modern auditing

Glossary

IPE

Also known as: information produced by the entity, IPE testing

Reports and data generated by the organisation being audited, which must be tested for completeness and accuracy before they can be relied on as evidence.

If a control operates on a report, and the report is wrong, the control is worthless — however diligently it was performed. IPE testing is the discipline of establishing that reports used as evidence are complete and accurate: where the data came from, whether the parameters captured everything in scope, and whether anything was altered between extraction and use.

It is the most commonly deficient area in SOX documentation, and the reason is mundane. IPE testing is tedious, it is often performed once and rolled forward for years, and the person performing it frequently does not have access to the source system needed to do it properly — so they test the report against itself.

Direct system access changes the economics completely. When the auditor pulls the population from the source, the report is the extraction, and completeness and accuracy are properties of a query rather than assertions about a spreadsheet somebody emailed. This is one of the clearest cases where modernisation is not about doing existing work faster but about removing a class of work that only existed because of an access limitation.


Related


Part of the Modern Auditing glossary. See also the maturity model and theartifact library.