Running Head: ACC 411 aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa 1
7-2 Final Project Submission
ACC 411
SNHU
ACC 411 aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa
aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 2
Subject: Evaluation of the internal controls of Robbins Network Solutions
Internal Controls of Robbins Network Solutions
Robbins Network Solutions (RNS) operates in the highly competitive and dynamic
market involving computers and networking products. An audit plan is created for the
organization to ensure that there exists proper internal control within the organization. A
detailed analysis of the business environment of RNS has been carried out. Additionally, the
focus has been laid on the typical business transactions that are performed by the firm. The
business risks that arise before RNS have also been identified. The impact of the current
events on the risks and internal controls of the firm in the future have been analyzed. The
memo also sheds light on the potential ethical issues that may arise for the firm and the
types of internal control that must be adopted to maintain ethical and professional practices.
Major financial business transactions
The chief financial business transactions that RNS is involved in include the selling
as well as installation of computer systems and networking software and hardware
components. In addition to making these offerings in the market, RNS provides information
technology consulting to diverse business entities. At present, the company has been
focusing on designing its computer networking software that will be sold to the customers.
By aggressively marketing the services and products of the business, the firm carries out its
major financial business transactions. While conducting business transactions, it is imperative
for firms to maintain proper evidence such as cash memos, invoices, salary slips, etc.
ACC 411 aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa
aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 3
Highest business risks
RNS encounters a broad range of risks and threats while conducting its business
activities. Some of the major risks include high competition from top market players such as
Dell, Apple and Hewlett Packard (HP) and high expenditure relating to advertising of its
products and services in the market. The unpredictability that exists in the macro
environment also increases the level of uncertainty for the form. For instance, a major
downturn in the U.S. economy could impact its financial performance and market demand.
Other risks that arise for RNS include the possibility of credit losses exceeding sales benefits
and the lack of viability of software development initiatives of the business. As the industry
in which RNS operates is influenced by evolving technology, the degree of risk is high.
Businesses that involve technology are prone to high risk and uncertainty (Samimi, 2020).
Competition is a major risk that could adversely affect its market share and profitability.
Appropriate types of internal controls for the industry
Internal controls can be categorized into detective, corrective and preventive. Each of
them plays a distinctive role in an organizational setting (Types of internal controls. Finance
& Accounting, 2021). In the computer products and technology services industry, there is a
need to have in place appropriate internal control mechanisms. Such control mechanisms are
critical since they can offer reasonable assurance about the operations, reporting, as well as
compliance dimensions while conducting an audit process. In the specific organizational
context, preventive internal control measures must be adopted so that proper actions can be
taken before the occurrence of fraud or erroneous activities. For instance, a robust corporate
governance framework must be adopted that focuses on confidentiality, availability and
ACC 411 aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 4
integrity of data. Preventive internal controls are suitable in the specific industrial setting
since they can act as a barrier and block undesirable events or occurrences from taking
place. Some of the key steps that can be taken are authorization of bills and invoices,
verification of the expenses, etc. (DiNapoli, 2007).
Ethical Issues
A number of ethical issues are related to the RNS company that could have a direct
impact on the outcome of a financial audit process. One of the main ethical issues is the
unethical behavior of the two stockholders who are actively involved in the organizational
transactions. There is a possibility that they could focus on their personal interests and gains.
The organization gives preference to staff members that possess high technical expertise and
skills. Such a staff selection and hiring procedure could adversely affect the financial
activities, including the manner in which the transactions are recorded and maintained. For
resolving the first ethical issue, all the stockholders must take part in the business activities
so that the possibility of fraud can be reduced. Similarly, the hiring process must be made
flexible so that employees with adequate financial knowledge can be hired.
Current events impacting RNS’s risks and internal controls in the future aa
Some of the current events that could impact RNS’s risks and internal controls in the
future include cybersecurity issues, changes relating to laws on taxes and accounting
principles. Additionally, regulations relating to the use of technology can also impact the
risks that it encounters and the manner in which it adopts internal control measures.
ACC 411 aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 5
Auditing of cash
Auditing of cash is regarded to be a critical process that helps in accurately
categorizing cash elements in the financial statements of an organization. In the case of
Robbins Network Solutions (RNS), the existence of a robust audit program (plan) is
essential for evaluating its internal controls for cash. It can help in ensuring the
completeness of the cash-related transactions of the organization. Both risk assessment and
control activities have been integrated into the audit plan and monitoring and communication
aspects.
Control environment
In order to ensure there is proper internal control of cash within RNS, the auditors
must have a thorough insight into the process of managing cash and recording cash-related
transactions. The policies and protocols relating to cash activities must be checked and
properly understood. Additionally, to ensure a robust control environment is in place while
understanding the cash management and recording processes, random testing must be done.
For example, while the financial officer of RNS explains the processes, he must be asked to
use a real-life example to show how internal control over cash accounts is maintained. The
accounts reconciliation or bank statements can be used to explain the current internal control
measures in RNS.
Risk assessment
The risk assessment must be done at an integrated level to ensure there is proper
internal control of cash. The chief elements that need to be taken into consideration while
assessing cash-related risks of the organization include the materiality of the balance sheet,
ACC 411 aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 6
segregation of duties, and cash account reviews. Checking balance sheet materiality is vital
to identify any misstatement in the records. Existing controls to detect fraudulent activities
must be examined in detail. While checking accounts such as accounts receivable, the
manner in which roles and duties are segregated must be checked. There must be a clear
distinction between the person that prepares these accounts within RNS and the person who
reviews them. The reconciliation of cash accounts must be done by the ones who prepare
them so that they can identify any omissions. The frequency of performing cash account
reviews as well as authorized signatories for the accounts must be checked.
Control activities
The existence of well-functional and effective control activities is vital to make sure
there is internal control of cash. In the context of RNS, a broad range of control activities
can be carried out to ensure compliance with Generally Accepted Accounting Principles
(GAAP) and identify the possibility of fraudulent activities. Some of the major control
activities that need to be conducted within the RNS entity are testing the account records,
confirmation of cash balances with financial institutions, and analysis of bank transfers.
Similarly, the comparison of cash receipt samples with the cash receipt journal of the
organization is vital to identify poor control over cash transactions. The presentation of
financial statements along with disclosures of RNS’ cash must be evaluated thoroughly.
Information and communication
Real-time communication of activities is vital to locating cash-related risks.
Information flow must be done in a timely manner, and any major concerns or weaknesses
need to be reported to the respective authority, such as managers or supervisors. Other minor
ACC 411 aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 7
issues or deficiencies must be addressed by the auditor, and they must be disclosed to the
management of RNS. According to the Sarbanes-Oxley Act (SOX), stringent reporting and
security standards must be in place so that proper control can be ensured. The external
auditors must conduct annual or quarterly reviews that can help in identifying any cash-
related concerns (Sox compliance: A smarter way forward a new approach can . Deloitte,
2021).
Monitoring
The monitoring of cash transactions of RNS must be done continuously. Innovative
analytical methods can be used during the activity. The management must ensure real-time
monitoring so that cash-related variance or discrepancies can be identified urgently and
proper control measures can be taken.
Relationship between audit risk, audit evidence, and financial statement assertions as
it specifically relates to this company and industry
Evidence
In the context of the Robbins Network Solutions organization, the specific pieces of
evidence or audit data that the team will be reviewing during the audit process include the
financial statements, i.e., the balance sheet, income statement and cash flow statement.
Additionally, accounts receivables and ageing of the accounts must also be reviewed to
ascertain the cash-related transactions are accurately maintained by the firm during the usual
course of the business operations. The bank statements of the firm must also be reviewed to
check for any kind of discrepancy that may arise in its books of accounts. A thorough
reviewing of the diverse financial accounts of the business entity can help to check its
ACC 411 aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 8
internal control quality and the accuracy of its financial performance (El Gharbaoui &
Chraibi, 2021).
Audit Universe
In case a major portion of the data of the organization is overseas, and thus, beyond
the jurisdiction or audit universe of the auditors, the scope of the auditing activity will
automatically get restricted. In such a context, the audit team might not have access to
relevant and necessary financial details and information about the business at an integrated
level. In order to handle such a situation can give rise to materiality risk relating to
misrepresentation or misstatement of financial data of RNS. Thus, the auditing team must
include an adverse opinion reflecting that the financial data relating to the overseas
operations was not available, due to which a thorough and rigorous auditing process could
not be carried out. ‘Auditing Standard (AS) 2110: Identifying and Assessing Risks of
Material Misstatement must be followed to optimally perform risk assessment procedures
(PCAOB, 2010).
Analytical procedures
An in-depth analysis is a vital part of auditing activity. The analytical procedures that
will be carried out for determining the sampling program in the context of the RNS
organization involve the segregation of the sampling process. Initially, it is necessary to
check whether the general ledge balance of RNS matches the balances captured in banking
and financial institution reports. Then the analysis would involve checking the firm’s
deposits to ensure their validity and correctness. For example, in case there are any void
cheques, they must be defaced so that they cannot be used for fraudulent activities. In case
ACC 411 aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 9
there is any abnormality in the accounts payable, then a thorough checking will be done to
ensure that all disbursements have been approved by the respective authorities. While
checking the gross margin for the specific financial year, a comparison will be made with
the previous year to locate a pattern. My internal control evaluation method will impact this
step since high priority will be given to elements such as segregation of duties among the
organizational personnel and ensuring the adherence to relevant accounting practices while
recording the financial transactions.
Types of audit evidence
The specific type of audit evidence that will be requested from RNS include:
• Client confirmations
• Accounts payable proof
• Physical examination of assets like cash
• General ledger account details
The client confirmations relating to purchase requests will be checked. As a vital piece
of evidence, purchase orders will be asked. For checking the accounts payable proof, some
of the key pieces of evidence that will be requested include invoices, approval documents of
signatories, and the general ledger of the company. The physical examination will be done
by going with an official to one of the banks or financial institutions where the business
deposits cash to ensure the amount presented in the statement is actually present. The
general ledger account details will also serve as useful pieces of evidence. They will be used
for reconciliation purposes and help to ensure that the figures that have been recorded are
accurate and match perfectly. aa
ACC 411 aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 10
Considerations while auditing subjective areas
While performing auditing of subjective areas, a number of considerations the
auditing team will have to make. One of the fundamental elements is that every request
must be presented in the form of writing. This form of communication will make sure that a
systematic procedure is adopted which can be well-documented as well. Another key
consideration is the existence of an internal audit function within the organization and the
role that it plays to contribute to the quality of the internal controls within the RNS
organization (PCAOB, 2010).
Factors while planning the nature and extent of audit documentation
Audit documentation fundamentally involves the recording of auditing procedures that
have been applied, the pieces of evidence that have been obtained from an organization and
the conclusions that have been arrived at by the auditors. In the context of the Robbins
Network Solutions organization, a diverse range of factors have been taken into account
while planning the nature as well as the extent of the audit documentation. One of the chief
factors that had been taken into consideration is the quality of the audit evidence, including
the availability of necessary supportive documents. The audit risk factor was also considered
since these elements could compromise the quality of the auditing outcome. The internal
communication was also a vital factor that was taken into account while planning the audit
documentation process. a
Responsibility for IT risk coverage
The Information technology (IT) landscape is highly dynamic. The responsibility for
IT, such as computer systems, software, databases and internet usage risk coverage for
ACC 411 aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 11
organizations that operate in the IT domain continuously evolves. IT has a high
responsibility to make sure that adequate protection is in place that can prevent malicious
actors such as online hackers and cybercriminals from compromising sensitive and
confidential business information. The IT department has to focus on deploying a robust and
well-functional cybersecurity framework that can ensure that the latest security elements are
in place that reduces the vulnerability of the business entity in the vast and unpredictable
cyber domain. Its responsibility also involves ensuring the employees get familiarized with
the IT elements and they have awareness relating to cybersecurity.
Social media facilitates direct and real-time communication in the virtual setting. However, it
also increased online risks through social engineering attacks by hackers, etc. Thus, it is the
responsibility of IT to tackle the security concerns that arise through social media channels.
Internal Controls
The internal controls that have been introduced to specifically safeguard computer
data and proprietary information in the IT industry include a dedicated team of cybersecurity
professionals, ell-defined IT policies that are aligned with industry-level regulations and
standards and the use of cybersecurity tools and technologies such as firewalls, antivirus
software and intrusion detection and prevention systems. Other internal controls are
maintaining data backup, software licensing and termination of unauthorized system access.
Current and Future vulnerabilities
The current and future vulnerabilities exist for Information Technology due to the use
of outdated software, lack of frequent audit of IT logs and limited cybersecurity awareness
of the staff. For addressing these gaps so that the IT vulnerabilities can be reduced, it is
ACC 411 aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 12
necessary to regularly update software and applications, ensure the timely and periodical
auditing of IT logs of an organization and offering training to staff members so that their
awareness on cybersecurity aspects can be improved and they can effectively identify and
respond to abnormal or malicious elements online.
References
DiNapoli, T. P. (2007). Standards for internal control. New York State Government.
El Gharbaoui, B., & Chraibi, A. (2021). Internal audit quality and financial performance: A
systematic literature review pointing to new research opportunities. International
Journal of Management Sciences, 4(2).
PCAOB, P. (2010). AS 2110: Identifying and Assessing Risks of Material Misstatement.
PCAOB: Washington, DC.
Samimi, A. (2020). Risk management in information technology. Progress in Chemical and
Biochemical Research, 3(2), 130-134.
Types of internal controls. Finance & Accounting. (2021). Retrieved July 14, 2022, from
https://www.fa.ufl.edu/directives/types-of-internal-controls/
ACC 411 aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 13
Sox compliance: A smarter way forward a new approach can . Deloitte. (2021). Retrieved
August 6, 2022, from
https://www2.deloitte.com/content/dam/Deloitte/us/Documents/risk/us-sox-compliance-
smarter-way-forward.pdf