Corporate Accounting and Auditing · Application of Technology in Audit and Audit Trail
Audit in a Computerised (CIS) Environment
Updated 10 October 2026 · Fact-checked
Audit in a CIS environment means auditing financial records that are processed by computer systems. The audit objectives stay the same, but the auditor must also understand the IT system, assess its risks, and test general controls and application controls before deciding how much to rely on system-generated data.
Understand Audit in a Computerised (CIS) Environment
A Computer Information System (CIS) is any system where a computer processes financial data, whether a small accounting package or a large ERP. The auditor's objective does not change. You still need sufficient appropriate evidence to give an opinion on the financial statements. What changes is how the records are created, stored and controlled.
In a manual system, people post entries, and a ledger clerk or supervisor checks them. In a CIS, the computer does the processing at speed and in volume. Records may exist only in electronic form. Paper trails shrink. Many checks that people once did are now built into software. So the auditor must test the system, not just the documents.
IT brings its own risks:
- Errors repeated consistently, because a wrong program logic is applied to every transaction.
- Unauthorised access, leading to changes in data or programs.
- Loss of data from failure, virus or poor backup.
- Less human review, so errors and fraud may go unnoticed.
- Over-reliance on system output without checking it.
- Unauthorised or untested program changes.
IT controls are of two kinds. General IT controls apply to the whole IT environment and support the proper working of all applications. Examples are access security, program change management, system development, backup and recovery, and operations controls. Application controls work inside one application, such as payroll or sales. They ensure that transactions are complete, accurate and authorised. Examples are input validation, sequence checks, reconciliation and output review.
The two work together. If general controls are weak, you cannot trust application controls to keep working, because anyone could change the program or data. So you test general controls first, then application controls, and then decide how much substantive testing is needed.
Key rules to remember
- General IT controls
- Access security + Program change + System development + Backup/recovery + IT operations
- Apply to the entire IT environment. Weakness here undermines every application.
- Application controls
- Input controls + Processing controls + Output controls + Master file controls
- Specific to one application. Aim at completeness, accuracy, validity and authorisation.
- Control reliance rule
- Strong general controls → test application controls → reduce substantive testing
- If general controls are weak, rely less on application controls and do more substantive work.
- Audit approaches in CIS
- Auditing around the computer | Auditing through the computer | Auditing with the computer
- Around: compare input with output, ignoring processing. Through: test processing logic with test data. With: use CAATs to analyse data.
How to solve Audit in a Computerised (CIS) Environment questions
Use this method for any question on auditing in a CIS environment, whether theory, a scenario, or a list of controls to classify.
- 1Identify what is asked: risks, controls, difference from manual audit, or an audit approach.
- 2Name the CIS feature involved, such as ERP, payroll package, online system or cloud storage.
- 3State the risk that feature creates, for example unauthorised access or consistent error.
- 4Classify each control as general or application. Ask: does it cover the whole IT environment, or one application?
- 5Link each control to the risk it addresses and to the assertion at stake, such as completeness or accuracy.
- 6Say how you would test it: inquiry, observation, inspection, re-performance or CAATs.
- 7Conclude with the effect on the audit: reliance on controls and the extent of substantive procedures.
Quickest way: Two-bucket sort: general or application
When to use it: Use when a question lists controls and asks you to classify them, or asks for examples quickly.
- Ask: if this control fails, does it affect many applications or one?
- Many applications: general control. Think access, changes, backup, development, operations.
- One application: application control. Think input, processing, output, master data.
- Write two headings, list items under each, and add one line on purpose for each item.
- Finish with one line on why general controls are tested first.
Common mistakes in Audit in a Computerised (CIS) Environment
Saying the audit objectives are different in a CIS environment.
Students see the new tools and assume a new purpose.
Fix: State that objectives and scope are unchanged. Only the procedures, risks and evidence type change.
Mixing up general and application controls.
Both are IT controls and some examples sound alike, such as passwords.
Fix: Use the test: whole environment means general, one application means application. A password to the network is general. A limit check on a sales entry is application.
Listing only risks and forgetting the controls to address them.
Students memorise risk lists without linking them.
Fix: For each risk, write a matching control and a test of it.
Claiming computers remove the risk of error.
Speed and accuracy of computers are over-credited.
Fix: Explain that a programming error is repeated consistently, and less human review can hide it.
Writing an answer without audit procedures.
Students describe the system but not what the auditor does.
Fix: Add how you test: inquiry, observation, inspection, re-performance, test data or CAATs.
Ignoring general controls when relying on application controls.
Application controls look more directly related to transactions.
Fix: State that effective general controls are needed for application controls to be relied on consistently.
Worked examples
Example 1
Distinguish between general controls and application controls in a CIS environment, with two examples of each.
Show the solution
- Define general controls: policies and procedures covering the whole IT environment and supporting all applications.
- Give examples: restricting system access through user IDs and passwords; formal approval and testing of program changes.
- Define application controls: controls within a specific application that ensure transactions are complete, accurate and authorised.
- Give examples: a validation check rejecting an invoice with an invalid customer code; a reconciliation of control totals between input and output.
- Link them: effective general controls let the auditor rely on application controls working consistently through the period.
Answer: General controls cover the entire IT environment (e.g. access security, change management). Application controls operate within one application (e.g. input validation, control total reconciliation). The auditor tests general controls first because weak general controls reduce reliance on application controls.
Example 2
Sundaram Textiles Ltd uses an ERP for sales and payroll. Identify four risks arising from the IT environment and suggest a control for each.
Show the solution
- Risk 1: unauthorised access to master data, such as changing employee pay rates. Control: role-based access with regular review of user rights.
- Risk 2: untested program changes affecting calculations. Control: formal change management with approval, testing and sign-off before going live.
- Risk 3: loss of data from system failure. Control: regular backups stored off-site, and a tested recovery plan.
- Risk 4: incomplete or wrong sales input. Control: input validation, sequence checks on invoice numbers and reconciliation of control totals.
- State the audit response: test general controls first, then the application controls, and set the extent of substantive testing based on the results.
Answer: Risks: unauthorised access, untested changes, data loss and input errors. Matching controls: role-based access, change management, backup and recovery, and validation with reconciliations. The auditor tests these controls and adjusts substantive procedures accordingly.
Exam tips
- Start any answer with one line: objectives are unchanged, but the risks and procedures change. It earns easy marks.
- In MCQs, check whether the control is system-wide or application-specific. That decides general or application.
- In written answers, use a two-column layout of risk and control. It is quick to write and easy to mark.
- Always link control testing to the extent of substantive procedures. Examiners look for that conclusion.
- Mention CAATs briefly as a way to audit with the computer, and refer to the CAAT topic for detail.
Practice questions from Application of Technology in Audit and Audit Trail
- A company's accounting software operated an audit trail from 1 April to 31 December, but the feature was disabled from 1 January to 31 March…
- In the context of the accounting software used by a company, an 'audit trail' (edit log) primarily refers to which of the following?
- Aarav & Co., auditors of Kaveri Retail Ltd., plan to rely on an automated three-way match control in the ERP. Which sequence of actions is m…
- Which of the following is a recognised risk that arises specifically from the increased use of IT in an entity's financial reporting environ…
- During the audit of a company, the auditor finds that the audit trail (edit log) feature was enabled at the application level of the account…
Audit in a Computerised (CIS) Environment: frequently asked questions
What is the difference between manual and computerised audit?
The objectives are the same. In a computerised audit, the auditor must also understand the IT system, test general and application controls, and deal with electronic records and system-specific risks. Evidence is often electronic, and CAATs may be used.
What are general controls and application controls in IT audit?
General controls apply across the IT environment, such as access security, change management and backup. Application controls operate in a specific application, such as input validation and output reconciliation. Both are needed for reliable data.
How do you audit a computerised accounting system?
Understand the system and its risks, test general controls, test application controls, and then perform substantive procedures. You may use test data or CAATs to examine processing and large data sets.
Why are general controls tested before application controls?
Application controls depend on the environment they run in. If access or program changes are poorly controlled, the application controls could be altered or bypassed, so they cannot be relied on.