1 / 12100%
Running Head: ACC 411 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 1
7-2 Final Project Submission
ACC 411
SNHU
August 13,2022
ACC 411 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 2
To: Auditing team of ABC Accounting Pvt. Ltd.
From: Mr. John Doe, Auditor of ABC Accounting Pvt. Ltd.
Date: July 14, 2022
Subject: Evaluation of the internal controls of Robbins Network Solutions
Internal Controls of Robbins Network Solutions
Robbins Network Solutions (RNS) operates in the highly competitive and dynamic market
involving computers and networking products. An audit plan is created for the organization to
ensure that there exists proper internal control within the organization. A detailed analysis of the
business environment of RNS has been carried out. Additionally, the focus has been laid on the
typical business transactions that are performed by the firm. The business risks that arise before
RNS have also been identified. The impact of the current events on the risks and internal controls of
the firm in the future have been analyzed. The memo also sheds light on the potential ethical issues
that may arise for the firm and the types of internal control that must be adopted to maintain ethical
and professional practices.
Major financial business transactions
The chief financial business transactions that RNS is involved in include the selling as well
as installation of computer systems and networking software and hardware components. In
addition to making these offerings in the market, RNS provides information technology consulting
to diverse business entities. At present, the company has been focusing on designing its computer
networking software that will be sold to the customers. By aggressively marketing the services and
products of the business, the firm carries out its major financial business transactions. While
ACC 411 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 3
conducting business transactions, it is imperative for firms to maintain proper evidence such as
cash memos, invoices, salary slips, etc.
Highest business risks
RNS encounters a broad range of risks and threats while conducting its business activities.
Some of the major risks include high competition from top market players such as Dell, Apple and
Hewlett Packard (HP) and high expenditure relating to advertising of its products and services in
the market. The unpredictability that exists in the macro environment also increases the level of
uncertainty for the form. For instance, a major downturn in the U.S. economy could impact its
financial performance and market demand. Other risks that arise for RNS include the possibility of
credit losses exceeding sales benefits and the lack of viability of software development initiatives
of the business. As the industry in which RNS operates is influenced by evolving technology, the
degree of risk is high. Businesses that involve technology are prone to high risk and uncertainty
(Samimi, 2020). Competition is a major risk that could adversely affect its market share and
profitability.
Appropriate types of internal controls for the industry
Internal controls can be categorized into detective, corrective and preventive. Each of them
plays a distinctive role in an organizational setting (Types of internal controls. Finance &
Accounting, 2021). In the computer products and technology services industry, there is a need to
have in place appropriate internal control mechanisms. Such control mechanisms are critical since
they can offer reasonable assurance about the operations, reporting, as well as compliance
dimensions while conducting an audit process. In the specific organizational context, preventive
internal control measures must be adopted so that proper actions can be taken before the occurrence
ACC 411 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 4
of fraud or erroneous activities. For instance, a robust corporate governance framework must be
adopted that focuses on confidentiality, availability and integrity of data. Preventive internal
controls are suitable in the specific industrial setting since they can act as a barrier and block
undesirable events or occurrences from taking place. Some of the key steps that can be taken are
authorization of bills and invoices, verification of the expenses, etc. (DiNapoli, 2007).
Ethical Issues
A number of ethical issues are related to the RNS company that could have a direct impact
on the outcome of a financial audit process. One of the main ethical issues is the unethical behavior
of the two stockholders who are actively involved in the organizational transactions. There is a
possibility that they could focus on their personal interests and gains. The organization gives
preference to staff members that possess high technical expertise and skills. Such a staff selection
and hiring procedure could adversely affect the financial activities, including the manner in which
the transactions are recorded and maintained. For resolving the first ethical issue, all the
stockholders must take part in the business activities so that the possibility of fraud can be reduced.
Similarly, the hiring process must be made flexible so that employees with adequate financial
knowledge can be hired.
Current events impacting RNS’s risks and internal controls in the future f
Some of the current events that could impact RNS’s risks and internal controls in the future
include cybersecurity issues, changes relating to laws on taxes and accounting principles.
Additionally, regulations relating to the use of technology can also impact the risks that it
encounters and the manner in which it adopts internal control measures.
ACC 411 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 5
Auditing of cash
Auditing of cash is regarded to be a critical process that helps in accurately categorizing
cash elements in the financial statements of an organization. In the case of Robbins Network
Solutions (RNS), the existence of a robust audit program (plan) is essential for evaluating its
internal controls for cash. It can help in ensuring the completeness of the cash-related transactions
of the organization. Both risk assessment and control activities have been integrated into the audit
plan and monitoring and communication aspects.
Control environment
In order to ensure there is proper internal control of cash within RNS, the auditors must
have a thorough insight into the process of managing cash and recording cash-related transactions.
The policies and protocols relating to cash activities must be checked and properly understood.
Additionally, to ensure a robust control environment is in place while understanding the cash
management and recording processes, random testing must be done. For example, while the
financial officer of RNS explains the processes, he must be asked to use a real-life example to show
how internal control over cash accounts is maintained. The accounts reconciliation or bank
statements can be used to explain the current internal control measures in RNS.
Risk assessment
The risk assessment must be done at an integrated level to ensure there is proper internal
control of cash. The chief elements that need to be taken into consideration while assessing cash-
related risks of the organization include the materiality of the balance sheet, segregation of duties,
and cash account reviews. Checking balance sheet materiality is vital to identify any misstatement
in the records. Existing controls to detect fraudulent activities must be examined in detail. While
ACC 411 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 6
checking accounts such as accounts receivable, the manner in which roles and duties are segregated
must be checked. There must be a clear distinction between the person that prepares these accounts
within RNS and the person who reviews them. The reconciliation of cash accounts must be done by
the ones who prepare them so that they can identify any omissions. The frequency of performing
cash account reviews as well as authorized signatories for the accounts must be checked.
Control activities
The existence of well-functional and effective control activities is vital to make sure there is
internal control of cash. In the context of RNS, a broad range of control activities can be carried out
to ensure compliance with Generally Accepted Accounting Principles (GAAP) and identify the
possibility of fraudulent activities. Some of the major control activities that need to be conducted
within the RNS entity are testing the account records, confirmation of cash balances with financial
institutions, and analysis of bank transfers. Similarly, the comparison of cash receipt samples with
the cash receipt journal of the organization is vital to identify poor control over cash transactions.
The presentation of financial statements along with disclosures of RNS’ cash must be evaluated
thoroughly.
Information and communication
Real-time communication of activities is vital to locating cash-related risks. Information
flow must be done in a timely manner, and any major concerns or weaknesses need to be reported to
the respective authority, such as managers or supervisors. Other minor issues or deficiencies must
be addressed by the auditor, and they must be disclosed to the management of RNS. According to
the Sarbanes-Oxley Act (SOX), stringent reporting and security standards must be in place so that
proper control can be ensured. The external auditors must conduct annual or quarterly reviews that
ACC 411 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 7
can help in identifying any cash-related concerns (Sox compliance: A smarter way forward a new
approach can . Deloitte, 2021).
Monitoring
The monitoring of cash transactions of RNS must be done continuously. Innovative
analytical methods can be used during the activity. The management must ensure real-time
monitoring so that cash-related variance or discrepancies can be identified urgently and proper
control measures can be taken.
Relationship between audit risk, audit evidence, and financial statement assertions as it
specifically relates to this company and industry
Evidence
In the context of the Robbins Network Solutions organization, the specific pieces of
evidence or audit data that the team will be reviewing during the audit process include the financial
statements, i.e., the balance sheet, income statement and cash flow statement. Additionally,
accounts receivables and ageing of the accounts must also be reviewed to ascertain the cash-related
transactions are accurately maintained by the firm during the usual course of the business
operations. The bank statements of the firm must also be reviewed to check for any kind of
discrepancy that may arise in its books of accounts. A thorough reviewing of the diverse financial
accounts of the business entity can help to check its internal control quality and the accuracy of its
financial performance (El Gharbaoui & Chraibi, 2021).
Audit Universe
ACC 411 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 8
In case a major portion of the data of the organization is overseas, and thus, beyond the
jurisdiction or audit universe of the auditors, the scope of the auditing activity will automatically
get restricted. In such a context, the audit team might not have access to relevant and necessary
financial details and information about the business at an integrated level. In order to handle such a
situation can give rise to materiality risk relating to misrepresentation or misstatement of financial
data of RNS. Thus, the auditing team must include an adverse opinion reflecting that the financial
data relating to the overseas operations was not available, due to which a thorough and rigorous
auditing process could not be carried out. ‘Auditing Standard (AS) 2110: Identifying and Assessing
Risks of Material Misstatement must be followed to optimally perform risk assessment procedures
(PCAOB, 2010).
Analytical procedures
An in-depth analysis is a vital part of auditing activity. The analytical procedures that will
be carried out for determining the sampling program in the context of the RNS organization involve
the segregation of the sampling process. Initially, it is necessary to check whether the general ledge
balance of RNS matches the balances captured in banking and financial institution reports. Then
the analysis would involve checking the firm’s deposits to ensure their validity and correctness. For
example, in case there are any void cheques, they must be defaced so that they cannot be used for
fraudulent activities. In case there is any abnormality in the accounts payable, then a thorough
checking will be done to ensure that all disbursements have been approved by the respective
authorities. While checking the gross margin for the specific financial year, a comparison will be
made with the previous year to locate a pattern. My internal control evaluation method will impact
this step since high priority will be given to elements such as segregation of duties among the
ACC 411 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 9
organizational personnel and ensuring the adherence to relevant accounting practices while
recording the financial transactions.
Types of audit evidence
The specific type of audit evidence that will be requested from RNS include:
• Client confirmations
• Accounts payable proof
• Physical examination of assets like cash
• General ledger account details
The client confirmations relating to purchase requests will be checked. As a vital piece of
evidence, purchase orders will be asked. For checking the accounts payable proof, some of the key
pieces of evidence that will be requested include invoices, approval documents of signatories, and
the general ledger of the company. The physical examination will be done by going with an official
to one of the banks or financial institutions where the business deposits cash to ensure the amount
presented in the statement is actually present. The general ledger account details will also serve as
useful pieces of evidence. They will be used for reconciliation purposes and help to ensure that the
figures that have been recorded are accurate and match perfectly. f
Considerations while auditing subjective areas
While performing auditing of subjective areas, a number of considerations the auditing
team will have to make. One of the fundamental elements is that every request must be presented in
the form of writing. This form of communication will make sure that a systematic procedure is
adopted which can be well-documented as well. Another key consideration is the existence of an
ACC 411 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 10
internal audit function within the organization and the role that it plays to contribute to the quality
of the internal controls within the RNS organization (PCAOB, 2010).
Factors while planning the nature and extent of audit documentation
Audit documentation fundamentally involves the recording of auditing procedures that
have been applied, the pieces of evidence that have been obtained from an organization and the
conclusions that have been arrived at by the auditors. In the context of the Robbins Network
Solutions organization, a diverse range of factors have been taken into account while planning the
nature as well as the extent of the audit documentation. One of the chief factors that had been taken
into consideration is the quality of the audit evidence, including the availability of necessary
supportive documents. The audit risk factor was also considered since these elements could
compromise the quality of the auditing outcome. The internal communication was also a vital
factor that was taken into account while planning the audit documentation process. f
Responsibility for IT risk coverage
The Information technology (IT) landscape is highly dynamic. The responsibility for IT,
such as computer systems, software, databases and internet usage risk coverage for organizations
that operate in the IT domain continuously evolves. IT has a high responsibility to make sure that
adequate protection is in place that can prevent malicious actors such as online hackers and
cybercriminals from compromising sensitive and confidential business information. The IT
department has to focus on deploying a robust and well-functional cybersecurity framework that
can ensure that the latest security elements are in place that reduces the vulnerability of the business
entity in the vast and unpredictable cyber domain. Its responsibility also involves ensuring the
employees get familiarized with the IT elements and they have awareness relating to cybersecurity.
ACC 411 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 11
Social media facilitates direct and real-time communication in the virtual setting. However, it also
increased online risks through social engineering attacks by hackers, etc. Thus, it is the
responsibility of IT to tackle the security concerns that arise through social media channels.
Internal Controls
The internal controls that have been introduced to specifically safeguard computer data and
proprietary information in the IT industry include a dedicated team of cybersecurity professionals,
ell-defined IT policies that are aligned with industry-level regulations and standards and the use of
cybersecurity tools and technologies such as firewalls, antivirus software and intrusion detection
and prevention systems. Other internal controls are maintaining data backup, software licensing
and termination of unauthorized system access.
Current and Future vulnerabilities
The current and future vulnerabilities exist for Information Technology due to the use of
outdated software, lack of frequent audit of IT logs and limited cybersecurity awareness of the staff.
For addressing these gaps so that the IT vulnerabilities can be reduced, it is necessary to regularly
update software and applications, ensure the timely and periodical auditing of IT logs of an
organization and offering training to staff members so that their awareness on cybersecurity aspects
can be improved and they can effectively identify and respond to abnormal or malicious elements
online.
Thank You
ACC 411 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 12
References
DiNapoli, T. P. (2007). Standards for internal control. New York State Government.
El Gharbaoui, B., & Chraibi, A. (2021). Internal audit quality and financial performance: A
systematic literature review pointing to new research opportunities. International Journal of
Management Sciences, 4(2).
PCAOB, P. (2010). AS 2110: Identifying and Assessing Risks of Material Misstatement. PCAOB:
Washington, DC.
Samimi, A. (2020). Risk management in information technology. Progress in Chemical and
Biochemical Research, 3(2), 130-134.
Types of internal controls. Finance & Accounting. (2021). Retrieved July 14, 2022, from
https://www.fa.ufl.edu/directives/types-of-internal-controls/
Sox compliance: A smarter way forward a new approach can . Deloitte. (2021). Retrieved August
6, 2022, from https://www2.deloitte.com/content/dam/Deloitte/us/Documents/risk/us-sox-
compliance-smarter-way-forward.pdf
Students also viewed