ICAI Standards That Apply to IS Audit
There is no single IS audit standard. Here's which SA, SIA or guide governs which situation.
ICAI has no single "Standard on IS Audit". The rules an IS auditor works under are spread across the Standards on Auditing (for IT within a financial statement audit), the Standards on Internal Audit (for internal IS audits), assurance standards for service organisations, and AASB guidance notes. ISACA's IT Assurance Framework (ITAF) sits alongside them, and ICAI's own DISA material quotes it heavily.
Knowing which pronouncement governs which situation is a frequent source of Assessment Test questions, and of real-world errors: a statutory auditor relying on a cloud provider's report needs SA 402 and SAE 3402, not the internal audit standards.
You save ₹450
- Full-length timed mocks
- Module-wise practice
- Emerging-tech coverage
One payment, no subscription · Valid for 2 months
Which ICAI Pronouncement Covers What
| Pronouncement | What it covers for IS work |
|---|---|
| SA 315 | Understanding the entity, including its IT; risks arising from IT; defines general IT-controls and application controls with examples |
| SA 330 | Responding to assessed risks: tests of controls and substantive procedures |
| SA 500 | Audit evidence, including evaluating information produced by the entity and choosing between 100% testing, specific items and sampling |
| SA 530 | Audit sampling: statistical and non-statistical, sample size factors, selection methods |
| SA 230 | Audit documentation: what to record so an experienced auditor could understand the work, evidence and conclusions |
| SA 265 | Communicating significant deficiencies in internal control, IT included, in writing |
| SA 402 and SAE 3402 | Using a service organisation (outsourced payroll, a cloud ERP host) and the type 1 and type 2 assurance reports on its controls |
| SA 620 | Using the work of an auditor's expert, such as an IT specialist |
| SIA 520 | Internal auditing in an IT environment: understanding, risk assessment, scoping, testing, documentation, reporting |
| SIA 530 | Internal audit where processes or IT are outsourced to third-party service providers |
| AASB Implementation Guide on Rule 11(g) | Auditor reporting on the accounting software audit trail (edit log) |
| AASB and DAAB Technical Guide on Digital Assurance | Practical guidance for audits in digital environments |
Type 1 vs Type 2 Service Organisation Reports
From SAE 3402, and a common confusion.
- Type 1 report
- Covers the service organisation's description of its system and the suitability of design of its controls, as at a specified date. It says nothing about whether controls worked over time.
- Type 2 report
- Adds operating effectiveness of the controls throughout a specified period. Only a type 2 report gives evidence a user auditor can use for reliance on controls across the year.
Where ISACA's ITAF Fits
ITAF is ISACA's framework of IS audit and assurance standards and guidelines. ICAI's ISA 3.0 Module 1 material quotes its standards on the audit charter, organisational and professional independence, reasonable expectation, materiality, evidence and using the work of experts, numbered in the 1000 and 1200 series. The material quotes the third edition; check isaca.org for the current edition before relying on a standard's number or wording in practice.
For a CA, ITAF does not replace the SAs or SIAs. Where an engagement is a statutory audit, the SAs govern. ITAF is the professional reference for standalone IS audits and is useful wherever the ICAI pronouncements are silent on IT-specific procedure.
Quick practice on audit concepts. No signup.
Check What Is in Force
Standards change and the background material is dated (Revised Edition, August 2020). SIA 520 and SIA 530 each state they apply to internal audits beginning on or after a date to be notified by ICAI's Council, and the SA 315 on ICAI's standards page is the version effective from April 2008. Before quoting a requirement in practice, check the current text and effective date on icai.org.
How the DISA Assessment Test Tests This
- check_circleStandard-to-situation matching: "an auditor relies on a payroll bureau's controls" points to SA 402 and SAE 3402.
- check_circleType 1 vs type 2: a question about reliance on controls throughout the year needs type 2.
- check_circleSA 315 vs SA 330: identifying and assessing risk vs responding to it.
- check_circleIndependence under ITAF: organisational independence is about where the audit function sits; professional independence is the auditor's attitude and appearance. The material quotes both.
- check_circleSIA 520 names DISA or an equivalent qualification as the credential for internal auditors performing IT audits, a detail that can turn up as a straight recall question.
FAQs
Does ICAI have a standard on information systems audit?expand_more
Not a single one. IS audit work draws on SA 315, SA 330, SA 402, SA 500, SA 530 and others for financial audits, SIA 520 and SIA 530 for internal audits, SAE 3402 for service organisation reports, and AASB guidance such as the Rule 11(g) implementation guide.
What is SIA 520?expand_more
ICAI's Standard on Internal Audit for internal auditing in an IT environment. It requires understanding the IT environment, an independent IT risk assessment, scoping, planning, testing of design, implementation and operating effectiveness, documentation and agreed action plans.
What is the difference between a type 1 and type 2 report under SAE 3402?expand_more
Type 1 covers the description and design of controls at a point in time. Type 2 also covers whether the controls operated effectively over a period.
Is ITAF binding on chartered accountants?expand_more
ITAF is ISACA's framework. ICAI's SAs and SIAs govern engagements under them; ITAF is a professional reference that ICAI's DISA material teaches alongside them.
Next steps
- ITGC vs Applicationarrow_forward
- Audit Samplingarrow_forward
- Outsourcing Riskarrow_forward
- Syllabusarrow_forward
Assessment Test format, timed and scored.
