1 Plan 1.1 Prepare Audit Plan
• Confirm detailed scope of work and audit objectives (processes, systems, organizational units, product class)
• Identify key contact persons and design interview schedule
• Agree on timing of audit procedures
• Agree on risk prioritization methodology.
2 Audit 2.1 Conduct Interviews
• Conduct kick-off meeting with stakeholders to brief on audit plan and required support.
• Interview identified key stakeholders to gain overall understanding of existing operations to identify processes for
walkthrough.
2.2 Review documentation
• Inspect relevant documentation of business processes and IT environment, such as process narratives, flowcharts, policies,
procedures, standards, system diagrams to identify key controls.
2.3 Walkthrough
• Perform walkthroughs of business and IT processes to understand existing practice and to determine whether key controls
are implemented and designed effectively.
• Obtain and inspect sample documents used in the process.
2.4 Test Effectiveness of Controls
• Evaluate the operating effectiveness of key controls by performing sample tests of control occurrences.
2.5 Document findings
• Document the factual findings and circulate them to responsible owners for review and confirmation.
• Conduct closing meeting with responsible owners to conclude on findings.
3 Report 3.1 Prepare Audit Report
• Draft audit report and circulate to owners to obtain written management response and action plan
© 2014 KPMG Phoomchai Audit Limited, a Thai limited liability company and a member firm of the KPMG network of independent member firms affiliated with
KPMG International Cooperative (‘KPMG International’), a Swiss entity. All rights reserved. Printed in Thailand.
plan.
3.2 Issue Audit Report
• Submit final report to the target recipients