Unit 6: Controls: Types and Frameworks Flashcards
is “any action taken by management, the board, and other parties to manage risk and
increase the likelihood that established objectives and goals will be achieved.”
Controls
“Management plans,
organizes, and directs the performance of sufficient actions to provide reasonable assurance that
objectives and goals will be achieved.”
Controls
“the policies, procedures (both manual and automated), and activities that
are part of a control framework, designed and operated to ensure that risks are contained within
the level that an organization is willing to accept.”
Control processes
“[t]he attitude and actions of the board and management regarding the
importance of control within the organization. The control environment provides the discipline
and structure for the achievement of the primary objectives of the system of internal control.
Control environment
Elements of Control Environment
● Integrity and ethical values
● Management’s philosophy and operating style
● Organizational structure
● Assignment of authority and responsibility
● Human resource policies and practices
● Competence of personnel
requires feedback on the results of organizational activities for the purposes of
measurement and correction.
controls
only provides reasonable assurance of achieving objectives. It cannot provide
absolute assurance because any system of internal control has inherent limitations
Internal control
is faulty, and controls may fail because of simple errors or mistakes. (internal Control inherent limitation)
Human Judgment
may inappropriately override internal controls, e.g., to fraudulently achieve
revenue projections or hide liabilities. (internal Control inherent limitation)
Management
Manual or automated controls can be circumvented (internal Control inherent limitation)
collusion
The _______ of internal control must not be greater than its __________.
Cost, Benefits
is a record by which accounting measurements, details of a trade, or other financial
data can be traced back to its source.
Audit Trails
can be used to verify and track transactions.
Audit Trails
For example, a transaction processing system can trace a purchase back to a copy of the purchase order to see when the items were ordered and who authorized the order.
Audit Trail
similar transactions to the same processing instructions
and thus virtually eliminates clerical error. But programming errors (or other similar systematic errors in either the hardware or software)
will result in all similar transactions being processed incorrectly when they are processed
under the same conditions.
Uniform Processing of Transactions
transaction, certain functions should be performed by separate individuals in different
parts of the organization.
Segregation of Duties
designed to detect fraud by one person but not fraud by collusion or management override.
internal control system
including those performing control procedures, to gain unauthorized
access to data, to alter data without visible evidence, or to gain access (direct or indirect) to assets
may be greater in computer systems.
Potential for Errors and Fraud
Computer systems offer management many analytical tools for review and supervision of
operations. These additional controls may enhance internal control.
Potential for Increased Management Supervision
Computer processing may produce reports and other output that are used in performing manual
control procedures.
Dependence of Controls in Other Areas on Controls over
Computer Processing
Certain transactions may be automatically initiated or certain procedures required to execute a
transaction may be automatically performed by a computer system.
Initiation or Subsequent Execution of Transactions by
Computer
(such as bank reconciliations or sign-offs on hard copy or electronic documents)
may be more suitable where judgment and discretion are required,
Manual Controls (Human Action)
For large, unusual, or nonrecurring transactions;
Manual Controls (Human Action)
For circumstances where misstatements are difficult to define, anticipate, or predict;
Manual Controls (Human Action)
In changing circumstances that require a control response outside the scope of an existing
automated control;
Manual Controls (Human Action)
In monitoring the effectiveness of automated controls.
Manual Controls (Human Action)
High-volume transactions that require additional calculations.
Automated Controls
(Electronic Action)
Routine errors that can be predicted and corrected.
Automated Controls
(Electronic Action)
Circumstances that require a high degree of accuracy.
Automated Controls
(Electronic Action)