Information Technology Audit Process - Generally Accepted Auditing Standards (GAAS)

Generally Accepted Auditing Standards (GAAS)

In 1947, the American Institute of Certified Public Accountants (AICPA) adopted GAAS to establish standards for audits. The standards cover the following three categories:

  • General Standards – relates to professional and technical competence, independence, and professional due care.
  • Field Work Standards – relates to the planning of an audit, evaluation of internal control, and obtaining sufficient evidential matter upon which an opinion is based.
  • Reporting Standards – relates to the compliance of all auditing standards and adequacy of disclosure of opinion in the audit reports. If an opinion cannot be reached, the auditor is required to explicitly state their assertions.


The auditor must plan and conduct the audit to ensure their audit risk (the risk of reaching an incorrect conclusion based on the audit findings) will be limited to an acceptable level. To eliminate the possibility of assessing audit risk too low the auditor should perform the following steps:

Obtain an Understanding of the Organization and its Environment: The understanding of the organization and its environment is used to assess the risk of material misstatement/weakness and to set the scope of the audit. The auditor’s understanding should include information on the nature of the entity, management, governance, objectives and strategies, and business processes. Identify Risks that May Result in Material Misstatements: The auditor must evaluate an organization’s business risks (threats to the organization’s ability to achieve its objectives). An organization’s business risks can arise or change due to new personnel, new or restructured information systems, corporate restructuring, and rapid growth to name a few. Evaluate the Organization’s Response to those Risks: Once the auditor has evaluated the organization’s response to the assessed risks, the auditor should then obtain evidence of management’s actions toward those risks. The organization’s response (or lack thereof) to any business risks will impact the auditor’s assessed level of audit risk. Assess the Risk of Material Misstatement: Based on the knowledge obtained in evaluating the organization’s responses to business risks, the auditor then assesses the risk of material misstatements and determines specific audit procedures that are necessary based on that risk assessment.

Read more about this topic:  Information Technology Audit Process

Famous quotes containing the words generally, accepted and/or standards:

    In doing good, we are generally cold, and languid, and sluggish; and of all things afraid of being too much in the right. But the works of malice and injustice are quite in another style. They are finished with a bold, masterly hand; touched as they are with the spirit of those vehement passions that call forth all our energies, whenever we oppress and persecute..
    Edmund Burke (1729–97)

    The percept is the reality. It is not in propositional form. But the most immediate judgment concerning it is abstract. It is therefore essentially unlike the reality, although it must be accepted as true to that reality. Its truth consists in the fact that it is impossible to correct it, and in the fact that it only professes to consider one aspect of the percept.
    Charles Sanders Peirce (1839–1914)

    In full view of his television audience, he preached a new religion—or a new form of Christianity—based on faith in financial miracles and in a Heaven here on earth with a water slide and luxury hotels. It was a religion of celebrity and showmanship and fun, which made a mockery of all puritanical standards and all canons of good taste. Its standard was excess, and its doctrines were tolerance and freedom from accountability.
    New Yorker (April 23, 1990)