External Audit and Assessment
External audits and assessments offer independent oversight, confirm compliance, identify weaknesses, and recommend improvements.
5 slides · 3 min read · Domain 6
An external audit is an assessment performed by a third party to demonstrate that the organization's controls and practices meet a compliance standard.
A compliance standard imposes consequences on the organization for not meeting the standard. These consequences can include financial penalties, criminal sanctions, limitations on business activities, or a variety of other actions.
External audits are regularly chartered by organizations to report on risk, governance, and financial status. These audits typically employ an independent organization with no conflict of interests related to the organization they are evaluating. In other cases, the compliance body performs the audit as part of their interactions with the covered organizations. Regardless, the audited organization is responsible for demonstrating compliance with the applicable standard.
Typically, external audits follow the assessment process, with greater rigor and documentation.
Chartering is the responsibility of the audited organization's governing body. They will ensure the audit schedule is set, the scope is identified, and the work is resourced. The governing body will also identify the individuals in the management structure responsible for the coordination of the audit activities. In many cases, these activities are directed by the compliance framework or auditing organization.
The audit charter will define the audit scope and objectives.
The scope and objectives will be influenced by the type of audit being performed and the standard to which the organization is being assessed.
The most common types of audit include: Typically, the organization being evaluated knows in advance that
- Compliance audits. Tests specific
the audit will be performed and the controls to determine whether the standard by which it will be applied controls meet a particular standard.
by the auditing organization. This allows the audited organization to plan
- Financial audits. Evaluates the accuracy I
appropriate support for the auditing of financial reporting.
agency, identifying artifacts and collection methods that the auditors will
- Operational audits. Tests the internal controls of a process.
need to prepare their report.
- Information systems audits. Evaluates controls performance in the development and operation of information systems.
- Integrated audits. Combines elements of operational and financial systems controls.
- Forensic audits. Focuses on discovering, investigating, and reporting fraud or other criminal activity.
Pre-audit planning is necessary to identify the skills and resources to meet audit objectives. Typically, this will include the preparation of an audit checklist that details the areas to be investigated, the necessary artifacts to be collected, the individuals to be interviewed, and the schedule of the audit.
The audit checklist is shared with the audited entity to identify any gaps in the coverage, ensure the availability of key personnel, and prepare for access to locations and facilities.
Audit execution occurs when the auditing organization begins to collect artifacts, perform the tests, and conduct the interviews identified during pre-audit planning. This includes on-site work as well as any testing performed remotely.
The audit reporting phase gathers the artifacts and subjects them to analysis and review.
The results of the auditing activities are generally compiled into a draft report, which details the draft findings. These are typically shared with the audited organization to ensure that the evidence is properly reflected by the findings. It is common for an artifact to be missed or improperly evaluated, so the review of the draft findings allows any errors to be clarified prior to the audit. This phase concludes when the final audit results are presented to the organization that chartered the audit, consistent with the audit charter.
It is essential that the auditing organization have sufficient expertise to evaluate the systems and environment defined in the scope of the audit. This may require the auditing agency to engage a third party to perform specialized tests or evaluations. These arrangements must be authorized by the audit charter and defined in the audit scope.
