Accounting Information
Systems
Chapter 6: Computer-Based
Information Systems Controls
Chapter 6: Learning Objectives
1. Describe the threats to an AIS and discuss why these threats are
growing.
2. Explain the basic concepts of control as applied to business
organizations.
3. Describe the major elements in the control environment of a business
organization.
4. Describe control policies and procedures commonly used in business
organizations.
5. Evaluate a system of internal accounting control, identify its
deficiencies, and prescribe modifications to remedy those
deficiencies.
6. Conduct a cost-benefit analysis for particular threats, exposures,
risks, and controls.
2
Introduction
• This chapter discusses the types of threats a company
faces.
• It also presents the five interrelated components of the
Committee of Sponsoring Organizations (COSO’s)
internal control model.
3
Threats to Accounting
Information Systems
• What are examples of natural and political disasters?
– fire or excessive heat
– floods
– earthquakes
– high winds
– war
4
Threats to Accounting
Information Systems
• What are examples of software errors and equipment
malfunctions?
– hardware failures
– power outages and fluctuations
– undetected data transmission errors
5
Threats to Accounting
Information Systems
• What are examples of unintentional acts?
– accidents caused by human carelessness
– innocent errors of omissions
– lost or misplaced data
– logic errors
– systems that do not meet company needs
6
Threats to Accounting
Information Systems
• What are examples of intentional acts?
– sabotage
– computer fraud
– embezzlement
7
Why are AIS Threats Increasing?
• Increasing numbers of client/server systems mean that
information is available to an unprecedented number of
workers.
• Because LANs and client/server systems distribute data to
many users, they are harder to control than centralized
mainframe systems.
• WANs are giving customers and suppliers access to each
other’s systems and data, making confidentiality a concern.
8
Why is Control Needed
• Any potential adverse occurrence or unwanted event
that could be injurious to either the accounting
information system or the organization is referred to as
a threat or an event.
• The potential dollar loss should a particular threat
become a reality is referred to as the exposure or
impact of the threat.
• The probability that the threat will happen is the
likelihood associated with the threat.
9
The primary objective of AIS?
• To control the organization so the organization can achieve its
objectives
• Management expects accountants to:
• Take a proactive approach to eliminating system threats.
• Detect, correct, and recover from threats when they occur.
10
Overview of Control Concepts
What is the traditional definition of internal control?
Internal control is the plan of organization and the methods
a business uses to safeguard assets, provide accurate and
reliable information, promote and improve operational
efficiency, and encourage adherence to prescribed
managerial policies.
11
Internal Controls
• Processes implemented to provide assurance that the following
objectives are achieved:
• Safeguard assets
• Maintain sufficient records
• Provide accurate and reliable information
• Prepare financial reports according to established criteria
• Promote and improve operational efficiency
• Encourage adherence with management policies
• Comply with laws and regulations
12
Functions of Internal Controls
• Preventive controls
• Deter problems from occurring
• Detective controls
• Discover problems that are not prevented
• Corrective controls
• Identify and correct problems; correct and recover from the
problems
13
Internal Control Classifications
• The specific control procedures used in the internal
control and management control systems may be
classified using the following four internal control
classifications:
1. Preventive, detective, and corrective controls
2. General and application controls
3. Administrative and accounting controls
4. Input, processing, and output controls
14
Examples of Controls
• General controls
• Controls for design, security and use of Information Systems
throughout the organisation
• Application controls
• Specific controls for each application
• User functionality specific
15
General Controls
• Implementation controls
• Audit system development
• Ensure properly managed and controlled
• Ensure user involvement
• Ensure procedures and standards are in use
• Software controls
• Authorised access to systems
16
General Controls
• Hardware controls
• Physically secure hardware
• Monitor for and fix malfunction
• Environmental systems and protection
• Backup of disk-based data
17
General Controls
• Computer operations controls
• Day-to-day operations of Information Systems
• Procedures
• System set-up
• Job processing
• Backup and recovery procedures
18
General Controls
• Data security controls
• Prevent unauthorised access, change or destruction
• When data is in use or being stored
• Physical access to terminals
• Password protection
• Data level access controls
19
General Controls
• Administrative controls
• Ensure organisational policies, procedures and standards and
enforced
• Segregation of functions to reduce errors and fraud
• Supervision of personal to ensure policies and procedures are
being adhered to
20
Application Controls
• Input controls
• Data is accurate and consistent on entry
• Direct keying of data, double entry or automated input
• Data conversion, editing and error handling
• Field validation on entry
• Input authorisation and auditing
• Checks on totals to catch errors
21
Application Controls
• Processing controls
• Data is accurate and complete on processing
• Checks on totals to catch errors
• Compare to master records to catch errors
• Field validation on update
22
Application Controls
• Output controls
• Data is accurate, complete and properly distributed on output
• Checks on totals to catch errors
• Review processing logs
• Track recipients of data
23
Control Frameworks
• COBI T
• Framework for IT control
• COS O
• Framework for enterprise internal controls (control-based
approach)
• C OS O-ER M
• Expands C OS O framework taking a risk-based approach
24
COBIT Framework
• Current framework version is C OBI T 2019
• Based on the following principles:
• Meeting stakeholder needs
• Covering the enterprise end-to-end
• Applying a single, integrated framework
• Enabling a holistic approach
• Separating governance from management
25
C O S O Internal Control –
Integrated Framework
• There are five components of the C OS O Internal Control –
Integrated Framework
• Control environment
• Risk assessment
• Control activities
• Information and communication
• Monitoring
26
The Control Environment
• The first component of COSO’s internal control model is
the control environment.
• The control environment consists of many factors, including
the following:
1. Commitment to integrity and ethical values
2. Management’s philosophy and operating style
3. Organizational structure
4. The audit committee of the board of directors
5. Methods of assigning authority and responsibility
6. Human resources policies and practices
7. External influences
27
Control Activities
• The second component of COSO’s internal control model
is control activities.
• Generally, control procedures fall into one of five
categories:
1. Proper authorization of transactions and activities
2. Segregation of duties
3. Design and use of adequate documents and records
4. Adequate safeguards of assets and records
5. Independent checks on performance
28
Risk Assessment
• The third component of COSO’s internal control model is risk
assessment.
• Companies must identify the threats they face:
– strategic — doing the wrong thing
– financial — having financial resources lost, wasted, or stolen
– information — faulty or irrelevant information, or unreliable
systems
29
Risk Assessment
• Companies that implement electronic data interchange
(EDI) must identify the threats the system will face,
such as:
1. Choosing an inappropriate technology
2. Unauthorized system access
3. Tapping into data transmissions
4. Loss of data integrity
5. Incomplete transactions
6. System failures
7. Incompatible systems
30
Risk Assessment
Some threats pose a greater risk because the
probability of their occurrence is more likely. For
example:
• A company is more likely to be the victim of a
computer fraud rather than a terrorist attack.
• Risk and exposure must be considered together.
31
Estimate Cost and Benefits
• No internal control system can provide foolproof
protection against all internal control threats.
• The cost of a foolproof system would be prohibitively
high.
• One way to calculate benefits involves calculating
expected loss.
32
Estimate Cost and Benefits
• The benefit of a control procedure is the difference
between the expected loss with the control procedure(s)
and the expected loss without it.
Expected loss = risk × exposure
33
Information and Communication
• The fourth component of COSO’s internal control model
is information and communication.
34
Information and Communication
• Accountants must understand the following:
1. How transactions are initiated
2. How data are captured in machine-readable form or converted from source
documents
3. How computer files are accessed and updated
4. How data are processed to prepare information
5. How information is reported
6. How transactions are initiated
35
Information and Communication
• All of these items make it possible for the system to have an
audit trail.
• An audit trail exists when individual company transactions
can be traced through the system.
36
Monitoring Performance
• The fifth component of COSO’s internal control model is
monitoring.
• What are the key methods of monitoring performance?
– effective supervision
– responsibility accounting
– internal auditing
37
Monitoring Performance…
• Perform internal control evaluations (e.g., internal audit)
• Implement effective supervision
• Use responsibility accounting systems (e.g., budgets)
• Monitor system activities
• Track purchased software and mobile devices
38
Monitoring Performance…
• Conduct periodic audits (e.g., external, internal, network
security)
• Employ computer security officer
• Engage forensic specialists
• Install fraud detection software
• Implement fraud hotline
39
References
i. Marshall B. Romney& Paul J. Steinbar(2021). Accounting
Information Systems (15th Edition), Pearson Education
ii. Gelinas, U. J., Dull, R. B., & Wheeler, P. R. (2018).
Accounting information systems (11th international),
Cengage Learning Australia.
iii. Simkin, M. G., Worrell, J. L. & Savage, A. A. (2019). Core
concepts of accounting information systems (Fourteenth
edition): John Wiley & Sons
iv. Quinn, M., & Strauss, E. (Eds.) (2018). The Routledge
companion to accounting information systems, Routledge.
40