Information Systems Examination

An internal document sets out a rule; the system executes it. Alignment between the two is assumed but seldom confirmed: organisations rely on the settings having been made correctly when the system entered service and on their having remained unchanged since.

Settings, however, change continually — on upgrades, on the introduction of new products and channels, on a change of administrator, on the correction of errors. The rule recorded in the internal document meanwhile stays as it was. The divergence accumulates unnoticed and comes to light, as a rule, through an external occasion: a customer complaint, a regulatory observation, a variance in reporting, a loss.

This service answers a narrowly framed question: whether a particular system executes a particular rule, what becomes of a transaction once the rule is triggered, and whether this is borne out by documented evidence. No full audit of the organisation is undertaken, which makes the work substantially shorter and less costly than a comprehensive engagement.

To obtain a preliminary estimate of scope, timing and fees, please complete the questionnaire. A response is provided within several business days.

Download the questionnaire

Circumstances of engagement

A reasonable doubt has arisen
A change of owner or of management
An external review is in prospect

Figures diverge from expectations, similar customer complaints are received, or transactions have been identified that ought not to have gone through. It must be established whether the rule itself or its execution by the system is at fault.

A new owner, board of directors or head of function takes charge of a system whose actual condition is known to them only through the accounts of those who ran it. Independent confirmation is required.

The organisation is preparing for an inspection, a transaction or the raising of finance and prefers to identify divergences in good time, while there is scope to address them.

     

What is established

  • whether the actual settings of the system correspond to the rules established by the internal documents of the organisation, by its contracts and by the requirements applicable to its activities
  • whether the rule covers its subject in full: whether all transactions, channels, products and categories of counterparty fall within its operation
  • what becomes of a transaction once the rule is triggered — by whom and within what time it is reviewed, how that review concludes and whether the outcome is recorded
  • who may alter the settings and by what procedure, whether a trace of alterations is retained, and whether it can be established by whom and when an alteration was made
  • what divergences between document and configuration exist in fact, what their possible consequences are, and in what order they are best addressed

Objects examined

The list reflects subject matters on which requests are received regularly. It is not exhaustive: a work programme for a subject matter not previously encountered is assembled from the methodological base of the practice within a matter of days.

Core banking system

Question

Whether the actual parameters of products and accounting rules correspond to the terms approved by the competent body of the organisation.

What is examined

Product parameterisation; the accrual of interest, fees and penalties; posting rules; the making and approval of correcting entries; segregation of duties among operational staff; separation of production and test environments; and the completeness of user activity logging.

Outcome

A schedule of divergences between the approved terms and the actual configuration, with supporting evidence and an assessment of possible consequences.

Anti-fraud and transaction monitoring

Question

Whether the rules operate as described in the internal policy, and what becomes of a transaction once a rule is triggered.

What is examined

Correspondence of the configured rules to those approved; coverage of channels and transaction types; thresholds and the basis on which they were set; the procedure and timeliness of alert review; the proportion closed without review; the procedure for amending rules and the retention of an audit trail; and interaction with the security function.

Outcome

A conclusion on the practical effectiveness of the rule set, identifying categories of transaction that go unaddressed, together with recommendations on the review process.

Financial monitoring: rules and scenarios

Question

Whether the detection scenarios contemplated by internal rules and applicable requirements are implemented in the system, and whether subsequent action is taken in good time.

What is examined

The composition and configuration of detection scenarios; coverage of the customer base and of transaction types; the currency of the lists used and the procedure for updating them; the maintenance and refreshment of customer information; the timeliness of preparing and submitting notifications; and the retention and accessibility of supporting materials.

Outcome

A schedule of divergences between the established rules and their implementation in the system, with an assessment of the risk of untimely detection.

Card processing and payment services

Question

Whether the actual rules of payment processing correspond to contractual terms, published tariffs and the requirements of payment systems.

What is examined

Transaction routing; limits and the basis for changing them; the procedure and completeness of reconciliation with payment systems and partner banks; the handling of disputed transactions and adherence to time limits; the treatment of card data and key material; segregation of access to management facilities; and continuity arrangements.

Outcome

An assessment of the correspondence of actual processing to the established terms, with a schedule of divergences and recommendations.

Tariffing and billing

Question

Whether customers are charged precisely what the approved tariffs and the concluded contracts provide for.

What is examined

Correspondence of tariff plans in the system to those approved; the application of discounts and individual terms; completeness of charging for services rendered; instances of duplicate and of omitted charging; the procedure for adjustments and the persons entitled to make them; and the retention of a trace of tariff changes.

Outcome

A schedule of the deviations identified, with an assessment of their effect on revenue and on obligations towards customers.

Inventory and stock accounting

Question

Whether the accounting system reflects the actual movement of goods, and whether the persons able to alter that record are suitably restricted.

What is examined

The procedures for receipt, transfer and write-off; the grounds for write-off and the persons vested with the corresponding rights; the conduct of stocktaking and the recording of its results; the treatment of misgrading; the completeness and reliability of data exchange with the point-of-sale and accounting environments; and the retention of a trace of backdated adjustments.

Outcome

An assessment of the reliability of the accounting data and a schedule of areas in which records may be altered without trace.

Human resources and payroll

Question

Whether payments are calculated in accordance with the approved rules, and whether access to employee information is suitably restricted.

What is examined

Correspondence of the configured calculation rules to the approved remuneration and bonus policies; the making and justification of manual adjustments; segregation of access to personal data and payment information; the timeliness of withdrawing access on termination; and the completeness of logging of access to employee information.

Outcome

A schedule of divergences in calculation rules and in access segregation, with an assessment of the attendant risks.

Electronic document management

Question

Whether documents circulating in the system possess the attributes required for them to serve as confirmation of the actions taken.

What is examined

The procedure for signing and verifying signatures; correspondence of approval routes to those approved; the possibility of amending a document after approval and the retention of a trace of such amendment; completeness of registration; adherence to established retention periods; and the granting of access to documents of restricted circulation.

Outcome

An assessment of the evidential suitability of the documents held in the system and a schedule of divergences from the established procedure.

Government information systems

Question

Whether the system placed into service corresponds to the design documentation and the technical specification, and whether the information processed is adequately protected.

What is examined

Completeness of implementation of functional requirements; the composition and conduct of inter-agency data exchange; access segregation and the procedure for granting access; logging of access to citizens’ data; correspondence of the actual architecture to the design decisions; and arrangements for support and change.

Outcome

A conclusion on the correspondence of the system to the established requirements, with a schedule of deviations and an assessment of their significance.

Video surveillance and access control

Question

Whether the recordings and logs of these systems are fit for the purposes for which the systems were installed.

What is examined

Correspondence of the actual fields of view and image quality to the stated purposes; the actual retention period against that established; the integrity of recordings and the procedure for their export; segregation of access to the archive and logging of access to it; time synchronisation; and compliance with personal data requirements and notification of individuals.

Outcome

An assessment of the suitability of recordings for use in the investigation of incidents, together with a schedule of the limitations identified.

Interfaces and data exchange

Question

Whether data pass between systems completely and without distortion, and whether transmission failures are detected.

What is examined

The composition and purpose of the interfaces in operation; the completeness and integrity of the data transmitted; error handling and the retransmission procedure; the scope for duplicate transactions to arise; the existence and regularity of reconciliations; the storage and protection of interface credentials; and the procedure for amending exchange formats.

Outcome

A schedule of the points at which data may be lost or distorted, with an assessment of the consequences for accounting and reporting.

Promotional draws and prize competitions

Question

Whether the outcome of a draw can be reproduced and confirmed by an independent party.

What is examined

The compilation and integrity of the register of participants; the mechanism of random selection employed and the reproducibility of its result; adherence to the published terms; the completeness and correctness of the record of proceedings; compliance with advertising and personal data requirements; and the retention of the materials of the draw.

Outcome

A conclusion on the correspondence of the draw conducted to the published terms and the applicable requirements.

Distinction from a review by the solution provider

Organisations are often able to obtain confirmation of proper operation from the developer or supplier of a system. Such a review answers the question whether the system operates in accordance with its own documentation. The question posed here is a different one: whether the behaviour of the system corresponds to the rules established by the organisation itself — rules of which the supplier is unaware and which its documentation does not reflect.

Furthermore, confirmation issued by the party that supplied or maintains the solution lacks the attribute of independence, which limits its evidential weight before a regulator, shareholders, an insurer or a court.

How the examination is performed

The sequence follows the general course of work of the practice: definition of scope, agreement of criteria, request for materials, fieldwork, evaluation of findings, discussion of preliminary results and report. What differs is the narrowness of the scope, which shortens the timetable.

The examination of a single system ordinarily requires two to four weeks of fieldwork, to which the scheduling lead time is additional.

Evidence is obtained through analysis of actual configurations, extracts and logs, interviews with staff, observation of operations, reperformance of control procedures and sample testing over the period under examination. Testing is performed on the data of the organisation; any action capable of affecting availability is agreed separately.

The full course of work →.

Form of the outcome

A report is delivered setting out the scope and the procedures applied, a schedule of findings identifying the criterion each contravenes together with evidence enabling the observation to be reproduced, a risk assessment for each finding, and a register of recommendations with an indication of priority.

The report is suitable for submission to the governing bodies of the organisation and, where required, to a regulator, a counterparty or another party in whose interest the examination was performed. Recommendations are expressed in terms of requirements and controls; the choice of particular solutions and vendors rests with the organisation.

Scope of the service

Application systems and management processes are within scope. Industrial automation and equipment firmware are not. Engagements to implement the solutions examined, and participation in remediation in the capacity of implementer, are not accepted.

The practice does not resell software or equipment, does not act as a partner of vendors and receives no remuneration from them. The outcome of an examination bears no relation to the organisation’s subsequent procurement.

Frequently asked questions

How does this differ from a comprehensive IT audit

In scope and in the form of the outcome. A comprehensive audit covers the information technology management processes of the organisation as a whole and concludes with a report containing an independent assurance conclusion. This examination is confined to a single system or a single rule and answers the specific question posed, which substantially reduces both time and cost.

Is access to the system required

In most cases extracts of settings, access rights and logs prepared by the organisation’s own staff, together with a demonstration of operations in the presence of a specialist, will suffice. Where direct access is required, it is granted in read-only form and within an agreed scope.

What if internal documents are absent or outdated

Their absence or obsolescence is recorded as a finding. The criteria are then agreed by reference to other sources: contracts, applicable requirements, terms published to customers, and decisions of the governing bodies.

Can the examination be conducted without informing the staff of the function

The work is conducted openly and presupposes interaction with staff. Matters calling for a different approach fall within the investigation of circumstances and are addressed separately.

Can the examination conclude that there are no divergences

Yes. Confirmation of compliance is as much an outcome as the identification of divergences and is reported in the same manner.