AN AUDIT RISK MODEL FOR IT AUDIT ECOSYSTEMS AND DIGITAL TRANSFORMATION (DX) DECISION MAKING. Issue 2 (3rd August 2021)
- Record Type:
- Journal Article
- Title:
- AN AUDIT RISK MODEL FOR IT AUDIT ECOSYSTEMS AND DIGITAL TRANSFORMATION (DX) DECISION MAKING. Issue 2 (3rd August 2021)
- Main Title:
- AN AUDIT RISK MODEL FOR IT AUDIT ECOSYSTEMS AND DIGITAL TRANSFORMATION (DX) DECISION MAKING
- Authors:
- Anomah, Sampson
Ayeboafo, Boadu
Aduamoah, Maurice - Abstract:
- ABSTRACT: Strategy has become indispensable for survival in a contemporary business environment. The role of IT audit or assurance review is now viewed from two perspectives – first, as an independent assessor and, second, as a consulting expert advisor. IT auditors are, therefore, expected to plan their reviews such that their scarce IT audit resources will be put to efficient use and at the same time effectively provide advisory opinions on IT governance and strategies to leverage business executives' function towards the achievement of their specified business objectives. The study used the design science approach using the audit risk model as a conceptual model to develop an objective approach to identify the quality of risk inherent in a digital transformation (dx) project. A major design output was that an Audit Risk model for IT (IAR) in the context of digital transformation is calculated as IAR = PR × SR × RR, where was PR is Primary Risk, SR is Secondary Risk and RR is Residual Risk. Also, Return on IT investment (ROI) has an inverse correlation with PR and was relevant in estimating the PR given IAR as equivalent to ROI. A mixture of a multiple case study approach, quasi experimentation and the Delphi method was used to evaluate the model. The Delphi approach used produced an overall significant value in evaluators' understanding of the usefulness, ease of use and acceptability of the model as an IS/IT audit risk model for the assessment of digital risks andABSTRACT: Strategy has become indispensable for survival in a contemporary business environment. The role of IT audit or assurance review is now viewed from two perspectives – first, as an independent assessor and, second, as a consulting expert advisor. IT auditors are, therefore, expected to plan their reviews such that their scarce IT audit resources will be put to efficient use and at the same time effectively provide advisory opinions on IT governance and strategies to leverage business executives' function towards the achievement of their specified business objectives. The study used the design science approach using the audit risk model as a conceptual model to develop an objective approach to identify the quality of risk inherent in a digital transformation (dx) project. A major design output was that an Audit Risk model for IT (IAR) in the context of digital transformation is calculated as IAR = PR × SR × RR, where was PR is Primary Risk, SR is Secondary Risk and RR is Residual Risk. Also, Return on IT investment (ROI) has an inverse correlation with PR and was relevant in estimating the PR given IAR as equivalent to ROI. A mixture of a multiple case study approach, quasi experimentation and the Delphi method was used to evaluate the model. The Delphi approach used produced an overall significant value in evaluators' understanding of the usefulness, ease of use and acceptability of the model as an IS/IT audit risk model for the assessment of digital risks and strategies of different organisations. The ICC which was used to measure the Intra-Class Correlation (ICC) which is the reliability of agreement among the participating evaluators showed an average ICC of 0.90 with a significant p -value of 0.000 to prove the validity of the model. The study contributes to practice because it provides a tool to assist IT audit practitioners and other business IT assessors to reduce the risk of subjectivity in the allocation of IT audit resources at the planning stage of the audit or assessment. … (more)
- Is Part Of:
- EDPACS. Volume 64:Issue 2(2021)
- Journal:
- EDPACS
- Issue:
- Volume 64:Issue 2(2021)
- Issue Display:
- Volume 64, Issue 2 (2021)
- Year:
- 2021
- Volume:
- 64
- Issue:
- 2
- Issue Sort Value:
- 2021-0064-0002-0000
- Page Start:
- 1
- Page End:
- 33
- Publication Date:
- 2021-08-03
- Subjects:
- Electronic data processing -- Auditing -- Periodicals
Computers -- Access control -- Periodicals
Electronic data processing departments -- Security measures -- Periodicals
005.8 - Journal URLs:
- http://www.tandfonline.com/toc/uedp20/current ↗
http://www.tandfonline.com/ ↗ - DOI:
- 10.1080/07366981.2021.1930643 ↗
- Languages:
- English
- ISSNs:
- 0736-6981
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 3661.115000
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 19828.xml