From the course: CISA Cert Prep: 1 Auditing Information Systems for IS Auditors

Unlock the full course today

Join today to access over 22,600 courses taught by industry experts or purchase this course individually.

Control self-assessments

Control self-assessments

From the course: CISA Cert Prep: 1 Auditing Information Systems for IS Auditors

Start my 1-month free trial

Control self-assessments

- [Instructor] Let's talk about control self-assessment. So, traditional audits versus control self-assessment, how are they different? Well, traditional audits are performed by some dedicated audit staff, or maybe an external auditor. They're managed by some kind of audit organization, if it's the internal folks, it's an audit group, if it's an external auditor, it's an external audit organization. And they tend to be periodic, it's once a quarter or once a year. The auditor comes in, swings in, swoops in and does some kind of audit and everyone gets freaked out and scared. With a control self-assessment approach, now the audit is done by the actual operational staff themselves. The guys in the trenches, the people working in the cubicles, the people doing their job, are self-assessing themselves. Now, that means we have an integrated audit and operational group, if you will. Everybody is now their own little auditor in some way. And it's on a sort of continuous basis. It's not like,…

Contents