النطاقScope
الوحدات المشمولة، الأنظمة المرتبطة، والفترة. النطاق غير المكتوب يُنتج تدقيقاً بلا حدود ولا نتيجة.Included modules, connected systems and the period. An unwritten scope produces an audit with no boundaries and no conclusion.
الضوابط العامةGeneral controls
الوصول، التغيير، العمليات، والنسخ. هذه الأربعة تحدد إن كان النظام نفسه تحت السيطرة.Access, change, operations and backup. These four determine whether the system itself is controlled.
الضوابط الآليةAutomated controls
التحقق من الإعدادات الحساسة: التسلسل، الاعتمادات، حدود الصلاحيات، ومنع الازدواج.Verify sensitive configuration: sequencing, approvals, permission limits and duplicate prevention.
البياناتData
اكتمال البيانات الرئيسية وصحتها: العملاء، الموردين، الأصناف، والحسابات. الضابط الجيد يفشل ببيانات سيئة.Completeness and accuracy of master data: customers, suppliers, items and accounts. A good control fails with bad data.
التقاريرReports
اختبار التقارير المفتاحية التي تُبنى عليها الضوابط والقرارات. التقرير الخطأ يُنتج ضابطاً خطأ.Test the key reports on which controls and decisions rest. A wrong report produces a wrong control.
المخرجاتOutputs
التدقيق الجيد يُنتج خطة تحسين مرتبة بالمخاطر، لا قائمة ملاحظات. الفرق بينهما هو التنفيذ الفعلي.A good audit produces a risk-ranked improvement plan, not a findings list. The difference is actual execution.

