Module 17 Flashcards
Three components of internal control assessed at planning stages
Control environment
Risk assessment procedures
Monitoring of controls
Components of internal control systems identified at the planning stage
Information systems
Control activities
Auditor must gain understanding of control activities in place relevant to the audit which they deem necessary to understand (2)
- Risk of material misstatement at the assertion level
- Significant risks identified
Tabs
Brown
Auditors understanding of ITGC should be documented as (4)
1) Understanding of ITGC
2) Procedures to evaluate design and implementation and operating effectiveness of controls
3) Deficiencies
4) Conclusion on relevant audit assertions
If the information system is very manual
Higher risk of human error
If the IT system is highly complex
May make it more risky
Additional risks of IT systems: (4)
- IT system is very manual
- Complex IT system
- New IT system
- Increased risk profile of transactions
Audit of IT may require (unless simple ITGCs)
IT Specialists
Understanding of IT control activities within a process can be gained through (3)
- Discussion with activity owners
- Reviewing procedural manuals
- Confirming procedures documented in PY audit file
Variety of methods to document cycles (3)
- Flowcharts
- Narrative notes
- Checklists
Impact of weak control environment/ monitoring (2)
Controls less likely to be designed well or operating consistently
Weaknesses likely to affect number of systems therefore number of areas in FS
Impact of weak risk assessment procedures
May indicate inefficiencies in control system (controls not addressing nature of risks)
Increases likelihood of those risks occurring
Impact of weak information systems
Potential for override of controls
Impact of weak ITGC
Potential for transactions being processed through system incorrectly Eg if no passwords - no segregation of duties