Financial statements may be presented by the finance function, but much of the underlying information is generated, processed, approved, transferred, and stored through technology.
Revenue may originate in a billing platform. Inventory quantities may be maintained in an operational application. Payroll may be calculated automatically. Management reports may combine information extracted from several systems and adjusted through spreadsheets.
Where the systems and controls behind this information are unreliable, financial reporting may also be unreliable.
IT assurance is not limited to cybersecurity. It also considers whether systems process transactions consistently, restrict inappropriate activity, retain reliable records, and generate information that users can trust.
Relevant areas may include user access, privileged accounts, segregation of incompatible system roles, change management, automated calculations, data interfaces, master data, system-generated reports, backup arrangements, and the completeness and accuracy of extracted information.
The IAASB has identified technology as a continuing priority at the intersection of audit, assurance, and engagement quality.
The scope of any assessment must nevertheless remain aligned with the purpose of the engagement and the systems relevant to the subject matter under examination.
Excessive or outdated access may allow one individual to initiate, approve, amend, and record the same transaction.
Shared usernames weaken accountability. Former employees may retain active access. Privileged users may be capable of altering configuration or data without independent monitoring. Incompatible roles may allow controls designed into the system to be overridden.
These are not merely technical concerns. They can affect authorization, segregation of duties, transaction integrity, and the reliability of the audit trail.
Management should therefore implement documented access approval, periodic recertification, timely removal of access, monitoring of privileged activity, and review of incompatible roles.
A report generated by an application should not automatically be assumed to be complete and accurate.
Management should understand the data source, report logic, parameters, filters, interfaces, and any manual adjustments performed after extraction.
Where spreadsheets support significant calculations or reporting, controls should address formula integrity, access, version control, review, protection of key cells, and reconciliation to source systems.
A technically sophisticated report can still be unreliable if the underlying data, extraction logic, or manual processing is not controlled.
Reliable technology-enabled reporting requires coordination among finance, operations, risk, and technology teams.
Finance understands the accounting and reporting objective. Operational teams understand how transactions originate. Technology personnel understand system architecture and data processing. Governance bodies are responsible for ensuring that significant technology risks receive appropriate oversight.
As organizations increase their dependence on digital records and automated processes, confidence in financial reporting will increasingly depend on confidence in the systems and controls behind the numbers.