CPE

An Auditor’s Responsibility for Cybersecurity Risks

7 min read
cybersecurity-risks-listing-image

Cybersecurity goes beyond IT as it's a critical factor in financial reporting and audit quality. Auditors have an increasing responsibility to understand how risks and incidents can affect financial reporting and what to do if they should occur. We're addressing your responsibility to your organization's cybersecurity risks and incidents, what's not your responsibility, and information into best practices. 

Summary

Learn how auditors distinguish between cybersecurity risks (potential threats) and incidents (actual events) and evaluate their impact on financial reporting and internal controls. It reinforces that auditors focus on assessing risk and financial impact—not preventing or managing cybersecurity.

Start earning CPE and CE credits with a FREE course!

 

An Auditor's Responsibility for Cybersecurity Risks

As cybersecurity threats continue to grow in frequency and complexity, auditors are increasingly need to understand how cybersecurity risks (potential threats) and cybersecurity incidents (realized events) may affect an organization’s financial statements, related disclosures, and internal control over financial reporting (ICFR). 

However, an auditor’s responsibility does not include managing, designing, or implementing cybersecurity programs. Instead, the auditor’s role is to assess how cyber-related risks and incidents affect the audit, with particular attention to financial reporting and ICFR.

Understanding the Scope of Responsibility

Auditors are not cybersecurity professionals hired to secure an organization’s systems. Their responsibility is more narrowly defined by auditing standards and focused on the areas that affect financial reporting. 

Specifically, auditors are required to understand how the organization uses IT systems and identify cybersecurity risks arising from the use of technology. These risks represent potential vulnerabilities or threats that could lead to errors, fraud, or disruption in financial reporting. 

They must also be able to evaluate the design and effectiveness of controls related to those risks and assess whether cybersecurity risks could lead to material misstatements in the financial statements or a deficiency in ICFR. 

When a cybersecurity incident, such as a data breach, ransomware attack, or unauthorized system access, does occur, the auditor’s responsibility shifts from risk identification to impact evaluation. The auditor must determine how the incident affects financial reporting, audit evidence, and disclosures.

Non-Audit Engagements Related to Cyber Security

In some cases, auditors may be engaged to provide broader assurance on cybersecurity risk management programs through frameworks such as SOC for Cybersecurity, developed by the AICPA. 

These engagements are distinct from a financial statement audit. They focus on evaluating how an organization identifies, manages, and responds to cybersecurity risks, rather than assessing the financial reporting impact of specific incidents. 

While separate from a financial statement audit, these services reflect the growing role of auditors in providing assurance over cybersecurity-related risks.

Why Cybersecurity Audits Matter More Than Ever

Cybersecurity doesn’t just belong to IT. It is both a risk issue (what could go wrong) and an incident issue (what has gone wrong). From an audit perspective, both dimensions matter because each can affect financial reporting, disclosure, and internal control over financial reporting. 

As a result, auditors must take a proactive, risk-based approach. This includes: 

  • Integrating cyber-related risks into audit planning 
  • Aligning IT risk assessment with financial reporting objectives 
  • Evaluating how well organizations prevent, detect, and respond to incidents within their control environment


What Auditors Are Not Responsible For

To avoid misconceptions, it’s equally important to understand what auditors do not do. Auditors are not responsible for:

  • Designing or implementing cybersecurity programs 
  • Preventing cyberattacks 
  • Monitoring systems in real time 
  • Guaranteeing that no breaches occur 

Cybersecurity ownership ultimately resides with management. The auditor’s role is to provide independent assurance, not operational oversight.

Get 30 AI prompts and use cases to streamline your workflows! 

 

Assessing Cybersecurity Risks as Part of Audit Risk

Cybersecurity-related risks are incorporated into the broader audit risk assessment process. Auditors must consider how threats, such as unauthorized access, system vulnerabilities, or phishing attacks could compromise financial records, allow unauthorized changes to financial data, or disrupt systems that support financial reporting. 

Auditing standards require auditors to identify and assess risks of material misstatement, including those arising from IT vulnerabilities or cybersecurity threats.

Evaluating IT Systems and Controls

A key part of the auditor’s responsibility is gaining an understanding of the entity’s IT environment and the role it plays in financial reporting. Auditors must: 

  • Understand how transactions flow through systems 
  • Identify which applications and systems are important to financial reporting 
  • Evaluate general IT controls (such as access controls, system changes, and data integrity processes) 

For example, if a company’s financial data is stored in an ERP system, auditors will assess whether access to that system is appropriately restricted, changes to system configurations are properly controlled, and data is protected from unauthorized modification. Weaknesses in these areas can increase the likelihood that a cybersecurity risk could materialize into an incident.

Testing Internal Controls Relevant to Financial Reporting

Auditors also evaluate internal controls that are designed to mitigate cybersecurity-related risks when those controls are relevant to financial reporting. 

These controls may include: 

  • Access controls over financial systems and data 
  • Change management controls over system configurations and programs 
  • Logging and monitoring controls relevant to the integrity of financial information 
  • Incident response procedures that help preserve data and support continuity of financial reporting 

By testing these controls, auditors provide assurance that systems supporting financial reporting are functioning as intended. Strong IT controls are critical because they help ensure the accuracy, integrity, and reliability of information used in financial reporting and audit procedures

Responding to Identified Cyber Risks

When auditors identify cybersecurity risks, they focus on prevention and likelihood. Their response typically includes:

  • Assessing whether controls are properly designed and implemented 
  • Testing the effectiveness of those controls 
  • Adjusting the audit approach if risk levels are higher than expected 

For example, if weak access controls are identified, the auditor may increase substantive testing due to higher risk of unauthorized changes.

Responding to Identified Cyber Incidents

When a cybersecurity incident has occurred, the auditor’s focus shifts to impact and evidence. This includes evaluating whether: 

  • Financial data was altered, destroyed, or made unavailable 
  • Internal controls were bypassed or failed 
  • Financial statement balances or disclosures are affected 
  • Additional audit procedures are necessary 

For example, following a ransomware attack, an auditor would assess whether financial records were compromised, whether backup data is reliable, and whether disclosures about the incident are required. 

The focus is always on how the incident affects financial reporting and audit conclusions—not on remediating the issue itself.

Learn More with CPE Courses from Becker

Build your audit skills and learn more about cybersecurity and emerging technology with these CPE courses

Icon of laptop computer illustration

Unlock Unlimited CPE with a Prime Subscription

Becker makes it easy to meet your CPE requirements, gain new skills, and stay aware of critical updates and changes in the industry! 

With Prime, you can access over 1,700 courses for a full year and earn unlimited CPE credits. 

Share

FacebookLinkedinXEmail
CPE FREE COURSE
Sidebar CTA
Browse our CPE Offerings

Now Leaving Becker.com

You are leaving the Becker.com website. Once you click “continue,” you will be brought to a third-party website. Please be aware, the privacy policy may differ on the third-party website. Adtalem Global Education is not responsible for the security, contents and accuracy of any information provided on the third-party website. Note that the website may still be a third-party website even the format is similar to the Becker.com website.

Continue