By Nana Kweku Ofori Atta
Security Analyst
1. Introduction
The increasing dependence of Ghana’s public institutions on complex software systems for revenue collection, national security, public service delivery, and data management necessitates a robust, independent, and specialized framework for auditing software development and related IT investments. Traditional financial audits alone are insufficient to detect inefficiencies, security weaknesses, procurement abuses, and governance failures embedded within software systems.
There is therefore an urgent need to establish an independent IT Auditing Agency within Ghana’s Supreme Audit Institution (SAI) architecture, with the authority to supersede routine software development auditing currently embedded within executive-controlled agencies.
⸻
2. Proposed Institutional Responsibility
The Auditor-General, operating as Ghana’s Supreme Audit Institution (SAI), should be the principal authority responsible for auditing software development in public institutions. This responsibility should be exercised in conjunction with specialized, independent IT audit units established by law, with strong collaboration mechanisms involving the Office of the Special Prosecutor where criminal or procurement irregularities are detected.
These institutions should:
•Be independent of the Executive branch
•Report directly to Parliament
•Possess statutory powers to audit, investigate, and enforce corrective actions
Comparable institutions internationally include the Court of Accounts and National Audit Offices in other jurisdictions.
⸻
3. Key Responsible Entities and Their Roles
a. Auditor-General (Supreme Audit Institution)
The Auditor-General should:
•Conduct performance, compliance, and value-for-money audits on government IT systems
•Audit software development projects for economy, efficiency, effectiveness, and sustainability
•Assess alignment between software systems and public policy objectives
b. Internal Audit Agency
Internal Audit Agencies should:
•Provide continuous internal oversight within Ministries, Departments, and Agencies (MDAs)
•Ensure adherence to approved IT governance standards
•Serve as a first line of defense before external audits
c. Specialized Independent IT Audit Units
A legally established IT Audit Division within the Auditor-General’s Department should:
•Conduct deep technical audits of software development, cybersecurity, and IT procurement
•Apply globally accepted frameworks such as COBIT (Control Objectives for Information and Related Technologies)
•Operate independently from system developers and procuring entities
⸻
4. Core Focus Areas of Government Software Audits
Governmental IT audits should cover the full software lifecycle, including:
a. Project Governance
•Assessment of governance structures, decision-making processes, and accountability mechanisms
•Evaluation of project planning, risk management, and stakeholder oversight
b. Software Development and Acquisition
•Review of development methodologies (Agile, Waterfall, Hybrid)
•Validation of business rules, data integrity, and functional requirements
•Verification that systems meet contractual and operational specifications
c. Security and Internal Controls
•Compliance with ISO/IEC 27001, national cybersecurity policies, and relevant frameworks
•Assessment of access controls, encryption, audit trails, and incident response capabilities
•Protection of sensitive citizen and government data
d. Outsourcing and Third-Party Risk
•Oversight of outsourced software development and managed services
•Evaluation of vendor security posture, data residency, and contractual safeguards
•Continuous monitoring of externally hosted systems
⸻
5. International Standards and Best Practices
All IT and software audits should align with standards issued by the International Organization of Supreme Audit Institutions (INTOSAI), particularly:
•ISSAI 5310 – Information Systems Security Review Methodology
These standards ensure consistency, credibility, and international comparability of audit outcomes.
⸻
6. International and Local Precedents
Globally, Supreme Audit Institutions such as:
•The Office of the Auditor-General
•Courts of Accounts
•National Audit Offices (e.g., Rigsrevisionen)
routinely conduct software development and IT audits as part of their mandate.
In Ghana, strengthening the Auditor-General’s IT audit capacity through statutory independent IT audit units would align the country with global best practices while enhancing transparency and safeguarding public funds.
⸻
7. Conclusion
To protect public resources, ensure national cybersecurity, and enhance trust in digital governance, Ghana must institutionalize independent, specialized IT auditing within the Auditor-General’s framework, supported by strong legislative backing and collaboration with anti-corruption institutions.
Software systems are now critical national infrastructure. Their oversight must therefore be independent, professional, and shielded from executive influence.



















