Thread Options
#1536677 - 04/18/11 03:04 PM External IT Audit and Internal Auditors Role
sway Offline
100 Club
Joined: Feb 2011
Posts: 127
We currently have an external company doing out IT audit due to its complexity. When the bank recieves this report, what should my role be? Do I need to make sure the external company's reccomendations are being followed or is that out of the scope of my responsibilities? Any information as to my role as an internal auditor would be greatly appreciated. We currently have no procedures that cover this and I have been receiving conflicting responses from management. Thanks.

Return to Top
Audit
#1536683 - 04/18/11 03:11 PM Re: External IT Audit and Internal Auditors Role sway
Kathleen O. Blanchard Offline

10K Club
Kathleen O. Blanchard
Joined: Dec 2000
Posts: 21,277
Generally Internal Audit reviews the report to make sure it agrees with the scope requested. You might also review the workpapers to ensure that they agree with the report. Internal audit does then follow up to make sure all recommendations are addressed just as with an audit you did yourself.
_________________________
Kathleen O. Blanchard, CRCM "Kaybee"
HMDA/CRA Training/Consulting/Mapping
The HMDA Academy
www.kaybeescomplianceinsights.com

Return to Top
#1536697 - 04/18/11 03:29 PM Re: External IT Audit and Internal Auditors Role Kathleen O. Blanchard
sway Offline
100 Club
Joined: Feb 2011
Posts: 127
Thanks for clearing this up!

Return to Top
#1537380 - 04/19/11 03:56 PM Re: External IT Audit and Internal Auditors Role sway
Justin Wesson Offline
Member
Joined: Jun 2008
Posts: 83
Internal audit should also review the findings and recommendations to make sure they are reasonable. You should help the auditee to make sure they present all the relevant information so that the report doesnt contain a bunch of findings that are not correct or only half true, and recommendations that are reasonable to address the concern. External auditors have their place, but they often miss...
_________________________
THANK YOU GOVERNMENT:
“If I seem unduly clear to you, you must have misunderstood what I said” - A. Greenspan

Return to Top
#1540295 - 04/25/11 06:17 PM Re: External IT Audit and Internal Auditors Role Justin Wesson
osoalone Offline
100 Club
Joined: Dec 2003
Posts: 146
Texas
Our examiners have stated I am required to perform follow-ups on all external audits.

Return to Top
#1542191 - 04/27/11 08:42 PM Re: External IT Audit and Internal Auditors Role osoalone
Comply 101 Offline
Platinum Poster
Comply 101
Joined: Jul 2001
Posts: 708
In banks I have worked at, the IA would not get involved with disputed findings. The person responsible for IT, GLBA, Vendor Mgmt, BCP etc would dispute the findings as they are most knowledgeable in those areas. I agree IA would make sure any findings were acted upon and resolved and follow up.
_________________________
CRCM CAMs

Return to Top

Moderator:  Andy_Z