0% found this document useful (0 votes)
12 views10 pages

Chapter 7

The document outlines the components and processes of internal control, which are designed to provide reasonable assurance regarding the reliability of financial reporting, operational efficiency, and compliance with laws. Key components include the control environment, risk assessment, information systems, communication, monitoring, and control activities, each with specific audit considerations. It also highlights inherent limitations of internal controls and provides pointers for assessing control risks.

Uploaded by

ns2xnzytxz
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
12 views10 pages

Chapter 7

The document outlines the components and processes of internal control, which are designed to provide reasonable assurance regarding the reliability of financial reporting, operational efficiency, and compliance with laws. Key components include the control environment, risk assessment, information systems, communication, monitoring, and control activities, each with specific audit considerations. It also highlights inherent limitations of internal controls and provides pointers for assessing control risks.

Uploaded by

ns2xnzytxz
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

INTERNAL CONTROL

INTERNAL CONTROLS
• The process designed, implemented
and maintained by those charged
with governance, management and
other personnel to provide
reasonable assurance about the
achievement of an entity’s
objectives with regard to reliability
of financial reporting, effectiveness
and efficiency of operations, and
compliance with applicable laws and
regulations
Components of Internal Control

Control Environment
Risk Assessment Process
Information System and
Communication
Monitoring
Existing Control Activities
Control Environment
Sets the tone of an organization, influencing the control consciousness of its people
The existence of a satisfactory control environment can be a positive factor when the
auditor assesses the risks of material misstatements. However, it is NOT an ABSOLUTE
deterrent to fraud.
✓ Audit Consideration
The auditor shall evaluate whether: (attitude,
Elements: awareness and actions)
a. Management, with the oversight of those
a. Commitment to competence charged with governance, has created and
b. Human resource policies and practices maintained a culture of honesty and ethical
behavior, and
c. Organizational structure b. The strengths in the control environment
elements collectively provide an appropriate
d. Participation by those charged with governance
foundation for the other components of internal
e. Philosophy and management style control, and whether those other components are
not undermined by deficiencies in the control
f. Ethical values and integrity environment.
g. Responsibility and authority assignment
Risk Assessment
Whether the entity has a process for : ✓ Audit Consideration
• Identifying business risk If the entity has established such a process (referred to
hereafter as the “entity’s risk assessment process”), the
• Estimating the significance of the risks auditor shall obtain an understanding of it, and the results
• Assessing the likelihood of their occurrence thereof. If the auditor identifies risks of material
misstatement that management failed to identify, the auditor
• Deciding about actions to address those risks shall evaluate whether there was an underlying risk of a kind
that the auditor expects would have been identified by the
Risks can arise or change due to circumstances entity’s risk assessment process. If there is such a risk, the
auditor shall obtain an understanding of why that process
such as the following: failed to identify it, and evaluate whether the process is
• Changes in operating environment appropriate to its circumstances or determine if there is a
significant deficiency in internal control with regard to the
• New personnel
entity’s risk assessment process.
• New or revamped information systems If the entity has not established such a process or has an ad
• Rapid growth hoc process, the auditor shall discuss with management
whether business risks relevant to financial reporting
• New technology objectives have been identified and how they have been
• New business models, products or activities addressed. The auditor shall evaluate whether the absence of
• Corporate restructuring a documented risk assessment process is appropriate in the
circumstances, or determine whether it represents a
• New accounting pronouncements significant deficiency in internal control.
Information System and Communication
INFORMATION SYSTEM COMMUNICATION
consists of infrastructure (physical or hardware involves providing an understanding of individual roles
components), software, people, procedures, and data and responsibilities pertaining to internal control over
financial reporting
those relevant to audit: methods and records that:
• identify and record all valid transactions e.g. policy manuals, accounting and financial reporting
manuals and memoranda
• describe on a timely basis the transactions in
sufficient detail to permit proper classification of may be made electronically, orally and through actions of
transactions for financial reporting management
• measure the value of transactions in a manner that
permits recording their proper monetary value in the ✓ Audit Consideration
financial statement Obtain understanding of
• determine the time period in which transactions ▪ Major transaction classes
occurred to permit recording of transactions in the ▪ How transactions are initiated
proper accounting period
▪ Available accounting records and support
• present properly the transactions and related ▪ Manner of processing of transactions
disclosures in the financial statements
▪ Financial reporting process used to prepare
the quality of system-generated information affects financial statements
management’s ability to make appropriate decisions in ▪ Means the entity uses to communicate financial
managing and controlling the entity’s activities and to
prepare reliable financial reports
reporting roles and responsibilities
Monitoring of Controls
Process to assess the effectiveness of controls on
a timely basis and taking necessary remedial actions ✓ Audit Consideration
The auditor shall obtain an understanding of the
Includes considering whether controls are major activities that the entity uses to monitor
operating as intended and that they are modified as internal control over financial reporting,
appropriate for changes in conditions including those related to control activities
Management’s monitoring activities may include relevant to the audit, and how the entity initiates
using information from communications from corrective actions to its controls.
external parties such as customer complaints and
regulator comments that may indicate problems or The auditor shall also obtain an understanding of
highlight areas in need of improvement. the sources of information used in the entity’s
monitoring activities, and the basis upon which
management considers the information to be
sufficiently reliable for the purpose.
Control Activities
Policies and procedures that help ensure that management
directives are carried out ✓ Audit Consideration
Includes: Control activities that are relevant to the audit
• Authorization are:
• Those that are required to be treated as such,
• Performance reviews
being control activities that relate to
• Information processing significant risks and those that relate to risks
❑ Application controls for which substantive procedures alone do not
• Apply to the processing of individual applications provide sufficient appropriate audit evidence.
❑ General IT controls • Those that are considered to be relevant in the
• Relate to many applications and support the judgment of the auditor.
effective functioning of application controls
• Physical controls
• Segregation of duties
Inherent Limitations of Internal Controls
1. Management’s usual requirement that a control be
cost effective (COST-BENEFIT constraint)
2. The possibility that a person reasonable for
exercising control could abuse that responsibility, for
example, a member of management overriding a control
(OVERRIDE by management)
3. The fact that most controls tend to be directed at
anticipated types of transactions and not at unusual
transactions, the potential for human error due to
carelessness, distraction, mistakes of judgment or the
misunderstanding of instructions (COMPETENCE
issues)
4. The possibility that procedures may become
inadequate due to changes in condition and compliance
with procedures may deteriorate (OBSOLESCENCE of
internal controls)
5. The possibility of circumvention of controls through
collusion with parties outside the entity or with
employees of the entity (COLLUSION)
Pointers when assessing control risks
CONTROL ENVIRONMENT
1. The existence of a satisfactory control environment is not an absolute deterrent to fraud
2. The control environment in itself does not prevent, or detect and correct, material misstatements
RISK ASSESSMENT PROCESS
1. Note how management performs the risk assessment process
2. Consider the existence of material weaknesses in internal control
INFORMATION SYSTEM AND COMMUNICATION
1. There is a possibility of inappropriate override of controls over journal entries
2. Check the resolution of incorrectly processed transactions
3. Focus on communications with the audit committee, and with regulatory authorities
CONTROL ACTIVITIES
1. The auditor’s primary consideration is whether, and how, a specific control activity, prevents or detects and corrects, material
misstatements
2. Consider the risks associated with information technology
MONITORING OF CONTROLS
1. In many entities, internal auditors or personnel performing similar functions contribute to the monitoring of an entity’s activities.

You might also like