Feature story from Azerbaijan: Use of IT Auditing Skills Within Other Types of Audit

18.06.2026

At present, the impact of the accelerating implementation of digitalization initiatives in the public sector has begun to attract attention from various perspectives. The automation of work procedures, integration of information systems, digitization of document authentication, and the formation of large-scale data repositories against this background have become factors influencing qualitative changes in the performance of any entity. The growing importance of information technologies and the expanding scope of their application have also created new challenges within the framework of public sector auditing in Azerbaijan.

Within the scope of its mandate, the Supreme Audit Institution (SAI) of Azerbaijan – the Chamber of Accounts of the Republic of Azerbaijan (CoA) – has recognized the necessity of the digital transformation of auditing, established ambitious goals in its strategic documents, and proceeded toward practical implementation. In order to advance in this direction, it is important to recognize that IT audit skills are not merely technical competencies, but resources that should be utilized in modern financial, compliance, and performance audits. This is further reinforced by the fact that the functional activities of auditees, execution of financial transactions, and management processes are currently carried out through relevant information systems, cloud-based platforms, and mobile applications.

IT audit, or more broadly information systems (IS) audit, is a professional activity process accompanied by the accumulation of specific competencies. Among these competencies, particular importance is attached to the acquisition and processing of digital data, understanding access controls and user authorizations, elementary SQL and database querying techniques, concepts of automated workflows and continuous monitoring, and the fundamentals of cybersecurity for the assessment of control environments. Considering modern technological trends, it is also necessary to emphasize skills related to the use of artificial intelligence in this context. From this perspective, the Chamber of Accounts pays special attention to developing IS audit competencies among its staff in order to improve auditing.

Azerbaijan pic1

Within the framework of the three main types of audits accepted by the INTOSAI community, the Chamber of Accounts’ experience in applying IS audit skills covers all stages of the audit assignment. Using the planning stage as an example, the importance of applying IS audit skills becomes evident during the evaluation of information systems, considered an element of the auditee’s internal control system, and in identifying related control risks. At this stage, the contribution of information systems to mitigating inherent risks is assessed. For example, audit procedures are carried out to determine the overall level of digitization within the auditee, verify the functionality of electronic accounting systems, assess the organization of physical and logical access to systems, evaluate the accuracy of reporting functions, assess the protection and retention of data, and evaluate IT human resource capacity.

Regarding the audit execution stage, the application of IS audit skills may differ depending on the type of audit. In financial audits, hardware and software components of information systems (licenses, financial subscriptions, databases, etc.) are treated as tangible and intangible assets. While standard audit procedures are used to ensure that such assets are correctly and fully reflected in accounting records and financial statements, knowledge derived from their technical specifications undoubtedly provides additional advantages.

The use of IS skills by the Chamber of Accounts’ staff within the framework of performance audits is related to the audit subject matter. Broadly speaking, three types of IT-oriented performance audits are conducted: 1) Evaluation of the 3Es (efficiency, effectiveness, and economy) of State Programs related to the application of information and communication technologies; 2) Evaluation of the 3Es of the implementation of a particular information system; 3) Evaluation of an institution’s digitalization activities, including electronic services, from the perspective of the 3Es. In this regard, audits conducted by the Chamber of Accounts on the implementation of the State Program on G-cloud, the E-University information system, and the Electronic Government Development Center have positively contributed to the development of IS audit competencies.

In compliance audits, the auditee’s management, development, and maintenance of information systems are examined for compliance with legislation, internal regulations, and information security standards. Particular attention is paid to compliance with the requirements of the Laws “On Information, Informatization and Protection of Information,” “On Personal Data,” “On Electronic Signature and Electronic Document,” “On Electronic Commerce,” and “On Telecommunications,” as well as the “Rules for the Formation, Maintenance, Integration and Archiving of State Information Resources and Systems,” approved by the Presidential Decree of the Republic of Azerbaijan dated 12 September 2018.

In summary, the experience of the Chamber of Accounts demonstrates that the application of IS audit skills covers three main directions:

The first is analytical verification of data. During financial audits, data extracted from auditee’s budget accounts, accounting registers, and electronic document management systems are analyzed using CAATs (Computer Assisted Audit Techniques). For example, in compliance audits related to public procurement, IS skills are used to identify tender participants, automatically compare contract conditions, and detect abnormal price proposals.

The second is the assessment of general IT controls (ITGC). During the planning stage, audit teams evaluate the effectiveness of controls related to database management, network security, differentiation of access rights, change management, and operational continuity. As a result of this assessment, if general IT controls are found to be weak, reliance on application-level controls is reduced and additional audit procedures, such as full transaction reconstruction or manual verification, are introduced into the audit assignment.

The third is testing automated controls. In performance audits, the Chamber of Accounts tests application controls within government information systems, such as social payment systems and tax administration systems, including access controls, sequence checks, logical validations, and calculation algorithms. Based on selected samples, audit teams verify whether the system actually complies with programmed rules. For example, in compliance audits of payroll projects, controls such as the correctness of automatically applied tax rates and the blocking of payments to inactive employees are evaluated.

Azerbaijan pic2

 

The Chamber of Accounts’ experience demonstrates that the integration of IS audit skills significantly reduces audit risk. In particular, fully automated processes in the public sector, such as electronic budget systems, cannot be adequately covered through traditional “paper-based” verification methods. Therefore, the Chamber of Accounts continuously improves the methodological basis of IS auditing: guidelines based on international standards have been prepared, and training on CAATs software has been organized for audit staff.

Finally, the strategic objective of the Chamber of Accounts is to develop IS auditing not only as a technical verification tool, but also as a management advisory mechanism.

  Azerbaijan pic3

Recommendations in audit reports concerning identified IS weaknesses, such as data backup retention, monitoring unauthorized access, and software license compliance, contribute to strengthening the internal control culture within government institutions. Thus, through the systematic application of IS skills in financial, performance, and compliance audits, the Chamber of Accounts makes a significant contribution to enhancing transparency and accountability in public financial management.

The experience of the Chamber of Accounts of the Republic of Azerbaijan demonstrates that the rapid digitalization of the public sector necessitates the mandatory and systematic application of IT audit skills in auditing. In all three types of audits - financial, performance, and compliance - the use of CAATs, the assessment of general IT controls, and the testing of automated controls significantly reduce audit risk. A key prerequisite for integrating IS audit skills is the regular training of audit staff, the improvement of methodological frameworks based on international standards, and the incorporation of modern technologies such as artificial intelligence into the audit process. The strategic objective of the Chamber of Accounts is to develop IS auditing not only as a technical verification instrument, but also as a management advisory mechanism serving to strengthen the internal control culture within public institutions. Consequently, the systematic application of IS skills in financial, performance, and compliance audits by the Chamber of Accounts makes a substantial contribution to strengthening transparency, accountability, and the effectiveness of digital transformation in public financial management.