Centralized Data Processing (CDP) involves all data processing being performed by one or more large computers housed at a central site that serve users throughout the organization
Audit Objectives - verify that the structure of the IT function is such that individuals in incompatible areas are segregated in accordance with the level of potential risk and in a manner that promotes a working environment.
Review the current organizational chart, mission statement, and job descriptions for key functions to determine if individuals or groups are performing incompatible duties
Verify that corporate policies and standards for systems design, documentation, and hardware and software acquisition are published and provided to distributed IT units
Verify that compensating controls, such as supervision and management monitoring, are employed when segregation of incompatible duties is economically infeasible
Review systems documentation to verify that applications, procedures, and databases are designed and functioning in accordance with corporate standards
(1) Reviewrelevant documentation, including the current organizational chart, mission statement, and job descriptions for key functions, to determine if individuals or groups are performing incompatiblefunctions.
(2) Review systems documentationandmaintenance records for a sample of applications.
(3) Verify that computeroperators do not have accessto theoperational detailsof a system’s internallogic.
(4) Through observation, determine thatsegregation policyis being followed in practice.
Data processing consists Organizational Functions such as:
Data Conversion - transcibes data from hard-copy source documents into coputer input
2. Computer Operations - processes the electronic files produced in data convesion
3. Data Library - provides storage for off-line data files
Data Librarian is RESPONSIBLE for Receipt,Storage, Retrieval, and Custody of data files
participants in system developments are
(1) Systems professionals - Gather facts about the user's problem, analyze the facts, & Formulate a solution. Includes
system analysts, database designers & programmers
(2) End users - for whom the sytem is built
(3) Stakeholders - individuals inside or outside the firm who have an interest in the system, but are not end users. Includes Accountants,Internal auditors,External auditors, Others who oversee system development.
3. Divide transaction-processing tasksamong individuals such that short of collusion between two or more individuals fraud would not be possible.
Segregation of Incompatible IT Functions:
Separating Systems Development from Computer Operations
Separating Database Administration from Other Functions: DBA responsibilities include creating database schema and user views, assigning database accessauthority to users, monitoring database usage, and planning for future expansion
Separating New Systems Development from Maintenance: divides the in-house systems development function into two groups: Systems Analysis and Programming
Systems analysis works with users to produce detailed designs of the new systems
Programming codes the programs according to design specifications
Alternative A - end users handle input and output but systems development, computer operations, and database administration remain centralized.
2. Alternative B - distributes all computer services to the end users, where they operate as standalone units.
Inefficient use of resources - (1) risk of mismanagement of organization-wide IT resources by end users (2) risk of operational inefficiencies (3) risk ofincompatible hardware and software among end-user functions
DDP has reduced costs in two other areas:
(1) data can be edited and entered by the end user
(2) application complexity can be reduced
DDP improves Three areas of need that too often go unsatisfied in the centralized model:
(1) users desire to control the resources that influence their profitability
(2) users want systems professionals to be responsive to their specific situation
(3) users want to become more actively involved in developing and implementing their own systems
Implement a Corporate IT Function
(1) Central testing of commercial software and hardware
(2) User services - provides technical help to users during the installation of new software and in troubleshooting hardware and software problems