Internal Control – Structured Study Notes (ACCA
AA)
1. Obtaining an Understanding of Internal Control
Definition: System of Internal Control
A system designed, implemented and maintained by TCWG, management and staff to provide
reasonable assurance regarding: - Reliability of financial reporting - Effectiveness and efficiency of
operations - Compliance with laws and regulations
Key Point
• The auditor obtains an understanding of internal control through risk assessment procedures.
• Focus is on how controls prevent, detect or correct material misstatements, not merely their
classification.
2. Components of Internal Control (5 Components)
1. Control Environment
2. Risk Assessment Process
3. Information System & Communication
4. Control Activities
5. Monitoring of Controls
These components are interrelated.
3. Audit Requirement
The auditor must understand all five components as part of risk assessment, especially: - Control
environment - Risk assessment process - Information system & communication (financial reporting) -
Control activities relevant to control risk - Monitoring process relevant to financial statements
4. Control Environment
Definition
Includes: - Governance and management functions - Attitudes, awareness and actions of TCWG and
management
1
Why It Is Important
• Sets the tone at the top
• Creates a culture of honesty and ethical behaviour
• Influences effectiveness of all other controls
The control environment does not directly prevent errors, but supports other controls.
Key Elements
• Management integrity and ethical values
• Independence and oversight of TCWG
• Assignment of authority and responsibility
• Recruitment, training and retention of competent staff
• Accountability for internal control responsibilities
Auditor Must Evaluate Whether:
• A culture of honesty and ethics exists
• Control environment supports other controls
• Weaknesses undermine the overall system
Dominant individuals can positively or negatively affect the control environment.
5. Entity’s Risk Assessment Process
Auditor Must Understand How the Entity:
• Identifies financial reporting risks
• Assesses significance and likelihood
• Responds to those risks
Auditor Evaluation
• Is the process suitable for the entity’s size and complexity?
If Management Failed to Identify a Risk:
The auditor should: - Assess whether management should have identified it - Understand why the
process failed - Reconsider the adequacy of the risk assessment process
6. Information System & Communication
Objective
Ensure financial information is: - Complete - Accurate - Recorded in correct period
2
6.1 Information System – What the Auditor Understands
How transactions are:
• Initiated
• Recorded
• Processed
• Corrected
• Posted to general ledger
• Reported in financial statements
Includes Understanding:
• Accounting records
• Financial reporting process
• IT environment
Accounting Records Include:
• Source documents (invoices, contracts)
• Journals and general ledger
• Spreadsheets and reconciliations
6.2 Elements of an Information System
• Hardware & infrastructure
• Software
• People
• Procedures
• Data
Transaction Stages:
• Initiate – manual or automated
• Record – valid and timely
• Process – calculate, classify, reconcile
• Report – financial & management reports
• Maintain accountability – assets and liabilities
Types of Transactions
• Standard (sales, purchases, wages)
• Non-standard (impairments, write-offs)
Handling Errors
• Use of suspense accounts
• Ability to override controls
• Management response to overrides
3
6.3 Communication
Communication ensures: - Roles and responsibilities are understood - Exceptions are reported properly
Forms of communication: - Policy manuals - Reports and memos - Electronic, oral or behavioural
7. Control Activities
Definition
Controls are policies and procedures designed to achieve control objectives.
Types of Controls
• Preventive / Detective
• Manual / Automated
Main Control Activities
1. Authorisation & Approval
Ensures transactions are valid Examples: - Asset purchases/disposals - Supplier payments - Payroll
changes - Journal entries
2. Reconciliations
• Compare two records
• Differences investigated and corrected
3. Verifications
• Match items to policies or records
• Includes edit checks and validation checks
4. Physical & Logical Controls
• Physical security of assets
• IT access controls
• Book-to-physical checks
5. Segregation of Duties
• Separate authorisation, recording and custody
• Reduces fraud and error
Auditor Responsibilities
Identify controls that address: - Significant risks - Journal entries - Controls planned for testing
Also identify: - IT-related risks - General IT controls
4
8. Monitoring of Controls
Definition
Monitoring ensures controls: - Are operating - Are effective
Types of Monitoring
• Ongoing (continuous)
• Separate evaluations
Auditor Considers:
• Design of monitoring activities
• Frequency
• Timely evaluation of results
• Corrective actions taken
If internal audit exists, auditor must understand its role.
9. Limitations of Internal Control
9.1 Manual vs Automated Controls
Manual controls: - More error-prone - Easier to override
Automated controls: - Consistent and reliable - Depend on correct programming
Manual controls are useful when: - Judgement is required - Transactions are unusual - Monitoring
automated controls
9.2 Inherent Limitations
• Internal control provides reasonable, not absolute assurance
• Cannot fully prevent fraud
• Management override always possible
10. Evaluation of Internal Controls
10.1 Design & Implementation
Auditor must: - Assess whether controls can prevent/detect misstatements - Confirm controls exist and
are used
Poorly designed controls should not be tested.
5
10.2 Risk Assessment Procedures
Methods: - Inquiry (not sufficient alone) - Observation - Inspection - Walk-through tests
Walk-through Test
Tracing a transaction through the system - Must be documented
11. Documentation Techniques
1. ICQs (Internal Control Questionnaires)
• Yes/No questions
• ‘No’ indicates weakness
Limitations: - Tick-box risk - Client bias
2. ICEQs (Internal Control Evaluation Questionnaires)
• Open-ended
• Focus on error and fraud
• Better linkage to audit testing
3. Flowcharts
• Visual system representation
• Easy to spot missing controls
4. Narrative Notes
• Written description of processes
• Simple but less effective for complex systems
12. Impact on Audit Approach
• Effective controls → reduced substantive testing
• Ineffective controls → higher control risk
• Audit strategy adjusted accordingly
6
13. Reporting Control Deficiencies
Auditor must report significant deficiencies to TCWG or management, including: - Uncontrolled risks -
Inadequate or missing controls - Weak risk assessment processes
Reported through management letter.
Exam Tip (AA)
Always link: - Control weakness → Risk → Audit response
End of Structured Study Notes