Internal Controls and
Auditor
1
1. Introduction
Preliminary engagement activities
Planning activities
The entity and its
environment
Understanding
Understanding thethe entity
entity
and
and its
its environment
environment
Internal
Internal control
control
Identifying and assessing risks of
material misstatements
Designing and implementing auditor’s
responses to assessed risks
Overall reviewing
Drawing audit conclusions
and reporting
2
4. Understanding the Entity
Perform
Perform risk
risk assessment
assessment procedures
procedures to to gather
gather
information
information about
about the
the entity
entity and
and its
its environment
environment
Objectives,
Objectives,
Industry,
Industry, Selection
Selection and
and Measurement
Measurement
strategies,
strategies,
regulatory,
regulatory, Nature
Nature of
of the
the application
application of
of and
and review
review of
of
and
and related
related
and
and other
other entity
entity accounting
accounting financial
financial
business
business
factors
factors policies
policies performance
performance
risks
risks
Internal
Internal control
control
3
INTERNAL CONTROL
Internal control – The process
• designed, implemented and maintained by those
charged with governance, management and other
personnel
• to provide reasonable assurance about the
achievement of an entity’s objectives with regard to
• reliability of financial reporting,
• effectiveness and efficiency of operations, and
• compliance with applicable laws and regulations.
The term “controls” refers to any aspects of one or more of
the components of internal control.
2. Understanding of Internal Control &
General Aspects of Internal Control
Performing
Performing risk
risk assessment
assessment procedures
procedures
To gather information about
The
The entity
entity and
and its
its
Understanding environment
environment
Understanding thethe entity
entity
and
and its
its environment
environment
Internal
Internal control
control
Identifying
Identifying and
and assessing
assessing risks
risks of
of
material
material misstatements
misstatements
5
Obtain an Understanding of Internal
Control
The auditor should obtain an understanding of each of the
five components of internal control in order to plan the audit.
This knowledge is used to:
Identify types of Pinpoint the factors
potential that affect the risk of
misstatement material misstatement
Design tests of
controls and
substantive
procedures
6-6
3. Controls Relevant to the Audit
• An auditor is required to understand internal control
relevant to the audit.
• Although most controls relevant to the audit are
likely to relate to financial reporting, not all controls
that relate to financial reporting are relevant to the
audit.
• It is a matter of the auditor’s professional judgment
whether a control, individually or in combination
with others, is relevant to the audit.
7
4. Nature & Extent of the Understanding
• When obtaining an understanding of controls that
are relevant to the audit, the auditor is required, by
performing procedures in addition to inquiry of the
entity’s personnel, to:
– evaluate the design of those controls and
– determine whether they have been implemented.
8
4. Nature & Extent of the Understanding
• Risk assessment procedures can be used
to obtain audit evidence about the design
and implementation of relevant control,
which include:
– inquiring entity personnel;
– observing the application of specific controls;
– inspecting documents and reports; and
– tracing transactions through the information
system relevant to financial reporting.
9
5. Components of Internal Control
• Five components of internal control are:
– The control environment
– The entity’s risk assessment process
– The information system, including the related business
processes, relevant to financial reporting, and
communication
– Control activities
– Monitoring of controls
10
1. Control Environment
• ISA 315 requires the auditor to obtain an
understanding of the control environment.
• The control environment:
– includes the governance and management functions and
the overall attitude, awareness and actions of those
charged with governance and management about the
entity’s internal control and its importance in the entity;
– sets the tone of an organization, influencing the control
consciousness of its people; and
– is the foundation for effective internal control.
11
The Control Environment
The control environment is concerned with the actions,
policies, and procedures that reflect the overall attitude
of the client’s top management, directors, and owners of
an entity about internal control and its importance.
Control Environment
• Elements of control environment include:
– Communication and enforcement of integrity and ethical
values;
– Commitment to competence;
– Participation by those charged with governance –
independence from management, their experience and
stature;
– Management’s philosophy and operating style;
– Organizational structure;
– Assignment of authority and responsibility; and
– Human resource policies and practices.
1. Integrity and Ethical Values
Management actions
to remove incentives
that prompt a person to
behave improperly.
Communication of
behavioral standards
by codes of conduct
and example.
2. Commitment to Competence
Management’s consideration
of the competence levels for
specific jobs and how those
translate into requisite skills
and knowledge.
3. Board of Directors and Audit
Committee
Board delegates
responsibility for internal
control to management and is
charged with regular
independent assessments of
management-established
internal control.
The major stock exchanges
require listed companies to
have an audit committee
composed of entirely
independent directors who
are financially literate.
4. Management’s Philosophy and
Operating Style
Management, through its activities, provides clear signals to
employees about the importance of internal control. For
example, are sales and earnings targets unrealistic, and are
employees encouraged to take aggressive actions to meet those
targets.
5. Organizational Structure
Understanding the client’s
organizational structure
provides the auditor with
an understanding of how
the client’s business
functions and
implements controls.
6. Assignment of Authority and
Responsibility
Formal methods of
communication including:
Top management
memoranda concerning
internal control
Organizational operating
plans
Employee job descriptions
7. Human Resource Policies and
Practices
If employees are honest
and trustworthy, other
controls can be absent
and reliable financial
statements will still result.
Methods by which
persons are hired,
trained, promoted, and
compensated are
important elements of
internal control.
Control Environment
• When assessing the risks of material
misstatement, the auditor considers
favorably if a satisfactory control
environment exists
• However, the control environment in itself
does not prevent, or detect and correct,
material misstatements
2. Entity’s Risk Assessment Process
• The entity’s risk assessment process is another
component of the internal control framework.
• ISA 315 explains it as a process for:
– identifying business risks relevant to financial reporting
objectives;
– estimating the significance of the risks;
– assessing the likelihood of their occurrence; and
– deciding about actions to address those risks.
• The auditor is required to obtain an understanding
whether an entity has such process.
22
Risk Assessment
Client management’s identification and analysis of risks
relevant to the preparation of the financial statements in
accordance with GAAP.
1. Client Management’s Risk Assessment
2. Auditor Risk Assessment
Client Management’s Risk
Assessment
Client management assesses risk as part of designing
and operating internal controls to minimize errors
and fraud. Three steps involve:
i. Identify factors that may increase risk
ii. Determine significance of risk and likelihood of
occurrence
iii. Develop specific actions to reduce risk to an
acceptable level.
Auditor Risk Assessment
The auditor obtains knowledge
about management’s risk
assessment process by:
Determining how management
identifies risks relevant to
financial reporting
Evaluating their significance
and likelihood of occurrence
Deciding the actions needed to
address the risks.
3. Information System and
Communication
• The information system relevant to financial reporting
includes the following areas:
– Significant classes of transactions;
– The procedures by which those transactions are initiated,
recorded, processed and reported in the financial
statements;
– The related accounting records;
– How the information system captures significant events and
conditions;
– The financial reporting process used to prepare the entity’s
financial statements, including significant accounting
estimates and disclosures; and
– Controls surrounding journal entries, including non-standard
journal entries used to record non-recurring, unusual
transactions or adjustments. 26
Information and Communication
Methods used to initiate, record, process, and report an
entity’s transactions and to maintain accountability for
related assets.
For a small company with active involvement by the owner, a
simple computerized accounting system that involves one
honest, competent accountant may provide an adequate
accounting system.
A larger company requires a more complex system that
includes carefully defined responsibilities and written
procedures.
4. Control Activities
• The auditor obtains a sufficient
understanding of control activities
– to assess the risks of material misstatement at
the assertion level, and
– to design further audit procedures responsive to
assessed risks.
• Control activities are those policies and
procedures that help to ensure management
directives are carried out.
28
Control Activities
• Good control activities include:
– Appropriate higher level policies on authorization
and adequate authorization limit at each appropriate
level;
– Regular and sufficient performance reviews;
– Sound information processing system with
adequate application controls and general IT
controls;
– Sufficient and adequate physical controls on assets;
and
– Adequate segregation of duties (between
authorization, recording and custody duties).
29
1. Adequate Segregation of
Duties
Separation of the
functions of authorization,
recordkeeping, and
custody.
Separating IT duties from
User Departments
2. Proper Authorization of
Transactions and Activities
General authorization is
permissible for routine
events for which there
are policies to follow.
For some transactions
specific authorization is
needed on a case-by-
case basis.
3. Adequate Documents and
Records
Prenumbered
consecutive documents
so missing items are
noticed
Prepared as near to
transaction time as
possible
Good design with
instructions and
appropriate spaces
4. Physical Control Over Assets
and Records
Deterrents to prevent
physical access.
Access controls to Incorrect
prevent getting into Password
computer system.
Backup and recovery
procedures
5. Independent Checks on
Performance
Personnel are likely to
forget or intentionally
fail to follow
procedures, or they
may become careless
unless someone
observes and evaluates
their performance.
Control Activities
• ISA 315 requires the auditor to obtain
an understanding of how the entity has
responded to risks arising from
information technology.
• The auditor would determine whether
the entity has responded adequately to
the risks arising from IT by establishing
effective general and application
controls.
35
5. Monitoring of Controls
• The auditor is required to obtain an understanding
of the major types of activities that the entity uses
to monitor internal control over financial reporting,
and how the entity initiates corrective actions to its
controls.
• The purpose of monitoring of controls is to assess
the effectiveness of internal control performance
over time.
• Management achieves this monitoring objective
through ongoing activities, separate evaluations
(say internal audit), or a combination of the two.
36
Monitoring
Client management’s ongoing and periodic assessment of
the quality of internal control performance to determine
whether controls are operating as intended and modified
when needed.
For many companies, especially larger ones, an internal
audit department is essential for effective monitoring.
To maintain internal audit independence, it is imperative
that they be independent of operating and accounting
departments; and that they report to a high level of
authority, preferably the audit committee of the board of
directors.
Process for Understanding Internal
Control and Assessing Control Risk
A. Phase 1: Obtain and Document Understanding of
Internal Control: Design and Operation
B. Phase 2: Assess Control Risk
C. Phase 3: Design, Perform, and Evaluate Tests of
Controls
D. Phase 4: Decide Planned Detection Risk and
Substantive Tests
11. Documentation
• As stated in Chapter 15, ISA 315 requires an auditor to
document:
– the discussion among the engagement team, and the significant
decisions reached;
– key elements of the understanding obtained regarding each of the
aspects of the entity and its environment and of each of the internal
control components;
– the sources of information from which the understanding was
obtained;
– the risk assessment procedures performed;
– the identified and assessed risks of material misstatement at the
financial statement level and at the assertion level (see Chapter
17);
– the risks identified, and related controls about which the auditor has
obtained an understanding (see Chapter 17).
40
Documenting the Understanding
of Internal Control
Procedure Manuals
and Organizational Flowcharts
Charts
Internal Control
Narrative Description
Questionnaires
The Limitations of an Entity’s
Internal Control
Override of
Internal Control by
Management
Human Errors
or
Mistakes
Collusion
6-42
Information technology controls – General
General IT controls are policies and procedures
that relate to many applications and support the
effective functioning of application controls by
helping to ensure the continued proper operation
of information systems. For example:
– controls over data centre and network operations;
system software acquisition, change and
maintenance; access security; back-up and
recovery; and application system acquisition,
development and maintenance.
IT controls – Application controls
Application controls are controls that apply to
applications that initiate, record, process and report
transactions (such as MS Office, SAP, QuickBooks),
rather than the computer system in general.
Examples are chart of accounts, edit checks of
input data, numerical sequence checks and manual
follow-up of exception reports.
IT risks
• Reliance on systems or programs that are
inaccurately processing data, processing
inaccurate data or both.
• Unauthorised access to data that may result in
destruction of data or improper changes to data.
• The possibility of IT personnel gaining access
privileges beyond those necessary to
perform their assigned duties thereby
breaking down segregation of duties.
• Unauthorised changes to data in master files.
IT risks (Continued)
• Unauthorised changes to systems or programs.
• Failure to make necessary changes to systems or
programs.
• Input by people or systems without authorised
access.
• Potential loss of data or inability to access data as
required.
• Management’s failure to commit sufficient resources to
address IT security risks may adversely affect internal
control by allowing improper changes to be made to
computer programs or to data, or unauthorised
transactions to be processed.
• Inconsistencies between the entity’s IT strategy and
its business strategies.
• Changes in the IT environment.
Evaluation of monitoring
When evaluating the ongoing monitoring the
following issues might be considered:
• Periodic comparisons of amounts recorded with the
accounting system and with physical assets.
• Responsiveness to internal and external auditor
recommendations to strengthen internal controls.
• Extent to which training seminars, planning sessions
and other meetings provide information on effective
operation of controls.
• Effectiveness of internal audit activities.
• Extent to which personnel obtain evidence on internal
control function.
Hard and soft control
• Management designs and sets in place a set of
rules, physical constraints and activities called
‘internal controls’. Due to the explicit, formal and
tangible character of these controls, these controls
are generally referred to as hard controls.
• Soft controls are the intangible factors in an
organisation that influence the behaviour of
managers and employees.
• Whereas soft controls are founded in the culture
or climate of an organisation, the hard-controls
are more explicit, formal and visible.
Seven factors influence the way people
examine their control activities
1. Clarity for directors, managers and employees as to
what constitutes desirable and undesirable behaviour.
2. Role-modelling among administrators, management
or immediate supervisors.
3. Achievability of goals, tasks and responsibilities set.
4. Commitment in the organisation.
5. Transparency of behaviour.
6. Openness to discussion of viewpoints, emotions,
dilemmas and transgressions.
7. Enforcement of behaviour, such as appreciation of
desirable behaviour, sanctioning of undesirable
behaviour.
Design and implementation of internal
control
• The auditor is required to evaluate the design
of a controls and determine whether they have
been implemented.
• Evaluating the design of a control involves
considering whether the control is capable of
effectively preventing or detecting and
correcting, material misstatements.
Methods for obtaining controls audit
evidence
Risk assessment procedures to obtain audit
evidence about the design and implementation
of relevant controls may include:
a. Inquiring of entity personnel
b. Observing and re-performing the application of
a specific control
c. Inspecting documents and reports
d. Tracing transactions through the information
system.
Preliminary assessment of control risk
• Consider the results of previous audits that
involved evaluating the operating effectiveness
of internal control.
• Discuss the possibility of audit risk with audit
firm personnel.
• Interview entity personnel to find evidence of
management’s commitment to the design,
implementation and maintenance of sound
internal control.
• Knowledge of the industry and the
environment.