Auditors have important role in cybersecurity

BY KEN TYSIAC

The steady stream of headlines about data breaches has the business community and regulators on high alert with regard to cybersecurity.

An online PwC survey of global executives and IT directors conducted early in 2013 found that detected cybersecurity incidents rose 25% over the previous year. And 31% of executives responding to EY’s Global Information Security Survey for 2013 said the number of cybersecurity incidents at their organization grew at least 5% over the previous year.

The SEC has taken notice of concerns over this issue and will hold a round-table meeting Wednesday to address cybersecurity.

In recognition of these trends, the Center for Audit Quality (CAQ) released an alert Friday to its nearly 600 public company audit firm members that summarizes external auditors’ duties with respect to cybersecurity. The CAQ is affiliated with the AICPA.

“Cybersecurity is one of the most complex and evolving issues facing public companies,” CAQ Executive Director Cindy Fornelli said in a news release. “All players in the financial reporting supply chain, including of course independent auditors, have an important role to play.”

External auditors’ duties, according to the alert, include:

  • Understanding how the company uses IT and the impact of IT on the financial statements.
  • Understanding the extent of the company’s automated controls as they relate to financial reporting. This should include an understanding of IT general controls that affect the automated controls, and the reliability of data and reports used in the audit that were produced by the company.
  • Taking into account the understanding of IT systems and controls in assessing the risks of material misstatement to the financial statements, including IT risks resulting from unauthorized access.


The audit’s focus is on access and changes to systems and data that would affect the financial statements and the effectiveness of internal control over financial reporting (ICFR), rather than the company’s overall IT platform, according to the alert.

Accordingly, the alert says execution of an audit of the financial statements and ICFR is unlikely to include areas that would address a cybersecurity breach outside that narrow area. But if a material breach is discovered, the auditor would need to consider the impact on financial reporting, including disclosures, and the impact on ICFR, the alert says.

The primary focus for auditors with respect to IT should be controls and systems in closest proximity to the application data of interest to the audit, according to the alert. These may include enterprise resource planning systems, single-purpose applications such as a fixed-asset system, and any set of connected systems that house data related to the financial statements.

Ken Tysiac ( ktysiac@aicpa.org ) is a JofA senior editor.

SPONSORED REPORT

Click-through nexus: Pushing the boundaries of sales tax compliance

Sales and use tax compliance has been complicated by nexus expansion. In this report, we provide an overview of this issue and include a handy state-by-state summary of click-through nexus or notification requirements.

QUIZ

News quiz: Making allowances for the kids and the economy

Recent news gives CPAs insight into Americans’ attitudes about children and money and gauges outlook on the economy. See how much you know about recent news and reports with this quiz.

CHECKLIST

Auditing risks in culture

Cultural flaws can seriously damage an organization. Here’s how internal auditors can reduce risks by embedding culture audits into existing audit programs.