Control, Security & Audit Flashcards
An internal control is…
…any action taken by management to enhance the likelihood that established objectives and goals will be achieved
The internal control system comprises…
…the control environment and control procedures.
It includes all the policies and procedures adopted by the directors and management of an entity to assist in achieving their objective of ensuring, the orderly and efficient conduct of its business, including:
1. Adherence to internal policies
2. Safeguarding of assets
3. Prevention and detection of fraud and error
4. Accuracy and completeness of accounting records
5. The timely preparation of reliable financial information
The control environment is…
…the overall context of control; the attitude of directors and managers towards control
…the overall attitude, awareness and actions of directors and management regarding internal controls and their importance in the entity
…management style, corporate culture and values shared by all employees
…the background against which the various other controls operate
Control procedures are…
…the detailed controls in place
…policies and procedures in addition to the control environment which are established to achieve the entity’s specific objectives
Elements of a strong control environment: (6)
- Clear strategies
- Culture, code of conduct, HR policies and performance reward systems support objectives, risk management and internal control systems
- Senior management’s commitment to competence, integrity and fostering a climate of trust
- Clear definition of authority, responsibility and accountability
- Communication
- Knowledge, skills and tools to support objectives
Controls can be classified in various ways:
- Administrative & accounting
- Prevent, detect & correct
- Discretionary & non-discretionary
- Voluntary & mandated
- Manual & automated
Classification of controls: Administration:
Concerned with achieving objectives and implementing policies; Relate to channels of communication and reporting responsibilties
Classification of controls: Accounting:
Aim to provide accurate accounting records and achieve accountability;
Apply to recording transactions and establishing responsibilities for records, transactions and assets
Classification of controls: Prevent:
Prevent errors from happening in the first place;
Checking invoices from suppliers against GRN’s before paying
Classification of controls: Detect:
Detect errors once they have happened;
Bank reconciliations; Physical checks of inventory against inventory records
Classification of controls: Correct:
Designed to minimise or negate the effect of errors;
Backup of computer input
Classification of controls: Discretionary:
Subject to human discretion
Checking a signature on a PO
Classification of controls: Non-discretionary:
Provided automatically by the system; cannot be overridden;
Pin at an ATM
Classification of controls: Voluntary:
Chosen by the organisation to support the management of the business
Classification of controls: Mandated:
Required by law; imposed by external authorities
Classification of controls: Manual:
Demonstrate a one-to-one relationship between the processing functions and the controls, and the human functions
Classification of controls: Automated:
Programmed procedures designed to prevent, detect and correct errors all the way through processing
Classification of controls: General:
Used to reduce the risks associated with the computer environment; Relate to the environment in which the application is operated
Classification of controls: Application:
Used to reduce the risks associated with the computer environment; Prevent, detect and correct errors
Classification of controls: Financial:
Focus on key transaction area, emphasis being on safeguarding assets and maintenance of proper accounting records and reliable financial information
Types of Financial Control Procedures: (8 - ‘SPAMSOAP’)
- Segregation of duties
- Physical
- Authorisation & approval
- Management
- Supervision
- Organisation
- Arithmetical and accounting
- Personnel
Internal controls should not be confused with internal checks which are…
…the checks on the day-to-day transactions whereby the work of 1 person is proved independently or is complementary to the work of another, the object being the prevention / early detection of errors and fraud;
Delegation
Allocation of authority and the division of work
Method of recording transactions
Use of independently ascertained totals
Arithmetical internal checks include: (3)
- A pre-list drawn up before any processing takes place
- A post-list drawn up during or after processing
- A control total used for control purposes by comparing to another total that ought to be the same
Characteristics of a good internal control system: (11)
- Clearly defined organisation structure (overall coordination of company activities)
- Adequate internal checks
- Acknowledgment of work done (Signatures)
- Physical security
- Formal documents acknowledging transfer of goods
- Pre-review
- Clearly defined system for authorising transactions
- Post-review
- Authorisation, custody and re-ordering procedures (Access to assets limited to authorised personnel)
- Capable and qualified personnel
- Internal audit department
Internal audit is…
…an independent appraisal activity established within an organisation as a service to it; control which functions by examining and evaluating the adequacy and effectiveness of other controls; Part of the internal control system
The need for internal audit will depend on: (7)
- Scale, diversity and complexity of activities
- Number of employees
- Cost-benefit consideration
- Changes in structure, reporting processes or information systems
- Changes in key risks
- Problems with internal control systems
- Increased number of unexplained or unacceptable events
Objectives of Internal Audit: Work may cover the following tasks: (8)
- Review of accounting and internal control systems
- Examination of financial and operating information
- Review of the economy, efficiency and effectiveness of operations
- Review of compliance
- Review of safeguarding assets
- Review of implementation of corporate objectives
- Identification of significant business & financial risks
- Special investigations
The 2 main features of internal audit:
- Independence
2. Appraisal (not carry out any organisational work themselves)
Accountability: The internal auditor is accountable to the Audit committee for 3 main reasons:
- Auditor needs access to all parts of the organisation
- Auditor should be free to comment on management performance
- Auditor’s report may need to be actioned at the highest level
External audit is…
…a periodic examination of the books of account and records of an entity carried out by an independent third party to ensure:
- they have been properly maintained
- accuracy and compliance with established concepts, principles, accounting standards and legal requirements
- Give a true and fair view of the financial state of the entity
IT Systems: Security can be divided into a number of aspects: (6)
- Prevention
- Detection
- Deterrence
- Recovery procedures
- Correction procedures
- Threat avoidance
Physical access controls: (4)
- Personnel
- Door locks
- Key pad / card entry system
- Intruder alarms
Controls in an information system: (3)
- Security controls
- Integrity controls
- Contingency controls
Security controls can be defined as…
…the protection of data from accidental or deliberate threats which might cause unauthorised modification, disclosure or destruction of data and the protection of the information system from the degradation or non-availability of services
Risks to data: (8)
- Human error
- Technical error
- Natural disasters
- Deliberate actions
- Commercial espionage
- Malicious damage
- Industrial action
- Malware programs
Integrity controls consist of: (2)
- Data integrity
2. Systems integrity
Data integrity is…
…preserved when data is the same as in source documents and has not been accidentally or intentionally altered, destroyed or disclosed
Systems integrity is…
…system operation conforming to the design specification despite attempts to make it behave incorrectly
Integrity controls include: (5)
- Input controls:
a. Data verification (Matches source documents)
b. Data validation (Check digits, control totals, hash totals, range checks, limit checks) - Processing controls
- Output controls
- Back up controls
- Archiving
Back up means…
…to make a copy in anticipation of future failure or corruption. A back-up copy is a duplicate kept separately from the main system; only used if the original fails
A password is…
…a set of characters which may be allocated to a person, a terminal or a facility which is required to be keyed into the system before further access is permitted
An audit trail is…
…a record showing who has accessed a computer system and what operations he or she has performed.
A contingency is…
… an unscheduled interruption of computing services that requires measures outside the day-to-day routine operating procedures
A disaster recovery plan must provide for: (3)
- Standby procedures
- Recovery procedures
- Personnel management policies
Types of audit: (5)
- Operational audit
- Systems audit
- Transactions audit
- Social audit
- Management investigations
An operational audit may also be known as a(n):
- Management audit
- Efficiency audit
- Value for money audit