3. The nature and process for effective internal controls Flashcards
What are internal controls?
The controls within a business, set up by management, designed to mitigate the risks against achieving business objectives
Why do small companies have problems implementing internal controls?
Fewer members of staff means less segregation of duties and less options to review work.
There may also be fewer members of experienced staff -> less technical knowledge
Match the example with the control activity it illustrates
- Finance costs posted to the P&L are matched to amounts specified in loan agreements
- Wages are compared to agreed rates of pay from authorised payroll records
a) Verification
b) Reconciliation
1 b
2 a
You wouldn’t reconcile wages - because wages never balance. Instead, you verify that the pay matches the authorised rate
Are information systems and communication controls limited to IT?
NO
Information systems consists of manual processes - such as posting journals for provisions - and automated IT systems
What are general IT controls?
Controls over an entity’s whole IT processing system, such as;
Passwords for the hosted desktop
Training for use of system
Back up procedures
What are information processing controls?
Specific controls to a particular section of a business’ processes
For each of the following IT controls, state whether they are general or information processing controls:
- One to one checking
- Segregation of duties
- Review of master files
- Back-up copies
- Virus checks
- Passwords
- Training
- Record counts
- Hash totals
- Program library
- Back-up power source
- Controls over deleting nil balance accounts
- One to one checking - IT controls
(Checking one document to another) - Segregation of duties - General
- Review of master files - IT controls
(Checking ledger to master file) - Back-up copies - General
- Virus checks - General
- Passwords - General
- Training - General
- Record counts - IT controls
- Hash totals - IT controls
(Batch totals checked to invoices) - Program library - General
- Back-up power source - General
- Controls over deleting nil balance accounts - IT controls
What 4 things can limit an entity’s internal controls?
Expense of control (cost to implement compared to benefit)
Human element (human error can impede manual controls)
Collusion (both parties involved in the process and the control can collude to override control)
Unusual transactions (unknown risks may not be sufficiently controlled against)
What are the 5 components of internal controls?
C - Control activities. What do you do in the control
R - Risk assessment. Identification of risks that the control intends to manage
I - Information communication systems - how effective are the systems that are in place
M - Monitoring - Ensures the controls are used
E - Control environment - management’s attitudes to controls
What are the 5 types of control activities
Segregation of duties
Physical or logical controls
Verification
Reconciliation
Authorisation and approval
Who comprises the audit committee?
Non-executive directors
Match the internal control with the appropriate method that auditors would use to document:
a) Simple, non-complex systems
b) Standard & comprehensive systems
c) Diagrams/flow charts
- Narrative notes
- Internal controls questionnaire
- Complex systems
1 a
2 b
3 c