Internal Control Structure and Procedures
Internal Control Structure and Procedures
CONTENT
INTRODUCTION
CHAPTER I
CHAPTER II
CONTROL PROCEDURES
CONCLUSIONES
BIBLIOGRAPHY
SELF-EVALUATION
INTRODUCTION
Before the auditor prepares the audit program, they must conduct an assessment.
preliminary review of internal accounting controls. This preliminary review may be conducted at
areas that are fundamental in the planning process, especially in those that the
The audit must place special emphasis on which study time should be extended.
The study and evaluation of internal control is carried out with the aim of complying with the standard of
execution of the work that is required that: "The auditor must conduct a study and evaluation
adequate internal control in place, which serves as a basis to determine the degree of
trust that you will place in him and allow him to determine the nature, extent, and timing
that will lead to the audit procedures.
The knowledge and evaluation of internal control must allow the auditor to establish a
specific relationship between the quality of the entity's internal control and its achievement, opportunity and
nature of audit tests. On the other hand, the auditor must communicate the
weaknesses or deviations in the client's internal control that are defined as 'situations to
Inform.
The objective is to define the elements of the internal control structure and establish the
regulatory procedures applicable to its study and evaluation, as a fundamental aspect
when establishing the audit strategy as well as outlining the guidelines that must be followed
Report on weaknesses or deviations in internal control.
The internal control structure of an entity consists of the policies and procedures
established to provide reasonable assurance of achieving the objectives
specific to the entity.
The internal control environment represents the combination of factors that affect the policies and
procedures of an entity, strengthening or weakening its controls.
The organizational structure of an entity provides the general framework for planning, directing,
and control the operations.
An appropriate structure includes the form and nature of the areas of the entity, including the
data procedure and the respective hierarchical relationships.
The audit committees are appointed by the Board of Directors and have a role
fundamental en vigilar el cumplimiento de las políticas y practicas contables y de información
financial of the entity.
The committee must support the Board of Directors in its responsibilities and assist in
maintain direct communication between the Council and the external auditors.
The methods for assigning authority and responsibility include, among other aspects, the
following:
Policies on matters such as business practices, conflicts of interest, and code of conduct.
conduct
These methods affect the direct control of the administration over the authority delegated to
others, as well as their ability to effectively oversee the activities of the entity in
general.
The effective internal audit function must have relationships of authority and information.
adequate, trained personnel and sufficient resources to carry out its function.
They include the procedures and policies for hiring, training, evaluating, promoting and
compensate employees, as well as to provide them with the necessary resources so that
can fulfill their assigned responsibilities.
They are represented by external factors that affect the operations and practice of
the same.
They include the surveillance and compliance requirements established by regulated organizations and the
evaluation affected by third parties, of the actions of the entity.
Although external influences are often beyond the entity's control, they may increase the
awareness and attitude of management towards the conduct and information of operations
and establish specific internal control procedures or policies to
regarding.
The quality of the internal control environment is a clear indication of the importance that the
The entity's administration adheres to the established controls.
ACCOUNTING SYSTEM
The accounting system consists of the methods and records established to identify, gather,
analyze, classify, record, and produce quantitative information about the operations carried out
an economic entity.
The following methods and records must be available for an accounting system to be useful and
reliable
1. Identify and record only the actual transactions that meet the criteria
established by the administration:
2. Promptly describe all transactions with the necessary detail that allows
its proper classification.
3. Quantify the value of operations in monetary units.
4. Record the transactions in the corresponding period.
5. Properly present and disclose such transactions in the financial statements.
CONTROL PROCEDURES
Control procedures pursue different objectives and are applied at different levels.
of organization and transaction processing.
Preventive in nature.
Of detective character.
SPECIFIC FACTORS OF THE CONTROL ENVIRONMENT, THE ACCOUNTING SYSTEM AND THE
CONTROL PROCEDURES
The factors that must be considered for a company or entity are the following:
Therefore, management must constantly monitor the internal control structure, with the
the purpose of seeing if it operates effectively or if it should be modified according to the conditions
existing within the company.
Every internal control structure can be affected in its effectiveness by various causes,
such as judgment errors, negligence, misunderstandings in instructions, lapses due to fatigue
of the staff, the disregard by management, among others.
In an audit, the auditor must document their knowledge and understanding of the structure
of internal control, as part of the planning process. The form and scope of the
documentation will be affected by the size and complexity of the entity and the nature of the
structure of internal control.
At this stage, the auditor must assess the risk involved in the work they are going to carry out.
with the aim of considering it in the design of their audit work programs and for
gradually identify the activities and specific characteristics of the entity.
Even though the internal controls have not been tested at this stage, the auditor must
mainly:
Evaluate the design of control systems to determine if they are likely to be effective.
to prevent or detect and correct identifiable potential errors.
To form a judgment about the trust that can be placed in the control that will be tested.
Once the auditor has acquired a general understanding of the internal control structure,
he will be qualified to decide the level of trust he will place in the existing controls,
for the prevention and detection of potentially significant errors or directly if they
audit objectives can be achieved more efficiently and effectively through the
application of substantive tests.
Determine in what way the PED can influence the nature, opportunity, or scope of
the audit procedures that need to be carried out.
Determine if the accounting controls of the data process need to be reviewed later.
IMPORTANCE OF PED
Due to the importance that PED systems have gained in accounting information, thus
as the volume of operations processed in them, the loss of visible traces and
concentration of accounting functions that frequently occur in an environment of this type,
The auditor must understand, evaluate, and if applicable, test the PED system as part of
fundamental of the study of internal control valuation and properly document its
conclusions about its effect on financial information and the degree of trust that
will deposit in the controls.
The procedures for reviewing the data process carried out by the auditor usually include
following matters:
Obtain and prepare an updated organizational chart of the department or functions of the process
data electronic.
Obtain copies of the reports of the reviews carried out by third parties if available.
if the client uses the services of a data processing center.
Forming a global opinion on the financial applications of the data processing center that
they are important for the audit and prepare brief descriptions of those that
they could significantly affect the nature, opportunity or scope of the procedures
of the audits that need to be carried out.
The factors to be considered include the degree of utilization of the processing center.
data in applications of important accounting controls, the basic structure of the
accounting controls of the entity, the flow of transactions, the supporting documents
from the same, the existence of other audits and the information relating to other points of
control.
COMPLIANCE TESTS
The purpose of compliance testing is to gather sufficient evidence to conclude whether the
control systems established by management will prevent or detect and correct
potential errors that could have a significant impact on the financial statements.
This conclusion allows for trust in control as a source of general auditing security and
reduce the scope of substantive tests.
These tests may involve the examination of transaction documentation to look for the
presence or absence of specific attributes (defective controls)
The final evaluation of the selected control procedures will take place after carrying out
I finish the compliance tests of said controls.
The evaluation will be carried out by determining whether the control procedures are functioning.
effectively as they were designed, throughout the entire period.
At the end of the internal control evaluation, the auditor as part of their work must
provide suggestions to improve the existing internal control structure.
These are matters that attract the auditor's attention and that in their opinion should be communicated to the
client, as they represent significant deficiencies in the design or operation of the structure
of internal control, which may negatively affect the organization's ability to
register, process, summarize and report uniform financial information with the statements of
the management in the financial statements.
The preliminary assessment of internal control often influences the identification of the main
visible control deficiencies.
Also during the course of their work, the auditor must be aware of the issues.
related to internal control that may be of interest to the client (situations to
to inform
The auditor's judgment regarding situations and reporting varies in each job and this
influenced by nature and the extent of audit procedures and other factors,
such as the size of the entity, its complexity, and the nature and diversification of its
activities.
This communication should be made with high-level authority and responsibility individuals.
such as the Board of Directors, the owner of the company, or with those who have
hired the auditor.
As part of their work, the auditor must also provide suggestions that allow for
improve the existing internal control structure.
The auditor may identify matters that, in their opinion, are not strictly situations to report.
or they are not very important and you will have to decide whether to communicate these matters or not
benefits of management.
Failures in the execution of functions that are part of the internal control structure, such as
as timely preparation or review of reconciliations.
Other deficiencies:
Failures in the monitoring and correction of previously reported internal control deficiencies.
Lack of objectivity of those responsible in the way of accounting and information decisions
financial.
In connection with our examination of the financial statements of Blam Eléctrica S.A.
de CTV. Por el año terminado el 31 de Diciembre de 1997, hemos evaluado la estructura del
internal control of the company, only up to the extent we consider necessary to
to have a basis on which to determine the nature, extent, and timing of the tests
of auditing. Applying in our examination of the company's financial statements. Our
The evaluation of the internal control structure did not include a detailed study and assessment.
of none of its elements and was not executed with the purpose of developing
detailed recommendations or evaluate the efficiency with which the internal control structure
the company allows to prevent or detect all errors or irregularities that may occur
occur. The matters discussed here were considered during our examination and do not modify
our opinion dated March 29, 1998 on said financial statements. The report
adjunto también incluye comentarios y sugerencias con respecto a otros asuntos financieros y
administrative, which we will notice during the course of our examination of the states
financial.
This report is for the exclusive use of the company management and should not be used
for no other purpose.
We would like to express our gratitude for the courtesy and cooperation extended to our
representatives during the course of their work. We would like to discuss these recommendations
in greater detail, if necessary, and likewise, provide the necessary assistance for its
implementation.
Very sincerely
Auditors, S.A. de CV
CONCLUSIONS
According to the study conducted, it is very important that a study and evaluation is carried out.
of internal control before the audit program is prepared or planned, this with the
Purpose of acquiring a general knowledge of the structure of internal control.
If a company has good internal control in the areas of its accounting and is
carrying out effectively we can conclude that one can have confidence in the control
internal of the company, but this must be verified by the auditor reviewing that the policies and
the procedures have been applied uniformly.
It is also necessary for management to have a positive attitude towards internal controls.
checking that the policies and procedures are being properly implemented
entity in order to see if it operates efficiently or if policies or the
existing procedures.
BIBLIOGRAPHY
Seventeenth Edition
Volume I
Eleventh Edition
SELF-EVALUATION
13 - What should be taken into account for the implementation of Internal Control or a System
Accountant
17. - Procedure for the Preliminary Review of the Electronic Data Procedure
19. - What does the Final Evaluation of Internal Control consist of?
20. - What should the final report of the Internal Control contain?