Skip to content

CMA Intermediate · Corporate Accounting and Auditing

Application of Technology in Audit and Audit Trail: formula sheet

Full chapter guide

Key formulas

Audit software tests
Audit software → tests DATA (files, balances, transactions)
Run on the client's actual records. Use for sampling, recalculation, duplicates, gaps, ageing.
Test data tests
Test data → tests PROCESSING (program logic and controls)
Dummy valid and invalid transactions are processed; compare actual output with expected output.
Test data limitation
Test data shows the program works for the cases tested, on the day tested
It does not prove the same program ran all year. Corroborate with controls over program changes.
Utility programs
Utility programs = general-purpose system tools (sort, extract, print)
Not designed for audit, so used for data handling support.
Data analytics
Import data → Validate completeness and accuracy → Analyse → Investigate exceptions → Conclude and document
Use this chain for any question on how analytics is applied in an audit.
Key point on AI
AI output = lead for investigation, not audit evidence by itself
Flagged items must be followed up and corroborated by the auditor.
Key point on RPA
RPA = rule-based + repetitive + high volume
If a task needs judgment, RPA is not suitable.
Key point on blockchain
Shared ledger + linked blocks + tamper-evident records
Improves reliability of transaction records, but input errors can still occur.
Continuous auditing
Live data + automated tests + alerts on exceptions
Tests run throughout the period, not only at year-end.
General IT controls
Access security + Program change + System development + Backup/recovery + IT operations
Apply to the entire IT environment. Weakness here undermines every application.
Application controls
Input controls + Processing controls + Output controls + Master file controls
Specific to one application. Aim at completeness, accuracy, validity and authorisation.
Control reliance rule
Strong general controls → test application controls → reduce substantive testing
If general controls are weak, rely less on application controls and do more substantive work.
Audit approaches in CIS
Auditing around the computer | Auditing through the computer | Auditing with the computer
Around: compare input with output, ignoring processing. Through: test processing logic with test data. With: use CAATs to analyse data.
Audit trail (meaning)
Source document → Journal/Voucher → Ledger → Trial balance → Financial statements (and back)
Two-way traceability is the core idea. Use it to define the term in one line.
Edit log content
Who + What (old and new value) + When (date and time) + Which transaction
Use this four-part list when asked what an edit log must capture.
Companies Act requirement (Rule 3(1), Companies (Accounts) Rules, 2014)
Software must: (1) record an audit trail of each transaction; (2) create an edit log of each change with date; (3) ensure the audit trail cannot be disabled
Applies when books are kept in electronic mode, for financial years from 1 April 2023. Keep all three parts.
Types of audit trail (by function)
Transaction trail | User/access trail | Change (edit) trail | System/event trail
Classification is a study aid. Name the type and say what it records.
Management's duty (Companies (Accounts) Rules, 2014, Rule 3(1))
Accounting software must record an audit trail of each transaction, create an edit log of each change, and the feature must not be disabled
This is the company's responsibility. The auditor reports on it but does not own it.
Auditor's reporting duty (Rule 11(g), Companies (Audit and Auditors) Rules, 2014)
Report whether (1) software has audit trail feature, (2) it operated throughout the year for all transactions, (3) it was not tampered with, and (4) the trail was preserved as per statutory requirements
Reported under Other Legal and Regulatory Requirements. Applies from financial years beginning on or after 1 April 2023.
Reporting outcome
Clean statement if all conditions are met; otherwise state the exception with specifics
A gap, such as the feature not enabled for a module or a database, must be stated in the report.

Quick revision

  • CAATs are audit tools that use computers to test data and systems, and they support the audit rather than replace judgement.
  • Two broad groups of CAATs: audit software for analysing data and test data techniques for checking system processing.
  • Data analytics lets the auditor test the whole population and spot unusual items instead of relying only on samples.
  • Technology does not change audit objectives; it changes how risks arise and how evidence is obtained.
  • General controls cover the whole IT environment, such as access, change management and backup.
  • Application controls work within a specific process, such as input checks, validation and output reconciliation.
  • An audit trail links each transaction from source to final account and shows who made or changed an entry and when.
  • An audit trail should not be capable of being disabled, and edited entries should leave the original record visible.
  • Auditors test whether the audit trail feature was on and working throughout the year, not just at year end.
  • Data from computer systems is only reliable if its completeness and accuracy have been checked first.
  • Use the structure meaning, example, risk and response for written answers.

Common mistakes

  • Writing that technology removes the need for the auditor's judgement. Fix: State clearly that tools support the auditor. Judgement, scepticism and the opinion remain with the auditor.
  • Listing only benefits and ignoring risks. Fix: Always give both sides. Use the Benefit, Risk, Response frame.
  • Saying test data checks the client's actual records. Fix: Remember test data is dummy data fed in to test program logic. Audit software works on real data.
  • Treating CAATs as a replacement for the auditor's judgement. Fix: State that CAATs are tools. The auditor plans, controls, interprets results and documents.
  • Saying AI or analytics replaces the auditor. Fix: State that tools support the auditor, who applies professional judgment and remains responsible for the opinion.
  • Confusing RPA with AI. Fix: RPA follows fixed rules and does not learn. AI learns from data and can predict or classify.
  • Saying the audit objectives are different in a CIS environment. Fix: State that objectives and scope are unchanged. Only the procedures, risks and evidence type change.
  • Mixing up general and application controls. Fix: Use the test: whole environment means general, one application means application. A password to the network is general. A limit check on a sales entry is application.
  • Treating audit trail as only the auditor's working papers. Fix: It is a record within the accounting system. The auditor examines it.
  • Leaving out the edit log when stating the rule. Fix: Always give all three parts: trail, edit log with date, and no disabling.

Exam tips

  • In MCQs, watch for options saying technology changes the audit objective or removes the auditor's responsibility. These are wrong.
  • For 5 to 7 mark answers, write headings and short points. Examiners give marks per valid point.
  • Always give a balanced answer with benefits, risks and the auditor's response.
  • Add one practical example to each main point to show application.
  • Link this topic to CAATs, data analytics and audit in a CIS environment, since questions often overlap.
  • Expect MCQs asking which CAAT fits a task. Decide between data and logic before looking at the options.
  • In descriptive answers, a 'differences' question scores best as a structured comparison on purpose, input, focus and limitation.
  • For advantages and disadvantages questions, give at least three points each and keep each to one line.