Skip to content

Automated Tools and Techniques

VIVA Subject Guide
YouTube video

1 Technique types

Automated tools and techniques refer to 'traditional' computer-assisted audit techniques (CAATs) and other data analytics tools.

These are three main types of CAAT:

  • Audit programs

  • Test data

  • Embedded test facilities

The techniques can add greatly to audit efficiency and effectiveness. For example, audit programs can very quickly read thousands of records, examining each according to the criteria set by the auditor. Test data can be used to investigate the operation of accounting programs that could not be easily tested in any other way.

1.1 Audit programs

Audit programs (also called 'audit software') are used to examine and interrogate clients’ accounting data. The auditor will have a program which can read the clients’ files. That program can be used for the following:

  • To select a sample of transactions to investigate.

  • The samples could be automatically stratified.

  • The program might be set to identify odd transactions or balances. For example, credit balances on a receivables ledger, or inventory which hasn’t moved for some time.

  • It could also re-perform calculations. For example it is important to check that the sum of the receivables accounts add up to the balance shown in the general ledger and hence in the financial statements.

Note that by using audit programs to scan clients’ data every transaction can be examined relatively easily. This can be particularly effective in the investigation of fraud where often major amounts are misappropriated by making many small thefts that evade clients’ normal internal controls. For example, every payment could be examined to see if any had gone to a particular bank account.

1.2 Test data

Test data is used to investigate the operation of clients’ programs. The auditor designs 'dummy' data that is then processed by the client’s programs. This enables the auditor to check whether or not the clients’ programs are operating correctly and as expected, and whether or not the various controls which were supposed to be present are actually operating. For example, what happens if a dispatch is entered for a zero quantity or for a non-existing product or for a non-existing customer, or would raise the balance on the customer’s account to above the credit limit? Test data would be designed to check that the controls are present. There would be some normal error-free items, some unusual items and some extreme or unexpected items.

The auditor should predict what the client’s program should do and then compare those predictions with what the client’s program actually produces. A problem with test data is that the auditor is processing dummy data. Therefore it is usual for test data to be run using copies of files (ie 'dead')

Audit programs
Test data

1.3 Embedded audit facilities

Integrated Test Facilities or a System Control and Review File ('SCARF') are permanent audit modules within the accounting system. During the accounting period certain transactions are also recorded in these files for later examination by the auditor. For example, large journal entries, large returns and so on. It can be difficult to discover these at the end of the period in a normal accounting system because they will be buried amongst routine transactions and might have been cleared from the files.

The review files should be encrypted and locked so that only the auditor can access the information on them.

2 Big data and data analytics

A current issue for the profession is the development of emerging technologies including big data and the use of data analytics. How may they affect the conduct of an audit and audit quality?

2.1 Big data

The characteristics which make data ‘big’ are:

  • Volume – will be vast

  • Variety – non-uniform/unstructured

  • Velocity – fast and continuous

See Chapter 23 of our Strategic Business Leader (SBL) notes for further details if you are not familiar with big data.

The fourth ‘V’ – veracity – is particularly relevant to auditing. Big data is likely to include bias, abnormalities, inconsistencies and/or duplication. So how true or accurate is the data? How trustworthy the sources?

2.2 Data analytics

Data analytics is the science of examining raw data to draw conclusions. So an obvious audit application is in analytical procedures – the main differences between ‘traditional’ analytical procedures and analytical procedures using data analytics are:

  • As the data is raw, the auditor must assess and verify the level of veracity

  • Data analytics must be computer-assisted.

The IAASB set up a Data Analytics Working Group (DAWG) to explore the increasing use of technology in audit with a focus on data analytics. It suggests that using data analytics can:

  • Enhance audit quality through a more robust understanding of the entity

  • Gather audit evidence from larger population

  • Improve risk-based sample selection for further testing.

However, it is important to recognise the limitations of data analytics:

  • Need for veracity

  • Even with 100% testing, assurance can only be ‘reasonable’

  • Not a substitute for professional judgment and professional scepticism

  • The risk of over confidence in using technology.

DAWG requested input from stakeholders (including regulators, national standard setters, accounting firms, member bodies, investors) about the use of data analytics in the audit. The following table summarises the questions asked and the feedback from respondents:

Questions

Feedback

What factors in the current business environment affect the use of data analytics?

Data acquisition (source, quality and access)

Legal and regulatory challenges

Resource availability

Investment in re-training/re-skilling auditors

What are the standard-setting challenges?

Determining whether requirements of ISAs have been met

Relevance and reliability of data

Managing expectations of ‘100% testing’

Using data analytics on non-financial data

What are the possible solutions to the challenges?

ISAs aren’t ‘broken’ and should remain principles-based and adaptable

Overwhelming need for non-authoritative practical guidance

What should be IAASB’s next step? (e.g. revised ISA 520)

Revision to ISA 230 and ISA 500 should be prioritised but …

… short-term guidance is the highest priority.

The use of data analytic tools is one of the fastest developing areas in audit and a current issue. You are strongly advised to visit the AAA Technical Articles page for relevant article now and again during your revision.