Before IT Audit , What is Audit Types?
Senior IT Engineer Sherif A Hassan Upper Egyptian Tunisian Algerian
(Azure-Vmware-Kaspersky-ITIL-CCNA-MCSE-CISA)
Hi All :) ,
Wish all things good , before we talk about IT Audit we need to know other types of audit?
Lets start
Audited areas include: secretarial and compliance, internal controls, quality management, project management, water management, and energy conservation. Information technology audit,Software audit,cost audit,academic audit,financial audit,mainframe audit,technical audit
_____________________________________________
Performance audits
Performance audit refers to an independent examination of a program, function, operation or the management systems and procedures of a governmental or non-profit entity to assess whether the entity is achieving economy, efficiency and effectiveness in the employment of available resources. Safety, security, information systems performance, and environmental concerns are increasingly the subject of audits.[16] There are now audit professionals who specialize in security audits and information systems audits. With nonprofit organizations and government agencies, there has been an increasing need for performance audits, examining their success in satisfying mission objectives.
_______________________________________________
Quality audits
Quality audits are performed to verify conformance to standards through review of objective evidence. A system of quality audits may verify the effectiveness of a quality management system. This is part of certifications such as ISO 9001. Quality audits are essential to verify the existence of objective evidence showing conformance to required processes, to assess how successfully processes have been implemented, and to judge the effectiveness of achieving any defined target levels. Quality audits are also necessary to provide evidence concerning reduction and elimination of problem areas, and they are a hands-on management tool for achieving continual improvement in an organization.
To benefit the organization, quality auditing should not only report non-conformance and corrective actions but also highlight areas of good practice and provide evidence of conformance. In this way, other departments may share information and amend their working practices as a result, also enhancing continual improvement.
_____________________________________________
Project audit
A project audit provides an opportunity to uncover issues, concerns and challenges encountered during the project lifecycle.[17] Conducted midway through the project, an audit affords the project manager, project sponsor and project team an interim view of what has gone well, as well as what needs to be improved to successfully complete the project. If done at the close of a project, the audit can be used to develop success criteria for future projects by providing a forensic review. This review identifies which elements of the project were successfully managed and which ones presented challenges. As a result, the review will help the organization identify what it needs to do to avoid repeating the same mistakes on future projects
Projects can undergo 2 types of Project audits:[16]
Regular Health Check Audits: The aim of a regular health check audit is to understand the current state of a project in order to increase project success.
Regulatory Audits: The aim of a regulatory audit is to verify that a project is compliant with regulations and standards. Best practices of NEMEA Compliance Centre describe that, the regulatory audit must be accurate, objective, and independent while providing oversight and assurance to the organization.
Other forms of Project audits:
Formal: Applies when the project is in trouble, sponsor agrees that the audit is needed, sensitivities are high, and need to be able prove conclusions via sustainable evidence.
领英推荐
Informal: Apply when a new project manager is provided, there is no indication the projects in trouble and there is a need to report whether the project is as opposed to where its supposed to Informal audits can apply the same criteria as formal audit but there is no need for such a in depth report or formal report.[18]
________________________________________________
Energy audits
An energy audit is an inspection, survey and analysis of energy flows for energy conservation in a building, process or system to reduce the amount of energy input into the system without negatively affecting the output(s).
__________________________________________________
Operations audit
An operations audit is an examination of the operations of the client's business. In this audit the auditor thoroughly examines the efficiency, effectiveness and economy of the operations with which the management of the entity (client) is achieving its objective. The operational audit goes beyond the internal controls issues since management does not achieve its objectives merely by compliance of satisfactory system of internal controls. Operational audits cover any matters which may be commercially unsound. The objective of operational audit is to examine Three E's, namely:[citation needed] Effectiveness – doing the right things with least wastage of resources. Efficiency – performing work in least possible time. Economy – balance between benefits and costs to run the operations[citation needed]
A control self-assessment is a commonly used tool for completing an operations audit.[19]
_____________________________________________
Forensic audits
Also refer to forensic accountancy, forensic accountant or forensic accounting. It refers to an investigative audit in which accountants with specialized on both accounting and investigation seek to uncover frauds, missing money and negligence.
Thank's
See you in the next episode IT Audit
Sherif Adly Hassan
IT Engineer
00201025502007
Egypt