Internal Auditors’ Perceptions of Information Technology-Related Risks: A Comparison Between General Auditors and Information Technology Auditors

A.L.P. Nuijten*, Mark Keil, Bert Zwiers

*Corresponding author for this work

Research output: Contribution to journalArticleAcademicpeer-review

Abstract

With the growing role of information technology (IT), many organizations have incorporated IT governance practices that include keeping executives apprised of IT risks. To perform this function, organizations rely upon their internal audit staff to obtain an independent evaluation of IT risks. Although both general and IT auditors are involved in assessing IT risks, they may not be equally adept at identifying such risks. We draw on the expert versus nonexpert perspective to understand how general and IT auditors perceive IT risks differently. Through a quasi experiment with 70 internal auditors of a financial institution, we found that general auditors perceived IT risks to be lower than their IT audit colleagues. We also found that personal IT risk preferences influenced the level of IT risks that general auditors perceived. Personal IT risk preferences did not affect the risk perceptions of IT auditors. Implications for both research and practice are discussed.

Original languageEnglish
Pages (from-to)67-83
Number of pages17
JournalJournal of Information Systems
Volume37
Issue number1
Early online date22 Nov 2022
DOIs
Publication statusPublished - Mar 2023

Keywords

  • Risk Perception
  • Expertise
  • Risk Propensity
  • IT Governance
  • IT Audit
  • Internal Audit
  • expertise
  • risk propensity
  • internal audit
  • IT governance
  • IT audit
  • risk perception

Fingerprint

Dive into the research topics of 'Internal Auditors’ Perceptions of Information Technology-Related Risks: A Comparison Between General Auditors and Information Technology Auditors'. Together they form a unique fingerprint.

Cite this