Running Head: ACC 411 bb bb b bb bb bb b bb bb bb b bb bb bb b bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb bb b bb bb bb b bb bb bb bb b bb
bb bb bb bb bb bb bb bb b bb bb bb b bb bb bb bb bb b bb bb bb b bb bb 1
7-2 Final Project Submission
ACC 411
SNHU
ACC 411 bb bb bb bb bb b bb bb bb bb bb b bb bb bb b bb bb bb b bb bb bb bb bb bb bb b bb bb bb b bb bb bb b bb bb bb b bb bb bb bb bb b bb bb bb bb b bb bb b
bb bb bb bb bb bb bb bb b bb bb bb b bb bb bb bb bb b bb bb bb bb b bb bb bb b bb bb bb bb 2
Subject: Evaluation of the internal controls of Robbins Network Solutions
Internal Controls of Robbins Network Solutions
Robbins Network Solutions (RNS) operates in the highly competitive and dynamic
market involving computers and networking products. An audit plan is created for the
organization to ensure that there exists proper internal control within the organization. A
detailed analysis of the business environment of RNS has been carried out. Additionally,
the focus has been laid on the typical business transactions that are performed by the firm.
The business risks that arise before RNS have also been identified. The impact of the
current events on the risks and internal controls of the firm in the future have been
analyzed. The memo also sheds light on the potential ethical issues that may arise for the
firm and the types of internal control that must be adopted to maintain ethical and
professional practices.
Major financial business transactions
The chief financial business transactions that RNS is involved in include the selling
as well as installation of computer systems and networking software and hardware
components. In addition to making these offerings in the market, RNS provides information
technology consulting to diverse business entities. At present, the company has been
focusing on designing its computer networking software that will be sold to the customers.
By aggressively marketing the services and products of the business, the firm carries out its
major financial business transactions. While conducting business transactions, it is
ACC 411 bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb
bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb 3
imperative for firms to maintain proper evidence such as cash memos, invoices, salary
slips, etc.
Highest business risks
RNS encounters a broad range of risks and threats while conducting its business
activities. Some of the major risks include high competition from top market players such
as Dell, Apple and Hewlett Packard (HP) and high expenditure relating to advertising of its
products and services in the market. The unpredictability that exists in the macro
environment also increases the level of uncertainty for the form. For instance, a major
downturn in the U.S. economy could impact its financial performance and market demand.
Other risks that arise for RNS include the possibility of credit losses exceeding sales
benefits and the lack of viability of software development initiatives of the business. As the
industry in which RNS operates is influenced by evolving technology, the degree of risk is
high. Businesses that involve technology are prone to high risk and uncertainty (Samimi,
2020). Competition is a major risk that could adversely affect its market share and
profitability.
Appropriate types of internal controls for the industry
Internal controls can be categorized into detective, corrective and preventive. Each
of them plays a distinctive role in an organizational setting (Types of internal controls.
Finance & Accounting, 2021). In the computer products and technology services industry,
there is a need to have in place appropriate internal control mechanisms. Such control
mechanisms are critical since they can offer reasonable assurance about the operations,
reporting, as well as compliance dimensions while conducting an audit process. In the
ACC 411 bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb
bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb 4
specific organizational context, preventive internal control measures must be adopted so that
proper actions can be taken before the occurrence of fraud or erroneous activities. For
instance, a robust corporate governance framework must be adopted that focuses on
confidentiality, availability and integrity of data. Preventive internal controls are suitable in
the specific industrial setting since they can act as a barrier and block undesirable events or
occurrences from taking place. Some of the key steps that can be taken are authorization of
bills and invoices, verification of the expenses, etc. (DiNapoli, 2007).
Ethical Issues
A number of ethical issues are related to the RNS company that could have a direct
impact on the outcome of a financial audit process. One of the main ethical issues is the
unethical behavior of the two stockholders who are actively involved in the organizational
transactions. There is a possibility that they could focus on their personal interests and
gains. The organization gives preference to staff members that possess high technical
expertise and skills. Such a staff selection and hiring procedure could adversely affect the
financial activities, including the manner in which the transactions are recorded and
maintained. For resolving the first ethical issue, all the stockholders must take part in the
business activities so that the possibility of fraud can be reduced. Similarly, the hiring
process must be made flexible so that employees with adequate financial knowledge can be
hired.
Current events impacting RNS’s risks and internal controls in the future b
Some of the current events that could impact RNS’s risks and internal controls in
the future include cybersecurity issues, changes relating to laws on taxes and accounting
ACC 411 bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb
bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb 5
principles. Additionally, regulations relating to the use of technology can also impact the
risks that it encounters and the manner in which it adopts internal control measures.
Auditing of cash
Auditing of cash is regarded to be a critical process that helps in accurately
categorizing cash elements in the financial statements of an organization. In the case of
Robbins Network Solutions (RNS), the existence of a robust audit program (plan) is
essential for evaluating its internal controls for cash. It can help in ensuring the
completeness of the cash-related transactions of the organization. Both risk assessment and
control activities have been integrated into the audit plan and monitoring and
communication aspects.
Control environment
In order to ensure there is proper internal control of cash within RNS, the auditors
must have a thorough insight into the process of managing cash and recording cash-related
transactions. The policies and protocols relating to cash activities must be checked and
properly understood. Additionally, to ensure a robust control environment is in place while
understanding the cash management and recording processes, random testing must be done.
For example, while the financial officer of RNS explains the processes, he must be asked
to use a real-life example to show how internal control over cash accounts is maintained.
The accounts reconciliation or bank statements can be used to explain the current internal
control measures in RNS.
ACC 411 bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb
bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb 6
Risk assessment
The risk assessment must be done at an integrated level to ensure there is proper
internal control of cash. The chief elements that need to be taken into consideration while
assessing cash-related risks of the organization include the materiality of the balance sheet,
segregation of duties, and cash account reviews. Checking balance sheet materiality is vital
to identify any misstatement in the records. Existing controls to detect fraudulent activities
must be examined in detail. While checking accounts such as accounts receivable, the
manner in which roles and duties are segregated must be checked. There must be a clear
distinction between the person that prepares these accounts within RNS and the person who
reviews them. The reconciliation of cash accounts must be done by the ones who prepare
them so that they can identify any omissions. The frequency of performing cash account
reviews as well as authorized signatories for the accounts must be checked.
Control activities
The existence of well-functional and effective control activities is vital to make sure
there is internal control of cash. In the context of RNS, a broad range of control activities
can be carried out to ensure compliance with Generally Accepted Accounting Principles
(GAAP) and identify the possibility of fraudulent activities. Some of the major control
activities that need to be conducted within the RNS entity are testing the account records,
confirmation of cash balances with financial institutions, and analysis of bank transfers.
Similarly, the comparison of cash receipt samples with the cash receipt journal of the
organization is vital to identify poor control over cash transactions. The presentation of
financial statements along with disclosures of RNS’ cash must be evaluated thoroughly.
ACC 411 bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb
bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb 7
Information and communication
Real-time communication of activities is vital to locating cash-related risks.
Information flow must be done in a timely manner, and any major concerns or weaknesses
need to be reported to the respective authority, such as managers or supervisors. Other
minor issues or deficiencies must be addressed by the auditor, and they must be disclosed
to the management of RNS. According to the Sarbanes-Oxley Act (SOX), stringent
reporting and security standards must be in place so that proper control can be ensured.
The external auditors must conduct annual or quarterly reviews that can help in identifying
any cash-related concerns (Sox compliance: A smarter way forward a new approach can .
Deloitte, 2021).
Monitoring
The monitoring of cash transactions of RNS must be done continuously. Innovative
analytical methods can be used during the activity. The management must ensure real-time
monitoring so that cash-related variance or discrepancies can be identified urgently and
proper control measures can be taken.
Relationship between audit risk, audit evidence, and financial statement assertions as
it specifically relates to this company and industry
Evidence
In the context of the Robbins Network Solutions organization, the specific pieces of
evidence or audit data that the team will be reviewing during the audit process include the
financial statements, i.e., the balance sheet, income statement and cash flow statement.
ACC 411 bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb
bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb 8
Additionally, accounts receivables and ageing of the accounts must also be reviewed to
ascertain the cash-related transactions are accurately maintained by the firm during the
usual course of the business operations. The bank statements of the firm must also be
reviewed to check for any kind of discrepancy that may arise in its books of accounts. A
thorough reviewing of the diverse financial accounts of the business entity can help to
check its internal control quality and the accuracy of its financial performance (El
Gharbaoui & Chraibi, 2021).
Audit Universe
In case a major portion of the data of the organization is overseas, and thus, beyond
the jurisdiction or audit universe of the auditors, the scope of the auditing activity will
automatically get restricted. In such a context, the audit team might not have access to
relevant and necessary financial details and information about the business at an integrated
level. In order to handle such a situation can give rise to materiality risk relating to
misrepresentation or misstatement of financial data of RNS. Thus, the auditing team must
include an adverse opinion reflecting that the financial data relating to the overseas
operations was not available, due to which a thorough and rigorous auditing process could
not be carried out. ‘Auditing Standard (AS) 2110: Identifying and Assessing Risks of
Material Misstatement must be followed to optimally perform risk assessment procedures
(PCAOB, 2010).
Analytical procedures
An in-depth analysis is a vital part of auditing activity. The analytical procedures
that will be carried out for determining the sampling program in the context of the RNS
ACC 411 bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb
bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb 9
organization involve the segregation of the sampling process. Initially, it is necessary to
check whether the general ledge balance of RNS matches the balances captured in banking
and financial institution reports. Then the analysis would involve checking the firm’s
deposits to ensure their validity and correctness. For example, in case there are any void
cheques, they must be defaced so that they cannot be used for fraudulent activities. In case
there is any abnormality in the accounts payable, then a thorough checking will be done to
ensure that all disbursements have been approved by the respective authorities. While
checking the gross margin for the specific financial year, a comparison will be made with
the previous year to locate a pattern. My internal control evaluation method will impact
this step since high priority will be given to elements such as segregation of duties among
the organizational personnel and ensuring the adherence to relevant accounting practices
while recording the financial transactions.
Types of audit evidence
The specific type of audit evidence that will be requested from RNS include:
• Client confirmations
• Accounts payable proof
• Physical examination of assets like cash
• General ledger account details
The client confirmations relating to purchase requests will be checked. As a vital piece
of evidence, purchase orders will be asked. For checking the accounts payable proof, some
of the key pieces of evidence that will be requested include invoices, approval documents
of signatories, and the general ledger of the company. The physical examination will be
ACC 411 bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb
bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb 10
done by going with an official to one of the banks or financial institutions where the
business deposits cash to ensure the amount presented in the statement is actually present.
The general ledger account details will also serve as useful pieces of evidence. They will
be used for reconciliation purposes and help to ensure that the figures that have been
recorded are accurate and match perfectly. bb
Considerations while auditing subjective areas
While performing auditing of subjective areas, a number of considerations the
auditing team will have to make. One of the fundamental elements is that every request
must be presented in the form of writing. This form of communication will make sure that
a systematic procedure is adopted which can be well-documented as well. Another key
consideration is the existence of an internal audit function within the organization and the
role that it plays to contribute to the quality of the internal controls within the RNS
organization (PCAOB, 2010).
Factors while planning the nature and extent of audit documentation
Audit documentation fundamentally involves the recording of auditing procedures
that have been applied, the pieces of evidence that have been obtained from an
organization and the conclusions that have been arrived at by the auditors. In the context
of the Robbins Network Solutions organization, a diverse range of factors have been taken
into account while planning the nature as well as the extent of the audit documentation.
One of the chief factors that had been taken into consideration is the quality of the audit
evidence, including the availability of necessary supportive documents. The audit risk factor
was also considered since these elements could compromise the quality of the auditing
ACC 411 bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb
bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb 11
outcome. The internal communication was also a vital factor that was taken into account
while planning the audit documentation process. bb
Responsibility for IT risk coverage
The Information technology (IT) landscape is highly dynamic. The responsibility for
IT, such as computer systems, software, databases and internet usage risk coverage for
organizations that operate in the IT domain continuously evolves. IT has a high
responsibility to make sure that adequate protection is in place that can prevent malicious
actors such as online hackers and cybercriminals from compromising sensitive and
confidential business information. The IT department has to focus on deploying a robust
and well-functional cybersecurity framework that can ensure that the latest security
elements are in place that reduces the vulnerability of the business entity in the vast and
unpredictable cyber domain. Its responsibility also involves ensuring the employees get
familiarized with the IT elements and they have awareness relating to cybersecurity.
Social media facilitates direct and real-time communication in the virtual setting. However,
it also increased online risks through social engineering attacks by hackers, etc. Thus, it is
the responsibility of IT to tackle the security concerns that arise through social media
channels.
Internal Controls
The internal controls that have been introduced to specifically safeguard computer
data and proprietary information in the IT industry include a dedicated team of
cybersecurity professionals, ell-defined IT policies that are aligned with industry-level
regulations and standards and the use of cybersecurity tools and technologies such as
ACC 411 bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb
bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb 12
firewalls, antivirus software and intrusion detection and prevention systems. Other internal
controls are maintaining data backup, software licensing and termination of unauthorized
system access.
Current and Future vulnerabilities
The current and future vulnerabilities exist for Information Technology due to the
use of outdated software, lack of frequent audit of IT logs and limited cybersecurity
awareness of the staff. For addressing these gaps so that the IT vulnerabilities can be
reduced, it is necessary to regularly update software and applications, ensure the timely and
periodical auditing of IT logs of an organization and offering training to staff members so
that their awareness on cybersecurity aspects can be improved and they can effectively
identify and respond to abnormal or malicious elements online.
Thank You
References
DiNapoli, T. P. (2007). Standards for internal control. New York State Government.
El Gharbaoui, B., & Chraibi, A. (2021). Internal audit quality and financial performance: A
systematic literature review pointing to new research opportunities. International
Journal of Management Sciences, 4(2).
ACC 411 bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb
bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb bb bb bb 13
PCAOB, P. (2010). AS 2110: Identifying and Assessing Risks of Material Misstatement.
PCAOB: Washington, DC.
Samimi, A. (2020). Risk management in information technology. Progress in Chemical and
Biochemical Research, 3(2), 130-134.
Types of internal controls. Finance & Accounting. (2021). Retrieved July 14, 2022, from
https://www.fa.ufl.edu/directives/types-of-internal-controls/
Sox compliance: A smarter way forward a new approach can . Deloitte. (2021). Retrieved
August 6, 2022, from
https://www2.deloitte.com/content/dam/Deloitte/us/Documents/risk/us-sox-compliance-
smarter-way-forward.pdf