0% found this document useful (0 votes)
5 views22 pages

Internal Control & Risk Assessment Guide

This document discusses the importance of internal control and risk assessment in accounting information systems (AIS), highlighting their role in ensuring financial reporting integrity, compliance, and asset protection. It outlines key components, types of controls, best practices, and the risk assessment process necessary for effective implementation. Additionally, it emphasizes the significance of monitoring activities and performance reviews to maintain the reliability and security of financial data.

Uploaded by

alyza.ambat
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
5 views22 pages

Internal Control & Risk Assessment Guide

This document discusses the importance of internal control and risk assessment in accounting information systems (AIS), highlighting their role in ensuring financial reporting integrity, compliance, and asset protection. It outlines key components, types of controls, best practices, and the risk assessment process necessary for effective implementation. Additionally, it emphasizes the significance of monitoring activities and performance reviews to maintain the reliability and security of financial data.

Uploaded by

alyza.ambat
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

INTERNAL

CONTROL AND
RISK
ASSESSMENT
BY: MIKHAJOY T. MANALO, MBA,
CTT
INTRODUCTION

Internal control and risk assessment are vital components


of an effective accounting information system (AIS). They
ensure the integrity of financial reporting, compliance with laws
and regulations, and the safeguarding of assets. This document
outlines the key elements of internal control, types of risks
associated with accounting information systems, and best
practices for implementing effective controls.
INTERNAL CONTROL

Internal control refers to the processes and procedures


implemented by an organization to achieve its objectives in
operational efficiency, reliable financial reporting, and
compliance with applicable laws. It encompasses a range of
activities designed to prevent errors and fraud, ensure the
accuracy of financial data, and promote accountability within
the organization.
INTERNAL CONTROL

IMPORTANCE:
◦ Ensure compliance with laws and regulations.
◦ Protect assets from theft or misuse.
◦ Enhance operational efficiency through accurate reporting
OBJECTIVES OF INTERNAL CONTROL
◦ Reliable Financial Reporting
Ensure accuracy and timeliness of financial statements.
◦ Compliance
Adhere to applicable laws, regulations, and internal policies.
◦ Operational Efficiency
Streamline processes to reduce errors and improve
performance.
COMPONENTS
OF INTERNAL CONTROL
◦ Control Environment - Establishes the organizational culture and ethical
standards.
◦ Risk Assessment - Identifies and analyzes risks that could impede achieving
objectives.
◦ Control Activities - Policies and procedures that mitigate risks.
◦ Information and Communication - Ensures relevant information is
communicated effectively.
◦ Monitoring Activities - Ongoing evaluations to ensure controls are functioning as
intended.
TYPES
OF INTERNAL CONTROL
1. Preventive Controls
Designed to deter errors or fraud before they occur.
Examples include:
◦ Segregation of duties to prevent one individual from
controlling all aspects of a transaction.
◦ Authorization requirements for transactions above a certain
threshold.
TYPES
OF INTERNAL CONTROL
2. Detective Controls
Aimed at identifying errors or irregularities after they
have occurred. Examples include:
◦ Regular reconciliations of accounts.
◦ Internal audits to assess compliance with policies and
procedures
BEST PRACTICES FOR
INTERNAL CONTROLS
 Establish Clear Policies
Develop comprehensive internal control policies that define
roles, responsibilities, and procedures for financial transactions.
 Regular Training
Provide training for employees on internal control procedures
and the importance of compliance.
 Utilize Technology
Implement software solutions that automate control
activities, such as access restrictions and transaction monitoring.
BEST PRACTICES FOR
INTERNAL CONTROLS
 Conduct Regular Audits
Schedule periodic internal audits to evaluate the
effectiveness of controls and identify areas for
improvement.
 Engage Management Oversight
Ensure that senior management is actively
involved in overseeing internal control processes and
addressing identified weaknesses promptly.
RISK ASSESSMENT IN
ACCOUNTING INFORMATION SYSTEM
Risk assessment involves identifying potential threats to the AIS and
evaluating their impact on financial reporting and operational efficiency. Key risks
include:
◦ Data Integrity Risks - Errors or inaccuracies in financial data due to input mistakes or
system malfunctions.
◦ Security Risks - Unauthorized access to sensitive financial information leading to data
breaches or fraud.
◦ Compliance Risks - Failure to adhere to regulatory requirements such as certain tax
laws can result in penalties
RISK ASSESSMENT PROCESS
Step 1: Identify Risks
Consider potential threats to financial reporting and asset security.

Step 2: Analyze Risks


Evaluate the likelihood and impact of identified risks.

Step 3: Implement Controls


Develop strategies to mitigate identified risks through appropriate
control activities.
BEST PRACTICES FOR
RISK ASSESSMENT
 Conduct regular internal audits to verify
the effectiveness of internal controls.
 Engage in ongoing training for employees
on compliance and ethical practices.
 Establish a culture of transparency where
employees feel empowered to report issue
CONTROL AND MONITORING IN
ACCOUNTING INFORMATION SYSTEM
Control activities and monitoring are essential
components of an effective Accounting Information System
(AIS). They ensure the accuracy, reliability, and integrity of
financial reporting while safeguarding assets. This
presentation covers key aspects such as performance
reviews, physical controls, segregation of duties,
information processing controls, and monitoring activities.
CONTROL AND MONITORING IN
ACCOUNTING INFORMATION SYSTEM
Performance Reviews
Performance reviews are systematic evaluations of actual performance
against established benchmarks such as budgets and forecasts. These
reviews help organizations identify variances and initiate corrective actions.

Types of Performance Reviews:


 Comparison of actual results to budgets or forecasts.
 Analysis of trends over time.
 Investigative actions to understand discrepancies.
CONTROL AND MONITORING IN
ACCOUNTING INFORMATION SYSTEM
Physical Controls
Physical controls involve securing assets to prevent unauthorized
access or theft. They are crucial for maintaining the integrity of physical
resources.

Examples of Physical Controls:


 Regular inventory counts to verify asset existence.
 Environmental controls to protect sensitive data and equipment.
 Use of locks, safes, and security systems.
CONTROL AND MONITORING IN
ACCOUNTING INFORMATION SYSTEM
Segregation of Duties
Segregation of duties is a fundamental internal control designed to
minimize the risk of errors or fraud by dividing responsibilities among different
individuals.

Key Responsibilities to Segregate:


 Authorization of transactions.
 Custody of assets.
 Recording transactions.
 Reconciliation activities.
CONTROL AND MONITORING IN
ACCOUNTING INFORMATION SYSTEM
Information Processing Controls
Information processing controls ensure the
accuracy and completeness of data within an AIS. They
include both general controls applicable across the system
and application-specific controls tailored to particular
processes. There are two types of information processing
controls, such as: general controls and application controls.
CONTROL AND MONITORING IN
ACCOUNTING INFORMATION SYSTEM
General Controls
General controls are overarching policies and procedures that apply to the
entire information system environment. They ensure that the overall system operates
effectively and securely, providing a stable foundation for application controls.

Examples:
 Access security
 Change Management
 Data Backup and Recovery
 Physical Security Controls
CONTROL AND MONITORING IN
ACCOUNTING INFORMATION SYSTEM
Monitoring Activities
Monitoring activities assess the effectiveness of internal controls
over time. They provide ongoing oversight and facilitate timely
adjustments when necessary.

Components of Monitoring:
 Regular management reviews and supervisory oversight.
 Periodic audits conducted internally or externally.
 Continuous feedback mechanisms to identify control deficiencies.
CONTROL AND MONITORING IN
ACCOUNTING INFORMATION SYSTEM
Application Controls
Application controls are specific to individual applications within an
AIS. They ensure that transactions are processed accurately, completely, and
in accordance with established policies.

Examples:
 Input Controls
 Processing Controls
 Output Controls
 Authorization Controls
Thank you!

You might also like