0% found this document useful (0 votes)
18 views11 pages

Overview of Internal Control Systems

The document discusses the nature and purpose of internal controls within an organization. It defines internal controls as processes designed to provide reasonable assurance regarding financial reporting reliability, operational effectiveness and efficiency, and compliance with laws and regulations. The key elements of an effective internal control system are described as the control environment, risk assessment, control activities, information and communication, and monitoring activities.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as TXT, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
18 views11 pages

Overview of Internal Control Systems

The document discusses the nature and purpose of internal controls within an organization. It defines internal controls as processes designed to provide reasonable assurance regarding financial reporting reliability, operational effectiveness and efficiency, and compliance with laws and regulations. The key elements of an effective internal control system are described as the control environment, risk assessment, control activities, information and communication, and monitoring activities.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as TXT, PDF, TXT or read online on Scribd

CHAPTER 13: OVERVIEW OF INTERNAL CONTROL

NATURE AND PURPOSE OF INTERNAL CONTROL


Internal control is the process designed and effected by those charged with
governance, management and other personnel to provide reasonable assurance about
the achievement of the entity's objectives with regard to reliability of financial
reporting, effectiveness and efficiency of operations and compliance with
applicable laws and regulations. It follows that internal control is designed and
implemented to address identified business risks that threaten the achievement of
any of these objectives.
⁃ Internal controls are a system of measures implemented by a company to
manage risks and ensure that its financial reporting is accurate, its operations
are efficient, and it complies with all applicable laws and regulations. These
controls are designed to address specific risks that could threaten the achievement
of these objectives.

Those objectives fall into three categories:


• Reliability of the entity's financial reporting
⁃ This ensures that financial statements are accurate and complete.

• Effectiveness and efficiency of operations


⁃ This ensures that the organization's operations are carried out in a
way that achieves its goals without wasting resources.

• Compliance with applicable laws and regulations


⁃ This ensures that the organization follows all relevant laws and
regulations.

Whether an entity achieves its objectives relating to financial reporting and


compliance is determined by activities within the entity's control. However,
achieving its objectives relating to operations will depend not only on
management's decisions but also on competitor's actions and other factors outside
the entity.

INTERNAL CONTROL SYSTEM DEFINED


Internal control system means all the policies and procedures (internal controls)
adopted by the management of an entity to assist in achieving management's
objective of ensuring, as far as practicable, the orderly and efficient conduct of
its business, including adherence to management policies, the safeguarding of
assets, the prevention and detection of fraud and error, the accuracy and
completeness of the accounting records, and the timely preparation of reliable
financial information.
⁃ An internal control system is a framework of policies and procedures
designed to safeguard an organization's assets, promote operational efficiency, and
ensure the accuracy of financial reporting. It's essentially a set of safeguards to
help businesses achieve their objectives.

ELEMENTS OF INTERNAL CONTROL


Internal control structures vary significantly from one company to the next.
Factors such as size of the business, nature of operations, the geographical
dispersion of its activities, and objectives of the organization affect the
specific control features of an organization. However, certain elements or features
must be present to have a satisfactory system of control in almost any large scale
organization.
⁃ Internal control systems are tailored to the specific needs of each
organization. However, there are common elements that most effective systems share,
regardless of the company's size or industry. These elements provide a foundation
for ensuring a well-controlled environment.
The internal control system extends beyond these matters which relate directly to
the functions of the accounting system and consists of the following components:

a. the control environment;


b. the entity's risk assessment process;
c. the information system, including the related business processes, relevant to
financial reporting, and communication;
d. control activities;
e. monitoring of controls.

A. Control Environment
The control environment which means the overall attitude, awareness and actions of
directors and management regarding the internal control system and its importance
in the entity. The control environment has an effect on the effectiveness of the
specific control procedures. A strong control environment, for example, one with
tight budgetary controls and an effective internal audit function, can
significantly complement specific control procedures. However, a strong environment
does not, by itself, ensure the effectiveness of the internal control system.
⁃ The control environment sets the tone for the effectiveness of internal
controls within an organization. It reflects the overall attitude, awareness, and
actions of management regarding the importance of internal control. A strong
control environment, with elements like clear codes of conduct and an ethical
culture, fosters a more effective internal control system.

Factors reflected in the control environment include:


• The function of the board of directors and its committees;
• Management's philosophy and operating style;
• The entity's organizational structure and methods of assigning
authority and responsibility;
• Management's control system including the internal audit function,
personnel policies and procedures and segregation of duties.

The environment in which internal control operates has an impact on the


effectiveness of the specific control procedures.

Several factors comprise the control environment, including:

1. Communication and Enforcement of Integrity and Ethical Values


Integrity and ethical values are essential elements of the internal control
environment. They affect the design, administration, and monitoring of other
components of internal control. An entity's ethical and behavioral standards and
the manner in which it communicates and reinforces them determine the entity's
integrity and ethical behavior. Integrity and ethical values include management's
actions to remove or reduce incentives and temptations that might prompt personnel
to engage in dishonest, illegal, or unethical acts. They also include the
communication of entity values and behavioral standards to personnel through policy
statements, a code of conduct, and management's example of appropriate behavior.
⁃ Integrity and ethical values are foundational elements of a strong
control environment. They set the tone for an organization's culture and influence
how employees approach their work. A company that prioritizes integrity will have a
more effective system of internal controls.
⁃ This includes setting clear standards of conduct and communicating them
to employees. It also includes taking steps to reduce temptations to engage in
unethical behavior.

2. Commitment to Competence
Competence is the knowledge and skills necessary to accomplish tasks that define an
employee's job. Commitment to competence means that management considers the
competence levels for particular jobs in determining the skills and knowledge
required of each employee and that it hires employees competent to perform the
tasks.
⁃ Competence is essential for an effective internal control system.
Management should assess the skills and knowledge required for each job and ensure
employees possess them. This promotes a workforce capable of carrying out their
duties effectively and reduces the risk of errors or misconduct.
⁃ This means that management should hire employees who have the skills
and knowledge necessary to do their jobs effectively.

3. Participation by those Charged with Governance


An entity's control consciousness is influenced significantly by those charged with
governance. Attributes of those charged with governance include independence from
management, their experience and stature, the extent of their involvement and
scrutiny of activities, the appropriateness of their actions, the information they
receive, the degree to which difficult questions are raised and pursued with
management, and their interaction with internal and external auditors. The
importance of responsibilities of those charged with governance is recognized in
codes of practice and other regulations or guidance produced for the benefit of
those charged with governance. Other responsibilities of those charged with
governance include oversight of the design and effective operation of whistle
blower procedures and the process for reviewing the effectiveness of the entity's
internal control.
⁃ The participation of those charged with governance is a critical aspect
of a strong internal control environment. Their independence, experience, and
involvement set the tone for the organization's control consciousness.
⁃ This refers to the role of the board of directors and other governing
bodies in overseeing the internal control system.

4. Management's Philosophy and Operating Style


This refers to management's attitude towards (a) business risk, (b) financial
reporting, (c) meeting budget, profit and other established goals which all have
impact on the reliability of the financial statements. Management's approach to
taking and monitoring business risks, its conservative or aggressive selection from
alternative accounting principles, its conscientiousness and conservatism in
developing accounting estimates, and its attitude toward information processing and
the accounting function and personnel are factors that affect the control
environment.
⁃ Management’s approach to risk taking, financial reporting, and
achieving goals all influence the effectiveness of internal controls. A strong
control environment emphasizes sound risk management practices and accurate
financial reporting. Management should balance the need to meet financial targets
with the need for accurate financial reporting.

Management's philosophy and operating style is indeed a crucial factor influencing


the control environment. It encompasses their approach to:
• Business risk management: A strong control environment prioritizes
sound risk assessment and mitigation strategies.
• Financial reporting: Management's commitment to accurate and
transparent financial reporting strengthens the control environment.
• Achieving financial targets: Overly aggressive pressure to meet budgets
or profit goals can incentivize manipulation of financial statements, weakening
controls.
These elements all impact the control environment's effectiveness in safeguarding
assets, ensuring accurate financial reporting, and promoting ethical conduct.

5. Organizational Structure
The responsibilities and authorities of the various personnel within the
organization should be established in such a manner as to (1) assist the entity in
meeting its goals and objectives and (2) ensure that transactions are processed,
recorded, summarized and reported in an accurate and timely manner. Organizational
structure provides the overall framework for planning, directing and controlling
operations.
Expla:

An organization's structure plays a critical role in its internal control system. A


well-defined structure clarifies roles, responsibilities, and reporting lines,
which helps ensure:
• Effective achievement of goals: Clear structures enable efficient
allocation of tasks and resources towards achieving the organization's objectives.
• Accurate and timely financial reporting: Defined roles and reporting
lines ensure proper transaction processing, recording, and financial reporting.
Overall, a well-designed organizational structure provides a strong foundation for
a robust system of internal controls.

6. Assignment of Authority and Responsibility


Personnel within an organization need to have a clear understanding of their
responsibilities and the rules and regulations that govern their actions.
Management may develop job descriptions, computer system documentation. It may also
establish policies regarding acceptable business practice, conflicts of interest
and code of conduct.
⁃ Within an organization, a clear assignment of authority and
responsibility is crucial for effective internal accounting controls. This ensures
that employees understand their roles and the guidelines that govern their actions.
To achieve this, management can implement various measures such as developing job
descriptions, establishing computer system documentation, and setting up policies
on acceptable business practices, conflicts of interest, and codes of conduct.
Expla:

Assigning authority and responsibility is another crucial element of a strong


control environment. It ensures that employees understand their roles and the
expectations associated with them. Here's how this is achieved:
• Job descriptions: These documents outline the specific duties and
responsibilities of each position.
• Policies and procedures: These establish clear guidelines for
acceptable business practices, conflict of interest scenarios, and ethical conduct.
• Computer system documentation: This documentation clarifies user roles
and access permissions within IT systems.
By clearly defining authorities and responsibilities, organizations can promote
accountability and mitigate the risk of errors or misconduct.

7. Human Resources Policies and Procedures


Perhaps the most important element of an internal accounting control. system is the
people who perform and execute the established policies and procedures. Personnel
policies should be adopted by the client to reasonably ensure that only capable and
honest persons are hired and retained. Policies with respect to employee selection,
training, and supervision should be adopted and implemented by the client. The
selection of competent and honest personnel does not automatically assure that
errors or irregularities will not occur. However, adequate personnel policies,
coupled with the design concepts suggested earlier in this section, enhance the
likelihood that the client's policies and procedures will be followed.

⁃ Human resources (HR) policies and procedures are essential for an
organization to maintain a strong internal accounting control system. These
policies help ensure that the company hires and retains competent and honest
employees. HR policies typically address employee selection, training, and
supervision. By implementing these policies, organizations can create a work
environment that minimizes the risk of errors or irregularities.

B. Entity's Risk Assessment Process


Risk assessment is the "identification, analysis, and management of risks
pertaining to the preparation of financial statements". For example risk assessment
may focus on how the entity considers the possibility of transactions not being
recorded or identifies and assesses significant estimates recorded in the financial
statements.
⁃ An entity's risk assessment process is a systematic approach to
identifying and evaluating potential risks that could affect the accuracy of
financial statements. This process helps management ensure the completeness and
fairness of financial reporting.

An entity's risk assessment process is its process for identifying and responding
to business risks and the results thereof. For financial reporting purposes, the
entity's risk assessment process includes how management identifies risks relevant
to the preparation of financial statements that are presented fairly, in all
material respects in accordance with the entity's applicable financial reporting
framework, estimates their significance, assesses the likelihood of their
occurrence, and decides upon actions to manage them. For example, the entity's risk
assessment process may address how the entity considers the possibility of
unrecorded transactions or identifies and analyzes significant estimates recorded
in the financial statements. Risks relevant to reliable financial reporting also
relate to specific events or transactions.

Risks relevant to financial reporting include external and internal events and
circumstances that may occur and adversely affect an entity's ability to initiate,
record, process, and report financial data consistent with the assertions of
management in the financial statements. Once risks are identified, management
considers their significance, the likelihood of their occurrence, and how they
should be managed. Management may initiate plans, programs, or actions to address
specific risks or it may decide to accept a risk because of cost or other
considerations.
Expla:

An entity's risk assessment process is crucial for ensuring the accuracy of


financial statements. It involves identifying and evaluating potential risks that
could distort financial reporting. These risks can be internal or external, and
management must determine their significance and likelihood of occurrence. Based on
this assessment, they can implement appropriate controls to mitigate these risks.

Risks can arise or change due to circumstances such as the following:


• Changes in operating environment. Changes in the regulatory or
operating environment can result in changes in competitive pressures and
significantly different risks.
• New personnel. New personnel may have a different focus on or
understanding of internal control.
• New or revamped information systems. Significant and rapid changes in
information systems can change the risk relating to internal control.
• Rapid growth. Significant and rapid expansion of operations can strain
controls and increase the risk of a breakdown in controls.
• New technology. Incorporating new technologies into production
processes or information systems may change the risk associated with internal
control.
• New business models, products, or activities. Entering into business
areas or transactions with which an entity has little experience may introduce new
risks associated with internal control.
• Corporate restructurings. Restructurings may be accompanied by staff
reductions and changes in supervision and segregation of duties that may change the
risk associated with internal control.
• Expanded foreign operations. The expansion or acquisition of foreign
operations carries new and often unique risks that may affect internal control, for
example, additional or changed risks from foreign currency transactions.
• New accounting pronouncements. Adoption of new accounting principles or
changing accounting principles may affect risks in preparing financial statements.

⁃ These factors highlight the importance of an ongoing risk assessment


process to proactively identify and address potential threats to the accuracy of
financial statements.

The basic concepts of the entity's risk assessment process are relevant to every
entity, regardless of size, but the risk assessment process is likely to be less
formal and less structured in small entities than in larger ones. All entities
should have established financial reporting objectives, but they may be recognized
implicitly rather than explicitly in small entities. Management may be aware of
risks related to these objectives without the use of a formal process but through
direct personal involvement with employees and outside parties.

Considerations Specific to Smaller Entities


Many small entities are carried out entirely by the engagement partner (who may be
a sole practitioner). In such situations, it is the engagement partner who, having
personally conducted the planning of the audit, would be responsible for
considering the susceptibility of the entity's financial statements to material
misstatement due to fraud and error.
Expla:

The core principles of risk assessment apply to all entities, but the formality of
the process can differ. Smaller businesses may not have a documented risk
assessment process, but management's awareness of risks is still crucial for
reliable financial reporting.

C. Information System, including the Business Processes, Relevant to Financial


Reporting and Communication
An information system consists of infrastructure (physical and hardware
components), software, people, procedures, and data. Infrastructure and software
will be absent, or have less significance, in systems that are exclusively or
primarily manual. Many information systems make extensive use of IT.

The Information System, Including Related Business Processes, Relevant to Financial


Reporting
Expla:

The information system (IS) is a critical component of an organization's internal


accounting controls. It encompasses the people, processes, and technology involved
in capturing, processing, storing, and reporting financial data. An effective IS
ensures the accuracy, completeness, and timeliness of financial information used
for reporting purposes.

The information system relevant to financial reporting objectives, which includes


the accounting system, consists of the procedures and records designed and
established to:
• Initiate, record, process, and report entity transactions (as well as
events and conditions) and to maintain accountability for the related assets,
liabilities, and equity;
• Resolve incorrect processing of transactions, for example, automated
suspense files and procedures followed to clear suspense items out on a timely
basis;
• Process and account for system overrides or bypasses to controls;
• Transfer information from transaction processing systems to the general
ledger;
• Capture information relevant to financial reporting for events and
conditions other than transactions, such as the depreciation and amortization of
assets and changes in the recoverability of accounts receivables; and
• Ensure information required to be disclosed by the applicable financial
reporting framework is accumulated, recorded, processed, summarized and
appropriately reported in the financial statements.

Journal Entries
An entity's information system typically includes the use of standard journal
entries that are required on a recurring basis to record transactions. Examples
might be journal entries to record sales, purchases, and cash disbursements in the
general ledger, or to record accounting estimates that are periodically made by
management, such as changes in the estimate of uncollectible accounts receivable.
⁃ Journal entries are the fundamental building blocks of accounting. They
serve as a chronological record of financial transactions impacting an entity's
financial statements. These entries are typically made in a general ledger, which
is the primary book of accounts for a business.

An entity's financial reporting process also includes the use of non-standard


journal entries to record non-recurring, unusual transactions or adjustments.
Examples of such entries include consolidating adjustments and entries for a
business combination or disposal or nonrecurring estimates such as the impairment
of an asset. In manual general ledger systems, non-standard journal entries may be
identified through inspection of ledgers, journals, and supporting documentation.
When automated procedures are used to maintain the general ledger and prepare
financial statements, such entries may exist only in electronic form and may
therefore be more easily identified through the use of computer- assisted audit
techniques.
⁃ Non-standard journal entries are essential for recording one-time or
uncommon transactions that don't fit neatly into the standard entries used for day-
to-day accounting. These entries help ensure the accuracy and completeness of an
entity's financial statements.

Expla:

Journal entries are a fundamental aspect of an entity's information system for


financial reporting. They serve two main purposes:
• Recording standard, recurring transactions such as sales, purchases,
and cash disbursements.
• Recording non-standard, non-recurring transactions like adjustments for
business combinations or asset impairments.
Journal entries can be identified manually in traditional ledger systems or through
computer-assisted audit techniques in automated systems.

Related Business Processes


An entity's business processes are the activities designed to:
• Develop, purchase, produce, sell and distribute an entity's products
and services;
• Ensure compliance with laws and regulations; and
• Record information, including accounting and financial reporting
information

Business processes result in the transactions that are recorded, processed and
reported by the information system. Obtaining an understanding of the entity's
business processes, which include how transactions are originated, assists the
auditor obtain an understanding of the entity's information system relevant to
financial reporting in a manner that is appropriate to the entity's circumstances.
⁃ Business processes are the foundation for a company's financial
transactions. By understanding these processes, auditors can gain valuable insights
into how the information system functions and how it captures, processes, and
reports financial data. This understanding is crucial for ensuring the accuracy and
reliability of an entity's financial statements.

Accordingly, an information system encompasses methods and records that:


• Identify and record all valid transactions.
• Describe on a timely basis the transactions in sufficient detail to
permit proper classification of transactions for financial reporting.
• Measure the value of transactions in a manner that permits recording
their proper monetary value in the financial statements.
• Determine the time period in which transactions occurred to permit
recording of transactions in the proper accounting period.
• Present properly the transactions and related disclosures in the
financial statements.

Communication involves providing an understanding of individual roles and


responsibilities pertaining to internal control over financial reporting. It
includes the extent to which personnel understand how their activities in the
financial reporting information system relate to the work of others and the means
of reporting exceptions to an appropriate higher level within the entity. Open
communication channels help ensure that exceptions are reported and acted on.

Communication takes such forms as policy manuals, accounting and financial


reporting manuals, and memoranda. Communication also can be made electronically,
orally, and through the actions of management.

Application to Small Entities


Information systems and related business processes relevant to financial reporting
in small entities are likely to be less formal than in larger entities but their
role is just as significant. Small entities with active management involvement may
not need extensive descriptions of accounting procedures, sophisticated accounting
records, or written policies. Communication may be less formal and easier to
achieve in a small entity than in a larger entity due to the small entity's size
and fewer levels as well as management's greater visibility and availability.

D. Control Activities
Control activities are the policies and procedures that help ensure that management
directives are carried out, for example, that necessary actions are taken to
address risks that threaten the achievement of the entity's objectives. Control
activities, whether within IT or manual systems, have various objectives and are
applied at various organizational and functional levels.

The major categories of control procedures are:

A. Performance Review
B. Information Processing Controls
1) Proper authorization of transactions and activities
2) Segregation of duties
3) Adequate documents and records
4) Safeguards over access to assets; and
5) Independent checks on performance
C. Physical controls

A brief discussion of these control procedures follows:


A. Performance Review
In a performance review management uses accounting and operating data to assess
performance, and it then takes corrective action. Such reviews include:
• comparing actual performance (or operating results) with budgets,
forecasts, prior period performance, or competitors' data or tracking major
initiatives such as cost-containment or cost-reduction programs to measure the
extent to which targets are being met.
• investigating performance indicators based on operating or financial
data, such as quantity or purchase price variances or the percentage of returns to
total orders.
• reviewing functional or activity performance, such as relating the
performance of a manager responsible for a bank's consumer loans with some
standard, such as economic statistics or targets.

Personnel at various levels in an organization may make performance reviews.


Performance reviews may be used by managers for the sole purpose of making
operating decisions. For example, managers may analyze performance data and base
operating decisions on them because the data are consistent with their
expectations. This type of review improves the reliability of the data. However,
when managers follow up on unexpected results determined by a financial reporting
system, performance reviews become a useful control over financial reporting.

B. Information Processing Controls


Information processing controls are policies and procedures designed to require
authorization of transactions and to ensure the accuracy and completeness of
transaction processing. Control activities may be classified according to the scope
of the system they affect. General controls are control activities that prevent or
detect errors or irregularities for all accounting systems. General controls affect
all transaction cycles and apply to information processing as a center, hardware
and systems software acquisition and maintenance, and backup and recovery
procedures. Application controls are controls that pertain to the processing of a
specific type of transaction, such a payroll, or sales and collections. These
controls help ensure that transactions occurred, are authorized, and are completely
and accurately recorded and processed. Examples of application controls include
checking the arithmetical accuracy of records, maintaining and reviewing accounts
and trial balances, automated controls such as input data and numerical sequence
checks, and manual follow-up of exception reports. General IT- controls are
policies and procedures that relate to many applications and support the effective
functioning of application controls by helping to ensure the continued proper
operation of information systems. General IT-controls commonly include controls
over data center and network operations; system software acquisition, change and
maintenance; access security; and application system acquisition, development, and
maintenance. These controls apply to mainframe, miniframe, and end-user
environments. Examples of such general IT-controls are program change controls,
controls that restrict access to programs or data, controls over the implementation
of new releases of packaged software applications, and controls over system
software that restrict access to or monitor the use of system utilities that could
change financial data or records without leaving an audit trail.

Internal controls relating to the accounting system are concerned with achieving
objectives such as:
• Transactions are executed in accordance with management's general or
specific authorization.
• All transactions and other events are promptly recorded in the correct
amount, in the appropriate accounts and in the proper accounting period so as to
permit preparation of financial stateinents in accordance with an identified
financial reporting framework.
• Access to assets and records is permitted only in accordance with
management's authorization.
• Recorded assets are compared with the existing assets at reasonable
intervals and appropriate action is taken regarding any differences.

Control activities related to the processing of transactions may be grouped as


follows: (1) proper authorization, (2) design and use of adequate documents and
records, and (3) independent checks on performance.

1. Proper authorization of transactions and activities


As suggested earlier, authorization for the execution of transactions flows from
the stockholders to management and its subordinates. Before a transaction is
entered into with another party, certain conditions must usually be met. As part of
the evaluation of the potential transaction, documentation will be created. The
auditor uses this documentation, to determine whether business transactions are
properly authorized. For example, the purchase of inventory may create a purchase
order, a receiving report, and a vendor invoice. By inspecting these documents and
comparing them with company policy, the auditor may be reasonably satisfied that a
business transaction was authorized and executed in a manner consistent with
company policy.

2. Segregation of duties
An important element in designing an internal accounting control system that
safeguards assets and reasonably ensures the reliability of the accounting records
is the concept of segregation of responsibilities. No one person should be assigned
duties that would allow that person to commit an error or perpetuate fraud and to
conceal the error or fraud. For example, the same person should not be responsible
for recording the cash received on account and for posting the receipts to the
accounting records.

3. Adequate documents and records


The use of adequate documents and records allow the company to obtain reasonable
assurance that all valid transactions have been recorded.

4. Access to assets
The resources of a client can be protected by the establishment of physical
barriers and appropriate policies. For example, inventories may be kept in a
storeroom, or negotiable instruments may be placed in a safe deposit box.
Appropriate company policies are adopted so that only authorized persons have
access to company resources. Safeguarding of assets is more than establishing
physical barriers. A client should design its internal accounting control system so
that documents authorizing the movement of assets into an organization or out of an
organization are adequately controlled.

5. Independent checks on performance


The objective of a well-designed internal accounting control system is the adoption
of procedures that periodically compare the actual asset with its recorded balance.
Regardless of the effectiveness of an internal control system, some transactions
may not be accurately recorded, and some assets may be misappropriated. An
important part of an internal accounting control system is to determine the
effectiveness of recording policies and asset access policies. This is accomplished
by periodic counts of assets by the client and comparing the counts to the balances
in the general ledger account. Examples are the count of inventory and the
preparation of monthly bank reconciliation.

C. Physical Controls
Controls that encompass:
• The physical security of assets, including adequate safeguards such as
secured facilities over access to assets and records.
• The authorization for access to computer programs and data files.
• The periodic counting and comparison with amounts shown on control
records (for example, comparing the results of cash, security and inventory counts
with accounting records).

The extent to which physical controls intended to prevent theft of assets are
relevant to the reliability of financial statement preparation, and therefore the
audit, depends on circumstances such as when assets are highly susceptible to
misappropriation.

The concepts underlying control activities in small entities are likely to be


similar to those in larger entities, but the formality with which they operate
varies. Further, small entities may find that certain types of control activities
are not relevant because of controls applied by management. For example,
management's retention of authority for approving credit sales, significant
purchases, and drawdown's on lines of credit can provide strong control over those
activities, lessening or removing the need for more detailed control activities. An
appropriate segregation of duties often appears to present difficulties in small
entities. Even companies that have only a few employees, however, may be able to
assign their responsibilities to achieve appropriate segregation or, if that is not
possible, to use management oversight of the incompatible activities to achieve
control objectives.

E. Monitoring of Controls
Monitoring, the final component of internal control, is the process that an entity
uses to assess the quality of internal control over time. Monitoring involves
assessing the design and operation of controls on a timely basis and taking
corrective action as necessary. Management monitors controls to consider whether
they are operating as intended and to modify them as appropriate for changes in
conditions. In many entities, internal auditors evaluate the design and operation
of internal control and communicate information about strengths and weaknesses and
recommendations for improving internal control.

Some monitoring activities may include communications from external parties. For
example, customers implicitly corroborate sales data by paying their bills or
raising questions. Also, bank regulators, other regulators, and outside auditors
may communicate about the design or effectiveness of internal control.

Monitoring activities may include using information from communications from


external parties that may indicate problems are highlight areas in need of
improvement. Customers implicitly corroborate billing data by paying their invoices
or complaining about their charges. In addition, regulators may communicate with
the entity concerning matters that affect the functioning of internal control, for
example, communications concerning examinations by bank regulatory agencies. Also,
management may consider communications relating to internal control from external
auditors in performing monitoring activities.

Application to Small Entities


Ongoing monitoring activities of small entities are more likely to be informal and
are typically performed as a part of the overall management of the entity's
operations. Management's close involvement in operations often will identify
significant variances from expectations and inaccuracies in financial data leading
to corrective action to the control.

Common questions

Powered by AI

Those charged with governance significantly influence a strong control environment by embedding a control consciousness within the organization . Their independence, experience, and involvement, as well as their scrutiny of activities and the information they receive, help set an appropriate tone . They oversee whistle blower procedures and review the system's effectiveness, enhancing accountability and transparency within the internal control framework .

The control environment sets the tone for the effectiveness of internal controls within an organization by reflecting the overall attitude, awareness, and actions of management regarding internal control importance . It influences specific control procedures' effectiveness, as a strong control environment can significantly complement them . However, even a strong environment does not ensure the system's success alone but serves as a foundational element that determines how effectively control measures operate . Factors such as management's ethical responsibilities, competence, and governance involvement play crucial roles .

Commitment to competence is crucial because it ensures that management assesses and hires employees with the requisite skills and knowledge to perform job tasks effectively, thereby reducing the risk of errors or misconduct . This foundational element of internal control supports a workforce capable of executing their duties efficiently and maintaining the system's effectiveness .

In small entities, information systems and related business processes concerning financial reporting are typically less formal than in larger entities but play a similarly significant role . Small entities often rely more on management's visibility and involvement for communication, due to fewer levels and greater informality in process descriptions and policy establishment, contrasting with the structured layers found in larger organizations .

Control activities facilitate the achievement of organizational objectives by ensuring management directives are executed through policies and procedures designed to address risk . They include performance reviews, information processing, and physical controls, each contributing to the accuracy, authorization, and safeguarding of financial data to support operational goals .

Management's philosophy and operating style directly impact the control environment by influencing approaches to business risk, financial reporting, and target achievement . Their attitude towards risk-taking and reporting obligations, from conservative to aggressive practices, affects the reliability of financial statements and effective risk management . Management's balance between financial goals and reporting accuracy also significantly influences the control environment, promoting sound practices .

Journal entries are critical in an entity's information system as they provide a chronological record of financial transactions impacting financial statements . They include standard entries for recurring transactions (e.g., sales, purchases) and non-standard ones for unique events (e.g., asset impairment) to ensure comprehensive and accurate financial documentations .

A robust human resources policy is vital in maintaining strong internal accounting controls because it reinforces a capable and honest workforce essential for executing policies and procedures . Such policies focus on employee selection, training, and supervision, ensuring that personnel involved have the integrity and skills needed, thereby sustaining control reliability and reducing risks of error or misconduct .

An information system can enhance financial reporting accuracy and completeness by ensuring valid transactions are timely recorded, classified, and valued properly . It defines procedures to initiate, process, and report transactions, including resolving incorrect processes and handling system overrides . Thus, it plays a pivotal role in maintaining reliable and detailed records necessary for accurate financial statements .

A well-defined organizational structure supports internal control effectiveness by clarifying roles, responsibilities, and reporting lines, facilitating effective goal achievement and timely financial reporting . It provides the framework for planning, directing, and controlling operations, ensuring accountability and proper execution of internal controls .

You might also like