Information Technology Reference
In-Depth Information
b) Does the implementation of the ERP system form part of the IT strategy which
is aligned to the enterprises business objectives?
The IS auditor will be trying to assess if the enterprise's IT strategy is aligned to business
objectives. The enterprise might not achieve its business objectives if the two are not
aligned and each one would be pulling in a different direction. The ERP system implemen-
ted by an enterprise should directly reflect how the enterprise wants to achieve its goals.
The evidence can be collected by reviewing IT and business strategies and objectives of the
ERP system which has been implemented. The IS auditor can also interview senior man-
agement to validate information found in IT and business strategy documents. Observing
how the system is being used in the enterprise would provide further information on wheth-
er the ERP system is helping the enterprise achieve its objectives.
c) How does the enterprise ensure that application systems enhance the efficiency
of the business operations?
Application systems are used to automate business processes so that delivery of services
is enhanced. Automated business processes enable faster, effective, and efficient provision
of services to customers. There is also lower operating costs and higher quality of service
when business processes are automated. Enterprises can ensure that efficiency is introduced
in the business by implementing IT systems. It is important that application systems ad-
dress the requirements of the business if efficiency and effectiveness is to be accomplished.
Evidence on the enhanced efficiency of an enterprise can be obtained by interviewing seni-
or management and finding out their views on business performance after introducing the
systems. IS auditors can obtain evidence by reviewing historical data on performance relat-
ing to costs, service delivery, and utilization of human resources. Return on IT investments
can be another way of assessing automation of business processes.
d) Does the enterprise have an application systems maintenance plan?
An enterprise should have a maintenance plan in place which will be used to ensure that
application systems are updated according to the agreed plan with the vendor. Patches to
the software in use should be done timely so that security issues are addressed as they are
identified. Maintenance also includes fine-tuning the system to meet increased capacity de-
mand by the enterprise. For example the system might need more hard disk capacity to
handle increased data needs or upgrading the processing unit so that the system is able to
handle more complex processing requirements.
The IS auditor can request for a written system maintenance plan which was approved by
management. The IS auditor may also seek more information on the performance of the
plan by reviewing what has been implemented and what is outstanding. Usually the IT de-
partment would have documents which have been signed off showing maintenance works
Search WWH ::




Custom Search