Course: Accounting Information System
Topic: AIS and Internal Control
I. LEARNING OBJECTIVES
At the end of this module, students should be able to:
1. Explain the concept and objectives of internal control within an AIS environment.
2. Discuss the components of internal control using the COSO framework.
3. Differentiate preventive, detective, and corrective controls.
4. Analyze internal control procedures embedded in AIS subsystems.
5. Evaluate risks and internal control weaknesses in computerized accounting systems.
6. Design appropriate control activities for a business scenario.
7. Apply AIS control concepts to Philippine business settings (SMEs, corporations,
government).
II. ENGAGE (Motivation & Problem Setting)
Case Scenario:
ABC Trading Corporation uses a computerized accounting system. One employee processes
purchases, updates inventory records, prepares checks, and reconciles the bank statement.
Recently, inventory shortages and unexplained cash discrepancies were discovered.
Guide Questions:
What went wrong?
Is technology enough to prevent fraud?
What controls should have been in place?
How does AIS strengthen or weaken internal control?
👉 Core Insight: Technology improves efficiency but does not automatically guarantee control.
III. EXPLORE (Concept Discovery Activity)
Activity: Identify the Weakness
Students will:
1. Identify at least 3 control weaknesses in the scenario.
2. Classify them as:
o Authorization problem
o Segregation of duties issue
o Lack of monitoring
o System design flaw
Discussion follows linking observations to formal internal control concepts.
IV. EXPLAIN (Comprehensive Discussion)
PART 1: FOUNDATIONS OF INTERNAL CONTROL IN AIS
1. Definition of Internal Control
According to COSO (2013):
Internal control is a process, effected by an entity’s board of directors, management, and other
personnel, designed to provide reasonable assurance regarding the achievement of objectives.
James Hall defines internal control in AIS as:
Policies, procedures, and information system structures designed to safeguard assets, ensure
accuracy of records, and promote operational efficiency.
2. Objectives of Internal Control
Internal control in AIS aims to:
1. Safeguard assets
2. Ensure accuracy and reliability of accounting records
3. Promote operational efficiency
4. Encourage adherence to policies
5. Ensure compliance with laws and regulations
3. Types of Controls
A. Preventive Controls
Segregation of duties
Authorization controls
Access controls
Password protection
Input validation checks
👉 Prevent errors before they occur.
B. Detective Controls
Bank reconciliation
Audit trails
Exception reports
Inventory counts
👉 Detect errors after occurrence.
C. Corrective Controls
Backup restoration
Error correction procedures
Disciplinary action
PART 2: THE COSO FRAMEWORK (Core Control Structure)
The COSO Internal Control Framework has 5 components:
1. Control Environment
2. Risk Assessment
3. Control Activities
4. Information & Communication
5. Monitoring
1. Control Environment
Foundation of internal control.
Includes:
Management integrity
Ethical values
Organizational structure
Assignment of authority
HR policies
Example (Philippine Context):
A family-owned SME where the owner overrides accounting procedures weakens the control
environment.
2. Risk Assessment
Process of identifying and analyzing risks.
Types of risks in AIS:
Fraud risk
Data entry errors
Cybersecurity risk
System downtime
Unauthorized access
Illustration:
Business Activity → Risk → Control Procedure
Sales Entry → Fake customer → Customer credit approval system
3. Control Activities
Policies and procedures that ensure directives are carried out.
Major Control Activities in AIS:
a. Segregation of Duties
Four functions:
1. Authorization
2. Custody
3. Recordkeeping
4. Reconciliation
No one person should perform more than one incompatible function.
b. Authorization Controls
Specific authorization
General authorization
Digital approval workflows
c. Documentation and Records
Pre-numbered documents
Audit trails
Electronic logs
d. Physical Controls
Locked warehouses
Biometric access
CCTV systems
e. Independent Verification
Internal audit
Supervisory review
Bank reconciliation
4. Information and Communication
AIS must:
Capture relevant data
Process information accurately
Communicate timely reports
Maintain audit trail integrity
5. Monitoring
Ongoing evaluation
Internal audit function
Continuous auditing systems
PART 3: INTERNAL CONTROL IN COMPUTERIZED AIS
Modern AIS introduces IT-specific risks.
1. General Controls vs Application Controls
A. General Controls (IT Environment Controls)
Access controls
System development controls
Backup and disaster recovery
Change management
These ensure overall system reliability.
B. Application Controls
Specific to individual applications.
Input Controls
Field checks
Limit checks
Validity checks
Check digits
Processing Controls
Run-to-run totals
Hash totals
Control totals
Output Controls
Reconciliation reports
Distribution controls
Review of exception reports
PART 4: ADVANCED AIS CONTROL CONCEPTS
1. Enterprise Resource Planning (ERP) Controls
ERP risks:
Excessive user access
Configuration errors
Master file manipulation
Controls:
Role-based access control (RBAC)
Segregation matrix
Audit logs
2. Continuous Auditing & Monitoring
Real-time analytics
Automated fraud detection
AI-based anomaly detection
3. Cybersecurity Controls in AIS
Encryption
Firewalls
Multi-factor authentication
Intrusion detection systems
4. Blockchain and Internal Control
Benefits:
Immutable records
Distributed ledger
Reduced fraud risk
Limitations:
Smart contract vulnerabilities
Implementation cost
PART 5: AIS CONTROL FAILURES (Lessons from Practice)
Common causes:
Management override
Collusion
Poor system design
Lack of monitoring
Inadequate IT governance
Internal control provides reasonable assurance, not absolute guarantee.
V. ELABORATE (Application Activity)
Case Analysis:
A manufacturing company uses an ERP system. The purchasing officer can:
Create vendors
Approve purchase orders
Process payments
Task:
1. Identify risks.
2. Classify type of control weakness.
3. Recommend control improvements.
4. Identify preventive and detective controls.
Students present solution using COSO structure.
VI. EVALUATE (ASSESSMENT)
Multiple Choice Test (25 Items)
1. The primary objective of internal control is to:
A. Eliminate all fraud
B. Provide absolute assurance
C. Provide reasonable assurance regarding objectives
D. Increase profitability
2. Which is NOT one of the four functions of segregation of duties?
A. Authorization B. Custody
C. Marketing D. Recordkeeping
3. A bank reconciliation is an example of:
A. Preventive control B. Detective control
C. Corrective control D. Physical control
4. Which COSO component serves as the foundation?
A. Monitoring B. Risk Assessment
C. Control Environment D. Control Activities
5. Limit checks and validity checks are examples of:
A. General controls B. Application input controls
C. Output controls D. Monitoring controls
6. Role-based access control is primarily designed to:
A. Increase sales B. Strengthen segregation of duties
C. Eliminate audit D. Reduce documentation
7. Which control ensures no unauthorized system modification occurs?
A. Change management control B. Bank reconciliation
C. Credit approval D. Inventory count
8. Hash totals are used to:
A. Detect processing errors B. Prevent access
C. Encrypt passwords D. Record transactions
9. Management override primarily weakens:
A. Risk assessment B. Control environment
C. Documentation D. Encryption
10. Blockchain strengthens control by:
A. Removing accounting standards B. Allowing data deletion
C. Creating immutable records D. Eliminating segregation of duties
Prepared by:
Sir Rey
ANSWER KEY
1. C
2. C
3. B
4. C
5. B
6. B
7. A
8. A
9. B
10. C