Specific transaction cycles Flashcards
Transaction cycle
A transaction cycle is a group of essentially homogeneous transactions, that is, transactions of a particular type. The bulk of a company’s economic activities can be grouped into a relative few categories called transaction cycles.
Implication
Within a given category of transactions, control risk is essentially constant, since all transactions within that category are processed subject to the same configuration of internal control policies and procedures. A transaction cycle is, therefore, the highest level of aggregation for which control risk may be viewed as a constant.
As a tool to analyze the audit considerations of internal control policies and procedures in each transaction cycle, remember that internal controls (specifically, “control activities”) should “SCARE”!
Segregation of duties, Controls (as in physical controls), Authorization, Reviews (as in performance reviews), and EDP/IT (information processing).
Segregation of duties
This is also referred to as separation of duties and involves separating incompatible functions to the extent possible. The same employee should not normally (1) authorize transactions (execution function), (2) have access to the related assets (custody function), and (3) perform accounting activities (record keeping function) in the ordinary course of duties. In essence, these three activities are like points on a triangle and each point of the triangle should ideally be vested in different employees, subject to cost-benefit considerations.
Controls (Physical Controls)
Access to assets (and to important accounting documents and computer systems) should be limited to authorized personnel. In addition, assets should be periodically counted, as appropriate, and compared to the corresponding accounting records for agreement. This is important in safeguarding assets and in establishing accountability for assets.
Authorization
Transactions should be executed in accordance with management’s authorization.
Reviews (Performance Reviews)
Actual performance should be compared to appropriate budgets and forecasts. Internal data should be compared to external sources of information as appropriate. Analyses of relationships should be performed and investigative and corrective action should be taken as needed.
EDP/IT (Information Processing)
Information technology (IT) controls consist of two basic categories:
1) General controls, which are policies and procedures that have widespread effect on many specific applications
2) Application controls, which refer specifically to the processing of particular computer applications
Proper segregation of duties reduces the opportunities to allow persons to be in positions to both
Segregation of duties involves the separation of the responsibilities of authorizing transactions, recording transactions, and maintaining custody of assets. It is intended to reduce the opportunities for any person to be in a position to both perpetrate and conceal errors or irregularities in the normal course of his/her duties.