0% found this document useful (0 votes)
12 views13 pages

Control

The document outlines the importance of internal controls in information systems, detailing types of information systems, security goals, and steps for creating an information system plan. It emphasizes the need for risk identification, assessment, and control, along with general controls related to systems development, accounting, backup, disaster recovery, and personnel. Additionally, it includes exercises to reinforce understanding of these concepts and their application in real-world scenarios.

Uploaded by

22102630
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
12 views13 pages

Control

The document outlines the importance of internal controls in information systems, detailing types of information systems, security goals, and steps for creating an information system plan. It emphasizes the need for risk identification, assessment, and control, along with general controls related to systems development, accounting, backup, disaster recovery, and personnel. Additionally, it includes exercises to reinforce understanding of these concepts and their application in real-world scenarios.

Uploaded by

22102630
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

University of San Carlos

School of Business and Economics


Department of Accountancy
CMA Review 2025

RCMA2 Rey D. Amaya, CPA, MAIA,


CMA (US)
Systems Controls and Security Measures Dec 2/4,
2025 (Tue/Thu)

INTERNAL CONTROL in INFORMATION SYSTEM


Information System -collects, process, organize and summarize data and information. The two
broad types of information system.
 Financial information system – an information system that generates organization’s
financial statements, budgets and cost report for managers.
 Operating information system – an information system that gathers information relating
to various operational activities and generate reports for managers.

It is essential that the entity’s “IS” must design and maintain an information security. It must
include not only computer hardware and software but all of an organization’s information,
regardless of medium.

Three Goals of Information System:


 Availability - it is the ability of the intended and authorized users to access computer
resources to meet the organization goals.
 Confidentiality - is the assurance of the secrecy of information that affects adversely if
revealed to unauthorized person.
 Integrity – is ensuring that the data accurately reflect the business events and
preventing the unauthorized or accidental modification of programs or data.

Steps in creating an information system plan


1. Risk Identification – identify the business assets which may include hardware, software,
data networks, people or procedure. These risks may include but not limited to the
following:
- Absence of audit trail
- Extortion
- Hardware and Software Failures
- Human error or failure
- Natural Disasters
- Service Failure
- Software Attacks
o Malware
o Virus
o Worms
o Logic Bombs
o Trojan Horse
o Backdoors
o Spyware
o Ransomware
o Phising
o Sabotage
o Software Bugs
o Input, Output and Program Manipulation
- Technical Obsolesence
- Theft of physical or intellectual property
- Trespass or Espionage

1
- Vandalism
2. Risk Assessment – determine the impact of the attack multiplied by the likelihood of a
vulnerability being exploited.

3. Risk Control – designing and maintaining an IS control and it must be coherent,


enterprise wide information security plan.

A. Information System Controls – General Controls


IT General Controls are pervasive controls. These are controls related to computer, technology or
IT Function. General Controls are Systems Development Control, Accounting Control, Bqckup
and Disaster Recovery Controls, Organizational, Personnel and Operations Control, Network,
Hardware and Facilities Control.

SYSTEMS DEVELOPMENT CONTROLS


These refers to standards and processes that should be followed when systems are updated or
when new systems are implemented. Internal controls related to systems develop:
1. Develop an appropriate set of systems development standards that covers the systems
development life cycle. The seven stages of systems development life cycle (1) Planning,
(2) Analysis, (3) Design, (4) Development, (5) Integration and Testing, (6) Implementation,
(7) Maintenance.

2. Setting priorities through steering committee. Effective system development requires


setting of priorities through steering committee composes of managers from the IT
function and the end user functions. The committee approves development projects,
assigns resources and reviews their progress.

3. Ensure separation of duties – The separation of duties under information system


environment is between (1) Computer operators, files, equipment and production
programs and (2) Programmers and system analyst.
- A computer operator or analyst should not be allowed to perform programming
duties.
- Operator should not have custody of file
- Auditors involved in systems development be excluded in the audit of
accounting system and related areas.

4. Install control during the development


Controls such as (a) document all changes and such changes are duly approved; (b)
follow standardized process for updating system; (c) adequately test all system, if they
functioned as design and (d) ensure updated system follows laws and regulations.

ACCOUNTING CONTROLS
These are controls to ensure the reliability of recorded data such as:
 Batch totals
 Control Accounts
 Voiding/ Cancelation
 Feedback Controls
 Feedforward preventive controls

BACKUP AND DISASTER RECOVERY CONTROLS


Business Continuity Plan (BCP) is a strategy that identifies an organizational exposure to internal
and external threats and brings critical resources together to protect, ensure continuing
operations and effective recovery such an adverse event. Two basic internal controls for an
adverse event are data backup policies and procedures and disaster recovery policies.

1. Data Backup Policies and Procedures


- This is to ensure that data can be recovered by copying files to tape or other
offline media or stored offsite (to reduce data loss in case a disaster in the
primary place of business.
- Through electronic vaulting (electronic transfer to offsite location).
- Using Grandfather – Father – Son method to store data.

2
2. Disaster Recovery Policies
It is a process of resuming normal information processing operations after the
occurrence of a major interruption. The objectives are (a) to secure temporary/permanent
alternative office space; (b) protect well-being of employees or business facilities (c)
protect company legally (d) protect electronic and hardcore records (e ) return to normal
operations as quickly as possible (f) ensure data is not lost and protected and (g) develop
alternative offsite working arrangement.

Types of Disasters
 Power Failure, random and deliberate intrusion – this type of disaster will not
affect the data centers physically. Thus, internal control for power failure is installing
back-up generator and for virus attacks is purchasing and installing antivirus software
and well-trained IT staff to handle it.
 Flood, Hurricanes, earthquake – this type of disaster will affect the data centers
physically thus there is a need to configure sites for a quick restart. There are three
different types of configure sites, these are:
Hot Sites – with hardware and software configured already for immediate use.
Warm Sites – with hardware and software are ready in a short period of time.
Cold Sites – only facility in case of emergency but no network or hardware
capabilities.

ORGANIZATIONAL, PERSONNEL AND OPERATIONS CONTROL


One of the basic controls for personnel is the segregation of duties. These are the following
functions that must be segregated.
1. Under the information system environment IT Function must be independent. Information
Technology or Chief Information Officer (CIO) report to CEO.
2. Separation of duties within IT Department
- Systems Development – IT analyst and APP developers who are accountable for
creating the system.
- IT Operations – Computer operators, data library custodian, and those
responsible for managing the input and output of the information system.
- Technical Support – Admin of network security, databases and network utilities
design to keep the IT Function running smoothly.
3. Proper Authority
- Ensuring that transaction originates and are authorized by individual outside of
it.
- Ensuring that accounting department authorizes all changes to the master file or
related transaction file.

NETWORK, HARDWARE AND FACILITIES CONTROLS


1. Facility and Hardware Control – Information technology protects key hardware
from threat of damage and unauthorized access.
- Systems and information asset (key computer equipment) with control
access to the building with access codes to specific personnel. Building
must be away from public.
- Computer hardware should be in rooms with protection from natural
disasters including power surges.
- Should have duplicate system to protect data and continue operations if
hardware malfunction.
2. Network Controls
Inherently, the risk involving network (internet) includes unauthorized access
through hacks, malware and risk of data theft or compromise. Internal control may
include using
a. local area network (LAN) or wide access network (WAN)
b. using of data encryption – data encryption converts data into an unreadable
format to reduce the possibility of unauthorized access. It can be either
hardware or software based. The private information must be protected
especially if it is transmitted over a public internet using either private or
public key for encryption.

3
c. use of firewalls – these are hardware, software or a combination of both
designed to prevent unauthorized use of company network and to limit the
access of internet users to designated sites.
 Network Firewall – regulate the traffic to an entire network, such as an
organization LAN.
 Application Firewall – regulate the traffic to a specified application,
such as email or file transfer application.
d. Testing the computer system weaknesses
 Vulnerability Testing – also known as “vulnerability scanning” which
identifies weaknesses in the IT Infrastructure (OS, outdated application,
missing patches, obsolete protocols and certificates, physical access or
open ports).
 Penetration Testing – also known as “pen test” which uses tools and
techniques of hackers to gain access to an application, system or network
by circumventing features.

Exercises
1. Increasing complexity of the information technology systems often blurs the boundaries
that separate the authorization, record keeping, and custody functions performed by the
information technology (IT) department and the system users. For example, when a sales
agent enters a customer's order online, the computer plays a significant role in authorizing
the sales transaction based on its comparison of preset customer credit limits in the
master file and consequently posting all approved sales transactions in the sales journals
and related sub-ledgers. In this scenario, what would be an example of the control that
would best minimize the lack of segregation of duties on the part of the computer system?
a. Responsibility for designing and controlling accounting software programs that
contain the sales authorization and posting controls should be under the authority
of the credit approval department; and the ability to update all the information in
the master file of customer credit limits should be under the authority of the IT
department.
b. In such situations, it is best to outsource such tasks to eliminate risking the lack of
segregation of duties.
c. Since the transaction is processed in an automated fashion, it really does not matter
which department performs a particular function.
d. Responsibility for designing and controlling accounting software programs that
contain the sales authorization and posting controls should be under the authority
of the IT department; and the ability to update all the information in the master file
of customer credit limits should be under the authority of the credit approval
department.

2. Ryan Company has an accounting information system that operates in a client/server


environment. Which of the following situations is least likely to provide Ryan with an
appropriate security environment?
a. Placing complete systems application controls under one individual
b. Use of application passwords
c. Power-on passwords for personal computers
d. Installation of antivirus programs

3. Data encryption:
a. converts data from easily read local language into a secret code and helps prevent
unauthorized usage of sensitive information.
b. converts graphics into binary code that can be more easily transmitted over the
Internet.
c. is less necessary over the Internet than on a local area network (LAN) or wide area
network (WAN) because e-mail and FTP cannot be intercepted.
d. is not necessary unless a business is working on government defense contracts.

4. Which of the following are potential threats to an information system?


I - Trojan horses
II - Manipulation of input data
III - Computer viruses
4
IV - Data theft

a. I, II, III, and IV. c. I, II and III only


b. III and IV only. D. I and II only

5. All of the following are examples of effective internal controls over the data and
intellectual property of an organization except:
a. Installing, and keeping up to date, the antivirus and other such software tools.
b. Implementing mandatory password changes.
c. Limiting access to sensitive information to key people in the organization who need
access to properly perform their responsibilities.
d. Conducting training programs to ensure employee compliance.

6. The most critical aspect of the separation of duties within a mainframe information
systems environment is between:
a. programmers and users.
b. programmers and project leaders.
c. programmers and systems analysts.
d. programmers and computer operators.

7. The most appropriate control to verify that a user is authorized to execute a particular on-
line transaction is a:
a. password. c. closed-loop verification.
b. challenge/response system. d. compatibility check.

8. Which of the following statements concerning disaster recovery planning is not correct?
a. A “hot site” is more expensive to set up and maintain than is a “cold site.”
b. A company would take longer to continue operations after a natural disaster if it had
a “warm site” than if it had a hot site.
c. The main difference between a warm site and a cold site is that the computers in a
warm site are fully configured while the computers in a cold site are not yet
configured.
d. A company would be able to continue operations after a natural disaster sooner if it
had a warm site than if it had a cold site.

9. Which of the following risks can be minimized by requiring all employees accessing the
information systems to use passwords?
a. Collusion c. Failure of server duplicating function
b. Data entry errors d. Firewall vulnerability

[Link] of the options below would best be categorized as a general accounting system
control in a control environment?
a. Mandating that all employees update their passwords every 45 days to ensure data
security
b. Securing inventory with RFID tags and other identifying information to maintain
control
c. Requiring employees to attend ethics and control training led by members of the
senior management team on an annual basis
d. Instituting a two-layer review process over all account reconciliations

[Link] purpose of disaster planning is to:


a. Ensure the business is not interrupted.
b. Identify the cost to the business.
c. Minimize potential losses and disruption of business activities.
d. Identify areas of weakness.

[Link] of the following is true?


a. A firewall system guarantees that unauthorized users will not be able to access the
backup data.
b. Data backups should be regularly stored off site for recovery in the event of the loss
of the facility in which the data resides.
c. Disaster recovery will be effective only for firms with subsidiaries in a different
region.

5
d. Automated backup systems are often ineffective; backups should be instituted
every day by an authorized computer manager

13.A company has in its disaster recovery plan a process to store in a secure, offsite
warehouse building a backup of its current financial operating systems. What type of
backup location is the company most likely using?
a. A hot site
b. A cold site
c. A mirrored data center
d. A recovery operations center

[Link] of the following best describes the relationship between business continuity
planning and corporate governance?
a. These two areas are not usually related because business continuity planning is
internally focused, and corporate governance is externally focused.
b. These two areas are not usually related because business continuity planning is
performed by management, and corporate governance is performed by the board.
c. The two areas are closely related because both business continuity planning and
corporate governance are only concerned with external activities, specifically
shareholder-oriented actions and engagements.
d. The two areas are closely related because both business continuity planning and
corporate governance have to do with navigating changes and forces on both an
internal and external basis.

15.A computer virus is different from a "Trojan Horse" because the virus can:
a. replicate itself.
b. erase executable files.
c. alter programming instructions.
d. corrupt data.

[Link] process of maintaining the last three backups so that data files can be recreated from
any one of them should a disaster occur is called:
a. Grandfather-father-son backup
b. Rollback backup
c. Tri-level backup
d. Checkpoint backup

17.A data backup:


a. helps recover data after data loss due to viruses, natural disasters, and hardware
failures and should be run on a daily basis.
b. should be run every day but is not helpful in the event of a data loss due to a
computer virus.
c. helps prevent hacking and should be run on a daily basis.
d. helps recover data after data losses but is done only if a company has a very large
database of information to recover.

[Link] of the following are included in the systems implementation process except:
a. training. c. conversion
b. systems design. d. testing

[Link] inherent risk specifically related to conducting business over the internet includes:
a. website denial of service attack.
b. exposure to viruses.
c. unauthorized access by hackers, exposure to viruses, and website denial of service
attacks.
d. unauthorized access by hackers.

[Link] is an unhappy employee, and he writes a line of code into the company's software
system that will erase every tenth transaction entered into the system. Which of the
following is this called?
a. Trojan horse. c. Revenge line
b. Virus. D. Saboteur

6
[Link] of the following represents a possible negative implication of having a system with
single sign-on functionality within an organization?
a. If an employee password is hacked or stolen, an unauthorized person can gain
access to multiple systems or datasets within the organization.
b. A system with single sign-on functionality will only improve the efficiency and speed
with which data is accessible, so none of these options represent a potential
negative implication of a system with single sign-on functionality.
c. The only negative implication of establishing a single sign-on system is that it is
very expensive, and another type of system will protect the organization’s
information just as well.
d. Single sign-on systems are only applicable to certain classes of information and
organizations, so there are no negative implications for the organization as a whole.

[Link] objective of a disaster recovery plan is to:


a. set forth procedures to follow if the building needs to be evacuated in the event of a
disaster.
b. provide protection against losses during times of severe recession.
c. provide for continuing business in the event of an emergency that results in the
inability to use the facility or the data center.
d. provide a plan in the event of a union strike when there are no operators for the
data and processing systems.

[Link] organizations participating in e-commerce have serious concerns about security,


therefore a new subdiscipline, internet assurance services, has evolved. Its main objective
is to:
a. provide assurances that web sites are reliable and transaction security is
reasonable.
b. insure against fraud and hackers by charging a fee per transmitted transaction.
c. provide assurance that electronic data transmissions reach their destinations and
on time.
d. provide value to data being transmitted by making it secure.

[Link] opens an e-mail that she doesn't realize contains a line of code that enters the
company local area network (LAN) via her computer. Three days later, all the data files on
the LAN and everybody's computers are erased. This is an example of:
a. a computer spam. c. a Trojan horse
b. a computer virus. D. a prototype

[Link] of the following is a risk of using the Internet to transmit data?


a. Encrypted files cannot be sent via the Internet.
b. Data is easily intercepted and can be stolen or altered when being sent on an
unsecured line.
c. Telecommunication lines connecting a wide area network (WAN) may corrupt data
due to the long distances between computers.
d. Data wires connecting a local area network (LAN) can easily be breached by
hackers.

[Link] of the following provides the best definition of the primary purpose of network
controls?
a. Network controls are used to identify an organization’s exposure to internal and
external threats.
b. Network controls are used to prevent unauthorized people both inside and outside
of the organization from accessing and altering critical information.
c. Network controls are used to prevent or detect and correct errors in transactions
that are processed by accounting systems.
d. Network controls are used to prevent unauthorized people outside of the
organization from accessing and altering critical information.
[Link] order to properly segregate duties, which function within the computer department
should be responsible for reprocessing the errors detected during the processing of data?
a. Computer programmer. c. Department manager
b. Systems analyst. d. Data control group

7
[Link] is the backup facility that can be up and running at a short notice called?
a. VAN b. Hot site c. Remote site d. Cold site

[Link] of the following statements is the most accurate definition of phishing?


a. The acts that an organization takes to mitigate the risk of social engineering attacks
such as establishing various system controls and training employees.
b. Links or attachments to general emails that inadvertently allow malicious software
into the organization.
c. Links or attachments to highly customized emails that inadvertently allow malicious
software into the organization.
d. Outside individuals posing as employees to obtain confidential and organizational
information via deceptive actions.

[Link] to limit the physical access to information systems hardware include all of the
following except:
a. requiring swipe card access to restricted areas.
b. requiring dual control of valuable assets
c. employing security guards
d. sending confirmations to satellite offices.

B. Information System Controls – Application Controls


IT Application controls consists of input, process and output controls. An effective accounting
information system must have a series of application controls to prevent, detect and correct
mistakes and intentional misstatements.

INPUT CONTROLS
These are controls that provides reasonable assurance that data submitted are authorized,
complete and accurate.
 Batch Controls – these are input controls that can be used when data are grouped
for processing in batches.
o Management Release – a batch is not release for processing until a manager
reviews and approve it.
o Record Count – counting the number of records in a batch or lines in a
document and the batch will not be released for processing if the record as
reported by the system will not be the same with the amount calculated by
the user.
o Control Totals – the batch will not be released for processing if the sum of
the dollar amounts of individual items (or any financial field) will not match
the amount calculated by the user.
o Hash Totals – the batch will not be released for processing if the sum of the
numeric field (ex. SSS number), which has no meaning by itself, will not
match as calculated by user.
 Online Input Controls – these are input controls when data are keyed into an input
screen.
o Supervisor Confirmation – Supervisor must confirm the accuracy of source
data before employee input into AIS
o Preformatting – the data entry screen mimics the old hardcopy document,
forcing data entry in all necessary fields.
o Approved Mechanism – appropriate approval procedure adopted by the
organization.
o Redundant Data Review – a check digit is used to check redundant digits to
ascertain the accuracy of digits when employee manually enter long strings
of numbers.
o Dual Review – dual review/ observation of data before inputting to the
Accounting information system.
o Interactive Edits – these are controls that ensures data entered into the
system meet certain requirements. Examples of interactive edits are
8
 Character checks – requires certain fields contain alphanumeric texts
 Completeness checks – ensuring that there is no missing fields
 Limit/Reasonable checks – comparing entered check with certain
requirements
 Validity checks – comparing entered text with pre-specified data stored
within the company’s information system.
o Prompting – asking questions of the user to ensure proper data entry
o Source Document Design – the design of source document must be
considered to reduce the probability of error.

PROCESS CONTROLS
These are controls that provides reasonable assurance that data submitted for processing are
processed and only approved data are processed.
o Balancing – confirming the balance of subsidiary ledger equals to the general ledger
(example Accounts Receivable).
o Redundant Process – implementing redundant processing of data to ensure the
same answers. Independent processing and data review reduce the data error or
fraudulent activity.
o Matching – Matching source document to processing records (ex. receiving report,
supplier invoice and purchase order). This will show the proper authority and
valuation of transactions.
o Standardization – using standard and consistent procedures for processing. Same
process to reduce the possibility of error (using a chart of accounts to identify
normal debit and credit for each account).
o Batch Balancing – balancing the processing totals against source document batch
totals to ensure all records have been processed and record accurately. (Cashier
deposit tickets to totals of cash remittances).
o Automation/ Mechanization – automating the process as much as possible to reduce
the human error and increase employee efficiency.
o Default Option – use predefined value as appropriate, such as a default of 40 hours
per week for labor, to reduce or eliminate repetitive entry of information.
o Clearing Accounts – balancing the processing totals against source document batch
totals to ensure all records have been processed and record accurately.
o Automated Error Correct – this control automatically corrects errors in transactions
or records that violate a detective control. (ex. a system that automatically issue a
credit memo if the customers will overpay their accounts).
o Run to Run Totals – using output totals from previous process as input control totals
over subsequent process. (beg AR less collection plus credit sales = ending AR).
o Tickler File – a control file consists of items sequenced by date for processing or
follow up. (A file for invoices received and arranged by their due dates).
o Trailer Label – provides a control total for comparison with accumulated counts or
values of records process. (The last record in a receivable file can be trailer label
that contain a count of the number of records in the file).

OUTPUT CONTROLS
These are controls that provides reasonable assurance that processing was complete and
accurate.
o Controls for Validating Process Result – activity reports can be that provides a
detailed information about the changes in the master file to ascertain the validity,
accuracy and completeness of output.
o Controls Regulating Distribution of Outputs – controls on the access, storage and
disposal of output and how these processes must be done.
o Specific Controls
 Periodic Audit – independent parties should audit files, processes or accounts
periodically to detect internal control issues (AR or AP confirmation).
 Aging – provides report on the movement and age of AR.
 Reconciliation – analyzes the differences between the values contained in a
detail file and a control total to identify errors (bank reconciliation).
 Discrepancy Report – a report that contains a list of items that have violated
a control and require further investigation. (A list of employees who have
exceeded overtime limits).

9
 Suspense File – a file containing unprocessed or partially complete
transactions for further review. (Back ordered raw materials awaiting for
receipt).
 Suspense Account – This is a control total for items that needs further
processing (total of general and subsidiary ledger must be equal).

Exercises
1. Data processed by a computer system are usually transferred to some form of output
medium for storage. However, the presence of computerized output does not, in and of
itself, ensure the output's accuracy, completeness, or authenticity. For this assurance,
various controls are needed. The major types of controls for this area include:
a. input controls, tape and disk output controls, and printed output controls.
b. hash totals, tape and disk output controls, and printed output controls.
c. tape and disk output controls and printed output controls.
d. transaction controls, general controls, and printout controls.

2. Which of the following best describes why input controls are needed in an accounting
information system?
a. Input controls are needed to help prevent incorrect data from being entered into an
accounting information system.
b. Input controls are needed to monitor how an accounting information system
processes input data into information output.
c. Input controls are needed to monitor the various stages of the accounting
information system development life cycle.
d. Input controls are needed to monitor whether an accounting information system
provides useful output for decision making.

3. Which of the following is not an example of a processing control in an accounting


information system?
a. Storing backup data at an offsite location
b. Confirming that the balance of the accounts receivable subsidiary ledgers equals
the balance in the accounts receivable general ledger
c. Having two employees count cash to be deposited in the bank and comparing
results
d. Standardizing the way credit applications are processed

4. Ellen is processing a group of transactions and indicates as she begins running the
program that there are 15 transactions in the batch, totaling $150,000 in orders. This
batch control is related to all of the following except:
a. a processing control c. an input control
b. an output control d. a program access control

5. Which of the following computer documentation would an auditor most likely utilize in
obtaining an understanding of the internal control structure?
a. Systems flowcharts c. Program listings
b. Record counts d. Record layouts

6. Which of the following is the correct definition of a processing control?


a. A control that helps an organization prevent and detect errors and irregularities
related to the input of data into the accounting information system
b. A control that helps an organization develop and monitor the standards to cover the
various stages of the system development life cycle
c. A control that helps an organization monitor how the accounting information system
turns input data into information output
d. A control that helps an organization determine if the input and processing activities
result in valid output

7. Which of the following is an example of a validity check?


a. The computer flags any transmission for which the control field value did not match
that of an existing file record.
b. The computer ensures that a numerical amount in a record does not exceed some
predetermined amount.
10
c. As the computer corrects errors and data are successfully resubmitted to the
system, the causes of the errors are printed out.
d. After data for a transaction are entered, the computer sends certain data back to
the terminal for comparison with data originally sent.

8. Which of the following statements regarding auditor documentation of the client's system
of internal control is correct?
a. Documentation must include flowcharts.
b. No one form of documentation is required, and the extent of documentation may
vary.
c. Documentation must include procedural write-ups.
d. No documentation is necessary, although it is desirable.

9. Edit checks in a computerized accounting system:


a. are easier to install after a system is operational.
b. should be performed immediately prior to output distribution.
c. should be performed on transactions prior to updating a master file.
d. are preventive controls.

[Link] processing sales invoices, an input control check of total sales


a. Missing data check c. Control total
b. Check digit d. Hash total

[Link] of the following best describes why output controls are needed in an accounting
information system?
a. Output controls are needed to help prevent incorrect data from being entered into
an accounting information system.
b. Output controls are needed to monitor how an accounting information system
processes input data into information output.
c. Output controls are needed to protect an organization’s information and data.
d. Output controls are needed to monitor whether an accounting information system
provides useful output for decision making.

[Link] needs to send a check to a contract worker. The check number is on the check, and
the computer program adds a second number while printing the check to aid in tracking
the transaction. This is an example of:
a. an input control c. a program access control
b. a processing control d. an output control

[Link] situations where it is crucial that data be entered correctly into an accounting
information system, the best method of data control would be to use:
a. compatibility tests c. reasonableness tests
b. limit checks d. key verification
14.A software program prompts the input clerk that an account number is incorrect. This
prompt is most likely based on what input control?
a. Hash total c. Formatted input
b. Reasonableness test d. Check Digit

[Link] of the following is an example of an output control in an accounting information


system?
a. A manager confirming order details before they are entered into the accounting
information system.
b. Storing backup data at an offsite location.
c. Having two payroll employees prepare payroll and compare results.
d. Preparing a report highlighting product returns that were not properly authorized.

16.A data flow diagram:


a. Is a graphical description of the relationship among the input, processing, and
output in an information system.
b. Is a graphical description of the sequence of logical operations that a computer
performs as it executes a program.
c. Is a graphical description of the source and destination of data that shows how data
flows within an organization.

11
d. Is a graphical description of the flow of documents and information between
departments or areas of responsibility.

[Link] is entering a transaction on the screen and receives an error message telling her the
account number does not match the customer name. This is an example of:
a. a program access control c. an input control
b. an output control. D. a processing control

[Link] of the following is the correct definition of an output control?


a. A control that helps an organization monitor how the accounting information system
turns input data into information output
b. A control that helps an organization prevent and detect errors and irregularities
related to the input of data into the accounting information system
c. A control that helps an organization ensure the accuracy and reliability of financial
information for decision making
d. A control that helps an organization determine if the input and processing activities
result in valid output

[Link] procedures may include a variety of computerized programs and accuracy tests to
confirm that the data processed by computer applications post to the correct general
ledger accounts. These procedures are referred to as:
a. input controls c. output controls
b. processing controls d. security controls

[Link] order to prevent, detect, and correct errors and unauthorized tampering, a payroll
system should have adequate controls. The best set of controls for a payroll system
includes:
a. passwords and user codes, batch totals, employee supervision, and record counts of
each run.
b. batch and hash totals, record counts of each run, proper separation of duties,
passwords and user codes, and backup copies of activity and master files.
c. employee supervision, batch totals, record counts of each run, and payments by
check.
d. batch totals, record counts, user codes, proper separation of duties, and online edit
checks.

[Link] controls provide reasonable assurance that data is complete, accurate, and
authorized?
a. Output controls c. Physical Controls
b. Input controls. D. Processing Controls

[Link] one of the following groups of controls are generally considered the most cost-
effective controls? I – Preventive; II – Corrective; III – Feedback; IV – Feedforward; V –
Detective
a. I, II and III c. I, III and V
b. I, II and V d. III, IV and V

23.A company has designed its accounting system to have an automated reconciliation
between its payroll and general ledger systems. Which type of control has the company
implemented?
a. Output control c. Processing control
b. Input control d. Transaction control

[Link] auditor's flowchart of a client's accounting system is a diagrammatic representation


that depicts the auditor's
a. Assessment of control risk.
b. Identification of weaknesses in the system.
c. Assessment of the control environment's effectiveness.
d. Understanding of the system.

[Link] controls provide assurance that processing is complete and accurate. Which of the
following controls is not an output control?
a. Password protection of document.
b. Reasonableness check.
12
c. Error listing.
d. Audit trail.

[Link] entering the billing address for a new client in Emil Company's computerized database,
a clerk erroneously entered a nonexistent zip code. As a result, the first month's bill
mailed to the new client was returned to Emil Company. Which one of the following would
most likely have led to discovery of the error at the time of entry into Emil Company's
computerized database?
a. Limit test c. Parity test
b. Validity test d. Record count test

[Link] of activities are used to:


a. help detect intrusion past the firewall into the network.
b. visually inspect, observe, and document a process in order to assess effectiveness
of control procedures.
c. help ensure that data transmitted over the Internet is not intercepted by
unauthorized personnel.
d. ensure that data can be recovered if it is lost.

[Link] of the following statements about flowcharts is not correct?


a. Flowcharts can be used to show where someone violated procedure and did not get
approval to write off an accounts receivable.
b. Flowcharts can be used to show how a document moves through a given process.
c. Flowcharts can be used to identify processes that are not efficiently designed.
d. Flowcharts can be used to identify potential internal control weaknesses.

[Link] of the following is an example of a processing control in an accounting information


system?
a. Redesigning a purchase order form to make it easier to understand
b. Confirming that the balance of the accounts receivable subsidiary ledgers equals
the balance in the accounts receivable general ledger
c. Reviewing exception reports highlighting significant changes to master files
d. Keeping the information technology (IT) department independent of other
departments in the organization

[Link] of the following is an example of a completeness control?


a. Pre-numbered forms that allow for reconciliation of form numbers against shipping
reports.
b. Facilities utilization reports.
c. Thorough training on proper accounting classes to which transactions should be
posted.
d. Employees time sheets that must be completed before employees can receive their
paycheck

13

You might also like