Para 3.22.46 — MSO (Audit)
Original Rule Text
3.22.46 The auditor should ensure that there are adequate plans and arrangements to resume processing in the event of failure of computer operations. The degree of continuity planning will depend on the size of the IT department and the dependence on computer processing. A significant and prolonged loss of IT capability in a mission
critical system may increase the risk of the financial statements being unavailable or materially misstated. Disaster recovery planning for IT facilities should be treated as one element of an organisation’s overall service or business continuity plan.
What This Means
The auditor must verify that government organisations have adequate plans to resume computer processing if systems fail. The level of continuity planning should match the organisation's size and dependence on computers. A prolonged loss of IT capability in a critical system could mean financial statements are unavailable or contain material errors. Disaster recovery for IT should be part of the organisation's overall business continuity plan.
This explanation was generated with AI assistance for educational purposes. Always refer to the official gazette notification for authoritative text.
Key Points
- 1Adequate plans must exist to resume processing after a computer system failure
- 2The degree of continuity planning should match the organisation's IT dependency
- 3Prolonged IT outages in critical systems risk financial statements being unavailable or materially misstated
- 4IT disaster recovery should be part of the overall business continuity plan
- 5Auditors must verify these plans are in place and adequate
Practical Example
A government Pay and Accounts Office processes salary for 10,000 employees using a computerised payroll system. Their service continuity plan specifies that if the primary server fails, a backup server at another location can take over within 4 hours. The plan identifies critical processing deadlines (salary must be processed by the 25th of each month) and includes alternative procedures for emergency manual processing if both servers fail during the pay window.
This explanation was generated with AI assistance for educational purposes. Always refer to the official gazette notification for authoritative text.
Frequently Asked Questions
Why is service continuity planning important for audit?▼
How does IT disaster recovery differ from overall business continuity?▼
This explanation was generated with AI assistance for educational purposes. Always refer to the official gazette notification for authoritative text.