ACADEMY OF FINANCE
ASSURANCE 1
Chapter 5
Introduction to internal control
Lecturer: Dang Thi Huong,
PhD, CPA , Valuer, ICAEW BFP.
Email: dxthanhhuong@[Link]
[Link]
CHAPTER 5
5.3
5.2
5.1
What is Components Information
internal of internal about
control ? control controls
[Link] 2
What is internal control?
Definition
The process designed, implemented and maintained by those
charged with governance, management, and other personnel to
provide reasonable assurance about the achievement of an entity's
objectives with regard to reliability of financial reporting,
effectiveness and efficiency of operations and compliance with
applicable laws and regulations.
[Link]
Reasons for internal controls
They include:
• minimising the company's business risks
• ensuring the continuing effective functioning of the
company
• ensuring the company complies with relevant laws
and regulations.
[Link]
Worked example: Truefood Co
Truefood Co is a food manufacturer. It is subject to a great number
of health and safety regulations and therefore must have
significant internal controls surrounding the food preparation areas.
If these controls were seriously breached, Truefood Co would be
forced to cease operations. The primary objective of each internal
control might focus on a particular operation, for example, that all
personnel must wear protective clothing when operating
machinery however, the ultimate objective is to ensure the
operation of the company continues. If the protective clothing
wasn't worn and hair or other items, such as jewellery from staff,
fell into the food, the company might be forced to stop operating
[Link]
Limitations of internal controls
Human Unusual transactions
+ Makes a mistake, Collusion + It is designed to
control might be deal with what
ineffective. Override or avoid routinely happens
+ Do not understand controls in order to in a business
the importance of defraud the + Standard controls
the control, less company may not be
inclined to adhere relevant to the
to it. unusual
+ Number of transaction
employees
[Link]
COMPONENTS OF INTERNAL CONTROL
(3)
Information
(2) Risk (4) Control
(1) Control system (5) Monitoring
assessment activities
environment relevant to
process
financial
reporting
[Link]
• Each particular control activity may also prevent an error
occurring (preventative control), or may identify that an error
has occurred and correct it (detective control). It is an important
part of understanding internal controls to be able to identify
what it is that each specific control actually does.
• The auditor will not waste time looking at company controls
that are not relevant to whether the financial statements are
true and fair, however those important controls might be to the
overall operating of the business; for example, control processes
over asset utilisation.
• The extent of reliance on internal control in an assurance
engagement will depend on the nature of the engagement and
the assurance provider's expectation of the effectiveness of
controls. Mức độ tin cậy vào kiểm soát nội bộ trong một cam kết đảm bảo sẽ phụ thuộc vào bản chất của
[Link] cam kết và kỳ vọng của nhà cung cấp dịch vụ đảm bảo về hiệu quả của các biện pháp kiểm soát.
Control environment
Set a tone of an organization, influencing the control
consciousness of its people
• Demonstrating a commitment to Integrity and Ethical Values
• Maintaining the independence of the board of directors from
management and their oversight of the entity’s internal control
• Establishing organizational structure, reporting lines, authority,
and responsibilities to pursue business objectives
• Demonstrating a commitment to attract, develop, and maintain
competent people
• Maintaining accountability for the execution of internal control
responsibilities
[Link]
[Link]
[Link]
Information and communication
Definitions
• Information system relevant to financial reporting: A component of internal control
that includes the financial reporting system, and consists of the procedures and records
established to initiate, record, process and report entity transactions (as well as events
and conditions) and to maintain accountability for the related assets, liabilities and
equity.
The auditors will be interested in:
• the classes of transactions that are significant to the entity's
financial statements
• the procedures by which transactions are initiated, recorded,
processed, corrected and reported
• the related accounting records and supporting information
• how the information system captures events other than
transactions that are significant to the financial statements
• the process of preparing the financial statements
[Link]
Control activities Nhieu câu hoi
• Control activities are the policies and procedures that help
ensure that management directives are carried out.
• Control activities may be manual or computer-specific
control activities.
• Computer-specific control activities: benefits and
drawbacks?
[Link]
Control activities
lquan den phe duyet
Ra soat danh gia
lai KQKD
[Link]
Control activities
[Link]
Information processing controls
Application controls: Manual or automated procedures that
typically operate at a business process level. Application controls can
be preventative or detective in nature and are designed to ensure the
integrity of the accounting records. Accordingly, application controls
relate to procedures used to initiate, record, process and report
transactions or other financial data.
Kiểm soát ứng dụng có thể mang tính chất phòng ngừa hoặc phát hiện và được thiết kế để đảm bảo tính toàn vẹn của hồ sơ kế toán. Theo đó,
kiểm soát ứng dụng liên quan đến các thủ tục được sử dụng để khởi tạo, ghi lại, xử lý và báo cáo các giao dịch hoặc dữ liệu tài chính khác.
General controls: Policies and procedures that relate to many
applications and support the effective function of application controls
by helping to ensure the continued proper operation of information
systems.
Các chính sách và thủ tục liên quan đến nhiều ứng dụng và hỗ trợ chức năng hiệu quả của các biện pháp kiểm soát ứng
dụng bằng cách giúp đảm bảo hoạt động liên tục phù hợp của các hệ thống thông tin.
[Link]
Information processing controls - General controls
Development of computer
applications
Prevention or detection of
unauthorized changes to program
Testing and documentation of
program changes
General
controls Controls to prevent wrong
programs or files being used
Controls to prevent unauthorized
amendments to data files
đảm bảo tính liên tục của Controls to ensure continuity of
hoạt động operations
[Link]
Information processing controls - Application controls
Completeness
Accuracy
Controls over input
Application
Authorisation
controls
Controls over
processing
Controls over master
files and standing
data
[Link]
Cyber security risks
Communication is a key barrier
to common understanding and
discussion.
Organisational structures need to
define responsibility and accountability
Cyber for cyber security.
security
Board- level accountability for cyber
risks needs to be determined
Non-executive directors and audit
committees also need to play a part
[Link]
Monitoring of controls
Giam sat ksoat
• It still meets its objectives,
• It still operates effectively and efficiently,
• Necessary corrections to the system are made on a
timely basis.
[Link]
Recording of controls
• Narrative notes
• Questionnaires/checklists; and
• Diagrams
[Link]
[Link]
[Link]
[Link]
[Link]