CHAPTER 3
INTERNAL CONTROL
LEARNING OBJECTIVES
❖ Understand what internal control system is and its importance.
❖ Identify the components of internal control system.
❖ Understand limitation of internal control
❖ Learn the types of tests of controls.
❖ Know how to assess and document the level of control risk.
Contents
1 INTERNAL CONTROL SYSTEM – AN OVERVIEW
2 INTERNAL CONTROL IN A FINANCIAL STATEMENT AUDIT
INTERNAL CONTROL SYSTEM – AN OVERVIEW
DEFINITION
COMMITTEE OF SPONSORING ORGANIZATION (COSO)
❖COSO’s Internal Control — Integrated Framework was
first developed in 1992
❖COSO updated the Framework in 2013
INTERNAL CONTROL SYSTEM – AN OVERVIEW
DEFINITION
Internal control is a process, effected by an entity’s board of
directors, management, and other personnel, designed to provide
reasonable assurance regarding the achievement of objectives in the
following categories:
- Effectiveness and efficiency of operations.
- Reliability of reporting.
- Compliance with applicable laws and regulations.
(COSO Framework,1992)
INTERNAL CONTROL SYSTEM – AN OVERVIEW
DEFINITION
PROCESS
Effectiveness
Board of and efficiency
Directors of operations
Internal
Managers Control Reliability of
reporting
Staffs Compliance
HUMAN with OBJECTIVES
applicable
Reasonable laws and
Assurance regulations
INTERNAL CONTROL SYSTEM – AN OVERVIEW
FIVE COMPONENTS OF INTERNAL CONTROL
INTERNAL CONTROL SYSTEM – AN OVERVIEW
CONTROL ENVIRONMENT
The control environment consists of the actions, policies, and
procedures that reflect the overall attitudes of top
management, directors, and owners of an entity about
internal control and its importance to the entity.
INTERNAL CONTROL SYSTEM – AN OVERVIEW
CONTROL ENVIRONMENT
➢ Integrity and ethical values
➢ Commitment to competence
➢ Board of directors or audit committee
participation
➢ Organizational structure
➢ Accountability
INTERNAL CONTROL SYSTEM – AN OVERVIEW
RISK ASSESSMENT
➢ Identify factors that may increase risk
➢ Estimate the significance of the risk
➢ Assess the likelihood of the risk occurring
➢ Determine actions necessary to manage the risk
✓ Acceptance: no action is taken
✓ Avoidance: exiting the activities giving rise to risk
✓ Reduction: action is taken to reduce risk likelihood or impact, or both.
✓ Sharing: reducing risk likelihood or impact by transferring or otherwise sharing
a portion of the risk.
INTERNAL CONTROL SYSTEM – AN OVERVIEW
CONTROL ACTIVITIES
Control activities are the policies and procedures, in addition to
those included in the other four control components, that help
ensure that necessary actions are taken to address risks to the
achievement of the entity’s objectives
In term of purpose, control activities can be:
✓ Preventive: procedures that prevent misstatements before they
occur
✓ Detective: procedures that detect misstatements after they occur
What is the primary objective of an internal control system?
a) To increase profitability.
b) To ensure compliance with financial regulations.
c) To prevent and detect fraud and error.
d) To speed up production processes.
C
Which component of internal control focuses on
the policies and procedures that help ensure
management directives are carried out?
a) Information and Communication
b) Monitoring
c) Control Activities
d) Risk Assessment
C
What is the role of the control environment in an internal control system?
a) It processes company transactions.
b) It sets the tone at the top regarding the importance of internal control.
c) It involves the actual procedures to record transactions.
d) It is only concerned with compliance with financial reporting.
B
Risk assessment in an internal control system helps an
organization:
a) Increase its investment returns.
b) Identify and analyze risks.
c) Ensure financial reports are distributed on time.
d) Hire competent staff.
B
Which of the following is a preventive control?
a) Reconciliation of bank statements.
b) Segregation of duties.
c) Monthly audit of financial statements.
d) Investigation of variances.
B
What type of internal control is primarily intended
to detect errors or fraud that has already
occurred?
a) Preventive
b) Detective
c) Corrective
d) Compensating
B
Which of the following best describes the objective of
internal controls related to operational efficiency?
a) Ensuring that external financial reporting is accurate.
b) Ensuring that the operations are effective and
efficient.
c) Guaranteeing the elimination of all business risks.
d) Avoiding any scrutiny from regulatory bodies.
B
Internal controls that focus on compliance with laws and regulations are
designed to:
a) Increase the profitability of the company.
b) Prevent legal penalties and associated financial consequences.
c) Simplify management responsibilities.
d) Facilitate the firing of non-compliant employees.
B
Internal controls related to financial reporting are
intended to:
a) Guarantee the company never incurs a financial loss.
b) Prevent any changes to financial data by internal
auditors.
c) Make sure all investments yield a positive return.
d) Ensure that financial statements are prepared in a
reliable manner.
D
Which objective of internal control is primarily
concerned with the prompt detection of unauthorized
acquisition, use, or disposition of company assets?
a) Ensuring accuracy and reliability of financial reporting.
b) Safeguarding assets against theft and unauthorized
use.
c) Promoting operational efficiency.
d) Complying with laws and regulations.
b
INTERNAL CONTROL SYSTEM – AN OVERVIEW
CONTROL ACTIVITIES
In term of functions, the categories of control activities are:
1. Adequate separation of duties
2. Proper authorization of transactions and activities
3. Adequate documents and records
4. Physical control over assets and records
5. Independent checks on performance
INTERNAL CONTROL SYSTEM – AN OVERVIEW
CONTROL ACTIVITIES -
Adequate separation of duties
Separation implies the number of people being involved in the
accounting process. This makes it more difficult for fraudulent
transactions and accidental errors to be processed
Three fundamental functions that must be separated:
✓ Authorization: the delegation of initiation of transactions and
obligations on the company’s behalf
✓ Custody: physical control over assets or records
✓ Recording
INTERNAL CONTROL SYSTEM – AN OVERVIEW
CONTROL ACTIVITIES
Proper authorization of transactions and activities
Transaction Approval Policies
General Specific
Authorization Authorization
INTERNAL CONTROL SYSTEM – AN OVERVIEW
CONTROL ACTIVITIES -
Adequate documents and records
➢ Prenumbered consecutively
➢ Prepared at the time of transaction
➢ Designed for multiple use
➢ Constructed to encourage correct preparation
Designed for multiple use
INTERNAL
CONTROL SYSTEM
– AN OVERVIEW
INTERNAL
CONTROL
SYSTEM –
AN
OVERVIEW
Constructed to encourage
correct preparation
INTERNAL CONTROL SYSTEM – AN OVERVIEW
CONTROL ACTIVITIES
Physical control over assets and records
The most important type of protective
measure for safeguarding assets and
records is the use of physical precautions.
✓ Petty cash should be kept locked in a fireproof safe.
✓ Raw material inventory should be retained in a locked storeroom
with a reliable and competent employee controlling access.
✓ Manufacturing equipment should be kept in an area protected by
security and fire alarms and kept locked when not in use.
INTERNAL CONTROL SYSTEM – AN OVERVIEW
CONTROL ACTIVITIES
Independent checks on performance (Performance review)
Independent checks on performance by a third
party not directly involved in the activity
✓ Reviews of actual performance versus budgets;
✓ Surprise checks of procedures
✓ Periodic comparisons of accounting records and physical assets
✓ Review of functional or activity performance
What is the primary purpose of control activities
in an internal control system?
a) To hire competent employees.
b) To ensure that necessary actions are taken to
address risks.
c) To audit financial reports.
d) To train management.
B
INTERNAL CONTROL SYSTEM – AN OVERVIEW
INFORMATION AND COMMUNICATION
The purpose of an accounting information
and communication system
Initiate
Report Maintain
Record Accountability
transactions
for Related Assets
Process
INTERNAL CONTROL SYSTEM – AN OVERVIEW
MONITORING
Monitoring activities deal with management’s
ongoing and periodic assessment of the
quality of internal control performance…
to determine whether controls are operating
as intended and modified when needed.
INTERNAL CONTROL SYSTEM – AN OVERVIEW
LIMITATION OF INTERNAL CONTROL
❖ Cost vs. Benefit
❖ Human error
❖ Collusion
❖ Management override
MANAGEMENT ASSERTIONS
Management assertions are implied or expressed representations by
management about classes of transactions and the related accounts and
disclosures in the financial statements.
1. Assertions about classes of transactions and events for the
period under audit
2. Assertions about account balances at period end
3. Assertions about presentation and disclosure
MANAGEMENT ASSERTIONS
Transactions and Events Account Balances Presentation and Disclosure
COMPONENTS
Occurrence Existence Occurrence and rights
OF INTERNAL and obligations
CONTROL
Completeness Completeness Completeness
Accuracy Valuation and Accuracy and
allocation valuation
Classification Classification and
understandability
Cutoff
Rights and
obligations
MANAGEMENT ASSERTIONS
Assertions about Classes of transactions and events
transactions and events that have been recorded have occurred and
Occurrence
pertain to the entity.
all transactions and events that should have been recorded have
Completeness
been recorded.
amounts and other data relating to recorded transactions and
Accuracy
events have been recorded appropriately
Classification transactions and events have been recorded in the proper accounts
transactions and events have been recorded in the correct
Cutoff
accounting period.
MANAGEMENT ASSERTIONS
Assertions about Account Balances
Existence assets, liabilities, and equity interests exist
all assets, liabilities, and equity interests that should have been
Completeness
recorded have been recorded.
assets, liabilities, and equity interests are included in the financial
Valuation and
statements at appropriate amounts and any resulting valuation
allocation
adjustments are appropriately recorded.
Rights and the entity holds or controls the rights to assets, and liabilities are
obligations the obligation of the entity.
MANAGEMENT ASSERTIONS
Assertions about Presentation and Disclosure
Occurrence and
Disclosed events and transactions have occurred and pertain to the
rights and
entity
obligations
all disclosures that should have been included in the financial
Completeness
statements have been included.
Accuracy and Financial and other information is disclosed appropriately and at
valuation appropriate amounts.
Classification and Financial and other information is appropriately presented and
understandability described and disclosures are clearly expressed
INTERNAL CONTROL IN A FINANCIAL AUDIT
PROCESS FOR UNDERSTANDING INTERNAL CONTROL
AND ASSESSING CONTROL RISK
INTERNAL CONTROL IN A FINANCIAL AUDIT
1. OBTAIN AND DOCUMENT UNDERSTANDING OF
INTERNAL CONTROL
Auditing standards require auditors to obtain
an understanding of internal control for every audit.
Procedures to obtain an understanding:
➢ Design of internal controls
➢ Whether placed in operation
➢ Uses this information as a basis for the integrated audit
INTERNAL CONTROL IN A FINANCIAL AUDIT
1. OBTAIN AND DOCUMENT UNDERSTANDING OF
INTERNAL CONTROL
Auditing standards require auditors to obtain
an understanding of internal control for every audit.
Purposes:
➢ Identify types of potential misstatements and factors that affect
the risks of material misstatement
➢ Design the nature, timing and extent of further audit procedures
INTERNAL CONTROL IN A FINANCIAL AUDIT
1. METHODS TO OBTAIN UNDERSTANDING OF
INTERNAL CONTROL
➢ Update and evaluate auditor’s previous
experience with the entity
➢ Inquiry of client personnel
➢ Inspection of documents and records
➢ Observation of entity activities and operations
➢ Perform walk-throughs of the accounting system
INTERNAL CONTROL IN A FINANCIAL AUDIT
1. DOCUMENT UNDERSTANDING OF INTERNAL
CONTROL
Internal control
Narrative questionnaire Flowchart
WALK - THROUGH
INTERNAL CONTROL IN A FINANCIAL AUDIT
2. ASSESS CONTROL RISK
CONTROL RISK is:
✓ The risk that a misstatement that could occur
✓ In an assertion about a class of transaction, account balance or disclosure
and
✓ That could be material, either individually or when aggregated with other
misstatements,
✓ Will not be prevented, or detected and corrected, on a timely basis by the
entity’s internal control.
INTERNAL CONTROL IN A FINANCIAL AUDIT
2. ASSESS CONTROL RISK (Preliminary)
Identify inherent risk from understanding
client business
Whether internal control system of client
can prevent, detect or correct these inherent
risk
Estimate the preliminary control risk
INTERNAL CONTROL IN A FINANCIAL AUDIT
3. TESTS OF CONTROLS
The procedures to test effectiveness of controls
in support of a reduced assessed control risk
are called tests of controls.
INTERNAL CONTROL IN A FINANCIAL AUDIT
3. TESTS OF CONTROLS
Procedures for Tests of Controls
Inquire of Examine
client personnel documents,
records, reports
Reperform Observe
client control-related
procedures activities
INTERNAL CONTROL IN A FINANCIAL AUDIT
3. TESTS OF CONTROLS
Procedures for Tests of Controls
1. Consists of seeking information of
Inquire of knowledgeable persons inside or
client personnel
outside the entity.
2. Interviews concerning the effectiveness
of controls.
INTERNAL CONTROL IN A FINANCIAL AUDIT
3. TESTS OF CONTROLS
Procedures for Tests of Controls
Observe 1. Consists of looking at a process or
control-related
procedure being performed by others
activities
INTERNAL CONTROL IN A FINANCIAL AUDIT
3. TESTS OF CONTROLS
Procedures for Tests of Controls
Examine
documents, 1. Consists of examining records,
records, reports documents, or tangible assets.
(Inspection)
INTERNAL CONTROL IN A FINANCIAL AUDIT
3. TESTS OF CONTROLS
Procedures for Tests of Controls
Reperform 1. perform the task done by an employee
client
procedures to verify the result of the transaction
INTERNAL CONTROL IN A FINANCIAL AUDIT
3. TESTS OF CONTROLS
Control activities
YES
Evidence trail?
Inspection NO
Observation
Inquiry
Reperformance
INTERNAL CONTROL IN A FINANCIAL AUDIT
DECIDE PLANNED DETECTION RISK AND
DESIGN SUBSTANTIVE TESTS
The auditor uses the control risk assessment
and results of tests of controls to determine
planned detection risk and related substantive
tests for the audit of financial statements.
Thank you!