Literature Review |
Academic editor: Barbara Majoor
© 2025 Edouard van den Heuvel.
This is an open access article distributed under the terms of the Creative Commons Attribution License (CC BY-NC-ND 4.0), which permits to copy and distribute the article for non-commercial purposes, provided that the article is not altered or modified and the original author and source are credited.
Citation:
van den Heuvel E (2025) Evolution of IT auditing in a nutshell – journey towards a dynamic landscape. Maandblad voor Accountancy en Bedrijfseconomie 99(2): 73-83. https://doi.org/10.5117/mab.99.140994
|
This paper offers a comprehensive analysis of the evolution of IT auditing amidst the dynamic digital transformation landscape. It delves into the profound changes in IT auditing driven by historical, technological, regulatory, and professional factors. The study identifies and explores pivotal drivers that have influenced this evolution and its integration into modern audit practices. It concludes that the multifaceted development of IT auditing is the result of interconnected factors. Altogether, these drivers have contributed to the transformation and integration of IT auditing into contemporary audit practices, with the paper summarizing and explaining eight key drivers.
IT auditing, evolution, digital transformation, technology integration, auditing practices
In today’s tech-dependent economic environment, understanding the evolution of IT auditing is essential not just for operational efficiency but for securing IT systems and managing risks effectively. Knowing how IT auditing has changed is vital in today’s tech-focused economy. This knowledge helps improve how businesses run, protect IT-systems, and manage risk better. As IT auditing now extends beyond traditional assessments, it plays a pivotal role in optimizing audit methodologies, ensuring regulatory compliance, mitigating cybersecurity and business risks, and facilitating informed decision-making in an increasingly digital landscape.
The auditing profession, broadly defined as the independent and objective assessment of audit subjects—ranging from financial statements to business processes, organizational culture and behavior, quality management systems, IT systems, and more – has a longstanding history. This study aims to analyze the development of auditing from when the first literature was formulated, to better understand the background of auditing and the evolution into IT auditing. The word ‘appears to be derived from the Latin word ‘audire’, which means “to hear”.
Internal or operational auditing is the auditing of governance, business processes, management accounting by a dedicated function in the organization, reporting to the board and to the audit committee. External or financial auditing is the auditing of the annual financial statements by an independent external auditor. A specific breed of auditing, which has developed during the last half century, is the auditing of IT systems, in the broadest sense. This paper seeks to explore integrated IT auditing practices in an era marked by the pervasive influence of the digital transformation in our societies and the global economy. As a component of both internal and financial auditing, but also as an independent activity, IT auditing has increased in intensity and intricacy. This increase is inextricably tied to the integration of technology into the critical operations of contemporary organizations. Gartner reported in 2013 that IT expenditures surpassed US $3 billion annually, with organizations allocating an average of 4.4% of their operating expenses to IT (
The rapid integration of digital technologies into modern enterprises has reshaped business operations and governance, making IT auditing pivotal in ensuring the integrity, security, and reliability of IT systems (
To what extent has the practice of IT auditing evolved over time, from its inception during the early days of auditing to its current state, and what are the key factors that have influenced its development and adaptation?
In addition to analyzing the evolution of IT auditing practices, this study provides key drivers for future research grounded in a thorough review of existing literature. This research explores the evolution of IT auditing and proposes significant areas for future investigation after thoroughly examining existing literature on the subject. These recommendations are designed to assist IT specialists and others in enhancing their auditing techniques. This will help them manage risks better, make audits more accurate, and improve decision-making in a rapidly changing digital world. Nonetheless, several digital aspects, such as cloud computing, data privacy, and the integration of AI, require further focus. This shows that more research and improvement are needed in these areas.
This historical analysis enables us to understand, analyze and interpret the evolution of the function of audits whereby the change in expectations of society plays a significant role. The review will be divided into meaningful periods from before 1840 until the present.
This study provides a chronological literature study which represents a deliberate and purposeful decision aimed at providing a comprehensive and nuanced understanding of the subject matter. Organizing the literature review in a chronological order, allows for the exploration of the historical development and evolution of key concepts, theories, and methodologies relevant to the research domain. This study facilitates the identification of significant shifts, trends, and paradigmatic changes over time, enabling a more profound analysis of how the field of auditing has evolved and responded to various influences.
Furthermore, the chronological literature methodology provides a structured narrative that elucidates the progression of ideas, debates, and advancements within the field of IT auditing. It allows for tracing the lineage of theories and identifying pivotal moments. This approach not only enhances the clarity and coherence of the literature review but also highlights the intellectual genealogy that has contributed to the formation of the current state of knowledge. By engaging with the literature chronologically, this study not only positions itself within the broader historical discourse but also contributes to the academic community by offering a synthesized narrative that can enrich the collective understanding of the developments within IT auditing in the era of digital transformation.
Neither a historical development nor a chronological literature review has been properly described yet (
Ten [logistae]….and ten [euthuni].. are chosen by lot. Every single public officer must account to them. They have sole control over those subject to [examination].. they place their findings before the courts. Anyone against whom they prove embezzlement is convicted and fined by the court ten times the sum discovered stolen. Anyone whom the court on [their].. evidence convicts of corruption, is also fined ten times the amount of bribe. If he is found guilty of administrative error, they assess the sum involved, and he is fined that amount provided in this case that he pays it within nine months; otherwise the fine is doubled.
A similarity with Aristotle was found in the ancient Exchequer of England (1100–1135), where special audit officers were appointed to make sure that expenditure transactions and state revenue were properly accounted for. The person with the responsibility for examinations was known as the ‘auditor’. The role of such examinations was to detect and prevent fraudulent actions (
During the pre-industrial era, the commercial industry was characterized by a smaller scale of operations, primarily consisting of individually owned (family) companies, which resulted in a lack of hierarchical structures and reporting lines to managers or directors. The limited scale and decentralized nature of the pre-industrial commercial industry resulted in a relatively low demand for auditing practices, as the need for formalized oversight and control mechanisms was not as pronounced (
To summarize, auditing in the period pre-1840 was restricted to performing a detailed verification of every transaction, whereby the concept of sampling or testing was not part of the auditing procedure.
The industrial revolution during the period from 1840s to the 1920s made a significant change in the practice of auditing (
In 1844, the Joint Stock Companies Act was passed in the United Kingdom; this act was a direct response to socio-developments in the UK during that period and the desire to transform unincorporated associations with many members, typical for those times, into incorporated companies with joined stocks, which made legal proceedings easier. The Joint Stock Companies Act described that ‘directors shall cause the Books of the Company to be balanced, and a full and fair Balance Sheet to be made up’. Additionally, and most importantly, the act stipulated the involvement of auditors to check the accounts of the company. This notwithstanding, the requirement of a statutory audit and the annual presentation of the balance sheet to shareholders was only made mandatory in the 1900s under the UK Companies Act 1962 (
In the early years of this 1900s, the accountant was normally a company manager with responsibilities to ensure the proper use of the funds entrusted to him (
According to
To summarize, the role of auditors during the period from 1840s to the 1920s was mainly about fraud detection and in the assessment of completeness of transactions in the financial statements of companies.
During the period from the 1920s to the 1960s, economic development predominantly centered on the United Kingdom (UK), despite the period of the Great Depression around 1930 (
In the context of auditing, the primary objective during this era was to provide reliability and credibility to financial statements presented by company managers to their shareholders. A noticeable shift occurred from a focus on fraud detection towards enhancing the credibility of financial statements. This transformation is evident in successive editions of Montgomery’s Auditing text, which emphasized that the auditor’s objective went beyond detecting fraud and extended to verifying the fairness and accuracy of financial statements.
By 1939, the profession of auditing had witnessed rapid growth (
During this period, the concepts of materiality (
In 1949, the committee on auditing procedure conducted a study focused on the nature and characteristics of internal control. This study laid the foundation for the discussion of sampling techniques and materiality and provided a graphical representation of internal control within companies. The initial definition of internal control encompassed various measures within a business including safeguarding assets, ensuring the accuracy and reliability of the accounting data, promoting operational efficiency, and encourage adherence to managerial policies. This broad definition recognized that internal control extended beyond accounting and financial functions, and encompassed activities such as budgetary control, standard costs, training programs, and quality control (
The auditing profession underwent significant transformations during these years, with increased emphasis on internal control systems, sampling techniques, and objective assessments of financial transactions and company performance. Shareholders’ demand for a formal, objective view of their investments led to many reports and discussions on the internal control environment and the assessment of financial transactions. Various accountant professionals introduced their definitions and elaborated on characteristics of internal control, focusing on segregation of responsibilities, authorization systems, and appropriate duties and functions across organizational departments (
Around the 1960s, the development of auditing was highly influential, with companies beginning to highlight characteristics of their audit approaches. This marked the beginning of the reliance on internal control systems and sampling techniques in auditing practices. Audit evidence was increasingly gathered through an assessment from an objective third party via physical observations, reflecting a growing emphasis on reliability assurance as organizations became more accountable for their financial statements, both internally and externally (
During the period under consideration, characterized by optimism, idealism, and economic growth, significant developments occurred in technology and the complexity of companies. Auditors played a crucial role in enhancing the credibility of financial information in the 1970s. While Leung et al. (2004) suggested that the role of auditors remained largely unchanged during this period,
One notable shift in auditing during this time was a heightened focus on the stability of the internal control environment within companies. Auditors transitioned from primarily verifying transactions in the books to placing greater reliance on internal control systems. This shift was driven by the economic growth, which resulted in a substantial increase in the number of transactions. Auditors found it increasingly impractical to verify all transactions individually. Therefore, they began relying more on effective internal control systems. By around 1980, auditors were required to document internal controls and accounting systems, which reduced the need for extensive substantive testing when the internal control environment was effective (
The early 1970s witnessed another change in auditors’ approaches. The process of completing assessments was deemed too expensive and time-consuming, leading auditors to adopt cost-effective strategies. They started making greater use of analytical procedures, primarily driven by the introduction of risk-based auditing (
This era also marked the widespread integration of computers in business, particularly in accounting. By 1975, a substantial number of computers were in use, predominantly for accounting-related applications. The introduction of Electronic Data Processing (EDP) systems revolutionized how data was stored, retrieved, and controlled, resulting in debates within the literature. Auditors needed to understand these systems to comprehend underlying transaction calculations. The American Institute of Certified Public Accountants (AICPA) released guidelines in 1968, addressing EDP audits, leading to the development of EDP auditing practices (
EDP auditors formed the Electronic Data Processing Association (EDPA) to establish standards, procedures, and guidelines for EDP audits. In 1977, Control Objectives around EDP were published, later evolving into Control Objectives for Information and related Technology (CobiT). Consequently, rapid technological changes, information security and EDP concerns began to emerge in academic literature (Ramamoorti and Weidenmier 2003). However, EDP auditing was not yet a distinct profession but was discussed as a subtopic within internal or financial auditing.
Professional associations, in contrast, were proactive in addressing EDP issues. AICPA published guidance on Auditing and EDP in 1969, followed by the Statement of Auditing Standards (SAS) No. 3, which introduced the terms general and application controls. The EDP Auditors Association (EDPAA), now ISACA, was formalized in 1969. The Institute of Internal Auditors (IIA) also responded with a focus on EDP auditing in 1973. A few auditors explored combined assurance practices, hiring specialized auditors for different aspects (
The early integration of computer techniques led to the development of tools such as generalized audit software, EDP control questionnaires, Computer Assisted Audit Tools/Techniques (CAATs), and integrated test facilities (ITF). While some authors advocated for auditors to develop EDP audit skills, others expressed concerns about the cost of training, cooperation between EDP auditors and non-specialized auditors, and the reliability of IT. Ultimately, a consensus was reached that all auditors needed to update their skills to adapt to technological advancements (
To summarize, this era witnessed the rapid adoption of technology within auditing, with a focus on addressing the risks introduced by technological advancements. Auditors with various specializations collaborated to develop effective approaches to auditing. The profession of auditing was attractive due to the career possibilities it offered, whether in financial, internal, or EDP auditing. Governmental jurisdiction over the EDP auditing profession was not clearly defined, but the focus was primarily on how to conduct audits rather than determining who should perform them.
During the 1970s and 1980s, the applications of computers expanded beyond mere accounting tasks. They started to be utilized in other crucial sectors, such as production and inventory management. One of the most critical technological advances during this time was Material Requirements Planning (MRP), an early way to use computers to manage inventory (
The move to MRP led to the creation of Manufacturing Resource Planning (MRP II). This improved system included planning when to make products, managing the workspace, and keeping track of supplies, influencing almost every part of a company. For IT auditors, this was the first time dealing with checking systems that weren’t just about money data (
The IIA expressed interest in the EDP audit field, suggesting its integration into their working domain. The EDPAA responded by asserting its jurisdiction and providing the Certified Information Systems Auditor (CISA) certification. The IIA, however, failed to secure a prominent leadership role in EDP audit, leading to EDPAA’s prominence in this complex field (Ramamoorti and Weidenmier 2003).
As technology continued to advance during the mid-1970s, there was a growing need for professional guidance related to technology and EDP auditing. Technology development often outpaced its implementation, leading to debates and discussions in the literature. Foreign Corrupt Practices Act scandals contributed to the maturation and growth of EDP as an audit profession (
Towards the end of this period, corporate financial scandals, such as the banking crisis of 1974–75, were marked by accounting manipulation facilitated by the incorporation of IT into business processes. These scandals led to further legislative scrutiny of the EDP profession.
To summarize, this period witnessed significant technological advancements and the expansion of auditing beyond accounting. It marked the growth of EDP as an audit profession, increased collaboration between different types of auditors, and the development of professional standards and certifications. The era was also characterized by corporate scandals that highlighted the importance of internal control and EDP audit in financial reporting and accountability.
During the period spanning from the early 1980s to the late 1990s, significant environmental factors led to the professional transformation of the Electronic Data Processing (EDP) profession. Developments during this period included the establishment of the Committee of Sponsoring Organizations (COSO) through a joint initiative involving AICPA, IIA, and IMA. This collaboration aimed to enhance guidance, reduce fraudulent financial statements, and improve financial reporting quality. Additionally, professional organizations such as the Association of Certified Fraud Examiners (ACFE) which emerged in 1988, contributed to updated guidance on internal control.
Technological growth and adoption, coupled with legislative changes like the Federal Sentencing Guidelines for Organizations (FSGO), incentivized organizations to bolster their internal auditing frameworks. The introduction of the IBM AS/400 in 1988 marked a shift in the use of computers, extending beyond organizational settings to private use. Moreover, the National Science Foundation’s endorsement of TCP/IP in 1992 facilitated the commercial use of the Internet, leading to greater decentralization of data processing (
The integration of technology into organizations prompted the need for systems and automation, resulting in the emergence of Enterprise Resource Planning (ERP) systems like SAP. This period also witnessed a shift in terminology from EDP to IT (ISCA 2019)), reflecting a focus on technology-related aspects. The EDPAA transformed into the Information Systems and Control Association (ISACA), aligning itself with the evolving landscape.
Academic research on EDP was initially limited but gained momentum in the late 1980s with the introduction of research journals like The Journal of Information Systems and the Managerial Auditing Journal (
The role of IT auditors and their skills underwent examination, with studies indicating that auditors were more efficient, particularly in IT and general control domains. Meanwhile, a growing reliance on advanced computer auditing tools as well as the provision of advisory services by auditors became more prevalent (
The time from the 1980s to the late 1990s was marked by fast improvements in technology, especially with computers. During this time, Mainframe computers became popular, bringing all IT work together in one place. Data Centers were created and became the main hub for business computing. The development of Electronic Data Processing (EDP) auditing during this period significantly changed IT auditors’ jobs (
Mainframe audits looked at how well these extensive computer systems worked and how secure they were since many organizations relied on them for essential tasks. Data Center audits, however, focused on the rules and protections in the data centre, including who could enter, plans for recovering from disasters and making sure the systems were always available (Treasury Inspector General for Tax Administration , 2022). IT auditors needed to learn special skills in building systems, keeping data safe and accurate, and following security rules. This change to more detailed audits focusing on specific systems meant that auditors needed to stay updated with new technology and how businesses increasingly depend on digital systems.
As IT grew in new business areas, ensuring rules were followed and accurate data became very important for auditors. During this time, a significant change happened. Auditors started to do more than just check financial information; they also had to ensure the computer systems that managed this information were safe and working well.
This period in the field of auditing and IT can be divided into two distinct halves, each marked by its unique characteristics and challenges. The first half of this period was influenced significantly by the Sarbanes-Oxley Act (SOx). Particularly Section 404, which became effective later in 2004, placed an emphasis on the importance of internal controls and IT auditing. Technological changes were also significant during this period, with a significant increase in IT spending per worker between 1995–2005, resulting in increased productivity for IT auditors (
The 1990s to the 2010s was a transformative period in IT auditing due to the rapid digitization of business operations and the rise of outsourcing. During this time, most organizations began outsourcing non-core IT functions like software development, help desk support, and infrastructure maintenance to reduce costs and focus on their core competencies (
At the same time, the increasing complexity of IT systems, particularly with the widespread adoption of Enterprise Resource Planning (ERP) systems, demanded new auditing approaches. ERP systems like SAP, Oracle, and PeopleSoft integrated various business processes into a single unified system, including finance, supply chain management, human resources, and customer relationship management (
The complexity of ERP systems and their centrality to business operations meant IT auditors needed to collaborate more closely with business stakeholders, management, and technical teams to ensure that controls were adequately designed and implemented. Additionally, as organizations became more dependent on these integrated systems, the need for IT governance frameworks, such as COBIT (Control Objectives for Information and Related Technologies) and ISO/IEC 27001, grew (
The growing prevalence of cybersecurity concerns and regulatory compliance (e.g., SOx, GDPR) further expanded the role of IT auditors. Cyber risks, such as data breaches, malware attacks, and system vulnerabilities, became top priorities, requiring auditors to focus on network security, access controls, encryption protocols, and incident response mechanisms (
Regulators responded to these changes by updating standards and introducing new legislation, such as the Health Insurance Portability and Accountability Act (HIPAA) and the Gramm-Leach-Bliley Act, to address information privacy and security concerns. Professional associations like ISACA and AICPA also issued updates to frameworks and certifications, reflecting the evolving landscape of IT auditing.
The second half of this era saw a significant shift in auditors’ approach due to SOx Section 404, which required CEOs and CFOs to certify the effectiveness of internal controls over financial reporting. This led to increased attention to internal control systems and a closer relationship between executive boards and internal audit functions.
The demand for IT auditors has risen as the importance of integrating IT into the audit process has become more widely recognized. Integrated auditing—an approach that merges IT and financial audits—has gained prominence, creating challenges in distinguishing between general IT controls and application-specific controls. This convergence necessitates closer collaboration between general IT personnel and specialized auditors (
Professional association membership trends showed substantial growth in organizations like NOREA (NL) and ISACA, highlighting an increasing importance of certifications and expertise in IT auditing and control.
Overall, this phase significant upheaval in the accounting and auditing profession, driven by technological advancements, regulatory changes, and a growing awareness of the importance of IT auditing and IT Security and Information Security. It set the stage for the continued evolution of the field in subsequent years.
Changes in the environment have significantly affected how IT audits are done. The fast growth of technology businesses use has made IT audit jobs more extensive and complicated (
Implementing the Sarbanes-Oxley Act (SOx) led to significant changes in traditional accounting roles as organizations began adopting ERP systems. This created a need for skills in IT auditing (
Professional associations like ISACA and the Institute of Internal Auditors (IIA) responded to the changing landscape by providing guidelines, introducing new certifications, and addressing the need for IT audit skills (
Research during this era focused on the impact of IT on internal audits, the detection of material weaknesses, and the relationship between IT integration and control deficiencies (
During this time, it was essential for IT auditors to have skills related to technology. With the rise of outsourcing, SAS 70 audits gained more significant importance for businesses. IT auditors were vital in checking the IT services provided by other companies. This change made people see IT auditors as necessary for financial audits and helping manage technology-related risks. The connection with information security and risk management gave IT auditors a more active and independent role.
Since 2010, quickly changing technology has changed how IT audits work, bringing new and complex challenges. New technologies like cloud computing, artificial intelligence (AI), the Internet of Things (IoT), and machine learning offer new chances and some risks. These risks include communication problems and reliance on vendors because critical IT services are outsourced (
IT auditors find themselves grappling with this constantly shifting technological landscape, which is further compounded by evolving regulatory and professional guidelines. These guidelines lack standardization and are subject to frequent revisions by organizations such as COSO, ISACA, and the IIA. Professional associations have attempted to collaborate to address these challenges, but the practical benefits of such collaborations have been limited (
Studies have shown that technology significantly affects auditors’ work, highlighting the need to understand IT to grow in their careers (
Reports from professional groups show that more people are joining IT auditing organizations. This indicates that technology is advancing and that more people understand how crucial IT auditing is. This trend suggests that more people in the professional world see IT auditing as an essential field. Many organizations now provide unique resources and certifications highlighting how established IT auditing has become as a profession. Refer to Table
Table
1995 | 2005 | 2009 | 2015 | 2024 | |
---|---|---|---|---|---|
IIA | 60,000 | 115,000 | 160,000 | 182,000 | 230,000 |
ISACA | 15,000 | 60,000 | 86,000 | 100,000 | 170,000 |
AICPA | n/a | n/a | 343,000 | 394,000 | 698,000 |
IMA | n/a | n/a | 60,000 | 65,000 | 140,000 |
NOREA (NL) | ± 350 | ± 1,000 | 1,809 (2010) | 1,686 | 1,962 |
IIA (NL) | Not known | 1.427 | 2,353 | Not known | 2,918 |
NBA, prior NIVRA/NOvAA (NL) | 13,848 | 20,550 (2006) | 20,895 | 21,290 | 26,010 (inc trainees) |
In the Netherlands, the professional associations NOREA and NBA (formerly NIVRA/NOvAA NL) present an intriguing narrative. Around the year 2010, NOREA’s membership peaked at 1,809, before stabilizing, with the NBA showing a similar trend of relative constancy in its membership figures. This stabilization within the Dutch professional landscape around 2010 is particularly noteworthy, marking a point of equilibrium and maturity in these associations’ memberships. The collective data showcased in this table serve as a valuable academic resource, shedding light on the growth trajectories and noteworthy stabilization of professional membership associations, both on an international scale and in the Netherlands. This insight into the evolving composition of these associations over time contributes to a deeper understanding of their respective fields and the broader context in which they operate. In annual reports and membership meetings of the professional associations, it is being argued that the stabilization of members is due to deregistration caused by pension-related considerations.
The journey of IT auditing reflects a dynamic evolution from a support role for financial audits to a mature and specialized profession. The field of IT auditing has changed a lot over time. It started mainly helping with financial audits and has now developed into a specialized and essential profession. This change, caused by improvements in technology, new rules, and the rise of digital problems, has turned IT auditing into a diverse area that needs skills in security, managing risks, and understanding governance. As technology keeps improving, IT auditors will probably take on more responsibilities. Their job will become even more critical in helping organizations stay solid and responsible as they go through changes in the digital world. This development highlights that IT auditing is valuable, not just for finances, and is vital for managing risks in today’s organizations.
Looking forward, the transformative trends observed over the past decades are expected to persist, propelling ongoing research and discussions within the accounting profession and professional associations. The evolution of IT auditing and control extends beyond traditional boundaries, impacting a broader range of domains and necessitating a proactive and adaptable approach by auditors, practitioners, and professional associations.
The development and adaptation of IT auditing have been influenced by a multitude of interconnected factors spanning historical, technological, regulatory, and professional dimensions. The evolution of IT auditing has been shaped by the following key drivers, which have collectively contributed to the transformation and integration of IT auditing into contemporary auditing practices.
In conclusion, the development and adaptation of IT auditing have been shaped by a confluence of historical, technological, regulatory, and professional factors. These interconnected factors have propelled IT auditing from its early origins as a mechanism for transaction verification to a sophisticated discipline that addresses the challenges and opportunities presented by modern technology and the ever-changing business environment. The evolution of IT auditing is a testament to dynamic interplay between historical foundations, technological innovation, regulatory imperatives, and the proactive response of auditing professionals to the demands of their times.
Drs. Ing. E.S. van den Heuvel RE – Edouard, PhD Candidate, University of Amsterdam (Amsterdam Business School); Executive MSc in Auditing.