How does ISA 315 affect an auditor's understanding of technology?
ISA 315 (Revised 2019) places greater emphasis on understanding how an entity uses information technology and how that use affects the financial reporting system, relevant controls and risks of material misstatement.
For auditors, this means looking beyond the general ledger. Teams need to understand the applications that initiate, process, record and report financial information; the interfaces and manual transfers between them; the automated controls on which the audit may depend; and the IT general controls that support those applications.
The required depth should match the nature and complexity of the client's environment. A straightforward owner-managed business using an unmodified accounting package does not need the same assessment as a multinational with multiple ERPs, feeder systems and automated interfaces. But “non-complex” still needs an evidenced conclusion. It should not be assumed because the client is small.
Technology can help firms make this work more consistent by guiding scoping, collecting relevant information and linking the complexity conclusion to evidence. The auditor remains responsible for considering whether the systems in scope are complete and whether the assessment is proportionate.
Platformed capability: Platformed gathers information about the client's applications, interfaces and technology dependencies, prepares an evidence-linked complexity assessment and directs the team to proportionate ITGC work. The auditor confirms completeness and approves the scope.
References: ISA 315 (Revised 2019) · AICPA SAS 145 risk-assessment guidance