0% found this document useful (0 votes)
10 views26 pages

Internal Controls

The document outlines the evaluation of internal control over financial reporting, emphasizing the identification and explanation of deficiencies, recommendations for improvement, and the auditor's testing of controls. It details the components of internal control, the importance of understanding these controls for accurate financial reporting, and the roles of management, the board of directors, and auditors in maintaining effective internal controls. Additionally, it discusses various methods for documenting and evaluating internal controls, including narrative notes, flowcharts, and questionnaires.

Uploaded by

abdullahm865
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
10 views26 pages

Internal Controls

The document outlines the evaluation of internal control over financial reporting, emphasizing the identification and explanation of deficiencies, recommendations for improvement, and the auditor's testing of controls. It details the components of internal control, the importance of understanding these controls for accurate financial reporting, and the roles of management, the board of directors, and auditors in maintaining effective internal controls. Additionally, it discusses various methods for documenting and evaluating internal controls, including narrative notes, flowcharts, and questionnaires.

Uploaded by

abdullahm865
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Evaluating Internal control over financial reporting

Examiner's comments

Internal control questions typically require internal control deficiencies to be identified{½ marks each}, explained
(½ marks each}, a relevant recommendation to address the control (1 mark}, and, often a test of control the
external auditor would perform to assess whether each of these controls, if implemented, is operating correctly
{1 mark).

Internal control questions may also require a covering letter to management to accompany the list of deficiencies
and recommendations.

Occasionally, as in September 2015, candidates may be asked to identify internal control strengths as
well as deficiencies.

Auditor's work re. internal control over financial reporting

1. Understand the components of internal controls over financial reporting


Narrt0vt! �
2. Document the systems t\owch°'.--1 S

(�H.1e{ho,.v, a.,·,��

3. Test the systems for deficiencies in design and perform TEST OF CONTROLS to find deficiencies in
implementation (operating effectiveness)

4. Report deficiencies to the management.

-A vc
/CS g1v 0 .,,1) les'i su!:is-� o/\
e. $.Lh st av--L<.
5. Decide extent of substantive testing
u., e <>1r I rY\O t

�---------------------------------- ThinkAhead
CACCA

Page 58 of 206
Internal controls: Internal control represents the system or policies and procedures implemented by an
organization.

Internal control over financial reporting: The process designed➔implemented➔ maintained by TCWG to
provide reasonable assurance about the reliability of financial reporting, effectiveness of operations and
compliance with laws and regulations.

Why does an auditor need to understand internal controls?

Internal controls assure management of the accuracy of the financial statements, that the operations of the
entity are conducted efficiently and that the entity has complied with all the laws and regulations which are
applicable to the entity.

The objectives of internal controls relevant to audit include:

1. Avoidance of fraud, errors, wastes and inefficiency


2. Maximum accuracy of all records, data and statements
3. Enables auditors to determine the degree of reliance they can place on the various systems. This will
enable the auditors to assess the correctness, truth and fairness of the financial statements.
4. Informing management about weaknesses detected in internal controls so that corrective action can be
taken.
5. Enabling planning of the audit
6. Understanding the components of internal control: While planning the audit, the auditor understands
the various components of the internal control so as to:
o identify the types of potential misstatements.
o consider the factors that affect the risk of misstatement.
o design effective substantive tests.

Components of internal control over financial reporting

ISA 315 Identifying and Assessing the Risks of Material Misstatement through Understanding the Entity and Its
Environment considers the components of an entity's internal control. It identifies the following components:
1. Control environment
2. Entity's risk assessment process
3. Information system and communication
4. Control activities
5. Monitoring of controls

Page 59 of 206
Understand client's Control The control environment sets the tone of an organisation, influencing the
Environment control consciousness of its people. It includes the attitudes, awareness, and
actions of TCWG concerning the entity's internal control and its importance in
the entity.

The control environment has many elements such as:


a) Communication and enforcement of integrity and ethical values
- essential elements which influence the effectiveness of the
design, administration and monitoring of controls.
b) Commitment to competence - management's consideration of
the competence levels for particular jobs and how those levels
translate into requisite skills and knowledge.
c) Management's philosophy and operating style- management's
approach to taking and managing business risks, and
management's attitudes and actions towards financial
reporting, information processing and accounting functions and
personnel.
d) Organisational structure- the framework within which an
entity's activities for achieving its objectives are planned,
executed, controlled and reviewed.
e) Assignment of authority and responsibility- how authority and
responsibility for operating activities are assigned and how
reporting relationships and authorisation hierarchies are
established.
f) Human resources policies and practices- recruitment,
orientation, training, evaluating, counselling, promoting,
compensating and remedial actions.
g) Participation by TCWG ( their independence from the
management, their experience, appropriateness of actions etc.)

Understand client's Risk Auditor needs to understand the management's process to identify and assess
Assessment Process risks in financial reporting. Auditor also needs to understand actions taken by
the management to address these [Link] auditor will then evaluate whether
there are deficiencies in the client's risk assessment process.

Understand client's Auditor will understand the process by which transactions and events are
Information systems initiated, recorded, processed, corrected, transferred to general ledger and
relevant to financial reported in the financial statements.
reporting
Auditor will also understand how the client communicates financial reporting
Plus roles and responsibilities as well as important matters relating to financial
reporting.
communication

Page 60 of 206
Understand the Control Control activities are the policies and procedures which help ensure that
Activities management directives are carried out.

Auditor has to understand control activities to assess risk of material


misstatement in the financial statements and to design further procedures.

Examples of controls are:

Segregation of duties :assignment of roles/responsibilities to different people,


thereby reducing the risk of fraud and error occurring. The concept is that no
individual person should be responsible for more than one of the following
duties:
(i) the authoristion of a transaction;
(ii) the recording of the transaction in the accounting records; and
(iii) the custody of the asset relating to the transaction.

Information processing: computer controls including general IT controls, which


cover a range of applications and support the overall IT environment and
application controls which operate on a cycle/business process level ( details
given separately)

Authorisation: approval of transactions by a suitably responsible official to


ensure transactions are genuine.

Physical controls : restricting access to physical assets such as cash, inventory


and plant and equipment, thereby reducing the risk of theft.

Performance reviews : comparison or review of the performance of the


business by looking at areas such as budget v actual results.

Arithmetical controls: controls which check the arithmetical accuracy of


accounting records.

Account reconciliations : comparison of an account balance with another


source; often this source is from a third party, such as the bank, with differences
being investigated.

Understand client's Auditor will understand how internal controls over financial reporting
Monitoring process monitored ( including whether there is an effective internal audit department)

Page 61 of 206
Computer Controls
GENERAL CONTROLS(Apply to the whole system}

Controls on the information system environment which ensure proper development of applications.

Examples include

• making regular back-ups of data and storing them off-site;


• having an IT help-desk and IT training for staff;
• keeping computers in locked rooms;
• having a disaster recovery plan;
• all computers have log in codes;
• anti-virus software and firewalls;
• segregation of duties between programmers and users.
• review of the data center or information processing facility should cover the adequacy of air
conditioning (temperature, humidity), power supply (uninterruptible power supplies, generators) and
smoke detectors

APPLICATION CONTROLS

Application controls are those controls that relate to the transaction and standing data relating to a computer­
based accounting system.

They are specific to a given application and their objectives are to ensure the completeness and accuracy of the
accounting records and the validity of entries made in those records.

An effective computer-based system will ensure that there are adequate controls existing at the point of input,
processing and output stages of the computer processing cycle and over standing data contained in master files.

Application controls need to be ascertained, recorded and evaluated by the auditor as part of the process of
determining the risk of material misstatement in the audit client's financial statements.

Input controls

Data input controls ensure the accuracy, completeness, and timeliness of data during its conversion from its
original source into computer data, or entry into a computer application. Examples are given below:

Format checks: These ensure that information is input in the correct form. For example, the
requirement that the date of a sales invoice be input in numeric format only- not numeric and
alphanumeric.

Range /Reasonableness checks: These ensure that input data is rejected or highlighted if it is
outside pre-set [Link] example, where an entity rarely, if ever, makes bulk-buy purchases
with a value in excess of $50,000, a purchase invoice with an input value in excess of $50,000 is
rejected for review and follow-up.

Page 62 of 206
Compatibility/dependence checks: These ensure that data input from two or more fields is
compatible. For example, a sales invoice value should be compatible with the amount of sales tax
charged on the invoice.

Exception checks: These ensure that an exception report is produced highlighting unusual situations
that have arisen following the input of a specific item. For example, the carry forward of a negative
value for inventory held.

Sequence checks: ensure that sequential input of documentation/data is maintained. These


facilitate completeness of processing by ensuring that documents processed out of sequence are
rejected. For example, where pre-numbered goods received notes are issued to acknowledge the
receipt of goods into physical inventory, any input of notes out of sequence should be rejected.

Control totals: These also facilitate completeness of processing by ensure that pre-input, manually
prepared control totals are compared to control totals input. For example, the total of all the
invoices, such as the gross value, is manually calculated. The invoices are input, the system
aggregates the total of the input invoices' gross value and this is compared to the control total. This
helps to ensure completeness and accuracy of input.

Existence checks : the system is set up so that certain key data must be entered, such as supplier
name, otherwise the invoice is rejected. This helps to ensure accuracy of input.

Check digit verification: Check digits are used to protect against the transposition of data i.e. errors
arising due to accidental reversal of digits. This process uses algorithms to ensure that data input is
accurate.

Document counts :the number of invoices to be input are counted, the invoices are then entered
one by one, at the end the number of invoices input is checked against the document count. This
helps to ensure completeness of input.

One for one checking: the invoices entered into the system are manually agreed back one by one to
the original purchase invoices. This helps to ensure completeness and accuracy of input.

Processing controls

Processing controls exist to ensure that all data input is processed correctly and that data files are appropriately
updated accurately in a timely manner.
For example, the balance carried forward on the bank account in a company's general (nominal) ledger.
Other processing controls should include the subsequent processing of data rejected at the point of input, for
example:
A computer produced print-out of rejected items.
Formal written instructions notifying data processing personnel of the procedures to follow with regard
to rejected items.
Appropriate investigation/follow up with regard to rejected items.
Evidence that rejected errors have been corrected and re-input.

Page 63 of 206
Output controls

Output controls exist to ensure that all data is processed and that output is distributed only to prescribed
authorised users. While the degree of output controls will vary from one organisation to another (dependent on
the confidentiality of the information and size of the organisation), common controls comprise:
Appropriate review and follow up of exception report information to ensure that there are no
permanently outstanding exception items.
Careful scheduling of the processing of data to help facilitate the distribution of information to end users
on a timely basis.
Ongoing monitoring by a responsible official, of the distribution of output, to ensure it is distributed in
accordance with authorised policy.

Term to remember: Standing Data

Standing data is the information that is held on computer files for long-term use. It is called standing data as it
tends to change less frequently than other data. Examples of standing data would be:
• the rate of sales tax to be applied to sales invoices;
• the hourly pay rate for a factory worker to be used when calculating payroll;
• employee bank account details.

Master file controls


The purpose of master file controls is to ensure the ongoing integrity of the standing data contained in the
master files. It is vitally important that stringent 'security' controls should be exercised over all master files.
These include:
-appropriate use of passwords, to restrict access to master file data
-the establishment of adequate procedures over the amendment of data, comprising appropriate segregation of
duties, and authority to amend being restricted to appropriate responsible individuals
-regular checking of master file data to authorised data, by an independent responsible official

Limitations of internal control components


The internal control system, even if well-designed and well-implemented, does not completely eliminate the
possibility of fraud or error. No internal control system can be perfect due to its inherent limitations.

Controls are far more expensive compared to the benefits from the system.
Overriding of controls by the management.
Control systems are not geared up to cater to non-routine transactions.
Possibility of human error.
Possibility of fraud on account of collusion between employees.
Possibility that, with a change in conditions, a control may not be modified and therefore may become
inadequate.
Obsolescence of controls.

Page 64 of 206
Responsibilities of various parties regarding ICS

Management: design and implement and effective ICS. Check and ensure it is working effectively on a
continuous basis

BOD: ensure that an effective ICS is designed, implemented and monitored by the management. Ensure ICS are
reviewed by internal and external auditors and their recommendations are implemented

Auditors: review and report on ICS and recommend changes

External auditor's work regarding controls

Document/Evaluate Narratives

Narrative notes consist of a written description of the system; they would detail what
occurs in the system at each stage and would include any controls which operate at
each stage.

Advantages of this method include:


-They are simple to record; after discussion with staff members of Oregano, these
discussions are easily written up as notes.

-They can facilitate understanding by all members of the internal audit team, especially
more junior members who might find alternative methods too complex.

Disadvantages of this method include:


- Narrative notes may prove to be too cumbersome, especially if the sales and
distribution system is complex.

-This method can make it more difficult to identify missing internal controls as the
notes record the detail but do not identify control exceptions clearly.

Flowcharts

Flowcharts are a graphic illustration of the internal control system for the sales and
despatch system. Lines usually demonstrate the sequence of events and standard
symbols are used to signify controls or documents.

Advantages of this method include:


- It is easy to view the sales system in its entirety as it is all presented together in one
diagram.
-Due to the use of standard symbols for controls, they are easy to spot as are any
missing controls.
Information is presented in a logical sequence.
-They ensure that a system is recorded in its entirety as all documents have to be

Page 65 of 206
traced from beginning to end.
- Facilitates easy understanding of a system.
- Facilitates the highlights of strengths and weaknesses of a system.
- Serves as a permanent record of a system that can be subject to a minor amendment
on a year-to-year basis.
- They can be prepared quickly by staff with little experience.

Disadvantages of this method include:


- They can sometimes be difficult to amend, as any amendments may require the whole
flowchart to be redrawn.
- There is still the need for narrative notes to accompany the flowchart and hence it can
be a time consuming method.
- Not generally suitable for recording systems with numerous unusual transactions.
- Only suitable for describing standard systems.
- Major amendment is not normally possible without redrawing.
- Time can be wasted by recording and checking areas that are of no audit significance.
- They are not normally appropriate for recording systems where there are subsystems
or subroutines.

Questionnaires
Internal control questionnaires are used to assess whether controls exist which meet
specific objectives or prevent or detect errors and omissions.

ICQ( designed to ask if certain controls are present)


ICEQ (designed to ask if certain errors can be prevented-Le. test the
effectiveness of controls)

An Internal Control Questionnaire (ICQ) normally comprises a checklist of standard


controls that should exist in a specified functional area (for example sales and trade
receivables or purchases and trade payables). Questions about the existence of
specified controls are usually phrased to generate a 'Yes' or a 'No' answer, with an
affirmative answer confirming the existence of the control and a negative answer
indicating the absence of the control and a weakness in the system.

A problem associated with ICQs is that whilst they do identify areas where controls
appear to be weak, they do not provide evaluation of those weaknesses. For example,
whilst a 'No' answer may indicate weakness in controls, it is possible that other controls
in the system, of which the auditor is unaware, may compensate for the weakness.

Internal Evaluation Questionnaires (ICEQs) provide an alternative and improved means


of evaluating control systems, by asking key questions about those systems. Key
questions are phrased such that answers in the positive should alert the auditor to the
fact that there are deficiencies in the systems because systems objectives are not being
met. ICEQs are usually designed to include a list of points that the auditor should
consider before answering each key question.

The auditor issues the questionnaires to the client, who in turn gets it filled by the
appropriate employees. The feedback on the questionnaire enables the auditor to

Page 66 of 206
assess the inherent limitations in the design of the internal controls.

The ICEQs contain detailed questions relating to the functioning of internal controls.
They are to be answered by the clients. The answers to the questions are generally in a
narrative form.
Information relating to the following matters is included the ICQs and ICEQs:
_ segregation and rotation of duties
maintenance of records and documents
_ accountability for, and safeguarding of assets
_ procedure for authorisations

The feedback received on the questionnaires will then be tested by the auditors and the
weaknesses, if any, will be communicated in the form of a letter of weakness to the
client.

Advantages
Questionnaires are quick to prepare, which means they are a cost effective method for
recording the system.

They ensure that all controls present within the system are considered and recorded;
hence missing controls or deficiencies are clearly highlighted.

Questionnaires are simple to complete and therefore any members of the team can
complete them and they are easy to use and understand.

Disadvantages
It can be easy for the company to overstate the level of the controls present as they are
asked a series of questions relating to potential controls.

Without careful tailoring of the questionnaire to make it company specific, there is a


risk that controls may be misunderstood and unusual controls missed.

Test!
Test of controls are performed to obtain audit evidence about 2 things:

1. Whether the ICS is designed suitably (to prevent, detect or correct material
misstatements)
2. Whether the ICS are operating properly ( test of controls)
Test of controls- examples

inspection of documents (e.g. authorizations)


enquiries about internal controls which leave no audit trail ( e.g. is the person who
is SUPPOSED to perform the function actually performing it or is someone else is
doing so)
Re-performance of control procedures ( e.g. reconciliations)
examination of evidence of management views(e.g. minutes of meetings)

Page 67 of 206
Observation of controls
Using TEST DATA(CAATs)

If controls appear strong, they are tested to ensure they operated as described
throughout the year. If the results show they operated effectively, substantive testing
may be reduced.

Report control A letter on internal control (also referred to as a management letter or letter of
weaknesses to weakness) is a letter usually forwarded by an auditor to the senior management of a
management company.
The letter should normally be forwarded immediately following the completion of the
tests of control and before the commencement of substantive procedures.

The letter contains weaknesses identified in the entity's system of internal control as
identified by the auditor when performing tests of control and the purpose of the letter
is to bring these weaknesses to the attention of management.

The weaknesses identified in the main body of the letter should be those which could
lead to fraud or material error in or omission from the company's financial statements,
and will be classified as those relating to:
(i) the design of the systems of accounting and internal control.
(ii) the operation of the systems of accounting and internal control.
For both categories the implication(s) of the weakness(es) should be identified,
however minor control issues which the auditor would wish to bring to the attention of
the company's senior management should be included in an appendix to the letter of
weakness or in a supplementary report.

Examples of matters the external auditor should consider in determining whether a


deficiency in internal controls is significant include:
- The likelihood of the deficiencies leading to material misstatements in the financial
statements in the future.
The susceptibility to loss or fraud of the related asset or liability, the subjectivity and
complexity of determining estimated amounts.
- The financial statement amounts exposed to the deficiencies.
- The volume of activity that has occurred or could occur in the account balance or
class of transactions exposed to the deficiency or deficiencies.
- The cause and frequency of the exceptions detected as a result of the deficiencies in
the controls.

Decide extent of Internal control over financial reporting strong-➔ decrease substantive testing
substantive testing
Internal control over financial reporting weak-➔ inccrease substantive testing

Page 68 of 206
Answer Technique

For deficiencies in the design of the system ( weaknesses in the way the system has been made):

Identify weakness from the scenario


Explain the impact of the weakness on the organization ( think of the problem it can casue for the
business or the recording in the Financial statements etc)

For Test of controls ( to confirm the operating effectiveness of internal control)

Remember: the idea of TOCs is to simply confirm that are the systems actually being implemented the
way auditors were told ( so confirm the 'stories' you were told!)
ldentidy the control from the scenario
Think of a way to test it to confirm it was actually being followed

Page 69 of 206
The Sales System

The sales cycle


Order received
l
Goods dispatched

Invoice generated

E� \ �
lavolce emeJi, the day book

: !?PU (Y)�hlj

General ledger C-<· So, le..i 1 '300( ie.�:h o-k....,..) M moran dger
A T C
J, 0(
Trial balance 1vv
�\ 9, lcO t
l
F/S

�--------------------------------- ThinkAhead
CACCA

Control objectives for sales and despatch system

To ensure that orders are only accepted if goods are available to be processed for customers.
To ensure that all orders are recorded completely and accurately.
To ensure that goods are not supplied to poor credit risks.
To ensure that goods are despatched for all orders on a timely basis.
To ensure that goods are despatched correctly to customers and that they are of an adequate quality.
To ensure that all goods despatched are correctly invoiced.
To ensure completeness of income for goods despatched.
To ensure that sales discounts are only provided to valid customers.

Page 70 of 206
Sales order - All sales orders documented on a sequentially numbered multi-part SALES ORDER
placed FORM.
- Confirm from the customer ( preferably in writing except on telephonic sales, a verbal
reconfirmation/ call recording should be acceptable)
- Inventory check
- One copy of the GDN is sent with the goods, one copy stays in the warehouse, stapled
to the relevant sales order, and one copy is sent to the invoicing department.
- New customer: credit checks, the obtaining of trade/bank references and the setting of
appropriate credit limits for customers
- Existing customer: credit limit check, Customer credit limits should be regularly
reviewed and updated based on the level of sales transactions and credit risk
- Any discounts committed to be authorized
- Follow up on unfulfilled orders- On a regular basis, a sequence check of orders should
be undertaken to identify any missing orders.
- Automated environment: access to master file limited to authorized individuals only

Goods - Sequentially pre-numbered Goods Dispatched Note


dispatched - Matched to the sales order- Upon despatch, the GDN should be matched to the order; a
to the regular review of unmatched orders should be undertaken to identify any unfulfilled
orders.
customer - Signed by the warehouse manager after quantity and quality checks
- 3 copies( warehouse, customer, accounts/invoicing)
- Customer should sign the copies to acknowledge receipt of goods

Sales invoice - Sequentially pre-numbered invoices


raised and - Matched to GDN
- 3 copies ( accounts/invoicing, customer, sales day book clerk if applicable)
entered in
- Ensure the authorized price list is used to prepare the invoice
the
- Any discounts authorized
accounting - Arithmetic checks on invoices
system - Sequence check on GDNs to ensure all GDNs have been invoiced
- Sequence check on Invoices to ensure all invoices have been entered in the accounting
system
- Customer statements should be sent monthly to ensure any errors and disputed
invoices are quickly identified and resolved
- The sales ledger control account should be reconciled on a monthly basis to the
individual ledger to identify any errors. The reconciliations should be reviewed by a
responsible official and they should evidence their review.

Page 71 of 206
Payment received from the customer Goods returned by the customer

Match payment to invoice Sequentially pre-numbered credit note


Check validity of any settlement Signed by the manager
discounts availed by the customer Matched to invoice
Segregation of duties: receiving Prepare a report for reasons for returns and actions
payment and recording taken by the management.
Encourage bank transfers
A Bank Reconciliation Statement
should be prepared on a monthly basis

Other Aged receivables report: prepare monthly and reviewed by a senior official
controls Exceptions reports created and reviewed ( old receivables, credit limit exceeded etc.)
Amendments to master file data should be restricted so that only senior officials can make
changes.

Page 72 of 206
The Purchase System

II The purchase cycle

Requisition

Orde laced
r

Goods received

I nvoice ceived
r

Invoice entered in the day book

� m(r0-t\.-j � r(\�'j
General ledger £ . . ) Memorandum ledge'('."---7 Supplier statement

l
Trial balance
1e�1\1�/N'\ "1(<(!"<'(1-f1·0:hi"'

F/S

�------------------------------------ ThinkAhead
CACCA

The main objectives in purchase transactions are:


Procurement is made only when the requirements are genuine.
Purchases are made at the most optimum prices and terms.
Purchases meet the required quality standards and if substandard quality is accepted, must be at negotiated
terms.
Payments are made according to agreed terms.
They are procured on time and the payments are made according to agreed terms.

Purchase Sequentially pre-numbered


requisition Authorized to ensure only those goods are ordered which are required
Monitor inventory level or Re-order level set
Inventory/ re-order level checked before raising the requisition to ensure only order
when required.

Page 73 of 206
Purchase Sequentially pre-numbered and matched to requisition
order Authorized supplier list used and updated annually (this should take into account the
price of goods, their quality and the speed of delivery.)
Authorized
- 3 copies ( supplier, order department, warehouse)
- Follow up on order placed but not yet received ( exception reports can be created in a
computerized environment) and sequence check can be performed for any unfulfilled
orders

Goods - Sequentially pre-numbered GRN


received - Matched to purchase order
- Signed by the warehouse manager after quantity and quality checks
- 3 copies ( ordering department, warehouse for their records, account)

Invoice Match to GRN


received File in an order ( CANNOT be Sequentially pre-numbered) but should be numbered
from supplier manually. This way, a sequence check can then be carried out to ensure all invoices
have been entered in the day book/ledger.
Arithmetic checks
- Entered in the ledger /day book on a daily basis-application controls( such as control
total) should be applied to ensure completeness and accuracy over the input of
purchase invoices.
- Stamp 'entered' when recorded
- Segregation of duties ( order placement, goods received and recording)
- Monthly reconciliation: PL to PLCA

Payment made Goods returned to the supplier

Segregation of duties ( Purchase order, goods received, Sequentially pre-numbered debit


payment ) notes
Before approving invoices for payment, a senior official
should match them to the audit trail ( [Link] GRN) Authorized
Bank transfer preferred
Vendor-wise analysis to identify
If payment by cheque: senior individuals only plus two
consistent quality problems
signatories for high amounts
Stamp invoice 'paid'
Try and avail settlement discounts and pay according to
supplier's terms to maintain supplier goodwill
Payment against specific invoices only ( avoid 'on account
payment')
Supplier statement reconciliation with PL
PL reconciliation with PLCA
Monthly BRS

Examples of Document counts - the number of invoices to be input are counted, the invoices are then
application entered one by one, at the end the number of invoices input is checked against the document

Page 74 of 206
controls to count. This helps to ensure completeness of input.
ensure the
Control totals - here the total of all the invoices, such as the gross value, is manually
Completeness calculated. The invoices are input, the system aggregates the total of the input invoices' gross
and accuracy value and this is compared to the control total. This helps to ensure completeness and
of the input of accuracy of input.
purchase
One for one checking- the invoices entered into the system are manually agreed back one by
invoices.
one to the original purchase invoices. This helps to ensure completeness and accuracy of input.

Check digits-this control helps to reduce the risk of transposition errors. Mathematical
calculations are performed by the system on a particular data field, such as supplier number, a
mathematical formula is run by the system, this checks that the data entered into the system is
accurate. This helps to ensure accuracy of input.

Range checks-a pre-determined maximum is input into the system for gross invoice value, for
example, $10,000; when invoices are input if the amount keyed in is incorrectly entered as
being above $10,000, the system will reject the invoice. This helps to ensure accuracy of input.

Existence checks - the system is set up so that certain key data must be entered, such as
supplier name, otherwise the invoice is rejected. This helps to ensure accuracy of input.

Page 75 of 206
The Payroll System

The main objective of a payroll is to ensure that:


Wages and salaries are paid at the correct rates.
Wages and salaries are paid to the right people.
Wages and salaries are paid on time.

Key terms: 1. Clock cards/ timesheets [Link] sheet [Link] slips [Link] Transfer List/payment list (instructions
to the bank)

Appointment/ leavers

Appointments: All appointment of staff, whether temporary or permanent, should only be made by the
human resources department, separate from the payroll department

There should be formal procedures requiring the interviews manager to provide detailed written
notification to a responsible official (for example the wages supervisor) of starters and leavers.

Update 'starters and leavers' details on a timely basis. Procedures should ensure that 'starters' and
'leavers' details are added to or deleted from the master file immediately after starting or leaving the
company's employment.

All increases of pay should be proposed by the HR department and then formally agreed by the board of
directors.

Standing data in the master file:


• 'Read' and 'amend' access to the master file should be available from specified
terminals to responsible officials who have a need and authorised cause to access the
information.
Maintain a log of access attempts (Controls should include a computer log which
registers date and time access to the master file by the various users. This should
regularly be reviewed by a senior responsible official of the company)
• Match standing data to the personnel filed periodically

At random intervals a more senior responsible official of the company (for example the company accountant),
should access the wages master file and check its contents to the manual records maintained, input
documentation and notifications from the interviews manager as appropriate.

Page 76 of 206
Calculations

Clock cards sequentially pre-numbered (which details the employee number and name)
Clock card machine supervised or in open view (Staff attendance machine kept near the security gate (to
ensure that there are no dummy attendances recorded).
Head count by area supervisor ( attendance matched to actual employees present)
Any overtime worked reviewed and then authorized. This should be evidenced by signature on the
employees' overtime sheets.
Periodic verification of staff cards with personal files of employees (to ensure that there are no ghost
employees).
Data input: Use application and general IT controls ( for example range checks, passwords)

Gross pay, deductions, net pay:


• Preferably automatically calculated by the payroll system.
• Calculations re checked on a sample basis- A senior member of the payroll team should
recalculate the gross to net pay workings for a sample of employees and compare their results
to the output from the payroll system.

Payments

Pay slips to be sequentially pre-numbered

Segregation of duties ( payroll sheet, recording, payment)

Salaries:
• Preferably through bank transfer
• Bank transfer list/payment list matched to payroll sheet prior to authorising the bank payment.
• When authorising the payments, the responsible official should on a sample basis perform
checks from payroll records to payment list and vice versa to confirm that payments are
complete and only made to bona fide employees.
• Bank transfer list/payment list preferably authorized by someone other than the person who
authorized payroll ( for example the Finance Director)

Wages (cash)/Pay packets


• All cash wages should only be paid upon sight of the employee's clock card and
photographic identification as this confirms proof of identity.
• Uncollected wage packets should be kept in a safe place/ deposited in the bank

Page 77 of 206
Revenue and Capital Expenditure

Capital Expenditure

Requisition

Order placed ( check if budgeted, if not budgeted, approval from BOD)

Asset received

Invoice received

Non-Current Asset Register ( asset code, location, supplier details, depreciaition, revaluation etc)
J,
General ledger

Trial balance

F/S

�------------------------------------ ThinkAhead
CACCA

Capital expenditure is incurred when a business spends money either to buy fixed assets or to add to the value
of an existing fixed asset.

Revenue expenditure is that expenditure which is incurred to maintain the existing capacity of an asset so that it
can do its daily work. Examples of revenue expenditure are cost of raw material and other stores, salaries and
wages, repairs and maintenance, stationery and printing, advertisements, postage, telephone, travel expenses
etc.
The main control objectives over revenue and capital expenditure are to ensure that:
► All expenditure is authorised.
► Proper segregation of capital and revenue expenses is made.
► Expenses are properly accounted for.

Page 78 of 206
The transaction cycle for capital and revenue expenditure is quite similar for purchases. However, certain
additional control points, which are to be ensured, are mentioned below:
► Am authorized budget is prepared for all expenditure.
► Preparation of a report of capital budget versus actual expenditure.
► Preparation of a periodic variance report of those expenses that do not match the budget.
► Orders for capital items should be authorised by appropriate levels of management.
► A document may be prepared for showing the distinction between capital and revenue expenditure and for
providing guidance on which expenses to be capitalised.
► All vouchers of revenue expenditure need to have approval of maintenance manager.
► A senior person should check the accounting treatment for the expenses (especially repairs and
maintenance).

Non-Current Asset register

The purpose of a tangible non-current assets register is to list details of all the non-current assets owned by an
entity, in order to facilitate control over those assets. Typically, the register should record cost, depreciation and
net book value information of each asset along with identifying details. For example in the case of plant and
machinery- gross cost, annual depreciation rate, depreciation provision, net book value, date of acquisition,
serial number and description and location of asset.

► The register should be updated by individuals who are separated from the acquisition, custody and
disposal of assets.
► Periodical reconciliation of non-current register with the general ledger to be done and any differences
to be investigated.
► Preparation of an exception report if the non-current register does not match the non-current assets
account maintained in accounts.
► Invoices should bear appropriate ledger code (distinguishing revenue items from capital expenditure) in
order to facilitate correct recording.
► Depreciation rates should be reasonable and authorised.
► Depreciation calculations should be checked
► NCA register should be used to confirm physical existence on a periodic basis
► To ensure completeness of recording, periodic checks should be made to ensure that assets in existence
are completely recorded in the register.

Page 79 of 206
Bank and Cash
The main objectives of cash and bank transactions are to ensure that:
► All money received is recorded.
► All money received is banked.
► Money is properly safeguarded.
► Payments are made to correct persons and properly recorded.

Controls over Cash receipts

Regular review of internal control over cash receipts and payments should be conducted by the Internal Audit
Department

On a daily basis, cash received should be matched with the sales made. This should be done for each till separately

Cash should be banked with proper security on a daily basis

Match bank deposit slips with the cash and cheque receipt register.

Access to the cash tills should be restricted to authorized individuals only

Monthly bank reconciliation statements should be performed and differences to be [Link] should be
reviewed by senior officials.

Segregation of duties between the person receiving the money, the person depositing it in the bank and the one
making the payments.

Receivables' ledger reconciled with control account.

Surprise cash counts by personnel other that the accounts department.

Cash to be suitably insured for cash in hand, and cash in transit.

Unused cheques to be kept under lock and key.

Cheques books to be in the custody of a responsible person

Minimum cash balance to be maintained needs to be decided. Whenever cash balance exceeds minimum balance,
excess balance deposited to be in the bank.

Page 80 of 206
Main controls on bank and cash
► Segregation of duties between the person receiving the money, the person depositing it in the bank and the
one making the payments.
► Match bank deposit slips with the cash and cheque receipt register.
► Daily cash receipts immediately recorded in the customers' accounts.
► Cash receipt register reconciled daily with the customer accounts.
► Periodical management review of the register is to be conducted to ensure that cheques are promptly
deposited into the bank.
► Bank reconciliation to be prepared periodically and differences to be investigated.
► Receivables' ledger reconciled with control account.
► Cash kept under the custody of the cashier. And there should be restricted access to cashier's room
► Security personnel to accompany the cashier while depositing or withdrawing cash from the bank
► Minimum cash balance to be maintained needs to be decided.
► Whenever cash balance exceeds minimum balance, excess balance deposited to be in the bank.
► Surprise cash counts by personnel other that the accounts department.
► Cash to be suitably insured for cash in hand, and cash in transit.
► Unused cheques to be kept under lock and key.
► Cheques books to be in the custody of a responsible person

Page 81 of 206
Writing the answers for deficiencies

Identify and explain Recommend a control


Deficiencies

0.5 mark for identifying 1 marks

0.5 mark for explaining

0.5 mark for identifying 1 marks

0.5 mark for explaining

�--------------------------------- ThinkAhead
CACCA

Test of controls
In the exam, you might be asked to:
Identify and explain deficiencies in the system
Recommend a control to address each of these deficiencies
Describe a TEST OF CONTROL the external auditors would perform to assess if each of these controls, if
implemented, is operating effectively.

What is a Test of Control? An audit procedure designed to evaluate the operating effectiveness of controls in
preventing, or detecting and correcting, material misstatements at the assertion level.

Examples of test of controls( also mentioned earlier):

inspection of documents (e.g. authorizations)


enquiries about internal controls which leave no audit trail ( e.g. is the person who is SUPPOSED to perform
the function actually performing it or is someone else is doing so)
Reperformance of control procedures ( e.g. reconciliations)
examination of evidence of management views(e.g. minutes of meetings)
Observation of controls
Using TEST DATA(CAATs)

Page 82 of 206
If you are confused about how to word a TOC, start with "The auditor should.... "
Example from a past exam
Deficiency Control Test of Control

Customer credit limits are set by sales Credit limits should be set by a senior The auditor should take a sample of new
ledger clerks. member of the sales ledger department customers accepted in the year and review
and not by sales ledger clerks. These limits the authorisation of the credit limit, and
Sales ledger clerks are not sufficiently should be regularly reviewed by a ensure that this was performed by a
senior and so may set limits too high, responsible official. responsible official.
leading to irrecoverable debts, or too low,
leading to a loss of sales. And/or

The auditor should enquire of sales ledger


clerks as to who can set credit limits.

Another example from a past exam


Deficiency Control Test of Control

Supplier statement reconciliations are no Supplier statement reconciliations should The auditor should review the file of
longer performed. be performed on a monthly basis for all reconciliations to ensure that they are
suppliers and these should be reviewed by being performed on a regular basis and that
This may result in errors in the recording of a responsible official. they have been reviewed by a responsible
purchases and payables not being official.
identified in a timely manner.

II The Audit Process

Think Ahead
CACCA

Page 83 of 206

You might also like