Internal Control Internal control is the process designed and affected by owners, management, and other personnel. It is implemented to address business.

Slides:



Advertisements
Similar presentations
Internal Control and Control Risk
Advertisements

Control and Accounting Information Systems
Auditing Concepts.
Internal Control.
INTERNAL CONTROL COMPONENT Pertemuan_6 Mata Kuliah: CSP402, IT Governance Tahun Akademik : 2012/2013 SAS 78 / COSO Describes the relationship between the.
The Islamic University of Gaza
OMB Circular A-123 – Management’s Responsibility for Internal Control Policy Applicability Sources of Information Assessment, Documentation and Reporting.
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
Review of Introduction to Auditing
INTERNAL CONTROL. INTERNAL CONTROL DEFINED  INTERNAL CONTROL IS A PROCESS - EFFECTED BY AN ENTITY'S BOARD OF DIRECTORS, MANAGEMENT, AND OTHER PERSONNEL.
Standar Pekerjaan Lapangan: Pemahaman Memadai atas Pengendalian Intern Pertemuan 5.
CHAPTER 9 UNDERSTANDING INTERNAL CONTROLS Winter 2004
6-1 McGraw-Hill/Irwin ©2002 by The McGraw-Hill Companies, Inc. All rights reserved. Chapter 6 Internal Control Evaluation: Assessing Control Risk.
Internal Control. COSO’s Framework Committee of Sponsoring Organizations 1992 issued a white paper on internal control Since this time, this framework.
Internal Control in a Financial Statement Audit
Internal Control. COSO’s Framework Committee of Sponsoring Organizations 1992 issued a white paper on internal control Since this time, this framework.
Section 404 Audits of Internal Control and Control Risk
Sarbanes-Oxley Project Summary of COSO Framework Presented by Larry Dillehay & Scott Reitan Parkfield Group LLC.
INTERNAL CONTROL OVER FINANCIAL REPORTING
Elements of Internal Controls Preventing Fraud, Waste, and Abuse in Urban and Rural Transit Systems.
Auditing Internal Control over Financial Reporting
Auditing Internal Control over Financial Reporting
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin 3-1 Chapter Three Risk Assessment and Materiality Chapter Three.
Chapter 07 Internal Control McGraw-Hill/IrwinCopyright © 2014 by The McGraw-Hill Companies, Inc. All rights reserved.
INTERNAL CONTROL OVER FINANCIAL REPORTING
Chapter 5 Internal Control over Financial Reporting
Considering Internal Control
Internal Control in a Financial Statement Audit
Understanding Audit Risk Assessment
Chapter 7 Auditing Internal Control over Financial Reporting McGraw-Hill/Irwin ©2008 The McGraw-Hill Companies, All Rights Reserved.
NO FRAUD LEFT BEHIND The Effect of New Risk Assessment Auditing Standards on Schools Runyon Kersteen Ouellette.
Internal Control in a Financial Statement Audit
9 - 1 ©2003 Prentice Hall Business Publishing, Essentials of Auditing 1/e, Arens/Elder/Beasley Internal Control and Control Risk Chapter 9.
SAS Update GFOA Western Pa – January 2008 Presented by Rob Lent, CPA, CGFM.
©2003 Prentice Hall Business Publishing, Auditing and Assurance Services 9/e, Arens/Elder/Beasley Internal Control and Control Risk Chapter 10.
Learning Objectives LO5 Illustrate how business risk analysis is used to assess the risk of material misstatement at the financial statement level and.
Evaluation of Internal Control System
Evaluation of Internal Control System. Learning Objective 1 Contrast management’s need for internal control with the auditor’s need to consider internal.
[Hayes, Dassen, Schilder and Wallage, Principles of Auditing An Introduction to ISAs, edition 2.1] © Pearson Education Limited 2007 Slide 7.1 Internal.
McGraw-Hill/Irwin © 2003 The McGraw-Hill Companies, Inc., All Rights Reserved. 6-1 Chapter 6 CHAPTER 6 INTERNAL CONTROL IN A FINANCIAL STATEMENT AUDIT.
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin 6-1 Chapter Six Internal Control in a Financial Statement Audit.
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin 7-1 Chapter Seven Auditing Internal Control over Financial Reporting.
A Guide for Management. Overview Benefits of entity-level controls Nature of entity-level controls Types of entity-level controls, control objectives,
McGraw-Hill/Irwin © The McGraw-Hill Companies 2010 Auditing Internal Control over Financial Reporting Chapter Seven.
[Hayes, Dassen, Schilder and Wallage, Principles of Auditing An Introduction to ISAs, edition 2.1] © Pearson Education Limited 2007 Slide 7.1 Internal.
Pertemuan 15 Business and Information Process Rules, Risks, and Controls Matakuliah: M0034 /Informasi dan Proses Bisnis Tahun: 2005 Versi: 01/05.
Internal Control Chapter 7. McGraw-Hill/Irwin © 2006 The McGraw-Hill Companies, Inc., All Rights Reserved. 7-2 Summary of Internal Control Definition.
©2012 Prentice Hall Business Publishing, Auditing 14/e, Arens/Elder/Beasley Section 404 Audits of Internal Control and Control Risk Chapter.
Copyright © 2007 Pearson Education Canada 9-1 Chapter 9: Internal Controls and Control Risk.
©©2012 Pearson Education, Auditing 14/e, Arens/Elder/Beasley Considering Internal Control Chapter 10.
Copyright © 2014 Pearson Education, Inc. Publishing as Prentice Hall. Chapter
McGraw-Hill/Irwin © The McGraw-Hill Companies 2010 Internal Control in a Financial Statement Audit Chapter Six.
Internal Control. McGraw-Hill/Irwin © 2004 The McGraw-Hill Companies, Inc., All Rights Reserved. 7-2 Summary of Internal Control Definition A process...designed.
Chapter 6 Internal Control in a Financial Statement Audit McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
©2005 Prentice Hall Business Publishing, Auditing and Assurance Services 10/e, Arens/Elder/Beasley Internal Control and Control Risk Chapter 10.
Internal Control Chapter 7. McGraw-Hill/Irwin © 2008 The McGraw-Hill Companies, Inc., All Rights Reserved. 7-2 Summary of Internal Control Definition.
8 INTERNAL CONTROL. Definition Duty  mgt (CEO)  Board  Internal auditor  Employee  External person.
Illinois Office of the Comptroller Financial Training Workshop 2016.
Section 404 Audits of Internal Control and Control Risk
Modern Auditing: Assurance Services and the Integrity of Financial Reporting, 8th Edition William C. Boynton California Polytechnic State University at.
Auditing Concepts.
Internal Control in a Financial Statement Audit
Internal Control Evaluation: Assessing Control Risk
Internal Control Principles
PLANNING, MATERIALITY AND ASSESSING THE RISK OF MISSTATEMENT
Internal Control in a Financial Statement Audit
Defining Internal Control
INTERNAL CONTROLS AND THE ASSESSMENT OF CONTROL RISK
AUDIT TESTS.
Presentation transcript:

UNDERSTANDING THE ENTITY AND ITS ENVIRONMENT AND ASSESSING THE RISKS OF MATERIAL MISSTATEMENT

Internal Control Internal control is the process designed and affected by owners, management, and other personnel. It is implemented to address business risks that threaten the achievement of any of these objectives Reliability of financial reporting, Effectiveness and efficiency of operations and Compliance with applicable laws and regulations. to identify types of potential misstatements; to consider factors that affect the risks of material misstatements; and to design the nature, timing and extent of further audit procedures.

Components of Internal Control The control environment The entity’s risk assessment process The information system, including the related business processes relevant to financial reporting and communication. Control activities Monitoring of controls

The Control Environment Communication and enforcement of integrity and ethical values. Commitment to competence Participation by those charged with governance Management’s philosophy and operating style Organizational structure Human resource policies and practices

The Entity’s Risk Assessment Process It is the process of identifying and responding to business risks that affect entity’s financial reporting. Such process includes how management: identifies risks that affect entity’s ability to produce financial statement that give true and fair view, estimates their significance, estimates likelihood of their occurrence and Decides upon actions to manage them.

Cont.…….. Risks relevant to financial reporting include: internal events, and external events and circumstance That may occur and adversely affect an entity’s ability to: initiate, record, process, and report the financial information.

Cont.…….. Risks can arise due to circumstances such as the following: (internal/external) Changes in operating environment New personnel New information systems Rapid growth New technology New business models, product or activities Corporate restructurings Expanded foreign operations New accounting pronouncements

Information system The information system consists of: infrastructure (physical and hardware components), software people procedures and data Infrastructure and software will be absent, or have less significance, in systems that are exclusively or primarily manual. Many information systems make extensive use of IT.

Importance of Information System Identify and record all valid transaction. Describe the sufficient detail to permit proper classification of transactions for financial reporting. Measure the value of transactions in a manner that permits recording their proper monetary value in the financial statements. Determine the time period in which transactions occurred to permit recording of transactions in the proper accounting period. Present properly the transactions and related disclosures in the financial statements.

Communication Communication involves: providing an understanding of individual roles and responsibilities pertaining to internal control, understanding roles of others and doing exception reporting to higher level management. Communication takes such forms as: policy manuals, accounting and financial reporting manuals. It may also be made: electronically, orally and through the actions of management

Control Activities Control activities include: a) Performance reviews b) Information processing c) Physical controls d) Segregations of duties

Performance reviews These control activities include: reviews and analyses of actual performance versus budgets, forecasts, and prior period performance; relating different sets of data - operating or financial - to one another, together with analyses of the relationships and investigative and corrective actions; comparing internal data with external sources of information; review of functional or activity performance, review of reports by branch, region, and loan type for loan approvals and collections

Information processing A variety of controls are performed to check accuracy, completeness, and authorization of transactions. The two broad groupings of information systems control activities are: application controls and general IT controls. Application controls apply to the processing of individual applications. These controls help ensure that transactions occurred, are authorized, and are completely and accurately recorded and processed. General IT-controls commonly include controls over data center and network operations; system software acquisition, change and maintenance; access security; and application system acquisition, development, and maintenance. These controls apply to main-frame, mini-frame and end-user environments.

Physical controls These activities include the: physical security of assets, including adequate safeguards such as secured facilities access to assets and records; authorization for access to computer programs and data files; and counting and comparison with amounts shown on control records (for example comparing the results of cash, security and inventory counts with accounting records).

Segregation of duties Assigning different people the responsibilities of authorizing transactions, recording transactions, and maintaining custody of assets is intended to reduce the opportunities errors or fraud in the normal course of the person's duties. Examples of segregation of duties include reporting, reviewing, approval and control of documents.

Monitoring of Control The auditor should obtain an understanding of the major types of activities that the entity uses to monitor internal control over financial reporting, and how the entity initiates corrective actions to its controls. Monitoring means and includes: If monitoring is not done, people may stop performing the functions they are required to perform. It also involves assessing the quality of internal control performance over times. Monitoring may be ongoing activities, separate evaluations or a combination of the two. Monitoring includes: Supervisions, functions of managers Internal audit Communication from external parties indicating areas requiring

Assessing the Risk of Material Misstatement The auditor should identify and assess the risks of material misstatement at the financial statement level, and at the assertion level for classes of transactions, account balances, and disclosures. Identifies risks throughout the process of obtaining an understanding of the entity and its environment, including relevant controls that relate to the risks, and by considering the classes of transactions, account balances, and disclosures in the financial statements. Relates the identified risks to what can go wrong at the assertion level; Considers whether the risks that could result in a material misstatement of the financial statements

Significant Risks that require Special Audit Considerations non-routine transactions (unusual) judgmental matters (e.g. accounting estimates) non-routine transactions arising from matters such as: greater management intervention to specify the accounting treatment greater manual intervention for data collection and processing complex calculations or accounting principles non-routine transactions (unusual) complex calculations or accounting principles

For significant risks, to the extent the auditor has not already done so, the auditor should evaluate the design of the entity’s related controls, including relevant control activities, and determine whether they have been implemented. If management has not appropriately responded by implementing controls over significant risks and if, as a result, the auditor judges that there is a material weakness in the entity’s internal control, the auditor communicates this matter to those charged with governance as required. In these circumstances, the auditor also considers the implications for the auditor’s risk assessment.

Risks for which substantive procedures alone do not provide sufficient appropriate audit evidence As part of the risk assessment the auditor should evaluate the design and determine the implementation of the entity’s controls, including relevant control activities, over those risks for which, in the auditor’s judgment, it is not possible or practicable to reduce the risks of material misstatement at the assertion level to an acceptably low level with audit evidence obtained only from substantive procedures.