Understanding Internal Control Flashcards
Control Environment
reflects the overall attitude, awareness, and actions of the board of directors, management, owners, and others concerning the importance of control and its emphasis in the entity.
I - Integrity and ethical values
C - Commitment to competence
H - Human resource policies and practices
A - Assignment of authority
M - Management’s philosophy and operating style
B - Board of directors or audit committee participation
O - Organizational structure
Components of Internal Control
- Control Environment
- Risk Assessment
- Control Activities
- Information and Communication
- Monitoring
Control Activities
P - Performance reviews (budget to actual, forecasts, etc)
I - Information processing (controls that check accuracy)
P - Physical controls (assure physical security of assets)
S - Segregation of duties
COSO Internal Control Principles
Control Environment
- demonstrates a commitment to integrity and ethical values
- exercises oversight responsibility
- establishes proper structures, reporting lines, authorities and responsibilities
- demonstrates a commitment to competence
- enforces accountability of individuals
Risk Assessment
- Specifies clear objectives
- Identifies and analyzes risks to achievement of it objectives
- Considers the potential for fraud in assessing risks
- Identifies and assesses changes that could affect internal control
Control Activities
- Selects and develops appropriate control activities to mitigate risks to achievement of objectives
- Selects and develops general control activities over technology
- Deploys control activities that establish what is expected and place policies into action
Information and Communication
- Obtains or generates and uses relevant information to support internal control
- Communicates information internally to support internal control
- Communicates information externally to support internal control
Monitoring
- Conducts evaluations of whether components of internal control are present and functioning
- Evaluates and communicates internal control deficiencies in a timely manner to appropriate parties
monitoring activities
assessing the design and operation of controls on a timely basis and taking necessary corrective actions
Risk Assessment Procedures
- inquiries of management and others
- observing the application of specific controls
- inspecting documents and records
- tracing transactions through the information system
Tests of Controls Approaches
- Inquiries of appropriate personnel
- Inspection of documents and reports
- Observation of the application of controls
- Reperformance of the control by the auditor
Understanding Information Systems
the auditor should obtain sufficient knowledge of the information system to understand the financial reporting process used to prepare the entity’s financial statements, including sufficient accounting estimates and disclosures. Helps the auditor understand:
- entity’s classes of transactions
- how transactions are initiated
- accounting records and support
- accounting processing involved from initiation of a transaction to its inclusion in the financial statements
Assessing control risk
assessing control risk at a low level involves
- identifying specific controls relevant to specific assertions that are likely to prevent or detect material misstatements in those assertions
- performing tests of controls to evaluate the effectiveness of such controls.
Deficiency
the design or operation of a control does not allow management or employees, in the normal course of business, to prevent or detect misstatements on a timely basis
Significant Deficiency
a deficiency, or combination of deficiencies, in internal control that is less severe than a material weakness, yet important enough to merit attention by those responsible for oversight
Material weakness
a deficiency, or combination of deficiencies, in internal control such that there is a reasonable possibility that a material misstatement of the company’s annual or interim financial statements will not be prevented or detected on a timely basis
Control objectives
a specific target against which to evaluate the effectiveness of controls. A control objective for internal control generally relates to a relevant assertion and states a criterion for evaluating whether the company’s control procedures in a specific area provide reasonable assurance that a misstatement in the relevant assertion is prevented or detected on a timely basis.
Management’s assessment
required under SOX
Relevant Assertion
a financial statement assertion that has a reasonable possibility of containing misstatements that could cause the financial statements to be materially misstated
a. existence or occurrence
b. completeness
c. valuation or allocation
d. rights and obligations
e. presentation and dislcosure