Unit- III
(Study the notes given in the class- can support with this study material also)
Five components of internal control Use and evaluation of internal control systems by auditors
Internal control is a process, effected by an entity's board of directors, management and other
personnel, designed to provide reasonable assurance: That information is reliable, accurate
and timely. Of compliance with applicable laws, regulations, contracts, policies and
procedures.
internal controls as processes designed to provide reasonable assurance regarding the
achievement of objectives related to operations, financial reporting, and compliance. It also
notes that internal controls can be detective, corrective, or preventive in nature.
Key elements of an internal control framework include the control environment, risk
assessment, information and communication, control monitoring, and control activities such
as authorization, documentation, reconciliation, security, and separation of duties.
seven main forms of control: feedforward, concurrent, feedback, multiple, strategic,
management, and operating control. It also discusses market, bureaucratic, and clan control.
The types of control focus on regulating inputs, ongoing activities, outputs, and strategy
implementation.
An internal controls evaluation reviews an internal controls system to detect deficiencies
proactively. These deficiencies can arise for numerous reasons, like employees
misunderstanding controls or controls falling out of step with recent regulations.
The control function can be viewed as a five-step process: (1) Establish standards, (2)
Measure performance, (3) Compare actual performance with standards and identify any
deviations, (4) Determine the reason for deviations, and (5) Take corrective action, if needed.
The five risk control measures are elimination, substitution, engineering controls,
administrative controls, and personal protective equipment (PPE). These measures are
arranged in order of decreasing effectiveness.
five main objectives of internal control are to protect assets, ensure accuracy, promote
efficiency, and ensure compliance with policies and laws.
Control environment
The foundation of internal control, this component establishes structure, responsibility, and
accountability. It also includes the ethical values and competence of the people in the
organization.
Risk management
This component involves identifying, evaluating, and managing risks that could prevent the
organization from achieving its objectives.
Control activities
These are the policies and procedures that help ensure compliance with policies and
laws. Examples include segregation of duties and variance analysis.
Information and communications
This component involves identifying, capturing, and communicating information in a way
that enables people to perform their responsibilities.
Operational efficiency
This component involves promoting efficiency in the organization's operations.
Tests of Control in Audit
A test of internal controls is an evaluation of the existing controls, either as part of an official
audit or in preparation for an audit, to see if the controls are in place and identify weaknesses.
Auditors cannot rely on automated controls if ITGC are not effective – if the foundations are
not there then you cannot rely on what you have built upon those foundations.
IT General Controls (ITGC) or General Computer Controls (GCC) are controls which relate
to the environment that supports IT Applications. The appropriateness and effectiveness of
ITGC’s therefore impacts on all the organisation’s IT applications. IT general controls are
policies and procedures that:
▪ Support application controls and IT components of manual controls
▪ Have a pervasive impact on controls at the application level
▪ Can relate to multiple applications
▪ Operate centrally or in multiple locations
▪ Support automated controls within applications
There are four main groupings of ITGC:
• Access to programs and data
• Program change
• Program development
• Computer operations
A "control objective" is the desired outcome of a specific internal control, while "procedures"
are the steps taken to achieve that objective; "activities" are the actions performed within
those procedures, "key controls" are the most critical controls to achieve the objective, and
"tests of controls" are audit procedures used to evaluate whether those controls are
functioning effectively; all of these elements are communicated within an organization to
ensure everyone understands their role in maintaining a robust internal control system.
Corporate Governance towards impact on internal auditing
Internal audit plays a crucial role in supporting and reinforcing corporate governance by
independently evaluating an organization's risk management, internal controls, and governance
processes, providing assurance to the board of directors that the company is operating effectively and
in compliance with laws and regulations, thus contributing to overall accountability and transparency
within the organization.
Key points about internal audit and corporate governance:
Assessment of risk and controls:
Internal auditors assess the effectiveness of an organization's risk management framework, identifying
potential threats and evaluating the adequacy of controls to mitigate them, ensuring proactive risk
identification and mitigation strategies.
Compliance verification:
Internal audits help verify adherence to relevant laws, regulations, and ethical codes, minimizing the
risk of legal and reputational issues associated with non-compliance.
Governance process review:
Internal auditors examine the design and effectiveness of governance processes including board
composition, board procedures, and communication channels, promoting transparency and
accountability within the leadership structure.
Financial reporting integrity:
By assessing internal controls over financial reporting, internal audits contribute to the accuracy and
reliability of financial information, safeguarding against fraud and errors.
Reporting to the board:
Internal audit findings are regularly communicated to the board of directors, enabling them to make
informed decisions regarding the company's strategic direction and risk management practices.
How internal audit supports good corporate governance:
Independent perspective:
Internal auditors operate independently, providing objective insights and assessments of the
organization's governance practices.
Early identification of issues:
By regularly evaluating controls, internal audits can identify potential problems early on, allowing
management to take corrective actions before they escalate.
Continuous improvement:
Internal audit reports can provide recommendations for improving existing processes and controls,
fostering a culture of continuous improvement within the organization.
Internal Audit with in structure and operations:
Internal audit provides assurance by assessing and reporting on the effectiveness of governance, risk
management, and control processes designed to help the organization achieve strategic, operational,
financial, and compliance objectives.
Structure:
Clear hierarchy: A well-defined chain of command for decision-making and
accountability.
Specialization: Assigning tasks based on individual expertise, promoting efficiency.
Departmentalization: Grouping related functions into departments for better
coordination.
Span of control: Appropriate number of direct reports for a manager to effectively
oversee.
Centralization vs. Decentralization: Determining the level of decision-making
authority at different levels.
Operations:
Process optimization: Identifying and streamlining repetitive tasks to minimize
waste and improve efficiency.
Quality control: Implementing measures to ensure consistent quality standards
across operations.
Performance metrics: Establishing key indicators to track progress and identify
areas for improvement
Continuous improvement: Fostering a culture of ongoing evaluation and refinement
of processes
Collaboration: Encouraging teamwork and cross-functional communication
Outsourcing in Audit:
Audit outsourcing is when a company hires an external service provider to perform audit
functions. This can include internal audits, external audits, and tax audits.
Benefits of outsourcing audits
Cost savings: Outsourcing can reduce costs by converting fixed costs into variable costs.
Access to expertise: External auditors have specialized knowledge and skills that can help
address complex issues.
Scalability: Outsourcing allows companies to scale up or down based on their needs.
Flexibility: Outsourcing can be more flexible than maintaining an in-house team.
Objectivity: External auditors can provide an independent perspective.
How does outsourcing work?
External auditors are trained in global audit regulations.
They can integrate with the firm's processes.
They can help manage more complex audits.
They can help ensure compliance with regulations.
They can improve service quality.
Who uses audit outsourcing?
CPA firms, Accounting firms, and Organizations that want to improve audit quality and efficiency.
Types of Outsourcing:
Key points about audit outsourcing forms:
Full outsourcing:
The entire responsibility of the internal audit function is transferred to an external service provider,
allowing the company to focus on core operations.
Co-sourcing:
A hybrid approach where the company maintains some internal audit staff but partners with an
external firm for specialized areas like IT audits or complex financial analysis.
Specific audit function outsourcing:
Companies can choose to outsource particular audit types like compliance audits, financial statement
audits, operational audits, or forensic audits based on their specific needs.
Loan-Staff Augmentation:
Partial Out Sourcing:
Contract outsourcing
Computerized Auditing:
Computerized audit is the use of technology to automate the audit process, including data collection,
analysis, and reporting. It involves the use of specialized software to access and evaluate financial
data, identify potential risks and errors, and generate audit reports.
Objectives:
It help auditors to change the focus from time consuming manual audit procedures to focused
analysis of data so as to provide better reports to clients.
In the absence of input documents, the use of computerised auditing helps with compliance.
Helps to increase audit quality and arithmetic accuracy of procedures.
Computerized accounting system is the integration of different component systems to produce
computerize books of accounts and computer generated accounting records and documents. It is a
system in which accountants enter financial data into spreadsheets and other accounting software, and
then mathematical algorithms compute the information into the necessary ledgers and financial
statements. Computerized system also allows Accountants to create trending analysis, and report any
variances quickly and accurately.
Audit Process – Computerized Auditing:
The audit process for a computerized accounting system involves five main steps: conducting the
initial review (planning the audit); reviewing and assessing internal controls; compliance testing
(testing the internal controls); substantive testing (testing the detailed data); and reporting
(conclusions and findings).
Demerits of Computerized Auditing:
There are actually several disadvantages of computerized accounting system. They may include the
following:
Not all software may be compatible for the things that you need to do when conducting your
accounting business.
The cost of computer and associated equipments are much more costly when compared to manual
processing equipments, such as pens and pencils.
Technological complexity of computer and its associated equipments makes it more difficult to learn
and maintain when compared to equipments of manual information processing.
The use of computers require additional infrastructure, such as power supply and software backup.
These increases the chances of problems due to failure of these infrastructures.
Failures of computer system can be more serious and difficult to correct, e.g. one scratch on a hard
disk can make the complete data on the disk inaccessible. In comparison, manual system faults have
comparatively limited impact.
Key points of the notes:
Structure:
Clear hierarchy: A well-defined chain of command for decision-making and
accountability.
Specialization: Assigning tasks based on individual expertise, promoting efficiency.
Departmentalization: Grouping related functions into departments for better
coordination.
Span of control: Appropriate number of direct reports for a manager to effectively
oversee.
Centralization vs. Decentralization: Determining the level of decision-making
authority at different levels.
Operations:
Process optimization: Identifying and streamlining repetitive tasks to minimize waste
and improve efficiency.
Quality control: Implementing measures to ensure consistent quality standards
across operations.
Performance metrics: Establishing key indicators to track progress and identify areas
for improvement
Continuous improvement: Fostering a culture of ongoing evaluation and refinement
of processes
Collaboration: Encouraging teamwork and cross-functional communication
Different organizational structures and their potential best practices:
Functional Structure:
Ideal for specialized expertise, focusing on optimizing processes within each department.
Divisional Structure:
Suitable for diverse product lines or markets, with each division having autonomy
Matrix Structure:
Facilitates collaboration across projects and departments, leveraging diverse skillsets
Flat Structure:
Promotes faster decision-making and employee empowerment, suitable for agile environments
Important considerations when implementing best practices:
Alignment with company strategy: Ensure operational practices support the overall business
goals.
Employee engagement: Involve employees in decision-making and improvement initiatives
Flexibility: Adapt processes to changing market conditions and customer needs
Technology utilization: Leverage technology to automate tasks and enhance operational
efficiency
1. Identify the limitations associated with the Internal Control System.
2. What do you mean by Corporate Governance?
3. What is Outsourcing?
4. Communication is crucial in an Internal Control System- Comment on this statement.
5. What is an audit deficiency?
6. Re-call the concept of relevance and reliability of audit evidence.
7. Write a brief note on the concept Internal Audit
8. What is mean by the term Opinion
9. What is mean by audit report
10. List the communication requirement for audit
1. Examine the five components of Internal Control System.
2. Discus the format of reporting significant deficiencies.
3. Examine the differences between tests of control and substantive procedures of audit.
4. Discuss in detail about the Computer Assisted Audit Techniques.
5. Different between Internal Check and Internal audit
6. Comparison of the concept verification and valuation
7. Elaborate the concept of Internal audit procedures
8. Compare the external and internal audit
9.