Topic 9 Systems Flashcards
What is the audit process with regards to systems
1) Ascertain the system
2) Document the system
3) Evaluate the system- TOC
Confirm the operation of the system (testing controls i.e. audit evidence)
.
5. Report on the deficiencies on a ‘Management Letter/Management Weakness letter’
What is internal control and it’s importance
Internal controls are the policies and procedures designed and effected by directors and managers to enable the achievement of the entity’s objectives with regard to reliability of financial reporting, effective and efficiency of operations and compliance with application of laws and regulations
The importance of internal control is quite simply to manage problems that could prevent organization from achieving it’s objectives
Internal controls are the policies and procedures used by directors and managers to help ensure the effective and efficient conduct of the business;
what are some examples of business objectives
safeguard of assets
regulatory compliance
prevention and detection of fraud and error
the accuracy and completeness of accounting records
the time preparation of reliable financial information
why is internal control important
more reliable systems of control mean lower risk of material misstatement
reliable systems contain stronger controls
The auditors must understand the system and the controls within the system. Once these are understood then only can they test whether the controls work
The more effective and reliable the system, the lower the audit risk and the greater the reliance the auditor can seek to place upon the system
what does a reliable system =?
reliable system = lower audit risk = less substantive testing
More reliable system of control mean lower risk of material misstatement. Reliable systems contain stronger controls
The auditor must: Understand the system. and the controls within the system and test whether the controls work
The more effective and reliable the system the lower the audit risk and the greater the reliance the auditor can seek to place upon the system
ISA 315 identifying and assessing the risks of material misstatement through understanding the entity and its environment” considers the components of an entitys internal control.
what are the components of Internal control (CRIME)
list them
control activities (APIPS+IT Controls) Risk assessment of entity Information system relevant to financial reporting Monitoring of controls Environment (control )
components of Internal control (CRIME)
what is Control activities (APIPS IT)
Authorisation Performance review Information processing Physical controls Segregation of duties IT Controls
Control activities (APIPS)
what are the two types of IT controls
Application controls
General controls
Control activities (APIPS)
what are application controls definition
These are controls build into a specific application within a system
can be auto or manual
Control activities (APIPS)
what are some examples of application controls
- Document counts (invoice on hand vs on screen)
2) Sequence checks (you can run missing sequence report for missing dispatch notes to help you realise you’ve missed out on revenue if you haven’t electronically delivered it yet)
3) Arithmetic checks e.g. VAT
4) Range checks (min & max pay)
5) Batch reconciliation/Batch control (checking the total on the system matches with what’s on hand- should balance) - Validation checks
Control activities (APIPS)
what are general controls definition
These are controls over the computer environment. it effects multiple areas of the IT controls.
These include policies and procedures that relate to many applications and support the effective functionating of application controls.
Control activities (APIPS)
what are some examples of general controls
- Software update
- systems are networked
- training provided
- software and hardware maintenance
- passwords and restricted access
- backup
- virus software
- door locks
components of Internal control (CRIME IT)
Back to CRIME, what is R.. explain
entity’s risk assessment process
A more robust risk assessment process will reduce the risk of misstatement
For Financial reporting purposes, the entity’s risk assessment process includes how management identifies ALL business risks relevant to the preparation of financial statements in accordance with the entity’s applicable financial reporting framework.
Can be ANY RISK that the management are concerned with (not just to do with statements)
It estimates their significance, assesses the likelihood of their occurrence, and decides upon actions to respond to and manage them and the results thereof.
components of Internal control (CRIME IT)
Back to CRIME, what is I.. explain
“Information system, including the related business processes, relevant to financial reporting and communication”
The auditor should obtain an understanding of the information system, including the related business processes, relevant to financial reporting
these include
- accounting system
- procedures and records designed and established to initiate records
- process of information
- and report entity transactions
These cover the important cycles;
- Sles
- Payroll
- Purchases
components of Internal control (CRIME IT)
Back to CRIME, what is M.. explain
Monitoring of controls (often done by internal auditor)
Management must monitor controls to ensure they are operating and are effective
It involves assessing the effectiveness of controls on a timely basis and taking necessary remedial actions.
Management accomplishes the monitoring of controls through on going activities, separate evaluations, or a
combination of the two.
On-going monitoring activities are often built into the normal recurring activities of an entity and include regular management and supervisory activities.
components of Internal control (CRIME IT)
Back to CRIME, what is E.. explain
Control environment
This includes the attitude and philosophy of management with regard to control e.g. commitment to integrity and ethical values, a formal organisation structure and proper training of staff
The control environment includes the governance and management functions and the:
- Attitudes
- Awareness
- Actions
of those charged with governance and management concerning the entity’s internal control and its importance in the entity.
The control environment sets the tone of an organisation, influencing the control consciousness of its people.
The control environment has many elements such as communication and enforcement of integrity and ethical values, commitment to competence, participation of those charged with governance, management’s philosophy and operating style, organisational structure, assignment of authority and responsibility and human resource policies and practices.
what are five systems that you will need to understand the process of
which you will need to know
- Control objective
- Controls that client has in place
- Test of control (Auditor checking the controls in place)
revenue purchase wages bank inventory
what is the general definition of a control objective in relation to the processes/systems
A control objective identifies the risk that the entity needs to manage i.e. the reason for a control procedure or activity being required.
wanting something good to happen
OR
Not wanting something bad to happen
For example, a risk within a purchasing system is that purchases could be made for personal use and paid by the company. Therefore the control objective is to ensure goods cannot be purchased for personal use. Most companies would have a control procedure in place to prevent this risk from occurring such as authorisation of purchase orders by a responsible official
what are the objectives of a sales/revenue system
✓ Sales are made to valid (good credit) customers
✓ Sales are recorded accurately
✓ orders are dispatched promptly and to correct person
✓ only valid sales are recorded
✓ all sales and receivables are recorded
✓ revenue is recorded in the period it relates to
✓ Cash collected and allocated on a timely manner
list briefly the stages of a sales/revenue cycle
1 Order received 2 Goods Dispatched (Department) 3 Invoice sent (accounts department) 4 Transactions recorded in books 5 Cash received & recorded
look at book to learn in detail the control procedure for each
what are the objectives of a wages system
- Pay the right people
- pay genuine people
- the right wage rate
- pay for the hours worked
- Gross pay is calculated and recorded accurately
- Net pay is calculated and recorded accurately
- correct amounts owed are calculated, recorded and paid to tax authorities
list briefly the stages of a wages cycle
- Clock cards submitted and input
- gross pay, deductions and net pay calculated
- Other amendments input
- Final payroll calculated and pay slips produced
- Payments to employees and tax authorities
(Separation of duty between those that store HR data and the people that process the wage
- Payroll costs and payments recorded
what are the objectives of a purchase system
✓ Order are made for a valid purchase
✓ they are of appropriate quality and price
✓ Cost effective
✓ Purchases are recorded accurately
✓ All purchases recorded
✓ Payables are recorded at appropriate value
✓ Expenditure is recorded in the period it relates to
✓ Cash paid and allocated on a timely manner
list briefly the stages of a purchases cycle
1 Requisition raised 2 Order placed 3 Accounts Department 4 Invoice received 5 Transactions recorded in the books 6 Cash payments