How is the complexity of an IT environment assessed?
IT complexity is assessed by considering how many systems support financial reporting, how those systems interact, how much they are customised and how dependent the business and audit are on automated processing.
Relevant indicators include multiple ERPs or feeder applications, custom code, automated interfaces, significant system changes, outsourced platforms, complex access models, extensive report reliance and manual data transfers between systems. The size of the client is relevant, but it is not a complete answer. A smaller business can have a complex technology stack, while a larger entity may use a relatively standardised environment.
The assessment should be evidenced at the right level. For some clients, one entity-level conclusion is enough. For others, complexity differs by application and the audit needs a more granular view.
AI can guide the information gathering, identify indicators in client responses and documents, and explain why an environment appears non-complex or complex. The auditor then reviews whether the conclusion reflects the systems in scope and the planned reliance. The purpose is to set the right depth of work, not to award a label for its own sake.
Platformed capability: Platformed applies the firm's complexity criteria to client responses and evidence, explains the proposed conclusion and adjusts the downstream workflow accordingly. Auditors can override the result and document why.
References: ISA 315 risk assessment resources · Platformed financial audit