Deck 5 Accounting Information Systems Romney and Steinbart Linda Batch February 2012.

Slides:



Advertisements
Similar presentations
Bodnar/Hopwood AIS 7th Ed1 Chapter 5 u TRANSACTION PROCESSING AND INTERNAL CONTROL PROCESS.
Advertisements

Chapter 10 Accounting Information Systems and Internal Controls
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
Control and Accounting Information Systems
Control and Accounting Information Systems
Internal Control.
The Islamic University of Gaza
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
Standar Pekerjaan Lapangan: Pemahaman Memadai atas Pengendalian Intern Pertemuan 5.
Chapter 4 Internal Control Bus 319 Accounting Information Systems.
6-1 McGraw-Hill/Irwin ©2002 by The McGraw-Hill Companies, Inc. All rights reserved. Chapter 6 Internal Control Evaluation: Assessing Control Risk.
Risk General Definition: exposure to the chance of adverse effects or loss; a hazard or dangerous chance Examples of risks to a company:  Erroneous Financial.
9 - 1 What is the purpose of an ICS? l First, what is it?? Policies and procedures established to provide reasonable assurance that the entities specific.
Internal Control. COSO’s Framework Committee of Sponsoring Organizations 1992 issued a white paper on internal control Since this time, this framework.
18- 1 © 2006 The McGraw-Hill Companies, Inc., All Rights Reserved. Chapter 18 Integrated Audits of Internal Control (For Public Companies Under Sarbanes-Oxley.
Internal Control. COSO’s Framework Committee of Sponsoring Organizations 1992 issued a white paper on internal control Since this time, this framework.
Sarbanes-Oxley Project Summary of COSO Framework Presented by Larry Dillehay & Scott Reitan Parkfield Group LLC.
Control and Accounting Information Systems
Chapter 4 Internal Controls McGraw-Hill/Irwin
Internal Auditing and Outsourcing
Control and Accounting Information Systems
Auditing Internal Control over Financial Reporting
Chapter 8 Introduction to Internal Control Systems
Chapter 9: Introduction to Internal Control Systems
Chapter 3 Internal Controls.
Transaction Processing and the Internal Control Process Small Business Information Systems Professor Barry Floyd.
Presented to President’s Cabinet. INTERNAL CONTROLS are the integration of the activities, plans, attitudes, policies and efforts of the people of an.
Auditing Internal Control over Financial Reporting
Introduction to Internal Control Systems
Vijay V Vijayakumar.  SOX Act  Difference between IT Management and IT Governance  Internal Controls  Frameworks for Implementing SOX  COSO - Committee.
Implementation Issues of Sarbanes-Oxley CASE Presentation September 23, 2004 By Denise Farnan.
Chapter Three IT Risks and Controls.
Internal controls. Session objectives Define Internal Controls To understand components of Internal Controls, control environment and types of controls.
INTRODUCTION Why AIS threats are increasing
Chapter 5 Internal Control over Financial Reporting
Considering Internal Control
Internal Control in a Financial Statement Audit
Chapter 7 Auditing Internal Control over Financial Reporting McGraw-Hill/Irwin ©2008 The McGraw-Hill Companies, All Rights Reserved.
Internal Control in a Financial Statement Audit
1 Chapter Three IT Risks and Controls. 2 The Risk Management Process Identify IT Risks Assess IT Risks Identify IT Controls Document IT Controls Monitor.
Risk Management. IT Controls Risk management process Risk management process IT controls IT controls IT Governance Frameworks IT Governance Frameworks.
Evaluation of Internal Control System
Business and Information Process Rules, Risks and Controls.
Chapter 7 Control and AIS (sistem pengendalian intern) Copyright © 2012 Pearson Education 7-1.
McGraw-Hill/Irwin © 2003 The McGraw-Hill Companies, Inc., All Rights Reserved. 6-1 Chapter 6 CHAPTER 6 INTERNAL CONTROL IN A FINANCIAL STATEMENT AUDIT.
IT Risks and Controls Revised on Content Internal Control  What is internal control?  Objectives of internal controls  Types of internal controls.
Chapter 9: Introduction to Internal Control Systems
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin 7-1 Chapter Seven Auditing Internal Control over Financial Reporting.
S5: Internal controls. What is Internal Control Internal control is a process Internal control is a process Internal control is effected by people Internal.
McGraw-Hill/Irwin © The McGraw-Hill Companies 2010 Auditing Internal Control over Financial Reporting Chapter Seven.
Deck 8 Accounting Information Systems Romney and Steinbart Linda Batch March 2012.
Copyright © 2007 Pearson Education Canada 9-1 Chapter 9: Internal Controls and Control Risk.
© 2008 Prentice Hall Business Publishing Accounting Information Systems, 11/e Romney/Steinbart1 of 315 C HAPTER 6 Control and Accounting Information Systems.
Copyright © 2014 Pearson Education, Inc. Publishing as Prentice Hall. Chapter
Company LOGO Chapter4 Internal control systems. Internal control  It is any action taken by management to enhance the likelihood that established objectives.
Lecture 5 Control and AIS Copyright © 2012 Pearson Education 7-1.
Governance, risk and ethics. 2 Section A: Governance and responsibility Section B: Internal control and review Section C: Identifying and assessing risk.
McGraw-Hill/Irwin © The McGraw-Hill Companies 2010 Internal Control in a Financial Statement Audit Chapter Six.
Chapter 6 Internal Control in a Financial Statement Audit McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
Auditors’ Dilemma – reporting requirements on Internal Financial Controls under the Companies Act 2013 and Clause 49 of the Listing agreement V. Venkataramanan.
Risk Management Dr. Clive Vlieland-Boddy. Managements Responsibilities Strategy – Hopefully sustainable! Control – Hopefully maximising profits! Risk.
Internal Control.
Chapter 4 Internal Controls McGraw-Hill/Irwin
Governance & Control in ERP Systems
Internal control - the IA perspective
Unit 11 October 22, 2017.
Control and Accounting Information Systems
Internal Control Internal control is the process designed and affected by owners, management, and other personnel. It is implemented to address business.
An overview of Internal Controls Structure & Mechanism
Presentation transcript:

Deck 5 Accounting Information Systems Romney and Steinbart Linda Batch February 2012

Contents Learning Objectives – Continue with Database design exercise – Start / Stop / Continue exercise – Chapter 7 Course material

Chapter 7 – Control and Accounting Info. Systems Definitions – Threat or event– a potential adverse occurrence – Exposure or impact – the potential dollar loss from a threat – Likelihood – the probability that it will occur – Intentional acts These are the words and criteria that are used when assessing whether controls are required.

Chapter 7 – Control Concepts Internal Control – Is the process implemented within your organization to provide reasonable assurance the following control objectives are achieved: Safeguard assets Maintain records with sufficient detail to support assets Provide accurate and reliable information Prepare financial reports in accordance with established criteria Promote and improve operating efficiency Encourage adherence to prescribed managerial policies Comply with applicable laws and regulations

Chapter 7 – Internal Controls Internal controls perform three functions – Preventive controls deter problems before they arise Segregating employee duties Controlling physical access to assets – Detective controls discover problems that were not prevented Preparing bank reconciliations Preparing monthly trial balances Duplicate checking of calculations – Corrective controls correct and recover from the resulting errors Maintaining backup copies of files Correcting data entry errors

Chapter 5 – Review – Fraud Triangle - Pressure General Controls make an organization’s control environment stable and well managed Security IT infrastructure Software acquisition Development Maintenance Application controls make sure transactions are processed correctly Accuracy Completeness Validity Authorization of the data captured, entered, processed, stored, and transmitted to other systems and reported. Internal controls are often segregated into two categories – General Controls – Application Controls

Chapter 7 – Large Control Breaches Enron - $62 billion in assets WorldCom - > $100 billion in assets Xerox Tyco Many more unfortunately In response to frauds – Sarbanes Oxley Act (SOX) was passed – Public company accounting oversight board (PCAOSB) – New rules for auditors – New roles for audit committees – New rules for management – New internal control requirements

Chapter 7 – Control Frameworks Three frameworks will be discussed that are used to develop internal control systems – COBIT – Information and Systems Audit and Control Association developed it for control objectives for Information and related technology – COSO – Committee of Sponsoring Organizations developed an Internal Control – Integrated Framework (IC) – COSO – Enterprise Risk Management – Integrated Framework (ERM)

Chapter 7 – Control Frameworks COBIT addresses control from three vantage points – Business Objectives To satisfy business objectives, information must conform to seven categories of criteria – IT Resources Including people, application systems, technology, facilities, and data – IT Processes Broken into four domains; planning and organization, acquisition and implementation, delivery and support, and monitoring and evaluation

Chapter 7 – Control Frameworks COSO’s Internal Control Framework – Control Environment – the core of any business is its people – Control Activities – control policies and procedures – Risk Assessment – identify, analyze, and manage risks – Information and Communication – systems capture and exchange the information needed to conduct, manage, and control the organizations operations – Monitoring- the entire process must be monitored and evolve as conditions warrant. Limitations of this framework – Examines controls without looking at the purpose and risks of business processes and does not provide context to determine which control process are most important, whether they address the risks, and if controls are missing.

Chapter 7 – Control Frameworks COSO’s ERM Framework – Takes a risk based approach rather than a controls based approach – It adds three additional elements to COSO’s IC Framework Setting objectives Identifying events that may affect the company Developing a response to assessed risk – Controls become flexible and relevant because they are linked to business objectives – ERM model also recognizes that in addition to being controlled, risk can be accepted, avoided, diversified, shared or transferred Example of a transferred risk?

Chapter 7 – ERM – Internal Environment Internal Environment A weak or deficient internal environment often results in a breakdown in risk management and control. Objective Setting Management sets objectives at the corporate level and these are cascaded down through other subunits Strategic Operational Reporting Compliance Event Identification Management sets objectives at the corporate level and these are cascaded down through other subunits Strategic Operational Reporting Compliance

Chapter 7 – Control Frameworks – Malware Any software that can be used to do harm. Spread through file sharing (72%), shared access to files (42%), attachments (25%), remote access vulnerabilities (24%)