As public finance and public assets are increasingly managed through data and information systems, the State Audit Office of Vietnam (SAV) needs a corresponding legal framework. The focus of legalizing auditing in the digital environment is not to introduce a new type of audit or incorporate specific technologies into the Law, but to ensure that the right to access data is enforceable, while going hand in hand with responsibilities for data protection and the quality of audit evidence.

Overview of the meeting of the Standing Committee of the Steering Committee for the assessment, review and revision of the Law on State Audit, held on the morning of September 11 and chaired by Auditor General Nguyen Huu Nghia. File photo.
Existing Rights Require Effective Mechanisms for Implementation
In the management of public finance and public assets, many transactions, approval steps, processing procedures, and control trails are created and stored in information systems. Printed records or consolidated reports provided by entities may reflect the final results but are not sufficient for auditors to examine original data, modification histories, access rights, or how systems process transactions. As the nature of evidence changes, the approach to obtaining and examining evidence must also change.
The current Law on State Audit already recognizes the right to request the provision of information and documents and to access electronic data. However, connecting to, sharing, and utilizing data from national databases, specialized databases, and systems of audited entities still face legal, technical, and coordination-related obstacles. The gap between “having the right” and “being able to exercise the right” is an issue that needs to be addressed in this revision of the Law.
Accordingly, the right of access must be concretized through corresponding obligations of data holders: providing data within the required scope, in full and in a timely manner; supporting connectivity and explaining data structures and processing procedures; ensuring data integrity and traceability; and not obstructing lawful access. Conversely, the SAV must use data for proper purposes and within the necessary scope, while assuming responsibility for data confidentiality and security. Rights and responsibilities must be designed together rather than separately.
Auditing in the Digital Environment Does Not Mean Remote Auditing
Three concepts that are easily confused need to be distinguished. Financial audit, compliance audit, and performance audit are types of audit classified according to their objectives and nature. Auditing in the digital environment refers to the use of digital data, information systems, electronic means, and digital technologies in part or all of the audit process. Meanwhile, on-site, remote, or hybrid auditing refers to the organizational forms through which an audit is conducted.
For example, an auditor may be physically present at an entity while accessing databases, examining system logs, analyzing all transactions, and collecting electronic evidence. This is still auditing in the digital environment. Conversely, working remotely does not automatically ensure audit quality if the data are incomplete or cannot be authenticated. Therefore, “digital auditing” or “remote auditing” should not be introduced as new types of audit. The Law should enable existing types of audit to be conducted on-site, remotely, or in combination, depending on the nature of the audit and the ability to obtain sufficient evidence.
Regardless of the technology applied, requirements concerning sufficient and appropriate audit evidence, professional judgment, quality control, and auditors’ responsibilities remain unchanged. Analytical tools and artificial intelligence can support the identification of anomalies, but they cannot replace the SAV in reaching audit conclusions.
Establishing Framework Provisions with Clear Rights and Responsibilities
One option for consideration is to add three principle-based provisions to the revised Law on State Audit, focusing on stable legal relationships rather than describing specific technologies in detail.
First, the Law should define the concept, scope, and principles of auditing in the digital environment, including compliance with the law, independence, objectivity, and verifiability; protection of state secrets, business secrets, and personal data; and assurance of the integrity and traceability of data and electronic evidence. It should clearly provide that electronic data may be used as audit evidence when they satisfy applicable legal requirements and auditing standards, avoiding the establishment of a separate “legal validity” regime that overlaps with laws governing data and electronic transactions.
Second, the Law should establish the right to access, connect to, collect, extract, reconcile, and analyze data relevant to the audit, while also specifying the obligations of audited entities and agencies and organizations managing data to provide, coordinate, authenticate, and explain such data. The right of access must be clearly limited in terms of purpose and scope, together with requirements for ensuring system security.
Third, the Law should prescribe responsibilities for managing audit data, including using data for proper purposes, controlling access rights, maintaining access logs, storing data, and protecting information in accordance with the law. This is not merely a technical requirement, but also a mechanism for ensuring accountability as the SAV gains access to increasingly large volumes of data.
A legal framework that is sufficiently strong in terms of rights and responsibilities, yet sufficiently open in terms of technology, will enable the SAV to perform its audit functions more effectively and securely in the digital environment.

Mr. Phan Truong Giang – Deputy Auditor General of State Audit Office of Vietnam Specialized Audit Department II
The Law Must Remain Stable, While Technical Regulations Must Remain Flexible
Data formats, extraction methods, algorithms, AI tools, and system architectures can change rapidly. If overly detailed provisions are incorporated into the Law, they may quickly become outdated and difficult to amend. The Law should establish rights, obligations, limitations on rights, and responsibilities; requirements for inter-agency data connectivity and sharing should be regulated within the relevant authorities; while professional procedures, standards, and technical requirements applicable to audit activities should be prescribed by the Auditor General. The division of authority must be clear to avoid multiple agencies issuing detailed regulations on the same matter.
Legalizing auditing in the digital environment, therefore, is not about following a technological trend. It is a necessary transition that will enable the SAV to examine how information is generated, rather than merely reviewing information products provided by entities; and gradually shift from an audit approach that relies heavily on documentation to one that is data-driven. A legal framework that is sufficiently strong in terms of rights and responsibilities, yet sufficiently open in terms of technology, will enable the SAV to perform its audit functions more effectively and securely in the digital environment.