AN AUDIT RISK MODEL FOR IT AUDIT ECOSYSTEMS AND DIGITAL TRANSFORMATION (DX) DECISION MAKING

Sampson Anomah,Boadu Ayeboafo,Maurice Aduamoah
DOI: https://doi.org/10.1080/07366981.2021.1930643
2021-08-03
EDPACS
Abstract:Strategy has become indispensable for survival in a contemporary business environment. The role of IT audit or assurance review is now viewed from two perspectives – first, as an independent assessor and, second, as a consulting expert advisor. IT auditors are, therefore, expected to plan their reviews such that their scarce IT audit resources will be put to efficient use and at the same time effectively provide advisory opinions on IT governance and strategies to leverage business executives' function towards the achievement of their specified business objectives. The study used the design science approach using the audit risk model as a conceptual model to develop an objective approach to identify the quality of risk inherent in a digital transformation (dx) project. A major design output was that an Audit Risk model for IT (IAR) in the context of digital transformation is calculated as IAR = PR × SR × RR, where was PR is Primary Risk, SR is Secondary Risk and RR is Residual Risk. Also, Return on IT investment (ROI) has an inverse correlation with PR and was relevant in estimating the PR given IAR as equivalent to ROI. A mixture of a multiple case study approach, quasi experimentation and the Delphi method was used to evaluate the model. The Delphi approach used produced an overall significant value in evaluators' understanding of the usefulness, ease of use and acceptability of the model as an IS/IT audit risk model for the assessment of digital risks and strategies of different organisations. The ICC which was used to measure the Intra-Class Correlation (ICC) which is the reliability of agreement among the participating evaluators showed an average ICC of 0.90 with a significant p-value of 0.000 to prove the validity of the model. The study contributes to practice because it provides a tool to assist IT audit practitioners and other business IT assessors to reduce the risk of subjectivity in the allocation of IT audit resources at the planning stage of the audit or assessment.
What problem does this paper attempt to address?