UST – AMV COA
FIRST TERM, ACADEMIC YEAR 2025-2026
AUDITING AND ASSURANCE PRINCIPLES
Prof. F. H. Villamin
========================================================================
MODULE 6
CONSIDERATION OF INTERNAL CONTROL
1. The auditor uses the understanding of internal control to identify the types of potential misstatements,
consider factors that affect the risks of material misstatement and design the nature, timing and extent
of further audit procedures.
2. The COSO Report, issued by the Committee on Sponsoring Organizations of the Treadway
Commission entitled “Internal Control – Integrated Framework”, is the most comprehensive document
issued on internal control to date. The report provides a framework against which entities can assess
their internal controls and establish a common definition of internal control that serves the needs of a
variety of groups.
Internal control is “a process, effected by those charged with governance, management, and other
personnel, designed to provide reasonable assurance regarding the achievement of objectives in
the following categories:
a. Effectiveness and efficiency of operations
b. Reliability of financial reporting
c. Compliance with applicable laws and regulations
It follows that internal control is designed and implemented to address identified business risks that
threaten the achievement of the above mentioned objectives.
3. Four key concepts embodied in the COSO Report’s definition of internal control
a. Internal control is a process. It is a means to an end, not an end in itself. It consists of a series of
actions that are pervasive and integrated with, not added onto, an entity’s infrastructure.
b. Internal control is affected by people. It is not achieved merely by having policy manuals and forms,
but by the actions and attitudes of people at every level of an organization including the board of
directors and management.
c. Internal controls can be expected to provide only reasonable assurance, but not absolute
assurance that entity’s objectives will be accomplished, since the benefits expected from some
controls may not be worth the cost of implementation and because limitations are inherent in
internal control systems.
d. Internal control is geared to the achievement of objectives in the overlapping categories of financial
reporting, compliance and operations.
Page 2 of 6
4. There is a direct relationship between an entity’s objectives and the controls it implements to provide
reasonable assurance about their achievement.
5. Management’s responsibilities in relation to internal control
Management has the responsibility for maintaining controls within an entity. It is also a requirement in
SEC Code of Corporate Governance for entities to establish sound system of risk oversight and
management and internal control.
6. Auditor’s responsibilities in relation to internal control
Auditors do not have statutory legal obligations to report internal control within the entity. The main
guidance on auditor’s requirements in relation to internal control is provided by PSA 315 which states
that the auditor must obtain an understanding of internal control relevant to the audit. This
understanding also has a significant impact on the audit strategy. The requirement is for the auditor to
focus on obtaining an understanding to facilitate the performance of the audit rather than to comment
on the controls as part of the audit.
7. The auditor’s risk assessment process relate to controls pertaining to the entity’s objective of preparing
financial statements for external purposes and the management risk that may give rise to a material
misstatement in those financial statements. It is a matter of professional judgment, subject to the
requirements of PSA, whether a control, individually or in combination with others, is relevant to the
auditor’s considerations in assessing the risks of material misstatement and designing and performing
further procedures in response to assessed risks. In exercising that judgment, the auditor considers
the applicable component and factors such as the following:
a. The auditor’s judgment about materiality
b. The size of the entity
c. The nature of the entity’s business, including its organization and ownership characteristics
d. The diversity and complexity of the entity’s operations
e. Applicable legal and regulatory requirements
f. The nature and complexity of the systems that are part of the entity’s internal control, including the
use of service organizations.
8. Areas of Internal Control
a. Administrative Control
This includes, but is not limited to, plan of organization and the procedures and records that are
concerned with the decision processes leading to management’s authorization of transactions.
Administrative controls promote operational efficiency and adherence to managerial policies.
b. Accounting Control
This comprises the plan of organization and the procedures and records that are concerned with
the safeguarding of assets and the reliability of financial records. It involves systems of
authorization and approval controls over assets, internal audit and all other financial matters.
9. The COSO Report also identifies five interrelated components of internal control that should be
integrated within the management process:
a. Control environment – Management’s and the board of director’s actions, policies and procedures
that reflect the overall attitude, awareness, and actions toward internal control. Sub elements:
1. Integrity and ethical values
2. Commitment and competence
3. Board of directors or audit committee
4. Management’s philosophy and operating style
5. Organizations structure
6. Assignment of authority and responsibility
7. Human resource policies and practices
b. Risk assessment – Management’s purpose in performing risk assessment is to identify the risks
that bear on their operations, financial reporting, and compliance objectives and to take the action
necessary to manage them. The entity’s business risk and their financial consequences
Page 3 of 6
Examples of risks (internal and external)
1. Changes in operating environment
2. New personnel
3. New information systems
4. New accounting pronouncements
5. New business models
6. Rapid growth
7. New technology
8. New products or services
9. Corporate restructurings
10. Expanded foreign operations
Procedures include:
1. Identify the essential resources of the business and determine which are at the most risk.
2. Identify possible liabilities that may arise.
3. Review the risks that have arisen in the past.
4. Consider any additional risks imposed by new objectives or new external factors.
5. Seek to anticipate change by considering problems and opportunities on a continuing basis.
c. Control activities – (also called control procedures) are policies and procedures in addition to
the control environment and the information system that management establishes to provide
reasonable assurance that their objectives are achieved. The independent auditor’s objective is to
understand an entity’s control activities sufficiently to plan the audit.
Control activities relevant to a financial statement audit may be categorized as follows:
1. Information processing controls
a. General controls
b. Application controls
1. Segregation of duties
2. Physical controls
3. Performance reviews
Information processing controls – cover risks related to authorization, completeness and
accuracy of transactions.
a. General controls are those controls that apply to computer information systems as a whole
and include controls related to such matters as data center organization, hardware and
systems software acquisition and maintenance, and backup and recovery procedures.
1. Organization controls.
2. Systems development and maintenance controls.
3. Access controls.
4. Data and procedural controls.
b. Application controls are those controls designed to provide reasonable assurance that the
recording, processing and reporting of computer information system are properly
performed for specific applications.
1. Input controls
2. Processing controls
3. Output controls
Segregation of duties – ensures that individuals do not perform incompatible duties.
To achieve optimum segregation of responsibilities, an entity’s management, custodial, accounting
and monitoring functions should be performed by different employees. That is, the following
responsibilities would be separated:
1. Transaction authorization ( a management function)
2. Transaction execution (a custodial function)
3. Transaction recording (an accounting function)
Page 4 of 6
4. Independent checks on (a monitoring function)
performance
Physical controls – limit access to assets and important records. These controls may either be
direct or indirect. Direct controls include initiating measures for the safekeeping of assets,
documents and records and restricting access to storage areas to authorized personnel only.
Indirect controls apply to the preparation or processing of documents that authorize the use or
disposition of assets.
Performance reviews – involve managers’ participation in the supervision of operations. These
are independent checks on performance by a third party not directly involved in the activity.
Sometimes called “internal verification”, these reviews include reviews of actual performance vs
budgets, surprise checks of procedures, periodic comparisons of accounting records and physical
assets and a review of functional or activity performance.
d. Information system – consists of procedures and records to initiate, record, process and report
entity transactions and maintain accountability for the related assets and liabilities. An effective
information system should
1. Identify and record only valid transactions of the entity that occurred in the current accounting
period. (Existence or occurrence assertion)
2. Identify and record all valid transactions of the entity that occurred in the current accounting
period. (Completeness assertion)
3. Ensure that recorded assets and liabilities are the result of transactions that produced entity
rights to, or obligations for, those items. (Rights and obligations assertion)
4. Measure the value of transactions that permit their proper monetary value in the financial
statements. (Valuation and allocation assertion)
5. Capture sufficient detail of all transactions to permit their proper presentation in the financial
statements including proper classification and required disclosures. (Presentation and
disclosure).
The central activity of most business typically involves a series of related functions, all of which
must be captured within the accounting system. The table below categorizes these functions into
four groups of transactions called transaction cycles, the means by which transactions are
processed by an accounting system:
(1) Financing
(2) expenditure/disbursement
(3) conversion
(4) revenue/receipt
An effective information system should provide a complete “audit trail” or “transaction trail”. An
audit trail is a chain of evidence from initiating a transaction to its recording in the general ledger
and financial statements provided by coding, cross-reference and documentation connecting
account balances and other summary results with original transaction data.
e. Monitoring – to assure quality, internal controls should be monitored through continuing or periodic
evaluations, or both. Discrepancies should be resolved by management at least one level above
those responsible.
1. The reliability of an accounting system can be evaluated by comparing recorded assets with
actual assets continually or periodically.
2. To maximize effectiveness, monitoring should take advantage of the element of surprise, be
performed by personnel independent of the functions tested, and result in appropriate
corrective action.
Page 5 of 6
Considering of Internal Control in an audit of Financial
Statements
1. In order to comply with the second standard of field work an auditor must acquire “a sufficient
understanding of internal control to plan the audit and to define the nature, timing, and extent of
tests to be performed.”
2. There are three steps to the auditor’s consideration of internal control:
a. Obtain an understanding of how management has designed policies and procedures for the
control environment, risk assessment, the control activities, information and communication,
and monitoring.
An understanding of internal control allows an auditor to identify the types of material
misstatements that could occur in the financial statements, to consider factors that affect the
risk of material misstatements, and to design substantive tests of account balances and
transaction classes that are processed by the internal controls.
Obtaining an understanding of internal control consists of:
1. Performing a preliminary review which provides an opinion on whether reliance on the
control is likely to be cost effective.
2. Documenting the system’s internal controls and identifying transaction cycles.
In practice today, auditors use one or more of the three means to document an entity’s internal
controls:
a. Narrative memorandum is a written description of a particular phase or phases of an
accounting system.
b. Flowchart or Data flow diagram consists of interrelated symbols that diagram the
flow of transactions and events through a system. Flowcharts capture the complexity
of the systems, allowing the auditors to focus sharply on key controls within the system.
c. Internal control questionnaire consists of a series of questions about accounting and
control policies that the auditor considers necessary to prevent material misstatements
in the financial statements. The questions are usually phrased in such a way that a
“yes” indicates a favorable condition.
3. Performing a transaction walk-through, and
4. Identifying controls that reduce to a relatively low level the risk of material misstatements.
b. Assess control risk for relevant assertions related to each significant account balance or
transaction class. To determine an assessed level of control risk the auditor:
1. Considers the errors or frauds that could occur and that could result in misstatements in
the financial statements.
2. Identifies relevant control activities designed to prevent or detect the errors or frauds, and
3. Performs tests of controls on the control activities that may prevent or detect the errors or
frauds.
In a financial statement audit, tests of controls consist of audit procedures directed toward
testing the effectiveness of the design or the operation of an internal control policy or procedure.
Tests of controls directed toward the design of a policy or procedure address one issue:
Whether or not the policy or procedure is suitably designed to prevent or detect material
misstatements in specific financial statement assertions.
Page 6 of 6
Tests of controls over the design of a policy or procedure include inquiring of client personnel,
inspecting documents and reports and observing employees performing the policy or
procedures.
c. Determine the nature, timing, and extent of substantive tests necessary to restrict
detection risk to an acceptable level. Control risk and detection risk are inversely related – as
assessed level of control risk increases, the acceptable level of detection risk decreases.
1. In planning substantive tests an auditor would perform more persuasive tests, perform tests
at the balance sheet date rather than at interim dates, and would test more extensively.
2. As assessed level of control decreases the acceptable level of detection risk increases. In
planning substantive tests an auditor would perform less persuasive tests, perform tests at
the interim dates rather than at the balance sheet date, and would test less extensively.
Documentation Requirements for Consideration of Internal Control
Control Risk at High Level Control Risk at Less than High
Level
1. Understanding of Internal Required Required
Control
2. Conclusion Required Required
3. Basis for the Conclusion Not Required Required
*************