top of page

Day 84 (21 Feb 2023)

Writer: Foo Yoong HouFoo Yoong Hou

Today, we visited the third property development company in Johor Bahru. Unlike the previous firms, this company lacked an established IT department, so we spent a considerable amount of time going through the information request list with the person in charge who lacked IT knowledge. We patiently explained the details and ensured that she understood the requirements.


After completing the information request list, we conducted a server room sighting and discovered several physical control weaknesses. For instance, the server room was located near the working space and was unlocked, providing unauthorized access to anyone. Furthermore, there was no log book or CCTV in the server room.


Regarding ITGC, we found that the company was using shared ID practice, which made it impossible to trace transactions to a specific employee as they all had the same ID with full module access. This posed a significant risk to the company as it created opportunities for fraud and manipulation of records without management's knowledge.


Finally, we held a brief exit meeting with the client to discuss our audit findings.

 

Main things that have learnt

  • Learn that the practice of sharing user ID will cause a material risk to the company.

  • Learn the important of having proper physical control in the server room.



 
 
 

Recent Posts

See All

Day 121 (14 Apr 2023)

Today is my last day as an intern, and my focus is on the sales matching test. My senior has asked me to teach the new joiners how to...

Day 120 (13 Apr 2023)

Today I focusing on helping my seniors with their CAATs, which are the purchase and sales match tests. As tomorrow is my last day as an...

Day 119 (12 Apr 2023)

Today, I faced an issue when one of the auditors inquired about the variances stated in the JV test report of our CAATs report. Upon...

Comments


THANKS FOR YOUR VISIT

bottom of page