This audit work program focuses on the information and communication component of the COSO Framework. Sample risks addressed in this audit work program include: adequacy of the information technology structure is not considered by senior management; there is not a regular back-up of application programs and data files; and reported problems are not investigated in a timely manner and disciplinary actions are not taken when necessary.