Which of the following types of controls should she examine?

An internal auditor observed that sales staff are able to modify or cancel an order in the system prior to shipping* She wonders whether they can also modify orders after shipping.

Which of the following types of controls should she examine?
A . Batch controls.
B . Application controls.
C . General IT controls.
D . Logical access controls

Answer: B

Explanation:

The internal auditor should examine application controls, which directly relate to specific computer applications. These controls ensure the accuracy, completeness, and authorization of transactions processed by the system. Since the auditor’s concern is whether sales staff can modify orders after shipping, which involves transactional changes in a specific application, application controls are the appropriate focus.

Reference: Information systems auditing standards and best practices.

Subscribe
Notify of
guest
0 Comments
Inline Feedbacks
View all comments