modern auditing

Glossary

Audit analytics

Also known as: data analytics in audit, CAATs

Applying queries, statistics and visualisation to full datasets to identify exceptions, patterns and risk — the bridge between sampling and genuinely continuous assurance.

Analytics has been the profession’s stated direction for twenty years, and adoption remains stubbornly shallow. The reason is rarely the analytics themselves; it is access and durability. Most analytics work is performed by one or two specialists, against data extracted manually, in scripts that live on a laptop and are rebuilt each year.

That model produces impressive one-off results and no compounding capability. The test of whether a function has a genuine analytics practice is not whether it can produce an analysis, but whether last year’s analysis ran again this year without being rewritten.

Two things change that. The first is direct, durable access to the source system, so the extraction step stops being a project. The second is treating each analysis as a versioned, owned artifact with change control — the same discipline applied to any other control-relevant code, and a requirement at level 4 of the maturity model.

Agents shift the balance again, by removing the specialist bottleneck for routine work. What they do not remove is the need for someone to decide what the exceptions mean, which remains the scarce skill.


Related


Part of the Modern Auditing glossary. See also the maturity model and theartifact library.