Controls Flashcards
SCRUM
- Segregation of duties - I RACE
- Custody of assets
- Reconciliations/Review
- Unused stationary
- Management Review and Supervision - CREFT
Segregation of duties
No employee should be in the position to commit and hide fraud THUS segregate functions: (I RACE)
- Initiation
- Recording
- Approval
- Custody of Assets
- Execution
Custody of assets
- What are the risks?
- What are some controls over assets?
Risk of:
- Theft
- Damage
- Loss
- Misappropriation - use for wrong purpose
Controls over assets:
- Physical security: locked doors, CCTV
- Service asset regularly
- Physical access restricted
- Responsibility over assets
- Check assets regularly (e.g. count at end of day)
Reconciliations/Review
Perform - reconcile [x] to [y]
Reconcile each of these aspects:
[Ask] – [Receive] –[Recorded in accounts]
E.g. Bank recon, stock count
*Segregate review and recon
Unused stationary
Valuable as people can use to commit fraud.
Controls:
- Keep locked away
- One person has responsibility and issues out
- Sign out on a register
- Sequentially number and check
Management Review and Supervision
Review over: (CREFT) - Customer complaints - Reconciliations - Exception reports *must write out what the error is o Reasonability i.e. anything that doesn’t make sense o Attempted access and failure to access o Different rates/prices used o Missing items in sequences o Duplicates o Exceed limits o Overrides o Outside normal hours o DR/CR balance
- Financial results
- Trends (think ARPs)
o Actual to budget
o Month on month
o Ratios
Valid (5)
TEA2R
1. Think like a THIEF (common sense)
Put 2/3 controls against
- Exception reports
- Access controls
- Authorisation
Where in the systems is authorisation crucial? (2 points) e.g. exceed certain limit - Reconciliation [falls under all VAC]
Accurate (2)
- Input controls
- VILR FSS - Calculations - reperform – think p(excl vat) x q
COMPLETE (3) – usually “checking controls”
- Sequence check – missing and duplicates
* Must pre-number - Complaints register
- Customers
- Whistleblowing - ARPs – “management to perform the following ARPs as part of their monthly review”