| Type | What it does | Best fit |
|---|---|---|
| Generalized audit software (GAS) | Software that reads the client’s data files and runs the auditor’s own procedures — extraction, stratification, ageing, duplicates, gaps, re-computation. Excel with discipline, IDEA and ACL/Diligent are the classic examples; scrutiny engines are its modern form. | Substantive testing over data the auditor controls a copy of |
| Test data | The auditor feeds dummy transactions into the client’s system and checks whether controls accept, reject or flag them — a purchase above the approval limit, a duplicate invoice number, a backdated entry. | Testing automated controls in the client’s application |
| Parallel simulation | The auditor re-performs the client’s processing independently — recompute depreciation, interest, TDS or GST on the full file and compare against the books. Differences are exceptions by construction. | Re-computation at population scale |
| Embedded audit modules / SCARF | Audit code living inside the client’s system, tagging transactions that meet audit criteria as they happen — continuous auditing’s ancestor. | Ongoing monitoring in high-volume environments |
The honest hierarchy in Indian practice: Excel on a Tally export is the CAAT ninety percent of firms actually run; GAS tools add power at the cost of setup; full-population engines remove the setup and the sampling compromise together. Whichever layer you use, the SA 230 rule from the FAQ below applies: re-runnable, or it isn’t evidence.
Two working papers turn CAAT output into an audit file: the journal-entry testing paper (SA 240) for the population screens, and the per-ledger scrutiny checklist for the account-by-account read.
CORAA runs the full-population battery on Tally books natively — every voucher, every check, exceptions explained. See transactional scrutiny or start free: your first audit is on us.
For internal audit, CAATs are most useful when they sit inside the RCM. A duplicate-payment test is stronger when the workpaper shows the P2P control objective, the population tested, the rule logic, the exception disposition and the owner response. The same logic can later become a continuous monitoring rule if it is stable and repeatable.
| Internal audit use | CAAT examples | Next workpaper |
|---|---|---|
| P2P leakage | Duplicate vendors, changed bank details, invoice duplicates, PO-after-invoice, GST ITC mismatches and MSME ageing exceptions. | Open resource |
| O2C leakage | Credit-limit overrides, manual pricing, invoice without dispatch, unusual credit notes, aged receivables and collection write-offs. | Open resource |
| R2R reliability | Manual journals, late postings, no-attachment journals, stale reconciliations, subledger-to-GL mismatches and provision reversals. | Open resource |
| H2R/payroll | Duplicate bank accounts, payroll after exit, salary changes without approval, overtime spikes and leaver access exceptions. | Open resource |
| ITGC and report reliance | Leaver access, privileged users, SoD conflicts, emergency changes, failed interfaces and audit reports without extraction evidence. | Open resource |
| Continuous monitoring | Repeatable exception rules with source data, cadence, owner, false-positive review and closure evidence. | Open resource |
The test is only useful if a reviewer can understand and re-run it. Keep the CAAT workpaper short, but make the data trail explicit.
Computer Assisted Audit Techniques are any use of software to perform audit procedures directly on the client’s data or systems — extracting and analysing full data files, re-computing balances, testing automated controls with dummy data, or embedding monitoring code. They exist because manual methods cannot read modern transaction volumes; the standards (SA 315/330 and ICAI’s automated-environment guidance) treat them as ordinary means of obtaining evidence, not a special category.
Most Indian audits already use CAATs without the label: Tally exports analysed in Excel (pivots, duplicate checks, ageing), day-book dumps tested for gaps in voucher sequences, TDS and GST re-computations across the full ledger, and dedicated tools like IDEA or ACL in larger firms. Purpose-built audit platforms take the same idea further — running a battery of deterministic checks across every voucher rather than a hand-built spreadsheet per test.
No standard mandates a tool. What SA 315 and SA 330 do require is responses that match the risk — and in an automated environment with lakhs of transactions, a purely manual approach often cannot deliver sufficient appropriate evidence in the time available. ICAI’s guidance on auditing in automated environments points the same way: understand the system, test what the system does, use the data.
Classic CAATs still ended in a sample: extract, stratify, select, vouch. Full-population testing inverts it — every transaction passes through every check (sequence gaps, duplicates, round sums, period-end patterns, tax applicability, related parties), and only exceptions reach the auditor. Sampling then survives where it belongs: substantive detail testing of the exceptions and the material items, not as the coverage strategy.
Same SA 230 discipline as any procedure, plus the tool specifics: what ran, on which data extract (source, date, record counts), the parameters, the exceptions raised and their disposition. Keep the extract or its hash — a reviewer should be able to re-run the procedure and land on the same exceptions.
Internal audit uses CAATs to convert recurring risks into data tests: duplicate payments, changed bank masters, credit-limit overrides, manual journals, payroll after exit, stale reconciliations, leaver access and other exceptions. The useful output is not a dashboard alone; it is an exception queue tied to an RCM row, source evidence and reviewer conclusion.
A CAAT may be run once during fieldwork on a data extract. Continuous monitoring takes the same logic and runs it repeatedly on refreshed data, with owner routing, false-positive tracking and closure evidence. Internal audit should first prove the CAAT logic works, then promote stable high-value tests into monitoring rules.
Retain the source report, extraction date, population count, filters, fields, rule logic, exception count, false-positive review, final exceptions and reviewer conclusion. Without those items, the CAAT result is difficult to defend in review even if the test itself was useful.
ICAI's CAAT guidance is the authority anchor for the terminology. The modern internal-audit recommendation on this page is CORAA's practitioner framing: use CAATs as documented audit procedures, then promote repeatable tests into continuous monitoring only when the data source and false-positive handling are reliable.