0% found this document useful (0 votes)
44 views53 pages

Auditor's Understanding of Internal Controls

The document discusses internal controls and the auditor's understanding of them. It begins by introducing internal controls and their purpose of providing reasonable assurance regarding financial reporting reliability, operational effectiveness and efficiency, and compliance with laws and regulations. It then describes the five components of internal control - control environment, risk assessment, information and communication, control activities, and monitoring. Several of the components are explained in more detail, including their objectives and key elements. In particular, it focuses on understanding the control environment, which sets the tone of an organization and is the foundation of effective internal controls.

Uploaded by

shifa asher
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
44 views53 pages

Auditor's Understanding of Internal Controls

The document discusses internal controls and the auditor's understanding of them. It begins by introducing internal controls and their purpose of providing reasonable assurance regarding financial reporting reliability, operational effectiveness and efficiency, and compliance with laws and regulations. It then describes the five components of internal control - control environment, risk assessment, information and communication, control activities, and monitoring. Several of the components are explained in more detail, including their objectives and key elements. In particular, it focuses on understanding the control environment, which sets the tone of an organization and is the foundation of effective internal controls.

Uploaded by

shifa asher
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

Internal Controls and

Auditor

1
1. Introduction

Preliminary engagement activities

Planning activities
The entity and its
environment
Understanding
Understanding thethe entity
entity
and
and its
its environment
environment
Internal
Internal control
control
Identifying and assessing risks of
material misstatements

Designing and implementing auditor’s


responses to assessed risks

Overall reviewing

Drawing audit conclusions


and reporting
2
4. Understanding the Entity

Perform
Perform risk
risk assessment
assessment procedures
procedures to to gather
gather
information
information about
about the
the entity
entity and
and its
its environment
environment

Objectives,
Objectives,
Industry,
Industry, Selection
Selection and
and Measurement
Measurement
strategies,
strategies,
regulatory,
regulatory, Nature
Nature of
of the
the application
application of
of and
and review
review of
of
and
and related
related
and
and other
other entity
entity accounting
accounting financial
financial
business
business
factors
factors policies
policies performance
performance
risks
risks

Internal
Internal control
control

3
INTERNAL CONTROL

Internal control – The process


• designed, implemented and maintained by those
charged with governance, management and other
personnel

• to provide reasonable assurance about the


achievement of an entity’s objectives with regard to

• reliability of financial reporting,


• effectiveness and efficiency of operations, and
• compliance with applicable laws and regulations.

The term “controls” refers to any aspects of one or more of


the components of internal control.
2. Understanding of Internal Control &
General Aspects of Internal Control

Performing
Performing risk
risk assessment
assessment procedures
procedures

To gather information about

The
The entity
entity and
and its
its
Understanding environment
environment
Understanding thethe entity
entity
and
and its
its environment
environment
Internal
Internal control
control

Identifying
Identifying and
and assessing
assessing risks
risks of
of
material
material misstatements
misstatements

5
Obtain an Understanding of Internal
Control

The auditor should obtain an understanding of each of the


five components of internal control in order to plan the audit.
This knowledge is used to:

Identify types of Pinpoint the factors


potential that affect the risk of
misstatement material misstatement

Design tests of
controls and
substantive
procedures

6-6
3. Controls Relevant to the Audit

• An auditor is required to understand internal control


relevant to the audit.

• Although most controls relevant to the audit are


likely to relate to financial reporting, not all controls
that relate to financial reporting are relevant to the
audit.

• It is a matter of the auditor’s professional judgment


whether a control, individually or in combination
with others, is relevant to the audit.
7
4. Nature & Extent of the Understanding

• When obtaining an understanding of controls that


are relevant to the audit, the auditor is required, by
performing procedures in addition to inquiry of the
entity’s personnel, to:
– evaluate the design of those controls and
– determine whether they have been implemented.

8
4. Nature & Extent of the Understanding

• Risk assessment procedures can be used


to obtain audit evidence about the design
and implementation of relevant control,
which include:

– inquiring entity personnel;


– observing the application of specific controls;
– inspecting documents and reports; and
– tracing transactions through the information
system relevant to financial reporting.
9
5. Components of Internal Control

• Five components of internal control are:


– The control environment
– The entity’s risk assessment process
– The information system, including the related business
processes, relevant to financial reporting, and
communication
– Control activities
– Monitoring of controls

10
1. Control Environment

• ISA 315 requires the auditor to obtain an


understanding of the control environment.
• The control environment:
– includes the governance and management functions and
the overall attitude, awareness and actions of those
charged with governance and management about the
entity’s internal control and its importance in the entity;
– sets the tone of an organization, influencing the control
consciousness of its people; and
– is the foundation for effective internal control.

11
The Control Environment

The control environment is concerned with the actions,


policies, and procedures that reflect the overall attitude
of the client’s top management, directors, and owners of
an entity about internal control and its importance.
Control Environment

• Elements of control environment include:


– Communication and enforcement of integrity and ethical
values;
– Commitment to competence;
– Participation by those charged with governance –
independence from management, their experience and
stature;
– Management’s philosophy and operating style;
– Organizational structure;
– Assignment of authority and responsibility; and
– Human resource policies and practices.
1. Integrity and Ethical Values

Management actions
to remove incentives
that prompt a person to
behave improperly.
Communication of
behavioral standards
by codes of conduct
and example.
2. Commitment to Competence

Management’s consideration
of the competence levels for
specific jobs and how those
translate into requisite skills
and knowledge.
3. Board of Directors and Audit
Committee
Board delegates
responsibility for internal
control to management and is
charged with regular
independent assessments of
management-established
internal control.
The major stock exchanges
require listed companies to
have an audit committee
composed of entirely
independent directors who
are financially literate.
4. Management’s Philosophy and
Operating Style

Management, through its activities, provides clear signals to


employees about the importance of internal control. For
example, are sales and earnings targets unrealistic, and are
employees encouraged to take aggressive actions to meet those
targets.
5. Organizational Structure

Understanding the client’s


organizational structure
provides the auditor with
an understanding of how
the client’s business
functions and
implements controls.
6. Assignment of Authority and
Responsibility

Formal methods of
communication including:
Top management
memoranda concerning
internal control
Organizational operating
plans
Employee job descriptions
7. Human Resource Policies and
Practices

If employees are honest


and trustworthy, other
controls can be absent
and reliable financial
statements will still result.
Methods by which
persons are hired,
trained, promoted, and
compensated are
important elements of
internal control.
Control Environment

• When assessing the risks of material


misstatement, the auditor considers
favorably if a satisfactory control
environment exists
• However, the control environment in itself
does not prevent, or detect and correct,
material misstatements
2. Entity’s Risk Assessment Process

• The entity’s risk assessment process is another


component of the internal control framework.
• ISA 315 explains it as a process for:
– identifying business risks relevant to financial reporting
objectives;
– estimating the significance of the risks;
– assessing the likelihood of their occurrence; and
– deciding about actions to address those risks.
• The auditor is required to obtain an understanding
whether an entity has such process.

22
Risk Assessment

Client management’s identification and analysis of risks


relevant to the preparation of the financial statements in
accordance with GAAP.

1. Client Management’s Risk Assessment


2. Auditor Risk Assessment
Client Management’s Risk
Assessment

Client management assesses risk as part of designing


and operating internal controls to minimize errors
and fraud. Three steps involve:
i. Identify factors that may increase risk
ii. Determine significance of risk and likelihood of
occurrence
iii. Develop specific actions to reduce risk to an
acceptable level.
Auditor Risk Assessment

The auditor obtains knowledge


about management’s risk
assessment process by:
Determining how management
identifies risks relevant to
financial reporting
Evaluating their significance
and likelihood of occurrence
Deciding the actions needed to
address the risks.
3. Information System and
Communication
• The information system relevant to financial reporting
includes the following areas:
– Significant classes of transactions;
– The procedures by which those transactions are initiated,
recorded, processed and reported in the financial
statements;
– The related accounting records;
– How the information system captures significant events and
conditions;
– The financial reporting process used to prepare the entity’s
financial statements, including significant accounting
estimates and disclosures; and
– Controls surrounding journal entries, including non-standard
journal entries used to record non-recurring, unusual
transactions or adjustments. 26
Information and Communication

Methods used to initiate, record, process, and report an


entity’s transactions and to maintain accountability for
related assets.

 For a small company with active involvement by the owner, a


simple computerized accounting system that involves one
honest, competent accountant may provide an adequate
accounting system.
 A larger company requires a more complex system that
includes carefully defined responsibilities and written
procedures.
4. Control Activities

• The auditor obtains a sufficient


understanding of control activities
– to assess the risks of material misstatement at
the assertion level, and
– to design further audit procedures responsive to
assessed risks.
• Control activities are those policies and
procedures that help to ensure management
directives are carried out.

28
Control Activities

• Good control activities include:


– Appropriate higher level policies on authorization
and adequate authorization limit at each appropriate
level;
– Regular and sufficient performance reviews;
– Sound information processing system with
adequate application controls and general IT
controls;
– Sufficient and adequate physical controls on assets;
and
– Adequate segregation of duties (between
authorization, recording and custody duties).
29
1. Adequate Segregation of
Duties
Separation of the
functions of authorization,
recordkeeping, and
custody.
Separating IT duties from
User Departments
2. Proper Authorization of
Transactions and Activities

General authorization is
permissible for routine
events for which there
are policies to follow.
For some transactions
specific authorization is
needed on a case-by-
case basis.
3. Adequate Documents and
Records

Prenumbered
consecutive documents
so missing items are
noticed
Prepared as near to
transaction time as
possible
Good design with
instructions and
appropriate spaces
4. Physical Control Over Assets
and Records

Deterrents to prevent
physical access.
Access controls to Incorrect
prevent getting into Password
computer system.
Backup and recovery
procedures
5. Independent Checks on
Performance
Personnel are likely to
forget or intentionally
fail to follow
procedures, or they
may become careless
unless someone
observes and evaluates
their performance.
Control Activities

• ISA 315 requires the auditor to obtain


an understanding of how the entity has
responded to risks arising from
information technology.
• The auditor would determine whether
the entity has responded adequately to
the risks arising from IT by establishing
effective general and application
controls.
35
5. Monitoring of Controls

• The auditor is required to obtain an understanding


of the major types of activities that the entity uses
to monitor internal control over financial reporting,
and how the entity initiates corrective actions to its
controls.
• The purpose of monitoring of controls is to assess
the effectiveness of internal control performance
over time.
• Management achieves this monitoring objective
through ongoing activities, separate evaluations
(say internal audit), or a combination of the two.
36
Monitoring

Client management’s ongoing and periodic assessment of


the quality of internal control performance to determine
whether controls are operating as intended and modified
when needed.

 For many companies, especially larger ones, an internal


audit department is essential for effective monitoring.
 To maintain internal audit independence, it is imperative
that they be independent of operating and accounting
departments; and that they report to a high level of
authority, preferably the audit committee of the board of
directors.
Process for Understanding Internal
Control and Assessing Control Risk

A. Phase 1: Obtain and Document Understanding of


Internal Control: Design and Operation

B. Phase 2: Assess Control Risk

C. Phase 3: Design, Perform, and Evaluate Tests of


Controls

D. Phase 4: Decide Planned Detection Risk and


Substantive Tests
11. Documentation

• As stated in Chapter 15, ISA 315 requires an auditor to


document:
– the discussion among the engagement team, and the significant
decisions reached;
– key elements of the understanding obtained regarding each of the
aspects of the entity and its environment and of each of the internal
control components;
– the sources of information from which the understanding was
obtained;
– the risk assessment procedures performed;
– the identified and assessed risks of material misstatement at the
financial statement level and at the assertion level (see Chapter
17);
– the risks identified, and related controls about which the auditor has
obtained an understanding (see Chapter 17).
40
Documenting the Understanding
of Internal Control

Procedure Manuals
and Organizational Flowcharts
Charts

Internal Control
Narrative Description
Questionnaires
The Limitations of an Entity’s
Internal Control

Override of
Internal Control by
Management
Human Errors

or
Mistakes
Collusion

6-42
Information technology controls – General

General IT controls are policies and procedures


that relate to many applications and support the
effective functioning of application controls by
helping to ensure the continued proper operation
of information systems. For example:
– controls over data centre and network operations;
system software acquisition, change and
maintenance; access security; back-up and
recovery; and application system acquisition,
development and maintenance.
IT controls – Application controls

Application controls are controls that apply to


applications that initiate, record, process and report
transactions (such as MS Office, SAP, QuickBooks),
rather than the computer system in general.
Examples are chart of accounts, edit checks of
input data, numerical sequence checks and manual
follow-up of exception reports.
IT risks
• Reliance on systems or programs that are
inaccurately processing data, processing
inaccurate data or both.
• Unauthorised access to data that may result in
destruction of data or improper changes to data.
• The possibility of IT personnel gaining access
privileges beyond those necessary to
perform their assigned duties thereby
breaking down segregation of duties.
• Unauthorised changes to data in master files.
IT risks (Continued)
• Unauthorised changes to systems or programs.
• Failure to make necessary changes to systems or
programs.
• Input by people or systems without authorised
access.
• Potential loss of data or inability to access data as
required.
• Management’s failure to commit sufficient resources to
address IT security risks may adversely affect internal
control by allowing improper changes to be made to
computer programs or to data, or unauthorised
transactions to be processed.
• Inconsistencies between the entity’s IT strategy and
its business strategies.
• Changes in the IT environment.
Evaluation of monitoring

When evaluating the ongoing monitoring the


following issues might be considered:
• Periodic comparisons of amounts recorded with the
accounting system and with physical assets.
• Responsiveness to internal and external auditor
recommendations to strengthen internal controls.
• Extent to which training seminars, planning sessions
and other meetings provide information on effective
operation of controls.
• Effectiveness of internal audit activities.
• Extent to which personnel obtain evidence on internal
control function.
Hard and soft control
• Management designs and sets in place a set of
rules, physical constraints and activities called
‘internal controls’. Due to the explicit, formal and
tangible character of these controls, these controls
are generally referred to as hard controls.
• Soft controls are the intangible factors in an
organisation that influence the behaviour of
managers and employees.
• Whereas soft controls are founded in the culture
or climate of an organisation, the hard-controls
are more explicit, formal and visible.
Seven factors influence the way people
examine their control activities

1. Clarity for directors, managers and employees as to


what constitutes desirable and undesirable behaviour.
2. Role-modelling among administrators, management
or immediate supervisors.
3. Achievability of goals, tasks and responsibilities set.
4. Commitment in the organisation.
5. Transparency of behaviour.
6. Openness to discussion of viewpoints, emotions,
dilemmas and transgressions.
7. Enforcement of behaviour, such as appreciation of
desirable behaviour, sanctioning of undesirable
behaviour.
Design and implementation of internal
control
• The auditor is required to evaluate the design
of a controls and determine whether they have
been implemented.
• Evaluating the design of a control involves
considering whether the control is capable of
effectively preventing or detecting and
correcting, material misstatements.
Methods for obtaining controls audit
evidence
Risk assessment procedures to obtain audit
evidence about the design and implementation
of relevant controls may include:
a. Inquiring of entity personnel
b. Observing and re-performing the application of
a specific control
c. Inspecting documents and reports
d. Tracing transactions through the information
system.
Preliminary assessment of control risk
• Consider the results of previous audits that
involved evaluating the operating effectiveness
of internal control.
• Discuss the possibility of audit risk with audit
firm personnel.
• Interview entity personnel to find evidence of
management’s commitment to the design,
implementation and maintenance of sound
internal control.
• Knowledge of the industry and the
environment.

You might also like