Chapter 8
Internal controls
Recording internal control
• Internal control is a process designed and effected
by the directors and others to provide reasonable
assurance about the achievements of entity
objectives with regard:
• Reliability of financial reporting
• Efficiency and effectiveness of the operations
• Compliance with the laws and regulation
• Safeguarding the investments of the shareholder
Recording internal control
• The first thing that auditor has to do in a new audit
is to record the clients accounting system.
• Where its repeat audit, the auditor must ensure
that there records of client systems are updated and
remain accurate.
• There are three ways of recording the system.
1) Narrative notes
2) Flow charts
3) Questionnaires
Recording internal control (Narrative)
• Where narrative notes, the auditor simply writes a few
paragraph.( for example what happens to the supplier invoices
when its received, how it may be matched with goods received
notes how the calculation is checked , how it is posted into the
payable ledger and how the amount is eventually paid.)
• narrative notes can be relatively quickly to prepare. Typically
you observes what happens , you asks the client what happens,
and you may also look at the accounting procedures which they
have established more formally.
• The main problems that arises with the narrative notes is the
structure and discipline, its very easy for the documents to
appear in narrative , and then not be mentioned again and the
audit team is then wondering what happens to these
documents where can it be found.
Recording internal control (Flowcharts)
• In flowcharts diagram are used to show the
documents, the file , the calculation and the checks
that are performed. Flowcharts can be somewhat
slower to produce and certainly more difficult to
amend.
• Flowcharting imposes a great discipline on how
system are recorded as it has very specific rules
about how flowcharts are to be drawn.
Recording internal control (questionnaires )
• Questionnaires can be used to record the accounting system
but they go slightly further then mere recording , they actually
begin to evaluate the accounting system.
• There are two main patterns of questionnaires
1) Internal control questionnaires (ICQs)
2) Internal control evaluation questionnaires (ICEQs)
In ICQs when you get the answer “yes ” to a question , it is good
sign, an example of question could be
“Are supplier invoices cancelled when they are paid” the answer
“yes ” is good and answer “no ”is bad because it means that
those invoices could be paid second time.
• An ICQ lists all possible controls for each area of the accounts;
the client’s system is examined to see which controls exist
Recording internal control (questionnaires )
1) Internal control evaluation questionnaires (ICEQs)
In this case answer “no” is good and typical question might
be “Can supplier invoices be paid twice” this involves asking
negative questions.
Internal control evaluation questionnaires are rather more
open ended and flexible. What they are addressing is internal
control objectives (The mistakes and error we want to stop).
Internal control questionnaires seek out specific internal
control which can help internal control objectives to be
achieved. ICEQs will almost certainly require greater skill
from the auditor. Instead of simply having to find out if
invoices are cancelled, you have to assess whether or not
invoices are liable to paid twice and that’s rather more highly
skilled operations.
Recording internal control (questionnaires )
There are five components of internal control
1) Control environment
2) Risk assessment
3) Control activities
4) Information and communication
5) Monitoring system
Internal control limitation
1. Cost vs benefit: The cost of establishing a system of internal
control may be greater then benefits. To take ridiculous
example, its very unlikely that any one is going to establish a
system of internal control over the issue of paperclips or
envelops. The amount of management time taken with
authorizing trivial amount of expenditure makes it
uneconomic.
2. Human error: For example , one person makes out an invoice
using the wrong selling price and another one checks it and
does not see the error , this is always a possibility even in
the best regulated circumstances.
3. Collusion : Where two or more cooperate to get around the
internal control system, collusion might be to carry out
fraud, or it might be to cover up some error that was made.
Internal control limitation
[Link] pass of control: say someone has forgotten to order a
vital piece of equipment and that to speed matter up ,
instead of getting the proper authorization to purchase ,
they issue the purchase order without authorization. They
are by passing the controls it may be done with best
possible intentions , but if by pass of control becomes too
common essentially the control are not operating.
5. Non -routine transactions : These are the transaction that
are so rare that no system of internal control is devised. An
example can be disposal of fixed assets. Many fixed assets
are scraped when they are disposed off and to establish a
system of internal control might not have been though
worthwhile.
Internal controls
ACCAMAP
1) Authorization
2) Comparison
3) Computer controls
4) Arithmetical controls
5) Maintaining a trial balance and control accounts
6) Accounting reconciliation
7) Physical controls
Application and general controls
• IT affects the way in which control activities are
implemented. It is important that auditors assess
how controls over IT maintain the integrity and
security of information held. Such controls are
normally divided into two categories:
• • Application
• • General
Application controls
• Application controls are either manual or automated and
typically operate at the business process level and apply to
the processing of transactions.
• Examples include:
• batch total checks (e.g. when entering batches of invoices
onto the accounts system)
• sequence checks
• matching master files to transaction records (e.g. sales
invoice discounts)
• arithmetic checks
• range checks (to ensure that data stays within reasonable
ranges)
• existence checks (e.g. to check employees exist)
General control
• General IT controls are policies and procedures that
relate to many applications and support the
effective functioning of application controls by
helping to ensure the continued proper operation
of information systems,
• e.g. controls over:
• • system software acquisition
• • program change and maintenance
• • access security – passwords, door locks, swipe
cards
• • backup procedures.
Revenue (Sales) Cycle
The objective is to ensure all valid sales are recorded accurately
and cash is received promptly
RAISING
ORDER GOODS THE SALE IS RECODED
TAKEN DISPATCHED INVOICE
PAYMENT IS
RECEIVED &
RECORDED
ORDER TAKEN
GOODS DISPATCHED
RAISING THE INVOICE
RECORDING OF THE SALE
PAYMENT IS RECEIVED AND RECORDED
TEST OF CONTROLS- Sales Cycle
1. Review new customers’ files for references, credit checks, authorization by senior staff
2. Ensure credit limits for customers are not exceeded by trying to post a sale which is beyond
the credit limit
3. Match GDN with sales invoices checking prices, quantities, arithmetical accuracy, VAT and
postings
4. Verify credit notes with correspondence, original invoices, amounts and authorisation
5. Check numerical sequence of invoices, credit notes, GDN’s and sales orders – enquire into
missing numbers
6. Review sales ledger reconciliations
7. Agree sample of accounts in sales ledger re-performing additions and balances carried
down
8. Inspect correspondence on overdue accounts
9. Review process for dispatch of statements and ensure regularly sent
[Link] bad debt write offs are authorised by managers
Purchase Cycle
Requisition RECEIPT RECORDING
GOODS
raised, and OF OF THE
RECEIVED
order placed INVOICE PURCHASE
PAYMENT MADE TO
SUPPLIER
Requisition raised, and order placed
GOODS RECEIVED
RECEIPT OF INVOICE
RECORDING OF THE PURCHASE
PAYMENT MADE TO SUPPLIER
Payroll Cycle
TIME INFORMATION STANDING PROCESSING
SHEETS ARE INPUT ONTO DATA &
SUBMITTED THE COMPUTER INPUT RECORDING
OF PAYROLL
PAYMENT MADE TO
STAFF
TIME SHEETS/ CLOCK CARDS
ARE SUBMITTED
INFORMATION INPUT ONTO THE COMPUTER
STANDING DATA INPUT
PROCESSING & RECORDING OF PAYROLL
PAYMENT MADE TO STAFF
Tests of Control - Payroll Cycle
1. A sample of wages and salaries should be re-performed
2. The calculation will agree with authorised pay rates and timesheets
3. Test sample of timesheets for authorisation (esp. overtime)
4. Attend a cash pay out looking for two people present & one wage
per person
5. Review wages reconciliation and ensure done regularly
6. Ensure changes to payroll are authorised
7. Check reasonableness of payroll deductions and ensure authorised
8. Test controls over unclaimed wages
Inventory Cycle
GOODS INVENTORY MATERIAL FINISHED
ARRIVE STORED UNTIL SENT FOR GOODS SENT
INTO NEEDED PRODUCTION TO
INVENTORY CUSTOMER
INVENTORY IS
COUNTED
GOODS ARRIVE INTO INVENTORY
INVENTORY STORED UNTIL NEEDED
MATERIAL SENT FOR PRODUCTION
FINISHED GOODS SENT TO CUSTOMER
INVENTORY IS COUNTED
Tests of Control - Inventory
1. Ensuring environment suitably secure and safe
2. For a sample of inventory records and agree to GRN or GDN
3. Confirm that all movements are authorized
4. For a sample of GRN and GDN’s agree to inventory records
5. Test check inventory count and investigate discrepancies
6. Review sequentially numbered GRN and GDN for
completeness
7. Attend inventory count to ensure it is carried out correctly