While planning a risk-based audit of a payments processor, the IS auditor finds that an outsourced settlement function has not been audited in four years, has no current process documentation, and processes roughly forty per cent of daily transaction value. The chief audit executive suggests deferring it again because the provider supplies a quarterly assurance summary. What should the IS auditor recommend as the PRIMARY basis for the planning decision?
- ADefer the review for another cycle on the basis that the quarterly provider summary already gives independent comfort over settlement processing.
- BSchedule the review immediately on the basis that the four-year gap since the last audit is the strongest indicator that coverage is overdue.
- CLimit the review to a walkthrough of the provider's quarterly summary, escalating only if the walkthrough identifies a control weakness in the summary itself.
- DInclude the review and prioritise it based on the inherent risk, control risk and residual risk of the settlement function relative to other auditable units. Correct
Why A is wrong: A provider-issued summary is management information from the auditee's perspective and does not substitute for independent audit assurance, especially where inherent risk is material and unverified.
Why B is wrong: Time since last audit is a useful input but it is not the primary driver in a risk-based plan, which should weight inherent and residual risk rather than rotation alone.
Why C is wrong: Restricting work to a walkthrough of management's own summary fails to gather sufficient and reliable evidence over a high-value process and treats provider assurance as a substitute for independent testing.
Why D is correct: Risk-based audit planning requires the auditor to rank auditable units by inherent and control risk and to allocate effort to areas of highest residual risk, which the settlement function's volume and documentation gaps clearly signal.