Cyber risk is defined as the combination of digital assets, threats, weak controls, and business impact, where digital assets include IT systems, financial data, customer information, vendor master data, passwords, intellectual property, ERP systems, and operational systems. The three-stage framework for understanding cyber risk involves: (1) Assessing the cyber risk by identifying potential attacks like malware, phishing, and denial of service; (2) Impact analysis to understand potential losses including regulatory costs, business interruption, data loss, reputational damage, and going concern issues; (3) Managing the cyber risk through a five-component security framework: Identify (periodic risk assessments, asset inventory, classification), Protect (training, access controls, password policies), Detect (monitoring systems, intrusion detection), Respond (incident response procedures), and Recover (disaster recovery plans, business continuity plans). Auditors must evaluate these components to understand how management manages cyber risk, and when evaluating controls around vendor management, they should assess who is responsible, how requests are authenticated, and how transactions are initiated, authorized, recorded, and processed.
Deep Dive
Prerequisite Knowledge
- No data available.
Where to go next
- No data available.
Deep Dive
Final Paper 3: AAA&PE | Topic: Ch12: Digital Auditing and Assurance | Session 2 | 22 July 2026
Added:So today we are going to continue our discussion on chapter number 12. Okay.
In previous session what we have done is we have understood about uh auditing digitally and digital audit. What we understood? we understood that what is digital audit and what is auditing uh digitally. So with respect to the digital audit, we understood the information systems like how uh how you can you know proceed toward the digital audit. You need to identify the system understanding the information system.
You need to uh list down the entire process flow. Okay. We went through the essay 315. Then we uh went through about the identifying and assessing the risk of material misstatement. The type of risk that can arise in the system. Over there we understood two type of one risk arising from the use of IT systems and second was cyber. Cyber is uh we have to discuss but we again discuss in detail the risk arising from the youth of IoT systems.
Then step three we identified and we understood that okay in order to identify the risk we also need to identify the IT dependencies and we need to associate and evaluate the risk associated with the IT dependencies. So you need to identify the risk which are also associated with the IoT dependencies. That was a step number four. So this is how we uh reached to a particular point where we understood okay what we need to do in order to get a good digital audit. Okay, I hope you guys have gone through the study material because now we are going to discuss very important part which is cyber risk and again with respect to you know this the way we did in the last session in the end 15 minutes I will be sharing the ID which you can use to login. Okay. Uh in the meeting and then you can ask your doubt. Till that you can list down all your doubts and when in the last 15 minutes when I will share the meeting ID use that meeting ID join the session and ask your doubts. Okay.
So in the end 15 minutes you will get a chance to ask your doubts. Okay.
Whatever doubts are there and no matter how many doubts are there even if you have asked in the previous session also you can ask it again. So do not hesitate in asking uh you know the doubts.
Okay. Now let's proceed to a one very important topic that is the cyber risk.
Very important very critical from today's uh time frame cyber risk and cyber security. Now cyber risk and cyber security is talk of the you know town and every regulator in India. Every regulator in India is focusing on the cyber security. Every regulator like RBI, SEBI, insurance regulator, RIBA, everyone has came up with a cyber security framework for the regulated entities. Okay. And even for the IT entities again there is there are IT uh you know who are dealing into the data.
Now you have a various you know privacy laws in India like the DPDP act and a lot of things are there with respect to the privacy. So now with respect to those uh laws and the regulations which are being you know uh enacted in India with respect to the cyber security. It has become very critical for the auditors to understand what is cyber risk and how the entity is managing the you know cyber security uh with respect to their systems with respect to their digital asset. See in simple words if I talk about cyber risk it's a very simple formula I will explain you in a terms of a formula cyber risk is equal to your digital asset which can be IT systems okay your digital asset Unless there is a risk of something can go wrong or kind of a threat which is there with respect to that digital asset.
Plus you have a weak controls which increase the chances of that risk to get materialized or rather than risk I will use the word which is appropriate is threat because once threat materializes it converts into a risk.
Okay. And this is not uh you know this will become very important when there is a business impact due to your threat and weak internal controls.
[clears throat] So cyber risk is a digital asset threat weak controls and the business impact and why we are learning cyber risk why we are understanding cyber risk because of this part.
Understand this is very important business impact.
This business impact is nothing but the impact on the financial statement also.
So later on when the cyber incident will happen when the threat will materialize when the risk will materialize at that point in time this business impact will translate into your financial statement impact.
Okay. So this business impact will become your financial statement impact.
Now as a result we need to understand is there any financial statement impact because this will again turn into your uh accounting related disclosures or audit related disclosures everything. So this will require audit consideration.
Okay. audit planning everything you need to put behind because if there is a financial statement impact and you need to assess that kind of risk that's where the cyber risk becomes very important to understand okay now what is cyber risk we need to understand that what is cyber risk okay cyber risk is a risk of technology okay that means when a technology is used in an incorrect way or there is a impact to the technology and because of that there is a impact to the business. For example, maybe the systems are not available, there's a deletion of the data, alteration, destruction of the data, systems are misused, you know, there's a financial losses because of that. So, whatever issue with the financial system causing loss to the business is nothing but a cyber business.
Now when I talk about digital assets, digital asset is not only the IT systems. Remember that most of the uh you know students have an opinion that okay cyber risk is related only to the IT systems. No cyber risk impact can be there on your financial data on the customer information vendor master data passwords intellectual property ERP and IT systems operational systems a lot of things are there where the cyber risk can be there. So the misconception is cyber risk is only restricted to the IT systems. No cyber risk can be associated with each and every element of the IT system rather financial data which is sitting inside the system, customer information which is sitting inside the system, vendor master data which is sitting inside the system and you need to assess cyber risk at the individual level because there can be a scenario that you know different different systems are involved for all these different data.
Okay.
Now when I talk about cyber risk, what can happen like let's understand with the help of example what can happen with the cyber risk like what problems can be there.
Okay.
What cyber risk and the problems can be there. Now you might have already heard about something called uh malware viruses okay ransomware I'll show you something similar okay I I will show you a particular ransomware rather that what ransomware does and you know how it works and what happens when there's a ransom uh ransomware attack and why they are important basically Okay. [clears throat] Now when I talk about ransomware, okay, uh what basically happens is that that the ransomware virus or some you can say the attack which happens it actually you know uh stops your entire system. It actually what it does is you know it encrypts your entire system and it asks a ransom.
So ransomware is kind of a virus which you know which uh which when happens what it does is it encrypts or it locks your entire system.
Sorry it locks your entire system and as a result you are not able to do anything in your system.
I'll just show you one image of the ransomware.
Okay, this is one of the image a reference image you can say of ransomware attack.
Okay. Now what happens is whenever this kind of attack happens your entire system is logged. Okay. This image will come on your screen. This is just one of the ransomware attack which was one acquire ransomware very you know very prominent one because the impact behind this ransomware if I talk about okay there were almost uh two lakh 30,000 computers which got affected with this particular uh ransomware attack in 150 countries. Okay. and a highprofile uh companies got you know uh like impacted with this. A lot of government data, a lot of private data was leaked and encrypted and destroyed because of this attack. It was a very big attack. You can go and search but it was one of the biggest ransomware attack uh which costed almost in billions if I'm not wrong.
billions of dollars loss uh behind this.
Okay.
So what happens is when this kind of risk uh there is a weak control let's say weak security. Now if there is a weak security there is a thread already ransomware attack. Okay. And uh when this kind of things happen entire PC is logged you need to pay them the ransom.
See here they are asking you to send the bitcoins on this particular address so that they can decrypt that means they can allow your computer to use otherwise what will happen is they will destroy entire thing whatever data is there in your PC when the timer stops this time is left your files will be lost on this thing okay so on this particular time like 6 days 23 hours entire PC will be wiped out and everything will be destroyed. So see the financial datas everything a huge impact can happen because of one ransomware attack and if I'm not wrong it was $4 million US that impacted in this particular one ransomware attack $4 million US sorry4 billion US okay the financial impact that we are talking about and multiple companies across cross the world they lost their financial data.
Now this is one such example. In your study material there [clears throat] are multiple examples given one and they are divided into categories. Okay. The first category is a malware.
It's very easy. Now I'll explain you one by one all these categories so that you know you can understand what happens when I use when I say the term malware.
Okay. It is it is a combination of two term two things which is mal plus uh where like from the software okay why which is from the malified intention this software is prepared for the malified intentions okay so uh when I talk about this malified intention software that is malware basically and because of which it can harm uh yours systems. That is where from malified softwares the term malware came into the picture. And malware can be of ransomware. Just now I show you uh want to cry. You can see as an example want to cry ransomware. Okay. There are fileless malwares also. Fileless means most of the malwares uh are kind of you know attached to a particular file.
That means they need some file to uh come into your computer like for example.exe files or some you know images, PDF files sometimes some they need some file to get started or get transferred in your computer. But fileless mar malares are not like this.
They basically uh you know look for some functionality in your PC for example something with respect to some broken functionality something different okay they are kind of you know uh they don't need any file to come to in your computer they like for example if you go and click on a particular website where it is downloading something it is file it is file malware but let's say for example if you're going on a website and if you are running something over there rather than the downloading you are running application over there and because of that uh you know the computer will take certain files onto into its memory over there along with that the malware goes the computer into the computer memory and it becomes a fileless malware okay so it's without file without exe file or uh you can say without any backup file it directly goes into the RAM of the computer.
Then torren uh torjen is kind of uh a malware basically okay a virus you can say which is hidden behind uh you know a particular safe program or behind uh a good program. So it's it is disguised.
Okay. So it it is not appearing in your computer like you know like a virus file but rather it will appear like okay it's a good file it's a good software and in that it is hidden. So the term torsion is for the hidden okay it's hidden behind some files and then when you operate that software it comes out of that particular hidden box you can say mobile marvel is for the mobile like Android and iOS okay now that is the type of malar we are talking about so to fileless ransomware okay these basically have some specific kind of functioning based on their type. Okay, how they work and how they actually impact your system. The second category is a denial of service DOS attacks.
DOS attacks are very interesting to understand denial of service. Let's say if I go ww.google.com, google.com it will open the website okay it will open the website now why it is opening the website what's happening in the back end I'll just show you and explain how the do works see there is a server and there is a your computer okay and this is basically the internet as of What happens when you access Google?
Your computer sends request to the internet. Internet goes to the server.
Server send backs the data and the internet gives you that data and shows the Google.
Now let's assume like this way in the similar fashion. Okay. I create multiple you know devices. I am the uh let's say you know person with a malified intention. I create multiple devices.
Now these are let's say computers or devices.
Now generally a server has a capacity.
Capacity as in how much you know request it can provide. Let's say this server has the capacity of 10 people catering 10 people at a time or 10 devices.
In today's time it is very large and the attacks happens as very large. So let's say here I have a 10 15 devices they are in thousands. Okay these devices are created in thousands for that and the limits are very high up. So what happens is let's say the server has a capacity of answering 10 people at a time or 10 devices at a time. I will use 15 to 20 devices. All the 15 to 20 devices will together will send the request to the internet. Give me Google. Internet will all send all the request to the server and server will get confused like like I have to provide I can provide 10 requests. I got 20 requests. So what it will do is it will serve first 10 requests and provide the data. Then another 10 requests and provide that data. And if let's say this works continuously. Okay, this round works continuously. That means rest of the people on the internet will not be able to access Google because this server is busy catering these people. They are out of their limit and the basically server is catering them and your computer if you will access so it will go to the internet it will go to the server server will reject it because it doesn't have the capacity. It is already dealing with a lot of people. This entire scenario, this entire working okay is known as a do denial of service attack. I create so many devices that the moment they request it goes to the internet the server sends back and this okay it creates an overload on the server kind of thing because of which the correct request are not being able to processed they stop it at the internet level only and they are you know server doesn't cater those request that's a denial of service [snorts] okay And there is one new term in this particular part. Okay. Do was is there and it's always there. Do has evolved because now with the cyber security and you know multiple IT systems DOS has become DDOS that is distributed denial of service.
This is kind of where we use multiple systems almost hacked thousand 10,000 computers those are known as a botn nets okay to launch coordinated effect uh uh you know attack simultaneously now distributed denial of service means in d in do okay in do all these botn nets are sitting at one place. So this botnet are sitting at one place and in DDoS these malwares that we were talking about fileless toen and everything behind the scene they send these requests your computer becomes a botnet. So that's the DDOS a higher version of that fishing.
Fishing is kind of uh a attack you can say or a exploit basically wherein uh you know the person who is trying to do something wrong is will you know will present himself like okay he's a genuine person or he's a you know kind of will try to exploit uh identity of someone [clears throat] that is fishing that you know uh basically a deceptive attack I would say this they will try to impersonate someone in this.
So they will try to show that okay we are the genuine person we are the uh you know one person but they are actually the scammers. So this is impersonating someone.
Now basically what happens in fishing is okay there are multiple type of fishing because someone can you know do uh someone can impersonate a lot of ways for example spear fishing that is a targeted spear means targeted. So targeted they will target certain people on the internet. Okay. Okay. I will send him a message that I am a trustworthy bank and you your password is about to expire.
Please reset your password. That is targeted. Whailing is kind of basically at large scale.
So at large scale they will try to you know send a lot of things irrespective of the you know the person uses that bank or not. Let's say for example I use a XY Z bank. So if they send to me it's a spear patient. If they send me a email that okay your XY Z bank password has been expired please log on to this link and reset the password okay by entering old password and credentials that's fishing the moment I will enter my old password it will go to hackers and they will you know scam meing is kind of irrespective whether the person has uh whether the person has a bank account with XY Z bank or not they send at a mass scale so let's say for example they will think okay no no let's do at the mass of mass scale so that you know uh what will happen is we will get some people and here the best part is it is targeted to CEOs and CFOs why because these are very big whales in the uh like if let's say for example if I can scam a CEO or CFO it's a very big whale I'll get a very big amount of you know money from them by scamming is scamming them so at a large scale CEO, CFOs are you know high-profile people are involved in whailing. you need they try to catch a big whale kind of that's a veiling okay smishing is kind of uh you can say this kind of uh you know impersonating carried through SMS okay this is something you know kind of scam carried through SMS and this is scam carried through voice calls you know they will call you and they will try to do something and they will say that okay enter this pin or whatever. So that's wishing.
Now spoofing is kind of you know uh basically again this is also kind of similar scenario where they will try to impersonate uh someone on the internet but it is with respect to the websites or uh with respect to the email. Okay.
When I say domain spoofing, what happens in the domain spoofing is uh you know they will try to mimic a legitimate website.
They will try to mimic like for example I'll just show you one example.
Domain spoofing is kind of instead of Google G O G L E what they will do is they will create a website with G O L E.com let's say when you do a spell mistake by forgetting a G in between in hurry you will go to gouble.com and that is a de when you open it it will appear same like Google but in actual it's a fake website.
Similarly for one of the website an uh sometimes what they do is they write in a particular font that it appears similar. So a r n okay z o n.com a normal person in a normal you know font it may appear rn separately but it sounds similar to am zo n am a z o n.com Amazon okay so they will try to replicate in certain way that okay it's similar to one of the website or kind of thing as like you know that's a domain scooping Email is also the same.
Email spoofing is kind of uh they will try to create emails which look similar to your own emails or the known emails.
Okay. So creating like emails like this that's a spoofing.
Insider threat means someone in the inside the company is trying to create uh you know threat for the IT system.
That's the inside threat.
DNLS uh DNS tunneling.
This is very interesting part. Okay.
Type of cyber attack.
What happens here is now what is DNS? It's a basically kind of you can say uh gates in a simple term. These are the gates through which the data flows.
Okay. If I go back over here, this is internet. Okay, the data will flow through this internet.
This is pretty much simple. The data will flow to the internet and will go to the server. Now in DNS tunneling, what happens is that instead of this internet, there is a private server.
Okay, private server of the scammer.
So your computer by you know they trick your computer to send the data to the private server of the scammer and from there it goes to the Google and then when Google send backs the data let's say it's a bank okay so bank will send the data with all the details it may include your credentials or when you try to log to the bank portal you send to the private server of the scammer that okay this is my data please allow me to log to the So they will create a copy of the data and they will you know go to the bank will provide them bank will provide the data and they will show you the data fine. You will never come to know that your data has been compromised.
So these kind of DNS tunneling happens and IoT beta uh uh attacks. IoT is kind of you know internet of thing devices small small devices that you have at your home which can be connected through Wi-Fi. Now they are pre-programmed sometimes and the moment they you connect them to your Wi-Fi they enter into the system and they create uh you know they try to do all the rest of the things like torion malwares and everything. So that's the IoT based attacks.
Okay. So every explanation that we understood right now it's there over here which is mentioned. Okay. Now why it is important to understand all these things because every risk every cyber risk has some stages.
Now what are stages of the cyber risk?
When I talk about stages of the cyber risk, basically cyber risk stages explains how an organization okay looks to the cyber risk, thinks about the cyber risk.
So when I talk about stages of cyber risk, that is where the organization or the auditor should look this is how the cyber risk works. This is how the cyber risk moves or this is the life cycle of the cyber risk. So the three stages explain is how an organization should think about the cyber risk.
Okay, it's cyber if you want to understand the cyber risk you need to understand the cyber risk in stages.
You cannot understand the cyber risk uh you know just in a one go. Why? Reason because these are very crucial risk number one. Number two, these are very complicated and they can have a varied impact.
That's where to understand the cyber risk, we have to divide them in the in the stages.
So for the cyber risk to understand divide them into the stages to understand the cyber risk.
Divide them into stages.
Okay. And how and which are the stages?
So to understand the cyber risk, you need to aim for it. Remember that to understand the cyber risk, you need to aim for it.
[snorts] A I M you need to aim for it. That is you need to assess the cyber risk first.
You need to calculate the impact of the cyber risk and then you need to manage it.
You need to aim for the cyber risk. Then only you will be able to understand the cyber risk.
Okay? Assessing the cyber risk, impact analysis of the cyber risk and then managing the cyber risk. If you can do that, then only you will be able to understand what is a cyber risk.
Okay. Now let's understand uh basically what is assessing a cyber risk.
Now when I talk about assessing a cyber risk in case of our techn uh in in I'll go back to our you know case study that were we were uh uh discussing quick card.
Now in case of a quick card this was a entire system flow that we had. Okay, this is the entire system flow we had.
Now if I have to assess a particular cyber risk over here, what cyber risk can be?
What cyber risk can be here?
Anyone? You think and write it down about the cyber risk.
I will show you a example of the cyber incident. Okay? And then what you need to do is you need to tell me few questions. You need to write down few questions and we will discuss further on that.
So on 12th February 2026 let's say the accounts payable manager received an email that appeared to come from a longstanding electronics vendor because cyber uh because quick cardart is a e-commerce they purchase inventory. So they got a email from the long-standing vendor. email requested an urgent change in the bank account details. The manager forwarded the request to the master data executive who updated the vendor master without an independent call back.
Payments aggregated uh of 2.8 crores were subsequently remitted to the fraudulent account. The actual vendor continues to demand payment. So there is a scam which has happened of 2.8 8 cr because of the wrong updation of the bank account and why this happened because there was a email that appear to come from a long-standing electronics vendor.
Now what kind of this attack is?
What kind of this attack? First of all ex identify the nature of cyber attack.
Identify the nature of cyber attack over here. Which kind of cyber attack was this scenario?
I would say this is something similar.
Remember we have seen something called uh spoofing, email spoofing. It's a type of cyber attack that targets the business by using email with the fraud for sender addresses. Okay. So they trust the alleged sender and they are more likely to open the email or you know do that what is written email spoofing or it's kind of you can say uh spear fishing also. So they will send target specific individuals uh malicious email. If you'll try to do that whatever written in the email it can impact your you know uh systems.
So something similar of that has happened in this scenario. So either it's a spear fishing.
Okay. Or basically if not spear fishing uh it can be kind of basically spoofing.
Any one of the two is there.
Sorry.
Okay. or spoofing if they use the same domain then spoofing can also be there.
Now if there is a spear fishing or spoofing that is happen the that's a cyber risk which got materialized. Why that it got materialized? Because of this particular part, vendor master update updated the vendor master without independent uh you know call back. This is known as a weak control.
What is this weak control?
And there we have a business impact.
So there was a risk or threat that threat got uh together with a weak control and because of that there is a business impact cyber risk.
Now when I talk about stages of cyber risk that you need to assess what I meant by that is you need to first understand okay what can happen in that particular area.
What can go wrong in that particular area? What is the problem in that particular area?
That is something the first step of understanding a cyber risk a first stage that you need to assess that cyber risk.
Okay.
So what attacks can happen type of attacks?
So you need to identify out of this given type okay this given list what can happen. Identify, assess the cyber risk.
First of all, possibility of fishing, possibility of vendor impersonating, possibility of torion, malware, what can happen out of this? That's the first thing assessing.
Second, second stage of the cyber risk is the impact itself. You need to understand the impact of the cyber risk.
If anything happens then what will uh be the loss in that scenario as of now I'm trying to understand each and every cyber risk that has to be done with each and every cyber risk so in assessing I will see the type here in impact I will see the cost if that happens okay and in third manage means what controls are there for that is there any controls which can you prevent that [clears throat] from happening.
If I aim for it, then only I will able to understand the level of the cyber risk. The extent of the cyber risk.
Simple example I will show you. Let's say I will explain you with the help of metrics.
So this is risk.
This is uh impact.
And these are the controls.
Okay. Now let's say risk is for me there is a risk of cyber risk of let's say malware.
If there is a malware attack then what impact it can be? I need to assess the impact also. Now impact can be regulatory cost. Impact can be various type of cost involved. Financial losses, goodwill losses. Okay, let's say quick card. If quickart tomorrow there is a malware attack and you know the systems are hacked, it's a ransomware attack, my entire business is closed, app is not working. What will happen? Regulatory cost is one thing but business interruption my entire business will go down.
data loss. All the order which are placed the order which were not delivered but placed or you know uh a lot of customer related information credit card related information a lot of thing can be at cost data loss reputation loss okay litigations and it may they may you know take or try to take the IP the the coding of the application or the how the application works intellectual property Okay, they can delete that, they can take away that breach of privacy, fines, penalties, a lot of things can you know occur in that if there's a malware impact, okay, or there is a ransomware to be precise in that what impacts it can be business interruptions. my business can you know uh stop entirely and if it is prolonged it is it is happening for a very long time it can be a issue of a going concern going concern issue also then they can delete the data data that will be loss of data litigations because a lot of customers who have placed the order they you know in between their order will be lost. There will be no trace of who placed the order, what happened litigations. Okay.
Because of that regulatory cost, privacy concerns, why data, the customer private data that okay, credit card data, financial information may get leaked.
Reputational loss, everyone will think twice before ordering ordering from that particular app. then fines and penalties.
Okay. So all these things can happen because of one malware risk or ransomware and what controls we have in place, what procedures we have.
So you may say okay we have backups, we have uh security systems, we have firewalls.
Okay. So you may you know list down some of these systems. Okay. What can help me if these things happen?
what I have unders like you know how my team is ready to face this particular part.
So this is something you need to do as a auditor to understand the cyber risk. So this exercise what we have done right now identifying the controls identifying the impact and the risk this entire metrics okay cyber risk okay impact assessment will help you to understand the cyber risk Okay, not only backups and controls but here we will also see that how much team is trained like management basically when I say team or management is trained to tackle these scenarios okay do they have SOPs for such disasters like it's a you know uh for such scenarios those. So sometimes they have SOP for let's say disaster uh recovery program, business recovery program. Okay. So like BRP and disaster recovery programs are there, business recovery programs and uh disaster management programs. So these are certain uh kind of uh you know basically programs or SOPs that tells what to do what not to do in these particular scenarios.
So uh disaster management systems and uh business recovery programs all these things are created in order to you know facilitate the entire businesses to basically uh uh basically you know navigate through the entire this scenarios. Okay. business recovery programs or disaster management programs kind of things are there.
So through this way you will be able to understand the cyber risk. Now this is something understanding the cyber risk.
Okay. Assess impact and manage. This is how I will understand the cyber risk.
This is just understanding clear with this. This is how I need to understand in your study material if you come. These are the stages of cyber risk. To understand the cyber risk.
So first stage is assessing the cyber risk. In order to understand it, you need to assess it like what can be there. Ransomware can disable their organization. Example quick card app.
Quick cart application. They can disable the quick card application in business.
Common criminals using email fishing.
The example we saw vendor bank account update insider committing malicious activities or uh accidental activities.
Uh there was a one uh example I would say over here sometimes ago like you know like some time ago there was basically a very big wide issue okay in past which actually crashed the entire uh you know Windows environment there was a global outage of a particular company some times ago.
Okay.
So there was a company which used to provide services to a very big you know companies IT companies. Okay. And there was a outage of that and because of that particular outage uh you know a lot of companies had to close down their you can say operations for some time because they were not able to you know kind of proceed ahead and there were some issues going on uh across the industry and this is very recent it is in the start of January this year. I will not name the company as of now but it was a prominent scenario where because of that particular one small issue. So when they were kind of you know uh deploying a software in by [clears throat] mistake they deployed a wrong software and entire thing you know went crashing one by one because of that a lot of companies faced the issue even Windows was failing. There was a network outage causing Windows operating system okay to show blue screens.
So basically it was very big issue.
Okay, very big issue and after that it was immediately fixed also but there was a very big issue uh on two different dates in the month of January and February which because of which there were a lot of outages.
Uh now that is something you know accidental activities they are but they result in such a scenario that you know your entire systems if if if your system is one of the crucial you know dependency for the technologies out there in the market.
If your system is down it can you know create havoc around uh everywhere. So you need to understand what is a cyber risk and sometimes your systems are dependent on other systems also.
Okay, the way I'm talking about the Windows died because of some other system on the internet was not able to work and there was a blue screen across countries okay on the windows.
Why? This is a risk. I'm talking about cyber risk. Real example that has happened. Not because of the windows. It was not Windows fault. It was fault of someone else. Because of which the Windows suffered and because of that then the businesses suffered.
Okay. There was a lot of airline companies who had to halt the flights and they had to you know uh reschedule the flights because they were not able to you know work on their systems on the checking systems and everything.
[snorts] So one such example is there. Okay. So it can be intentional, it can be accidental, both scenarios can be there.
So that is first identifying the cyber risk then impact as we discussed what happens when this kind of cyber risk goes into the place you need to assess the impact you need to identify what impact it can have regulatory cost business interruption best example that we discussed now quick data loss ransomware IP okay breach of privacy fines penalty a lot of things and then you need to understand what enterprise is doing to basically look for this cyber risk.
That means what management uh you know has followed a approach with respect to the cyber risk.
So gaining a holistic approach of understanding the cyber risk basically the IT cyber security program capabilities of the companies. Okay. Uh then what objectives the companies and on a very big scale this the plan what plan company has with respect to these cyber risk then only you will be able to basically understand the cyber risk. Now let's say for example company doesn't have any plan over the ransomware.
So it's a very big risk. You don't have any controls or plan in place if something happens.
Okay. So these are the three stages which are broader and strategic in nature to understand the cyber risk. So you can say they are strategic and broad.
They talk about the risk management journey. How the risk is un required to be understood.
Okay. So how The risk is required to be understood.
Now if I tell if I tell you like in order to understand the fraud risk you have a SA 240 but to understand the cyber risk this model or this approach you can follow similar the way we follow SA 240 to understand the fraud risk red flags everything okay fraud triangle there's a fraud triangle okay fraud diamond there are certain models to understand the uh risk fraud risk similarly this model is there to understand the cyber risk.
Okay. Now the next part after understanding the cyber risk what you will do after understanding the cyber risk there is one more thing we need to understand as I said in the start of the session itself cyber security framework that is something is required to be understood in much more detail.
Cyber security framework is what see cyber risk is for you how you identify the risk. Cyber security framework is kind of putting all these things into operational and SOP part into controls part into business.
Okay.
The fivepart cyber security framework basically provides that okay how you can actually on paper protect yourself from cyber risk.
Once you identify then you go and implement the cyber security framework.
So now if I have identified the cyber risk, if I understood the cyber risk, the next stage is for me understanding cyber security framework because after risk similarly the way you understand in a audit. Okay, this is the risk. These are the processes entirely.
These are the controls. Okay, but there are more than controls that you need to understand. Like now we need to test the controls and for that we need to do walk throughs.
Okay, understanding cyber security framework is kind of that only you are doing the walk through more detailed control oriented operational approach to understand the part.
Okay.
Now whatever stages we have identified now we need to see how operationally they are implemented.
Okay. simple if I put it in a way that stages its operational implementation.
Okay. So if I talk about stage of assessing the cyber risk.
So the operational implementation can be how management identifies this management identification.
when I talk about impact assessing the impact of cyber okay uh risk impact of the cyber risk how management uh kind of you know identify detect and respond from it so you can say I I'm you know matching all these things and it will be kind of scenario that uh I will be matching one component at multiple places. So how management basically identify once after identifying it detects and responds to it and managing the cyber risk is kind of you know not only uh detecting and responding is also management. And just a minute management kind of protecting and recovering from it.
So you can align the operational implementation of the stages is where the you know cyber security framework comes into the picture.
These cyber security framework is the journey is the activities which are performed at the ground after understanding the activities that you perform at the ground are the cyber security framework basically in the cyber security framework the moment I say ident assess the risk it's after assessing whatever you want ground it's the identification okay the two things are not different.
Some people say that okay no stages are different than cyber security framework.
No stages is kind of a plan when you implement on the ground it becomes cyber security framework. So when I say assessing the cyber risk in uh ground it becomes identification of the risk. What management does to identify it? How management identify it?
Here we are talking about type like what type of risk. Okay.
What type can be there? Here we are talking about how to identify.
There's a difference between both. Over there I'm talking about what kind of risk? Which kind of risk? Here the question which is asked is what type?
Which type?
Here the question which is asked how to identify okay how what you do to identify the risk basically like for example periodic risk assessments develop a management strategy which identifies the security cyber security risk failures okay entity should uh basically what they should do they should periodically review their IT systems the way we did for example in our quick chart. This is something you can do to identify what can go wrong for each system by preparing a risk control audit procedure matrix or kind of risk control matrix.
Okay, audit is later on. But let's say for example if I cut off till here this is known as RCM that is the risk control matrix and if I add audit it becomes RCMA okay but usually we call it RCM risk control matrix where I have a risk area I have what can go wrong and the relevant control in front of that.
Okay. So I does management have a RCM in place. What management is doing to identify the risk?
This is where the cyber security framework comes into the picture like I will understand what management is doing.
Okay. Are they maintaining the list of systems the way we have in quickart? We have a list of systems identification of the IT environment.
This is the list of system I have. This is a list of IT dependencies I have.
Okay. So, is management maintaining this kind of list or not? Inventory of IT systems, information systems?
Is management classifying like which is more critical, which is less critical?
Who is responsible in the entire organization to look for all these things? When I say management, the entire board of directors will not run behind this, you know, systems. Okay.
Who is responsible over here for all these preparation of documents? Who will prepare these documents?
Who is responsible for this?
Someone has to document all these things. Who is responsible for that?
In an organization, most of this role is done by either uh CTO or CISO.
CTO, chief technology officer or CISO is a chief information security officer.
Okay. So CTO or CISO are kind of you know uh responsible person in an organization who have to look after for the cyber security. So they have to list down all these things. So that's the first thing identification of the risk and to identify the risk we have to identify the asset. I'm not saying anything else. Whatever we have learned I'm discussing that only okay remember in the digital audit what we did we first identified the system identification identification of the system that's I'm talking about in order to understand and identify the risk first identify the system similarly in the cyber security framework identify the risk like how management what management does to identify the risk. Okay. Are they periodically reviewing the asset management and information systems?
Is there any you know uh overall responsibility for cyber security like CISO, CIO in the business? These are the things they can do to identify the risk.
Okay. Once they identify the risk, the second thing they need to do in the cyber security framework is protection of the uh risk that how they are protecting the system like are they providing the training unauthorized access? What trainings have they provided on the ground? For example, password reset policy that within 90 days the password should be resetted like if password should be you know complex uh combination of alpha numerical characters. What data security trainings are being given on the ground to the employees?
So how the risk is being protected?
Okay. trainings, unauthorized access, password security, safeguarding, what happening, what is happening on the ground.
Then comes the detection part.
Okay, detection is is something like you know protection you you can prevent a risk from happening but not always you know you can there is no 100% safe prevention of the cyber risk. Okay. So there are chances that even after preventing it the cyber risk might have happened and there's a cyber security issue in the in the company.
So you should have these systems in place to identify this uh a cyber security breach detection of the breach.
Okay. Like once now for example in our quick cut case let's say the vendor the vendor which was there who was demanding the payment if he never demands the payment let's say you know there is a routine transaction going on and there's a reconciliation which is happening and every time there is a 2.8 cr of difference in the reconilation vendor is also not worried because he also you know is getting timely payments and the 2.8 8 cr is a small amount and this particular company is also not you know bothered till that time it's not a big issue no one will focus on this that's very small amount so is there any way to detect if the vendor doesn't flag it or if the internal team doesn't identify it how someone will come to know there is fraud going on how someone will detect a fraud till the time there is no mechanism of the detection So detection is the next step in the cyber security framework.
So detect the risk. So for that you should have a control procedures that should identify the cyber security risk.
[clears throat] And they should monitor and detect the breaches and incident kind of a intrusion detection system IDs or firewalls which can you know provide that okay if there is anything happening immediately they will trigger a notification there is a security alert okay they will detect any repetitive attacks.
So these kind of things should be there and then there is a respond once you identified the organization should be aware how to manage respond and recover.
Okay that is the managing part kind of.
So first of all respond is immediate respond like if now the breach has happened what I will take action immediately immediate action I'm talking about okay [clears throat] how nature of the incident what incident happened data breach everything how I will gather the information what is the loss what has happened getting the information Okay. Uh taking a quick step [clears throat] communicating with the right people in the organization. So that is something I will do immediately right now. If there is a ransomware attack in my company let's say tomorrow if I see this image what I will do immediately I will call some people. Okay. What I will do is I will call my team. I will ask them if you are not able to see this message, if your system is secure, shut it off immediately. Okay? So I will identify the safe PCs in my team.
I will check my app. I'm talking about from the quick cuts perspective.
Okay. I will check the app if app is running or not. Okay. I will see. Okay.
is a which systems are online or which systems are offline. Okay, inventory check or check other systems.
I will call the my CTO that this has happened. What to do now?
[clears throat] I will provide the details like what I did this happened after what it got triggered. Okay. So incident report a report will be prepared. How many employees are having this problem? What triggered this problem? Who reported first? Which systems are safe? Which are not safe? What data is at risk? So data risk.
Let's say my system is encrypted or there's a ransomware attack. what was there as a data in my system?
Is there any backup of this data? So immediately what I will do this is the responding part. [clears throat] Once I prepare, once I respond it, then I will be clear how to recover from it.
Okay.
Now I have a information how many PCs what data is at risk uh what data if I don't pay what data I will lose is there any backup of that particular data or not okay uh can we restart our application all these questions you know I will be able to answer once I can respond to the risk once I will have that information so kind of at the end of responding to the risk okay you will have incident report.
This report will help you to understand the impact severity of the attack and this plan basically this plus the plan that you have already prepared okay will help you to recover. So incident report plus plan when you will implement that plan. So this is nothing but implementation of disaster recovery plan.
Okay.
So this is nothing but implementation of my disaster recovery plan DRP or business continuity BCP plan all these things you know into the place. So once I will do that okay I will implement the DRP or business continuity plan that means I will run my uh backups I will you know uh discard uh kind of you know format or I will you know clean my pieces which are infected with the ransomware I will see the impact over the data and I'll try to recover that data. I will bring the cyber security expert to remove that particular virus from my computers. So something I will do and I will try to run the app quickly on alternate servers.
[clears throat] So patch upgrades, better control, improve technologies, antivirus tools, virus, firewalls, everything I will deploy so that my business can come back online.
So my target is up and running. My business, my app should be up and running. This is something I will do.
That's your entire cyber security framework and this is how actually a framework should be there means the document I'm talking about cyber security plan cyber security framework should have all these elements okay so this is cyber security framework once you understand the cyber risk you translate it into a cyber security framework.
Okay. To understand that what will happen when a cyber security risk will get materialized.
So cyber security framework is nothing but a plan on paper implemented kind of operational plan okay to manage the cyber risk. is a more detailed operational framework okay including controls activities functions okay through which cyber risk is managed.
So this is a combination of you can say functions, controls, activities.
Okay.
Through which cyber risk is managed.
That is cyber security framework.
See when we were talking about the managing the cyber risk over here over there we discussed cyber security program existing assess existing IT and cyber security program.
So understanding the risk involves understanding the cyber security program.
Okay. To ma to you know understand the stage three you need to actually understand the cyber security program.
So I will write it here over here to understand stage three.
You need to understand cyber security program and cyber security program. To understand the cyber security program you have to divide it into five components.
Okay, you have to divide it into the five components. I cannot you know say that okay this cyber security program is very good but on what parameters? Divide it into the five components and then on each component rate that program. Yes, this program is good. Yes, this program is good on the identification. This program is good on the protection. This program is good on the detection. This program is good on responding. This program is good on recovering.
You need to assess the cyber security program at the five component stages.
Then only you will say yes the entire cyber security program is good. And once you say that then you go back to the stage three and say that okay now I can say that the cyber risk you know uh the entire management of the cyber risk is good.
So to understand the cyber risk I will assess the cyber risk.
I will do the impact analysis of the cyber risk and I will see how management is managing the cyber risk. In that managing the cyber risk involves managing the cyber security program and to evaluate the cyber security program I will evaluate the cyber security program at the five stages here. This is how the flow works between both.
Okay. So do not confuse the stages of the cyber risk. Stages of the cyber risk is to understand the cyber risk as a broader level.
To understand the cyber risk, you also need to understand the cyber security program. In nutshell, in summary, if I'll tell you.
So [clears throat] this is something my cyber risk. Okay.
Stages of cyber risk or understanding of cyber risk which is divided into three stages.
Okay. So understanding happens on three stages understanding of cyber risk or at three stages and one such stage which is the managing okay now that managing the cyber risk involves understanding of the cyber security program. So understanding the cyber security program is part of this.
Understanding cyber security program add five components.
Okay. It's a part of the entire big broad strategic understanding the cyber risk at this three-stage level. So if it is understanding the cyber risk you need to understand through aim. Remember that understand through aim.
If it is cyber security program if you need to evaluate cyber security program CSP you need to evaluate this at the five stages which is IPDR.
simple identify, protect, detect, respond and recover.
So aim and IPDR that is way you can understand the entire cyber risk and cyber security.
If you have any doubts you can write it down in the last 15 minutes when we will you know uh open up for everyone by providing you a meeting ID you can ask your doubts now in your study material. Okay. Once you understand the cyber risk, this is very good chart which is given. Okay. Cyber risk management process you can go through you can understand very good one. Okay. Now when uh once you implement this particular uh cyber risk if you understand the cyber risk there could be controls around each and every area as I said vendor management. Okay. In our question vendor modification.
So when we were discussing this so identify the nature of the cyber attack we did explain the accounting and financial statement consequences. So this 2.8 cr pay payment is kind of you know a loss for the business.
Identify the failed controls.
That is very important because now you need to talk about the controls. What went wrong and where? And on that let us take one question very good question on the similar lines.
TP Limited is a medium-sized company involved in the manufacturing and retailing of home appliances to cater the daily needs of wide range of consumers. The company has in place proper cyber security policies, procedures and framework. Regular assessment of the same is also carried out by the management. The company faced a cyber attack incident of the email fishing scam which resulted in an appropriate disbers uh dispersal to various individuals posing a vendor and added causing a substantial financial loss.
This incident highlighted the need for a strong update in internal controls to mitigate the cyber risk.
Okay. What it did? It highlighted need for a strong update in internal controls to mitigate the cyber risk. As a statutory auditor of the company, how will you evaluate the controls around the vendor setup and modifications?
This is the part where you need to answer.
Now always when you get a question you need to read what is asked from you as the statutory auditor of the company how will you evaluate the controls around the vendor setup and modifications.
Majority of the students over here they will write what are the controls around vendor setup and modifications.
Okay.
So the question never asked you the controls. Is it is it the question asking name the controls or uh provide the examples of the controls.
This is not asked. Provide the example of controls or name some controls.
No, this is not asked.
No, what is asked is how you will evaluate the controls.
How you will evaluate the controls.
Now when we are talking about evaluation of the controls, okay, so we need to think from the cyber security point of view. Okay.
How we need to evaluate the controls?
How we need to evaluate the controls?
Like the way we have a cyber security program. Similarly, we need to evaluate here also the controls on the similar lines. First we need to identify okay who is doing what?
We need to identify who is doing what.
Number two, we need to identify, we need to evaluate how the request is being transferred for the vendor.
So remember like this question which is there if I talk about the example of quick card this one.
Now how will you evaluate this control?
Number one, who is responsible for managing this particular uh control? Who is the guy who has to update this uh master data? Who is responsible? Which team is responsible for this?
I have to evaluate. Then I have to answer certain questions. However, I evaluate by evaluating the elements of the control.
Who does what?
Who is responsible [clears throat] for updating this? Number two, how they are you know identifying the risk. What let's say for example if the person who is managing this vendor master updation is he uh you know able to identify the risk able to identify the issues able to identify a fraud scheme.
how he will identify if he is getting a fake email.
Okay. What systems are in place to identify this is the authentic customer or vendor request? This is not a authentic vendor request.
Third, what systems are used to detect these kind of things?
how the transaction is you know initiated, authorized, processed.
Remember uh with what we discussed with respect to the transaction part whenever there is a transaction flow you understand a particular part of the transaction that is how the transaction is initiated, recorded, processed, corrected, transferred.
Okay. So this you understand for the transaction. So whatever we have understood till now it's a combination of that we need to apply how the transaction is identified how the transaction is basically initiated recorded reported processed all these things we need to understand for that particular transaction how this happens okay then only we will be able to answer that okay whether basically this control that is there is appropriate or not.
Okay, I need to understand all these things about a control that you need to write in your answer.
So if I talk about the answer, it is the same that we are talking about evaluation of the control. The question asks how we'll evaluate what examples do not write an example two-way match or maker checker. No, what you need to write how you will evaluate.
So evaluation happens that who is responsible for making changes to the vendor master. Is it process centralized or decentralized? First you need to perform the identification who is responsible for this.
Then the technologies that are used in initiation, authorization, processing, recording, changing all those things that we understood how the request is received, communication channels, whether it's a email because if it's a email then there can be fishing, there can be email spoofing. Okay, if there is a email then there is a risk of fishing plus email spoofing.
So how I receive a request I need to understand that understand the flow of the process understand how the basically uh whatever the transaction is there let's say here the customer master or vendor master change how this vendor master change is recorded okay how a vendor master change is identified okay authorized recorded, processed, rectified. Okay, how it happens? You need to evaluate on those basis.
Okay. And when I say authentication, here is it authentication protocols.
What authentication is happening to make sure that it is not a fishing, not a email spoofing.
That is something you need to write in your answer. Rather than writing maker checker, rather than writing uh you know there is a person who checks it then the person sends to someone whether the vendor is there calling back the vendor you need to answer how you will evaluate they are not asking what type of control that can be placed. So most of the students make a mistake by wrongly answering the question. I hope it is clear.
Okay.
So this is how you need to answer the question with respect to the controls also.
Any doubt and if there is a doubt you can write it down. We will discuss once you will get a you know uh 15 minutes part uh where we will be discussing the queries.
Okay. So what we do is let's take a break of 10 minutes. After the break we will gather back and we will continue session. I will take up some more questions on this topic. Okay. So that you guys can understand how to answer over here. But that's more important answering the question which is asked and understanding the question over here.
Okay. Let's take a quick 10-minut break.
Okay, thank you G.
Thank you.
Uh break Shall we continue?
Hello everyone. Let's continue the discussion. Let me take up one more important question recently asked in the exam and very good question because that will enhance our understanding about the topic itself.
The question is GTech Solutions Limited a large multinational corporation engage in providing cloud-based financial services. The company operations are heavily reliant on the proprietary software application and extensive database containing sensitive client financial information.
During the statutory audit for financial year 2526, the engagement partners Y Hersh observed that the company has recently integrated multiple new digital platforms to automate revenue recognition process and safeguard its trade secrets. Further, the company has disclosed that an incident involving an attempt unauthorized access to its network occurred approximately 6 months prior to the year end although the management has described the incident as a minor. As the statutory auditor, CA hers is planning stage of the audit and wants to evaluate the entity's risk assessment process with specific reference to the cyber security risk.
Explain the key aspects that the CA hers would evaluate in identifying the entity's risk assessment process relating to the cyber security.
Now here we are talking about risk assessment process with respect to the cyber security.
Okay.
Now simple uh basically on this particular point if you have to answer this question okay if you have to answer this question what you will answer so you need to identify the entity's risk assessment process relating to the cyber security.
This was for the four marks which was asked in the recent exam and that is very important to understand what to answer for this question.
Take a minute, read the question and then tell me what will you write in the answer for this question.
See uh the answer hint is already given in the question itself.
So explain the key aspect okay that the CAR should evaluate in identifying the entity's risk assessment process relating to the cyber security.
If I summarize this, so it says that evaluate the identifying cyber risk component. and evaluate identifying the cyber risk component.
That means what is [clears throat] saying that how a entity will identify the cyber risk this line identifying the entity's risk assessment process relating to the cyber security that means how the entity will identify the cyber risk.
You need to evaluate this.
You need to evaluate this that the how the entity will identify the cyber risk.
And just now we saw this as a part of the cyber security program identification of the cyber risk. The first component remember to manage the cyber risk entity has to perform entity has to develop a cyber security program and to evaluate the cyber security program you have to evaluate the program at the five stages.
Identify.
Okay. Identify. Then what was the next step? Protect, detect, respond and recover. That is the cyber security program. Why the program is designed to manage the cyber risk of the entity.
That is the entity's risk assessment framework. That is the entity's risk managing framework.
So identifying the entity's risk assessment process identifying the cyber risk. So entities risk assessment process relating to the cyber security that means cyber risk.
So identifying the cyber risk you need to evaluate that simple how will you evaluate? Who is responsible?
What are the IT systems?
So in order to see that uh key expects so we need to provide the key aspects or pointers basically that would evaluate uh that would you know explain the key aspects that the CA hir would evaluate. So what I will evaluate the uh identification process and the key aspects to evaluate that are I will evaluate whether the entity is identifying all the IT systems digital assets whether the entity has a person who is overall responsible like CTO CISO whether the entity uh you know is appropriately uh you know kind of doing uh what you can say trainings or how the entity is you know periodically reviewing its uh information.
Okay. Is there any periodic risk assessment or training or you know some some kind of program which is there?
So who is responsible overall? Okay.
what are the program you know framework like like uh you know a lot of frameworks are there for example you can say ISOs or you know standards are there on which the program can be created so if we go to the answer this is the answer how to identify these are the key expect so these are the key expects that we are talking Okay. Periodic review of information system. Periodic risk assessment should classify and prioritize their information assets based on the sensitivity which is more sensitive which is more critical governance perspective.
uh framework which is used for the cyber based risk security program like NIST and ISOs.
Okay. Who is overall responsible CIO, CTO, CISO for the business environment?
This is what you need to write.
That's it.
[snorts] Now what will happen is most of the students over here what they will write it identifying risk assessment process.
They will go on risk assessment.
Trust me, they will write the answer as per essay 315, risk assessment, walkthroughs, controls. They will write on uh you know performing the uh what you can say design effectiveness, operating effectiveness, all these things, substantive procedure, a maker, checker or what not. They will write fraud, risk, a lot of things they will write over here.
But you need to understand what you need to write. What is asked for?
That is the basic part that first you need to understand in the question what I need to write, what is asked for then only you can answer the question.
Okay. So your uh question will only provide you that this is something it is asked for. You need to write this.
You are not required to write on the entity's risk assessment process but you are need to write on evaluation.
This word is very important evaluate in identifying entities risk assessment process relating to the cyber security that is the cyber risk.
If I talk about this entire term entities risk assessment process relating to the cyber security it is nothing but cyber risk.
So this is equal to cyber risk which is part of my cyber security framework. So identification of the cyber risk uh under the cyber security framework simple clear.
So that is one more interesting question that we have in uh in the recent exam and this is how you should evaluate what is required to be written.
Okay. Now what we have covered till now.
So we have covered till now some very important parts of digital audit, cyber security, cyber risk. Okay. Now we are going to cover one important concept called remote audit.
Now this is nothing but we are transiting towards the auditing digitally.
We are now transiting towards the auditing digitally.
So when you do auditing digitally you use technology, you use software. Yes. Till now we were talking about digital audit, we were talking about systems, we were talking about cyber risk. Now what we are talking about? We are talking about auditing digitally.
So audit auditing digitally basically is on the two fronts where you do a remote audit through technology and you use emerging technologies.
in audit.
Okay, that is part this is these are the parts of auditing digitally.
Now when I talk about remote audit, remote audit basically uh helps you you you are at some places the way we are talking on Zoom right now. We are discussing on Zoom. Similarly, remote audits happens on zoom, micro, Microsoft teams or Google meet. Okay. So, you do planning on the on the teams when you meet with the people, you meet the relevant you know officers from the company, you conduct the data exchange online, you access information system, IT systems. Okay. So entire planning happens online and then after that there is data security, data confidentiality in the data transfer that you need to take care for. Okay. So basically you need to consider for uh okay how I will do the planning, how I will meet the team. Okay then how I will you know secure the data, how I will perform the risk assessment. I need to think of all these things when I talk about uh auditing digitally because now our focus has shifted from the risk to how we can do audit better.
Okay. So when I talk about remote audit okay or when I talk about auditing digitally for each and every technology we need to understand the objective is understand pros and cons of technology.
Okay. So that is our objective that you need to understand the pros and cons of the technology and it may include okay what are the some features of that particular technology that will give you a guidance of what is a pro for that particular technology what is a con for that technology okay so till the time you don't have this information you will not be sure that should I adopt that technology in the audit or not till the time you are not confirmed you you don't have you know uh like uh what you can say clarity what is the benefit of the technology or what is not the benefit of the technology you will not be able to basically you know decide whether should I go for that technology or not.
So that is one of the aspect that you need to understand each and every technological pro and con so that you can you know decide basically uh like whether I should go for this technology or not. Okay, that is the our goal for the auditing digitally as of now.
Okay, now remote audit again when I talk about remote audit, I need to basically understand uh that in remote audit what are the key things that I need to take care of.
So key factors to consider for remote audit so that I can decide whether I need to use or not.
Factor number one is planning.
See planning of audit is very important because if your plan is wrong your audit is wrong. Whatever you do at the later stage it's a very crucial portion of the audit. So you need to understand that very crucial portion of the audit, very crucial stage of the audit. How you will perform remotely? What are the considerations you need to talk about?
For example, you may think of uh how I will meet through zooms, Microsoft teams, how I will take the data, how I will understand the processes, everything you need to understand about the planning of audit online.
Then comes the uh risk assessment procedure. Again very important part how you will perform the risk assessment uh online through remote audit. Is there any restriction?
Okay. Is there any problem that you may face?
Anything that can you know restrict you from performing appropriate risk assessment? How you will do risk assessment through remote audit or remote meeting?
For example, if I have to talk about risk assessment, then uh I need to understand the business process. I need to identify the relevant risk. So I need to you know think about the risk assessment.
So how will I do that particular risk assessment through remote audit or remote features?
How will I do the documentation?
Risk assessment not only requires identification but also communication with the team members under SA 315. The moment you will see SA 315 you will realize that risk assessment is not only restricted to the identification it is communication also. So how will you do to communicate then data security?
How will you secure your data that you are getting? So data which is being received, data which is being stored, how will you ensure the data is complete, encrypted, okay, is there any screenshot that you can take, you can maintain what is authorized, what is not authorized, all those things with respect to the data security and then I will understand what are the advantages and disadvantages, pros and cons of a technology. So these are the special areas, key factors and after that I will understand uh the pros and cons of remote audit so that I can decide basically okay whether I should go for a remote audit or should not go for a remote audit.
Okay. What would be the advantages of a pro for the remote audit?
cost effective, saves times, no travel required.
Okay. Comfort and flexibility, team can work from their home. Okay. Evidence uh basically can be gathered concentrated in small calls you know and then on the basis of that it can be shared and daily activity maintenance everything can you know happen online.
Uh auditor can get this uh audit evidence from the IT system directly.
Let's say for example quick card if everything is systemdriven you can access system from anywhere no need to go to the you know client's office because servers are on cloud you can access this from anywhere again plus if there is no location restriction auditor can be from any place so if you have a team in Chennai you can and that is a one of the best team you can involve that that team to audit a company which is having a registered office in Mumbai they do not need to travel to Chennai for So flexibility these are some benefits of the advantages of the remote audit.
Disadvantage network issue basic you don't have a network to conduct the appropriate interviews or meetings Wi-Fi internet access availability.
Number two most of the time you are speaking to one or two people over the call. when you go and visit the uh location or do the you know physical audit you meet multiple people you understand how they work on ground in remote audit you see documents you don't see the process which is happening over the uh over the ground best example inventory count if you are doing remote audit you can see inventory count documents but you cannot see what is inventory count which is happening over the ground over the floor or in process so we can see the documents we cannot see the process in line again documents can be genuine cannot be genuine can be fake also so there is a risk of that IT issues sometimes because of the security reasons you might not have they might not allow you the access of the IT systems when you are sitting somewhere else okay local laws or the language for example the IT team is not based in India. They are based in Switzerland where where they are using let's say uh German or you can say some other language or let's say they are in the Germany where the German German is spoken for the documents like they they speak in German documents are in German what you will do so all these are disadvantages that can restrict uh you know selection of my remote audit so I need to understand should I go or should I not I may go partially I may go fully and this advantages and disadvantages is good uh you know appropriately given on page number 12.28 28 in your study materials, no travel, flexibility, uh you know like uh then time required you can divide in several weeks first and evidence from the IT system selection of the auditors globally but on the same time the disadvantages network issues uh ability to visualize like to see the process on the floor doctor documents That mean fake documents, remote access to the sensitive IC systems may not be allowed. Cultural challenges, local laws can be an issue. Physical verification of the assets you cannot do through remote audit not possible at all. So these are some disadvantages and based on that you need to decide whether you should go for a remote audit or you should not go for a remote audit.
Okay.
Similarly, we have other emerging technologies. One is data analytics.
Now, I will show you one example of a data analytics. Okay? And basically we will try to understand uh you know how data analytics works and what is uh you know basically how quickly it can be our to our help that how we can you know get the data uh out of you know the analytic analytical that has been performed over U let me share my screen and show you some great data analytics.
Okay, this is one of the uh PowerBI dashboard. Okay, for a general this is kind of you know publicly available data. It's kind of a demo data which is there. This is a PowerBI dashboard. In the behind of this dashboard you have a data.
Okay. Now what this data is doing is this data through this PowerBI dashboard is being converted into the very big you know charts and analysis. So here you can do a analysis. Now again this is into a different language. Apologies for that. But this is you know helps you to understand data very quickly. I can easily identify uh you know over here.
So let me zoom in for you.
Let me do a zoom in.
Let's say this chart over here like I can you know figure it out. Okay.
January, February, March, April months are there and how the sales is working.
Okay. Then what are the top five clients for me immediately then how the money is catch is flowing for me. So immediately through data analytics I can identify that okay what was the yearon-year revenue how much increase is done periodon period comparison okay so taxable revenue all these things is you know immediately and quickly available over here with just uh you know data being given to a tool and that tool prepares this particular for me for uh this dashboard for me based on this immediately I can figure it out like you know what areas I need to focus on, what areas I shouldn't focus on.
And this is not just one thing. There could be multiple. I'll show you one more thing.
That was revenue.
Now this is on the business. So there is a motorcycle business dummy data. Let's say someone is operating motorcycle business. Okay. So by using this dummy data I can create this dashboard for example business overview like what are the best uh you know bikes which are being sold for my company best profitable models okay key features of the bike how many units I have sold what is the gross profit everything customer information the moment I'll click on customer I'll get customer information how many pay cash up UPI credit card finance what is you know color analysis like which color bike is being sold more which is the highest city where I have a sales okay even I will click over there let's say if I click on Delhi it will show me all the results of Delhi okay in Delhi what is happening which color is more dominant 19% black 18% blue uh Delhi statistics is coming unit sold 148 in Delhi female male registrations everything just for the Delhi with one click If I remove this click, all the numbers are back customer wise. Then dealership wise, which dealers are active more like everything. And this is dummy data.
Okay, this is entirely dummy. For example, if I select this particular bike unicorn, the entire numbers and everything will come for unicorn if they are there. Okay, let's say net sales.
If I select this bike then accordingly numbers will come from that or if I select something else let's say segment premium segment it will show me which is a premium segment over for me like this is CB 350 the premium segment okay like if I select this one computer so these are the two computers and the data will appear appear accordingly so this is the power of analytics that we have and this is the technology okay so When we talk about emerging technologies, one such is data analytics techniques that we are talking about.
What is data analytics techniques? Just just now we saw we through visualization through large set of datas we can you know see trend analysis. We can easily draw conclusions make informed decisions.
Okay. and easily with a quick uh charts and everything I can see okay what is happening in the data which city is more which city is less so if I go back to that data this motorcycle business okay if I go to the customers I can quickly see on this chart this one that I have a huge sale in Delhi but I have a very less sale in other cities other states. So I have a huge sale in Delhi.
So my you know uh like sample selection risk assessment accordingly will flow.
Let's say cash over here cash payment I have 28% people who customers who are paying me in cash and the highest amount again in Delhi. If I go for a finance, I have a this one is finance. I have basically you know good amount of finance in across all the states which is 22%.
More finance and what is the revenue? So I can you know by this way I can easily uh come to a conclusions some actions which are there you know this is again the insights from the data which is automatically calculated and automatically uh you know being recorded dynamically generated that computer drives sales volume scooter drives margin that means the computer segment is based on the volume I don't have a margin over there but the scooter segment is where there is a more margin.
Okay, digital booking uh has increased more. So all these things, all these action items I have on my you know fingertips easily.
Let's say I'll select a particular model and everything is available that okay uh you know what is the key insight for that particular segment and by this way I can do my you know risk assessment very quickly analytics very quickly.
This is the power of data analytics and this is one such tool which is PowerBI.
There are various tools like ACL like Altrix.
Okay. Then PowerBI just now we saw Kear.
Okay. There are multiple tools available for the data analytics. Now what data analytics helps uh does is discover analyze it helps you to discover the pattern like Delhi example in two-heer data Delhi sales was a pattern yes or no identifying anomalies if some state or somewhere I have a very less sale extract useful information that computer segment and drives volume margin is in scooter example. These are examples. Okay. So this is very useful information with the quick data analytics uh I you know got from the entire set of data. There could be bulk data in behind and basically trust me when I talk about this bulk data this is the data which is in GBs in very very high data sets okay so it's not something which is you know kind of uh you would say that you know very small data data analytics is basically used for uh kind of you know with very large data sets huge data sets And I can create any number of dashboards a lot of dashboards. I'll show you again one more example CFO dashboard. So there are you know executive wise dashboards also. This is kind of CFO level dashboard like CFO view.
This is summary of my financials.
Financial statement summary kind of P&L summary. What is increasing? What is decreasing? This is income statement.
Similarly, financial details for me with one click I can get the entire financial detail. I can read it. I can you know evaluate it that is what revenue insights which are the products which are being sold more which are less. Balance sheet cash flow statement insights. This is balance sheet insight. Debt ratio how it has progressed. working capital. Okay.
Uh asset main uh part total liabilities total asset how it is working cash flow with one click I have entire cash cash flow uh you know in uh in comparison format with me.
I can select the years also let's say instead of 2024 I select 2025.
So large data sets are available. I can easily identify okay what is happening at what level.
So these are the dashboards uh you know which are created in for the data analytics very useful tool.
Okay.
Then uh IoT IoT are kind of uh things uh you know connected tools and secure uh you know devices which helps you to record the data for example uh let's say if there is some you know uh security camera that security camera uh captures that when an employee come enters into a premises and leaves a premises So it does the attendance for example security camera recording attendance.
So IoT can also be used to record the data. Now again IoT have their risk involved okay of device hijacking, data siphoning, a lot of things are there.
Then comes the AI. We will briefly discuss all these uh emerging technologies. Then comes the AI. AI again uh everyone knows AI. There is no introduction required. Okay. Chad, GBD, Germany, Claude, a lot of AI are there.
But there are implications of using AI.
Number one, transparency. So invisible nature of algorithm. That means that how the AI works, it's not available.
The way we have the code in the uh you know RPA, AI doesn't have that code available in in picture. That means you struggle basically to understand how AI works behind the scene. That information is not available.
Okay. Second, AI has a tendency of the hallucination.
So if there is a bug or vulnerability or is there any wrong coding it may give you wrong answer.
Okay. Your data can be used for other purpose. So there is a data privacy concerns. So there are many concerns for the AI. Okay. Security hallucination inappropriate configuration if there is no appropriate you know uh way it is structured. So a lot of things are problem there in the AI blockchain again we have discussed what is blockchain. Blockchain uh technology is kind of you know block systems where one block is you know uh having information of its previous block so that no one can break the chain but again it has its uh you know risk that without that encryption anyone can edit the block. What if if I edit the block and if I have a technology to edit all the blocks subsequently?
What I have a technology to reverse the transaction then the blockchain fails. Blockchain purpose is that it cannot be edited when a transaction happens. You cannot edit the transaction later on. If you are able to edit the transaction, you you will lose the facility of the blockchain.
So trail is not there.
Okay. Again, NFT NFTs are kind of tokens, nonfgeible tokens. That means they are unique.
Okay. They can be traded, exchange, uh they cannot be replaced by another same token. Simple example, one Bitcoin BTC of one particular BTC will be equal to another one BTC.
Okay, that means if I have a BTC, I have a bitcoin, one bitcoin and you have a one bitcoin, we both are intangible.
That means there is no separate feature in a bitcoin which can say that your bitcoin is different from my bitcoin.
No, but NFT is like that one NFT is not equal to another NFT.
Each NFT is backed by a particular okay asset. So nonfgeible tokens are backed by a digital asset.
So if I just show you a uh NFT token wait a minute I'll show you NFT blockchain. So NFT technology can be combined with the NFT blockchain. Okay.
And we have a uh I will show you uh ETHbased N uh you know NFT blockchain.
Let me see if I can have a access right now.
Okay. Yeah, I do have a access. Just give me a minute. Let me share my screen.
Okay. So, I will show you something.
Uh, basically a design is there. Okay.
This is an NFT token. This design you are seeing on your screen. Okay. It is an NFT gift token.
Okay. Now, this is valued for something.
it is valued. It has a value of 6 ETH equals to 12.9K US and if I go about this blockchain detail that means uh from where it is bought where it is sold everything. So this is one of the kind of token means I will not get this similar token with someone else. Okay. This is how it is generated from somewhere like this token has been redeemed to a ticket in this particular website. Then each year there are 12 tokens. So this is very unique token.
Okay. Token ID is there. Okay. It is a based on Etherum blockchain and this is the address of that particular contract from which this this token is coming. So if I sell this token, okay, this token number, it will this image will be sold with that and the person who who will get will be owner of this image.
Example, okay, this is one of the example of NFT.
So NFTs are tokens which have a digital asset at their backing.
Basically there are asset involved and the those assets are then you know uh placed on the blockchain or any technology and there are multiple assets digital asset IPS uh which are there on the NFTs then there's a you know there's a challenge in the NFT is the copyright concerns as I said one NFT is not equal to another NFT but no one is you know stopping them from copying the NFT. So copyright concerns can be there original fake NFT. Okay, there can be fake NFT but uh as I said one NFT will be unique to another. There can be copyright concerns that is some different story that we that will be there but yes fake NFT can be there.
Then comes the another concern is a fraud because these transactions happen online. So there are huge risk of the fraud fraud risk involved in that okay in the NFTs.
Then basically uh you can say that another issue that can happen uh with the NFT is ownership.
even though it is on the blockchain, there are sometimes you know scenarios where those NFTs are uh stolen and you know kind of uh not the owner is not owning the NFT because it is stolen you may not be able to check the ownership of that NFT.
Okay.
So basically these are kind of you know scenarios where uh you know this kind of uh risk is there in the NFT sorry so these are certain security concerns which are there with the NFT And Mr. Wait a minute. Uh, sorry for the interruption. The screen is has frozen.
Sorry for that.
Okay.
Yeah. Now the next is Robotic process automation, RPA. RPA very simple. RPA are the standard technology and the code which is determined to run basically uh every time the way you want. Okay. The benefit of the RPA is that they will run every time in the way that you will ask them to run.
So I will show you a RPA code example.
Now what is the benefit of RPA? RPA is they are transferent.
Okay, RPA they are transparent. That means that every time if you ask them to do something they will do in a way that is they are programmed for and every time you will let's you know the output is predictable. If you give this data they will do this only. So they have this programming already.
Okay. And with the help of that programming they basically uh do what is asked for.
So let me show you an example.
Now RPA is not only for audit, it can be for process also. Now this is one of the code for the RPA. Now this code I can validate what is what is this doing? It is an XML file. I can do that. So I'll also show you some examples of RPA like uh let's say word replacement. Okay. It replaces the text in a particular document again XML file. It can be you know you run on the VBA or in Microsoft's environment. It's a VBA file uh visual basics for the Microsoft. So it is programmed to change some words you know sanitize the document. So these kind of RPAs are used to prepare the documents appropriately or workpapers appropriately. Okay. They are designed in a such a way that you they uh you know will remove some formatting issues from your document. So predictable code.
Okay. Again speech related a lot of things are there. Okay. in RPA a lot of example I can show you this is OCR that uh this particular uh RPA will read the image and uh it will convert the text which is there in the image again a lot of you know code is there in this but it is predictable I know I can audit I see how it works and it will work for a specific purpose only that is an RPA it is there for a purpose okay so It's repetitive in nature.
It's a processdriven and I know that what it will do. It is something for the automation and it is 100% reliability and precision. That means it is kind of you know predictable because the code will work in the same way. The way it calcs 1 + 1 it will show two it will show two. And if I do automatically that every time uh you know two numbers are entered on the internet you take those two numbers and do the calculation that is robotic process automation non-stop much faster 100% reliable kind of thing.
Okay.
So these are certain you know again technologies involved and uh these are the technologies that can you you can use for your audit. Now the question comes is that when you are doing auditing digitally okay emerging technologies can bring risk okay I have to when I'm doing auditing digitally that means I'm using the technology to audit to test the control to perform the risk assessment so how I as a auditor okay how I will face these challenges like as a auditor I need to perform the risk assessment and control testing.
So I how what I what the what are the areas that I need to think of okay that I should focus on with respect to the controls and the risk assessment when I go for auditing digitally okay because what happens is see uh if I'm implementing new technology there will be risk from new technology so I need to understand those risk I need to place some controls on these some technologies then only I will able to you know see that okay now this technology is good for me now I can use this technology efficiently otherwise it will be a problem for me okay and I have to place some appropriate controls on the digital systems so that I can rely okay on these technologies otherwise what will happen is there is a problem and I need to test some controls also so that I can rely on these technology otherwise I will not be able to tech rely on these technologies.
Okay. So if I talk about some some areas where uh as an auditor okay I should address and uh you know the challenges that are faced with respect to this technology risk an auditor should focus upon with this technology when auditing digitally. I'm not talking about digital audit. I'm now talking about auditing digitally and the risk with respect to that.
So first of all an holistic approach and holistic understanding of the changes how the change is happening what technology is being implemented so that I can evaluate effectively the you know processes which are there then only I will be able to you know do digital auditing digitally. That means if I want to implement RPA I need to have an entire understanding.
Okay. So I cannot blindly implement RP or data analytics. Till the time I do not understand holistically the entire IT environment, I cannot go for uh emerging technologies. Okay.
Till the time I do not understand the entire IT system, I will not be able to do remote audit.
Can I do remote audit for the manufacturing entity? No. I can do remote audit for the IT sector company but I cannot do manufacturing audit through remote audit. So I need to understand holistically the industry the process how the management is initiating processing recording the transactions so that I can use the emerging technology for that.
Consider the new risk resulting from emerging technologies.
For example, what are the risk in remote audit? What are the risk in RPA? What are the risk in your uh new technologies that are being implemented?
Should we upskill or should we bring a specialist PowerBI? Yes, you can understand. You can you know learn PowerBI. Digital upscaling is process is possible. Should you go now learn the RPA the coding or should you bring specialist for that?
So you need to think of should I bring a specialist in the coding or AI or NFT or should I learn as a auditor the PowerBI or the coding. You need to decide that so that you can understand the technology and which then can be used to design implement and test the controls because at the end you are using the technology to do the audit. What is auditing digitally? using technology using tech to do audit.
So for that you need to understand the technology and then you need to understand how I can use the new technology to do the risk assessment design implementation all the audit procedures clear.
So that is something uh basically which is there in new and emerging technologies.
Now we have discussed the uh you know auditing digitally. Let's go back and let's discuss some questions further.
Okay. So that we can now understand further how to basically write the answers. Okay. for the questions which are there in the exam.
So let me bring up a question on the screen.
Basically now we will basically understand that okay what uh you know how to answer these questions in the exam. Okay.
So uh one very good question I have just a minute.
Yeah.
So very good question. This is an online retail company operates through a website where thousands of the customer place order daily. One day hacker carries out a cyber attack and installed a ransom ransomware that encrypted the company's database and critical systems. As a result, employees were unable to access operational data.
Customer could not place orders and the website become unavailable. The attackers demanded a large ransom payment in exchange for restoring the access. Further, there was a possibility that the customer personal data has been compromised.
The company also incurred cost for investigation and system restoration and faced a decline in the customer trust along with the potential scrutiny from authorities.
Identify and explain the indicative areas where the organization may face impact of the cyber risk in the above situation.
read this question and meanwhile let me share the ID for you guys to join. Take a minute read the question and also I'll share the ID which you can use to join the session.
Okay. So the meeting ID is 873 07 58 491 1. The meeting ID is 873 0758 4911.
You can join and you can ask your questions also and we will discuss this question and then we will take up the uh your questions.
Okay. So what do you think?
What is required to be answered in this scenario?
How will you answer this particular area in this scenario? In this question, what you will answer? What is asked? So what is asked is identify and explain the indicative areas where the organization may face the impact of the cyber risk in the above situation.
Simply we are talking about the impact of the cyber risk. Here we are trying to understand the cyber risk. Yes or no? So the question focuses on understand uh standing of cyber risk and you understand through three ways aim for it. In order to understand the cyber risk you need to assess, you need to do impact analysis and you need to manage. Here it is specifically asked impact.
So you need to talk about the impact of the cyber risk in order to understand what impact it can have. Regulatory cost, business interruptions, data loss, ransomware, okay, intellectual property threat, privacy, fines penalty, going concern issue, a lot of things can be there that we discussed. All these things you need to write the answer over here.
Yes or no?
Any doubts on this or any doubts on any other topic? You can unmute yourself and ask any doubt.
>> Yes Rada.
Uh yes sir. Um before asking that out actually sir there was a glitch on your end with regards to one topic which you were explaining uh with regards to powerbi dashboard and uh till revenue and motorcycle till the gender one which you said male and female who has purchased it. So till that it was not being visible. So that was totally unclear that what you were trying to explain in that with regards to data analytics >> basically see the point was the powerbi dashboard that I uh >> sir it was not visible over the screen.
Yes sir.
>> Let me show you again.
>> Yeah.
>> Now basically the PowerBI dashboards that I'm showing you these are the example dashboards. There are multiple ways to prepare these.
>> Again it is not visible. So let me share I'm sharing you just a bit I'm sharing don't worry I'm just telling you these are the example dashboards that I'm going to share and you know make you visible but uh the point is there can be multiple permutation and combination of these dashboards which can be there in the market or which can be prepared. So what I was showing the dashboard is again this is another example of the dashboard. Now what these dashboards are through these dashboard I can easily figure out the patterns. Okay, I can easily see what is happening like number of services as I said there can be various type of dashboards on various data.
So uh again like uh as I said you know there were examples of different different examples earlier and this is one such example of the PowerBI dashboard. I was just showing the examples of these dashboards track in that way.
>> Yes sir.
>> Let me let me show you another one.
Okay, >> see again this is another PowerBI dashboard. So if I will click uh let's say this is sales overview. If I'll click on accessories, it will show me the entire sales in region like it's in it was for the US data. So accordingly it is showing the US data like which accessories are being sold like this way. So this is power with one click I can do the analytics easily like what is happening what is not happening which region is most so for example highest sale in US south less sale in US north with one click I can get it which state is contributing more over there like this way >> yes sir so with regards to the tools of data analytics which you discussed so uh like every data analytical tool is having this sort of dashboard by which we can do the analysis >> so Yes. So when I talk about different different tools of the data analytics, Altrix and all those tools, let me show you go back on that particular point.
Okay. Now let's say for example ACL uh ACL is a language and the tool both. Now how ACL works is ACL is a language. You need to write a code uh for the data analytics and the system that particular tool will read the language and will present the dashboard to you. It is bit different.
Elrix it is used for uh you know uh it's it's a more advanced than PowerBI because in PowerBI you need to create the dashboards and you know you need to create uh a lot of things before you can see the outcome. Elrix is more advanced.
It's very easy but it is more advanced in the data analytics. You can combine and relate the data.
PowerBI we discussed case where again one [clears throat] competitor you can say of the Altrix and the PowerBI in the market similar use.
Okay. So these are certain you know data analytics tool which are there.
>> Okay. So sir there are few queries which I would like to ask you now. uh I read read the module with regards to that u under the blockchain definition in the initial pages it was uh mentioned about use of smart contracts which can be embedded in a blockchain to automate business process. So what is this smart contracts?
>> These are known as the decentralized contracts. Uh it is a coming from a term called D5. Okay. You will search on internet you will come to know D5 is a decentralized finance and there are smart contracts on that which are there on the blockchain. Remember uh in my previous session I gave an example of a blockchain like insurance contract can be there smart contracts like you know insurance contracts which are there on the blockchain or some contracts on the blockchain. So these are you know uh contracts or you can say decentralized finance contracts various type of contracts can be there which can be there on the blockchain you can identify who is the party what is the contract which whether it has been endosed or not. So a lot of things are there on that.
>> So next one is little bit crucial for me for my understanding. uh basically in the module there is no as such specifically classified that it is uh under the head of digital audit of what five steps you explain. So sir uh technically digital audit and auditing digitally actually seem to be the same words for me but what all I understand in today's class was that digital audit is involving analysis of the cyber risk and security framework and auditing digitally is using the remote auditing and the other RPAs and other technologies. Is it correct? Radha I think uh Harsh sir in the last session also cleared your doubt specifically and thereafter he asked this question also what is digital audit and what is auditing digitally and you in fact answered also.
>> No ma'am today >> if you can just re uh look at that video I hope it will be clear.
>> Uh no Karuna ma'am that is a confusion with regards to auditing digitally.
today sir had um you know introduced certain new things with regards to remote auditing and emerging technologies that's why I'm asking that it is only being uh just associated with that or it is having a more broader framework that is my query >> okay so see definition if you go from digital audit and auditing digitally what is dig uh digital auditing digitally it is using the technology to audit okay if you see over here also RPA AI blockchain techn technology everything is you know part of under the auditing digitally and from a common understanding if you use any technology to do the audit it is auditing digitally if you audit the system it is digital audit >> only that was the only thing I wanted to clear uh sir next one was with regards to denial of service like how overload is possible and under that you also explained us with regards to DDoS and that is not clear to me distributed denial of See these are I would say these are kind of you know uh cyber attacks that can be there.
What is more important for the auditor to understand is the uh what type of cyber attacks are there rather than going into detail and understanding those. I would rather you know ask you to focus on that okay what kind of cyber attacks can be there so that when you do the cyber security program when you evaluate the cyber security program over there uh you know you will be able to identify that okay these whether these are covered or not. Now if I talk >> this kind of question is also being asked in the paper now so that they can identify which kind of part is this. So that is the reason he is specifically told you about all these because this kind of questions are being asked in the examination if you have uh seen the suggested answers of previous examination.
>> Yeah I need to view it. I will definitely refer it. And uh with regards to insider threats uh and the IoT based how hacking of the system is based and what kind of insider threats you were talking about >> there can be various.
>> Yeah.
>> Okay.
>> There can be various like it's [clears throat] kind of you know non-ending discussion on that because >> it it is very big different all together area.
>> Okay. No issues. Uh I will self-study that and I will ask you in the next session. And the next uh final query which I had is with regards to the one of the case study which we were discussing. Uh so sir I had a confusion that uh does it always essential to always integrate the evaluation of this I risk with that of the parah heating of 315 with regards to IPR which you explain >> like I say 315 itself says you need to understand and understand the IT environment and IT environment will include your cyber security program.
>> So yes sir. So that is what I was asking that because that specific question I was not able to understand it because it was little bit vague for me to just integrate the SA 315 principles to in that along with the cyber risk.
>> See first of all what is SA 315? SA 315 is risk assessment. Okay you need to perform the risk assessment. Risk can be various type risk related to the IT systems, risk related to the financial fraud risk everything. Okay. Now when I talk about risk related to the IT systems, it can be coming from the use of IT or cyber risk. So SA 315 talks about understanding the you know uh entity and its environment including IT systems. When I say IT systems, it says that you understand the risk which is there in the IT systems including the kind of you know uh through cyber security program and all these stages that we have discussed today.
>> Okay. And just the final thing uh so you were explaining about that NFT uh you made us read through the module but uh one thing is if it is unique then how the copyright concerns would eventually evolve and if for and on the other hand you said that uh it is getting stolen then it it is unable to you know we are unable to trace it but sir is token number as you said so by that the police can get it now >> uh again very technical there are things which are uh I just gave you an overview but There are few you know nuances which run in background public private key a lot of things are there. So if any of the thing is missing let's say you don't have a private key your token is gone even though you have a public key. So there are nuances in background which can uh trigger these risk.
>> Okay. So that's what because you also associated with that of bitcoins. So bitcoins is also so there is risk for stealing of bitcoin also sir. Yes, it's there. There are happening. There are cases in the market.
>> Okay, sir. That's that's all. Thank you.
>> Yes. Uh Rameshwari, you can ask a doubt.
A kamehwari gishwar you can unmute yourself and ask a doubt.
>> Yes. Yes ma'am. I just wanted to know it's uh in the module it's given common risk of IoT. What is the meaning of data siphoning sir?
>> Data safing is a data stealing kind of that means you know the data is there in your IoT device and someone also also is also you know stealing the data.
>> Okay. Okay. Thank you sir.
So one more thing I wanted to ask this uh um this RPA uh says in the module it is given RPA to check indestr what is this if FR >> this is internal financial control over financial reporting s what what what can you just elaborate something on this >> so see what is internal financial control these are the financial controls, okay, internal controls which are there over the financial reporting.
That means they are designed in a way that they uh they they are on the risk on the financial reporting side. So when you do a risk assessment, you identify there's a risk with respect to the financial reporting. Your financial statement might not be prepared correctly. You miss out some segments some related risk over there. Now there could be controls to mitigate those risk. So these are the internal financial control over financial reporting.
I'm thank you so much. Thank any other doubt anything else anyone.
Uh sir basically what I seen like the way uh this zoom we can interact is much better. So how long it will take because see if we have audio video connect real time now it will be more concentration from our side also because in YouTube we are going the picture quality is not up to the mark I no it will take some time for can we don't have the classes from this zoom only all classes from starting is it >> it's only time being phase maybe by next week you will be on normal mode so don't worry just be with us it's just teething phase nothing uh to worry in the hopefully By next week it will be normal.
>> Okay. Thank you.
>> Right.
>> Yeah. Yeah.
>> Like audio video mode real time because see more we have video look like we are more concentrated like more interaction will happen. Is it not possible?
>> That will going to be happen but later on.
>> Okay. Yeah. Thank you. Thank you. And if every time only doubts will be there definitely we want doubts but if every time doubts will be asked then maybe chapter will not get completed but yes doubts will be taken in the in the like in between but yes in the next week hopefully it will be normal course only just like we were having earlier >> it's like not like uh it's like private coaching only like full interaction so we both are happy more utilization can happen That is my objective >> in private interaction. It's like that only you are asking your doubts. You can like now only it is for last 15 minutes otherwise so it was from the beginning only.
>> Correct.
>> And nobody stopped to ask the queries.
I said by next week it will be normal course. It is not like that for this time only just because of certain issues >> we have allowed to join in the last 15 minutes. No >> and you can ask your doubts there in during that duration but otherwise we allow the students to be there by 6 p.m.
itself and they can definitely in between ask their queries.
>> Fair point. Fair point. Thank you. Thank you both of you. Thank >> the at final level the students can unmute and anytime they can ask the query.
Uh yes actually uh last time you said about the WhatsApp group I already joined it but yet the notes have not been >> who is who is talking this side.
Okay. Yeah. Yeah ma'am actually WhatsApp group no worries today it will be because now topic will be completed today and if you have seen majorly it is from the study material itself and I hope you are having study material and uh today the topic will be will be completed so it will be shared in the group maybe tomorrow you will get that >> definitely ma'am uh thank you so much and one more uh thing which I would like to ask you specifically from you ma'am H >> since uh auditing is a huge vast subject definitely it requires our own professional judgment. So in my article ship definitely I wasn't able to get that much exposure in this vivid fields and especially in the digital audit audit stuff. So now how to read this chapter or in every chapter like how to get the corrects and assimilate that is the main concern like to present answer because I get always confused that what to write what not to write.
So you first practice this chapter and after like uh after learning and completing this chapter we can like uh interact you can call on 01203045925 you can write on auditing final at the rate ici.in in also so we can interact on that and uh after understanding if it is good for all the students we will address in the class also.
>> Correct. First I request you to complete the chapter the way hers has taught and definitely you can directly also like read the chapter understand wherever you are finding difficulty you are I think um uh other students generally get hesitant but you are not like that you tend to ask your doubts and it's very good habit so you can definitely ask the doubts also and uh some of the points which we will discuss maybe tomorrow you can call me after discussion of the same we we can jot down certain points which we will share in the next class to all the students also. So if any of the student want uh to understand the strategy and how to study for that we will definitely take uh maybe sir when sir complete we will take 10 minutes on that. Uh yes suggestion which I would like to add upon if it is possible uh like a chapter wise test is it possible I really want to give chapter wise test so that I can get the prep edge over the preparation just at the end of each and every chapter there are certain questions you can do writing practice and you can review in case if you find any guid you feel I need certain guidance on this you can reach out to us also >> after each and every chapter there are tester your uh knowledge questions there. There are test or understanding questions also there. So you can solve those questions and if you find any difficulty >> while solving or while any for any conceptual clarity or for any stepwise guidance that how much to write because in the answer sometimes it is lengthy one.
>> Yes.
>> And in the examination you need to need to write appropriate length of the answer.
>> Yes sir. So for that kind of guidance if you feel we can definitely uh discuss that.
>> Okay. Thank you so much. I'm so happy today also like every every session is going so happily with you all. I didn't expected that LBC is going to be so fun for me. Yeah. And we really enjoy if student share their frank feedback and what kind of issue students are facing if it is known to us we can definitely address. But yes, I would like to interact with you and we can jot down certain points which we will share with all the students so that they and if they are also having any issue they can also talk to me and call or mail so that we can share with other students so that they are if they are also facing same issue they can also get guidance.
Okay. Yeah. Hash >> any other doubt I think Aditi you were having some doubt.
Any doubt? Anyone else?
>> Good evening sir.
>> Yes, >> this is uh actually this is a question to ma'am. Ma'am, how to join the group which you said for note sharing?
>> Uh you just call me tomorrow. I will uh try to share the link with you because right now I'm not having link. Uh if Ajit or Darendra any one of you is there please share the link of the WhatsApp group in the chat so that they can join.
If they write to you in the group uh chat you can definitely join the group otherwise you call me tomorrow I will give it to you. Your number ma'am >> 01203045925 >> or you can write on mail also auditing vinyl at the rate ici.in Same.
>> Yes ma'am. That would be better. Yeah.
Thank you ma'am. Thank you sir.
>> Any any other doubts? Anything else?
>> One last doubt. Professional ethics is changed now. So we will cover based on revision only. Correct.
>> Yeah. For May 27 examination it is changed and definitely in the class uh latest one will be taught to you.
So this may be after some uh one after month maybe you know immediately or >> as per it will be as per schedule. Now right now we have started with section two thereafter we are covering section three thereafter section four and maybe section five and then section one or maybe section one and thereafter section five. So it's not like that next month or like uh any other particular time >> is not updated. Now next week also we are not able to obey like what we are covering. I think on website still >> so I'm I'm telling you now so we have started with section two I spoken uh on Monday also that we have started with section 2 digital auditing and assurance and its weightage is 3% to 6% that is four to seven marks and after completion of this topic we will start with our unit uh section three group audit in the sequence only we will be continuing okay and after that section four ES PSG.
So it is not being compromised and student uh generally skip this these chapters but these are very scoring chapters. So we have started this way this time otherwise we start with either professional ethics or either with standards.
So this time we have started with section 2 3 4 and then we will be moving towards 105.
>> Okay.
And in NBF chapter also there are amendments. So that will also being covered uh in the class.
>> So that is section three only. So very soon we will be on that chapter.
>> I said chapter wise question answers is not there. Now like if you want to study in deep other than this like we have >> there you refer study material in the study material also test your understanding is there. Then see sir is showing you test your knowledge and sir scrolled. Yeah. See everything is there >> options are there.
>> Even if you think these are less you can go for MTP you can go for RTP >> MTP RTP suggested RTP everything is not uh like chapter specific you you should study all then we can do because I thought anything is little chapter specific now we can do more deep dive study. No see I >> 19 questions are there. Yeah yeah.
>> Yes ma'am please please continue.
>> No you you can guide please.
>> See in MTP RTP in exam also you will not get a question chapter wise like this question is from this chapter just chapter >> just to build up confidence because right now we are doing chapter wise. So that's why >> so chapter wise you can go for test your knowledge. Okay. In RTP there is a heading given. In MTP the headings are not given because you need to identify from which chapter which topic the question is and according to you you know you need to answer as per the exam.
So RTP yes you will get the headings test your knowledge over here you will get the headings chapter wise questions you will get okay but MTP and other material like suggested and everywhere you like there are you know there will be chapters uh there will be question from this chapter because as you as ma'am also said it has weightages but you need to just identify which one is there >> and and for MCQ also this is sufficient >> there is a MCQ booklet also entire MCQ booklet over there you will find a lot of MCQs on this topic booklet also like full no chapter wise now so got it booklet >> can't be chapter wise because uh for if you want to practice MCQ you need to log in MCQ practice portal there you will find independent MCQ that is chapter wise but otherwise in the paper case scenarios are being asked which is integrated not only single chapter two three chapters may be integrated so in case scenario booklet integrated case scenarios are there Mhm. Okay.
>> Okay. So there you will not find specific chapter but yes on MCQ practice portal you can go to particular chapter and you can practice the MCQ.
>> Thank you. Thank you >> Harsh sir just one uh suggestion to you actually you were discussing the case based problems which are being asked in latest examinations. I would just like to tell like you know can you please just quote it next time whenever you're discussing such case laws. it will be easy for us to track in the near future.
>> Quoting means like from >> quoting means like for example it is asked from May 2026 examinations like that. So I can just you know just mark it cross reference it. So while revising before the exam so I can just uh you know refer it. That is the thing.
>> That was the only thing.
Uh I think I have received one question on chat like uh what should be our approach for writing answer for this chapter because majority of the time is consuming learning keywords. No see again in order to write answer for this chapter you need to understand the topic and what is asked in the question. So once you will understand the topic and once you will understand what is asked in the question accordingly you need to write the answer. So if you have a good understanding of the topic, if you have a understanding of what is asked, I don't think so you will have a problem with respect to uh writing the answers and what is asked in the question.
Any other doubt?
Okay. Uh no doubts.
Okay. If uh no doubts then what we can do is let me take up a closing quick 10 or five MCQs kind of where you need to answer and you know it will kind of serve as a revision for the chapter and we can then you know we'll close the chapter. So let me share my screen. So just one second you can share your screen in the meantime. Dear students, my request to you all whatever is being covered till today. Please go through, revise, thoroughly study from the chapter and still if you have any doubt, you can reach out to us. Right? And uh for the practice of the question, we have already told you that test your knowledge, test your understanding is there. There are certain examples also being given. In case if you feel you want to practice more question, you please talk to us.
Okay.
So, uh here are the questions. So, we have a question small question, small MCQ, quick revision sort of things. So, the question number one is auditing digitally is defined as in using advancement in the technology to conduct a these are the options audit of IT systems, effective and efficient audit, manual audit or compliance check. What is the answer?
>> Effective and efficient audit.
Absolutely correct. Which of the following is listed one of the five main types of IT dependencies? Interfaces, manual general, business strategy, physical controls.
>> Interfaces.
>> Good. Uh, a type of malware that encrypts a victim data and demands payment for description uh, decryption key is called >> ransomware.
>> Yes.
A fishing attack that specifically targets seale executives employee is known as >> failing failing.
>> The five components of the cyber security framework are identify, protect, detect, respond and >> recover.
>> Recover a tool that is described in the data extraction and analysis software for the fraud detection such as finding irregularity in the large data set.
I'll it is bit of uh kind of you know uh what you can say complicated I'll let tell you it's a ACL because uh it is command based so it is used for more into the fraud detection okay then what RPA stands for >> robotic process automation a digital asset that represent ownership of a unique item like art or collectibles >> NF NF Very good.
Using drone technology to photograph and physically examine large quantities of fixed asset and inventory is an example.
>> You sir, you can ask others also.
>> Yeah.
Anyone else to answer?
>> Next gen audit.
>> Yes. Next gen audit. Very good.
A key shift in the nextG order is moving from sampling population to population.
>> Full population.
Yes. Very good. So basically this was a quick revision of the chapter. You can ask your doubts. If you have any doubts, you can reach out on the details that ma'am has also given to you for your doubts. And uh again last any doubts >> sir basically nextg audit you have not covered yet. So is the chapter completed?
>> Yes basically see nextg audit is kind of uh detail which is there uh like you know the new technology that can be there. So we have I have covered majority of the all the topics which are there. So rest you can read and if you have any doubt that's why I said reading is very important. You need to read like you know I uh here we are not reading all the topics but majority the main topics for your understanding. So reading is required reading for your entire study material is is not an you know uh acceptable like you know you cannot you know remove that.
>> Okay no problem. Still rather after reading if you have any doubt >> in the next session on Monday we can discuss the same and u if anything you feel that this is miss out and this is important or as a form in form of doubt also you can ask >> yeah ma'am because I wasn't sure that whether this chapter is completed or not I think it is officially completed now >> right >> if something is small a little bit is pending it will be covered in the next session otherwise it's majorly majorly I think it's covered Yes. No issues sir. Thank you.
>> So again the homework is you have to study from the chapter right. So maybe in the on Monday in the last 15 minutes we may take a quick quiz through app. So if you're ready all the student can write their answers and we will get all the answers. So you be ready with that uh preparation level so that we can play the quiz also. Okay.
>> Okay then. Uh if >> Thank you Hash. Yeah, would you like to add something?
>> No no no that's it. So yes ma'am.
>> So thank you Hash. Thank you dear students. Again I have already given you homework. You have to read the whole chapter. You have to make your notes and all the test your understanding and test your knowledge questions you have to complete right and if you have any doubt please feel free so that Monday we can have your doubts and uh proceed further.
So this way our section two will be complete and four to seven marks, four to six marks will be like in your hands if you are prepared well and this is really going to be interesting and uh Radha please call me what kind of issues you are facing when you're writing the answer because I think you have not practiced till now test your knowledge question. So test your knowledge question once you read and try to write.
If you find still any doubt we can definitely uh discuss in the class itself.
>> Sure ma'am today only chapter got completed so I didn't practice yet. So I will do it definitely. No issues. That's the reason you are having Thursday, Friday, Saturday and Sunday. All four days are with you. So that you can have ample of time and you can complete the chapter in best effective manner and in-depth studies required.
>> Yes ma'am. Do it. Yes. Thank you so much. Thank you.
>> Thank you. Thank you all.
>> Thank you. Thank you everyone.
Thank you. Thank you. Thank you.
>> Recording stopped.
>> Yes.
Related Videos

Drop the Loser Mentality
houseitlexi
180 views•2026-04-20

Arrête de louer en Floride Tu passes à côté d’une opportunité énorme !
thierryburtincfde
104 views•2026-04-21

SINGAPORE UNCOVER INVESTIGATION - Eco Ring Japan luxury goods buying centre in Singapore
PaulPlutaPrestige
5K views•2019-03-29

Humanizing Data | Stan Lee | TEDxUTAR
TEDx
472 views•2019-03-07

Mastering the Restaurant Industry - From Dive Bars to Michelin Stars
RestaurantRockstars
118 views•2025-04-06

Ep. 35: How to Send Lots of Satellites to Space (for Cheap)
crossingthevalley
188 views•2025-03-05

Ford CEO Jim Farley on the Future of the Essential Economy
markets
56K views•2025-10-04

Motivating Behavior
GreggU
5K views•2019-11-08
Trending

Playstation NO DISC/NO BUY Fight Is Over...
DavidJaffeGames
4K views•2026-07-23

Steam and Xbox Just Dropped The Hammer On PlayStation
OhNoItsAlexx
9K views•2026-07-23

Americans Confused in Australia for 17 Minutes Straight
IWrocker
17K views•2026-07-23

SuperBike Factory Has Gone... What's Next for the Motorcycle Industry?
thatbikersimon
11K views•2026-07-22