IDEAS home Printed from https://ideas.repec.org/a/eee/ijoais/v56y2025ics1467089525000028.html

Characteristics of cybersecurity and IT involvement by the IA activity

Author

Listed:
  • Calvin, Christopher
  • Eulerich, Marc
  • Holt, Matthew

Abstract

We provide the first, large scale, global study on the characteristics associated with an internal audit function’s involvement in IT and cybersecurity assurance. Using a unique dataset of 1,142 survey responses, we identify internal audit development (i.e., level of maturity) and two characteristics of internal audit knowledge availability (CAE IT certification and external sourcing) as being positively associated with the performance of IT assurance, cybersecurity assurance, or both. Our findings are informative to academia, laying the groundwork for further exploration of internal audit’s engagement in IT and cybersecurity assurance. They are also informative to practice, as they provide insight to standard setters, practitioners, management, and governance bodies about characteristics that can enhance internal audit’s ability to provide IT and cybersecurity assurance.

Suggested Citation

  • Calvin, Christopher & Eulerich, Marc & Holt, Matthew, 2025. "Characteristics of cybersecurity and IT involvement by the IA activity," International Journal of Accounting Information Systems, Elsevier, vol. 56(C).
  • Handle: RePEc:eee:ijoais:v:56:y:2025:i:c:s1467089525000028
    DOI: 10.1016/j.accinf.2025.100726
    as

    Download full text from publisher

    File URL: http://www.sciencedirect.com/science/article/pii/S1467089525000028
    Download Restriction: Full text for ScienceDirect subscribers only

    File URL: https://libkey.io/10.1016/j.accinf.2025.100726?utm_source=ideas
    LibKey link: if access is restricted and if your library uses this service, LibKey will redirect you to where you can use your library subscription to access this item
    ---><---

    As the access to this document is restricted, you may want to

    for a different version of it.

    References listed on IDEAS

    as
    1. repec:eme:maj000:maj-02-2018-1804 is not listed on IDEAS
    2. Lawrence J. Abbott & Brian Daugherty & Susan Parker & Gary F. Peters, 2016. "Internal Audit Quality and Financial Reporting Quality: The Joint Importance of Independence and Competence," Journal of Accounting Research, John Wiley & Sons, Ltd., vol. 54(1), pages 3-40, March.
    3. Sezer Bozkus Kahyaoglu & Kiymet Caliyurt, 2018. "Cyber security assurance process from the internal audit perspective," Managerial Auditing Journal, Emerald Group Publishing Limited, vol. 33(4), pages 360-376, May.
    4. Paul Coram & Colin Ferguson & Robyn Moroney, 2008. "Internal audit, alternative internal audit structures and the level of misappropriation of assets fraud," Accounting and Finance, Accounting and Finance Association of Australia and New Zealand, vol. 48(4), pages 543-559, December.
    5. Steinbart, Paul John & Raschke, Robyn L. & Gal, Graham & Dilla, William N., 2012. "The relationship between internal audit and information security: An exploratory investigation," International Journal of Accounting Information Systems, Elsevier, vol. 13(3), pages 228-243.
    6. Steinbart, Paul John & Raschke, Robyn L. & Gal, Graham & Dilla, William N., 2018. "The influence of a good relationship between the internal audit and information security functions on information security outcomes," Accounting, Organizations and Society, Elsevier, vol. 71(C), pages 15-29.
    Full references (including those not matched with items on IDEAS)

    Citations

    Citations are extracted by the CitEc Project, subscribe to its RSS feed for this item.
    as


    Cited by:

    1. Tang, Rui & Li, Mingyu, 2026. "Cybersecurity and corporate resilience –a study based on listed companies in China," Technology in Society, Elsevier, vol. 84(C).

    Most related items

    These are the items that most often cite the same works as this one and are cited by the same works as this one.
    1. Sylvie Héroux & Anne Fortin, 2025. "How the three lines of defense can contribute to public firms’ cybersecurity effectiveness," International Journal of Disclosure and Governance, Palgrave Macmillan, vol. 22(2), pages 377-396, June.
    2. Slapničar, Sergeja & Axelsen, Micheal & Bongiovanni, Ivano & Stockdale, David, 2023. "A pathway model to five lines of accountability in cybersecurity governance," International Journal of Accounting Information Systems, Elsevier, vol. 51(C).
    3. Slapničar, Sergeja & Vuko, Tina & Čular, Marko & Drašček, Matej, 2022. "Effectiveness of cybersecurity audit," International Journal of Accounting Information Systems, Elsevier, vol. 44(C).
    4. Chelsea Liu & Muhammad Ali Babar, 2026. "Corporate cybersecurity risk and data breaches: A systematic review of empirical research," Australian Journal of Management, Australian School of Business, vol. 51(1), pages 62-92, February.
    5. Yusheng Kong & Peter Yao Lartey & Fatoumata Binta Maci Bah & Nirmalya B. Biswas, 2018. "The Value of Public Sector Risk Management: An Empirical Assessment of Ghana," Administrative Sciences, MDPI, vol. 8(3), pages 1-18, July.
    6. Mélanie Roussy & Alexandre Perron, 2018. "New Perspectives in Internal Audit Research: A Structured Literature Review," Accounting Perspectives, John Wiley & Sons, vol. 17(3), pages 345-385, September.
    7. Wu, Tung-Hsien & Huang, Shaio Yan & Chiu, An-An & Yen, David C., 2024. "IT governance and IT controls: Analysis from an internal auditing perspective," International Journal of Accounting Information Systems, Elsevier, vol. 52(C).
    8. Wang, Pengmian & Liang, Shuguang, 2025. "Internal audit independence, legal person governance structure, and financial reporting quality," International Review of Economics & Finance, Elsevier, vol. 101(C).
    9. Nan Hu & Xingnan Xue & Ling Liu, 2022. "The impact of air pollution on financial reporting quality: evidence from China," Accounting and Finance, Accounting and Finance Association of Australia and New Zealand, vol. 62(3), pages 3609-3644, September.
    10. Shana Clor-Proell & Steven Kaplan & Chad Proell, 2015. "The Impact of Budget Goal Difficulty and Promotion Availability on Employee Fraud," Journal of Business Ethics, Springer, vol. 131(4), pages 773-790, November.
    11. David T. Tan & Larelle Chapple & Kathleen D. Walsh, 2017. "Corporate fraud culture: Re-examining the corporate governance and performance relation," Accounting and Finance, Accounting and Finance Association of Australia and New Zealand, vol. 57(2), pages 597-620, June.
    12. Ari Fahimatussyam Putra Nusantara & Gugus Irianto & Yeney Widya Prihatiningtias, 2020. "Fraud prevention and detection practices in the perspective of Jember Regency internal auditor," International Journal of Research in Business and Social Science (2147-4478), Center for the Strategic Studies in Business and Finance, vol. 9(4), pages 377-384, July.
    13. Didier Fass & Stéphanie Thiéry, 2020. "Cybersecurity risks and situation awareness: Audit committees' appraisal," Post-Print hal-03198562, HAL.
    14. Ya-Fang Wang & Yu-Chu Hsieh, 2023. "Credit Rating and Board Evaluation of Family Firms," International Journal of Business and Economic Sciences Applied Research (IJBESAR), Democritus University of Thrace (DUTH), Kavala Campus, Greece, vol. 16(1), pages 7-18, October.
    15. Isabel Z. Wang & Neil Fargher, 2017. "The effects of tone at the top and coordination with external auditors on internal auditors’ fraud risk assessments," Accounting and Finance, Accounting and Finance Association of Australia and New Zealand, vol. 57(4), pages 1177-1202, December.
    16. Wang, Xiong & Ferreira, Fernando A.F. & Chang, Ching-Ter, 2022. "Multi-objective competency-based approach to project scheduling and staff assignment: Case study of an internal audit project," Socio-Economic Planning Sciences, Elsevier, vol. 81(C).
    17. Kocsis, David, 2019. "A conceptual foundation of design and implementation research in accounting information systems," International Journal of Accounting Information Systems, Elsevier, vol. 34(C), pages 1-1.
    18. Ujkan Bajra & Simon Cadez, 2018. "The Impact of Corporate Governance Quality on Earnings Management: Evidence from European Companies Cross†listed in the US," Australian Accounting Review, CPA Australia, vol. 28(2), pages 152-166, June.
    19. Abdulkarim Hamdan J. Alhazmi & Sardar Islam & Maria Prokofieva, 2024. "The Impact of Changing External Auditors, Auditor Tenure, and Audit Firm Type on the Quality of Financial Reports on the Saudi Stock Exchange," JRFM, MDPI, vol. 17(9), pages 1-26, September.
    20. Monica Ramos Montesdeoca & Agustín J. Sánchez Medina & Felix Blázquez Santana, 2019. "Research Topics in Accounting Fraud in the 21st Century: A State of the Art," Sustainability, MDPI, vol. 11(6), pages 1-31, March.

    More about this item

    Keywords

    ;
    ;
    ;

    JEL classification:

    • M42 - Business Administration and Business Economics; Marketing; Accounting; Personnel Economics - - Accounting - - - Auditing
    • M15 - Business Administration and Business Economics; Marketing; Accounting; Personnel Economics - - Business Administration - - - IT Management
    • L86 - Industrial Organization - - Industry Studies: Services - - - Information and Internet Services; Computer Software

    Statistics

    Access and download statistics

    Corrections

    All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:eee:ijoais:v:56:y:2025:i:c:s1467089525000028. See general information about how to correct material in RePEc.

    If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.

    If CitEc recognized a bibliographic reference but did not link an item in RePEc to it, you can help with this form .

    If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.

    For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: Catherine Liu (email available below). General contact details of provider: https://www.journals.elsevier.com/international-journal-of-accounting-information-systems/ .

    Please note that corrections may take a couple of weeks to filter through the various RePEc services.

    IDEAS is a RePEc service. RePEc uses bibliographic data supplied by the respective publishers.