XBRL and Auditing

Total Page:16

File Type:pdf, Size:1020Kb

XBRL and Auditing TECHNOLOGY XBBy Kristine Brands,R CMA L XBRL and Auditing With its standardized data structure, sion. This provision gives filers limited nished to filed , making them subject to eXtensible Business Reporting Language liability for data XBRL submissions for the same liability that applies to filing of (XBRL) is suitable for a company’s assur - 24 months after a company’s initial related documents under the Securities ance needs. This column examines compliance with the mandate or by Act of 1934 that could lead to civil and several of these opportunities, including October 15, 2014, whichever is earlier. criminal penalties. Filers must recognize the status of auditing XBRL-tagged This means that as long as a filer sub - that, sometime in the future, the SEC financial statements filed under the mitted its financial statements with tags may require an auditor’s attestation Securities & Exchange Commission (SEC) XBRL Reporting Mandate of 2009 and Despite the absence of an audit requirement, internal and external auditing using XBRL. companies need to be diligent about the quality of XBRL-tagged data. No SEC Mandate Audit Requirement—Yet The SEC mandate’s final rules don’t that were chosen in good faith and report for XBRL data. When and if this require a company’s auditors to audit corrected errors promptly, the filer becomes a requirement, the PCAOB XBRL-tagged financial statements or to wouldn’t face SEC liability penalties for would likely need to develop standards participate in the tagging process. This filing errors. The provision was adopted and add this requirement to its oversight is in sharp contrast to the position because of the developmental state of activity. described in the Sarbanes-Oxley Act of the initial U.S. Generally Accepted Despite the absence of an audit 2002 (SOX) in which the SEC was to Accounting Principles (GAAP) tax - requirement, companies need to be dili - require an external audit of a company’s onomies and the lack of tools available gent about the quality of XBRL-tagged internal control system —a requirement to evaluate the accuracy of the tags and data. The SEC evaluates all inbound that frustrated filers. In a 2005 Q&A for the tagging process, issues that have XBRL filings to identify outlier data, and AT Section 101, “Attest Engagements,” been addressed since the mandate’s SEC XBRL viewer tools (tools that read the Public Company Accounting Over - effective date. an SEC filing’s tagged data and render it sight Board (PCAOB) said it permits The key language in the provision is as a financial statement) are readily avail - third-party assurance of tagged state - that the company’s interactive data is able that allow the public to access fil - ments because tagging is an element considered furnished , not filed . The SEC ings. This means that a company’s filings of disclosure controls and procedures. hasn’t issued a statement about post - can be used to generate SEC comment This is strictly voluntary, but filers need poning the provision’s expiration date. letters and that the filings are readily to monitor a key provision of the Expiration of the provision means that accessible through the Internet. The mandate—the modified liability provi - the statements’ status changes from fur - mandate has achieved transparency of 56 STRATEGIC FINANCE I February 2013 SEC XBRL-filed financial statements, one and external audit functions because of a higher degree of reliability for audit of its main objectives. Companies whose information comparability. If an organi - evidence because it’s automatically filings aren’t high quality face increased zation’s business reporting supply chain generated from the company’s data scrutiny from their stakeholders and the has XBRL-enabled systems, audit re - source—the company’s ERP database. SEC. quirements can be met with XBRL-GL Conventional auditing approaches rely Now let’s turn to how a company’s information such as the annual financial heavily on document photocopies and XBRL-tagged data can be leveraged for statement audit. Continuous auditing is manually prepared spreadsheets, internal and external auditing. a tool that organizations can use to processes that lengthen data gathering achieve that objective. and are prone to error. Additional XBRL Internal and External CA is a technology model that audits taxonomies needed to facilitate auditing Auditing with XBRL accounting data in real-time or soon are audit schedules, work papers, and Two XBRL tools that can facilitate inter - after recording transactions. Accounts audit opinions. If external stakeholders, nal and external auditing are the XBRL- can be audited directly from within the such as banks and suppliers, have XBRL- GL (Global Ledger) and continuous company’s ERP system with an embed - based systems, data sharing and transfer auditing (CA). The XBRL-GL is a taxon - ded auditing module or by transferring can be performed continuously between omy that defines financial and business the data from the company to the data - the company and these parties to meet information used in a general ledger to base of the company’s auditor. The com - audit requirements. enable a company to embed XBRL at pany can map and tag its accounts to the transaction level in its enterprise taxonomies that auditors also use, such What’s the Outlook? XBRL reporting is gaining traction and If an organization’s business reporting supply acceptance. Leveraging it for the assur - ance function is another example of how chain has XBRL-enabled systems, audit require - it can be used to streamline business ments can be met with XBRL-GL information… processes to help companies save time and money and improve the quality of resource planning (ERP) system. The as the U.S. GAAP taxonomy and XBRL- financial reporting. SF value of this framework is that it allows GL. There are several advantages to this an organization to assign XBRL tags to approach. Auditors can use tools that Kristine Brands, CMA, CPA (Minn.), is an its financial and business transactions, are standardized on a recognized XBRL assistant professor at Regis University in account balances, and data master files. taxonomy to reduce the time and cost of Colorado Springs, Colo., and is a mem - It’s also a tool that multinational compa - the audit analysis because it’s unneces - ber of IMA’s XBRL Advisory Committee nies can use to standardize their general sary to customize audit analytical and and IMA’s Pikes Peak Chapter. You can ledgers, which facilitates the internal testing tools for each client. There’s also reach her at [email protected] . February 2013 I STRATEGIC FINANCE 57.
Recommended publications
  • Continuous Auditing: Implications for Assurance, Monitoring, and Risk
    ® IPPF – Practice Guide Continuous Auditing: Implications for Assurance, Monitoring, and Risk Assessment Global Technology Audit Guide Continuous Auditing: Implications for Assurance, Monitoring, and Risk Assessment Author David Coderre, Royal Canadian Mounted Police (RCMP) Subject Matter Experts John G. Verver, ACL Services Ltd. J. Donald Warren Jr., Center for Continuous Auditing, Rutgers University Copyright © 2005 by The Institute of Internal Auditors, 247 Maitland Avenue, Altamonte Springs, Florida 32701-4201. All rights reserved. Printed in the United States of America. No part of this publication may be reproduced, stored in a retrieval system, or transmitted in any form by any means — electronic, mechanical, photocopying, recording, or otherwise — without prior written permission of the publisher. The IIA publishes this document for informational and educational purposes. This document is intended to provide information, but is not a substitute for legal or accounting advice. The IIA does not provide such advice and makes no warranty as to any legal or accounting results through its publication of this document. When legal or accounting issues arise, professional assistance should be sought and retained. GTAG — Table of Contents 1. Executive Summary Summary for Chief Audit Executive ………………………………………………………………………...............1 Continuous Auditing ………………………………………………………………………………………1 The Need for a Continuous Auditing/Continuous Monitoring: An Integrated Approach ………………1 The Roles of Internal Audit Activity and Management ……………………………………………………2 The Power of Continuous Auditing …………………………………………………………………………2 Implementation Issues ………………………………………………………………………………………2 2. Introduction …………………………………………………………………………………………………3 Continuous Auditing: A Brief History ………………………………………………………………………3 Today’s Audit Environment …………………………………………………………………………………3 COSO Enterprise Risk Management (ERM) Framework …………………………………………………4 The Roles of the Internal Audit Activity and Management ………………………………………………5 Benefits of Continuous Auditing and Monitoring …………………………………………………………5 3.
    [Show full text]
  • Transferring Continuous Auditing to The
    View metadata, citation and similar papers at core.ac.uk brought to you by CORE provided by AIS Electronic Library (AISeL) Association for Information Systems AIS Electronic Library (AISeL) Research Papers ECIS 2016 Proceedings Summer 6-15-2016 TRANSFERRING CONTINUOUS AUDITING TO THE DIGITAL AGE – THE KNOWLEDGE BASE AFTER THREE DECADES OF RESEARCH Andreas Kiesow Osnabrueck University, [email protected] Tim Schomaker Osnabrueck University, [email protected] Oliver Thomas Osnabrueck University, [email protected] Follow this and additional works at: http://aisel.aisnet.org/ecis2016_rp Recommended Citation Kiesow, Andreas; Schomaker, Tim; and Thomas, Oliver, "TRANSFERRING CONTINUOUS AUDITING TO THE DIGITAL AGE – THE KNOWLEDGE BASE AFTER THREE DECADES OF RESEARCH" (2016). Research Papers. 42. http://aisel.aisnet.org/ecis2016_rp/42 This material is brought to you by the ECIS 2016 Proceedings at AIS Electronic Library (AISeL). It has been accepted for inclusion in Research Papers by an authorized administrator of AIS Electronic Library (AISeL). For more information, please contact [email protected]. TRANSFERRING CONTINUOUS AUDITING TO THE DIGITAL AGE – THE KNOWLEDGE BASE AFTER THREE DECADES OF RESEARCH Research Kiesow, Andreas, Osnabrueck University, Germany, [email protected] Schomaker, Tim, Osnabrueck University, Germany, [email protected] Thomas, Oliver, Osnabrueck University, Germany, [email protected] Abstract Financial auditing is faced with an intensified regulatory framework and an increasing volume of ac- counting-relevant data. In order to address these challenges, information technology (IT) and corre- sponding information systems (IS) are implemented to improve the effectiveness and efficiency of audit services. In this context, continuous auditing (CA) is defined as an approach to deliver audit assurance in terms of an audit subject in real-time or almost real-time.
    [Show full text]
  • Continuous Monitoring: the Path to Continuous Auditing
    Continuous Monitoring: Paving the Road to Continuous Auditing The Less Subtle Sequel to Patrick’s Last Three Presentations Chris Rossie Co-founder & Vice President, Public Sector and International Historical Context Three Years Ago • ROI from Continuous Monitoring Two Years Ago • Continuous Monitoring Driving Operational Value One year ago • The Top Ten Wrong Things in Continuous Auditing Projects Copyright 2011 Oversight Systems. All rights reserved. / Page 2 The Problem with Continuous Auditing is Audit Audits are Pass/Fail • Little incentive for “extra credit” • Objective is to “check the boxes” Audit Budgets are Tight • External audit fees are under pressure • Internal audit department budgets are under pressure There is Tension Between Reduced Budgets and the Investments Required to Leverage Technology Copyright 2011 Oversight Systems. All rights reserved. / Page 3 Our Experiences That’s Not Bad, It’s Just Reality CM Drives Large ROI … and Does It in a Short Period of Time CA Create Value, Just Not as Large and Visible as CM But … CM Can Pave the Road to CA Let’s Look at Some Examples … Copyright 2011 Oversight Systems. All rights reserved. / Page 4 What Value Does Monitoring Deliver? • Regulations • Improper payment- FCPA real-time error OFAC prevention SOX Errors • Best practices Fraud/misuse COSO • Un-recovered GRC Program payments • Internal policies/ • Cost of capital procedures • Margin optimization • Audit Automation • 100% transaction • Resource review optimization • Fraud • Error correction Employee and prevention Vendor • Audit fees • Policy/procedures • Internal audit Procurement efficiency T&E • Recovery Audit P-cards Fees • Reporting reliability • Transaction-level analytics • Errors in Financial • Outsource • Decision support • Process improvement Reporting Effectiveness • Automated testing/reporting • Outsource SLA Management Copyright 2011 Oversight Systems.
    [Show full text]
  • UTRGV Procurement Card
    •••••••••••••••••••••••••••••••••••••••••••••••••••••• Brownsville • Edinburg • Harlingen Procurement Card – Continuous Auditing Report No. 17-06 March 2017 Office of Audits & Consulting Services March 15, 2017 Dr. Guy Bailey, President The University of Texas Rio Grande Valley 1201 West University Drive Edinburg, Texas 78539 Dear Dr. Bailey, The Office of Audits & Consulting Services has completed the audit of Procurement Card - Continuous Auditing as part of our fiscal year 2016 Audit Plan. The audit objectives were to: • develop custom data analytic reports that continuously identify procurement card transactions that may require further review; • test the items identified in the custom reports to ensure they adhere to procurement card policies and procedures; and, • determine if the custom reports could be used by management as a tool to increase awareness and compliance throughout the institution. The scope of this audit consisted of all procurement card transactions for the first eight months of fiscal year (FY) 2016 (September 1, 2015 through April 30, 2016). Our examination was conducted in accordance with guidelines set forth in The University of Texas System’s Policies UTS 129 and the Institute of Internal Auditors’ International Standards for the Professional Practice of Internal Auditing (Standards). The Standards set criteria for internal audit departments in the areas of independence, professional proficiency, scope and performance of audit work, and management of internal auditing department. UTS 129 requires that we adhere to the Standards. Overall, we concluded the majority of the procurement card transactions tested complied with procurement card policies and procedures, and were adequately documented and reviewed by the Procurement Office. In addition, we determined certain custom IDEA reports could assist management with compliance monitoring of procurement card transactions; therefore, we will continue to provide procurement management with exception reports.
    [Show full text]
  • Continuous Auditing and Continuous Monitoring: Transforming Internal Audit and Management Monitoring to Create Value
    Continuous Auditing and Continuous Monitoring: Transforming Internal Audit and Management Monitoring to Create Value ADVISORY Continuous Auditing and Continuous Monitoring: Transforming Internal Audit and Management Monitoring to Create Value As global organizations aim to address the rapidly evolving and often complex risk environment and meet ever-changing regulatory, business, and industry requirements, leaders are searching for innovative ways to efficiently meet corporate objectives. Many have begun to advance their efforts by implementing continuous auditing (CA) and continuous monitoring (CM) disciplines around their organizational processes, transactions, systems, and controls. Leveraging proactive, technology-based applications to manage performance and key areas of risk and control has become a practical and necessary alternative to meet the growing needs of the organization. Together, CA and CM offer a broad range of benefits that can help organizations add value and improve business performance. CA/CM can deliver regular insight into the status of controls and transactions across the global enterprise, enhancing risk and control oversight capability through monitoring and detection. What Is Continuous Auditing and Continuous Monitoring? Across organizations and industries, while the definitions may vary, the goal of CA/ Integrated CA/CM Model CM is to provide greater transparency into the operations and more timely reporting –Enterprise Risk + of concerns. Continuous auditing consists of the automated collection of audit evidence and indicators by an internal or Continuous Monitoring Continuous external auditor from an entity’s IT systems, processes, transactions, and controls Auditing on a frequent or continuous basis. This Controls Portfolio information enhances auditor capabilities ed and helps to ensure compliance with Processes and Transactions omat policies, procedures, and regulations.
    [Show full text]
  • AUDIT ANALYTICS and CONTINUOUS AUDIT
    AUDIT ANALYTICS and CONTINUOUS AUDIT AUDIT ANALYTICS AICPA Assurance Services Executive Committee The mission of the AICPA Assurance Services Executive Committee (ASEC) is to assure the quality, relevance, and usefulness of information or its context for decision-makers and other users by (1) identifying and prioritizing emerging trends and market needs for assurance, and (2) developing related assurance methodology guidance and tools as needed. ASEC achieves its mission by: providing guidance and leadership in identifying and prioritizing significant emerging assurance trends and market needs while engaging users, preparers, and influencers toward action; AUDIT developing assurance guidance by creating suitable criteria when necessary, and/or performance guidance, as appropriate; ANALYTICS communicating new assurance methodologies, guidance, and and opportunities to our members and the profession on a global basis; and creating alliances with industry, government, or other specialized groups to improve CPA access to new assurance opportunities. CONTINUOUS For additional information on the AICPA’s Assurance Services Executive Committee please visit aicpa.org/ASEC. AUDIT AICPA Business Reporting, Assurance and Advisory Services Team Looking Toward the Future The overarching role of the AICPA’s Business Reporting and Assurance & Advisory Services Team is to provide leadership oversight, direction and visioning for emerging business reporting and assurance issues and initiatives that are identified and addressed through input from AICPA
    [Show full text]
  • Continuous Auditing in the Shadow of SOX: Re-Engineering Interim Reporting and Assurance
    Continuous Auditing in the Shadow of SOX: Re-Engineering Interim Reporting and Assurance Efrim Boritz* Ontario Chartered Accountants Chair School of Accountancy University of Waterloo October 31, 2005 Work in Progress; Subject to Change *The author would like to acknowledge the extensive assistance provided by Chris Hicks of the Canadian Institute of Chartered Accountants and the funding provided by the Capital Markets Leadership Task Force. The views expressed in this paper are solely those of the author and may not represent the views of the members of the CMLTF. 1 of 21 - DRAFT Continuous Auditing in the Shadow of SOX: Re-Engineering Interim Reporting and Assurance A DISCUSSION PAPER October 31, 2005 J. Efrim Boritz Introduction This discussion paper is based on extensive discussions with capital markets stakeholders in Canada over the past 6 months. These discussions have included issuers/preparers, investors, auditors, board members and regulators. The purpose of these discussions was to surface issues that need to be addressed to reduce information risks borne by capital markets participants and thereby contribute to market efficiency and lower cost of capital. The key points raised in this discussion paper are: • There is a need to focus more attention on the quality of interim/continuous reporting and disclosure not just annual financial statements, because timely information is highly valued by capital market participants but the reliability of this information can be improved. • The auditing profession should strive to re-allocate much of the year end “audit” work pertaining to material transactions and events that occur throughout the year into the interim periods in which those transactions and events first occur.
    [Show full text]
  • Innovation and Practice of Continuous Auditing
    Innovation and Practice of Continuous Auditing David Y. Chan Rutgers Business School Rutgers University One Washington Park Newark, NJ 07102-3122 (E) [email protected] (T) 973-353-5172 (F) 973-353-1283 Miklos A. Vasarhelyi1 Rutgers Business School Rutgers University One Washington Park Newark, NJ 07102-3122 (E) [email protected] (T) 973-353-5172 (F) 973-353-1283 1 Respectively PhD Student and KPMG Professor of AIS, Rutgers Business School. Corresponding author [email protected]. We express our gratitude to Andreas Nicolaou, anonymous reviewer(s), participants of the Rutgers Accounting Research Forum, participants of the 2nd Annual Pre-ICIS Workshop on Accounting Information Systems, and JP Krahel for their contribution to the refinement of this paper. 1 I. Abstract The traditional audit paradigm is outdated in the real time economy. Innovation of the traditional audit process is necessary to support real time assurance. Practitioners and academics are exploring continuous auditing as a potential successor to the traditional audit paradigm. Using technology and automation, continuous auditing methodology enhances the efficiency and effectiveness of the audit process to support real time assurance. This paper defines how continuous auditing methodology introduces innovation to practice in seven dimensions and propose a four stage paradigm to advance future research. In addition, we formulate a set of methodological propositions concerning the future of assurance for practitioners and academic researchers. Keywords: Continuous Auditing, Traditional Auditing, Innovation, Audit Methodology, Audit Process, Audit Stages, Audit Practice, Analytical Procedures, Data Modeling, Data Analytics II. Introduction The objective of financial reporting is to provide information that is useful to management and stakeholders for resource allocation decisions (FASB, 2006).
    [Show full text]
  • Continuous Auditing: the Usa Experience and Considerations for Its Implementation in Brazil
    Revista de Gestão da Tecnologia e Sistemas de Informação Journal of Information Systems and Technology Management Vol. 3, No. 2, 2006, p. 211-224 ISSN online: 1807-1775 CONTINUOUS AUDITING: THE USA EXPERIENCE AND CONSIDERATIONS FOR ITS IMPLEMENTATION IN BRAZIL Michael G. Alles Rutgers Business School, U.S.A Fernando Tostes State University of Rio de Janeiro, Brazil Miklos A. Vasarhelyi Rutgers Business School, U.S.A Edson Luiz Riccio University of Sao Paulo, Brazil ______________________________________________________________________ ABSTRACT Continuous Auditing, broadly defined as the transformation of internal and external auditing through the application of modern information technology, is being increasingly adopted by firms throughout the world. Organizations ranging from Siemens, HCA, the Royal Canadian Mounted Police, BIPOP Bank and the Internal Revenue Service are developing tools and practices that will bring assurance closer to the transaction and reduce through automation, the cost of auditing. A June 2006 PricewaterhouseCoopers survey finds that 50% of U.S. companies now use continuous auditing techniques and 31% percent of the rest have already made plans to follow suit. In this article we introduce the concepts of CA to a Brazilian audience and discuss its further application there. Keywords: Continuous Auditing, CA, Auditing, Implementation, Brazil _____________________________________________________________________________________ Recebido em/Manuscript first received: 06/06/2006 Aprovado em/Manuscript accepted: 13/09/2006 Michael G. Alles, Associate Professor, Rutgers Business School, Department of Accounting & Information Systems, Ackerson Hall # 300P, 180 University Avenue, Newark, NJ 07102-1897 (973) 353 5352 (W) E-mail: [email protected] Fernando Tostes, Professor Adjunto, Universidade do Estado do Rio de Janeiro, Brasil, E-mail: [email protected] Miklos A.
    [Show full text]
  • Continuous Audit & XBRL
    A Framework for Identifying Potential Synergistic Combinations of Continuous Auditing and XBRL Glen L. Gray, PhD, CPA California State University, Northridge Rick S. Hayes, PhD, CPA California State University, Los Angeles Simple Question/Complex Answer Question: Where can synergy best be achieved between XBRL and continuous auditing? Answer: Complex m x n problem space, where m is the alternative dimensions of continuous auditing implementations and n is the alternative characteristics of XBRL implementations. Continuous auditing can be m1 x m2, where m1 is many definitions of continuous and m2 is many definitions of auditing “…„continuous‟ is a malapropism.” McCann (2009) Simple Question/Complex Answer The missing word: population Continuous auditing is almost always 100% population sample Hidden cost: What about massive false positives? Hidden risk: What about missed smoking gun? 2-step process: (1) CA, then (2) sample CA results Client-side XBRL Data Hub Client Auditor Management Mainframe XBRL Standardized Internet data analysis/ data hub mining tools Server Server Servers Internal Auit Servers Populating the XBRL Data Hub Centralized Conversions Conversion at data hub Data hub holds legacy and XBRL data Distributed Local Conversions Conversion at/near source Data hub holds XBRL data Native XBRL No conversion Data hub holds XBRL data Benefits/Costs Dimensions Implement any CA: Benefits > Costs Benefits Tangibles Increase revenue Reduce costs (efficiency) XBRL = economy of scale Shifting skill level of auditors
    [Show full text]
  • The Impact of the XBRL Environment on Auditing
    2018 9th International Symposium on Advanced Education and Management (ISAEM 2018) The impact of the XBRL environment on auditing Yuanqing Mao1, Liucheng Zhang2, * 1 School of Accounting, Harbin University of Commerce, Harbin, 150028, China 2School of Accounting, Harbin University of Commerce, Harbin, 150028, China [email protected] Keywords: XBRL, audit, impact Abstract: XBRL comes into being with the continuous development of information technology. Its application not only brought a series of positive influence to the audit works, but also made the audit works face the challenge in many aspects. This paper analyzes the effect of XBRL technology on audit and its deficiencies, and proposes corresponding countermeasures to solve problems, so as to hope that XBRL technology can more effectively reduce audit risks and improve audit service quality. 1. The concept of XBRL As an extensible business reporting language, XBRL is an emerging electronic financial reporting format. It is mainly caused by the fact that different enterprises have different forms of financial reports. In traditional electronic financial reports, there are problems that need to be converted according to different users, which makes their utilization rate very low. By adding specific labels and classifications to the data in financial accounting, XBRL enables the computer to automatically extract and process the corresponding data according to user requirements. Since XBRL is an xml-based data transfer standard, if the user's browser supports XML, it can browse and download financial reports in XBRL format, just as if the user's browser supports XML. In the current big data environment, the rapid development of the Internet has made XBRL more important, and also brought profound influence to the audit industry.
    [Show full text]
  • Continuous Monitoring and Continuous Auditing from Idea to Implementation Continuous Monitoring and Continuous Auditing: from Idea to Implementation
    Continuous monitoring and continuous auditing From idea to implementation Continuous Monitoring and Continuous Auditing: From Idea to Implementation Most financial and auditing executives are aware of The current environment of rising risks, regulatory activity, continuous controls monitoring and continuous auditing and compliance costs makes this the ideal time to consider and of the general benefits of such programs. Yet (or to reconsider) the potential role of CM or CA, or both, relatively few enterprises have realized their full potential, in your enterprise. You might also consider what it would particularly at the enterprise-wide level. Deloitte sees take to implement them, what they would look like, how the reason for this as twofold: first, executives have not they would operate, and whether to further investigate seen a clear, strong business case for establishing either these modes of monitoring and auditing. continuous monitoring (CM) or continuous auditing (CA) in their enterprises; second, they lack a clear picture of how This paper, prepared for internal audit, accounting, CM or CA would be implemented in their organizations. financial, and risk management executives, can guide you in these considerations. CEOs, COOs, and board members A quick definition, to be expanded upon below, may be who share those executives’ concerns about rising risk, in order because we have found that some confusion regulation, and costs — and the potential impact on their surrounds CM and CA. Although they are often lumped enterprises — may also find this paper informative. together, perhaps because they are both automated, ongoing processes, they are actually two distinct types of programs. As the name implies, continuous monitoring Continuous auditing enables internal audit enables management to continually review business to continually gather from processes data processes for adherence to and deviations from their that supports auditing activities.
    [Show full text]