0% found this document useful (0 votes)
4 views32 pages

Chapter 16 Internal Control

Chapter 16 discusses the importance of internal control systems in ensuring reliable financial reporting, efficient operations, and compliance with laws. It outlines the components of internal control, including the control environment, risk assessment, control activities, and monitoring, while emphasizing the roles of management and audits in maintaining these controls. The chapter also highlights the use of information technology in enhancing internal controls and the distinctions between internal and external audits.

Uploaded by

anupamkrishnak02
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
4 views32 pages

Chapter 16 Internal Control

Chapter 16 discusses the importance of internal control systems in ensuring reliable financial reporting, efficient operations, and compliance with laws. It outlines the components of internal control, including the control environment, risk assessment, control activities, and monitoring, while emphasizing the roles of management and audits in maintaining these controls. The chapter also highlights the use of information technology in enhancing internal controls and the distinctions between internal and external audits.

Uploaded by

anupamkrishnak02
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Chapter 16 Audit and financial control

Internal Control
A system designed by management to make sure:
Financial reports are reliable
Operations are efficient and effective
Laws and rules are followed
✓ Before paying a supplier, the accounts team checks the invoice calculations
to ensure correct payment.
This improves accuracy of financial records.
Internal Check
A part of internal control where:
No single person does all steps of a task
Each person’s work is automatically checked by another during their routine
work
Example:
One person prepares the invoice, and another approves it.
→ This helps detect errors or fraud early.
 Purpose of Internal Control
 Internal control helps management achieve business goals by:
 Ensuring smooth and efficient operations
 Safeguarding company assets
 Preventing and detecting fraud and errors
 Keeping accounting records accurate and complete
 Preparing reliable financial reports on time
 the information system and communication
The components of internal control
 the control environment
 the entity’s risk assessment process
 control activities
 the entity’s process to monitor the system of internal control
Control Environment
It is the overall attitude and actions of management towards internal controls.
It shows how seriously the company treats rules, ethics, and control systems.
▪ Management’s commitment to honesty and ethics
▪ Proper organizational structure
▪ Staff training and awareness
▪ Clear responsibilities and authority
 If top managers follow rules and promote ethical behavior, employees are
more likely to respect controls.
 But if a CEO says, “Ignore the approval process, just get it done,”
employees may also skip controls.
Risk Assessment Process
Identify Risks
 Understand what could go wrong (internal or external)
Assess Significance
 How serious is the risk?
Assess Likelihood
 How likely is it to happen?
Decide Response/Management
 What should be done to prevent or reduce the risk?
Business Risk
Business risk is the possibility that something may happen which:
Harms the business
Affects its goals or strategy
Causes misstatements in financial statements
Types of Business Risk:
Internal Risks (from inside the business):
Sales
Procurement
Production
Product delivery
After-sales service
External Risks (from outside the business):
Political factors
Laws and regulations
Socioeconomic trends
Technological changes
The information system and communication
refers to:
The procedures and records used to process all business transactions,
And to track assets, liabilities, and equity balances for accurate financial
reporting.
Most systems today use Information Technology (IT) for faster and more
accurate processing.
Function What it Means Simple Example

System should record only A sales system records only


1. Identify & record valid
genuine business confirmed customer orders,
transactions
transactions. not canceled ones.

Enough details must be An invoice shows product


2. Describe transactions
provided for correct type, quantity, price, and
clearly
classification. customer name.

System must assign the A purchase of ₹10,000 is


3. Measure in monetary terms correct value to each correctly entered in
transaction. accounting software.

Transactions must be A sale made on March 30 is


4. Record in the right
recorded in the correct recorded in the financial year
accounting period
period. ending March 31.

Transactions must appear A loan is shown under


5. Present properly in financial
with correct classification and liabilities, with interest shown
statements
disclosures. separately.
Control Activities:
Control activities are the policies and procedures put in place to:
Ensure management instructions are followed
Help manage or reduce business risks
Support achievement of the company’s objectives
Type Purpose Example

Approve transactions to Manager signs off large


1. Authorisation
ensure they are valid payments

Match records to ensure


Bank statement is
2. Reconciliation accuracy and
matched with cash book
completeness

Cross-check details to Stock count compared


3. Verification
confirm correctness with stock records

Locking storeroom or
4. Physical/Logical Protect assets or data
using password
Controls from loss or theft
protection

One person enters


No single person controls
5. Segregation of Duties invoices, another
all steps of a process
approves them
Monitoring Internal Controls:
Regularly checking if the internal controls are working properly and
Fixing problems if controls are weak or failing.

Aspect Explanation

To check the quality and effectiveness of


1. Purpose
internal controls over time

- Control design (is the control properly


2. What is monitored? planned?) - Control operation (is it working
properly?)

Controls may stop working if: – Company grows


3. Why is it needed?
too fast – Poor training – Staff are not motivated

Take corrective action (e.g., update controls,


4. What if problems are found?
train staff, assign duties better)
Three Key Types of Internal Controls
1. Preventive Controls
These stop problems before they happen.
What they do : Prevent errors/frauds before they occur
Examples
▪ Manager authorises payments before they’re made
▪ Segregation of duties (e.g., one staff raises a purchase order, another
approves it)
▪ Creating a strong ethical culture in the company
▪ Hiring and training qualified employees
2. Detective Controls
These find out if something has gone wrong.
Detect errors/fraud after they occur
examples
▪ Monthly bank reconciliation
▪ Exception reports (e.g., alert for payments over ₹1 lakh without approval)
▪ Internal checks or supervisor review of work
Helpful for identifying and tracking issues that were not prevented.
3. Corrective Controls
These fix the problem once it's found.
Correct errors/fraud that have already occurred
examples
▪ Manager takes follow-up action when a mistake is detected
▪ Updating system settings after a control failure
▪ Re-training staff who made recurring errors
Use of Information Technology (IT) in Internal Control
IT helps businesses set up and apply internal controls effectively in two key
areas
1. Financial Control
IT helps control money-related activities.
Example Situation:
Suppose a customer is allowed to buy up to ₹50,000 on credit.
If they already owe ₹50,000 and the staff tries to create a new order for
₹10,000:
The IT system will block the sale automatically.
This prevents financial risk for the company.
2. Operational Controls
IT helps control daily work activities in the business.
Example Situation:
If a biscuit-making machine finds that some biscuits are broken or
underweight,
The machine will automatically remove those bad biscuits from the
production line.
This ensures that only good-quality products are packed and sold.
Protection of IT Systems and Software
Businesses must protect their IT systems to make sure they run properly and
securely.
Non-discretionary controls are automatic system controls that cannot be
changed by users.
Control Type Simple Example

User must enter a password to log in —


Password Protection
system won’t allow access without it.

If the computer is idle for 10 minutes, it


Auto Log-Off
automatically logs out the user.

A junior employee can’t approve


User Permissions
payments — system blocks the option.

Two Main Categories of IT Controls

1. General IT Controls

These ensure the overall IT system works properly and securely.


Type What it Controls Example

Prevent physical damage or Security guards, door locks,


Physical controls
theft of IT equipment CCTV

Ensure new
Hardware/software Testing before adding a
software/hardware is
configuration new software update
installed correctly
Prevent people from using
Logical access the system without Passwords, biometric logins
permission
Keep systems running after
Backup systems at another
Disaster recovery problems like fire, flood, or
location
hacking
Ensure system reports are
Only managers get sales
Output controls complete and only seen by
reports
right people
Make sure users are trained
IT help desk, staff training
Technical support and can get help when
sessions
needed
Information Processing Controls
These controls help ensure that the data entered into a system is correct,
complete, valid, and properly authorized.
Main Objectives of These Controls
Control Goal What It Ensures Real-World Example

At a supermarket, all items


All data is entered, none
Completeness scanned → system shows
missing
"Total 25 items scanned"

In a bank, only the branch


Only approved persons can
Authorisation manager can approve loans
enter/process data
above ₹10 lakhs

A hospital system logs:


Who entered the data can
Identification "Patient record updated by
be clearly tracked
Nurse ID: NRS102 at 4:35 PM"

Data entered is real and System doesn’t allow delivery


Validity
makes sense date before order date

Payroll software checks: Basic


Calculations are
Forensic Checks Pay + Allowances –
mathematically accurate
Deductions = Net Pay
Examples of Information Processing Controls

Type of Control Simple Explanation Real-World Example

System shows total number or Accountant enters 25 supplier


Batch Total Checks value of entries; user compares invoices → system confirms “25
it with expected totals. invoices recorded”.

Invoice numbers must follow


System ensures document
Sequence Checks 101, 102, 103…; missing number
numbers are in order.
triggers an alert.

Billing system compares price


Verifies data (like prices) against
Match with Master Files on invoice with company’s
the official database.
product price list.

System recalculates math to System checks if ₹500 × 4 =


Arithmetic Checks
verify accuracy. ₹2,000 on a purchase order.

Employee age must be


Ensures entered data falls within
Range Checks between 18 and 60; 100 is
acceptable limits.
rejected.
Management Responsibility for Internal Control
1. Who is Responsible?
 Directors and senior management are responsible for setting up internal
controls.
 Responsibility comes from:
 Law (legal duty to maintain records and prevent fraud).
 Corporate governance principles.
2. Legal Duties of Directors
 Maintain proper accounting records.
 Safeguard company assets.
 Take reasonable steps to detect and prevent fraud.
3. Management’s Role
 Implement the policies approved by the board.
 Report regularly to the board about:
 Major risks.
 Effectiveness of internal controls.
All employees must support internal control in their roles.
Board’s Internal Control Review

Review Area What to Check Practical Example

Company launches
Has the business faced
online sales → faces
Changes in risks new or growing risks this
cybersecurity threats not
year?
present earlier.

Monthly reports from


Are managers and
finance detect rising
Risk monitoring auditors actively
bad debts → board is
tracking key risks?
alerted early.

Staff was able to steal


Were there any control
cash due to no
Control failures breakdowns or frauds
segregation between
this year?
billing and collection.
Point Internal Audit External Audit
Internal review function set up by Independent audit conducted by
Definition management to check systems, external professionals to check
risks, and controls. the truth and fairness of accounts.

Improve efficiency, check internal Provide an independent opinion


Objective
controls, and assist management. on the financial statements.
Management/Board of the Shareholders or Law (e.g.
Appointed by
company. Companies Act).
Management and Board (for Shareholders and sometimes
Report submitted to
internal use). government/regulators.
Entire operations (both financial Mainly the financial statements
Main focus area
and operational controls). and related accounting records.
Continuous or periodic – done
Timing Annual – done once a year.
throughout the year.
Internal auditor checks whether External auditor verifies whether
Example employees are following inventory closing stock in balance sheet is
control rules. correctly valued.
Works within the company, but
Fully independent from the
Independence should be independent from the
company being audited.
departments it audits.
Helps in risk reduction, fraud Builds stakeholder trust by
Usefulness prevention, and improving certifying the accuracy of
processes. financial statements.
Internal vs External Audit
Internal Audit (Real-World External Audit (Real-World
Point
Example) Example)
An internal auditor at a An external auditor from
company like TCS checks if Deloitte checks TCS’s financial
1. Role
staff are following company statements for accuracy and
expense policies. compliance.

TCS may choose to have TCS must appoint external


2. Legal Basis internal audit for better control, auditors by law as a public
not required by law. listed company in India.

Internal audit checks External audit only checks


everything: payroll, IT security, financial records like sales,
3. Scope
inventory handling, HR policies, purchases, assets, liabilities,
etc. etc.

Internal auditor tests if External auditor tests if invoices


4. Approach employees are bypassing the and payments are properly
purchase order process. recorded in the financials.

Reports go to senior
Reports go to shareholders and
management and audit
5. Report to regulators to show true and fair
committee for internal
financial position.
improvements.
Limitations of Internal Audit

Limitation Simple Explanation Real-World Example

Internal auditors work for


An internal auditor may
1. Lack of management, so full
hesitate to criticize the
Independence objectivity may be
CEO’s decisions.
difficult.

A company with only 1


If there are not enough
internal auditor cannot
2. Resource Constraints staff, or poor skills, the
check all departments
audit may be weak.
properly.

If they find fraud by top


Auditors may hide
managers, they may
3. Fear of Consequences serious issues (like fraud)
fear being fired if they
to protect their jobs.
report it.
How an Audit Committee Can Help (Solutions)

Support from Audit


Simple Explanation Example
Committee

Audit committee decides


Tells auditor to review IT
Set Work Plan what the internal audit
security this quarter.
should check.

Auditor sends reports to


Helps avoid pressure from
Receive Reports the audit committee, not
company managers.
just management.

Audit committee checks if


Approves budget to hire 2
Ensure Resources the audit team has
more audit staff.
enough people and tools.

Committee can raise Reports fraud risk in


Board-Level Voice audit issues directly with procurement directly to
main board of directors. the board.
Advantages of External Audit

Advantage Simple Explanation Example

Helps settle disagreements by Two partners disagree on profit


1. Resolves disputes giving an independent view of share → audit clarifies the actual
the accounts. figures.

Two shop owners merge →


2. Helps during ownership Builds trust when merging or
audited accounts help decide
change selling a business.
fair share.

Lenders prefer audited accounts Bank may trust a business with


3. Better chance for loans
as they show more reliability. audited financials more.

Auditor may give suggestions for


Auditor suggests better inventory
4. Expert business advice improving operations and
control to reduce waste.
efficiency.
Disadvantages of External Audit

Disadvantage Simple Explanation Example

Audit fees may be high,


A small bakery avoids
1. Costly especially for small
audit due to high cost.
businesses.

Staff must spend time


Office staff spend 3 days
2. Time-consuming for helping the auditor with
helping auditor find old
staff records and
invoices.
explanations.
Internal Control & Audit
Why Internal Control is Important to External Auditors

Point Simplest Explanation Example


If purchase approvals are
To reduce detailed checking
well-controlled, fewer
Purpose of Interest (called substantive testing) if
purchase invoices need to
controls are strong.
be checked.

Cross-checking a sales
Accuracy checks to confirm
What are Substantive Tests? invoice with delivery records
if figures are true.
and payment entries.

If expense claims require


Auditors check early if manager approval, auditors
Early Assessment
controls are reliable. may skip detailed review of
all claims.

Auditors adjust their If during testing a control


checking depending on fails, auditors will increase
Review During Audit
how controls perform during their checking of related
testing. data.
 Why Internal Control Interests the Internal Auditor

Point Simplest Explanation Real-Life Example


Internal auditors check if They check if employee
Main Role internal controls are expenses are verified
working properly. before payment.
They make sure the Ensure that approvals are
Corporate Governance company follows proper in place before any big
rules and systems. payments.
Internal auditors do system Check whether inventory
System Audit audits to test overall systems prevent theft or
control strength. errors.
Based on how strong or
If payroll system is secure,
weak a control is, they
Risk-Based Testing fewer employee salary
decide how much testing
records are checked.
is needed.

Internal control is a Monthly checks on sales


Ongoing Monitoring continuous task for internal returns to detect fraud or
auditors. system errors.
Ensuring the Effectiveness of Internal Financial Procedures
Internal controls should help the company to:

Goal Simple Explanation

Company runs in a smooth and


Orderly business conduct
efficient way.

Protect cash, stock, and equipment


Safeguarding of assets
from loss or theft.

Stop mistakes or cheating before they


Prevention of fraud and error
happen.

Accounts must show true and full


Accuracy of records
details.

Reports (e.g. profit/loss) must be


Timely and reliable information
correct and on time.
How to Ensure Effectiveness

Step Simple Example

Segregate duties: one staff collects


Set strong financial controls
cash, another records it.

Control environment, risk assessment,


Implement 5 components of control control activities, info systems,
monitoring

Internal auditor checks payroll process


Use internal audit
and suggests better approval steps.

Auditor finds weak inventory checks


Consider external auditor feedback
and recommends barcode scanning.

You might also like