Choose an area of interest:
Search 

Choose an area of interest:


IIA Releases New IT Risk Guidance


March 18, 2008 (SmartPros) The Institute of Internal Auditors has issued two new documents in its Guide to the Assessment of IT Risk (GAIT) series. The guides address updates and revisions to regulations as well as the needs of organizations to link IT controls to critical business risks.



The second guide, GAIT for IT General Control Deficiency Assessments, gives auditors and management an approach to assess whether IT general control deficiencies identified during their Sarbanes-Oxley Section 404 assessment represent significant deficiencies or material weaknesses in the system of internal control over financial reporting. It builds on guidance provided in 2004 by nine CPA firms, A Framework for Evaluating Control Exceptions and Deficiencies, and reflects recent changes in the definitions of material weakness and significant deficiency.

The third guide in the series, GAIT for Business and IT Risk, helps managers and auditors identify all the key controls that are critical to achieving business goals and objectives. It identifies the critical aspects of information technology that are essential to the management and mitigation of organizational risk. These critical IT functionalities and their corresponding risks can then be considered when planning audit work.

Both sets of guidance can be downloaded free of charge from The IIA Web site at www.theiia.org/guidance/technology.

2008 SmartPros Ltd. All rights reserved.

Related Stories
 
 
This Week in the SmartPros News & Insights Newsletter

  Related Courses
 


 
Would you recommend this article?
5 (yes, highly)
4
3
2
1 (no, not at all)
Comments:


 
 
About SmartPros | Accounting Products | Professional Education | Marketing Services | Consulting | Engineering Products | Contact Us
2007 SmartPros Ltd.