case study 4-5 Pages + charts

profileMbab4
romney_ais14_inppt_07.pptx

Accounting Information Systems

Fourteenth Edition

Chapter 7

Control and Accounting Information Systems

Copyright © 2018 Pearson Education, Inc. All Rights Reserved

Copyright © 2018 Pearson Education, Inc.

Chapter 7: Control and Accounting Information Systems

Slide 1 - ‹#›

If this PowerPoint presentation contains mathematical equations, you may need to check that your computer has the following installed:

1) MathType Plugin

2) Math Player (free versions available)

3) NVDA Reader (free versions available)

1

Learning Objectives (1 of 2)

Explain basic control concepts and why computer control and security are important.

Compare and contrast the COBIT, COSO, and ERM control frameworks.

Describe the major elements in the internal environment of a company.

Describe the control objectives that companies need to set and how to identify events that affect organizational uncertainty.

Copyright © 2018 Pearson Education, Inc.

Chapter 7: Control and Accounting Information Systems

Slide 1 - ‹#›

2

Learning Objectives (2 of 2)

Explain how to assess and respond to risk using the Enterprise Risk Management model.

Describe control activities commonly used in companies.

Describe how to communicate information and monitor control processes in organizations.

Copyright © 2018 Pearson Education, Inc.

Chapter 7: Control and Accounting Information Systems

Slide 1 - ‹#›

3

Why Is Control Needed?

Any potential adverse occurrence or unwanted event that could be injurious to either the accounting information system or the organization is referred to as a threat or an event.

The potential dollar loss should a particular threat become a reality is referred to as the exposure or impact of the threat.

The probability that the threat will happen is the likelihood associated with the threat.

Copyright © 2018 Pearson Education, Inc.

Chapter 7: Control and Accounting Information Systems

Slide 1 - ‹#›

Many organizations have real risks by not adequately protecting their data. Although they may see the threat of the risk, many organizations underestimate the impact and the liklelihood that a threat will occur.

4

A Primary Objective of an AIS

Is to control the organization so the organization can achieve its objectives

Management expects accountants to:

Take a proactive approach to eliminating system threats.

Detect, correct, and recover from threats when they occur.

Copyright © 2018 Pearson Education, Inc.

Chapter 7: Control and Accounting Information Systems

Slide 1 - ‹#›

Internal Controls

Processes implemented to provide assurance that the following objectives are achieved:

Safeguard assets

Maintain sufficient records

Provide accurate and reliable information

Prepare financial reports according to established criteria

Promote and improve operational efficiency

Encourage adherence with management policies

Comply with laws and regulations

Copyright © 2018 Pearson Education, Inc.

Chapter 7: Control and Accounting Information Systems

Slide 1 - ‹#›

Good internal controls are necessary for an organization to achieve its goals.

6

Functions of Internal Controls

Preventive controls

Deter problems from occurring

Detective controls

Discover problems that are not prevented

Corrective controls

Identify and correct problems; correct and recover from the problems

Copyright © 2018 Pearson Education, Inc.

Chapter 7: Control and Accounting Information Systems

Slide 1 - ‹#›

In addition to the functions of internal controls, controls are segregated into two categories:

General controls which ensure that organization’s control environment is stable and well managed.

Application controls that prevent, detect, and correct transaction errors and fraud in application programs. These controls are concerned with the accuracy, completeness, validity, and authorization of the data captured, entered, processed, stored, transitted to other systems and reported.

7

Foreign Corrupt Practices (FCPA) and Sarbanes–Oxley Acts (SOX)

FCPA is legislation passed (1977) to

Prevent companies from bribing foreign officials to obtain business

Requires all publicly owned corporations to maintain a system of internal accounting controls.

SOX is legislation passed (2002) applies to publicly held companies and their auditors to

Prevent financial statement fraud

Financial report transparent

Protect investors

Strengthen internal controls

Punish executives who perpetrate fraud

Copyright © 2018 Pearson Education, Inc.

Chapter 7: Control and Accounting Information Systems

Slide 1 - ‹#›

Both these legislative acts rely on good internal control systems, without good internal controls, the entire capital markets would be questionable of its value. Its important to point out to students their role in society as an accountant and why internal controls are so important as investors from wall street to main street place reliance on the financial statements.

With the passage of SOX, it changed the way accountants operate, specifically:

PCAOB, which enforces auditing, quality control, ethics, independence, and other auditing standards.

New rules for auditors: must report specific information to the company’s audit committee; prohibits auditors from performing nonaudit services; audit firms cannot provide services if top management was employed by the auditing firm and worked on the company’s audit in the preceding 12 months.

New rules for audit committees.

New rules for management.

New internal control requirements.

8

Control Frameworks

COBIT

Framework for IT control

COSO

Framework for enterprise internal controls (control-based approach)

COSO-ERM

Expands COSO framework taking a risk-based approach

Copyright © 2018 Pearson Education, Inc.

Chapter 7: Control and Accounting Information Systems

Slide 1 - ‹#›

COBIT Framework

Current framework version is COBIT5

Based on the following principles:

Meeting stakeholder needs

Covering the enterprise end-to-end

Applying a single, integrated framework

Enabling a holistic approach

Separating governance from management

Copyright © 2018 Pearson Education, Inc.

Chapter 7: Control and Accounting Information Systems

Slide 1 - ‹#›

The COBIT framework has evolved over the years and each time there are major changes to the framework, the framework is numbered to its current version. The current version of COBIT for IT controls is COBIT5.

The benefit of a standard framework for IT controls is that it allows:

Management to benchmark their environments and compare it to other organizations

Because the framework is comprehensive, it provides assurances that IT security and controls exist

Allows auditors to substantiate their internal control opinions

The framework is based on the five principles:

Meeting stakeholders needs means that enterprises exist to create value to their shareholders. Thus, the governance objective is value creation.

Covering the enterprise from end-to-end means that COBIT5 addresses governance and management of information and information-related technologies throughout the enterprise. This means that it is not focused solely on the IT function as information technology runs throughout the enterprise.

Applying a single, integrated framework means that COBIT5 can align with other governance frameworks such as COSO and COSO-ERM.

Enabling a holistic approach includes the following enablers:

Processes—a set of activities to achieve an overall IT related goal

Organizational structures—key decision-making entity

Culture, ethics, and behavior of individuals and the organization

Principles and policies guide the day-to-day management

Information

Infrastructure, technology, and applications

People, skills, and competencies

5. Separating governance from management

10

COBIT5 Separates Governance from Management

Copyright © 2018 Pearson Education, Inc.

Chapter 7: Control and Accounting Information Systems

Slide 1 - ‹#›

Copyright © 2018 Pearson Education, Inc.

Chapter 7: Control and Accounting Information Systems

Slide 1 - ‹#›

COBIT5 is a framework that identifies five governance processes using the Evaluate Direct Monitor (EDM), which are:

1. Ensure governance framework setting and maintenance

2. Ensure benefits delivery

3. Ensure risk optimization

4. Ensure resource optimization

5. Ensure stakeholder transparency

There are 32 management processes that are organized under the following four domains:

Align, plan, and organize

Build, acquire, and implement

Deliver, service, and support

Monitor, evaluate, and assess

11

Components of COSO Frameworks

COSO

COSO-ERM

Control (internal) environment

Risk assessment

Control activities

Information and communication

Monitoring

Internal environment

Objective setting

Event identification

Risk assessment

Risk response

Control activities

Information and communication

Monitoring

Copyright © 2018 Pearson Education, Inc.

Chapter 7: Control and Accounting Information Systems

Slide 1 - ‹#›

The major difference between COSO and COSO-ERM is that COSO-ERM’s focus is on a risk-based approach and the components are expanded for this approach (objective setting, event identification, and risk response are added).

All of the other components are similar.

12

Internal Environment

Management’s philosophy, operating style, and risk appetite

Commitment to integrity, ethical values, and competence

Internal control oversight by Board of Directors

Organizing structure

Methods of assigning authority and responsibility

Human resource standards

Copyright © 2018 Pearson Education, Inc.

Chapter 7: Control and Accounting Information Systems

Slide 1 - ‹#›

The internal environment establishes the foundation for all other components of the internal control model.

Assessing the internal environment involves observance of the organizational behavior of management actions and evaluation of policies and procedures. For example, is there a written code of conduct that explicitly describes honest and dishonest behaviors. Does the company exhibit good hiring practices to by evaluating qualified applicants and conducting thorough background checks.

13

Objective Setting

Strategic objectives

High-level goals

Operations objectives

Effectiveness and efficiency of operations

Reporting objectives

Improve decision making and monitor performance

Compliance objectives

Compliance with applicable laws and regulations

Copyright © 2018 Pearson Education, Inc.

Chapter 7: Control and Accounting Information Systems

Slide 1 - ‹#›

Objective setting is what the company hopes to achieve. This is broken down into four categories beginning from a high level to specific levels.

Strategic objectives are high-level goals and may include considerations that involve the organizational direction relating to governance, business model, or strategy (e.g., grow market share)

Operations objectives involve the operations which we can think of as people, process, and technology. Examples of these types of objectives include internal controls, supply chain and distribution, human resources.

Reporting objectives ensure the accuracy and reliability of your reports. This would include objectives covering access to the systems and protecting the IT systems. In addition, ensuring adequate management review of the reports.

Compliance objectives are focused on the compliance of all applicable laws and regulations. Many industries have specific regulations (e.g., food manufacturing and financial services). In addition, there are local, state, and federal laws that organizations must comply with meaning that there are environmental, legal, and contractual compliance considerations.

It is also noted at the high level that an organizations risk appetite (how much risk is an organization willing to take?) and risk tolerance is formed. So in other words, there are trade-offs with risk in organizations. Organizations need to think about how much risk they are willing to take for a certain level of return. Of course there are uncertainties, that is why thinking about risk is so important.

14

Event Identification

Identifying incidents both external and internal to the organization that could affect the achievement of the organizations objectives

Key Management Questions:

What could go wrong?

How can it go wrong?

What is the potential harm?

What can be done about it?

Copyright © 2018 Pearson Education, Inc.

Chapter 7: Control and Accounting Information Systems

Slide 1 - ‹#›

Risk is two-sided:

Opportunities (upside to uncertainty)

Risk (downside to uncertainty)

For example, a chocolate manufacturer that relies on sourcing its cacao beans from certain regions in Africa to get their signature blend of chocolate flavor for their truffles. Their organizational objective is to increase revenues and profitability.

What could go wrong?

We may not get enough supply of cacao beans to meet our customer demand.

How can it go wrong?

It is possible that the weather conditions produced a smaller crop limiting the supply; or

it is possible that a civil war broke out in the African region and the crop produced, but no one was

there to get the product off the trees in time due to the war.

What is the potential harm?

The cost of our cacao beans will go up do to limited supply, it will have an impact on our customers as we

may have to increase our prices.

What can be done about it?

If we buy cacao bean futures on the market we may be able to hedge any potential risk due to our

supply of cacao required to meet our customer demand to achieve our organizational goals of increasing

revenues and profitability.

15

Risk Assessment

Risk is assessed from two perspectives:

Likelihood

Probability that the event will occur

Impact

Estimate potential loss if event occurs

Types of risk

Inherent

Risk that exists before plans are made to control it

Residual

Risk that is left over after you control it

Copyright © 2018 Pearson Education, Inc.

Chapter 7: Control and Accounting Information Systems

Slide 1 - ‹#›

Risk assessment is perhaps the most difficult step for organizations because once they identify what can go wrong, organizations need to think about the probability that it actually will happen and estimate costs. This truly can be a daunting task with a lot of uncertainty!

Many organizations will look at this task from a qualitative and quantitative perspective provided that they have enough data. From a qualitative perspective, management can simply assign high, medium, or low risk based upon their collective discussion. After assessing all the risks identified in this manner, a heat map can be generated to determine which risks have high (usually a red color), medium (orange color), or low (yellow color).

Quantitative analysis can examine probabilistic techniques to model the cashflow or earnings based upon the risk identified.

16

Risk Response

Reduce

Implement effective internal control

Accept

Do nothing, accept likelihood, and impact of risk

Share

Buy insurance, outsource, or hedge

Avoid

Do not engage in the activity

Copyright © 2018 Pearson Education, Inc.

Chapter 7: Control and Accounting Information Systems

Slide 1 - ‹#›

Management can respond to risk in four ways:

Reduce the amount of risk by implementing internal controls

Do nothing and accept the likelihood and impact of the risk

Share the risk by buying insurance, doing a joint venture, or hedging transactions (chocolate company example in slide 7-13 notes)

Avoid the risk entirely and sell off a division or not manufacture that product line

17

Control Activities

Proper authorization of transactions and activities

Segregation of duties

Project development and acquisition controls

Change management controls

Design and use of documents and records

Safeguarding assets, records, and data

Independent checks on performance

Copyright © 2018 Pearson Education, Inc.

Chapter 7: Control and Accounting Information Systems

Slide 1 - ‹#›

Segregation of Accounting Duties

Copyright © 2018 Pearson Education, Inc.

Chapter 7: Control and Accounting Information Systems

Slide 1 - ‹#›

Copyright © 2018 Pearson Education, Inc.

Chapter 7: Control and Accounting Information Systems

Slide 1 - ‹#›

Good internal control requires that no single employee of a company have too much responsibility over transactions and business processes. Segregation of duties prevents an employee from committing and concealing fraud. The three functions that need to be segregated are:

Custodial function which handles cash and assets (inventory, fixed assets)

Recording function which involves preparing source documents, entering data into the system, maintaining journals or data files , and performing reconciliations of accounts

Authorizing function which involves approving transactions and decisions

19

Segregation of Systems Duties

Segregation of systems duties as to divide authority and responsibility between the following systems functions

System administration

Network management

Security management

Change management

Users

Systems analysts

Programmers

Computer operators

Information system librarian

Data control

Copyright © 2018 Pearson Education, Inc.

Chapter 7: Control and Accounting Information Systems

Slide 1 - ‹#›

Systems administrators make sure all information system components operate smoothly and efficiently

Network managers ensure that devices are linked to the organization’s internal and external networks and that those networks operate properly

Security management makes sure that systems are secure and protected from internal and external threats

Change management is the process of making sure changes are made smoothly and efficiently and do not negatively affect systems reliability, security, confidentiality, integrity, and availability.

Users record transactions, authorize data to be processed, and use system output

Systems analysts help users determine their information needs and design systems to meet those needs

Programmers take the analysts’ design and develop, code, and test computer programs

Computer operators run the software on the company’s computers; they ensure that data are input properly, processed correctly, and that needed output is produced

Information system librarian maintains custody of corporate databases, files, and programs in a separate storage area called the information system library

Data control group ensures that source data have bee properly approved, monitors the flow of work through the computer, reconciles input and output, maintains a record of input errors to ensure their correction and resubmission, and distrutes systems output.

20

Monitoring

Perform internal control evaluations (e.g., internal audit)

Implement effective supervision

Use responsibility accounting systems (e.g., budgets)

Monitor system activities

Track purchased software and mobile devices

Conduct periodic audits (e.g., external, internal, network security)

Employ computer security officer

Engage forensic specialists

Install fraud detection software

Implement fraud hotline

Copyright © 2018 Pearson Education, Inc.

Chapter 7: Control and Accounting Information Systems

Slide 1 - ‹#›

Key Terms (1 of 3)

Threat/Event

Exposure/impact

Likelihood/risk

Internal controls

Preventive controls

Detective controls

Corrective controls

General controls

Application controls

Belief system

Boundary system

Diagnostic control system

Interactive control system

Foreign Corrupt Practices Act (FCPA)

Sarbanes-Oxley Act (SOX)

Public Company Accounting Oversight Board (PCAOB)

Control Objectives for Information and Related Technology (COBIT)

Committee of Sponsoring Organizations (COSO)

Internal control-integrated framework (IC)

Enterprise Risk Management Integrated Framework (ERM)

Internal environment

Copyright © 2018 Pearson Education, Inc.

Chapter 7: Control and Accounting Information Systems

Slide 1 - ‹#›

22

Key Terms (2 of 3)

Risk appetite

Audit committee

Policy and procedures manual

Background check

Strategic objectives

Operations objectives

Reporting objectives

Compliance objectives

Event

Inherent risk

Residual risk

Expected loss

Control activities

Authorization

Digital signature

Specific authorization

General authorization

Segregation of accounting duties

Collusion

Segregation of systems duties

Systems administrator

Network manager

Security management

Change management

Users

Systems analysts

Programmers

Computer operators

Information system library

Copyright © 2018 Pearson Education, Inc.

Chapter 7: Control and Accounting Information Systems

Slide 1 - ‹#›

23

Key Terms (3 of 3)

Data control group

Steering committee

Strategic master plan

Project development plan

Project milestones

Data processing schedule

System performance measurements

Throughput

Utilization

Response time

Postimplementation review

Systems integrator

Analytical review

Audit trail

Computer security officer (CSO)

Chief compliance officer (CCO)

Forensic investigators

Computer forensics specialists

Neural networks

Fraud hotline

Copyright © 2018 Pearson Education, Inc.

Chapter 7: Control and Accounting Information Systems

Slide 1 - ‹#›

24

Copyright © 2018 Pearson Education, Inc.

Chapter 7: Control and Accounting Information Systems

Slide 1 - ‹#›

25