantive testing determines whether the data or the outcome is materially correct, regardless of what the controls did. Recalculating gross-to-net pay for a sample of employees. Confirming the entitlements in the identity provider match the approved matrix. That is what would have caught the overpayment.
And the two are connected, which the exam tests constantly. The result of compliance testing drives the extent of substantive work. If controls test clean, control risk is lower and you can justify less substantive testing. If exceptions are high, the control cannot be relied upon and substantive testing increases. More control exceptions mean more substantive work, never less.
Beyond those two, there are engagement types the exam expects you to recognise. An operational audit examines whether a process achieves its objectives economically, efficiently and effectively. Benefits realisation and capacity utilisation live here. It is not concerned with compliance for its own sake.
An integrated audit combines information systems audit with financial or operational audit, so that general and application controls are evaluated alongside the financial assertions that depend on them. This is the natural home of the question, can we rely on this automated control.
And a forensic audit responds to suspected fraud or irregularity. It differs in method, in how evidence is handled, and in the need to preserve chain of custody. Nothing about the routine audit approach applies unchanged when fraud is suspected.
Which brings us to the two reflexes that cost marks. The first is presenting compliance results as if they answered a substantive question. All changes were approved says nothing about whether the changes were correct. Auditors who have spent years in controls testing develop a reflex that a clean control test means a clean outcome, and the exam sets traps on exactly that reflex.
The second is misreading the direction of that relationship. More control exceptions mean more substantive work. If an option offers to reduce testing because a deficiency has already been identified, it is wrong. Carry both away, and read carefully which question the engagement is actually asking.
1.An IS auditor tests whether every change deployed in the period had an approved change ticket. This is an example of:
2.Compliance testing of access provisioning controls produces a high exception rate. What is the MOST appropriate effect on the substantive testing planned?
3.Management asks whether the new procurement system is delivering the efficiency savings promised in its business case. This is BEST addressed by:
Independent training produced by Marco Cavani. Not affiliated with, endorsed by, or sponsored by ISACA. CISA is a registered trademark of ISACA. Practice questions are written for this course and are not reproduced from ISACA materials.
Stay ahead of cyber threats
Get the latest cybersecurity reports, threat intelligence, and IT governance insights delivered straight to your inbox. No spam. Unsubscribe any time.
No spam. Unsubscribe at any time.
