0% found this document useful (0 votes)
8 views11 pages

Internal Control Structure and Procedures

The document outlines the structure and evaluation of internal control systems essential for auditors in assessing the effectiveness of an entity's controls. It details the objectives, elements, and procedures of internal control, emphasizing the importance of compliance testing and communication of deficiencies. The auditor's role is highlighted in understanding and documenting the internal control framework to ensure reliable financial reporting.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
8 views11 pages

Internal Control Structure and Procedures

The document outlines the structure and evaluation of internal control systems essential for auditors in assessing the effectiveness of an entity's controls. It details the objectives, elements, and procedures of internal control, emphasizing the importance of compliance testing and communication of deficiencies. The auditor's role is highlighted in understanding and documenting the internal control framework to ensure reliable financial reporting.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Internal Control

CONTENT

INTRODUCTION

CHAPTER I

STRUCTURE OF INTERNAL CONTROL

1. OBJECTIVE OF THE INTERNAL CONTROL STRUCTURE


2. DEFINITION OF THE INTERNAL CONTROL STRUCTURE
3. ELEMENTS OF THE INTERNAL CONTROL STRUCTURE
4. INTERNAL CONTROL ENVIRONMENT
5. ACCOUNTING SYSTEM

CHAPTER II

CONTROL PROCEDURES

2.1 OBJECTIVES OF CONTROL

2.2 TYPES OF PROCEDURES

2.3 FACTORES ESPECIFICOS DEL AMBIENTE DEL CONTROL

2.4 PRELIMINARY EVALUATION OF INTERNAL CONTROL

2.5 EVALUATION OF THE ELECTRONIC PROCEDURE

2.6 COMPLIANCE TESTING

2.7 FINAL EVALUATION OF INTERNAL CONTROL

2.8 COMMUNICATIONS OF SITUATIONS TO REPORT

2.9 EXAMPLE INTRODUCTORY LETTER OF INTERNAL CONTROL

CONCLUSIONES

BIBLIOGRAPHY

SELF-EVALUATION

INTRODUCTION

Before the auditor prepares the audit program, they must conduct an assessment.
preliminary review of internal accounting controls. This preliminary review may be conducted at
areas that are fundamental in the planning process, especially in those that the
The audit must place special emphasis on which study time should be extended.
The study and evaluation of internal control is carried out with the aim of complying with the standard of
execution of the work that is required that: "The auditor must conduct a study and evaluation
adequate internal control in place, which serves as a basis to determine the degree of
trust that you will place in him and allow him to determine the nature, extent, and timing
that will lead to the audit procedures.

The knowledge and evaluation of internal control must allow the auditor to establish a
specific relationship between the quality of the entity's internal control and its achievement, opportunity and
nature of audit tests. On the other hand, the auditor must communicate the
weaknesses or deviations in the client's internal control that are defined as 'situations to
Inform.

OBJECTIVE OF THE INTERNAL CONTROL STRUCTURE

The objective is to define the elements of the internal control structure and establish the
regulatory procedures applicable to its study and evaluation, as a fundamental aspect
when establishing the audit strategy as well as outlining the guidelines that must be followed
Report on weaknesses or deviations in internal control.

DEFINITION OF THE INTERNAL CONTROL STRUCTURE

The internal control structure of an entity consists of the policies and procedures
established to provide reasonable assurance of achieving the objectives
specific to the entity.

ELEMENTS OF THE INTERNAL CONTROL STRUCTURE

The elements of the internal control structure are:

The internal control environment


2. The accounting system.
3. The procedures of internal control.

THE ENVIRONMENT OF INTERNAL CONTROL

The internal control environment represents the combination of factors that affect the policies and
procedures of an entity, strengthening or weakening its controls.

FACTORS OF THE INTERNAL CONTROL ENVIRONMENT

The factors of the internal control environment are as follows:

ATTITUDE OF THE ADMINISTRATION TOWARDS THE ESTABLISHED INTERNAL CONTROLS

The operations of the administration include a great diversity of characteristics among


others, the following approach to assume and monitor business risks, attitudes, and actions
regarding the financial information, including the emphasis on compliance
budgets, achieving profits and other financial and operational aspects.

These characteristics substantially influence the control environment, especially when


a few people master management, regardless of the considerations
that are given to other factors of the control environment itself.

ORGANIZATIONAL STRUCTURE OF THE ENTITY

The organizational structure of an entity provides the general framework for planning, directing,
and control the operations.
An appropriate structure includes the form and nature of the areas of the entity, including the
data procedure and the respective hierarchical relationships.

In addition, appropriate authority and responsibility must be assigned within the


entity.

FUNCTIONING OF THE ORGANIZATION OF THE ENTITY

The audit committees are appointed by the Board of Directors and have a role
fundamental en vigilar el cumplimiento de las políticas y practicas contables y de información
financial of the entity.

The committee must support the Board of Directors in its responsibilities and assist in
maintain direct communication between the Council and the external auditors.

METHODS FOR ASSIGNING AUTHORITY AND RESPONSIBILITY

These methods affect the understanding of hierarchical relationships and responsibilities.


established within the entity.

The methods for assigning authority and responsibility include, among other aspects, the
following:

Policies on matters such as business practices, conflicts of interest, and code of conduct.
conduct

Assignment of responsibilities and delegation of authority to address matters such as


goals and objectives of the organization, operational functions and legal requirements.

Job description of employees, outlining specific functions, relationships


hierarchical and restrictions.

Documentation of the computing systems, indicating the procedures for authorization.


transactions and approve changes to existing systems.

ADMINISTRATIVE CONTROL METHODS TO MONITOR AND TRACK


COMPLIANCE WITH POLICIES AND PROCEDURES, INCLUDING THE FUNCTION OF
INTERNAL AUDIT

These methods affect the direct control of the administration over the authority delegated to
others, as well as their ability to effectively oversee the activities of the entity in
general.

Administrative control methods include, among others:

Establishment of planning and information reporting systems that establish the


objectives of management and the results of actual performance.

Such systems may include strategic planning, budgets, forecasts, planning of


utilities and accounting by area of responsibility.

Establishment of methods that identify actual performance and exceptions to it


planned performance, as well as communication to the appropriate administrative levels.

Use of appropriate methods to investigate deviations from expectations and take


timely and appropriate corrective actions.
Establishment and oversight of policies to develop and modify accounting systems
the control procedures, including the development, modification, and use of programs
computing and related data files.

The effective internal audit function must have relationships of authority and information.
adequate, trained personnel and sufficient resources to carry out its function.

PERSONNEL POLICIES AND PRACTICES

These policies and practices affect an entity's ability to employ staff.


competent to achieve their goals and objectives.

They include the procedures and policies for hiring, training, evaluating, promoting and
compensate employees, as well as to provide them with the necessary resources so that
can fulfill their assigned responsibilities.

EXTERNAL INFLUENCES AFFECTING OPERATIONS AND PRACTICES OF


ENTITY

They are represented by external factors that affect the operations and practice of
the same.

They include the surveillance and compliance requirements established by regulated organizations and the
evaluation affected by third parties, of the actions of the entity.

Although external influences are often beyond the entity's control, they may increase the
awareness and attitude of management towards the conduct and information of operations
and establish specific internal control procedures or policies to
regarding.

The quality of the internal control environment is a clear indication of the importance that the
The entity's administration adheres to the established controls.

ACCOUNTING SYSTEM

The accounting system consists of the methods and records established to identify, gather,
analyze, classify, record, and produce quantitative information about the operations carried out
an economic entity.

METHODS AND RECORDS OF THE ACCOUNTING SYSTEM

The following methods and records must be available for an accounting system to be useful and
reliable

1. Identify and record only the actual transactions that meet the criteria
established by the administration:
2. Promptly describe all transactions with the necessary detail that allows
its proper classification.
3. Quantify the value of operations in monetary units.
4. Record the transactions in the corresponding period.
5. Properly present and disclose such transactions in the financial statements.

CONTROL PROCEDURES

The control procedures consist of the additional procedures and policies.


to the control environment and to the accounting system
The auditor must determine how the entity has applied the policies and procedures,
its uniform application and who has carried them out, to conclude that
They are indeed operating.

OBJECTIVES OF CONTROL PROCEDURES

Control procedures pursue different objectives and are applied at different levels.
of organization and transaction processing.

Among others, the following objectives are established:

Proper authorization of transactions and activities.


2. Adequate segregation of functions and responsibilities.
3. Design and use of appropriate documents and records to ensure proper recording.
of the operations.
4. Establishment of security devices that protect assets.
5. Independent verification of the actions of others and adequate evaluation of the
registered operations.

TYPES OF CONTROL PROCEDURES

The control procedures can be:

Preventive in nature.

Of detective character.

Preventive procedures are established to avoid errors during the


development of transactions.

The detection control procedures aim to detect errors or


the deviations that during the development of the transactions, had not been identified
for preventive control procedures.

SPECIFIC FACTORS OF THE CONTROL ENVIRONMENT, THE ACCOUNTING SYSTEM AND THE
CONTROL PROCEDURES

The factors that must be considered for a company or entity are the following:

Size of the entity.


2. Characteristics of the industry in which it operates.
3. Organization of the entity.
4. Nature of the accounting system and the established control techniques.
5. Specific business problems.
6. Applicable legal requirements.

The establishment and maintenance of a whole internal control structure represents a


great responsibility of management, to provide reasonable assurance that
the objectives of an entity are achieved.

Therefore, management must constantly monitor the internal control structure, with the
the purpose of seeing if it operates effectively or if it should be modified according to the conditions
existing within the company.

Every internal control structure can be affected in its effectiveness by various causes,
such as judgment errors, negligence, misunderstandings in instructions, lapses due to fatigue
of the staff, the disregard by management, among others.
In an audit, the auditor must document their knowledge and understanding of the structure
of internal control, as part of the planning process. The form and scope of the
documentation will be affected by the size and complexity of the entity and the nature of the
structure of internal control.

PRELIMINARY EVALUATION OF INTERNAL CONTROL

At this stage, the auditor must assess the risk involved in the work they are going to carry out.
with the aim of considering it in the design of their audit work programs and for
gradually identify the activities and specific characteristics of the entity.

Even though the internal controls have not been tested at this stage, the auditor must
mainly:

Understand the control environment established by management to detect errors


potentials.

Describe and verify your understanding of the management control procedures.

Evaluate the design of control systems to determine if they are likely to be effective.
to prevent or detect and correct identifiable potential errors.

To form a judgment about the trust that can be placed in the control that will be tested.

Once the auditor has acquired a general understanding of the internal control structure,
he will be qualified to decide the level of trust he will place in the existing controls,
for the prevention and detection of potentially significant errors or directly if they
audit objectives can be achieved more efficiently and effectively through the
application of substantive tests.

EVALUATION OF THE ELECTRONIC DATA PROCEDURE (PED)

The objectives of the electronic data procedure evaluation are:

Develop a global interpretation of the organization's structure.

Determine in what way the PED can influence the nature, opportunity, or scope of
the audit procedures that need to be carried out.

Determine if the accounting controls of the data process need to be reviewed later.

IMPORTANCE OF PED

Due to the importance that PED systems have gained in accounting information, thus
as the volume of operations processed in them, the loss of visible traces and
concentration of accounting functions that frequently occur in an environment of this type,
The auditor must understand, evaluate, and if applicable, test the PED system as part of
fundamental of the study of internal control valuation and properly document its
conclusions about its effect on financial information and the degree of trust that
will deposit in the controls.

PROCEDURES FOR THE PRELIMINARY REVIEW OF THE PED

The procedures for reviewing the data process carried out by the auditor usually include
following matters:
Obtain and prepare an updated organizational chart of the department or functions of the process
data electronic.

Entrevistar al personal competente del proceso electrónico de datos y obtener información y


descriptions of the central processor, peripherals, application software, and expected changes in
the hardware of the department.

Obtain copies of the reports of the reviews carried out by third parties if available.
if the client uses the services of a data processing center.

Forming a global opinion on the financial applications of the data processing center that
they are important for the audit and prepare brief descriptions of those that
they could significantly affect the nature, opportunity or scope of the procedures
of the audits that need to be carried out.

The factors to be considered include the degree of utilization of the processing center.
data in applications of important accounting controls, the basic structure of the
accounting controls of the entity, the flow of transactions, the supporting documents
from the same, the existence of other audits and the information relating to other points of
control.

COMPLIANCE TESTS

The purpose of compliance testing is to gather sufficient evidence to conclude whether the
control systems established by management will prevent or detect and correct
potential errors that could have a significant impact on the financial statements.

This conclusion allows for trust in control as a source of general auditing security and
reduce the scope of substantive tests.

Compliance tests are designed to support the assessment of the apparent


reliability of specific control procedures.

These tests may involve the examination of transaction documentation to look for the
presence or absence of specific attributes (defective controls)

When conducting a compliance test on a sample of selected transactions, one ...


it can determine an estimated maximum rate of deviations and thus reach a conclusion about
the efficiency of the control procedures during the examined period.

In addition to the tests described, it is necessary to establish, through inquiry and


observation and inspection of documentation, the way in which the administration has
ensured that the control system continues to operate effectively despite possible
changes in the environment.

The audit procedures could vary if as a result of the tests of


compliance, weaknesses or deviations from control procedures are detected.

FINAL EVALUATION OF INTERNAL CONTROL

The final evaluation of the selected control procedures will take place after carrying out
I finish the compliance tests of said controls.

The evaluation will be carried out by determining whether the control procedures are functioning.
effectively as they were designed, throughout the entire period.
At the end of the internal control evaluation, the auditor as part of their work must
provide suggestions to improve the existing internal control structure.

COMMUNICATIONS OF SITUATIONS TO REPORT

These are matters that attract the auditor's attention and that in their opinion should be communicated to the
client, as they represent significant deficiencies in the design or operation of the structure
of internal control, which may negatively affect the organization's ability to
register, process, summarize and report uniform financial information with the statements of
the management in the financial statements.

Such deficiencies can include different aspects of internal control.

IMPORTANCE OF THE SITUATIONS TO REPORT

The preliminary assessment of internal control often influences the identification of the main
visible control deficiencies.

Also during the course of their work, the auditor must be aware of the issues.
related to internal control that may be of interest to the client (situations to
to inform

The auditor's objective in an audit is to form an opinion on the financial statements.


of the entity, therefore it is not obligated to investigate and find situations to report.
However, you should be aware of them through the evaluation of the elements of the
structure of internal control, of the application of audit procedures on balances or
transactions in some other way during the course of the review.

The auditor's judgment regarding situations and reporting varies in each job and this
influenced by nature and the extent of audit procedures and other factors,
such as the size of the entity, its complexity, and the nature and diversification of its
activities.

This communication should be made with high-level authority and responsibility individuals.
such as the Board of Directors, the owner of the company, or with those who have
hired the auditor.

As part of their work, the auditor must also provide suggestions that allow for
improve the existing internal control structure.

The auditor may identify matters that, in their opinion, are not strictly situations to report.
or they are not very important and you will have to decide whether to communicate these matters or not
benefits of management.

Intentional violation of established controls by senior staff


hierarchical, to the detriment of control objectives.

Failures in the protection of assets against loss, damage, or misuse.

Failures in the execution of functions that are part of the internal control structure, such as
as timely preparation or review of reconciliations.

Improper application of accounting principles with the intention of distorting information


financial.

Violations of the policies and procedures established by the administrator.


Lack of capacity and training of employees or officials for the proper
development of its activities.

Other deficiencies:

Failures in the monitoring and correction of previously reported internal control deficiencies.

Important transactions with undisclosed related parties.

Lack of objectivity of those responsible in the way of accounting and information decisions
financial.

Incorrect statements by client personnel towards the auditor.

EXAMPLE OF A INTRODUCTORY LETTER TO THE REPORT ON MATTERS


RELATED TO THE INTERNAL CONTROL STRUCTURE.

To the board of directors

De Blam Electric S.A. de CV,

In connection with our examination of the financial statements of Blam Eléctrica S.A.
de CTV. Por el año terminado el 31 de Diciembre de 1997, hemos evaluado la estructura del
internal control of the company, only up to the extent we consider necessary to
to have a basis on which to determine the nature, extent, and timing of the tests
of auditing. Applying in our examination of the company's financial statements. Our
The evaluation of the internal control structure did not include a detailed study and assessment.
of none of its elements and was not executed with the purpose of developing
detailed recommendations or evaluate the efficiency with which the internal control structure
the company allows to prevent or detect all errors or irregularities that may occur
occur. The matters discussed here were considered during our examination and do not modify
our opinion dated March 29, 1998 on said financial statements. The report
adjunto también incluye comentarios y sugerencias con respecto a otros asuntos financieros y
administrative, which we will notice during the course of our examination of the states
financial.

All these comments are presented as constructive suggestions for consideration


of the Administration; as part of the continuous process of modification and improvement of the
existing internal control structure and other administrative practices and procedures
financial.

This report is for the exclusive use of the company management and should not be used
for no other purpose.

We would like to express our gratitude for the courtesy and cooperation extended to our
representatives during the course of their work. We would like to discuss these recommendations
in greater detail, if necessary, and likewise, provide the necessary assistance for its
implementation.

Very sincerely

Auditors, S.A. de CV

CONCLUSIONS
According to the study conducted, it is very important that a study and evaluation is carried out.
of internal control before the audit program is prepared or planned, this with the
Purpose of acquiring a general knowledge of the structure of internal control.

It is essential to conduct a study and evaluation of internal control as through it the


the auditor will be able to determine the trust they will place in internal control and know whether they should or
do not apply the audit tests.

If a company has good internal control in the areas of its accounting and is
carrying out effectively we can conclude that one can have confidence in the control
internal of the company, but this must be verified by the auditor reviewing that the policies and
the procedures have been applied uniformly.

It is also necessary for management to have a positive attitude towards internal controls.
checking that the policies and procedures are being properly implemented
entity in order to see if it operates efficiently or if policies or the
existing procedures.

BIBLIOGRAPHY

Audit Standards and Procedures

Mexican Institute of Public Accountants A.C.

Seventeenth Edition

Volume I

Generally Accepted Accounting Principles

Mexican Institute of Public Accountants A.C.

Eleventh Edition

SELF-EVALUATION

What is the objective of the Internal Control structure?

2. - Define the structure of Internal Control

3. - Mention the elements of the internal control structure

4. - What is understood by the Internal Control environment

5. - What does the structure of the Organization consist of?

6. - What should be taken into account to assign Authority and Responsibility in a


organization.

7. - What do the methods of Administrative Control consist of?

8. - What does an Accounting System consist of?

9. - What do personnel policies and practices consist of?

10. - What must an accounting system contain for it to be considered reliable


11 - Mention the Objectives of Control Procedures

12. - Mention what types of Control Procedures there are.

13 - What should be taken into account for the implementation of Internal Control or a System
Accountant

14 - What does the Preliminary Evaluation of Internal Control consist of?

15. - Mention of the electronic data procedure

16. - What importance does the Electronic Data Procedure have?

17. - Procedure for the Preliminary Review of the Electronic Data Procedure

18. - What do the Compliance tests consist of?

19. - What does the Final Evaluation of Internal Control consist of?

20. - What should the final report of the Internal Control contain?

You might also like