Governance, Risk & Compliance Advisory Blog
Insights on best practices related to IT Audit & Compliance

Factors and guidelines to be considered while deciding the frequency of testing an IT control ?

April 18, 2010 08:47 by nirav

You would need to consider the frequency of the activity itself to decide on the frequency of the testing of the control. If the activity happens many times, you would typically test quarterly. If an activity happens twice per year, test 1 time in the first half of the year and 1 time in the second half of the year. Treat testing of IT controls the same way that the business controls are tested that would give you an opportunity to fix any issues that arise through testing. Scanning is left to departmental decisions, controls are usually tested annual at 1/3 test to be compliant. But if a control is compliant, you may not need to test it again unless something in the configuration or process has changed Business impact and business risk are the major drivers in determining the frequency of testing an IT control. Testing involves money but failures can cost a lot more. Not all controls are created equal. In very high risk situations you might need to test weekly or monthly (although that would suggest that the controls aren't adequate); in others annual will be sufficient.

Apart from the annual timelines one of the other important points to be considered for the ITGC testing will depend on the level an organisation is.
For eg:- For an organisation which does not have a well organized IT division, it would be advisable to have the review / testing / audit of the IT controls on 6 months basis. For a matured organisation, a year’s time frame is suitable.

To make it short, in an matured organisation the IT controls gets tested on regular interval depending on the certification and level a company has. In a year it can undergo SOX audit, SAS Attestation, IT Audit. All these do t ouch bases on few of the very important controls which do overlap. So the IT controls do get tested.


Currently rated 5.0 by 2 people

  • Currently 5/5 Stars.
  • 1
  • 2
  • 3
  • 4
  • 5

Related posts

Comments

April 20. 2010 19:50

Gravatar

The issuance of AS5 was followed by many discussions on how companies should adopt a risk-based control rationalization approach as part of a larger effort towards SOX optimization. These discussions centred on designing and deploying only the most effective and efficient controls to address financial reporting risks. Control rationalization applies a top-down, risk-based approach, eliminates unnecessary controls, uses risk-based testing plans, and optimizes the design of company-level and transaction controls.
The Special Topics appendix of AS5 deals with the benchmarking of automated controls. It states, 'Entirely automated application controls are generally not subject to breakdowns due to human failure. This feature allows the auditor to use a "benchmarking" strategy.'

And even though AS5 specifically addresses the possibility of using a benchmarking test strategy, it is not new, as section E122 of Auditing Standard No. 2 (AS2) specifically acknowledges benchmarking as a testing strategy permitted by the standard.


Benchmarking as mentioned in AS5 is different in the sense that it implies a testing strategy for audited automated controls in subsequent-year tests. Benchmarking as such involves documenting and testing controls embedded in an organization's applications and key reports, in order to determine whether they have maintained their integrity over time. In other words, if you are feeling well, you do not have to go the doctor every year or undergo a full-body scan. This approach is attractive since a full audit of controls in the first year without re-auditing them in subsequent years (unless a major change is made) represents a significant cost-saving opportunity.

You want to know more on this then let me know.

Regards,
Ramon

Ramon

May 18. 2010 11:34

Gravatar

I agree that IT controls are tested during audits and any misstatement can be easily identified.

Canada Business Plans

May 24. 2010 11:56

Gravatar

This blog is very informative and focuses on factors that auditors should keep in mind while performing the audit of an organization.

catering business plan

October 12. 2010 19:24

Gravatar

A 1000 payday loan can be gotten with no credit check and even online too. You may want to try applying for a check or 1000 payday loan if you are in desperate need of cash to pay bills. You don�t even have to worry about having bad credit because they accept everyone. That money can be used for just about anything you wish and the loan service can even deposit right into your account for you. The only requirement you need is to have a steady income and a checking account at the bank and you will be approved.

1000 Payday Loan

October 12. 2010 22:24

Gravatar

A 1000 payday loan can be gotten with no credit check and even online too. You may want to try applying for a check or 1000 payday loan if you are in desperate need of cash to pay bills. You don�t even have to worry about having bad credit because they accept everyone. That money can be used for just about anything you wish and the loan service can even deposit right into your account for you. The only requirement you need is to have a steady income and a checking account at the bank and you will be approved.

1000 Payday Loan

October 12. 2010 22:55

Gravatar

A 1000 payday loan can be gotten with no credit check and even online too. You may want to try applying for a check or 1000 payday loan if you are in desperate need of cash to pay bills. You don�t even have to worry about having bad credit because they accept everyone. That money can be used for just about anything you wish and the loan service can even deposit right into your account for you. The only requirement you need is to have a steady income and a checking account at the bank and you will be approved.

1000 Payday Loan

October 13. 2010 05:05

Gravatar

A 1000 payday loan can be gotten with no credit check and even online too. You may want to try applying for a check or 1000 payday loan if you are in desperate need of cash to pay bills. You don�t even have to worry about having bad credit because they accept everyone. That money can be used for just about anything you wish and the loan service can even deposit right into your account for you. The only requirement you need is to have a steady income and a checking account at the bank and you will be approved.

1000 Payday Loan

December 23. 2010 22:06

Gravatar

Your work is very good and I appreciate you and hopping for some more informative posts. Thank you for sharing great information to us

online flower delivery in abu dhabi

December 23. 2010 22:18

Gravatar

Hey great stuff, thank you for sharing this useful information and i will let know my friends as well.

flower delivery australia

January 15. 2011 17:09

Gravatar

Thanks,have a good time in diablo 2!

diablo 2 cd key

February 2. 2011 01:20

Gravatar

I suggest this site to my friends so it could be useful & informative for them also. Great effort.

send flowers philippines

February 12. 2011 08:57

Gravatar

Im not going to say what everyone else has already said, but I do want to comment on your knowledge of the topic. Youre truly well-informed. I cant believe how much of <A href="http://www.getsecuredloans.com";>secured loans</A> I just wasnt aware of. Thank you for bringing more information to this topic for me.

secured personal loans

March 14. 2011 05:08

Gravatar

The wise man will love; all others will desire.

cheap payday advance

March 31. 2011 19:32

Gravatar

Its been nice to go through your post.
It has given me much knowledge & so many valuable information.

travel marketing

June 13. 2011 07:08

Gravatar

This blog is very informative and focuses on factors that auditors should keep in mind while performing the audit of an organization.

Pandora UK

June 24. 2011 19:41

Gravatar

My developer is trying to convince me to move to .net from PHP. I have always disliked the idea because of the costs. But he's tryiong none the less. I've been using WordPress on various websites for about a year and am concerned about switching to another platform. I have heard fantastic things about blogengine.net. Is there a way I can import all my wordpress content into it? Any help would be greatly appreciated!

Cheap Loans UK

July 17. 2011 16:04

Gravatar

I was very pleased to find this web-site.I wanted to thanks for your time for this wonderful read!! I definitely enjoying every little bit of it and I have you bookmarked to check out new stuff you blog post.

SJR Builders

August 13. 2011 06:38

Gravatar

This feature allows the auditor to use a "benchmarking" strategy.'

apb cash

August 14. 2011 20:48

Gravatar

In a year it can undergo SOX audit, SAS Attestation, IT Audit. All these do t ouch bases on few of the very important controls which do overlap. So the IT controls do get tested.

buy dragon nest gold

September 17. 2011 10:49

Gravatar

Thanks sharing the valuable information in IT control sector,I like it keep it up these interesting and valuable post.

UAE universities

November 7. 2011 19:20

Gravatar

There are certainly a lot of details like that to take into consideration. That is a great point to bring up. I offer the thoughts above as general inspiration.

cabin crew training

November 14. 2011 19:15

Gravatar

This is getting a bit more subjective, but I much prefer the Zune Marketplace. The interface is colorful, has more flair, and some cool features like 'Mixview' that let you quickly see related albums, songs, or other users related to what you're listening to. Clicking on one of those will center on that item, and another set of "neighbors" will come into view, allowing you to navigate around exploring by similar artists, songs, or users. Speaking of users, the Zune "Social" is also great fun, letting you find others with shared tastes and becoming friends with them. You then can listen to a playlist created based on an amalgamation of what all your friends are listening to, which is also enjoyable. Those concerned with privacy will be relieved to know you can prevent the public from seeing your personal listening habits if you so choose.

Shampoo

November 15. 2011 17:49

Gravatar

Sorry for the huge review, but I'm really loving the new Zune, and hope this, as well as the excellent reviews some other people have written, will help you decide if it's the right choice for you.

Sulfate Free Shampoo

November 26. 2011 22:43

Gravatar

our compagnie holds IT control regular. So we don't have any problems in this domain.

3g booster

December 20. 2011 23:49

Gravatar

Hi, I found your post really helpful. It helped me all the way in completing my assignment, I am also giving a reference link of your blog in my case study. Thanks for posting such informative content. Keep posting.

hotel apartments Sharjah

December 29. 2011 13:46

Gravatar

Thank you very much for this valuable post. I just want to let you know that I just check out your site and and you rock!. I'm looking forward to read lots more of your articles... You got it covered buddy.

Sharjah hotel apartments

Add comment


(Will show your Gravatar icon)  

  Country flag




Live preview

February 5. 2012 11:18

Gravatar