Auditing and Assurance Standards and Guidance

Auditing Standards (Ireland)

FRC ISAs (UK and Ireland) applicable for periods beginning on or after 15 December 2010 but before 17 June 2016

ISA (UK and Ireland) 315 Identifying and assessing the risk of material misstatement through understanding the entity and its environment

ISA (UK and Ireland) 315 applicable for periods ending on or after 15 December 2010
Application and Other Explanatory Material
The Required Understanding of the Entity and Its Environment, Including the Entity's Internal Control
The Entity's Internal Control (Ref: Para. 12 )
Components of Internal Control— Control Activities (Ref: Para. 20 )
Risks Arising from IT (Ref: Para. 21 )
A95.The use of IT affects the way that control activities are implemented. From the auditor's perspective, controls over IT systems are effective when they maintain the integrity of information and the security of the data such systems process, and include effective general IT-controls and application controls.
A96.General IT-controls are policies and procedures that relate to many applications and support the effective functioning of application controls. They apply to mainframe, miniframe, and end-user environments. General IT-controls that maintain the integrity of information and security of data commonly include controls over the following:
 dotbulletData center and network operations.
 dotbulletSystem software acquisition, change and maintenance.
 dotbulletProgram change.
 dotbulletAccess security.
 dotbulletApplication system acquisition, development, and maintenance.
 They are generally implemented to deal with the risks referred to in paragraph A56 above.
A97.Application controls are manual or automated procedures that typically operate at a business process level and apply to the processing of transactions by individual applications. Application controls can be preventive or detective in nature and are designed to ensure the integrity of the accounting records. Accordingly, application controls relate to procedures used to initiate, record, process and report transactions or other financial data. These controls help ensure that transactions occurred, are authorized, and are completely and accurately recorded and processed. Examples include edit checks of input data, and numerical sequence checks with manual follow-up of exception reports or correction at the point of data entry.
Top