免费注册 查看新帖 |

Chinaunix

  平台 论坛 博客 文库
12
最近访问板块 发新帖
楼主: lf5043
打印 上一主题 下一主题

问大家一个关于内审的问题 [复制链接]

论坛徽章:
0
11 [报告]
发表于 2004-06-24 13:43 |只看该作者
最初由 tttkoo 发布\r\n[B]任何一个经理都可以,原因: 1.如果AUDIT SCOPE包含IT审计;2.有APPLICATION SYSTEM如SAP支持公司的关键业务,而IT MGR是SAP的SYSTEM OWNER(相对CFO/FC是SAP的BUSINESS PROCESS OWNER说来).\r\n另外还有,这些流程可以是POLICY,PROCEDURE,,但是:1.得有相应的FORM,DELEGATION OF AUTHORIZATION FOR BUSINESS OWNER, R&R等参考/支持文件; 2.公司高层要批准和发布;如果这些流程能够容入公司的质量保证体系,IA就无可挑剔了 [/B]
\r\n\r\n讨论两个问题:\r\n1、是否任何经理都可以拿到Engagement Letter;\r\n2、是否拿到Engagement Letter就可以知道是不是要审计软件的License;\r\n\r\n对于第一问题,以我的经验,内审一般是在Kick-off  Meeting的时候会把所有本次审计涉及的部门经理召集过来,主要是为了介绍审计范围和审计目的。内审是不会发给涉及经理一个Engagement Letter的,最多发一个Planning Memo,而Planning Memo基本也是发给Coordinator,比如Finance  Controller之类的角色。因此,说任何一个经理都可以,真是何处此言?当然,如果该经理凭着和Coordinator良好的私人关系拿到,又另当别论。\r\n\r\n第二个问题,即使凭着关系拿到了,难道就能从一份Engagement Letter上看出是否要对软件的License这一控制点进行测试吗?我不知道哪家事务所会把自己的Audit Program写到Engagement Letter上去?

论坛徽章:
0
12 [报告]
发表于 2004-06-24 17:16 |只看该作者
最初由 jacky761229 发布\r\n[B]\r\n\r\n讨论两个问题:\r\n1、是否任何经理都可以拿到Engagement Letter;\r\n2、是否拿到Engagement Letter就可以知道是不是要审计软件的License;\r\n\r\n对于第一问题,以我的经验,内审一般是在Kick-off  Meeting的时候会把所有本次审计涉及的部门经理召集过来,主要是为了介绍审计范围和审计目的。内审是不会发给涉及经理一个Engagement Letter的,最多发一个Planning Memo,而Planning Memo基本也是发给Coordinator,比如Finance  Controller之类的角色。因此,说任何一个经理都可以,真是何处此言?当然,如果该经理凭着和Coordinator良好的私人关系拿到,又另当别论。\r\n\r\n知道审计范围不就知道IF LICENSE AUDIT INCLUDING?\r\nFC should be the organization owner to inform internal dept. mgr to prepare after receiving engagement letter, it\' his/her duty\r\n\r\n第二个问题,即使凭着关系拿到了,难道就能从一份Engagement Letter上看出是否要对软件的License这一控制点进行测试吗?我不知道哪家事务所会把自己的Audit Program写到Engagement Letter上去? [/B]
\r\nAudit program should compliance with general audit program, you needn\'t to know how they will conduct audit but you should know audit scope, that\'s the point. You can defer such quation beyond scope.

论坛徽章:
0
13 [报告]
发表于 2004-06-24 18:43 |只看该作者
最初由 tttkoo 发布\r\n[B]\r\nAudit program should compliance with general audit program, you needn\'t to know how they will conduct audit but you should know audit scope, that\'s the point. You can defer such quation beyond scope. [/B]
\r\n\r\nOk, your point is , if you know the audit scope, then, you can determine whether the software license testing would be included.\r\n\r\nHowever, i don\'t think so. If i told you the audit scope would cover purchasing and revenue cycle. Could you ensure that software license testing would not be included? In addition, if i told you the audit scope include gerneral computer contorl review. Could you say that the license testing must be performed? That will base on the final audit program and the program could be largely different for different enterprise, different industry or different audit, such as internal audit or external audit.  \r\n\r\nI also don\'t know what your \'general audit program\' refer to. Anyway, that\'s not important, i believe each firm has different methodolgy or term.

论坛徽章:
0
14 [报告]
发表于 2004-06-24 20:15 |只看该作者
最初由 jacky761229 发布\r\n[B]\r\n\r\nOk, your point is , if you know the audit scope, then, you can determine whether the software license testing would be included.\r\n\r\nHowever, i don\'t think so. If i told you the audit scope would cover purchasing and revenue cycle. Could you ensure that software license testing would not be included? In addition, if i told you the audit scope include gerneral computer contorl review. Could you say that the license testing must be performed? That will base on the final audit program and the program could be largely different for different enterprise, different industry or different audit, such as internal audit or external audit.  \r\n\r\nI also don\'t know what your \'general audit program\' refer to. Anyway, that\'s not important, i believe each firm has different methodolgy or term. [/B]
\r\n\r\nYou can say that again, we aligned.! Please refer my first reply.

论坛徽章:
0
15 [报告]
发表于 2004-06-25 11:21 |只看该作者
最初由 tttkoo 发布\r\n[B]\r\n\r\nYou can say that again, we aligned.! Please refer my first reply. [/B]
\r\n\r\nPlease define our discussion point. Could you answer following question:\r\n\r\nWhether Software License would be tested should be determined by:\r\n1) Audit Scope; or\r\n2) Audit Program
您需要登录后才可以回帖 登录 | 注册

本版积分规则 发表回复

  

北京盛拓优讯信息技术有限公司. 版权所有 京ICP备16024965号-6 北京市公安局海淀分局网监中心备案编号:11010802020122 niuxiaotong@pcpop.com 17352615567
未成年举报专区
中国互联网协会会员  联系我们:huangweiwei@itpub.net
感谢所有关心和支持过ChinaUnix的朋友们 转载本站内容请注明原作者名及出处

清除 Cookies - ChinaUnix - Archiver - WAP - TOP