0% found this document useful (0 votes)
18 views46 pages

Understanding Internal Control Systems

Module 3 AA BCOM 5TH SEM

Uploaded by

Sreya
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
18 views46 pages

Understanding Internal Control Systems

Module 3 AA BCOM 5TH SEM

Uploaded by

Sreya
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

MODULE 3

INTERNAL CONTROL
• Whole system of control established by the management for the
proper conduct of various activities of the organization.
• It is the overall control adopted by the organization
• Number of checks and controls exercised in business to ensure
efficient and economic working.
• It comprises of internal check, internal audit, accounting control and
administrative control.
Definition
• W.W. Bigg: "Internal Control is best regarded as indicating the whole
system of controls, financial and otherwise, established by the
management in the conduct of a business including internal check,
internal audit and other forms of control.“
Features
i) Internal control is a system of controls.
ii) Controls are established over financial and non financial areas.
iii) The mechanism of control may manifest itself in the forms of
internal check, internal audit or other forms.
iv) Devising and installation of internal control is the responsibility of
management.
v) An efficient internal control system in operation allows the auditor
to rely greatly on the financial data generated with only test
checking of select items.
Administrative
Financial controls
controls
• Accounting • Plans of the
control organization.
• Operating control • Quality control
• Budgetary control • Performance
• Internal auditing reports
Objectives
• To ensure adherence to policies and procedures
• Safeguarding of assets
• To prevent and detect frauds and errors
• To see all transactions are recorded
• To ensure timely preparation of reliable information
• To promote operational efficiency
• To evaluate the efficiency of performance
Uses

For the organisation For the auditor


• Helps to meet its goals • Helps to decide whether audit
• Reliable data is possible
• Safeguards assets and records • Determines the scope of audit
• Promotes operational • Basis of reliance for the audit
efficiency procedures
• Encourages adherence to • No need for detailed checking
policies
Internal Control and Auditor
• If there is a good internal control system, the work of auditor is easy.
• Rely on test checking
• Need a review of internal control system
1. Understand the nature of business of the client
2. Study of accounting routine
3. Study of financial powers
4. Inspection over financial and other accounting duties.
5. Check the degree of internal check system
6. Ascertain about internal auditing system
INTERNAL CONTROL
QUESTIONNAIRE (ICQ)
• List of questions prepared by the auditors to test the adequacy of
internal control system.

• Helps the auditor to find out the merits, demerits and assess the
strength and weakness of the system

• Standardized questionnaire is developed by ICAI.

• Generally contains close ended questions.


Advantages of ICQ

It ensures every aspect is covered

Model of an efficient system

Brings to light the strength and weakness in


the system
Rapid assessment of the system

Indicate where detailed checking is needed.


Internal Control and Computerized
Environment

• Control procedures include both manual and computer procedures.


• Internal control procedures may be grouped into General EDP Controls and
EDP Application Controls

General controls Application Controls


• Overall controls • Specific control
affecting EDP functions procedures
General Controls

Organisation and Data entry and


Computer
management programme
operation controls
controls controls

System
development and System software Back up and
maintenance controls recovery controls
controls
Application Controls

Documentation Processing
Input controls
controls controls

Output Master file


controls controls
INTERNAL CHECK
• Arrangement of duties among employees in such a way that the work
done by one employee is automatically checked by another
employee.
• No chance of errors and frauds
• Specialisation of work
“ A system of internal check is an arrangement of staff duties whereby
no one person is allowed to carry through and to record every aspect of
a transaction, so that, without collusion between two or more persons ,
fraud is prevented and at the same time the possibilities of errors are
reduced to a minimum.” – Spicer and Pegler
Objectives of Internal Check
Moral check over staff
Reliable and adequate information
Protection to the resources of the business
No work is left unrecorded
Allocation of duties and responsibilities
Reduce the occurrence of errors and frauds
Increase efficiency of clerks
Preparation of final accounts with ease
Ensures that one person does not perform any single task
Principles of a good Internal
Check system
Separation of
Division of work Job rotation Authority levels custody and
recording

Well established
Accounting Cross checking Compliance
policies and
controls of transactions with statutes
procedures

Preparation of
Safe guarding Filing and Use of labour
financial
assets documentation saving devices
statements
Advantages and Disadvantages
of Internal Check
Advantages Disadvantages
Difficult to commit fraud Expensive
Dishonesty of staff can be found Quality is sacrificed
Allocation of responsibility If not properly organised –
Moral check on employees disorder in work
Greater efficiency in work
Helpful to the auditor
Duties of an auditor as regards
Internal Check
Should call for a brief statement from his client
Should examine the system in the light of size and nature of business
Should see whether the system has any errors and frauds
Careful examination of system
If not defective- can avoid in-depth checking
Select representative transactions or particular books
Should not be negligent
If defective- detailed checking
INTERNAL AUDIT

• Independent appraisal of activity within an organisation for the


review of accounting, financial and other business practices.

• Review by a team of experts

“Internal auditing consists of a continuous , critical review of financial


and operating activities by a staff of auditors functioning as full time
salaried employees.” – Prof. walter B Meigs
Features of Internal Audit

• It is a type of control

• Performed by salaried employees

• Audit of accounts

• Staff may not possess professional audit qualifications


Objectives of Internal Audit
• To comment on the effectiveness of internal control system.
• Verify accuracy and authenticity of accounting records
• Detection and prevention of errors and frauds
• To ensure that standard accounting practices are followed
• Safeguarding of assets
• To suggest ways to improve
• To ensure acquisition and disposal of assets are under proper
authority.
• To ensure liabilities are valid
Advantages and Disadvantages of Internal Audit

Advantages Disadvantages
Detection and Prevention of errors Expensive
and frauds. Influence of management
Test the accuracy, reliability of No prescribed qualification for
accounting information internal auditor
Bring out weakness and Inefficient audit staff
inefficiencies
Provide suggestion
Early completion of annual audit
Assistance to independent auditor
Internal Auditor v/s
Basis
Independent
Internal Auditor
Auditor
External Auditor
Appointment Management Shareholders or by government
Employee Regular employee Not an employee
Status No independent status Independent of management
Qualification No prescribed qualification Must have professional qualifications

Scope Determined by management Laid down by statute


Approach To ensure that accounting information To ensure that the financial statements
presented by the management is show a true and fair view of the company
accurate
Responsibility To the management To the Shareholders or to the government
Watch dog Watch dog of management Watch dog for shareholders
Procedure Detailed checking Test checking
Periodicity Throughout the year After the end of financial year
Difference between Internal Check,
Internal Control and Internal Audit
Internal Check Internal Control Internal Audit
Arrangement of work in such a Whole system of controls Continuous process of
way that the work done by established by the examining the operations of a
one person is automatically management in the conduct of concern by its employees
checked by another business

Scope- limited Scope – very wide Scope - broad


Part of internal control Includes internal check, Part of internal control
internal audit and other types
of controls
Aim- prevention of errors and Detection and prevention of Detection of errors and frauds
frauds errors and frauds
Device for doing the work Device for both doing and Device for checking the work
checking the work
AUDIT RISK
• Audit risk means the risk that the auditor gives an
inappropriate audit opinion when the financial
statement are materially misstated. Thus, it is the
risk that the auditor may fail to express an
appropriate opinion in an audit assignment.

• Audit Risk could be simply understood as follows:


During the audit of a company if the financial
statements of that company are misstated and those
misstatements are material in nature, then there will
be a risk that audit opinion given by the auditor
regarding audit of that company would be incorrect.
Then that risk will be known as Audit Risk.
What is not included in Audit Risk?

• Audit risk does not include the risk that the auditor might
express an opinion that the financial statements are
materially misstated when they are not. This risk is ordinarily
insignificant.
• Further, audit risk is a technical term related to the process
of auditing; it does not refer to the auditor’s business risks
such as loss from litigation, adverse publicity, or other
events arising in connection with the audit of financial
statements.
Components of Risk of Material Misstatement

A. Risks of material misstatement at


the assertion level consist of two
components:
• Inherent risk and
• Control risk
• Inherent risk and control risk are the
entity’s risks; they exist independently
of the audit of the financial statements.
B. Detection Risk
From the above, it is clear that –
Audit Risk = Risk of Material Misstatement x Detection Risk----- (1)

Risk of Material Misstatement= Inherent Risk x Control Risk ----- (2)


From (1) and (2), we arrive at-
Audit Risk = Inherent Risk x Control Risk x Detection Risk
Inherent risk
• Inherent risk is higher for some assertions and related classes of
transactions, account balances, and disclosures than for others. For
example, technological developments might make a particular
product obsolete. Factors in the entity and its environment may also
influence the inherent risk related to a specific assertion.

Example

A lack of sufficient working capital to continue operations or a declining industry


characterised by a large number of business failures.
Control risk
• Control risk is a function of the effectiveness of the design,
implementation and maintenance of internal control by
management. However, internal control can only reduce but not
eliminate risks of material misstatement in the financial
statements. This is because of the inherent limitations of internal
control.
• Example:
The possibility of human errors or mistakes, or of controls being circumvented bycollusion. Accordingly, some
control risk will always exist
Detection Risk
• Auditor checks the efficiency and effectiveness of various control
systems in place. He would do that by making observation,
inspection, enquiry, etc. In addition to these, the auditor would also
employ sampling techniques to check few sales transactions from
beginning to end. However, despite all these procedures, the auditor
may not detect the items which have been stolen or misappropriated.
IDENTIFYING AND ASSESSING THE RISKS OF
MATERIAL MISSTATEMENT

• Objective of Auditor as per SA 315: As per SA 315 - “Identifying and


Assessing the Risks of Material Misstatement through Understanding
the Entity and its Environment”, the objective of the auditor is to
identify and assess the risks of material misstatement, whether due to
fraud or error, at the financial statement and assertion levels, through
understanding the entity and its environment…
Identify and assess the risks of material misstatement

1) The auditor shall identify and assess the risks of material


misstatement at:
• the financial statement level
• the assertion level for classes of transactions, account balances,
and disclosures
To provide a basis for designing and performing further audit
procedures
2) For the purpose of Identifying and assessing the risks of
material misstatement, the auditor shall:

• Identify risks throughout the process of obtaining an understanding of


the entity and its environment, including relevant controls that relate to
the risks, and by considering the classes of transactions, account
balances, and disclosures in the financial statements;
• Assess the identified risks, and evaluate whether they relate more
pervasively to the financial statements as a whole and potentially affect
many assertions;
• Relate the identified risks to what can go wrong at the assertion level,
taking account of relevant controls that the auditor intends to test.
Risk Assessment Procedure
• Definition: The audit procedures performed to
obtain an understanding of the entity and its
environment, including the entity’s internal
control, to identify and assess the risks of
material misstatement, whether due to fraud or
error, at the financial statement and assertion
levels.
What is included in Risk Assessment
Procedures ?

The risk assessment procedures shall include the following:

(a) Inquiries of management and of others within the entity who in the auditor’s
judgment may have information that is likely to assist in identifying risks of
material misstatement due to fraud or error.

(b) Analytical procedures.

(c) Observation and inspection.


• Inquiries of Management and Others Within the Entity: The auditor
may also obtain information, or a different perspective in identifying
risks of material misstatement, through inquiries of others within the
entity and other employees with different levels of authority.
• Analytical Procedures: Analytical procedures performed as risk
assessment procedures may include both financial and non-financial
information, for example, the relationship between sales and square
footage of selling space or volume of goods sold.
• Observation and Inspection: Observation and inspection may support
inquiries of management and others, and may also provide
information about the entity and its environment.
Example
Examples of such audit procedures include observation or inspection of the
following:
The entity’s operations.
Documents (such as business plans and strategies), records, and internal
control manuals.
Reports prepared by management (such as quarterly management reports and
interim financial statements) and those charged with governance (such as minutes
of board of director’s meetings)
The entity’s premises and plant facilities.
Internal control Check List
• This is a series of instructions and/or questions which a member of the auditing
staff must follow and/or answer. Answers to the check list instructions are usually
Yes, No or Not Applicable. This is framed having regard to the desirable elements
of control.
Example
• Are tenders called before placing orders?
• Are the purchases made on the basis of a written order?
• Is the purchase order form standardized?
• Are purchase order forms pre-numbered?
• Are the inventory control accounts maintained by persons who have nothing to do
with custody of work, receipt of inventory, inspection of inventory and purchase
of inventory?
• The complete check list is studied by the Principal/Manager/Senior to ascertain
existence of internal control and evaluate its implementation and efficiency.
INTERNAL CONTROL AND IT ENVIRONMENT

1. Controls in Manual and IT System: The use of manual or automated elements in internal
control affects the manner in which transactions are initiated, recorded, processed, and
reported:
• Controls in a manual system may include such procedures as approvals and reviews of
transactions, and reconciliations and follow- up of reconciling items. Alternatively, an
entity may use automated procedures to initiate, record, process, and report
transactions, in which case records in electronic format replace paper documents.
• Controls in IT systems consist of a combination of automated controls (for example,
controls embedded in computer programs) and manual controls. Further, manual
controls may be independent of IT, may use information produced by IT, or may be
limited to monitoring the effective functioning of IT and of automated controls, and to
handling exceptions.
2. Use of IT: An entity’s mix of manual and automated elements in internal control varies
with the nature and complexity of the entity’s use of IT.
[Link], IT benefits an entity’s internal control by enabling an
entity to:
• Consistently apply predefined business rules and perform complex
• calculations in processing large volumes of transactions or data;
• Enhance the timeliness, availability, and accuracy of information;
• Facilitate the additional analysis of information;
• Enhance the ability to monitor the performance of the entity’s activities
and its policies and procedures;
• Reduce the risk that controls will be circumvented; and
• Enhance the ability to achieve effective segregation of duties by
implementing security controls in applications, databases, and
operating systems.
Benefits of IT in an Entity’s
Internal Control
4. IT also poses specific risks to an entity’s internal control, including, for example:
• Reliance on systems or programs that are inaccurately processing data, processing
inaccurate data, or both.
• Unauthorised access to data that may result in destruction of data or improper
changes to data, including the recording of unauthorised or non- existent transactions, or
inaccurate recording of transactions. Particular risks may arise where multiple users access a
common database.
The possibility of IT personnel gaining access privileges beyond those necessary to perform
their assigned duties thereby breaking down segregation of duties.
• Unauthorised changes to data in master files.
• Unauthorised changes to systems or programs.
• Failure to make necessary changes to systems or programs.
• Inappropriate manual intervention.
• Potential loss of data or inability to access data as required.
[Link]: Manual elements in internal control may be more suitable
where judgment and discretion are required.
[Link]: Manual elements in internal control may be less reliable than
automated elements because they can be more easily bypassed, ignored,
or overridden and they are also more prone to simple errors and mistakes.
Consistency of application of a manual control element cannot therefore
be assumed.
[Link] of Entity’s Information System: The extent and nature of the risks
to internal control vary depending on the nature and characteristics of the
entity’s information system. The entity responds to the risks arising from
the use of IT or from use of manual elements in internal control by
establishing effective controls in light of the characteristics of the entity’s
information system.

You might also like