Research Article
Development of a Decision Support System for EDI Auditing
Published: January 1998 · Vol. 27, No. 2 · pp. 465-493
Full Text
Abstract
This study developed a decision support system for EDI (Electronic Data Interchange) auditing. The decision support system for EDI auditing is based on a database system that stores data on controls, risks, company profiles, and test items. For system development, logical design was conducted through E-R (Entity-Relationship) and DFD (Data Flow Diagram) analysis. The system was developed using the database package FoxPro. Through this system, auditors can retrieve or store necessary test results, and can easily look up required controls or risk levels through cross-referencing of controls, risks, and company information. When the checklists of necessary controls, risks, and test items differ for each company, this system allows for the input and storage of different checklists for each respective company. This system is applicable not only to EDI auditing but also to general EDP (Electronic Data Processing) auditing. In an EDI environment, traditional audit trails are absent, making traditional approaches to EDI auditing inadequate. At a time when domestic research in the field of EDP audit systems is virtually nonexistent, this study attempted to develop a system that supports EDI auditing, and it is hoped that research in this area will be invigorated going forward. This study can contribute to enhancing the efficiency of EDI security and auditing operations and to effectively addressing risks associated with EDI. Furthermore, by building such security and auditing techniques and control models into a knowledge base, the system can support the selection of optimal security controls and auditing techniques by considering cost-benefit analysis, efficiency, company policies, and legal issues when multiple control measures are available for actual risk exposure situations.
