Skip to content

CA Intermediate · Auditing and Ethics · Audit of Banks

CA Imran is planning the audit of a bank branch that carries out most of its transactions through core banking software. Which of the following is the most appropriate step in his audit approach?

The auditor should test the relevant IT general controls and application controls and then rely on system reports whose integrity he has checked. Agreeing balances to a trial balance from the same system is circular, and a vendor's assurance does not replace the auditor's own evidence.

  1. AIgnore IT general controls because the balances can be agreed to the trial balance generated by the same system
  2. BRely on the system-generated reports after testing the relevant IT general controls and application controls, and test the integrity of key reports used in the auditCorrect
  3. CPerform the entire audit manually by ignoring system reports
  4. DRely on the bank's IT vendor's assurance that the software is accurate, without any testing

Explanation

In a core banking environment, the reliability of data depends on IT general and application controls, so the auditor tests these and the completeness and accuracy of system reports he uses. Agreeing to a system-generated trial balance is circular, and a vendor's assurance is not a substitute for the auditor's own evidence.

Did you get it right without looking?

One question tells you little. A timed set on Audit of Banks shows your real accuracy, how long you take and where you lose marks.

More Audit of Banks questions