Obtaining Assurance for Critical Calculation Functionality

Ensuring Accuracy: Best Practices for Validating Critical Calculations

Prev Question Next Question

Question

An IS auditor noted that a change to a critical calculation was placed into the production environment without being tested.

Which of the following is the BEST way to obtain assurance that the calculation functions correctly?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

B.

The scenario presented in the question implies that there is a risk that the untested calculation could produce incorrect results, which could have serious consequences for the organization. Therefore, the IS auditor needs to determine the best way to obtain assurance that the calculation functions correctly.

A. Checking regular execution of the calculation batch job could provide some assurance that the calculation is producing the expected results, but it does not necessarily confirm the accuracy of the calculation. This option may be appropriate for monitoring ongoing production processes, but it is not the best option in this situation.

B. Performing substantive testing using computer-assisted audit techniques (CAATs) is likely the best option to obtain assurance that the calculation functions correctly. CAATs are computer programs that can be used to perform detailed analysis of data, including the results of calculations. By using CAATs, the auditor can perform testing that is more rigorous and comprehensive than manual testing, and can quickly identify any errors or anomalies in the calculation.

C. Obtaining post-change approval from management may be necessary to ensure that proper change management procedures were followed, but it does not provide any assurance that the calculation functions correctly. Approval from management only confirms that the change was authorized, not that it was implemented correctly.

D. Interviewing the lead system developer may provide some insight into the change process, but it is not a reliable way to obtain assurance that the calculation functions correctly. The developer may not have performed any testing or may not have recognized the potential risks associated with the change.

In summary, the best way to obtain assurance that the calculation functions correctly is to perform substantive testing using computer-assisted audit techniques (CAATs). This will provide a more comprehensive and reliable assessment of the accuracy of the calculation.