{"product_id":"it-auditing-and-application-controls-for-small-and-mid-sized-enterprises-isbn-9781118072615","title":"IT Auditing and Application Controls for Small and Mid-Sized Enterprises","description":"\u003cb\u003eEssential guidance for the financial auditor in need of a working knowledge of IT\u003c\/b\u003e  \u003cp\u003eIf you're a financial auditor needing working knowledge of IT and application controls, \u003ci\u003eAutomated Auditing Financial Applications for Small and Mid-Sized Businesses\u003c\/i\u003e provides you with the guidance you need. Conceptual overviews of key IT auditing issues are included, as well as concrete hands-on tips and techniques. Inside, you'll find background and guidance with appropriate reference to material published by ISACA, AICPA, organized to show the increasing complexity of systems, starting with general principles and progressing through greater levels of functionality.\u003c\/p\u003e \u003cul\u003e \u003cli\u003eProvides straightforward IT guidance to financial auditors seeking to develop quality and efficacy of software controls\u003c\/li\u003e \u003cli\u003eOffers small- and middle-market business auditors relevant IT coverage\u003c\/li\u003e \u003cli\u003eCovers relevant applications, including MS Excel, Quickbooks, and report writers\u003c\/li\u003e \u003cli\u003eWritten for financial auditors practicing in the small to midsized business space\u003c\/li\u003e \u003c\/ul\u003e \u003cp\u003eThe largest market segment in the United States in quantity and scope is the small and middle market business, which continues to be the source of economic growth and expansion. Uniquely focused on the IT needs of auditors serving the small to medium sized business, \u003ci\u003eAutomated Auditing Financial Applications for Small and Mid-Sized Businesses\u003c\/i\u003e delivers the kind of IT coverage you need for your organization.\u003c\/p\u003e \u003cp\u003ePreface xi\u003c\/p\u003e \u003cp\u003eAcknowledgments xiii\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 1: Why Is IT Auditing Important to the Financial Auditor and the Financial Statement Audit? 1\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eManagement’s Assertions and the IT Audit 2\u003c\/p\u003e \u003cp\u003eObjectives of Data Processing for Small and Medium‐Sized Enterprises (SMEs) 5\u003c\/p\u003e \u003cp\u003eSpecial Challenges Facing SMEs 8\u003c\/p\u003e \u003cp\u003eResearch Confirming the Risks Associated with SMEs 13\u003c\/p\u003e \u003cp\u003eA Framework for Evaluating Risks and Controls, Compensatory Controls, and Reporting Deficiencies 16\u003c\/p\u003e \u003cp\u003eSummary: The Road Ahead 20\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 2: General Controls for the SME 21\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eGeneral Controls: Scope and Outcomes 22\u003c\/p\u003e \u003cp\u003eThe “COSO Process”—Putting It All Together: Financial Statements, Assertions, Risks, Control Objectives, and Controls 30\u003c\/p\u003e \u003cp\u003eSummary 35\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 3: Application‐Level Security 37\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eKey Considerations 37\u003c\/p\u003e \u003cp\u003eInitial Security Setup 40\u003c\/p\u003e \u003cp\u003eSecurity Role Design 42\u003c\/p\u003e \u003cp\u003ePassword Configuration 44\u003c\/p\u003e \u003cp\u003eSegregation of Duties 48\u003c\/p\u003e \u003cp\u003ePersonnel, Roles, and Tasks 49\u003c\/p\u003e \u003cp\u003eAccess Reviews 56\u003c\/p\u003e \u003cp\u003eHuman Error 58\u003c\/p\u003e \u003cp\u003eSummary 58\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 4: General Ledger and the IT Audit 59\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eThe General Ledger: A Clearinghouse of Financial Information 60\u003c\/p\u003e \u003cp\u003eChart of Accounts for QuickBooks 62\u003c\/p\u003e \u003cp\u003eSME Risks Specific to the General Ledger and the Chart of Accounts 65\u003c\/p\u003e \u003cp\u003eAssertions Underlying the Financial Statements and General Ledger Controls 66\u003c\/p\u003e \u003cp\u003eIT Controls, the Transaction Level, and the General Ledger 66\u003c\/p\u003e \u003cp\u003eSummary 78\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 5: The Revenue Cycle 81\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eRisk Exposures and Subprocesses 81\u003c\/p\u003e \u003cp\u003eApplication Controls, Revenue Cycle Risks, and Related Audit Procedures 84\u003c\/p\u003e \u003cp\u003eSummary 105\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 6: The Expenditure Cycle 107\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eRisk Exposures and Subprocesses 107\u003c\/p\u003e \u003cp\u003eApplication Controls, Expenditure Cycle Risks, and Related Audit Procedures 111\u003c\/p\u003e \u003cp\u003eSummary 133\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 7: The Inventory Cycle 135\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eRisk Exposures and Subprocesses 136\u003c\/p\u003e \u003cp\u003eApplication Controls, Inventory Cycle Risks, and Related Audit Procedures 143\u003c\/p\u003e \u003cp\u003eSummary 157\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 8: The Payroll Cycle 159\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eRisk Exposures and Subprocesses 159\u003c\/p\u003e \u003cp\u003eApplication Controls, Payroll Cycle Risks, and Related Audit Procedures 163\u003c\/p\u003e \u003cp\u003eSummary 248\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 9: Risk, Controls, Financial Reporting, and an Overlay of COSO on COBIT 249\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003ePCAOB Warnings: Insufficient Evidence to Support Opinions 250\u003c\/p\u003e \u003cp\u003eHow We Got Here: A Historical Perspective 251\u003c\/p\u003e \u003cp\u003eRisk 260\u003c\/p\u003e \u003cp\u003eRisk and Fraud 261\u003c\/p\u003e \u003cp\u003eControls 262\u003c\/p\u003e \u003cp\u003eFinancial Reporting 269\u003c\/p\u003e \u003cp\u003ePCAOB Guidance on IT Controls 279\u003c\/p\u003e \u003cp\u003eIntegrating COSO, COBIT, and the PCAOB 280\u003c\/p\u003e \u003cp\u003eSummary 286\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 10: Integrating the IT Audit into the Financial Audit 289\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eRisks, Maturity, and Assessments 290\u003c\/p\u003e \u003cp\u003eCross‐Referencing COBIT to the PCAOB and COSO 295\u003c\/p\u003e \u003cp\u003ePlan and Organize 303\u003c\/p\u003e \u003cp\u003eProgram Development and Change 311\u003c\/p\u003e \u003cp\u003eComputer Operations and Access to Programs and Data 317\u003c\/p\u003e \u003cp\u003eMonitor and Evaluate 330\u003c\/p\u003e \u003cp\u003eSummary 334\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 11: Spreadsheet and Desktop Tool Risk Exposures 337\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eSpecific Types of Risks and Exposures 338\u003c\/p\u003e \u003cp\u003eResearch on Errors in Spreadsheets 339\u003c\/p\u003e \u003cp\u003eCompliance Dimensions of Spreadsheet Risk Exposures 344\u003c\/p\u003e \u003cp\u003eSpreadsheet Auditing Tools 348\u003c\/p\u003e \u003cp\u003eGovernance of Spreadsheets and Desktop Tools 352\u003c\/p\u003e \u003cp\u003eControl Considerations 355\u003c\/p\u003e \u003cp\u003eAuditing Controls and Creating a Baseline 356\u003c\/p\u003e \u003cp\u003eLife after the Baseline: Maintaining Spreadsheets and Desktop Tools 368\u003c\/p\u003e \u003cp\u003eSummary 369\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 12: Key Reports and Report Writers Risk Exposures 371\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eHow Reports Are Used 371\u003c\/p\u003e \u003cp\u003eOriginal Reports within the Application 372\u003c\/p\u003e \u003cp\u003eModified or Customized Reports within the Application 376\u003c\/p\u003e \u003cp\u003eReports Using Third‐Party Packages 378\u003c\/p\u003e \u003cp\u003eAnalyzing and Validating Reports 382\u003c\/p\u003e \u003cp\u003eSummary 383\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 13: IT Audit Deficiencies: Defining and Evaluating IT Audit Deficiencies 385\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eA Framework for Audit Deficiencies 385\u003c\/p\u003e \u003cp\u003eTypes of IT Audit Failures and Illustrative Cases 388\u003c\/p\u003e \u003cp\u003eUse of Compensatory Controls 388\u003c\/p\u003e \u003cp\u003eIdeas for Addressing Segregation‐of‐Duties Issues 388\u003c\/p\u003e \u003cp\u003eSummary 398\u003c\/p\u003e \u003cp\u003eReferences 399\u003c\/p\u003e \u003cp\u003eAbout the Authors 405\u003c\/p\u003e \u003cp\u003eIndex 407\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eJASON WOOD, CPA, CITP, CIS, CIA, CFF, MBA,\u003c\/b\u003e is President of WoodCPA???Plus, a certified public accounting firm that focuses on IT auditing, consulting, and training. Mr. Wood has over seventeen years of international business experience in IT auditing, helping middle market and global Fortune 500 companies. He is an alumnus of the Big Four accounting firmsDeloitte, E\u0026amp;Y, and PwC. \u003c\/p\u003e\u003cp\u003e\u003cb\u003eWILLIAM BROWN, P\u003csmall\u003eH\u003c\/small\u003eD, CPA, CISA, CITP,\u003c\/b\u003e is Chair of Accounting at Minnesota State University, Mankato, where he has taught accounting and management information systems. He has over twenty years of business experience including roles as vice president, controller, and CFO of several publicly traded companies and the CIO of an IT intensive high-growth SME. \u003c\/p\u003e\u003cp\u003e\u003cb\u003eHARRY HOWE, P\u003csmall\u003eH\u003c\/small\u003eD,\u003c\/b\u003e is Professor of Accounting and Director of the MS in Accounting Program at SUNY-Geneseo. Howe has coauthored two volumes in the BNA Policy and Practice series and published numerous articles in scholarly and practitioner journals.   \u003c\/p\u003e\u003cp\u003eRisk is inevitable. As an auditor, you must help your clients not only manage their risk by performing audits and other assessments but also help them understand the nature and extent of risks that exist in the control environment. Information technology (IT) controls are a key aspect of that control environment. Written to help financial auditors provide better service to their clients in the context of application controls, \u003ci\u003eIT Auditing and Application Controls for Small and Mid-Sized Enterprises\u003c\/i\u003e illustrates and explains many of the basic IT controls common to the types of reporting systems used by small and medium-sized enterprises (SMEs).\u003c\/p\u003e \u003cp\u003eSharing their collective decades of experience practicing and teaching in the field, authors Jason Wood, William Brown, and Harry Howe provide you with the tools, guidance, and working knowledge to get started in IT auditing. The authors highlight conceptual and practical topics that are immediately relevant to understanding applications typically used by these businesses, such as MS Excel, QuickBooks, and FRx (Microsoft Dynamics) report writer.\u003c\/p\u003e \u003cp\u003eOrganized to illustrate the increasing complexity of systems, the book begins with general principles and progresses through greater levels of functionality in subsequent modules. Featuring conceptual overviews of key IT auditing issues as well as concrete, hands-on tips and techniques, \u003ci\u003eIT Auditing and Application Controls for Small and Mid-Sized Enterprises\u003c\/i\u003e examines:\u003c\/p\u003e \u003cul\u003e \u003cli\u003eSpecial challenges facing SMEs\u003c\/li\u003e \u003cli\u003eThe COSO process\u003c\/li\u003e \u003cli\u003eApplication-level security\u003c\/li\u003e \u003cli\u003eGeneral ledger and the IT audit\u003c\/li\u003e \u003cli\u003eThe revenue, expenditure, inventory, and payroll cycles\u003c\/li\u003e \u003cli\u003ePCAOB warnings\u003c\/li\u003e \u003cli\u003eIntegrating the IT audit into the financial audit\u003c\/li\u003e \u003cli\u003eSpreadsheet auditing tools\u003c\/li\u003e \u003cli\u003eMaintaining spreadsheets and desktop tools\u003c\/li\u003e \u003cli\u003eAnalyzing and validating reports\u003c\/li\u003e \u003cli\u003eIT audit deficiencies\u003c\/li\u003e \u003c\/ul\u003e \u003cp\u003e\u003ci\u003eIT Auditing and Application Controls for Small and Mid-Sized Enterprises\u003c\/i\u003e empowers you with the skills and knowledge to provide better, more accurate service to your clients.\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eIT AUDITING AND APPLICATION CONTROLS FOR SMALL AND MID-SIZED ENTERPRISES\u003c\/b\u003e Revenue, Expenditure, Inventory, Payroll, and More \u003c\/p\u003e\u003cp\u003eRisk is inevitable. As an auditor, you must help your clients not only manage their risk by performing audits and other assessments but also help them understand the nature and extent of risks that exist in the control environment. Information technology (IT) controls are a key aspect of that control environment. Written to help financial auditors provide better service to their clients in the context of application controls, \u003ci\u003eIT Auditing and Application Controls for Small and Mid-Sized Enterprises\u003c\/i\u003e illustrates and explains many of the basic IT controls common to the types of reporting systems used by small and medium-sized enterprises (SMEs). \u003c\/p\u003e\u003cp\u003eSharing their collective decades of experience practicing and teaching in the field, authors Jason Wood, William Brown, and Harry Howe provide you with the tools, guidance, and working knowledge to get started in IT auditing. The authors highlight conceptual and practical topics that are immediately relevant to understanding applications typically used by these businesses, such as MS Excel, QuickBooks, and FRx (Microsoft Dynamics) report writer. \u003c\/p\u003e\u003cp\u003eOrganized to illustrate the increasing complexity of systems, the book begins with general principles and progresses through greater levels of functionality in subsequent modules. Featuring conceptual overviews of key IT auditing issues as well as concrete, hands-on tips and techniques, \u003ci\u003eIT Auditing and Application Controls for Small and Mid-Sized Enterprises\u003c\/i\u003e examines: \u003c\/p\u003e\u003cul\u003e \u003cli\u003eSpecial challenges facing SMEs\u003c\/li\u003e \u003cli\u003eThe COSO process\u003c\/li\u003e \u003cli\u003eApplication-level security\u003c\/li\u003e \u003cli\u003eGeneral ledger and the IT audit\u003c\/li\u003e \u003cli\u003eThe revenue, expenditure, inventory, and payroll cycles\u003c\/li\u003e \u003cli\u003ePCAOB warnings\u003c\/li\u003e \u003cli\u003eIntegrating the IT audit into the financial audit\u003c\/li\u003e \u003cli\u003eSpreadsheet auditing tools\u003c\/li\u003e \u003cli\u003eMaintaining spreadsheets and desktop tools\u003c\/li\u003e \u003cli\u003eAnalyzing and validating reports\u003c\/li\u003e \u003cli\u003eIT audit deficiencies\u003c\/li\u003e \u003c\/ul\u003e \u003cp\u003e\u003ci\u003eIT Auditing and Application Controls for Small and Mid-Sized Enterprises\u003c\/i\u003e empowers you with the skills and knowledge to provide better, more accurate service to your clients.\u003c\/p\u003e","brand":"Wiley","offers":[{"title":"Default Title","offer_id":47989483798757,"sku":"NP9781118072615","price":90.0,"currency_code":"USD","in_stock":false}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/1842\/7735\/files\/9781118072615.jpg?v=1761784284","url":"https:\/\/k12savings.com\/products\/it-auditing-and-application-controls-for-small-and-mid-sized-enterprises-isbn-9781118072615","provider":"K12savings","version":"1.0","type":"link"}