Information technology auditing (IT auditing) began as electronic data processing auditing and developed with the use of technology in accounting systems. Its development was affected by the need for controls over information technology and by the use of computers in performing attestation services. Accounting scandals and regulatory changes have affected the scope and practice of IT auditing. Compared with auditing more broadly, IT auditing is a relatively recent field and continues to change in response to technological and regulatory developments. The introduction of computer technology into accounting systems changed the way data was stored, retrieved and controlled. It is believed that the first use of a computerized accounting system was at General Electric in 1954. During the time period of 1954 to the mid-1960s, the auditing profession was still auditing around the computer. At this time only mainframe computers were used and few people had the skills and abilities to program computers. This began to change in the mid-1960s with the introduction of new, smaller and less expensive machines. This increased the use of computers in businesses and with it came the need for auditors to become familiar with EDP concepts in business. Along with the increase in computer use, came the rise of different types of accounting systems. The industry soon realized that they needed to develop their own software and the first of the generalized audit software (GAS) was developed. In 1968, the American Institute of Certified Public Accountants (AICPA) had the Big Eight (now the Big Four) accounting firms participate in the development of EDP auditing. The result of this was the release of Auditing & EDP. The book included how to document EDP audits and examples of how to process internal control reviews. Around this time EDP auditors formed the Electronic Data Processing Auditors Association (EDPAA). The goal of the association was to produce guidelines, procedures and standards for EDP audits. In 1977, the first edition of Control Objectives was published. This publication is now known as Control Objectives for Information and related Technology (COBIT). COBIT is the set of generally accepted IT control objectives for IT auditors. In 1994, EDPAA changed its name to Information Systems Audit and Control Association (ISACA). The period from the late 1960s through today has seen rapid changes in technology from the microcomputer and networking to the internet and with these changes came some major events that change IT auditing forever. The internet and e-commerce can increase the need for information technology auditing. The incidence of cybercrime may also increase, and IT auditing can help identify security risks associated with online activities.
Major events There are five major events in U.S. history which have had significant impact on the growth of IT auditing. These are the Equity Funding scandal, the development of the Internet and e-commerce, the 1998 IT failure at AT&T Corporation, the Enron and Arthur Andersen LLP scandal, and the September 11, 2001 Attacks. These events increased attention to the reliability, accuracy, and security of financial reporting systems and the accounting profession. Accountants audit public companies' financial statements to assess whether they conform to accounting standards. This increased scrutiny has also led to changes in regulatory requirements, internal controls, and professional standards, including those related to information technology auditing.
Equity Funding Corporation of America The first known case of misuse of information technology occurred at Equity Funding Corporation of America. Beginning in 1964 and continuing on until 1973, managers for the company booked false insurance policies to show greater profits, thus boosting the price of the capital stock of the company. If it wasn't for a whistle blower, the fraud may have never been caught. After the fraud was discovered, it took the auditing firm Touche Ross two years to confirm that the insurance policies were not real. This was one of the first cases where auditors had to audit through the computer rather than around the computer.
AT&T In 1998 AT&T suffered an IT failure that impacted worldwide commerce and communication. A major switch failed due to software and procedural errors and left many credit card users unable to access funds.
Enron and Arthur Andersen The Enron and Arthur Andersen LLP scandal led to the demise of a foremost accounting firm, an investor loss of more than $60 billion, and the largest bankruptcy in U.S. history. Although Arthur Andersen were found guilty of obstruction of justice for their role in the collapse of the energy giant in the US District Court for the Southern District of Texas (and affirmed by the Fifth Circuit in 2004), the conviction was overturned by the U.S. Supreme Court in Arthur Andersen LLP v. United States. This scandal had a significant impact on the Sarbanes-Oxley Act and was a major self-regulation violation.
See also Government Accountability Office Information technology audit
References Senft, Sandra; Manson, Danial P. PhD; Gonzales, Carol; Gallegos, Frederick (2004). Information Technology Control and Audit (2nd Ed.). Auerbach Publications. ISBN 0-8493-2032-1
External links "Spiraling Upward-History of Internal Auditing and the Institute of Internal Auditors". Internal Auditor. 48 (3). Archived from the original on March 12, 2008 – via FindArticles. Systems Auditability and Control-A History History of the Privacy Act of 1974 Computer Fraud Abuse Act Electronic the Institute of Internal Auditors Systems Auditability and Control-A History History of the Privacy Act of 1974 Computer Fraud Abuse Act Electronic Privacy Information Center-Computer Security Act of 1987 Federal Trade Commission-Privacy Act of 1974 AICPA-Summary of Sarbanes Oxley Act of 2002 Financial Privacy: The Gramm Leach Bliley Act Reference Library: Regulation California Financial Information Privacy Act Financial Accounting Standards Board
