1 / 12100%
Running Head: ACC 411 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 1
7-2 Final Project Submission
ACC 411
SNHU
August 13,2022
ACC 411 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 2
Date: July 14, 2022
Subject: Evaluation of the internal controls of Robbins Network Solutions
Internal Controls of Robbins Network Solutions
Robbins Network Solutions (RNS) operates in the highly competitive and dynamic market
involving computers and networking products. An audit plan is created for the organization to
ensure that there exists proper internal control within the organization. A detailed analysis of the
business environment of RNS has been carried out. Additionally, the focus has been laid on the
typical business transactions that are performed by the firm. The business risks that arise before
RNS have also been identified. The impact of the current events on the risks and internal controls
of the firm in the future have been analyzed. The memo also sheds light on the potential ethical
issues that may arise for the firm and the types of internal control that must be adopted to maintain
ethical and professional practices.
Major financial business transactions
The chief financial business transactions that RNS is involved in include the selling as
well as installation of computer systems and networking software and hardware components. In
addition to making these offerings in the market, RNS provides information technology
consulting to diverse business entities. At present, the company has been focusing on designing its
computer networking software that will be sold to the customers. By aggressively marketing the
services and products of the business, the firm carries out its major financial business transactions.
While conducting business transactions, it is imperative for firms to maintain proper evidence
such as cash memos, invoices, salary slips, etc.
ACC 411 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 3
Highest business risks
RNS encounters a broad range of risks and threats while conducting its business activities.
Some of the major risks include high competition from top market players such as Dell, Apple and
Hewlett Packard (HP) and high expenditure relating to advertising of its products and services in
the market. The unpredictability that exists in the macro environment also increases the level of
uncertainty for the form. For instance, a major downturn in the U.S. economy could impact its
financial performance and market demand. Other risks that arise for RNS include the possibility
of credit losses exceeding sales benefits and the lack of viability of software development
initiatives of the business. As the industry in which RNS operates is influenced by evolving
technology, the degree of risk is high. Businesses that involve technology are prone to high risk
and uncertainty (Samimi, 2020). Competition is a major risk that could adversely affect its market
share and profitability.
Appropriate types of internal controls for the industry
Internal controls can be categorized into detective, corrective and preventive. Each of
them plays a distinctive role in an organizational setting (Types of internal controls. Finance &
Accounting, 2021). In the computer products and technology services industry, there is a need to
have in place appropriate internal control mechanisms. Such control mechanisms are critical since
they can offer reasonable assurance about the operations, reporting, as well as compliance
dimensions while conducting an audit process. In the specific organizational context, preventive
internal control measures must be adopted so that proper actions can be taken before the
occurrence of fraud or erroneous activities. For instance, a robust corporate governance
framework must be adopted that focuses on confidentiality, availability and integrity of data.
ACC 411 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 4
Preventive internal controls are suitable in the specific industrial setting since they can act as a
barrier and block undesirable events or occurrences from taking place. Some of the key steps that
can be taken are authorization of bills and invoices, verification of the expenses, etc. (DiNapoli,
2007).
Ethical Issues
A number of ethical issues are related to the RNS company that could have a direct impact
on the outcome of a financial audit process. One of the main ethical issues is the unethical
behavior of the two stockholders who are actively involved in the organizational transactions.
There is a possibility that they could focus on their personal interests and gains. The organization
gives preference to staff members that possess high technical expertise and skills. Such a staff
selection and hiring procedure could adversely affect the financial activities, including the manner
in which the transactions are recorded and maintained. For resolving the first ethical issue, all the
stockholders must take part in the business activities so that the possibility of fraud can be
reduced. Similarly, the hiring process must be made flexible so that employees with adequate
financial knowledge can be hired.
Current events impacting RNS’s risks and internal controls in the future e
Some of the current events that could impact RNS’s risks and internal controls in the
future include cybersecurity issues, changes relating to laws on taxes and accounting principles.
Additionally, regulations relating to the use of technology can also impact the risks that it
encounters and the manner in which it adopts internal control measures.
ACC 411 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 5
Auditing of cash
Auditing of cash is regarded to be a critical process that helps in accurately categorizing
cash elements in the financial statements of an organization. In the case of Robbins Network
Solutions (RNS), the existence of a robust audit program (plan) is essential for evaluating its
internal controls for cash. It can help in ensuring the completeness of the cash-related transactions
of the organization. Both risk assessment and control activities have been integrated into the audit
plan and monitoring and communication aspects.
Control environment
In order to ensure there is proper internal control of cash within RNS, the auditors must
have a thorough insight into the process of managing cash and recording cash-related
transactions. The policies and protocols relating to cash activities must be checked and properly
understood. Additionally, to ensure a robust control environment is in place while understanding
the cash management and recording processes, random testing must be done. For example, while
the financial officer of RNS explains the processes, he must be asked to use a real-life example to
show how internal control over cash accounts is maintained. The accounts reconciliation or bank
statements can be used to explain the current internal control measures in RNS.
Risk assessment
The risk assessment must be done at an integrated level to ensure there is proper internal
control of cash. The chief elements that need to be taken into consideration while assessing cash-
related risks of the organization include the materiality of the balance sheet, segregation of duties,
and cash account reviews. Checking balance sheet materiality is vital to identify any misstatement
in the records. Existing controls to detect fraudulent activities must be examined in detail. While
ACC 411 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 6
checking accounts such as accounts receivable, the manner in which roles and duties are
segregated must be checked. There must be a clear distinction between the person that prepares
these accounts within RNS and the person who reviews them. The reconciliation of cash accounts
must be done by the ones who prepare them so that they can identify any omissions. The
frequency of performing cash account reviews as well as authorized signatories for the accounts
must be checked.
Control activities
The existence of well-functional and effective control activities is vital to make sure there
is internal control of cash. In the context of RNS, a broad range of control activities can be carried
out to ensure compliance with Generally Accepted Accounting Principles (GAAP) and identify
the possibility of fraudulent activities. Some of the major control activities that need to be
conducted within the RNS entity are testing the account records, confirmation of cash balances
with financial institutions, and analysis of bank transfers. Similarly, the comparison of cash
receipt samples with the cash receipt journal of the organization is vital to identify poor control
over cash transactions. The presentation of financial statements along with disclosures of RNS’
cash must be evaluated thoroughly.
Information and communication
Real-time communication of activities is vital to locating cash-related risks. Information
flow must be done in a timely manner, and any major concerns or weaknesses need to be reported
to the respective authority, such as managers or supervisors. Other minor issues or deficiencies
must be addressed by the auditor, and they must be disclosed to the management of RNS.
According to the Sarbanes-Oxley Act (SOX), stringent reporting and security standards must be
ACC 411 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 7
in place so that proper control can be ensured. The external auditors must conduct annual or
quarterly reviews that can help in identifying any cash-related concerns (Sox compliance: A
smarter way forward a new approach can . Deloitte, 2021).
Monitoring
The monitoring of cash transactions of RNS must be done continuously. Innovative
analytical methods can be used during the activity. The management must ensure real-time
monitoring so that cash-related variance or discrepancies can be identified urgently and proper
control measures can be taken.
Relationship between audit risk, audit evidence, and financial statement assertions as it
specifically relates to this company and industry
Evidence
In the context of the Robbins Network Solutions organization, the specific pieces of
evidence or audit data that the team will be reviewing during the audit process include the
financial statements, i.e., the balance sheet, income statement and cash flow statement.
Additionally, accounts receivables and ageing of the accounts must also be reviewed to ascertain
the cash-related transactions are accurately maintained by the firm during the usual course of the
business operations. The bank statements of the firm must also be reviewed to check for any kind
of discrepancy that may arise in its books of accounts. A thorough reviewing of the diverse
financial accounts of the business entity can help to check its internal control quality and the
accuracy of its financial performance (El Gharbaoui & Chraibi, 2021).
Audit Universe
ACC 411 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 8
In case a major portion of the data of the organization is overseas, and thus, beyond the
jurisdiction or audit universe of the auditors, the scope of the auditing activity will automatically
get restricted. In such a context, the audit team might not have access to relevant and necessary
financial details and information about the business at an integrated level. In order to handle such
a situation can give rise to materiality risk relating to misrepresentation or misstatement of
financial data of RNS. Thus, the auditing team must include an adverse opinion reflecting that the
financial data relating to the overseas operations was not available, due to which a thorough and
rigorous auditing process could not be carried out. ‘Auditing Standard (AS) 2110: Identifying and
Assessing Risks of Material Misstatement must be followed to optimally perform risk assessment
procedures (PCAOB, 2010).
Analytical procedures
An in-depth analysis is a vital part of auditing activity. The analytical procedures that will
be carried out for determining the sampling program in the context of the RNS organization
involve the segregation of the sampling process. Initially, it is necessary to check whether the
general ledge balance of RNS matches the balances captured in banking and financial institution
reports. Then the analysis would involve checking the firm’s deposits to ensure their validity and
correctness. For example, in case there are any void cheques, they must be defaced so that they
cannot be used for fraudulent activities. In case there is any abnormality in the accounts payable,
then a thorough checking will be done to ensure that all disbursements have been approved by the
respective authorities. While checking the gross margin for the specific financial year, a
comparison will be made with the previous year to locate a pattern. My internal control evaluation
method will impact this step since high priority will be given to elements such as segregation of
ACC 411 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 9
duties among the organizational personnel and ensuring the adherence to relevant accounting
practices while recording the financial transactions.
Types of audit evidence
The specific type of audit evidence that will be requested from RNS include:
• Client confirmations
• Accounts payable proof
• Physical examination of assets like cash
• General ledger account details
The client confirmations relating to purchase requests will be checked. As a vital piece of
evidence, purchase orders will be asked. For checking the accounts payable proof, some of the
key pieces of evidence that will be requested include invoices, approval documents of signatories,
and the general ledger of the company. The physical examination will be done by going with an
official to one of the banks or financial institutions where the business deposits cash to ensure the
amount presented in the statement is actually present. The general ledger account details will also
serve as useful pieces of evidence. They will be used for reconciliation purposes and help to
ensure that the figures that have been recorded are accurate and match perfectly. e
Considerations while auditing subjective areas
While performing auditing of subjective areas, a number of considerations the auditing
team will have to make. One of the fundamental elements is that every request must be presented
in the form of writing. This form of communication will make sure that a systematic procedure is
adopted which can be well-documented as well. Another key consideration is the existence of an
ACC 411 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 10
internal audit function within the organization and the role that it plays to contribute to the quality
of the internal controls within the RNS organization (PCAOB, 2010).
Factors while planning the nature and extent of audit documentation
Audit documentation fundamentally involves the recording of auditing procedures that
have been applied, the pieces of evidence that have been obtained from an organization and the
conclusions that have been arrived at by the auditors. In the context of the Robbins Network
Solutions organization, a diverse range of factors have been taken into account while planning the
nature as well as the extent of the audit documentation. One of the chief factors that had been
taken into consideration is the quality of the audit evidence, including the availability of necessary
supportive documents. The audit risk factor was also considered since these elements could
compromise the quality of the auditing outcome. The internal communication was also a vital
factor that was taken into account while planning the audit documentation process. e
Responsibility for IT risk coverage
The Information technology (IT) landscape is highly dynamic. The responsibility for IT,
such as computer systems, software, databases and internet usage risk coverage for organizations
that operate in the IT domain continuously evolves. IT has a high responsibility to make sure that
adequate protection is in place that can prevent malicious actors such as online hackers and
cybercriminals from compromising sensitive and confidential business information. The IT
department has to focus on deploying a robust and well-functional cybersecurity framework that
can ensure that the latest security elements are in place that reduces the vulnerability of the
business entity in the vast and unpredictable cyber domain. Its responsibility also involves
ACC 411 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 11
ensuring the employees get familiarized with the IT elements and they have awareness relating to
cybersecurity.
Social media facilitates direct and real-time communication in the virtual setting. However, it also
increased online risks through social engineering attacks by hackers, etc. Thus, it is the
responsibility of IT to tackle the security concerns that arise through social media channels.
Internal Controls
The internal controls that have been introduced to specifically safeguard computer data
and proprietary information in the IT industry include a dedicated team of cybersecurity
professionals, ell-defined IT policies that are aligned with industry-level regulations and
standards and the use of cybersecurity tools and technologies such as firewalls, antivirus software
and intrusion detection and prevention systems. Other internal controls are maintaining data
backup, software licensing and termination of unauthorized system access.
Current and Future vulnerabilities
The current and future vulnerabilities exist for Information Technology due to the use of
outdated software, lack of frequent audit of IT logs and limited cybersecurity awareness of the
staff. For addressing these gaps so that the IT vulnerabilities can be reduced, it is necessary to
regularly update software and applications, ensure the timely and periodical auditing of IT logs of
an organization and offering training to staff members so that their awareness on cybersecurity
aspects can be improved and they can effectively identify and respond to abnormal or malicious
elements online.
Thank You
ACC 411 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 12
References
DiNapoli, T. P. (2007). Standards for internal control. New York State Government.
El Gharbaoui, B., & Chraibi, A. (2021). Internal audit quality and financial performance: A
systematic literature review pointing to new research opportunities. International Journal of
Management Sciences, 4(2).
PCAOB, P. (2010). AS 2110: Identifying and Assessing Risks of Material Misstatement.
PCAOB: Washington, DC.
Samimi, A. (2020). Risk management in information technology. Progress in Chemical and
Biochemical Research, 3(2), 130-134.
Types of internal controls. Finance & Accounting. (2021). Retrieved July 14, 2022, from
https://www.fa.ufl.edu/directives/types-of-internal-controls/
Sox compliance: A smarter way forward a new approach can . Deloitte. (2021). Retrieved August
6, 2022, from https://www2.deloitte.com/content/dam/Deloitte/us/Documents/risk/us-sox-
compliance-smarter-way-forward.pdf
Students also viewed