0% found this document useful (0 votes)
16 views51 pages

Understanding Internal Control Systems

Internal control is a process implemented by governance and management to ensure the reliability of financial reporting, operational efficiency, and compliance with laws. It includes a control environment, risk assessment, information systems, control activities, and monitoring of controls. Effective internal control is essential for achieving organizational objectives and mitigating risks associated with financial reporting.

Uploaded by

jairahsanchez00
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
16 views51 pages

Understanding Internal Control Systems

Internal control is a process implemented by governance and management to ensure the reliability of financial reporting, operational efficiency, and compliance with laws. It includes a control environment, risk assessment, information systems, control activities, and monitoring of controls. Effective internal control is essential for achieving organizational objectives and mitigating risks associated with financial reporting.

Uploaded by

jairahsanchez00
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

INTERNAL CONTROL

Start Slide
INTERNAL
CONTROL
Internal Control is the process designed and effected by
those charged with governance, management, and
other personnel to provide reasonable assurance about
the achievement of the entity’s objectives concerning
reliability of financial reporting, effectiveness and
efficiency of operations, and compliance with applicable
laws and regulations. Internal control is designed and
implemented to address identified business risks that
threaten the achievement of any of these objectives.

The objectives fall into three categories:


·Reliability of the entity’s financial reporting
·Effectiveness and efficiency of operations
Compliance with applicable laws and regulations
INTERNAL CONTROL
SYSTEM
The set of policies and procedures, activities, and
practices (internal controls) adopted by the management
to assist in achieving management’s objective of ensuring
the orderly and efficient conduct of its operations, as far
as practicable, including adherence to management
policies, the safeguarding of assets, the prevention and
detection of fraud and error, the accuracy and
completeness of accounting records, and the timely
preparation of reliable financial information.
ELEMENTS OF 01 THE CONTROL ENVIRONMENT
INTERNAL
CONTROL THE ENTITY’S RISK ASSESSMENT
02
PROCESS

03 THE INFORMATION SYSTEM,


INCLUDING THE RELATED
BUSINESS PROCESSES, RELEVANT
TO FINANCIAL REPORTING, AND
COMMUNICATION

04 CONTROL ACTIVITIES

05 MONITORING OF CONTROLS
THE CONTROL ENVIRONMENT
It is the overall attitude, awareness, and actions of directors and management
regarding the internal control system and its importance in the entity. The control
environment affects the effectiveness of the specific control procedures.

A strong control environment, for example, one with tight budgetary controls and an
effective internal audit function, can significantly complement specific control
procedures. However, a strong environment does not, by itself, ensure the
effectiveness of the internal control system.

Factors reflected in the control environment include;


The function of the board of directors and its committees;
Management’s philosophy and operating style;
The entity’s organizational structure and methods of assigning authority and
responsibility; and
Management’s control system, including the internal audit function, personnel
policies and procedures, and segregation of duties.
Factors to Consider in the Control Environment
1. Communication and enforcement of integrity and ethical values
Integrity and ethical values affect the design, administration, and monitoring of
other components of internal control. An entity’s ethical and behavioral
standards and the manner in which it communicates and reinforces them
determine the entity’s integrity and ethical behavior.
.Integrity and Ethical Values include management’s actions to remove or reduce
incentives and temptations that might prompt personnel to engage in dishonest,
illegal, or unethical acts. They also include the communication of entity values
and behavioral standards to personnel through policy statements, a code of
conduct, and management’s example of appropriate behavior.

2. Commitment to Competence
Competence is the knowledge and skills necessary to accomplish task that define
an employee’s job. Commitment to competence means that management
considers the competence levels for particular jobs in determining the skills and
knowledge required of each employee and that it hires employees competent to
perform the tasks.
Factors to Consider in the Control Environment
3. Participation by Those Charged with Governance
An entity’s control consciousness is influenced significantly by those charged
with governance. Attributes of those charged with governance include
independence from management, their experience and stature, the extent
of their involvement and scrutiny of activities, the appropriateness of their
actions, the information they receive, the degree to which difficult questions
are raised and pursued with management, and their interaction with internal
and external auditors.

The importance of responsibilities of those charged with governance is


recognized in codes of practice and other regulations or guidance produced for
the benefit of those charged with governance. Other duties of those charged
with governance include oversight of the design and effective operation of
whistleblower procedures and the process for reviewing the effectiveness of the
entity’s internal control.
Factors to Consider in the Control Environment
4. Management’s Philosophy and Operation Style
This refers to management’s attitude towards
business risk
(financial reporting,
meeting budget, profit, and other established goals

Management’s approach to taking and monitoring business risks, its


conservative or aggressive selection from alternative accounting principles, its
conscientiousness and conservatism in developing accounting estimates, and its
attitude toward information processing and the accounting function and
personnel are factors that affect the control environment.

5. Organizational Structure
The responsibilities and authorities of the various personnel within the
organization should be established in such a manner as to:
(1) assist the entity in meeting its goals and objectives and
(2) ensure that transactions are processed, recorded, summarized, and reported
in an accurate and timely manner.
Factors to Consider in the Control Environment
6. Assignment of Authority and Responsibility
Personnel within an organization need to have a clear understanding of their
responsibilities and the rules and regulations that govern their actions.
Management may develop job descriptions, computer system documentation. It
may also establish policies regarding acceptable business practice, conflicts of
interest, and code of conduct.

7. Human Resource Policies and Procedures


The most important element in an internal accounting control system is the
people who perform and execute the established policies and procedures.
Personnel policies should be adopted by the client to reasonably ensure that
only capable and honest persons are hired and retained.

Policies with respect to employee selection, training, and supervision should be


adopted and implemented by the client. The selection of competent and honest
personnel does not automatically assure that errors or irregularities will not
occur. However, adequate personnel policies, coupled with the design concepts
suggested earlier in this section, enhance the likelihood that the client’s policies
and procedures will be followed.
THE ENTITY’S RISK ASSESSMENT PROCESS
Risk assessment involves the identification, analysis, and management of risks that
affect the preparation of financial statements.
An entity’s risk assessment process identifies and responds to business risks that could
impact financial reporting.
It focuses on the possibility of transactions not being recorded or identified, and the
evaluation of significant estimates in the financial statements.
Management determines how to ensure financial statements are fairly presented in
accordance with applicable reporting frameworks.
Risks related to reliable financial reporting often arise from specific events or
transactions within the entity, which can be internal or external.
Risk assessment process includes:
Identifying risks relevant to financial reporting.
Estimating the significance of each risk.
Assessing the likelihood of occurrence.
Deciding on actions or controls to manage or mitigate the risks.
Examples of focus areas include:
The possibility of unrecorded transactions
The accuracy and reasonableness of accounting estimates
THE ENTITY’S RISK ASSESSMENT PROCESS
Management may initiate plans, programs, or actions to address specific risks or it may
decide to accept a risk because of cost or other considerations. Risk can arise or
change due to circumstances such as the following:

Changes in the operating environment. Changes in the regulatory or


operating environment can result in changes in competitive pressures and
significantly different risks.
New personnel. New personnel may have a different focus on or
understanding of internal controls.
New or revamped information systems. Significant and rapid changes in
information systems can change the risks relating to internal control
Rapid growth. Significant and rapid expansion of operations can strain
controls and increase the risk of breakdown in controls.
New business models, products, or activities. Entering into business
areas or transactions with which an entity has little experience may
introduce new risks associated with internal control.
THE ENTITY’S RISK ASSESSMENT PROCESS
Corporate restructuring. Restructurings may be accompanied by staff
reduction and changes in supervision and segregation of duties that may
change the risk associated with internal control.
Expanded foreign operations. The expansions or acquisition of foreign
operations carries new and often unique risks that may affect internal, for
example, addiction or changed risks from foreign currency transactions.
New accounting pronouncement. Adoption of new accounting principles or
changing accounting principles may affect risks in preparing financial
statements.

Considerations Specific to Smaller Entities


Many small entities are carried out entirely by the engagement partner
(who may be a sole practitioner). In such situations, it is the engagement partner
who, having personally conducted the planning of the audit, would be responsible
for considering the susceptibility of the entity's financial statements to material
misstatement due to fraud and error.
Information Systems, including the Business
Process, Relevant to Financial Reporting and
Communication
An information system consists of infrastructure (physical and hardware components),
software, people, procedures, and data. Infrastructure and software will be absent, or
have less significance, in systems that are exclusively or primarily manual. Many
information systems make extensive use of IT.

INFORMATION SYSTEMS
The information system relevant to financial reporting objectives, which includes the
accounting system, consists of the procedures and records designed and established to:

Initiate, record, process, and report entity transactions (as well as events and
conditions) and maintain accountability for the related assets, liabilities, and equity;
Resolve incorrect processing of transactions, for example, automated suspense files
and procedures followed to clear suspense items out on a timely basis;
Process and account for system overrides or bypasses to controls;
Transfer information from transaction processing systems to the general ledger;
INFORMATION SYSTEMS, INCLUDING THE
BUSINESS PROCESS, RELEVANT TO FINANCIAL
REPORTING AND COMMUNICATION
INFORMATION SYSTEMS
Capture information relevant to financial reporting for events and conditions other
than transactions, such as the depreciation and amortization of assets and changes
in the recoverability of accounts receivable; and
Ensure information required to be disclosed by the applicable financial reporting
framework is accumulated, recorded, processed, summarized, and appropriately
reported in the financial statements.
INFORMATION SYSTEMS, INCLUDING THE
BUSINESS PROCESS, RELEVANT TO FINANCIAL
REPORTING AND COMMUNICATION
Journal Entries
An entity's information system typically includes the use of standard journal entries that
are required on a recurring basis to record transactions. Examples might be journal
entries to record sales, purchases, and cash disbursements in the general ledger, or to
record accounting estimates that are periodically made by management, such as
changes in the estimate of uncollectible accounts receivable.

An entity's financial reporting process also includes the use of non-standard journal
entries to record non-recurring, unusual transactions or adjustments. Examples of such
entries include consolidating adjustments and entries for a business combination or
disposal or nonrecurring estimates such as the impairment of an asset. In manual
general ledger systems, non-standard journal entries may be identified through
inspection of ledgers, journals, and supporting documentation. When automated
procedures are used to maintain the general ledger and prepare financial statements,
such entries may exist only in electronic form and may therefore be more easily
identified using computer-assisted audit techniques (CAATs).
Information Systems, including the Business
Process, Relevant to Financial Reporting and
Communication
RELATED BUSINESS PROCESS
An entity's business processes are the activities designed to:
Develop, purchase, produce, sell, and distribute an entity's products and services;
Ensure compliance with laws and regulations; and
Record information, including accounting and financial reporting information.
Business processes generate the transactions that are recorded, processed, and
reported by the information system.
Understanding these processes helps auditors understand how the information
system supports financial reporting.
An information system includes methods and records that:
- Identify and record all valid transactions
- Describe transactions accurately and promptly for proper financial classification
- Measure transactions to record their correct monetary value
- Determine the proper accounting period for each transaction
- Present transactions and disclosures properly in the financial statements
Information Systems, including the Business
Process, Relevant to Financial Reporting and
Communication
COMMUNICATION
Communication ensures personnel understand their roles and responsibilities in
internal control over financial reporting.
Employees should know how their tasks relate to others and how to report
exceptions or issues.
Open communication channels ensure that errors or irregularities are reported and
addressed.
Communication may take the form of manuals, memoranda, electronic messages,
oral instructions, or management actions.

Application to Small Entities


Information systems and processes may be less formal but still essential.
Active management involvement often substitutes for formal procedures.
Communication is typically simpler and more direct due to a smaller size and
fewer organizational layers.
CONTROL ACTIVITIES
Control activities are the policies and procedures that help ensure that management
directives are carried out, for instance, that necessary actions are taken to address risks
that threaten the achievement of the entity's objectives. Control activities, whether
within IT or manual systems, have various objectives and are applied at various
organizational and functional levels.
The major categories of control procedures are:

A. Performance Review

B. Information Processing Controls


1) Proper authorization of transactions and activities
2) Segregation of duties
3) Adequate documents and records
4) Safeguards over access to assets; and
5) Independent checks on performance

C. Physical controls
CONTROL ACTIVITIES
A. Performance Review
Management uses accounting and operational data to assess performance and take
corrective actions.

Examples of performance reviews include:


Comparing actual results with budgets, forecasts, prior periods, or competitors’
data.
Tracking major initiatives (e.g., cost-reduction or efficiency programs).
Investigating performance indicators such as variances or return rates.
Reviewing functional or managerial performance against set standards or
benchmarks.

Purpose:
Helps improve decision-making and ensures the reliability of data.
Becomes an internal control when unexpected results are investigated and
followed up for accuracy and integrity in financial reporting.
CONTROL ACTIVITIES
B. Information Processing Controls
Information processing controls are policies and procedures designed to require
authorization of transactions and to ensure the accuracy and completeness of transaction
processing. Control activities may be classified according to the scope of the system they
affect.

Types of controls:
General controls
– prevent or detect errors or irregularities for all accounting systems
– apply to all systems and processes (e.g., IT security, software
maintenance, data backups).
Application controls
– apply to specific transactions (e.g., payroll, sales).

Objectives of Internal Controls in the Accounting System:


Ensure that transactions are authorized by management.
Record all transactions promptly, accurately, and in the correct period.
Allow access to assets and records only by authorized personnel.
Compare recorded assets with actual assets regularly and resolve discrepancies.
CONTROL ACTIVITIES
Control activities related to the processing of transactions may be grouped as follows:
1. Proper authorization of transactions and activities
Transactions must be approved according to management’s policies before execution.
Documentation (e.g., purchase orders, invoices) serves as evidence of authorization.
2. Segregation of Duties
No single employee should have control over all aspects of a transaction.
Prevents errors and fraud by separating recordkeeping, custody, and
authorization duties.
3. Adequate Documents and Records
Ensures all valid transactions are properly recorded and traceable.
4. Access to Assets
Protect assets through physical safeguards (e.g., locked storerooms, safes).
Limit access only to authorized personnel.
Maintain control over documents authorizing asset movement.
5. Independent Checks on Performance
Conduct periodic comparisons of actual assets and recorded balances (e.g., inventory
counts, bank reconciliations).
Detect errors, omissions, or misappropriation of assets.
CONTROL ACTIVITIES
C. Physical Controls
Focuses on the physical protection of assets and records. Physical controls may
include:
Secured facilities and restricted access.
Authorization controls for access to computer programs and data files.
Periodic counts and reconciliations of cash, securities, and inventory.

The importance of physical controls depends on how vulnerable


assets are to misappropriation.
Small and large entities share similar control concepts, but small ones
apply them less formally.
Management’s direct involvement (e.g., approving sales, purchases, or
credit use) can substitute for detailed controls.
Segregation of duties may be limited, but active oversight by
management can achieve similar control objectives.
MONITORING OF CONTROLS
Monitoring is the process of evaluating the effectiveness of internal controls over
time. It ensures that controls are properly designed, operating as intended, and
updated when conditions change. Management and internal auditors play key
roles by reviewing controls, identifying weaknesses, and recommending
improvements.
Monitoring through External Communications
External parties can provide valuable information for monitoring internal control
effectiveness.
Customers help validate sales or billing data by paying invoices or raising disputes.
Regulators and bank examiners may communicate findings that reveal control
weaknesses or areas for improvement.
External auditors’ feedback on internal controls can also guide management in
strengthening control systems.

Application to Small Entities


Ongoing monitoring is usually informal and integrated into daily management
activities.
As management is closely involved in operations, they can quickly detect and
correct significant variances or errors in financial information.
INTERNAL CONTROL

CONTROL ACTIVITIES
CASH

Prenumbered use of official receipts Pre-numbered use of vouchers and checks


Daily deposit of collections Bonding (through an Approval of cash disbursements
insurance company) of cash custodians Limited authorization to sign checks
Authorization for the opening of bank accounts No signing of blank checks
Comparison of deposit slips with cash book Mutilation of voided checks
Separation of duties between cashier personnel and Control over signature machines
accounting personnel . Control over interbank transfers
Use of cash registers Checks not payable to cash
Preparation of daily cash collection reports Physical control of unused checks
Use of cash vaults and locks Cancellation of paid vouchers to prevent double
Access to cash vaults only given to authorized cash payment
personnel Surprise cash counts
Preparation of monthly bank reconciliations Periodic confirmation of cash in bank balances with
the depository bank
INTERNAL CONTROL

CONTROL ACTIVITIES
INVESTMENTS

Proper authorization of investment purchase Limited access to the safety deposit box
transactions Dual control (presence of two officers for
Use of a safety deposit box for the safekeeping access to the investment)
of investment documents Investment securities in the name of the
Bonding (through an insurance company) of the company ·
investment custodian Periodic internal audit
Investment custodian function is separate from Periodic appraisal of the investments
investment accounting Authorization for the disposal of the
investments
INTERNAL CONTROL

CONTROL ACTIVITIES
SALES AND ACCOUNTS RECEIVABLE

Credit approval before making deliveries of Authorization for the disposal of the
products to the customer investment
Use of credit limits for customers ·Use of Sending of billing statements to customers
prenumbered sales order Control over write-off of worthless accounts
Independence or separation between the credit Periodic preparation of A/R ageing schedule
and sales departments Segregation of collection function from A/R
Pre-numbering of shipping documents posting function
Control over returned goods Review of proper pricing charged to
Control over scrap sales customers
Periodic reconciliation of customers' AR Sales cut-off procedures
balances Ensuring the dispatching of accurate
quantities of goods to customers
INTERNAL CONTROL

CONTROL ACTIVITIES
INVENTORIES
Periodic inventory counts Physical safeguards against theft of
Use of perpetual inventory records inventories
Periodic comparison of general ledger (GL) and Authorization over inventory purchases
perpetual inventory records Inspection procedures upon receipt of
Periodic comparison of inventory records inventories (quantity, quality, and
against physical count . specifications)
Investigation of discrepancies in case of Procedures in the dispatch of inventories
inventory short or overage (ensure that inventories actually ordered by
Use of prenumbered receiving reports customers are the amount of inventories to
Separation of inventory custodian from be dispatched or released)
inventory accounting/record-keepina function Procedures on inventory returns
Adequacy of insurance on inventories Requiring inventory requisitions prior to
Physical safeguards on inventory against fire purchase ordering
and other catastrophes ods Control over in-transit goods
INTERNAL CONTROL

CONTROL ACTIVITIES
FIXED ASSETS
Use of detailed property records Adequacy of insurance over fixed assets
Periodic comparison of property records with Fixing of the accountability of fixed asset
physical assets custodians
Periodic counts of fixed assets Review of depreciation computations
Policy on capitalization of expenditures Control over fully-depreciated fixed assets
Physical safeguards over assets (e.g, machines, Review of useful lives
equipment, facilities) Control over disposal of fixed assets
Use of property identification numbers (for Control over scrap sales
specific identification of assets)
INTERNAL CONTROL

CONTROL ACTIVITIES
PAYROLL
Effective hiring procedures Transmittal to the bank of official roster of
Maintenance of personnel data records employees for ATM payroll arrangements
Use of a time clock or through biometric device Periodic head count of all company
Supervisor review of time cards personnel
Review of payroll calculations (gross salaries, Control over the rendering of overtime
withholding tax, SSS premiums, net pay) Access controls to prevent unauthorized use
Procedures in distributing payroll checks of payroll system
Control over unclaimed wages Timely removal of retired employees from
payroll system
Periodic audit of payroll
INTERNAL CONTROL

CONTROL ACTIVITIES
ACCOUNTS PAYABLE
Independence of A/P function from purchasing Investigation of discounts not taken
function Periodic comparison with budgets
Periodic reconciliation of A/P subsidiary records Checking for personal purchases
with the A/P control account Vendor accreditation procedures (the company
Control over purchase returns buys materials only from duly accredited
Review of vendor's invoices vendors)
Matching of purchase order. receiving report, System access to create, edit, or delete
and vendor invoice purchase orders is restricted to authorized
Reconciliation of vendor statements with A/P personnel
detail Ability to create or add, or delete vendor
Review of A/P debit balances records in the vendor master is restricted to
Review of unmatched receiving reports authorized personnel
Review of A/P postings Periodic audit of A/P balances
Bidding procedures for significant purchases Comparison of purchase amounts to budgets
INTERNAL CONTROL

LIMITATIONS OF INTERNAL CONTROL


A good internal control system can only provide reasonable assurance that business objectives will be
achieved. There is no such thing as a perfect internal control because of the inherent limitations.

POSSIBILITY OF COLLUSION

MANAGEMENT OVERRIDE

HUMAN FACTORS
FRAUD AND ERROR
Fraud - intentional act involving use of deception that results in a material misstatement of the financial statements

Error - unintentional mistakes in financial statements often due to oversight, carelessness, or lack of knowledge

Two types of misstatements that are relevant to auditors' consideration of fraud:

(a) misstatements arising from misappropriation of assets


(b) misstatements arising from fraudulent financial reporting
Misstatements arising from
Misappropriation of Assets
Asset misappropriation occurs when a perpetrator steals or misuses an
organization's assets. Asset misappropriations are the dominant fraud
scheme perpetrated against small businesses, and the perpetrators are
usually employees. Asset misappropriations can be accomplished in
various ways, including embezzling cash receipts, stealing assets, or
causing the company to pay for goods or services that were not received.

Asset misappropriation commonly occurs when employees:

·Gain access to cash and manipulate accounts to cover up cash


thefts.
·Manipulate cash disbursements through fake companies.
·Steal inventory or other assets and manipulate the financial
records to cover up the fraud.
Misstatements arising from Fraudulent
Financial Reporting
The intentional manipulation of reported financial results to misstate
the economic condition of the organization is called fraudulent financial
reporting. The perpetrator of such a fraud generally seeks gain through
the rise in stock price and the commensurate increase in personal
wealth. Sometimes the perpetrator does not seek direct personal gain
but instead uses the fraudulent financial reporting to "help" the
organization avoid bankruptcy or to avoid some other negative financial
outcome.

Three common ways in which fraudulent financial reporting can take


place include:

Manipulation, falsification, or alteration of accounting records or


supporting documents.
Misrepresentation or omission of events, transactions, or other
significant information
Intentional misapplication of accounting principles.
THE FRAUD TRIANGLE
Incentives or Pressure to Commit Fraud
Incentives relating to asset misappropriation include:
Personal factors, such as severe financial considerations
Pressure from family, friends, or the culture to live a more lavish lifestyle
than one's personal earnings allow for
Addictions to gambling or drugs

Incentives relating to fraudulent financial reporting include:


Management compensation schemes
Other financial pressures for either improved earnings or an improved
balance sheet
Debt covenants
Pending retirement or stock option expirations
Personal wealth is tied to either financial results or the survival of the
company
Greed - for example, the backdating of stock options was performed by
individuals who already had millions of pesos of wealth through stock
Opportunities to Commit Fraud
A key finding in fraud research is that fraud occurs when there is an opportunity to
commit it. This opportunity arises from weak or lacking controls or when complex
transactions make detection unlikely. Top management should therefore identify
and address areas where such opportunities for fraud may exist.

Significant related-party transactions


The company's industry position, such as the ability to dictate terms or conditions to
suppliers or customers that might allow individuals to structure fraudulent
transactions
Management's inconsistency involving subjective judgments regarding assets or
accounting estimates
Simple transactions that are made complex through an unusual recording process
Complex or difficult-to-understand transactions, such as financial derivatives or
special-purpose entities
Ineffective monitoring of management by the board, either because the board of
directors is not independent or effective, or because there is a domineering manager
Complex or unstable organizational structure
Weak or nonexistent internal controls
Rationalizing the Fraud
For asset misappropriation, personal rationalizations often revolve around
mistreatment by the company or a sense of entitlement by the individual
perpetrating the fraud.

The following are some common rationalizations for asset misappropriation:

Fraud is justified to save a family member or loved one from


financial crisis.
We will lose everything (family, home, car, and so on) if we don't
take the money.
No help is available from outside.
This is "borrowing", and we intend to pay the stolen money back
at some point.
Something is owed by the company because others are treated
better.
We simply do not care about the consequences of our actions or
of accepted notions of decency and trust; we are for ourselves.
Rationalizing the Fraud

For fraudulent financial reporting, the rationalization can range from "saving
the company" to personal greed, and may include the following:

This is a one-time thing to get us through the current crisis


and survive until things get better.
Everybody cheats on the financial statements a little; we are
just playing the same game.
We will violate all of our debt covenants unless we find a way
to get this debt off the financial statements.
We need a higher stock price to acquire company XYZ, or to
keep our employees through stock options, and so forth.
Risk Factors Contributory to
Misappropriation of Assets
Misappropriation of assets refers to the theft or misuse of a company’s resources,
often committed by employees in small amounts but sometimes by management
who can better conceal it. It can occur in various forms and is often difficult to detect.

Embezzling receipts (for example, misappropriating collections on


accounts receivable or diverting receipts in respect of written off
accounts to personal bank accounts).
Stealing physical assets or intellectual property (for example,
stealing inventory for personal use or for sale, stealing scrap for
resale, or colluding with a competitor by disclosing technological
data in return for payment).
Causing an entity to pay for goods and services not received (for
example, payments to fictitious vendors, kickbacks paid by vendors
to the entity's purchasing agents in return for inflating prices,
payments to fictitious employees).
Using an entity's assets for personal use (for example, using the
entity's assets as collateral for a personal loan or a loan to a related
party).
A. Incentives/Pressures
1. Personal financial obligations may create pressure on management or
employees with access to cash or other assets susceptible to theft to
misappropriate those assets.

2. Adverse relationships between the entity and employees with access to


cash or other assets susceptible to theft may motivate those employees to
misappropriate those assets. For example, adverse relationships may be
created by the following:

(a) Known or anticipated future employee layoffs.


(b) Recent or anticipated changes to employee compensation or
benefit plans.
(c) Promotions, compensation, or other rewards inconsistent with
expectations.
B. Opportunities
1. Certain characteristics or circumstances may increase the
susceptibility of assets to misappropriation. For example, opportunities
to misappropriate assets increase when the following situations exist:
(a) large amounts of cash on hand or processed
(b) inventory items that are small in size, of high value, or in high
demand
(c) fixed assets that are small in size, marketable, or lacking observable
identification of ownership

2. Inadequate internal control over assets may increase the susceptibility


of misappropriation of those assets. For example, misappropriation of
assets may occur because of the following:
(a) inadequate segregation of duties or independent checks
(b) inadequate oversight of senior management expenditures, such
as travel and other reimbursements
(c) Inadequate management oversight of employees responsible for
assets
B. Opportunities

(d) Inadequate job applicant screening of employees with access to


assets
(e) Inadequate record keeping with respect to assets
(f) Inadequate system of authorization and approval of transactions (for
example, in purchasing)
(g) Inadequate physical safeguards over cash, investments, inventory, or
fixed assets
(h) Lack of complete and timely reconciliations of assets
(i) Lack of timely and appropriate documentation of transactions, for
example, credits for merchandise returns
(j) Lack of mandatory vacations for employees performing key control
functions
(k) Inadequate management understanding of information technology,
which enables information technology employees to perpetrate a
misappropriation
(l) Inadequate access controls over automated records, including
controls over and review of computer systems event logs
C. Attitudes/ Rationalizations

1. Disregard for the need for monitoring or reducing risks related to


misappropriation of assets.

2. Disregard for internal control over the misappropriation of assets by


overriding existing controls or by failing to correct known
internal control deficiencies.

3. Behavior indicating displeasure or dissatisfaction with the entity


or its treatment of the employee.

4. Changes in behavior or lifestyle that may indicate assets have


been misappropriated.

5. Tolerance of petty theft


Risk Factors Contributory to Fraudulent
Financial Reporting

Fraudulent financial reporting may be accomplished by the following:

1. Manipulation, falsification (including forgery), or alteration of


accounting records or supporting documentation from which
the financial statements are prepared.

2. Misrepresentation in, or intentional omission from, the financial


statements of events, transactions, or other significant
information.

3. Intentional misapplication of accounting principles relating to


amounts, classification, manner of presentation, or disclosure.
A. Incentive/Pressure
Incentive or pressure to commit fraudulent financial reporting may
exist when management is under pressure, from sources outside or
inside the entity, to achieve an expected (and perhaps unrealistic)
earnings target or financial outcome particularly since the
consequences to management for failing to meet financial goals can be
significant.

B. Opportunities
A perceived opportunity for fraud arises when someone believes they
can bypass or override internal controls, often due to their position of
authority or awareness of control weaknesses. Fraudulent financial
reporting frequently involves management override of controls, using
various techniques to manipulate or conceal information despite
controls seeming effective.
Fraud can be committed by management overriding controls using such
techniques as:

Recording fictitious journal entries, particularly close to the end of an


accounting period, to manipulate operating results or achieve other
objectives.
Inappropriately adjusting assumptions and changing judgments used to
estimate account balances.
Omitting, advancing, or delaying recognition in the financial statements
of events and transactions that have occurred during the reporting
period.
Concealing, or not disclosing, facts that could affect the amounts
recorded in the financial statements.
Engaging in complex transactions that are structured to misrepresent
the financial position or financial performance of the entity.
Altering records and terms related to significant and unusual
transactions.
C. Rationalizations
Individuals may be able to rationalize committing a fraudulent act.
Some individuals possess an attitude, character or set of ethical
values that allow them knowingly and intentionally to commit a
dishonest act. However, even otherwise honest individuals can
commit fraud in an environment that imposes sufficient pressure
on them.
Material Weakness in Internal Control

A material weakness is a deficiency (or group of deficiencies) in


internal control over financial reporting.

It means there is a reasonable possibility that a material


misstatement may not be prevented or detected on time.

Such weaknesses indicate that internal control is not effective.

A material weakness does not necessarily mean a misstatement has


occurred—only that one could reasonably occur due to the
deficiency.
Responsibility for the Prevention and Detection of Fraud

The primary responsibility for preventing and detecting fraud lies


with management and those charged with governance.

Management should emphasize fraud prevention (reducing


opportunities) and fraud deterrence (discouraging attempts through
risk of detection and punishment).

A strong culture of honesty and ethical behavior is essential and


should be supported by active oversight.

Governance bodies must be alert to risks of management override


or manipulation of financial reporting to influence perceptions of
performance.
Responsibility for the Prevention and Detection of Fraud

The primary responsibility for preventing and detecting fraud lies


with management and those charged with governance.

Management should emphasize fraud prevention (reducing


opportunities) and fraud deterrence (discouraging attempts through
risk of detection and punishment).

A strong culture of honesty and ethical behavior is essential and


should be supported by active oversight.

Governance bodies must be alert to risks of management override


or manipulation of financial reporting to influence perceptions of
performance.

You might also like