{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,6]],"date-time":"2026-01-06T13:14:30Z","timestamp":1767705270836,"version":"3.41.2"},"reference-count":46,"publisher":"Emerald","issue":"6","license":[{"start":{"date-parts":[[2011,10,18]],"date-time":"2011-10-18T00:00:00Z","timestamp":1318896000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.emerald.com\/insight\/site-policies"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2011,10,18]]},"abstract":"<jats:sec><jats:title content-type=\"abstract-heading\">Purpose<\/jats:title><jats:p>The purpose of this article is to provide a selective and comprehensive literature review based on previous research within auditing and enterprise systems (ES). This is done to identify research gaps, propose directions for future research and guide researchers and practitioners on how to better synthesize these two areas. Interaction between ES and auditing is in need of more academic research and practical investigation, which may lead to the development of better solutions, guidelines and frameworks.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Design\/methodology\/approach<\/jats:title><jats:p>A total of 31 academic studies from 2000 to 2010 were included in this study. After reading these studies, different areas had been selected and were addressed in five categories: the future of audit in ES environment, modern audit tools and techniques, changes of auditors' role, differences in perceptions between financial auditors and IT auditors, ERP and compliance with regulations.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Findings<\/jats:title><jats:p>ES implementation results in audit process reengineering and increases the need of continuous monitoring of transactions. The presence of IT auditors becomes critical, while financial auditors are asked to enhance their skills in order to be able to conduct effective audit tests. Modern audit tools and techniques must be used so that internal control processes will be appropriate for an ES.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Research limitations\/implications<\/jats:title><jats:p>It is not an exhaustive list and some relevant publications might have been overlooked. Much literature has been scanned by reading the title only. In order to conduct a comprehensive review the topical focus was kept relatively narrow on auditing and ES.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Practical implications<\/jats:title><jats:p>Researchers and practitioners must take into consideration the interaction between ES and auditing in order to advance research in this area. Companies must understand the changes that occur in the audit procedure due to ES implementation, so that they will design efficient audit tests and auditors must enhance their knowledge in order to be able to conduct these tests effectively.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Originality\/value<\/jats:title><jats:p>This study uncovers and classifies current research within auditing and ES (focusing mostly on ERP systems).<\/jats:p><\/jats:sec>","DOI":"10.1108\/17410391111166549","type":"journal-article","created":{"date-parts":[[2011,10,29]],"date-time":"2011-10-29T07:14:21Z","timestamp":1319872461000},"page":"494-519","source":"Crossref","is-referenced-by-count":17,"title":["Auditing in enterprise system environment: a synthesis"],"prefix":"10.1108","volume":"24","author":[{"given":"Alexandra","family":"Kanellou","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Charalambos","family":"Spathis","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"140","reference":[{"key":"key2022021220100635600_b1","doi-asserted-by":"crossref","unstructured":"Ajzen, I. (1991), \u201cThe theory of planned behavior\u201d, Organizational Behavior and Human Decision Processes, Vol. 50 No. 2, pp. 179\u2010211.","DOI":"10.1016\/0749-5978(91)90020-T"},{"key":"key2022021220100635600_b3","doi-asserted-by":"crossref","unstructured":"Alles, M.G., Kogan, A. and Vasarhelyi, M.A. (2008), \u201cPutting continuous auditing theory into practice: lessons from two pilot implementations\u201d, Journal of Information Systems, Vol. 22 No. 2, pp. 195\u2010214.","DOI":"10.2308\/jis.2008.22.2.195"},{"key":"key2022021220100635600_b2","doi-asserted-by":"crossref","unstructured":"Alles, M.G., Brennan, G., Kogan, A. and Vasarhelyi, M.A. (2006), \u201cContinuous monitoring of business process controls: a pilot implementation of a continuous auditing system at Siemens\u201d, International Journal of Accounting Information Systems, Vol. 7, pp. 137\u201061.","DOI":"10.1016\/j.accinf.2005.10.004"},{"key":"key2022021220100635600_b4","unstructured":"American Institute of Certified Public Accountants (AICPA) (2001), Statement on Auditing Standards No. 94: The Effect of Information Technology on the Auditor's Consideration of Internal Control in a Financial Statement Audit, AICPA, New York, NY."},{"key":"key2022021220100635600_b5","unstructured":"Bae, B. and Ashcroft, P. (2004), \u201cImplementation of ERP systems: accounting and auditing implications\u201d, Information Systems Control Journal, Vol. 5, pp. 43\u20108."},{"key":"key2022021220100635600_b6","doi-asserted-by":"crossref","unstructured":"Best, P. (2000), \u201cAuditing SAP R\/3 \u2010 control risk assessment\u201d, Australian Accounting Review, Vol. 10 No. 3, pp. 31\u201042.","DOI":"10.1111\/j.1835-2561.2000.tb00068.x"},{"key":"key2022021220100635600_b7","doi-asserted-by":"crossref","unstructured":"Best, P., Rikhardsson, P. and Toleman, M. (2009), \u201cContinuous fraud detection in enterprise systems through audit trail analysis\u201d, Journal of Digital Forensics, Security and Law, Vol. 4 No. 1, pp. 39\u201060.","DOI":"10.15394\/jdfsl.2009.1053"},{"key":"key2022021220100635600_b8","doi-asserted-by":"crossref","unstructured":"Brazel, J.F. (2005), \u201cA measure of perceived auditor ERP systems expertise. Development, assessment and uses\u201d, Managerial Auditing Journal, Vol. 20 No. 6, pp. 619\u201031.","DOI":"10.1108\/02686900510606100"},{"key":"key2022021220100635600_b9","doi-asserted-by":"crossref","unstructured":"Brazel, J.F. and Agoglia, C.P. (2007), \u201cAn examination of auditor planning judgements in a complex accounting information system environment\u201d, Contemporary Accounting Research, Vol. 24 No. 4, pp. 1059\u201083.","DOI":"10.1506\/car.24.4.1"},{"key":"key2022021220100635600_b10","doi-asserted-by":"crossref","unstructured":"Brown, W. and Nasuti, F. (2005), \u201cWhat ERP systems can tell us about Sarbanes\u2010Oxley\u201d, Information Management and Computer Security, Vol. 13 No. 4, pp. 311\u201027.","DOI":"10.1108\/09685220510614434"},{"key":"key2022021220100635600_b11","doi-asserted-by":"crossref","unstructured":"Burnaby, P. and Hass, S. (2009), \u201cA summary of the global Common Body of Knowledge 2006 (CBOK) study in internal auditing\u201d, Managerial Auditing Journal, Vol. 24 No. 9, pp. 813\u201034.","DOI":"10.1108\/02686900910994782"},{"key":"key2022021220100635600_b12","unstructured":"Cerullo, M.V. and Cerullo, M.J. (2003), \u201cImpact of SAS 94 on computer audit techniques\u201d, Information Systems Control Journal, Vol. 1, available at: www.isaca.org."},{"key":"key2022021220100635600_b13","doi-asserted-by":"crossref","unstructured":"Chang, S.I., Wu, C.C. and Chang, I.C. (2008), \u201cThe development of a computer auditing system sufficient for Sarbanes\u2010Oxley Section 404 \u2013 a study on the purchasing and expenditure cycle of the ERP system\u201d, Information Systems Management, Vol. 25, pp. 211\u201029.","DOI":"10.1080\/10580530802151145"},{"key":"key2022021220100635600_b14","doi-asserted-by":"crossref","unstructured":"Chen, J.R. (2009), \u201cAn exploratory study of alignment ERP implementation and organizational development activities in a newly established firm\u201d, Journal of Enterprise Information Management, Vol. 22 No. 3, pp. 298\u2010316.","DOI":"10.1108\/17410390910949733"},{"key":"key2022021220100635600_b15","unstructured":"Coppers, C. and Lybrand, L.L.P. (2002), Security, Audit and Control Features SAP R\/3: A Technical and Risk Management Reference Guide, IT Governance Institute, Rolling Meadows, IL."},{"key":"key2022021220100635600_b16","doi-asserted-by":"crossref","unstructured":"Curtis, M.B., Jenkins, J.G., Bedard, J.C. and Donald, R.D. (2009), \u201cAuditors' training and proficiency in information systems: a research synthesis\u201d, Journal of Information Systems, Vol. 23 No. 1, pp. 79\u201096.","DOI":"10.2308\/jis.2009.23.1.79"},{"key":"key2022021220100635600_b17","doi-asserted-by":"crossref","unstructured":"Debreceny, R.S., Gray, G.L., Ng, J.J.J., Lee, K.S.P. and Yau, W.F. (2005), \u201cEmbedded audit modules in enterprise resource planning systems: implementation and functionality\u201d, Journal of Information Systems, Vol. 19 No. 2, pp. 7\u201027.","DOI":"10.2308\/jis.2005.19.2.7"},{"key":"key2022021220100635600_b18","doi-asserted-by":"crossref","unstructured":"Eilifsen, A., Knechel, W.R. and Wallage, P. (2001), \u201cApplication of the business risk audit model: a field study\u201d, Accounting Horizons, Vol. 15, pp. 193\u2010207.","DOI":"10.2308\/acch.2001.15.3.193"},{"key":"key2022021220100635600_b19","unstructured":"Gallegos, F. (2005), \u201cAudit concerns: looking at ERP application integration and implementation issues\u201d, Informations Systems Audit and Control Association, Vol. 4, available at: www.isaca.org."},{"key":"key2022021220100635600_b20","doi-asserted-by":"crossref","unstructured":"Goldberg, S. and Godwin, J.H. (2003), \u201cOperational reviews and auditing ERP\u201d, The Journal of Corporate Accounting and Finance, Vol. 14 No. 4, pp. 63\u20105.","DOI":"10.1002\/jcaf.10171"},{"key":"key2022021220100635600_b22","doi-asserted-by":"crossref","unstructured":"Grabski, S.V. and Leech, S.A. (2007), \u201cComplementary controls and ERP implementation success\u201d, International Journal of Accounting Information Systems, Vol. 8, pp. 17\u201039.","DOI":"10.1016\/j.accinf.2006.12.002"},{"key":"key2022021220100635600_b21","doi-asserted-by":"crossref","unstructured":"Grabski, S.V., Leech, S.A. and Lu, B. (2001), \u201cRisks and controls in the implementation of ERP systems\u201d, The International Journal of Digital Accounting Research, Vol. 1 No. 1, pp. 47\u201068.","DOI":"10.4192\/1577-8517-v1_3"},{"key":"key2022021220100635600_b23","doi-asserted-by":"crossref","unstructured":"Huang, S.M., Hsieh, P.G., Tsao, H.H. and Hsu, P.Y. (2008), \u201cA structural study of internal control for ERP system environments: a perspective from Sarbanes\u2010Oxley Act\u201d, International Journal of Management and Enterprise Development, Vol. 5 No. 1, pp. 102\u201021.","DOI":"10.1504\/IJMED.2008.015909"},{"key":"key2022021220100635600_b24","doi-asserted-by":"crossref","unstructured":"Huang, S.M., Yen, D.C., Hung, Y.C., Zhou, Y.J. and Hua, J.S. (2009), \u201cA business process gap detecting mechanism between information system process flow and internal control flow\u201d, Decision Support Systems, Vol. 47, pp. 436\u201054.","DOI":"10.1016\/j.dss.2009.04.011"},{"key":"key2022021220100635600_b25","doi-asserted-by":"crossref","unstructured":"Hunton, J.E., Mauldin, E.G. and Wheeler, P.R. (2008), \u201cPotential functional and dysfunctional affects of continuous monitoring\u201d, The Accounting Review, Vol. 83 No. 6, pp. 1551\u201069.","DOI":"10.2308\/accr.2008.83.6.1551"},{"key":"key2022021220100635600_b26","doi-asserted-by":"crossref","unstructured":"Hunton, J.E., Wright, A.M. and Wright, S. (2004), \u201cAre financial auditors overconfident in their ability to assess risks associated with enterprise resource planning systems?\u201d, Journal of Information Systems, Vol. 18 No. 2, pp. 7\u201028.","DOI":"10.2308\/jis.2004.18.2.7"},{"key":"key2022021220100635600_b27","doi-asserted-by":"crossref","unstructured":"Kuhn, J.R. and Sutton, S.G. (2006), \u201cLearning from WorldCom: implications for fraud detection through continuous assurance\u201d, Journal of Emerging Technologies in Accounting, Vol. 3, pp. 61\u201080.","DOI":"10.2308\/jeta.2006.3.1.61"},{"key":"key2022021220100635600_b28","doi-asserted-by":"crossref","unstructured":"Kuhn, J.R. and Sutton, S.G. (2010), \u201cContinuous auditing in ERP system environments: the current state and future directions\u201d, Journal of Information Systems, Vol. 24 No. 1, pp. 91\u2010112.","DOI":"10.2308\/jis.2010.24.1.91"},{"key":"key2022021220100635600_b29","doi-asserted-by":"crossref","unstructured":"Kumar, K. and Hillegersberg, J.V. (2000), \u201cEnterprise resource planning experiences and evolution\u201d, Commun ACM, Vol. 43 No. 3, pp. 22\u20106.","DOI":"10.1145\/332051.332063"},{"key":"key2022021220100635600_b30","doi-asserted-by":"crossref","unstructured":"Lee, G.H. (2008), \u201cRule\u2010based and case\u2010based reasoning approach for internal audit of bank\u201d, Knowledge\u2010Based Systems, Vol. 21, pp. 140\u20107.","DOI":"10.1016\/j.knosys.2007.04.001"},{"key":"key2022021220100635600_b31","doi-asserted-by":"crossref","unstructured":"Madani, H.H. (2009), \u201cThe role of internal auditors in ERP\u2010based organizations\u201d, Journal of Accounting and Organizational Change, Vol. 5 No. 4, pp. 514\u201026.","DOI":"10.1108\/18325910910994702"},{"key":"key2022021220100635600_b32","doi-asserted-by":"crossref","unstructured":"Maurizio, A., Girolami, L. and Jones, P. (2007), \u201cEAI and SOA: factors and methods influencing the integration of multiple ERP systems (in an SAP environment) to comply with the Sarbanes\u2010Oxley Act\u201d, Journal of Enterprise Information Management, Vol. 20 No. 1, pp. 14\u201031.","DOI":"10.1108\/17410390710717110"},{"key":"key2022021220100635600_b33","doi-asserted-by":"crossref","unstructured":"Messier, W.F., Eilifsen, A. and Austen, L.A. (2004), \u201cAuditor detected misstatements and the effect of information technology\u201d, International Journal of Auditing, Vol. 8, pp. 223\u201035.","DOI":"10.1111\/j.1099-1123.2004.00092.x"},{"key":"key2022021220100635600_b34","doi-asserted-by":"crossref","unstructured":"Munter, P. (2002), \u201cWill technology defeat your auditor?\u201d, The Journal of Corporate Accounting and Finance, Vol. 13 No. 4, pp. 17\u201022.","DOI":"10.1002\/jcaf.10065"},{"key":"key2022021220100635600_b35","unstructured":"Public Oversight Board (POB) (2000), Panel on Audit Effectiveness: Report and Recommendations, AICPA, Stamford, CT."},{"key":"key2022021220100635600_b36","doi-asserted-by":"crossref","unstructured":"Rezaee, Z. and Reinstein, A. (1998), \u201cThe impact of emerging information technology on auditing\u201d, Managerial Auditing Journal, Vol. 13 No. 8, pp. 465\u201071.","DOI":"10.1108\/02686909810236271"},{"key":"key2022021220100635600_b37","doi-asserted-by":"crossref","unstructured":"Spathis, C. (2006), \u201cEnterprise systems implementation and accounting benefits\u201d, Journal of Enterprise Information Management, Vol. 19 No. 1, pp. 67\u201082.","DOI":"10.1108\/17410390610636887"},{"key":"key2022021220100635600_b38","doi-asserted-by":"crossref","unstructured":"Spathis, C. and Constantinides, S. (2004), \u201cEnterprise resource planning systems' impact on accounting processes\u201d, Business Process Management Journal, Vol. 10 No. 3, pp. 234\u201047.","DOI":"10.1108\/14637150410530280"},{"key":"key2022021220100635600_b39","doi-asserted-by":"crossref","unstructured":"Sutton, S.G. (2000), \u201cThe changing face of accounting in an information technology dominated world\u201d, International Journal of Accounting Information Systems, Vol. 1, pp. 1\u20108.","DOI":"10.1016\/S1467-0895(99)00002-0"},{"key":"key2022021220100635600_b40","doi-asserted-by":"crossref","unstructured":"Sutton, S.G. (2006), \u201cEnterprise systems and the re\u2010shaping of accounting systems: a call of research\u201d, International Journal of Accounting Information Systems, Vol. 7, pp. 1\u20106.","DOI":"10.1016\/j.accinf.2006.02.002"},{"key":"key2022021220100635600_b41","doi-asserted-by":"crossref","unstructured":"Vasarhelyi, M., Alles, M. and Kogan, A. (2004), \u201cPrinciples of analytic monitoring for continuous assurance\u201d, Journal of Emerging Technologies in Accounting, Vol. 1, pp. 1\u201021.","DOI":"10.2308\/jeta.2004.1.1.1"},{"key":"key2022021220100635600_b42","doi-asserted-by":"crossref","unstructured":"Vendrzyk, V.P. and Bagranoff, N.A. (2003), \u201cThe evolving role of IS audit: a field study comparing the perceptions of IS and financial auditors\u201d, Advances in Accounting, Vol. 20, pp. 141\u201063.","DOI":"10.1016\/S0882-6110(03)20007-9"},{"key":"key2022021220100635600_b43","doi-asserted-by":"crossref","unstructured":"Winograd, B.N., Gerson, J.S. and Berlin, B.L. (2000), \u201cAudit practices of PricewaterhouseCoopers\u201d, Auditing: A Journal of Practice and Theory, Vol. 19, pp. 175\u201082.","DOI":"10.2308\/aud.2000.19.2.176"},{"key":"key2022021220100635600_b44","doi-asserted-by":"crossref","unstructured":"Wright, S. and Wright, A.M. (2002), \u201cInformation system assurance for enterprise resource planning systems: unique risk considerations\u201d, Journal of Information Systems, Vol. 16, pp. 99\u2010113.","DOI":"10.2308\/jis.2002.16.s-1.99"},{"key":"key2022021220100635600_b45","doi-asserted-by":"crossref","unstructured":"Yang, D.C. and Guan, L. (2004), \u201cThe evolution of IT auditing and internal control standards in financial statement audits. The case of the United States\u201d, Managerial Auditing Journal, Vol. 19 No. 4, pp. 544\u201055.","DOI":"10.1108\/02686900410530547"},{"key":"key2022021220100635600_b46","unstructured":"Yen, C.C., Huang, S.M., Li, C.L. and Hsiah, Y.C. (2006), \u201cApplication, influence and impact of Sarbanes\u2010Oxley Act\u201d, Computer Auditing Journal, Vol. 15, pp. 1\u201011."}],"container-title":["Journal of Enterprise Information Management"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/www.emeraldinsight.com\/doi\/full-xml\/10.1108\/17410391111166549","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/17410391111166549\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/17410391111166549\/full\/html","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,25]],"date-time":"2025-07-25T00:19:31Z","timestamp":1753402771000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.emerald.com\/jeim\/article\/24\/6\/494-519\/194998"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011,10,18]]},"references-count":46,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2011,10,18]]}},"alternative-id":["10.1108\/17410391111166549"],"URL":"https:\/\/doi.org\/10.1108\/17410391111166549","relation":{},"ISSN":["1741-0398"],"issn-type":[{"type":"print","value":"1741-0398"}],"subject":[],"published":{"date-parts":[[2011,10,18]]}}}