6 - Application Controls, Masterfiles & ITGC Flashcards
input controls examples?
- validity check (reconcile against masterfile)
- limit checks
- reasonableness check
- format checks
types of processing?
- batch entry AND processing (both later)
- online entry and batch processing
- online entry, real-time processing
processing controls examples?
- sequence test
- limit test
- matching
- reasonability
validity objectives for masterfiles?
- only valid amendments made
- only auth. people are able to make changes
- fictitious, unapproved changes could be processed due to staff not involved in the amendment process making changes
accuracy risks in masterfiles?
- details are not recorded correctly (capturing errors)
- person capturing could be incompetent, untrained
completeness risks in masterfiles?
all amendments are not captured and processed because MAF is lost
overall controls for masterfile amendments?
- duty segregation
- restrict physical access
- reconciliation of input to output
- keep a back-up
- audit trails
- exception reports
control environment consists of?
- comm/enforcement of ethical values in IT env
- mgmt philosophy / operating style
- assigning auth/resp
- commit to competence
systems dev/impl controls?
- change requests approved by IT manager
- changes to system must be made by programmers not users
- IT manager to review changes once made
access controls examples?
- cctv
- passwords, IDs, biometric scans
- physical restrictions
continuity of operations controls?
- physical security to protect computer system from damage, theft
- disaster recovery such as back-ups
documentation?
- document all IT processes and controls in detail
- restrict important documents to only be used by authorized people
what are application controls?
controls within any application the org uses to ensure the VAC of the processing and recording of transactions in that application