On 17th December 2018, the Competition and Markets Authority (CMA) published an update paper outlining serious competition concerns and proposing changes to legislation to improve the audit sector for the benefit of savers and investors alike.
Use with Auditing 10e by Alan Millichamp and John Taylor
ISBN 9781408044087
© 2012 Cengage Learning EMEA
Week 4a
Internal Controls
Use with Auditing 10e by Alan Millichamp and John Taylor
ISBN 9781408044087
© 2012 Cengage Learning EMEA
Introduction • Professional standards require auditors to obtain an
understanding of the entity and its environment which includes its internal control systems.
• Internal control is the process designed and effected by the directors to provide reasonable assurance about the achievement of the entity’s objectives, namely:
• the reliability of financial reporting
• effectiveness and efficiency of operations
• compliance with applicable laws and regulations
Use with Auditing 10e by Alan Millichamp and John Taylor
ISBN 9781408044087
© 2012 Cengage Learning EMEA
Introduction (continued) ISA 315 (UK & Ireland) understanding the entity and its environment and assessing risks of material misstatement details the following elements:
• the control environment
• the entity’s risk assessment process
• the information systems
• control activities
• monitoring of controls
Use with Auditing 10e by Alan Millichamp and John Taylor
ISBN 9781408044087
© 2012 Cengage Learning EMEA
The control environment
This is the attitudes, awareness and actions of the directors about internal controls.
A good control environment can be seen by:
• Directors enforce integrity and ethical values
• Directors participate in control activities and operate in a way that promotes control
• Authority and responsibility for controls is assigned to people
• Human resources policies promote control
Use with Auditing 10e by Alan Millichamp and John Taylor
ISBN 9781408044087
© 2012 Cengage Learning EMEA
Entity’s risk assessment process
All entities will have some sort of process (not necessarily formal) for assessing the risks a company faces and then implementing strategies (controls) to mitigate the risks.
Use with Auditing 10e by Alan Millichamp and John Taylor
ISBN 9781408044087
© 2012 Cengage Learning EMEA
The information system
An information system is the infrastructure, software, people, procedures and data used to create information within the company.
The larger the company, the more complex its information system is likely to become.
Use with Auditing 10e by Alan Millichamp and John Taylor
ISBN 9781408044087
© 2012 Cengage Learning EMEA
Control activities Control activities are the policies and procedures that help ensure management instructions are carried out.
Control activities may include the following:
• Approval and control of documents
• Controls over computerised applications
• Controls over arithmetical accuracy
• Maintaining control accounts and trial balances
• Reconciliations
• Comparing assets to records
• Restricting assets
• Application computer controls (Controls over input, processing and standing data)
Use with Auditing 10e by Alan Millichamp and John Taylor
ISBN 9781408044087
© 2012 Cengage Learning EMEA
Monitoring of controls
• This is the process to assess the quality of internal control performance over time.
• Who monitors is likely to be affected by the size of the company, e.g. a small company is unlikely to have an internal audit department.
• Monitoring of controls is also likely to be informal in a small company.
▪ The control environment
Use with Auditing 10e by Alan Millichamp and John Taylor
ISBN 9781408044087
© 2012 Cengage Learning EMEA
Types of computer controls
• The controls which should be implemented for computer systems can be considered in two categories:
(a) General Controls: controls ‘around’ the computer system to ensure it is operating in a secure environment
There are two types of General Control,
(i) Systems Development Controls: to ensure that the system in operation has been planned to meet the needs of the organisation and that there has been proper training and testing prior to implementation.
(ii) Administrative Controls: to ensure that the operation of the system is efficient, controlled and properly supervised so that the system is operating smoothly and efficiently.
Use with Auditing 10e by Alan Millichamp and John Taylor
ISBN 9781408044087
© 2012 Cengage Learning EMEA
Types of computer controls (continued) (b) Application Controls: manual or automated procedures to ensure that the transactions processed by the system result in information which is accurate, complete and valid.
• Application controls consist of controls over input, processing, output and standing data.
• Application controls and general controls are inter-related.
• Strong general controls contribute to the assurance which may be obtained by an auditor in relation to application controls.
• Unsatisfactory general controls may undermine strong application controls.
Use with Auditing 10e by Alan Millichamp and John Taylor
ISBN 9781408044087
© 2012 Cengage Learning EMEA
General controls Systems development controls (a) Cost/benefit analysis
(b) Project management
(c) Design controls
(d) Documentation
(e) Training
(f) Review and maintenance
Use with Auditing 10e by Alan Millichamp and John Taylor
ISBN 9781408044087
© 2012 Cengage Learning EMEA
Administrative controls The principal administrative controls are as follows:
(a) Restriction of access using passwords e.g. in a wages system some staff may be able to read data whereas others may be allowed to change data;
(b) Regular backup and secure storage of files; (c) Maintaining operating logs showing when users have accessed the system
and the files they used; (d) Job scheduling to allow central control over when users have access; (e) Dedicated terminals e.g. the terminals in the purchases department are
unable to access sales or wages data; (f) Maintenance agreements; (g) Standby arrangements with either the users of similar systems or a
computer firm. (h) Disasters, Recovery and Contingency Plan (i) Firewalls (j) Anti-virus software
Use with Auditing 10e by Alan Millichamp and John Taylor
ISBN 9781408044087
© 2012 Cengage Learning EMEA
Application controls Input controls
(a) Batch controls where data entered onto the system is first subject to manual processes to pre-determine the results and the input data will only be accepted by the system when it meets the pre-determined totals. Typically the information checked is;
Number of documents Net amount Gross amount Hash totals due dates and codes
(b) Range/Limit checks which specify maximum and minimum expected values (e.g. in a wages system an exception report may be generated for employees receiving net pay of more than £3,000 per month to allow management to follow up and investigate before a payment is made)
(c) Existence checks that will only data to be input for valid account codes. This is useful in a sales or purchases system.
Use with Auditing 10e by Alan Millichamp and John Taylor
ISBN 9781408044087
© 2012 Cengage Learning EMEA
Application controls (continued) Input controls (continued)
(d) Check digits which give codes a mathematical pattern and data will not be accepted for codes which do not match this pattern. These are used to prevent transposition errors.
(e) Sequence checks which will highlight gaps in data both within and between batches.
Controls over processing The control techniques used over input may also be used to ensure the completeness and accuracy of processing provided they are applied to the results of processing e.g. a batch reconciliation produced after processing
Use with Auditing 10e by Alan Millichamp and John Taylor
ISBN 9781408044087
© 2012 Cengage Learning EMEA
Application controls (continued) Controls over standing data (master files)
- Amendments to standing data should only be made by authorised persons
- This can be achieved either through passwords or pre-numbered forms.
- Regular printouts of data should be obtained and reviewed by someone in authority.
- The computer could be programmed to provide a list of all amendments, additions and deletions on a daily or weekly basis. These could then be reviewed to ensure that all changes have been properly authorised.
Use with Auditing 10e by Alan Millichamp and John Taylor
ISBN 9781408044087
© 2012 Cengage Learning EMEA
Application controls (continued) Controls to prevent access through telephone lines - Ex-directory telephone numbers.
- Private lines can be used to transfer data between terminals. These lines would be owned by the telephone operator (BT) but they would only allow transmission of data between terminals.
- A call back system can be used. This will ensure that access is only from authorised sources as the main terminal will check the user’s telephone number on its file.
- Confidential data can be encrypted.
- The main terminal may have a number of telephone numbers which can be used for access; and some of these may restrict the systems which can be accessed e.g. one number to access stock data and another to access customer information.
Internal Controls and Transaction Cycles (ISA315/330)
Use with Auditing 10e by Alan Millichamp and John Taylor
ISBN 9781408044087
© 2012 Cengage Learning EMEA
Homework 1. What are the key inherent limitations in systems of internal controls?
2. Suggest suitable controls for each stage of the wages cycle.
Objectives Stage of Cycle Outline of Control procedures
(1) All work is recorded Record work
(2) Only genuine work is recorded Record work
(3) Work done is recorded accurately Record work
(1)Liability correctly calculated-no error in pay rates
Recognition of payroll liability
(2) Proper statutory liability is recognised Recognition of payroll liability
(1)Each employee is paid the correct amount
Payment is made
(2) Only genuine employees are paid Payment is made
(3) All payments are recorded in the nominal ledger
Payment is made