GRADUATION PROJECT THE APPLICATION OF INFORMATION TECHNOLOGY AUDIT PROCESS FOR ENTERPRISES AT KPMG LIMITED Do Duy Son Hanoi – Year 2023 VIETNAM NATIONAL UNIVERSITY, HANOI INTERNATIONAL SCHOOL GRADUATION PROJECT THE APPLICATION OF INFORMATION TECHNOLOGY AUDIT PROCESS FOR ENTERPRISES AT KPMG LIMITED SUPERVISOR Ph. Truong Cong Doan STUDENT Do Duy Son STUDENT ID 19071076 COHORT MIS2019B 2 MAJOR Management Information System Hanoi – Year 2023 VNUIS - 2023 DO DUY SON - 19071076 ACKNOWLEDGEMENTS To complete the graduation thesis, I would like to express my heartfelt gratitude to the International School, Vietnam National University, where I have spent almost four years gaining knowledge and so many soft skills. Especially, I would like to sincerely thank Ph. Truong Cong Doan for supervising me in the process of completing the thesis.
In addition, I want to spend sincerely thank some of KPMG’s staff, who have supported me by providing data and participating in my interview to complete the graduation thesis. However, from the perspective of an ungraduated student with limited practical knowledge and experience, I may be unable to avoid mistakes when completing this thesis. Thereby, I am looking forward to receiving gentle recommendations from you on my thesis. Yours sincerely, Do Duy Son i VNUIS - 2023 DO DUY SON - 19071076 LETTER OF DECLARATION I hereby declare that the Graduation Thesis titled "The Process of Information Technology Business Audit for Enterprises at KPMG Limited" is the outcome of my independent research and has not been previously published in any other work.
Throughout the project, I have adhered to research ethics and all the findings presented are the result of my own research and interviews. I have appropriately cited all references in accordance with the regulations. Furthermore, I have taken measures to ensure confidentiality and comply with KPMG's information privacy policy. The names, numbers, and sensitive information referred to or illustrated in the thesis have been altered and concealed.
I assume full responsibility for the accuracy of the numbers, data, and other contents presented in my graduation project. Hanoi, 2023 Student Do Duy Son ii VNUIS - 2023 DO DUY SON - 19071076 LIST OF ABBREVIATION No. Abbreviation Meaning 1 IT Information Technology 2 ERP Enterprise Resource Planning 3 GITC General Information Technology Controls 4 ITAC Information Technology Application Controls 5 ITA Information Technology Audit 6 A&C Accuracy and Completeness 7 D&I Design & Implementation 8 TOE Test of Operating Effectiveness 9 RAFIT Risk(s) Arising From IT 10 RAWTC Risk(s) Associated with The Control 11 OS Operating System 12 DB Database 13 UAT User Acceptance Test 14 PRP Process Risk Point 15 RMM Risk of Material Misstatement iii VNUIS - 2023 DO DUY SON - 19071076 LIST OF TABLES Table 2. APD1 Control Attributes (Source: KPMG).
APD2 Control Attributes (Source: KPMG). APD3 Control Attributes (Source: KPMG). APD4 Control Attributes (Source: KPMG). APD5 Control Attributes (Source: KPMG).
CM1 Control Attributes (Source: KPMG). CM2 Control Attributes (Source: KPMG). CM3 Control Attributes (Source: KPMG). CM4 Control Attributes (Source: KPMG).
CM5 Control Attributes (Source: KPMG). PD1 Control Attributes (Source: KPMG). PD2 Control Attributes (Source: KPMG). PD3&4 Control Attributes (Source: KPMG).
PD5 Control Attributes (Source: KPMG). PD6 Control Attributes (Source: KPMG). CO1 Control Attributes (Source: KPMG). CO2 Control Attributes (Source: KPMG).
CO3&4 Control Attributes (Source: KPMG). CO5 Control Attributes (Source: KPMG). Select sample size based on the size of the population (Source: KPMG). Select sample size based on the frequency of the control (Source: KPMG).
ITAC scoping for ABC Insurance (Source: KPMG working paper). GITC scoping for ABC Insurance (Source: KPMG working paper). Interview ABC Insurance's IT Operator Officer using questionnaire. ABC Insurance IT Layer (Source: KPMG working paper).
ABC Insurance's IT Department (Source: KPMG working paper). ABC Insurance's IT sites (Source: KPMG working paper). General IT system access policy (Source: KPMG working paper). Access to Program and Data understanding (Source: KPMG working paper).
Access to Program and Data TOE (Source: KPMG working paper). Change Management understanding (Source: KPMG working paper). Change Management TOE (Source: KPMG working paper). Computer Operations understanding (Source: KPMG working paper).
Computer Operations TOE (Source: KPMG working paper). Accuracy & Completeness Testing determine the appropriate procedures (Source: KPMG working paper). Directly test the Accuracy & Completeness of the information (Source: KPMG working paper). ITAC-03 understanding and assessment (Source: KPMG working paper) 50 iv VNUIS - 2023 DO DUY SON - 19071076 Table 3.
Audit procedure of ITAC-01 D&I testing (Source: KPMG working paper). Audit procedure of ITAC-01 TOE (Source: KPMG working paper). Automated Controls summary (Source: KPMG working paper). 56 v VNUIS - 2023 DO DUY SON - 19071076 LIST OF FIGURES Figure 2.
Layers of IT system illustration (Source: KPMG). Overall IT Controls illustration (Source: KPMG). Application automated control process illustration (Source: KPMG). Example of an evidence (Source: KPMG working paper).
Oracle Database Password setting (Source: KPMG working paper). Oracle Database Password setting (Source: KPMG working paper). IP address of the people have the access to development environment. IP address of the people have the access to production environment (Source: KPMG working paper).
The Incidents classification matrix of ABC Insurance (Source: KPMG working paper). Type of Earn/Unearned contract (Source: KPMG working paper). Earn/Unearned method is set to 3 which is daily (Source: KPMG working paper). A screenshot part of List of Contract type exported from P400 (Source: KPMG working paper).
General information of Direct premium (Source: KPMG working paper). Gross Original premium of CDF Agricultural Machinery (Source: KPMG working paper). 54 vi VNUIS - 2023 DO DUY SON - 19071076 TABLE OF CONTENTS ACKNOWLEDGEMENTS. I LETTER OF DECLARATION .II LIST OF ABBREVIATION.
III LIST OF TABLES. IV LIST OF FIGURES. VI TABLE OF CONTENTS. OBJECTIVES OF THE STUDY.
SCOPE AND LIMITATIONS OF THE STUDY. DEFINITION AND CONCEPT OF INFORMATION TECHNOLOGY AUDIT. PREVIOUS STUDIES RELATED TO IT AUDIT. PROCEDURES AND AUDIT METHODS.
Test of Information Technology Controls. Summarizing and Evaluating IT System Controls Deficiencies. DATA COLLECTION METHODS. Identify sample size.
PLANNING FOR ABC INSURANCE IT AUDIT ENGAGEMENT. Scoping and Requirements. UNDERSTANDING ABC INSURANCE IT SYSTEM. Inquiry person in-charge/relevant of the IT system.
ABC Insurance IT System understanding profile. IT CONTROLS TESTING. General IT Controls Testing. Accuracy & Completeness testing.
IT Application Controls Testing. SUMMARIZING AND EVALUATING ABC INSURANCE’S IT SYSTEM CONTROLS DEFICIENCIES. Information technology audit summary. IT System controls deficiencies evaluation.
SUMMARY OF THE STUDY'S FINDINGS AND ANALYSIS. RECOMMENDATIONS FOR IMPROVING AND DEVELOPING THE PROCESS. 60 vii VNUIS - 2023 DO DUY SON - 19071076 ABSTRACT The necessity for an audit arises from the fact that business owners rely on external auditors to independently analyze and report on the truth and fairness of financial statements. In Vietnam, the profession of auditing IT processes and systems is relatively new.
This study aims to delve into the work of Information Technology Audit, both in general and specifically at KPMG, to understand the requirements of IT audit for human resources in the auditing field in Vietnam. It also seeks to provide practical experience for future career development. A purely qualitative research method is employed, utilizing interviews, archival records, and secondary data to evaluate the role of IT auditors or IT team members and their actual work in an audit at KPMG. The study focuses on the actual work of IT auditors at KPMG and the requirements for auditing information technology systems.
The structure of the research comprises five chapters. Chapter 1 provides an introduction, setting the context and significance of the study. Chapter 2 presents a literature review, exploring the existing body of knowledge on IT audit. Chapter 3 outlines the research design and methodology, elucidating the data collection and analysis methods employed.
Chapter 4 presents the findings and analysis of the research, offering insights into the role and work of IT auditors at KPMG. Finally, Chapter 5 provides recommendations and conclusions based on the study's outcomes. This graduation thesis contributes to the understanding of IT audit practices, particularly within the framework of KPMG Limited. It provides valuable insights for practitioners, organizations, and the auditing profession in Vietnam to enhance their IT audit capabilities and improve overall financial reporting integrity.
Keywords: Information Technology Audit, General Information Technology Controls, Information Technology Application Controls, Design & Implementation, Deficiency, Effectiveness. 1 VNUIS - 2023 DO DUY SON - 19071076 INTRODUCTION 1. Research Rationale In recent years, the application and growth of IT in organizational administration, production, and business operations has grown in importance. As a result, preserving data security, integrity, availability, and reliability depends on strengthening information technology risk management.
The role of IT audits in the audit engagements1 of independent auditing firms in Vietnam and even worldwide, however, has not received much in-depth research. Furthermore, only the Big Four firms in Vietnam, including KPMG, offer professional IT consulting and auditing services; smaller auditing firms haven't yet made a mark in this field. Therefore, this study seeks to address a gap in the literature by investigating the particular function of IT audit within the audit engagement process at KPMG Limited. The study will examine the role that IT audits play in the overall audit quality as well as the efficiency with which KPMG's IT auditing procedures can verify financial statements.
Additionally, the study will look at the issues the audit team ran into while assessing the accuracy of the data flowing via complex IT systems, such as Enterprise Resource Planning (ERP) solutions, and it will provide remedies. By assessing the audit quality and roles of KPMG's IT audit in the context of rising audit cost competitiveness, the research will provide fresh perspectives and contribute to the existing literature on IT auditing. Objectives of the Study This study investigates the significance of IT audit and the specific responsibilities of IT auditors at different levels of KPMG employees involved in audit engagements. The primary objectives of the research are as follows: • Analyze the role of the IT Audit.
• Examine the research and analysis basis of each IT audit engagement. • Examine the KPMG methodologies to conduct an IT system assessment. 1 Audit engagement: It is an audit commitment contract between KPMG and the client. Instead of using "Campaign" or "Project" for audit campaigns, KPMG uses “Engagement Profile” to refer to its audit campaigns.
2 VNUIS - 2023 DO DUY SON - 19071076 3. Scope and Limitations of the Study This thesis examines the role of IT audit and the tasks performed by IT auditors during the financial statement audit at KPMG Limited in Vietnam. The research participants consist of IT consultants (assistants), solution consultants (senior), managers, and associate directors. Interviews were conducted with these participants between March 2023 and May 2023.
The scope of the research is specifically limited to the study of IT audit and the actual work of IT auditors within the context of independent audit activities related to financial statements, excluding other types of audits such as state audit or performance audit. Research Questions The author will direct this study to answer the following research questions: • RQ1: To conduct an IT system assessment, what information does KPMG base on from an organization? • RQ2: What tools or methodologies that KPMG used to assess the enterprises’ IT systems? • RQ3: How did KPMG known the assessments are reliable? 3 VNUIS - 2023 DO DUY SON - 19071076 CHAPTER 1. Definition and Concept of Information Technology Audit An information technology audit involves evaluating and assessing an organization's IT infrastructure, applications, data usage and management, policies, procedures, and operational processes against established standards or guidelines.