CORAA
Audit Technology · SA 315/330

CAAT tools: what they are, and what they grew up into.

Computer Assisted Audit Techniques are the exam-syllabus name for a simple idea — let software perform audit procedures on the client’s data. The four classic types still frame the topic; what changed is scale: the modern CAAT does not help you pick a better sample, it reads the whole population and hands you the exceptions.

The four classic CAAT types

TypeWhat it doesBest fit
Generalized audit software (GAS)Software that reads the client’s data files and runs the auditor’s own procedures — extraction, stratification, ageing, duplicates, gaps, re-computation. Excel with discipline, IDEA and ACL/Diligent are the classic examples; scrutiny engines are its modern form.Substantive testing over data the auditor controls a copy of
Test dataThe auditor feeds dummy transactions into the client’s system and checks whether controls accept, reject or flag them — a purchase above the approval limit, a duplicate invoice number, a backdated entry.Testing automated controls in the client’s application
Parallel simulationThe auditor re-performs the client’s processing independently — recompute depreciation, interest, TDS or GST on the full file and compare against the books. Differences are exceptions by construction.Re-computation at population scale
Embedded audit modules / SCARFAudit code living inside the client’s system, tagging transactions that meet audit criteria as they happen — continuous auditing’s ancestor.Ongoing monitoring in high-volume environments

The honest hierarchy in Indian practice: Excel on a Tally export is the CAAT ninety percent of firms actually run; GAS tools add power at the cost of setup; full-population engines remove the setup and the sampling compromise together. Whichever layer you use, the SA 230 rule from the FAQ below applies: re-runnable, or it isn’t evidence.

In practice · From technique to working paper

Run the population, file the exceptions

Two working papers turn CAAT output into an audit file: the journal-entry testing paper (SA 240) for the population screens, and the per-ledger scrutiny checklist for the account-by-account read.

JE testing working paper →Ledger scrutiny checklist →

CORAA runs the full-population battery on Tally books natively — every voucher, every check, exceptions explained. See transactional scrutiny or start free: your first audit is on us.

Where CAATs fit in internal audit

For internal audit, CAATs are most useful when they sit inside the RCM. A duplicate-payment test is stronger when the workpaper shows the P2P control objective, the population tested, the rule logic, the exception disposition and the owner response. The same logic can later become a continuous monitoring rule if it is stable and repeatable.

Internal audit useCAAT examplesNext workpaper
P2P leakageDuplicate vendors, changed bank details, invoice duplicates, PO-after-invoice, GST ITC mismatches and MSME ageing exceptions.Open resource
O2C leakageCredit-limit overrides, manual pricing, invoice without dispatch, unusual credit notes, aged receivables and collection write-offs.Open resource
R2R reliabilityManual journals, late postings, no-attachment journals, stale reconciliations, subledger-to-GL mismatches and provision reversals.Open resource
H2R/payrollDuplicate bank accounts, payroll after exit, salary changes without approval, overtime spikes and leaver access exceptions.Open resource
ITGC and report relianceLeaver access, privileged users, SoD conflicts, emergency changes, failed interfaces and audit reports without extraction evidence.Open resource
Continuous monitoringRepeatable exception rules with source data, cadence, owner, false-positive review and closure evidence.Open resource
Process mining guideMonitoring rules repository

Documentation checklist for CAAT evidence

The test is only useful if a reviewer can understand and re-run it. Keep the CAAT workpaper short, but make the data trail explicit.

  1. Source system, report name, extraction date and report owner.
  2. Population count and control-total reconciliation to GL, subledger or operational register.
  3. Filters, parameters, fields used, join keys and exclusion logic.
  4. Rule logic or script version, including who prepared and reviewed it.
  5. Exception count, cleared false positives, final observations and reviewer conclusion.
  6. Retained extract, hash or re-run evidence sufficient for SA 230-style review.
Download monitoring workbookOpen fieldwork tracker

CAATs, frequently asked

What are CAAT tools in auditing?

Computer Assisted Audit Techniques are any use of software to perform audit procedures directly on the client’s data or systems — extracting and analysing full data files, re-computing balances, testing automated controls with dummy data, or embedding monitoring code. They exist because manual methods cannot read modern transaction volumes; the standards (SA 315/330 and ICAI’s automated-environment guidance) treat them as ordinary means of obtaining evidence, not a special category.

What are examples of CAAT tools in Indian practice?

Most Indian audits already use CAATs without the label: Tally exports analysed in Excel (pivots, duplicate checks, ageing), day-book dumps tested for gaps in voucher sequences, TDS and GST re-computations across the full ledger, and dedicated tools like IDEA or ACL in larger firms. Purpose-built audit platforms take the same idea further — running a battery of deterministic checks across every voucher rather than a hand-built spreadsheet per test.

Are CAATs mandatory under the Standards on Auditing?

No standard mandates a tool. What SA 315 and SA 330 do require is responses that match the risk — and in an automated environment with lakhs of transactions, a purely manual approach often cannot deliver sufficient appropriate evidence in the time available. ICAI’s guidance on auditing in automated environments points the same way: understand the system, test what the system does, use the data.

How is full-population testing different from classic CAATs?

Classic CAATs still ended in a sample: extract, stratify, select, vouch. Full-population testing inverts it — every transaction passes through every check (sequence gaps, duplicates, round sums, period-end patterns, tax applicability, related parties), and only exceptions reach the auditor. Sampling then survives where it belongs: substantive detail testing of the exceptions and the material items, not as the coverage strategy.

Do CAAT results need special documentation?

Same SA 230 discipline as any procedure, plus the tool specifics: what ran, on which data extract (source, date, record counts), the parameters, the exceptions raised and their disposition. Keep the extract or its hash — a reviewer should be able to re-run the procedure and land on the same exceptions.

How do CAAT tools help internal audit?

Internal audit uses CAATs to convert recurring risks into data tests: duplicate payments, changed bank masters, credit-limit overrides, manual journals, payroll after exit, stale reconciliations, leaver access and other exceptions. The useful output is not a dashboard alone; it is an exception queue tied to an RCM row, source evidence and reviewer conclusion.

What is the difference between CAAT and continuous monitoring?

A CAAT may be run once during fieldwork on a data extract. Continuous monitoring takes the same logic and runs it repeatedly on refreshed data, with owner routing, false-positive tracking and closure evidence. Internal audit should first prove the CAAT logic works, then promote stable high-value tests into monitoring rules.

Which CAAT documentation should an auditor retain?

Retain the source report, extraction date, population count, filters, fields, rule logic, exception count, false-positive review, final exceptions and reviewer conclusion. Without those items, the CAAT result is difficult to defend in review even if the test itself was useful.

Authority notes

ICAI's CAAT guidance is the authority anchor for the terminology. The modern internal-audit recommendation on this page is CORAA's practitioner framing: use CAATs as documented audit procedures, then promote repeatable tests into continuous monitoring only when the data source and false-positive handling are reliable.