Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Information Systems
Systems Development Life Cycle and IS Audit Explained
Updated 11 October 2026 · Fact-checked
The **Systems Development Life Cycle (SDLC)** is a structured sequence of stages used to plan, build, test, deploy and maintain an information system. An **IS audit** independently examines whether that system and its controls protect assets, keep data accurate and meet legal and business needs. Answer by naming stages, then controls, then audit findings.
Understand Systems Development Life Cycle and IS Audit
An information system is built to meet a business need. Building it without a plan leads to cost overruns, missed needs and weak security. The SDLC gives the build a fixed order, so each stage has a clear output and a review point.
The common stages are: preliminary investigation or feasibility study, requirements analysis, system design, development or acquisition, testing, implementation, and post-implementation review and maintenance. Books name and group the stages slightly differently. Learn the logic, not just one list, and use the names in your study material.
A company can build a system in-house or buy it. In systems acquisition, you prepare requirements, invite proposals from vendors, evaluate them on cost, fit, support and vendor stability, and sign a contract with clear service terms. Implementation covers data conversion, user training and the changeover. Changeover can be direct (old system stops, new starts), parallel (both run together), phased (module by module) or pilot (one unit first). Parallel is safest but costly. Direct is fastest but riskiest.
An IS audit is an independent review of the information system and its controls. It checks three broad things: that data is confidential, accurate and available, that the system supports business objectives, and that laws and company policies are followed. It looks at general controls (access, change management, backup, operations) and application controls (input, processing, output checks).
The audit is also used on the SDLC itself. An auditor may review a project at each stage to check approvals, testing evidence and user sign-off. For a company secretary, this links to governance: the board must know that systems handling statutory records and financial data are controlled and documented.
Key rules to remember
- SDLC stage order
- Feasibility → Requirements → Design → Development/Acquisition → Testing → Implementation → Review and Maintenance
- Stage names vary by source. Keep the order and the output of each stage.
- Changeover methods
- Direct | Parallel | Phased | Pilot
- Parallel runs old and new together and has the lowest risk. Direct has the highest risk.
- Information security objectives
- Confidentiality + Integrity + Availability
- Use these as the test for what an IS audit protects.
- IS audit flow
- Planning → Fieldwork (evidence and testing) → Reporting → Follow-up
- Risk assessment and scoping sit inside planning.
- Control types
- Preventive | Detective | Corrective
- Classify each control by when it acts. A password is preventive, a log review is detective, a backup restore is corrective.
How to solve Systems Development Life Cycle and IS Audit questions
Exam questions are case-based. Work through the facts in a fixed order so you do not miss a mark.
- 1Read the facts and identify the task: SDLC stage, acquisition, changeover, or audit.
- 2Name the relevant stage or audit phase and state its purpose in one sentence.
- 3Link each fact in the case to a stage, a risk or a control gap.
- 4State the control or method that fits, for example parallel run, user acceptance testing, access control or change approval.
- 5Explain the risk if the control is missing, in terms of confidentiality, integrity or availability.
- 6Conclude with a clear recommendation and who is responsible, such as the board, IT head or auditor.
- 7Add a documentation or compliance point, such as sign-off, audit trail or a report to the audit committee.
Quickest way: Stage, risk, control, recommendation
When to use it: Use this when time is short or the question asks for short notes or a list.
- Write the stages in order, with a one-line output for each.
- For each stage the case mentions, add one risk and one control.
- For audit questions, write the four phases and one activity each.
- Close with a one-line conclusion tied to the facts.
Common mistakes in Systems Development Life Cycle and IS Audit
Listing SDLC stages in the wrong order or skipping testing.
Students memorise a list without understanding that each stage feeds the next.
Fix: Remember the logic: decide, specify, design, build, test, deploy, maintain. Write one output per stage.
Confusing implementation with development.
Both sound like building the system.
Fix: Development creates or buys the system. Implementation puts it into live use through conversion, training and changeover.
Saying parallel changeover is the cheapest.
Students focus on safety and forget the cost of running two systems.
Fix: Say parallel is the safest but costly. Direct is cheapest and fastest but riskiest.
Treating an IS audit as only a check of hardware or software.
The name suggests a technical review.
Fix: Cover controls, processes, people, policies and legal compliance, not just equipment.
Mixing general controls with application controls.
Both are called IT controls.
Fix: General controls cover the whole environment, such as access and backups. Application controls sit inside one program, such as input validation.
Giving a generic answer that ignores the facts.
Students write memorised theory and do not apply it.
Fix: Quote the case facts, then link each to a stage, risk and control.
Worked examples
Example 1
Kaveri Textiles Ltd is replacing its old accounting software. The CFO wants the new system to go live on 1 April and the old one switched off the same day. Advise the board on the risk and suggest a safer changeover.
Show the solution
- Identify the method: switching off the old system on the go-live day is a direct changeover.
- State the risk: if the new system has errors, there is no fallback, so accounting and statutory records may be disrupted.
- Suggest a safer method: a parallel run, where both systems process the same transactions for a set period.
- Explain the benefit: outputs of both systems can be compared, and differences show errors in data conversion or logic.
- State the cost: parallel running needs extra effort and staff time.
- Add a control: obtain user acceptance sign-off before the old system is retired.
Answer: The planned approach is a direct changeover, which is high risk. Advise a parallel run, or a phased or pilot rollout, with user acceptance sign-off before the old system is retired. Accept the extra cost because it protects the accounting records.
Example 2
Explain the main phases of an IS audit of a company's payroll system, with one activity in each phase.
Show the solution
- Planning: define the scope and objective, understand the payroll process, and assess risk, for example unauthorised changes to salary data.
- Fieldwork: collect evidence by reviewing access rights, testing whether salary changes carry approval, and checking that backups exist.
- Reporting: record findings with the risk, the evidence and a recommendation, and present them to management or the audit committee.
- Follow-up: check later whether management has fixed the gaps reported.
Answer: An IS audit of the payroll system runs through four phases: planning (scope and risk assessment), fieldwork (testing access, change approval and backups), reporting (findings and recommendations) and follow-up (checking that corrective action was taken).
Exam tips
- Write stages in order and add an output for each. A bare list earns fewer marks than a list with purpose.
- In case questions, quote the facts and tie each one to a stage or control.
- Compare changeover methods by risk and cost. Examiners like a recommendation with a reason.
- For audit answers, use the four-phase flow and mention evidence and independence.
- Use the terms confidentiality, integrity and availability when explaining why a control matters.
Practice questions from Information Systems
- In business continuity planning, which term describes the maximum amount of data loss, measured in time, that an organisation can tolerate a…
- A company's payroll software takes raw attendance records and leave data and produces salary slips. In information systems terms, the salary…
- A bank's transaction system transfers Rs 10,000 from account A to account B. The debit succeeds but the system crashes before the credit, an…
- A company secretary reviews a customer table in which each customer has a unique customer ID, and an orders table that stores the customer I…
- Which statement correctly distinguishes data from information in an information system?
Systems Development Life Cycle and IS Audit in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Systems Development Life Cycle and IS Audit: frequently asked questions
What are the SDLC phases for CS Professional?
The usual phases are feasibility study, requirements analysis, design, development or acquisition, testing, implementation, and post-implementation review and maintenance. Your study material may name or group them slightly differently, so follow its terms and keep the order.
What is the difference between SDLC and software development life cycle?
SDLC here refers to the systems development life cycle, which covers the whole information system including people, process, data and hardware. The software development life cycle focuses only on the software part. The stages are similar, and this paper stresses the system view.
How do you conduct an IS audit in simple steps?
Plan the audit by setting scope and assessing risk. Collect and test evidence on controls such as access, change management and backups. Report findings with recommendations, then follow up to confirm that the gaps were fixed.
Which changeover method is best?
No method is best in every case. Parallel is the safest but costs more. Direct is quick but risky. Phased and pilot methods balance risk and cost, so choose based on how critical the system is.