THE STUDY & EVALUATION OF INTERNAL CONTROL. Definition Professional Standards Data-Oriented  Small, simple systems  Weaker controls System-Oriented.

Slides:



Advertisements
Similar presentations
Audit of Autonomous District Councils (in an IT environment using FAAM)
Advertisements

Internal Control and Control Risk
Internal Controls Becoming Compliant. Design & Implementation of Internal Controls. Design: Need to show that a framework is in place to establish internal.
Auditing Concepts.
Learning Objectives LO5 Document an accounting system to identify key controls and weaknesses in order to assess control risk. LO6 Write key control tests.
Auditing Computer-Based Information Systems
The Islamic University of Gaza
Chapter 5 Expenditure Cycle Applications. Expenditure Documents i.Purchase Requisitions ii.Purchase Orders iii.Receiving Report iv.Voucher Systems v.Invoice.
CHAPTER 10 UNDERSTANDING INTERNAL CONTROLS Fall 2007
Chapter 9 The Study of Internal Control and Assessment of Control Risk
Auditing A Risk-Based Approach To Conducting A Quality Audit
Chapter 4 IDENTIFYING RISKS AND CONTROLS IN BUSINESS PROCESSES.
Section 404 Audits of Internal Control and Control Risk
Chapter 13 Auditing Information Technology
INTERNAL CONTROL OVER FINANCIAL REPORTING
Copyright © 2013 by The McGraw-Hill Companies, Inc. All rights reserved.McGraw-Hill/Irwin.
Today’s Lecture application controls audit methodology.
Chapter 17: Computer Audits ACCT620 Internal Accounting Otto Chang Professor of Accounting.
CHAPTER 11 SUBTANTIVE AUDIT TESTING: Revenue Cycle
Auditing Internal Control over Financial Reporting
Chapter 5 Internal Control over Financial Reporting
Considering Internal Control
Auditing Complex EDP Systems
Chapter 7 Auditing Internal Control over Financial Reporting McGraw-Hill/Irwin ©2008 The McGraw-Hill Companies, All Rights Reserved.
Internal Control in a Financial Statement Audit
9 - 1 ©2003 Prentice Hall Business Publishing, Essentials of Auditing 1/e, Arens/Elder/Beasley Internal Control and Control Risk Chapter 9.
SAS Update GFOA Western Pa – January 2008 Presented by Rob Lent, CPA, CGFM.
©2003 Prentice Hall Business Publishing, Auditing and Assurance Services 9/e, Arens/Elder/Beasley Internal Control and Control Risk Chapter 10.
[Hayes, Dassen, Schilder and Wallage, Principles of Auditing An Introduction to ISAs, edition 2.1] © Pearson Education Limited 2007 Slide 8.1 Control Risk,
Copyright © 2007 Pearson Education Canada 1 Chapter 13: Audit of the Sales and Collection Cycle: Tests of Controls.
Evaluation of Internal Control System
1 Chapter 1 Introduction to Accounting Information Systems Chapter 18 Systems Implementation and Operation.
Audit Strategy and Audit Program
Understanding the IT environment of the entity. Session objectives Defining contours of financial accounting in an IT environment and its characteristics.
S4: Understanding the IT environment of the entity.
Evaluation of Internal Control System. Learning Objective 1 Contrast management’s need for internal control with the auditor’s need to consider internal.
Chapter 6 Internal Control in a Financial Statement Audit Copyright © 2014 McGraw-Hill Education. All rights reserved. No reproduction or distribution.
1 Chapter Nine Conducting the IT Audit Lecture Outline Audit Standards IT Audit Life Cycle Four Main Types of IT Audits Using COBIT to Perform an Audit.
Today’s Lecture Covers
McGraw-Hill/Irwin © 2003 The McGraw-Hill Companies, Inc., All Rights Reserved. 6-1 Chapter 6 CHAPTER 6 INTERNAL CONTROL IN A FINANCIAL STATEMENT AUDIT.
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin 6-1 Chapter Six Internal Control in a Financial Statement Audit.
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin 7-1 Chapter Seven Auditing Internal Control over Financial Reporting.
Auditing Internal Control Studies & Risk Assessment Chapter 9 Internal Control Studies & Risk Assessment Chapter 9.
BA 427 – Assurance and Attestation Services Lecture 21 Tests of Controls.
A Guide for Management. Overview Benefits of entity-level controls Nature of entity-level controls Types of entity-level controls, control objectives,
Learning Objectives LO5 Document an accounting system to identify key controls and weaknesses in order to assess control risk. LO6 Write key control tests.
IS 630 : Accounting Information Systems Auditing Computer-based Information Systems Lecture 10.
Copyright © 2007 Pearson Education Canada 1 Chapter 11: Overall Audit Plan and Audit Program.
Statement of Auditing Standard No. 94 The Effect of Information Technology on the Auditor’s Consideration of Internal Control in a Financial Statement.
Copyright © 2007 Pearson Education Canada 9-1 Chapter 9: Internal Controls and Control Risk.
Chapter 8-1 Chapter 8 Accounting Information Systems Information Technology Auditing Dr. Hisham madi.
Chapter 3-Auditing Computer-based Information Systems.
1 CHAPTER 5 - b INTERNAL CONTROL OVER FINANCIAL REPORTING.
©©2012 Pearson Education, Auditing 14/e, Arens/Elder/Beasley Considering Internal Control Chapter 10.
Copyright © 2014 Pearson Education, Inc. Publishing as Prentice Hall. Chapter
McGraw-Hill/Irwin © The McGraw-Hill Companies 2010 Internal Control in a Financial Statement Audit Chapter Six.
©2005 Prentice Hall Business Publishing, Auditing and Assurance Services 10/e, Arens/Elder/Beasley Internal Control and Control Risk Chapter 10.
8 INTERNAL CONTROL. Definition Duty  mgt (CEO)  Board  Internal auditor  Employee  External person.
Auditing Concepts.
Obtain and document understanding of internal control
Internal Audit & Accounting Systems Review
Problem 9-3, Page 473 Key Control, Control Test Evaluation
Internal Control in a Financial Statement Audit
Defining Internal Control
Problem DC 10-2, Page 547 What is K? The confidence factor
Statement of Auditing Standard No. 94
Audit Execution Session 5.
AUDIT TESTS.
Internal Control Internal control is the process designed and affected by owners, management, and other personnel. It is implemented to address business.
Presentation transcript:

THE STUDY & EVALUATION OF INTERNAL CONTROL

Definition Professional Standards Data-Oriented  Small, simple systems  Weaker controls System-Oriented  Large, complex  Strong controls Advanced Systems or Audits SYSTEMS-ORIENTED vs DATA-ORIENTED

Chronology of an Audit of Computer-based Accounting System document systems and controls plan and perform tests of systems and controls assess and document adequacy of systems and controls extend tests of systems, transactions and/or balances internal control letter use of/provide third party report for service bureau

Chronology of an Audit of a Computer-based Accounting System Document systems and controls Plan and perform tests of systems and controls Assess and document adequacy of systems and controls Extend tests of systems, transactions and/or balances Internal Control letter

Understand and document IT environment Review and document application Perform “walk - throughs” DOCUMENT SYSTEMS & CONTROLS

IT Strategic Plan IT Business Plan Organization Chart Information Security Policy Technology Summary Application Summary DOCUMENT IT ENVIRONMENT

Change Controls Logical access controls Business continuity plans System development policies Operation policies and procedures DOCUMENT IT ENVIRONMENT

Prepare Summary Flowchart Detailed flowcharts Narrative description Summary Processing Chart Summary Run Structure Chart REVIEW & DOCUMENT APPLICATION

Document Systems and Controls document applications, hardware, software, how EDP costs are accounted for/allocations, organization, policies and procedures, and any special risks review general computer controls document the results of the review

Document Systems and Controls document application processing procedures prepare/update summary flowchart then manual phase document computer processing phase update of master files, summarization of data, arith calcs, sorting/merging data, extraction of data from one/more files printing prepare EDP processing report

Confirm understanding of system Tests should cover:  key transactions types  related control information  error correction procedures LIMITED TESTS OR “WALK-THROUGHS”

Document Tests of Transaction Flows do walk-throughs to ensure that documentation accumulated to date reflects actual system in place trace computer phase recalc invoices, test ageing trace control info and balance procedures obtain and check batch totals

Document Tests of Transaction Flows trace error correction procedures select a few errors and check back to original source documents done to determine nature and that error was identified on exception report ensure properly rejected and properly corrected

Identify risks - ‘What Could Go Wrong’ Identify controls to mitigate risks Design appropriate tests Document test results PERFORM TESTS OF SYSTEMS & CONTROLS

What is the control objective What could happen to defeat objective Is there significant risk Identify key controls WHAT COULD GO WRONG

Identify controls to rely on High level versus low level controls Controls covering multiple control objective Interdependency of Controls DESIGN APPROPRIATE TESTS

Review of Error/Exception Reports  starts with reported error  point in time test  use of suspense accounts Replicate data entry Recompute procedure Use of test data PROGRAMMED ACCOUNTING PROCEDURES & CONTROLS

1.Interval testing 2.Reliance on Program Change Controls  authorised  tested  implemented correctly EXTENT OF PROGRAMMED CONTROL TESTING

Make clear it is programmed controls Extent of tests Reliance on change control DOCUMENTATION OF TESTS

Objective is to assess overall adequacy of internal control in areas to be relied on Assessment made at both general controls and application controls levels ASSESS ADEQUACY OF SYSTEMS & CONTROLS

Has each primary control objective been achieved If not:  document on weakness evaluation schedule  assess impact on individual applications Direct impact objectives:  logical access controls  program change controls EVALUATE GENERAL CONTROLS

Use of Evaluation Guides Could material error occur? Id. system efficiencies ADEQUACY OF CONTROLS BY SYSTEM

Planning and Performing Tests of Systems and Controls determine whether reliance warranted cost/benefit vs substantive ID key controls where reliance is appropriate consider overlapping manual controls look at related application controls

Planning and Performing Tests of Systems and Controls design and record tests arith accuracy (prog errors would be the cause) key totals having no documentary evidence (such as review/existence of a control group) key controls evidenced by completed accounting routines (monthly totals, error logs) key controls evidenced by signatures,initials (initially master file changes)

Assessing and Documenting Adequacy of Systems and Controls evaluate adequacy of general and financial controls use computer control evaluation guide assess impact of deficiencies use control weakness evaluation schedule evaluate adequacy of controls in each major system application controls master file changes, data controls, error controls use application control evaluation guide document conclusions

General Computer Control Weaknesses Application Control Weakness  reliance on preventive controls  reliance on detective controls Absent Control vs Ineffective Control Specific period control breakdown Reporting to management EXTENDED TESTS & REPORTING

Extended Tests of Systems, Transactions, Balances general control weaknesses must evaluate in light of each accounting application if preventive - need to look at associated detective controls if detective- may need to do procedure to check for evidence of errors CAATs, review transactions, reconciliations entire - vs specific period

Internal Control Letter basic information risks service opportunities general control weaknesses application control weaknesses practical recommendations

Chronology of an Audit of a Computer-based Accounting System Document systems and controls Plan and perform tests of systems and controls Assess and document adequacy of systems and controls Extend tests of systems, transactions and/or balances Internal Control letter