Skip to content

CA Final · Advanced Auditing, Assurance and Professional Ethics · Digital Auditing & Assurance

While auditing Himalaya Pharma Ltd, the auditor finds that a few users in the IT department have unrestricted privileged access to the production database and can change financial data directly, bypassing the application. Management says the access is needed for emergencies and no logs are reviewed. What is the most appropriate auditor conclusion?

Unmonitored privileged database access is a general IT control deficiency that threatens data integrity and reliance on application controls. The auditor should reassess risks, extend substantive procedures and communicate the deficiency to those charged with governance, rather than ignoring it or automatically resigning.

  1. AThere is no audit impact because the access is restricted to IT staff
  2. BThis is a deficiency in general IT controls that may undermine reliance on automated controls and data integrity, so the auditor should extend substantive procedures and consider communicating it to those charged with governanceCorrect
  3. CThe auditor must immediately resign since IT access weaknesses always prevent an audit
  4. DThe auditor should rely fully on application controls since they operate independently of database access

Explanation

Unmonitored privileged access is a general IT control deficiency that can compromise the reliability of application controls and data. The auditor should reassess risk, increase substantive testing and communicate the deficiency. Resignation is not automatically required, and application controls cannot be assumed independent.

Did you get it right without looking?

One question tells you little. A timed set on Digital Auditing & Assurance shows your real accuracy, how long you take and where you lose marks.

More Digital Auditing & Assurance questions