Topic 9 Systems Flashcards
What is the audit process with regards to systems
1) Ascertain the system
2) Document the system
3) Evaluate the system- TOC
Confirm the operation of the system (testing controls i.e. audit evidence)
.
5. Report on the deficiencies on a ‘Management Letter/Management Weakness letter’
What is internal control and it’s importance
Internal controls are the policies and procedures designed and effected by directors and managers to enable the achievement of the entity’s objectives with regard to reliability of financial reporting, effective and efficiency of operations and compliance with application of laws and regulations
The importance of internal control is quite simply to manage problems that could prevent organization from achieving it’s objectives
Internal controls are the policies and procedures used by directors and managers to help ensure the effective and efficient conduct of the business;
what are some examples of business objectives
safeguard of assets
regulatory compliance
prevention and detection of fraud and error
the accuracy and completeness of accounting records
the time preparation of reliable financial information
why is internal control important
more reliable systems of control mean lower risk of material misstatement
reliable systems contain stronger controls
The auditors must understand the system and the controls within the system. Once these are understood then only can they test whether the controls work
The more effective and reliable the system, the lower the audit risk and the greater the reliance the auditor can seek to place upon the system
what does a reliable system =?
reliable system = lower audit risk = less substantive testing
More reliable system of control mean lower risk of material misstatement. Reliable systems contain stronger controls
The auditor must: Understand the system. and the controls within the system and test whether the controls work
The more effective and reliable the system the lower the audit risk and the greater the reliance the auditor can seek to place upon the system
ISA 315 identifying and assessing the risks of material misstatement through understanding the entity and its environment” considers the components of an entitys internal control.
what are the components of Internal control (CRIME)
list them
control activities (APIPS+IT Controls) Risk assessment of entity Information system relevant to financial reporting Monitoring of controls Environment (control )
components of Internal control (CRIME)
what is Control activities (APIPS IT)
Authorisation Performance review Information processing Physical controls Segregation of duties IT Controls
Control activities (APIPS)
what are the two types of IT controls
Application controls
General controls
Control activities (APIPS)
what are application controls definition
These are controls build into a specific application within a system
can be auto or manual
Control activities (APIPS)
what are some examples of application controls
- Document counts (invoice on hand vs on screen)
2) Sequence checks (you can run missing sequence report for missing dispatch notes to help you realise you’ve missed out on revenue if you haven’t electronically delivered it yet)
3) Arithmetic checks e.g. VAT
4) Range checks (min & max pay)
5) Batch reconciliation/Batch control (checking the total on the system matches with what’s on hand- should balance) - Validation checks
Control activities (APIPS)
what are general controls definition
These are controls over the computer environment. it effects multiple areas of the IT controls.
These include policies and procedures that relate to many applications and support the effective functionating of application controls.
Control activities (APIPS)
what are some examples of general controls
- Software update
- systems are networked
- training provided
- software and hardware maintenance
- passwords and restricted access
- backup
- virus software
- door locks
components of Internal control (CRIME IT)
Back to CRIME, what is R.. explain
entity’s risk assessment process
A more robust risk assessment process will reduce the risk of misstatement
For Financial reporting purposes, the entity’s risk assessment process includes how management identifies ALL business risks relevant to the preparation of financial statements in accordance with the entity’s applicable financial reporting framework.
Can be ANY RISK that the management are concerned with (not just to do with statements)
It estimates their significance, assesses the likelihood of their occurrence, and decides upon actions to respond to and manage them and the results thereof.
components of Internal control (CRIME IT)
Back to CRIME, what is I.. explain
“Information system, including the related business processes, relevant to financial reporting and communication”
The auditor should obtain an understanding of the information system, including the related business processes, relevant to financial reporting
these include
- accounting system
- procedures and records designed and established to initiate records
- process of information
- and report entity transactions
These cover the important cycles;
- Sles
- Payroll
- Purchases
components of Internal control (CRIME IT)
Back to CRIME, what is M.. explain
Monitoring of controls (often done by internal auditor)
Management must monitor controls to ensure they are operating and are effective
It involves assessing the effectiveness of controls on a timely basis and taking necessary remedial actions.
Management accomplishes the monitoring of controls through on going activities, separate evaluations, or a
combination of the two.
On-going monitoring activities are often built into the normal recurring activities of an entity and include regular management and supervisory activities.
components of Internal control (CRIME IT)
Back to CRIME, what is E.. explain
Control environment
This includes the attitude and philosophy of management with regard to control e.g. commitment to integrity and ethical values, a formal organisation structure and proper training of staff
The control environment includes the governance and management functions and the:
- Attitudes
- Awareness
- Actions
of those charged with governance and management concerning the entity’s internal control and its importance in the entity.
The control environment sets the tone of an organisation, influencing the control consciousness of its people.
The control environment has many elements such as communication and enforcement of integrity and ethical values, commitment to competence, participation of those charged with governance, management’s philosophy and operating style, organisational structure, assignment of authority and responsibility and human resource policies and practices.
what are five systems that you will need to understand the process of
which you will need to know
- Control objective
- Controls that client has in place
- Test of control (Auditor checking the controls in place)
revenue purchase wages bank inventory
what is the general definition of a control objective in relation to the processes/systems
A control objective identifies the risk that the entity needs to manage i.e. the reason for a control procedure or activity being required.
wanting something good to happen
OR
Not wanting something bad to happen
For example, a risk within a purchasing system is that purchases could be made for personal use and paid by the company. Therefore the control objective is to ensure goods cannot be purchased for personal use. Most companies would have a control procedure in place to prevent this risk from occurring such as authorisation of purchase orders by a responsible official
what are the objectives of a sales/revenue system
✓ Sales are made to valid (good credit) customers
✓ Sales are recorded accurately
✓ orders are dispatched promptly and to correct person
✓ only valid sales are recorded
✓ all sales and receivables are recorded
✓ revenue is recorded in the period it relates to
✓ Cash collected and allocated on a timely manner
list briefly the stages of a sales/revenue cycle
1 Order received 2 Goods Dispatched (Department) 3 Invoice sent (accounts department) 4 Transactions recorded in books 5 Cash received & recorded
look at book to learn in detail the control procedure for each
what are the objectives of a wages system
- Pay the right people
- pay genuine people
- the right wage rate
- pay for the hours worked
- Gross pay is calculated and recorded accurately
- Net pay is calculated and recorded accurately
- correct amounts owed are calculated, recorded and paid to tax authorities
list briefly the stages of a wages cycle
- Clock cards submitted and input
- gross pay, deductions and net pay calculated
- Other amendments input
- Final payroll calculated and pay slips produced
- Payments to employees and tax authorities
(Separation of duty between those that store HR data and the people that process the wage
- Payroll costs and payments recorded
what are the objectives of a purchase system
✓ Order are made for a valid purchase
✓ they are of appropriate quality and price
✓ Cost effective
✓ Purchases are recorded accurately
✓ All purchases recorded
✓ Payables are recorded at appropriate value
✓ Expenditure is recorded in the period it relates to
✓ Cash paid and allocated on a timely manner
list briefly the stages of a purchases cycle
1 Requisition raised 2 Order placed 3 Accounts Department 4 Invoice received 5 Transactions recorded in the books 6 Cash payments
what are the objectives of a cash system
✓ Cash is safeguarded
✓ Minimal cash held on site for legitimate expenditure
✓ Payments for authorised business expenditure only
✓ Cash and cheque books are safeguarded
✓ Receipts are banked on a timely basis
✓ Cash movements are recorded on a timely basis
list briefly the stages of a cash cycle
- Request for payment
- Payment authorisation
- Payments made/ receipts
- Payments and receipts are recorded
what are the objectives of a inventory system
- Inventory levels meet the needs of production (raw materials and components) and customer demand (finished goods)
- Inventory levels are not excessive, preventing obsolesence and unnecessary storage costs
- inventory is safeguarded from theft, loss or damage
- Inventory movements are recorded on a timely basis
- All inventory is recorded
- Inventory is valued at lower of cost and NRV
list briefly the stages of a Inventory cycle
1) Goods Received (Supplier) or Good Dispatched/Returned goods
2) goods are stored in a warehouse + Recorded / dispatch recorded
3) Movements posted to nominal ledger and inventory cards
From the audit process below, what happens in ascertaining the system
1) Ascertain the system
2) Document the system
3) Evaluate the system- TOC
.
4. Confirm the operation of the system (testing controls i.e. audit evidence)
.
5. Report on the deficiencies on a ‘Management Letter/Management Weakness letter’
Procedures used to obtain evidence regarding the design and implementation of controls include:
examine previous audit work
Enquiries of relevant personnel.
Observing the procedures / application of controls.
Tracing a transaction through the system to understand what happens (a walkthrough test).
.
Inspecting documents, such as internal procedure manuals.
It should also be noted that enquiry alone is not sufficient to understand the nature and extent of controls.
Auditors can also use existing knowledge of the client and the operation of the systems. However, the auditor cannot simply rely on their knowledge from the prior year audit as changes may have occurred. Systems knowledge must be updated and the systems tested once more.
.
.
From the audit process below, what happens in Testing Controls/the system and give examples of methods
- plan the audit
. - understand/ascertain the systems and controls
-> System notes (note taking of the system by auditor)
-> Components (CRIME)
-> Activities/systems ( APIPS)
. - Confirm the operation of the system (testing controls i.e. audit evidence)
. - Report on the deficiencies
A test of control involves the auditor obtaining evidence that the client has implemented the controls they say they have, and that they have worked effectively, during the period. Typical methods of controls testing include:
Walk through (confirmation of the auditors understanding of a system and how it works- THIS IS NOT A TOC)
below are all test of controls:
Observation of control activities, e.g. observing the inventory count to ensure it is conducted effectively and in accordance with the count instructions.
.
Inspection of documents recording performance of the control, e.g. inspecting an order for evidence of authorisation.
.
Computer-assisted audit techniques (such as test data to ensure the programmed controls are working effectively. See the ‘Evidence’ chapter).
From the audit process below, what happens in communicating control deficiencies and give examples of methods
1) Ascertain the system
2) Document the system
3) Evaluate the system- TOC
.
4. Confirm the operation of the system (testing controls i.e. audit evidence)
.
5. Report on the deficiencies on a ‘Management Letter/Management Weakness letter’
The Auditors will communicate deficiencies in the internal controls to those charged with governance and management. This will be communicated via a management letter or report to management sent at the end of the audit process. This is a two part :
1) Covering letter
- covers the deficiencies identified during audit work
- for sole use of the company
- no disclosure to third parties without agreement
- no responsibility assumed to any other parties
2) Appendix
- Deficiencies
- Consequences
- Recommendations
Space for managements response
In the exam, you have to follow this:
1) Identify the deficiency
2) The consequence of that deficiency
3) Recommendation
From the audit process below, what happens in documenting the system and give examples of methods
1) Ascertain the system
2) Document the system
3) Evaluate the system- TOC
.
4. Confirm the operation of the system (testing controls i.e. audit evidence)
.
5. Report on the deficiencies on a ‘Management Letter/Management Weakness letter’
The auditor must document the client’s control systems before evaluating whether the system is adequate and working effectively.
- Narrative notes (written desctiption of system)
- Flow charts
- Organisation chart
- Questionnaires
- > Internal control questionnaire (ICQ)
- > Internal control evaluation questionnaire)
what is a narrative notes and advantages
The main advantage of narrative notes is that they are simple to record, after discussion with the company these discussions are easily written up as notes.
Additionally, as the notes are simple to record, this can facilitate understanding by all members of the team, especially more junior members who might find
alternative methods too complex.
what are narrative notes dis-advantages
Narrative notes may prove to be too cumbersome, especially if the system is complex.
This method can make it more difficult to identify missing internal controls as the notes record the detail but do not identify control exceptions clearly.
what is a flow charts and advantages
A pictorial of how the system works
Can be prepared quickly.
Tend to be easily followed and understood.
Eliminates the need for detailed narrative notes.