10

Click here to load reader

COUNTRY PAPER IT AUDIT: ISSUES, LESSONS …intosaiitaudit.org/WGITA23rd/23rdWGITAMeeting/MALAYSIA COUNTRY... · IT Audit is carried out by the IT Audit Division which ... Computer

  • Upload
    lamcong

  • View
    212

  • Download
    0

Embed Size (px)

Citation preview

Page 1: COUNTRY PAPER IT AUDIT: ISSUES, LESSONS …intosaiitaudit.org/WGITA23rd/23rdWGITAMeeting/MALAYSIA COUNTRY... · IT Audit is carried out by the IT Audit Division which ... Computer

COUNTRY PAPER

“IT AUDIT: ISSUES, LESSONS LEARNT AND ACTIONS FOR A SUCCESSFUL IT SYSTEM IMPLEMENTATION”

PRESENTED BY CAROLINA MUYANG LILENG SAI OF MALAYSIA

Page 2: COUNTRY PAPER IT AUDIT: ISSUES, LESSONS …intosaiitaudit.org/WGITA23rd/23rdWGITAMeeting/MALAYSIA COUNTRY... · IT Audit is carried out by the IT Audit Division which ... Computer

INTRODUCTION

This paper aims to share an overview of technology

development in the Malaysian Public Service, the National

Audit Department of Malaysia’s (NADM) experiences in IT

audit by highlighting some of the audit issues and lessons

learnt as well as actions for a successful implementation of IT

system.

Page 3: COUNTRY PAPER IT AUDIT: ISSUES, LESSONS …intosaiitaudit.org/WGITA23rd/23rdWGITAMeeting/MALAYSIA COUNTRY... · IT Audit is carried out by the IT Audit Division which ... Computer

ICT DEVELOPMENT IN MALAYSIAN PUBLIC SERVICE

The Government of Malaysia recognised that ICT is a strategic enabler in improving the Government delivery system founded on the Concept of 1Malaysia: People First, Performance Now.”;

10th Malaysia Plan emphasises on leveraging ICT to increase productivity, minimise redundancies and improve efficiency;

The Malaysian Public Sector ICT Strategic Plan (2011 -2015) provides the blueprint to accelerate the innovative utilisation and development of ICT in the public sector;

11th Malaysia (2016 – 2020) to ensure that its citizens and economy keep pace with the digital global economy;

Government increased the allocation for ICT development from RM2.8 billion to RM5.17 billion. To date, more than 500 major systems have been developed and used in various ministries, departments and agencies at the federal government level to improve public service delivery;

Despites being able to bring remarkably changed to the manner in which the Government operates, nevertheless new technology brings new organisational risks and thus ultimately bring new financial risks.

Page 4: COUNTRY PAPER IT AUDIT: ISSUES, LESSONS …intosaiitaudit.org/WGITA23rd/23rdWGITAMeeting/MALAYSIA COUNTRY... · IT Audit is carried out by the IT Audit Division which ... Computer

OVERVIEW OF IT AUDITS CONDUCTED BY NADM

Technology adoption project in NADM commenced as early as 1980’s where the technology enabled audit method begun with the purchase of audit software, ACL;

CAATTs was initially used in doing the interim audit;

Initially, data were downloaded from Accountant General Office using round tape, then cartridge platform was used to download data. Nowadays, with remarkable progress in IT and sophisticated communication infrastructure, data are downloaded from the client office using the Infra Network.

IT Audit is carried out by the IT Audit Division which conducts monthly analysis of financial data from 23 branches and had successfully verified transactions worth RM475 billion for Financial Year 2012 and RM488.2 billion for Financial Year 2013 through concurrent audit processes;

In performing the attestation audits, Computer Assisted Audit Techniques & Tools (CAATTs) approach is used for data analytics using ACL.

NADM reviewed various major ICT projects implemented by the public agencies. Concurrent audits during development as well as the pre and post implementation phases are carried out.

Page 5: COUNTRY PAPER IT AUDIT: ISSUES, LESSONS …intosaiitaudit.org/WGITA23rd/23rdWGITAMeeting/MALAYSIA COUNTRY... · IT Audit is carried out by the IT Audit Division which ... Computer

IT AUDIT ISSUES AND LESSONS LEARNT

Underutilisation of IT System;

Conflict in managing the ICT systems among the public sector and system developer;

ICT outsourcing issues;

Personnel competency, expertise and responsibilities;

Effectiveness of information system’s performance ; and

Management gaps of ICT projects.

Page 6: COUNTRY PAPER IT AUDIT: ISSUES, LESSONS …intosaiitaudit.org/WGITA23rd/23rdWGITAMeeting/MALAYSIA COUNTRY... · IT Audit is carried out by the IT Audit Division which ... Computer

ACTIONS FOR A SUCCESSFUL IT SYSTEM IMPLEMENTION

Broaden the scope of work of the R & D Division to

address business risk;

To overcome the weaknesses in the IT system, R&D

team should conduct studies on various area of IT

Established talent pools capability to reduce gaps

between the staff in public sector and system

developer;

R&D staff should be part of the team to provide

guidelines and system resilient for future

development;

Page 7: COUNTRY PAPER IT AUDIT: ISSUES, LESSONS …intosaiitaudit.org/WGITA23rd/23rdWGITAMeeting/MALAYSIA COUNTRY... · IT Audit is carried out by the IT Audit Division which ... Computer

ACTIONS FOR A SUCCESSFUL IT SYSTEM IMPLEMENTION

R&D partnership with several experts such as environmental

modelling, system analyst, programmer, accountants,

auditors, statistician, and software engineer can help develop

a more advanced and reliable system application or tool;

The driving force for change is to change people’s attitudes

and behaviours – could be done through coordination,

communication, participation and performance assessment;

Develop users’ application skills and expertise to removed

barriers to performance e.g.. practices and hand holding,

systematic training program for knowledge enhancement and

advancement and experience sharing.

Page 8: COUNTRY PAPER IT AUDIT: ISSUES, LESSONS …intosaiitaudit.org/WGITA23rd/23rdWGITAMeeting/MALAYSIA COUNTRY... · IT Audit is carried out by the IT Audit Division which ... Computer

CONCLUSIONS

IT failures will have a significant impact on the organisation’s survival and success therefore there is a need to analyse the business functions supported by information systems.

IT auditing being an integral part of the audit function gives assurance that the IT systems are adequately managed, protected, utilised, and provide reliable information as well value for money.

IT auditing reduces the risk of data tampering, data loss or leakage, service disruption and poor management of IT systems.

The audit findings show significant weaknesses in the project management, implementation and monitoring which affected the performance and utilisation of the systems and thus is the quality service rendered.

Page 9: COUNTRY PAPER IT AUDIT: ISSUES, LESSONS …intosaiitaudit.org/WGITA23rd/23rdWGITAMeeting/MALAYSIA COUNTRY... · IT Audit is carried out by the IT Audit Division which ... Computer

CONCLUSIONS

Common weaknesses in the IT projects among others are system underutilisation in terms of functionality, unclear roles and responsibilities; lack of technical expertise and experiences; incompetent staff to manage the system and responsibilities were not properly aligned, ineffective system performance; ineffective quality management; management gaps among the government bodies, and lack of optimisation of ICT resources.

The bottom line is “IT audit requires specialised knowledge and practicable ability to keep pace with current technological development”.

Page 10: COUNTRY PAPER IT AUDIT: ISSUES, LESSONS …intosaiitaudit.org/WGITA23rd/23rdWGITAMeeting/MALAYSIA COUNTRY... · IT Audit is carried out by the IT Audit Division which ... Computer

THANK YOU TERIMA KASIH

Carolina Muyang Lileng Email: [email protected]

Telephone Contact: +60388899035/+60163813165