1
IT-audit
Forum
Overall picture of the EUROSAI IT Working Group and its functionsIT = Information Technology
2
IT-audit
Forum
• Brief introduction of the presenter• INTOSAI, EUROSAI, EURORAI• EUROSAI Organisation
• Working Areas• IT-Working Group
• History• Organisation• Functions• Projects• ITSA Lessons Learned• Further Activities
• INTOSAI Working Group on IT Audit
Overall Picture of Eurosai ITWG - Agenda
3
IT-audit
Forum
Supreme Audit Institutions (SAIs)
4
IT-audit
Forum
DFA/FOR/DDPS
EDP/IntOrganis.
DETECSSA/DEA
FCh/PS/FDF
Social Ins./FDJP
Mandate sectorSpeciali
st sector
Building and procurement
Economic evaluations
ManagementManagement
Fin. super-vision, audit 1
Fin. super-vision, audit 2Fin. super-vision, audit 3
IT audits
Staff SupportInternational
SFAO Organisational Chart
Decision
Execution
MatrixMatrix
60 Auditors
(9 IT Auditors!)
Total number of Staff 90
5
IT-audit
Forum
Massimo Magnini, CISA, CIA, CISM*Swiss Federal Audit Office (SFAO)Competence Centre IT AuditsMonbijoustrasse 45CH - 3003 Bern
Tel. +41 031 323 10 82Fax +41 031 323 11 01
E-Mail: [email protected]
Web: www.efk.admin.ch
CISA = Certified Information Systems Auditor (ww.isaca.org) CISM = Certified Information Security ManagerCIA = Certified Internal Auditor (www.theiia.org The Institute of Internal Auditors
SFAO – IT Audits
*
6
IT-audit
Forum INTOSAI, EUROSAI, EURORAI
7
IT-audit
Forum
EUROSAI was established in 1990.
The objectives of the Organisation are:
• to promote professional co-operation among SAI members,
• to encourage the exchange of information and documentation,
• to advance the study of public sector audit,
• to stimulate the creating of University Professorships in this subject,
• to work towards the harmonisation of terminology in the field of public audit.
8
IT-audit
Forum EUROSAI Organisation
9
IT-audit
Forum EUROSAI ITWG - History
Oct. 2002: 1st Meeting
The Hague
March 2004: 2nd Meeting
Bern
Feb. 2005: 3rd Meeting
Nicosia
Sept. 2006: 4th Meeting
Bratislava
Feb. 2008: 5th Meeting
Ljubljana
June 2009: 6th Meeting
Bern
At its Congress held in Kraków in June 2008, the EUROSAI approved the handover of the chair of the EUROSAI IT Working Group from the Netherlands to Switzerland. As of 1. June 2008 Switzerland is responsible for the EUROSAI ITWG website and activities.
The EUROSAI IT Working Group was created in 2002, during the V EUROSAI Congress:
10
IT-audit
Forum
The EUROSAI IT Working Group will deploy activities on four strategic IT-related areas:
1. the development of IT-driven international agreements and regulations, for instance privacy rulings, and how to audit these;
2. the emergence of E-Governance, E-Procurement and electronic service delivery and how to audit these;
3. the investment of governments in hardware, software and "humanware" for the running of their offices and for the implementation of programmes, for instance E-Procurement, and how to audit this.
4. Developing the capacity of SAIs to meet their strategic goals by: - utilising IT to support their own internal management; - exploiting IT to enhance the efficiency and effectiveness of their audits; - acquiring the skills necessary to audit in an IT-environment.
Eurosai ITWG - Work Areas
11
IT-audit
Forum Eurosai ITWG “Outputs” in 5 areas
Electronic Records
Management
1
IT Self-assessment
2
E-Government3
Inventory IT Training
Courses
4
Website5
12
IT-audit
Forum
E-Government
Inventory IT Training
Courses
IT Self-assessment
Website
Electronic Records
Management
1
Electronic Records Management
13
IT-audit
Forum
• Aimed at IT Auditors
• What and how to audit
• Audit Checklist
Electronic Records Management
Document “Audit Briefing”
14
IT-audit
Forum
Electronic Records
Management
E-Government
Inventory IT Training
Courses
Website
IT Self-assessment
2
IT Self-assessment (ITSA)
15
IT-audit
Forum
Lead:Switzerland
Members:
Belgium
Bulgaria
European Court of Auditors
Germany
Lithuania
Netherlands
Norway
Spain
Project Team:
ITSA IT Self-assessment
(Rollout)
16
IT-audit
Forum
• Small mixed team
• Business professionals and IT
professionals
• Managers and non-managers
• Moderated• Result: Action Plan• Roll-out into EUROSAI
membership• Regular revision
IT Self-assessment (ITSA)
17
IT-audit
Forum
Lead:Switzerland
Members:
European Court of Auditors
Finland
Germany
Hungary
Latvia
Lithuania
Malta
Netherlands
Norway
Ukraine
Questionnaire
« IT Audit »
Project Team:
ITASA IT Audit Self-assessment
18
IT-audit
Forum
IT Self-assessment
Electronic Records
Management
Inventory IT Training
Courses
Website
E-Government3
E-Government
19
IT-audit
Forum
Lead: Portugal
Members:
Germany
Lithuania
Netherlands
Poland
Russia
UK
Switzerland
Project Team:
E-Government
20
IT-audit
Forum
• Aimed at board and senior management
• Cooperation with INTOSAI IT Committee
• Executive Summary submitted as EUROSAI document
• Full report also available
Executive Summary ‘E-Government in an Audit Perspective’
E-Government
21
IT-audit
Forum www.egov.nik.gov.pl
22
IT-audit
Forum
IT Self-assessment
Electronic Records
Management
E-Government
Website
Inventory ofIT Training
Courses
4
Inventory IT Training Courses
23
IT-audit
Forum
• SAIs and IDI have courseware available
• Limited number commercial off the shelf courses
• Accounting firms prepared to develop tailor-made courses
Inventory of IT Training Courses
24
IT-audit
Forum …… Training News …..
25
IT-audit
Forum
IT Self-assessment
Electronic Records
Management
E-Government
Inventory IT Training
Courses
Website5
Eurosai ITWG Website
26
IT-audit
Forum Welcome to the site ……!!
As of 1
. June 2008
Switzerla
nd is responsib
le
for the EUROSAI IT
WG
website and activ
ities.
27
IT-audit
Forum
Lead:Netherlands
Members:
Austria
Bulgaria
Finland
Germany
Lithuania
Russia
Slovenia
Switzerland
Sounding Board
Project Team:
Relevance of IT in Public Revenue Fraud
28
IT-audit
Forum EUROSAI ITWG – Further Activities
29
IT-audit
Forum INTOSAI Working Group on IT Audit
30
IT-audit
Forum
Thank you!
Act Local, Think Global
Top Related