Download as pdf or txt
Download as pdf or txt
You are on page 1of 3

IS Audit and Assurance Standard 1002 Organisational Independence

The specialised nature of information systems (IS) audit and assurance and the skills necessary to perform such engagements require standards that apply specifically to IS audit and assurance. The development and dissemination of the IS audit and assurance standards are a cornerstone of the ISACA professional contribution to the audit community. IS audit and assurance standards define mandatory requirements for IS auditing and reporting and inform: IS audit and assurance professionals of the minimum level of acceptable performance required to meet the professional responsibilities set out in the ISACA Code of Professional Ethics Management and other interested parties of the professions expectations concerning the work of practitioners Holders of the Certified Information Systems Auditor (CISA) designation of requirements. Failure to comply with these standards may result in an investigation into the CISA holders conduct by the ISACA Board of Directors or appropriate committee and, ultimately, in disciplinary action.
IS audit and assurance professionals should include a statement in their work, where appropriate, that the engagement has been conducted in accordance with ISACA IS audit and assurance standards or other applicable professional standards.

The ITAF framework for the IS audit and assurance professional provides multiple levels of guidance: Standards, divided into three categories: General standards (1000 series)Are the guiding principles under which the IS audit and assurance profession operates. They apply to the conduct of all assignments, and deal with the IS audit and assurance professionals ethics, independence, objectivity and due care as well as knowledge, competency and skill. The standards statements (in bold) are mandatory. Performance standards (1200 series)Deal with the conduct of the assignment, such as planning and supervision, scoping, risk and materiality, resource mobilisation, supervision and assignment management, audit and assurance evidence, and the exercising of professional judgement and due care Reporting standards (1400 series)Address the types of reports, means of communication and the information communicated Guidelines, supporting the standards and also divided into three categories: General guidelines (2000 series) Performance guidelines (2200 series) Reporting guidelines (2400 series) Tools and techniques, providing additional guidance for IS audit and assurance professionals, e.g., white papers, IS audit/assurance programmes, the COBIT 5 family of products An online glossary of terms used in ITAF is provided at www.isaca.org/glossary. Disclaimer: ISACA has designed this guidance as the minimum level of acceptable performance required to meet the professional responsibilities set out in the ISACA Code of Professional Ethics. ISACA makes no claim that use of this product will assure a successful outcome. The publication should not be considered inclusive of any proper procedures and tests or exclusive of other procedures and tests that are reasonably directed to obtaining the same results. In determining the propriety of any specific procedure or test, controls professionals should apply their own professional judgement to the specific control circumstances presented by the particular systems or IS environment. The ISACA Professional Standards and Career Management Committee (PSCMC) is committed to wide consultation in the preparation of standards and guidance. Prior to issuing any document, an exposure draft is issued internationally for general public comment. Comments may also be submitted to the attention of the director of professional standards development via email (standards@isaca.org), fax (+1.847. 253.1443) or postal mail (ISACA International Headquarters, 3701 Algonquin Road, Suite 1010, Rolling Meadows, IL 60008-3105, USA).
ISACA 2012-2013 Professional Standards and Career Management Committee Steven E. Sizemore, CISA, CIA, CGAP, Chairperson Texas Health and Human Services Commission, USA Christopher Nigel Cooper, CISM, CITP, FBCS, M.Inst.ISP HP Enterprises Security Services, UK Ronald E. Franke, CISA, CRISC, CFE, CIA, CICA Myers and Stauffer LC, USA Murari Kalyanaramani, CISA, CISM, CRISC, CISSP, CBCP British American Tobacco IT Services, Malaysia Alisdair McKenzie, CISA, CISSP, ITCP IS Assurance Services, New Zealand Katsumi Sakagawa, CISA, CRISC, PMP JIEC Co. Ltd., Japan Ian Sanderson, CISA, CRISC, FCA NATO, Belgium Timothy Smith, CISA, CISSP, CPA LPL Financial, USA Rodolfo Szuster, CISA, CA, CBA, CIA Tarshop S.A., Argentina

IS Audit and Assurance Standard 1002 Organisational Independence


'/5/1617/0 !""#$!

%&' () *+,-. */, *00+1*/2' 3+/2.-4/ 0&*55 6' -/,'7'/,'/. 43 .&' *1'* 41 *2.-8-.9 6'-/: 1'8-';', .4 7'1<-. 46='2.-8' 24<75'.-4/ 43 .&' *+,-. */, *00+1*/2' '/:*:'<'/.$ <.1 &' 5=3,/ 573 500=+57;1 >=7;/,?7 0.?=*3@ A1:?+/ /? 5 *121* B,/.,7 /.1 5=3,/11 ?+-57,05/,?7 /.5/ :+?2,310 ?+-57,05/,?75* &731:17317;1 573 175C*10 /.1 &' 5=3,/ 573 500=+57;1 >=7;/,?7 /? :1+>?+6 ,/0 +10:?70,C,*,/,10 B,/.?=/ ,7/1+>1+17;14 D,0;*?01 /.1 31/5,*0 ?> /.1 &6:5,+617/ /? /.1 5::+?:+,5/1 :5+/,10 ,> ,731:17317;1 ,0 ,6:5,+13 ,7 >5;/ ?+ 5::15+57;14 (2?,3 7?7 5=3,/ +?*10 ,7 &' ,7,/,5/,210 /.5/ +1E=,+1 500=6:/,?7 ?> 6575-1617/ +10:?70,C,*,/,10 50 0=;. +?*10 ;?=*3 ,6:5,+ >=/=+1 ,731:17317;14 (33+100 ,731:17317;1 573 5;;?=7/5C,*,/9 ?> /.1 5=3,/ >=7;/,?7 ,7 ,/0 ;.5+/1+ 573F?+ 17-5-1617/ *1//1+4 %'1< &6:5,+617/ >'3-/-.-4/ ( ;?73,/,?7 /.5/ ;5=010 5 B15G7100 ?+ 3,6,7,0.13 5C,*,/9 /? 1H1;=/1 5=3,/ ?CI1;/,210 &6:5,+617/ /? ?+-57,05/,?75* ,731:17317;1 573 ,73,2,3=5* ?CI1;/,2,/9 659 ,7;*=31 :1+0?75* ;?7>*,;/ ?> ,7/1+10/J 0;?:1 *,6,/5/,?70J +10/+,;/,?70 ?7 5;;100 /? +1;?+30K :1+0?771*K 1E=,:617/ ?+ >5;,*,/,10J 573 +10?=+;1 *,6,/5/,?70 L0=;. 50 >=73,7?+ 0/5>>,7-M4 <.1 >+113?6 >+?6 ;?73,/,?70 /.5/ /.+15/17 ?CI1;/,2,/9 ?+ /.1 5::15+57;1 ?> ?CI1;/,2,/94 '=;. /.+15/0 /? ?CI1;/,2,/9 6=0/ C1 6575-13 5/ /.1 ,73,2,3=5* 5=3,/?+K 17-5-1617/K >=7;/,?75* 573 ?+-57,05/,?75* *121*04 &731:17317;1 ,7;*=310 &731:17317;1 ?> 6,73N573 &731:17317;1 ,7 5::15+57;14 <.1 52?,357;1 ?> >5;/0 573 ;,+;=60/57;10 /.5/ 5+1 0? 0,-7,>,;57/ /.5/ 5 +150?75C*1 573 ,7>?+613 /.,+3 :5+/9 B?=*3 C1 *,G1*9 /? ;?7;*=31K B1,-.,7- 5** /.1 0:1;,>,; >5;/0 573 ;,+;=60/57;10K /.5/ 5 >,+6K 5=3,/ >=7;/,?7 ?+ 5 616C1+ ?> /.1 5=3,/ /156O0 ,7/1-+,/9K ?CI1;/,2,/9 ?+ :+?>100,?75* 0;1:/,;,06 .50 C117 ;?6:+?6,0134 <.1 0/5/1 ?> 6,73 /.5/ :1+6,/0 /.1 1H:+100,?7 ?> 5 ;?7;*=0,?7 B,/.?=/ C1,7- 5>>1;/13 C9 ,7>*=17;10 /.5/ ;?6:+?6,01 :+?>100,?75* I=3-1617/K /.1+1C9 5**?B,7- 57 ,73,2,3=5* /? 5;/ B,/. ,7/1-+,/9 573 1H1+;,01 ?CI1;/,2,/9 573 :+?>100,?75* 0;1:/,;,064 <.1 5C,*,/9 /? 1H1+;,01 I=3-1617/K 1H:+100 ?:,7,?70 573 :+1017/ +1;?661735/,?70 B,/. ,6:5+/,5*,/9

819 (0:1;/0

<1+60

&731:17317;1

&731:17317;1 ,7 5::15+57;1

&731:17317;1 ?> 6,73

PCI1;/,2,/9

!"#$% &'()(

(** +,-./0 +101+2134

"

IS Audit and Assurance Standard 1002 Organisational Independence


Q,7G5-1 /? R=,31*,710

%97' R=,31*,71

%-.5' "##" P+-57,05/,?75* &731:17317;1

P:1+5/,21 D5/1

<.,0 &'()( 0/5735+3 ,0 1>>1;/,21 >?+ 5** &' 5=3,/ 573 500=+57;1 17-5-1617/0 C1-,77,7- $ S?216C1+ "#$%4

ISACA 2013

All rights reserved.

You might also like