Information Technology and CAATs
Weighing in at 30-40% of the exam, Section 3 is where most points live, and IT questions appear on every exam form because almost all modern financial reporting runs through IT systems. The setup to watch is testing application controls before confirming that IT general controls work. If ITGCs are weak, every application control built on that infrastructure may be unreliable, no matter how well it is designed. Candidates also flip test data (the auditor's fictitious data through the client's system) and parallel simulation (the client's real data through the auditor's software), the data flows in opposite directions. And many miss the line between IT general controls (environment-wide: access, change management, operations) and application controls (transaction-specific: input validation, edit checks, batch totals).
What AICPA wants you to know
- 1Distinguish between IT general controls and application controls
- 2Identify common IT risks and their impact on the audit
- 3Understand computer-assisted audit techniques (CAATs)
- 4Explain the impact of IT on internal control and audit strategy
- 5Recognize IT governance and security concepts relevant to auditing
Patterns in this topic
The exam re-skins the same archetypes. Recognize these here, then drill them in the Pattern Lab.
Exam tip