- Get link
- X
- Other Apps
Audit Evidence Attributes for Access Control (Key Control Evaluation)
Beyond Sufficient, Appropriate, and Competent Evidence
Yes. Although Sufficient, Appropriate, and Competent are the most widely recognized characteristics of audit evidence, they are not the only attributes discussed in auditing, internal control, information security, and digital forensics.
Various professional standards and frameworks describe additional characteristics that strengthen the quality, reliability, and defensibility of audit evidence.
Primary Audit Evidence Attributes
| Attribute | Meaning | Common Reference |
|---|---|---|
| Sufficient | Adequate quantity of evidence. | ISA, GAAS |
| Appropriate | Relevant and reliable evidence. | ISA, GAAS |
| Competent | Credible, trustworthy, and obtained from dependable sources. | Traditional Auditing, ISACA |
| Relevant | Directly supports the audit objective. | ISA, IIA |
| Reliable | Accurate, dependable, and unbiased. | ISA, COSO |
| Valid | Measures or proves what it is intended to measure. | Research, Forensics |
| Authentic | Genuine and not altered. | Digital Forensics |
| Verifiable | Can be independently confirmed. | ISACA, ISO |
| Objective | Free from personal bias. | IIA, ISACA |
| Complete | Contains all required information. | ISO 27001 |
| Consistent | Produces consistent conclusions. | Quality Assurance |
| Timely (Current) | Relates to the relevant audit period. | ISA, ISO |
| Accurate | Correct and free from material error. | COSO, ISO |
| Traceable | Can be linked to its original source. | ISO 27001, Digital Forensics |
| Corroborated | Supported by multiple independent sources. | Audit Methodology |
Hierarchy of Audit Evidence Attributes
- Sufficient (Quantity of Evidence)
-
Appropriate (Overall Quality)
- Relevant
- Reliable
-
Competent (Credibility)
- Authentic
- Verifiable
- Objective
- Accurate
Comprehensive Statement for Access Control
Audit evidence supporting Access Control (Key Control Evaluation) should be sufficient, appropriate, competent, relevant, reliable, authentic, verifiable, objective, complete, timely, and corroborated to provide a sound basis for evaluating the effectiveness of Segregation of Duties (SoD) controls.
Practical "10-C" Audit Evidence Framework
- Sufficient
- Appropriate
- Competent
- Complete
- Consistent
- Credible
- Current (Timely)
- Corroborated
- Correct (Accurate)
- Confirmable (Verifiable)
Key Takeaway
Modern auditing standards primarily emphasize Sufficient and Appropriate audit evidence. The concept of Competent remains widely recognized in auditing practice and professional education as an important indicator of evidence credibility. The remaining attributes generally serve as supporting qualities that strengthen or define what makes evidence appropriate and competent.
Comments