A proactive and risk-based audit approach will be involved in the Systems
Development Life Cycle (SDLC) of a new application system. The critical
phase of the SDLC is the user requirements phase. This is where each
user defines his/her detailed requirements. A finance group might define
reconciliation routines, payment order processing or exception reports,
to name a few. Other departments and users will do the same. As
requirements are finalized, the system is configured or further developed
to accommodate all of the requirements. It is within the SDLC process
that auditors need to establish themselves as an end user – not only as an
oversight function that is at the table to partner and help manage risk.