8. Internal Control, Fraud Flashcards
What does the term internal controls refer to?
The collection of mechanisms whereby an organisation tries to ensure that all it’s transactions are properly authorized and recorded, and that it’s assets are safeguarded.
Who’s responsibility is it to ensure that a good system of internal control is operating?
The directors’
What are the two parts of internal control?
- Control environment
- Detailed control processes
What is the control environment?
The views that a company has on internal control.
Why is a good control environment important?
Because if a company sees it as a nuisance then the detailed control processes would likely be ignored
What are examples of detailed control processes?
- Overtime being authorised by a manager
- Cancelling a suppliers invoice once it’s been paid to avoid paying twice
- Taking up a credit reference before sending goods to a new customer
- Making it impossible to dispatch goods to a customer if it puts them over their credit limit
- Following up aged receivables
- Segregation of duties for each part of a transaction to reduce fraud and error
What are examples of internal control methods?
- Physical safeguarding (eg for cash and inventory)
- Authorization (eg overtime)
- Segregation of duties
- Reconciliations
- Trial balances and control account reconciliation
- Recalculation and re-performance (eg recalculating an invoice to ensure correct prices are used)
- Internal audit
- Separating clients and company’s money (eg for law firms)
What are some risks involved with IT systems?
- Inaccurate processing of data
- Unauthorized access to data
- IT personnel gaining access beyond what’s required
- Unauthorized changes to master files
- Unauthorized changes to systems or programs
- Failure to keep systems or programs up to date
- Potential loss of data
- Inability to access data
- Cyber attacks
What are the two types of controls for IT systems?
- General controls
- Application controls
What are general controls?
- Policies and procedures relating to the computer environment and therefore all applications
- Ensures continued, proper operation of information systems
What are examples of things covered by general controls?
- Data centre and network operations
- System software acquisition, change and maintenance
- Application system acquisition, development and maintenance
- Access security
- Internet connections
Examples of general controls used for data center and network operations:
- Anri-virus
- Firewalls
- Disaster recovery plans
What are application systems?
Programs that carry out specific operations needed by the company.
Eg
- Calculating wages
- Inventory forecasting
What are general controls used to protect systems connected to the internet?
- Passwords
- Virus-checkers
- Encryption
What are application controls?
Manual or automated procedures that typically operate at a business process level to ensure transactions are authorized, accurately recorded, processed and reported.
Business process level includes processing of:
- Sales orders
- Wages
- Payments to suppliers