l7 : controls & recommendations Flashcards
what are controls?
management put these in place to prevent, detect or correct errors
why are controls tested?
reduce the control risk which reduces overall audit risk. reduces need for substantive testing. ensures that controls are effective.
what are the 5 types of control?
Physical
Authorisation
Reconciliation
Information Processing
Segregration of duties
what is the process of controls testing?
- control in place, someone does something (be precise) (PARIS)
- what error does this control prevent, detect or correct? use assertions (CAVECOP)
- carry out control test (EIOU)
give 3 examples of physical as a type of control.
- cash in a safe
- physical locks
- passwords on systems
give 2 examples of authorisation as a type of control.
- authorising buying things
- needing signatures
give 2 examples of reconciliation as a type of control.
- matching bank & cash
- matching invoices & bank statements with each expense
give an example of information processing as a type of control.
- passwords
give an example of segregration of duties as a type of control.
- use diff people to verify & check transactions as more likelihood for mistakes or fraud to be made if only one person involved in process
what is the process of control recommendations?
- deficiency. what is not happening?
- implication. so what? persuade client to implement the controls
- recommendation. who? what? when? how often? in the ideal world.