LECTURE 12 – Chapter 12
Topic: Internal Control System
SIGNIFICANCE LEVEL:
1) V.V.V Imp Topic for your exam.
2) Always comes in your exam
1) DISCUSSION:
Risk assessment procedures and substantive procedures are required for every area of financial
statements. Test of Controls are required only:
i) Controls are operating effectively and auditor plan to rely on internal control in his Risk Assessment, Or
ii) Substantive Procedure alone do not provide sufficient appropriate audit evidence.
2) NOTE:
Do not get confused between the Test of Controls and Substantive audit procedures. Test of Control
means you’ve to ensure that there must an automated process. Everything must pass from a certain
process. Substantive audit procedures are the actions which you (as an auditor) performed during the
audit to obtain Sufficient appropriate audit evidence.
Let’s say:
Entity A receives an order of 20,000 unit of branded jeans. Now, the Entity A does not send a Quotation
sheet to the customer. Also, there is no proper communication between the Entity A production
department and the sales department.
Due to which, the order gets delayed because production department don’t know about the no of
orders requested by the customer
So, while performing the procedures and obtaining the evidence you’ve to ensure that the invoices must
duly signed by the authorized representative. If no proper authorization, then it’s a control weakness.
We as an Auditor should not express an Opinion on Internal Controls. We only give recommendations to
the management if the Entity’s Internal Controls are not operating effectively.
Implementing and designing the Internal Controls is the responsibility of the Management not with the
Auditors. If auditor design and implement the Internal Controls then it’s an (Management Threat) which
is significant and can’t be mitigate by any safeguard. We can only monitor the Internal Controls.
Never put yourself into the Management Shoe. Never assume the Managements Responsibility as it will
impair the Independence (Objectivity).
LO 1: DEFINITAION LIMITATIONS & RESPONSIBILITY REGARDING IC:
Definition of Internal Controls:
Limitations of Internal Control:
Responsibilities Regarding Internal Control:
Managements Responsibilities:
Design, Implement and Operate Internal Controls necessary for the preparation of Financial
statements.
Auditors Responsibilities:
Understand Internal Control Systems.
Perform tests to determine if the controls are operating effectively.
Communicate significant deficiencies in Internal Controls to management and TCWG if found.
NOTE:
The auditor does not express an opinion on Internal Controls but focuses on the accuracy of
Financial Statements.
2
LO 2: UNDERSTANDING ELEMENTS OF INTERNAL CONTROL SYSTEM:
1) Control Environment:
Key Factors Evaluated by the auditor:
A weak control environment will likely result in a weak overall Internal Control System
3
2) Information system relevant to Financial Statements & Communication:
Auditor’s Focus Areas:
3) Entity’s Risk Assessment Process:
Identifying Risk means: Recognizing potential Risk.
Assessing Risk means: Determining the significance of the identified Risk.
Managing Risk means: Designing controls to minimize the risk.
Factors Influencing Risk Changes:
A strong risk assessment process helps in promptly addressing risks and ensures adequate
Internal Controls.
4
4) Control Activities Relevant to Audit:
Categories of Control Activities:
5) Monitoring of Controls:
Examples:
5
LO 3: SALES SYSTEMS
Sales Order Function:
Objectives of Controls in the Sales Order Department:
1) Orders should only be approved when within the customers credit limit.
2) Orders must follow authorized rates and discounts
3) All customer orders must be processed, ensuring no order is processed more than once.
6
Note:
Credit limits, Prices, and discounts must be set by an independent department, not the sales order
department.
Dispatch Function:
Objectives of Controls in the Dispatch Department:
1) Goods must be dispatch for all sales order
2) Goods should not be dispatched twice for the same order
3) The right goods should be dispatched to the right customer.
4) Customer must acknowledge receipt of goods.
Invoicing / billing Function:
Objectives of Controls in the Invoicing Department:
1) Invoices must be prepared for all goods dispatched.
2) Invoices should use the correct quantity, price and discount.
3) Credit notes should be authorized for goods return.
7
GL / Accounts Function:
Objectives of Controls in the GL/Accounts Department:
Other Key Controls:
Timely transfer of sales order, GDN’s and invoices between department
A consolidated list showing the sales order, corresponding sales invoice no. and GDN no should be
mentioned.
8
LO 4: PURCHASE SYSTEMS:
Purchase system is the reciprocal of the Sales System.
Purchase Order Department:
Objectives of Controls in the Purchase Order Department:
1) All purchase orders must be properly authorized.
2) Orders should only be given to an Approved supplier.
3) Orders should be made at the lowest possible rates (Negotiation)
9
Receiving Department:
Objectives of Controls in the Receiving Department:
1) Goods are received in accordance with valid purchase order
2) Goods are received for all purchase orders.
Invoicing / billing Department:
Objectives of Controls in the Invoicing/billing Department:
1) Suppliers invoices are processed only for goods received.
2) Discount from suppliers are obtained only when available.
3) Debit notes must be taken for returned goods.
10
GL / Accounts Department:
Objectives of Controls in the Accounts Department:
1) Purchases are recorded only for goods / services received.
2) Purchase invoices (and debit notes) are accurately and completely recorded in the Purchase Journal
3) Purchase invoices and debit notes are posted to the correct suppliers account.
11
LO 5: PAYROLL SYSTEMS:
Objectives of Controls:
Payroll is calculated only for real employees (no dummy/ghost employees).
Objectives of Controls:
Wages are calculated based on actual work done.
Objectives of Controls:
Payroll Gross-pay should be calculated correctly.
12
Objectives of Controls:
Deductions should be authorized and correct.
Payment of wages and Salaries:➔
Correct amount should be paid to employees and authorities timely.
Objectives of Controls:
Ensure gross pay, deductions and net pay are accurately recorded in the accounts.
13
14
LO 6: CASH AND BANK STATEMENT:
Cash Receiving:
Objectives of Controls:
All money received by post of at counter (cash-in-hand) should be recorded and deposited into Bank.
Cash Payment:
Objectives of Controls:
Ensure all payments are properly authorized, made to the correct person, and accurately recorded.
15
Cash Balances:
Objectives of Controls:
All money (Cash, Cheques, notes) should be properly safeguarded (protected)
Cash Balances:
Objectives of Controls:
Ensure Petty cash spendings are authorized, accounted for and cash is secured.
16
LO 7: INVENTORY SYSTEM:
Recording Inventory:
Objectives of Controls:
Inventory records should be accurate, complete and all inventory movements should be timely,
correctly recorded and authorized.
Physical safeguarding of Inventory:
Objectives of Controls:
Inventory is protected against the theft and damaged.
Valuation of Inventory:
Objectives of Controls:
Inventory should be valued at the lower of cost or NRV as per IAS-2.
17
Management level of Inventory:
Objectives of Controls:
Maintain an appropriate levels of inventory to avoid stock-outs or obsolescence.
18
LO 8: NON-CURRENT ASSETS:
Addition deletion of Non-Current Assets:
Objectives of Controls:
Ensure that all purchases and disposals of Non-Current Assets are properly authorized, and the relevant
records are updated.
Recording of Expenditures on Non-Current Assets:
Objectives of Controls:
All expenditures should be properly classified as capital or revenue, and all capital expenditures should
be accurately recorded.
19
LO 9: METHODS OF DOCUMENTATION:
There are three primary method for recording a client’s accounting and internal control system.
20
LO 10: TYPES OF QUESTIONNAIRE:
What is a questionnaire in audit?
A questionnaire in auditing is a structured list of questions prepared by the auditor to obtain information
from the client about their systems, controls, and procedures.
It’s a common audit tool used to:
• Understand the client’s internal control system.
• Identify weaknesses, risks, or areas needing further testing.
• Save time by asking standardized questions rather than doing lengthy interviews each time.
Types of Audit Questionnaires
1. Internal Control Questionnaire (ICQ)
o Covers whether specific controls exist (Yes/No questions).
o Example: “Are supplier statements regularly reconciled with purchase ledger balances?”
2. Internal Control Evaluation Questionnaire (ICEQ)
o Focuses more on weaknesses by asking negative questions.
o Example: “Can the same person both approve payments and record them in the
ledger?”
3. General Audit Questionnaire
o Broader set of questions about policies, compliance, ethics, etc.
Example (simple) – Payroll Audit Questionnaire
• Are payroll records authorized by management?
• Is there segregation of duties between payroll preparation and payment?
• Are salary bank transfers reviewed before release?
• Are employee master files regularly updated for resignations?
21
LO 11: CHECKING ACCURACY OF PREVIOUS YRS ICQ:
Instead of prepared new ICQs each year, it is better to use previous year’s ICQ after checking their
accuracy and updating them.
Steps to follow:
LO 12: AUDITORS COURSE OF ACTION IF WEAKNESS IN INTERNAL CONTROLS:
22
LO 13: INTERNAL CONTROL SYSTEM IN SMALL ENTITIES:
LO 14: AUDIT LETTERS:
Planning stage is done. Major Portion of your AA exam is covered. Be alert.
------------------------------Best Wishes------------------------------
23