Data Integrity and Completeness using IDEA · Data Integrity and Completeness using IDEA ISACA...

17
Data Integrity and Completeness using IDEA ISACA Accra Chapter's IT Audit, Information Security and Risks Insights Alisa Hotel, North Ridge 21 May 2014

Transcript of Data Integrity and Completeness using IDEA · Data Integrity and Completeness using IDEA ISACA...

Page 1: Data Integrity and Completeness using IDEA · Data Integrity and Completeness using IDEA ISACA Accra Chapter's IT Audit, Information Security and Risks Insights Alisa Hotel, North

Data Integrity and

Completeness

using IDEA

ISACA Accra Chapter's IT Audit, Information

Security and Risks Insights

Alisa Hotel, North Ridge

21 May 2014

Page 2: Data Integrity and Completeness using IDEA · Data Integrity and Completeness using IDEA ISACA Accra Chapter's IT Audit, Information Security and Risks Insights Alisa Hotel, North

1© 2014 KPMG, a partnership established under Ghanaian law and a member firm of the KPMG network of independent member firms affiliated with

KPMG International Cooperative (“KPMG International”), a Swiss entity. All rights reserved.

Overview of CAATs…

Introducing IDEA

Other Products

Data Integrity and Completeness Case Study

Page 3: Data Integrity and Completeness using IDEA · Data Integrity and Completeness using IDEA ISACA Accra Chapter's IT Audit, Information Security and Risks Insights Alisa Hotel, North

2© 2014 KPMG, a partnership established under Ghanaian law and a member firm of the KPMG network of independent member firms affiliated with

KPMG International Cooperative (“KPMG International”), a Swiss entity. All rights reserved.

Overview of CAATs

CAATs- Computer Assisted Audit Techniques/Tools

- Also know as data-analysis/data mining.

CAATs can be classified into four broad categories:

IDEA is a Data Analysis software.

Data Analysis Software

Network Security

Evaluation Software/ Utilities

OS and DBMS

Security Evaluation Software/ Utilities

Software and Code Testing Tools

Page 4: Data Integrity and Completeness using IDEA · Data Integrity and Completeness using IDEA ISACA Accra Chapter's IT Audit, Information Security and Risks Insights Alisa Hotel, North

3© 2014 KPMG, a partnership established under Ghanaian law and a member firm of the KPMG network of independent member firms affiliated with

KPMG International Cooperative (“KPMG International”), a Swiss entity. All rights reserved.

Introducing IDEA

IDEA stands for:

It is a computer-based interrogation tool for use by auditors, accountants, investigators, and IT staff.

Page 5: Data Integrity and Completeness using IDEA · Data Integrity and Completeness using IDEA ISACA Accra Chapter's IT Audit, Information Security and Risks Insights Alisa Hotel, North

4© 2014 KPMG, a partnership established under Ghanaian law and a member firm of the KPMG network of independent member firms affiliated with

KPMG International Cooperative (“KPMG International”), a Swiss entity. All rights reserved.

Introducing IDEA – Historical Perspective

Created by the Office of the Auditor General for Canada in the mid 80's

Developed commercially by the Canadian Institute of Chartered Accountants.

Currently owned by Caseware International.

Page 6: Data Integrity and Completeness using IDEA · Data Integrity and Completeness using IDEA ISACA Accra Chapter's IT Audit, Information Security and Risks Insights Alisa Hotel, North

5© 2014 KPMG, a partnership established under Ghanaian law and a member firm of the KPMG network of independent member firms affiliated with

KPMG International Cooperative (“KPMG International”), a Swiss entity. All rights reserved.

Introducing IDEA - What Can it do?

Analyzes data

Allows data extraction

Sampling

Manipulation of data

Can read data from almost any source

Export data in a multitude of formats

Page 7: Data Integrity and Completeness using IDEA · Data Integrity and Completeness using IDEA ISACA Accra Chapter's IT Audit, Information Security and Risks Insights Alisa Hotel, North

6© 2014 KPMG, a partnership established under Ghanaian law and a member firm of the KPMG network of independent member firms affiliated with

KPMG International Cooperative (“KPMG International”), a Swiss entity. All rights reserved.

Introducing IDEA - How Can IDEA be Used?

General use is validating the accuracy and

integrity of the data

Displaying data in different ways

Generating analysis that

would not otherwise be unavailable

Identifying unusual or strange items

Testing validity of items

Increase your coverage

Page 8: Data Integrity and Completeness using IDEA · Data Integrity and Completeness using IDEA ISACA Accra Chapter's IT Audit, Information Security and Risks Insights Alisa Hotel, North

7© 2014 KPMG, a partnership established under Ghanaian law and a member firm of the KPMG network of independent member firms affiliated with

KPMG International Cooperative (“KPMG International”), a Swiss entity. All rights reserved.

Introducing IDEA - Where can IDEA be Used?

Examine subsets of a population (sample)

Substantive testing

Increase or widen the scope of

investigation

IDEA

Page 9: Data Integrity and Completeness using IDEA · Data Integrity and Completeness using IDEA ISACA Accra Chapter's IT Audit, Information Security and Risks Insights Alisa Hotel, North

8© 2014 KPMG, a partnership established under Ghanaian law and a member firm of the KPMG network of independent member firms affiliated with

KPMG International Cooperative (“KPMG International”), a Swiss entity. All rights reserved.

Introducing IDEA - Features Specific for Consideration

No limit to the number of records

Own programming language that is compatible with Visual Basic for Applications (VBA)

Has a File Explorer

Can create or download additional options for IDEA

Page 10: Data Integrity and Completeness using IDEA · Data Integrity and Completeness using IDEA ISACA Accra Chapter's IT Audit, Information Security and Risks Insights Alisa Hotel, North

9© 2014 KPMG, a partnership established under Ghanaian law and a member firm of the KPMG network of independent member firms affiliated with

KPMG International Cooperative (“KPMG International”), a Swiss entity. All rights reserved.

Introducing IDEA - The Stages of Using IDEA

Determine if IDEA is appropriate for the audit

Consider audit objectives and where IDEA can be used

Determine data required and arrange download

Use IDEA Functions

Review and Housekeeping

Page 11: Data Integrity and Completeness using IDEA · Data Integrity and Completeness using IDEA ISACA Accra Chapter's IT Audit, Information Security and Risks Insights Alisa Hotel, North

10© 2014 KPMG, a partnership established under Ghanaian law and a member firm of the KPMG network of independent member firms affiliated with

KPMG International Cooperative (“KPMG International”), a Swiss entity. All rights reserved.

Why perform data analysis?

It cannot be ignored

A good system is useless with bad data

(“GIGO”)

Solvency II requirements for data quality in insurance

Enhanced risk management

Better coverage, up to 100% of population

Easier to identify unusual or large

transactions/items

Analysis of data from different

sources/combining data

Provides audit trail for review

Specific Benefits

Reduces less interesting manual

review of data

Analyzes data more quickly and efficiently

Identifies trends, exceptions and potential

areas of concern

Responds to client expectations or

demands

Efficiencies from reuse

Page 12: Data Integrity and Completeness using IDEA · Data Integrity and Completeness using IDEA ISACA Accra Chapter's IT Audit, Information Security and Risks Insights Alisa Hotel, North

11© 2014 KPMG, a partnership established under Ghanaian law and a member firm of the KPMG network of independent member firms affiliated with

KPMG International Cooperative (“KPMG International”), a Swiss entity. All rights reserved.

Triggers for data analysis

• Responds to client expectations or demands

• Required by legislation/regulators

• Solvency II

• Anti Bribery & Corruption

• Losses caused by fraud

• Improve business decision making and gain competitive advantage

• Demonstrate good governance or thought leadership (e.g. CA/CM)

• Data cleansing for upload to new systems implementation

From the client

• Differentiate our proposition in proposals (egg CA/CM)

• Reduce audit costs and achieve efficiencies

• Provide more value-added analysis and insight to maintain client relationship

Internally within KPMG

Page 13: Data Integrity and Completeness using IDEA · Data Integrity and Completeness using IDEA ISACA Accra Chapter's IT Audit, Information Security and Risks Insights Alisa Hotel, North

12© 2014 KPMG, a partnership established under Ghanaian law and a member firm of the KPMG network of independent member firms affiliated with

KPMG International Cooperative (“KPMG International”), a Swiss entity. All rights reserved.

Introducing IDEA - Import Different File Types

ASCII (fixed, delimited)

EBCDIC dBASE IV Print Report and Adobe PDF Files

Microsoft Excel and Microsoft

Access

SAP / AIS ODBC Other (AS400 / XML)

Page 14: Data Integrity and Completeness using IDEA · Data Integrity and Completeness using IDEA ISACA Accra Chapter's IT Audit, Information Security and Risks Insights Alisa Hotel, North

Section 2

Other Products

Page 15: Data Integrity and Completeness using IDEA · Data Integrity and Completeness using IDEA ISACA Accra Chapter's IT Audit, Information Security and Risks Insights Alisa Hotel, North

14© 2014 KPMG, a partnership established under Ghanaian law and a member firm of the KPMG network of independent member firms affiliated with

KPMG International Cooperative (“KPMG International”), a Swiss entity. All rights reserved.

Other Products

• CaseWare Smart Analyzer

• IDEAServer

• Smart Exporter

• CaseWare Monitor

Page 16: Data Integrity and Completeness using IDEA · Data Integrity and Completeness using IDEA ISACA Accra Chapter's IT Audit, Information Security and Risks Insights Alisa Hotel, North

Case Study – Employee

Database Integrity and

Completeness Test

Page 17: Data Integrity and Completeness using IDEA · Data Integrity and Completeness using IDEA ISACA Accra Chapter's IT Audit, Information Security and Risks Insights Alisa Hotel, North

Thank you

Presentation by:

Leah Kimata

Risk Consulting ManagerCISA/ Certified ISO Business

Continuity Management System

Lead Auditor