Accounting Information System Mini Case - Internal Controls
Summarizing Our Knowledge of the Application
Reports created
(standard and exception)
Report distribution
Review
Reconciliation
Output interfaces to
other applications
Output
Audit trails
Error reporting
Internal controls
Frequency of application
processes
Dependency of application on
processing cycles and
other applications
Processing Cycle
Initial edits
Data correction
Maintenance of master files
Data Edits
How data enters the processing
cycle
Input interfaces for
other applications
Source Data
© CPE Interactive, Inc., 2011-2015 2
Application Processes
Source Data Preparation & Authorization
Source Data Collection and
Entry
Data Processing
Output Review, Reconciliation, &
Error Handling
© CPE Interactive, Inc., 2011-2015 3
Data Between Other Apps
Authentication Completeness
Accuracy Integrity
Application Transaction Cycle
© CPE Interactive, Inc., 2011-2015 4
Data Origination
Data Preparation
Data Processing
Data Output
Internal or external
• Internal • Customer via
extranet or Web browser
• Interfacing application
• Edits • Calculation
s • Lookups • Logical
processes
• Report Distribution
• Document Distribution
• Reconciliation s
INPUT CONTROLS
© CPE Interactive, Inc., 2011-2015 5
Application Input Control Objectives
Input Controls – controls to ensure that transactions are: – Correctly input to the system
– Received by the system
– Accepted by the system
– Properly recorded and stored by the system
– Processed only once
– Are authorized
– Errors are identified, segregated from valid transactions, corrected in a timely manner
© CPE Interactive, Inc., 2011-2015 6
Source Data Preparation and Authorization
Control Objective (AC1) – Ensure that documents are prepared by authorized and qualified personnel following established procedures, taking into account segregation of duties regarding the origination and approval of these documents. Minimize errors and omissions through good input form design. Detect errors and irregularities so they can be reported and corrected.
© CPE Interactive, Inc., 2011-2015 7
Initial Data Conversion
Source Document
Web Input eCommerce
Partners
Process
© CPE Interactive, Inc., 2011-2015 8
Internal Source Data Preparation and Authorization – User Data Entry
Source documents and data entry form aligned Source documents accepted from specific departments aligned with
segregation of duties Documents are authorized according to a bill of authority, with
examples of signatures Source documents are uniquely numbered Source documents are batched and transmitted, with transmittal
documents and logs to ensure completeness Data preparation procedures are documented, followed, and
monitored, with appropriate training Cutoff times are established and maintained Erroneous source documents are uniquely numbered, returned to
originator, and followed-up for re-entry
© CPE Interactive, Inc., 2011-2015 9
Transaction Processing Internal Control
Objectives Description Specific Example (using accounts receivable/sales cycles)
Occurrence Recorded transactions are valid and documented
Recorded sales are supported by invoices, shipping documents, and customer order
Completeness All valid transactions are recorded, and none are omitted
All shipping documents are prenumbered and matched with sales invoices daily
Authorization Transactions are authorized according to company policy
Credit sales over $00 receive prior approval by a credit supervisor; credit sales over $,000 receive prior approval by cred manager
© CPE Interactive, Inc., 2011-2015 10
Transaction Processing Internal Control (2)
Objectives Description Specific Example (using accounts receivable/sales cycles)
Accuracy Transaction dollar amounts are properly calculated
Sales invoices contain correct quantities and are mathematically correct
Classification Transactions are properly classified in the account
• Sales to subsidiaries and affiliates are classified as intercompany transactions
• All sales on credit are charged to customers’ individual accounts
Cutoff Transactions are recorded in the proper period
Sales of the current period are charged to customers in the appropriate period, and sales in the succeeding period are charged in that period
© CPE Interactive, Inc., 2011-2015 11
Source Data Collection and Entry
Objectives – Ensure all transactions prepared for entry are entered
– Only authorized users are entering transactions
– Separation of duties is in place for mutually exclusive processes
– Transactions are validated to ensure accuracy
– Error re-entry processed as transactions are entered, if possible
– Transactions not passing edit, are identified, monitored and re-entered
© CPE Interactive, Inc., 2011-2015 12
Source Data Collection and Entry
TRX
Online Update Process
© CPE Interactive, Inc., 2011-2015 13
Source Data Collection and Entry Controls
Ensure all transactions prepared for entry are entered – Batch control
• Batch headers or trailers with transaction counts, financial totals, and/or has totals
• Reconciliation of batch totals at end of entry
– Entry of single entry with confirmation number that must be entered on source document
– After the fact batch control • System generates totals
• Data entered is totaled
– None • Rely on customer to complain
© CPE Interactive, Inc., 2011-2015 14
Only Authorized Users Are Entering Transactions
Identity Management (IdM) and Access Controls – Role-based IdM and Access Control
– Unique user id’s and no sharing of id’s
– Minimize system administration user id’s and limit privileges if possible
– Monitor user access
– Require manager review and recertification of users having privileges to their assigned data ownership
Unique id of user entering transaction is entered and maintained in the record
Date and time of transaction is recorded in the record
© CPE Interactive, Inc., 2011-2015 15
Separation of Duties
Transaction assignment based upon job function
Transactions aggregated into roles
Mutually exclusive roles for transactions that require separation of duties
Special attention to master table/file transactions
Exception reporting for unusual transactions, access, and other identifiable activities
© CPE Interactive, Inc., 2011-2015 16
Transaction Validation / Editing
Pull-down fields or displayed valid value selection Field formatting
– Telephone numbers – Postal Code – Social insurance number – Internal codes with defined formats
Check digits Item counts
– Invoice has x lines
Valid character tests Missing data – verify no data missing before accepting the
transaction Sequence tests
© CPE Interactive, Inc., 2011-2015 17
Transaction Validation / Editing (2)
Limit tests – Type of transaction – Value within the transaction
• Payroll class • Vendor payment plan
Reasonableness test – Require double entry for unusual amounts – Dialog -> ARE YOU SURE?
Lookup and verification Double entry with masking previous entry
– Similar to password entry
Suspension of records not passing validation / editing
© CPE Interactive, Inc., 2011-2015 18
Transaction Authorization
Reliance on IdM
Authority levels assigned by role
Secondary authorization established to achieve separation of duties, or satisfy validation / editing processes
Secondary authorization recorded in transaction record (date, time, id)
Suspension of record if immediate secondary authorization is not possible
© CPE Interactive, Inc., 2011-2015 19
Error Processing
All errors that can be identified as entered are identified and require correction prior to acceptance
All errors that are identified after entry and all suspended records are subject to “issue monitoring”
Issue Monitoring process includes: – Aging of suspended or erroneous record – Timely reporting of issues to appropriate management and
staff – Escalation of issues remaining open – Summary reporting of issues, identify
• Systemic issues • Additional training requirements • System modifications
© CPE Interactive, Inc., 2011-2015 20
Special Considerations
Client/Server
– Client on the workstation has to be the same version as the server
– Verification of version levels during connection
Web Applications
– Browser Cache emptied after each use
– All input is recalculated after entry
– Data in the URL of the browser is unreconizable
© CPE Interactive, Inc., 2011-2015 21
Special Considerations (2)
Data Received from External Source
– Defining External Source
• SaaS vendor
• Trading partner
– Encryption
• Symmetric Keys
• Public Keys
– Header/Trailer Batch Totals
© CPE Interactive, Inc., 2011-2015 22
PROCESSING CONTROLS
© CPE Interactive, Inc., 2011-2015 23
Processing Controls
Objectives:
– Ensure accuracy and completeness of processed data
– Ensure data at rest (on a file/database) remains accurate and complete until it is changed as a result of authorized processing or modification
© CPE Interactive, Inc., 2011-2015 24
Processing Controls (2)
Completeness – Batch
• Reconciliation - Transaction file totals compared to master file totals before and after process – Three-way match:
» master file = transaction file + old_masterfile
» Transaction file = batch totals of data entry forms
• Control totals: – Transaction monetary amount
– Item count
– Documents count
– Hash total of numeric field
© CPE Interactive, Inc., 2011-2015 25
Processing Controls (3)
Completeness (Continued)
– Batch and online
• Reliance on database management system – Test for DBMS verification of processing success
» Return_code = Addrec or chgrec
» Return_code must equal 0 (as defined by DBMS) to indicate successful add or change
» Test return_code after each transaction and report to user disposition
© CPE Interactive, Inc., 2011-2015 26
Processing Controls (4)
Accuracy
– Reliance on change management and testing
Occurrence
– Matching transaction to another source
• Three way purchase cycle match – invoice/purchase order/receiving document
© CPE Interactive, Inc., 2011-2015 27
Processing Controls (5)
Classification
– Valid classifications based on record type (Chart of Accounts, customer, employee HR level)
Cutoff
– Date established by system at time of entry or processing, not editable
– Date defined in process in accordance with accounting rules
– Processes started once all data is available
© CPE Interactive, Inc., 2011-2015 28
Error Processing
Objective:
– Ensure that all transactions not completing the processing cycle are identified, researched, and either corrected or removed from the processing cycle
– Ensure that all transactions with errors are disposed of on a timely basis
© CPE Interactive, Inc., 2011-2015 29
Error Processing
Batch error handling (legacy systems) and interfacing system: – Rejecting only transactions with errors – Rejecting the whole batch of transactions – Holding the batch in suspense – Accepting the batch and flagging error transactions
Batch re-entry controls – Notification of pending batches – Aging of open batches
Online – Immediate operator notification – Prohibit transaction to continue prior to correction – Suspense transactions that can’t be completed
• Unique ID • Follow-up process
© CPE Interactive, Inc., 2011-2015 30
Data File or Data Base Tables
Encryption of key data fields
Limitation of table and column access
– Only via authorized programs
– Limiting ODBC access
Monitoring SA (super user) or equivalent user IDs
© CPE Interactive, Inc., 2011-2015 31
OUTPUT CONTROLS
© CPE Interactive, Inc., 2011-2015 32
Output Controls
Provide assurance that data and information delivered to users and other systems will be:
– Relevant and reliable
– Presented and formatted to help ensure understandability
– Consistent and secure
– Available when needed
© CPE Interactive, Inc., 2011-2015 33
Output Controls (2)
Logging and storage of negotiable, sensitive and critical forms in a secure place – Checks
– Certificates
Computer generation of negotiable instruments, forms and signatures – Control of signature plate
– Limit access to the print queue
– Sequential numbering
– Inventory of forms
© CPE Interactive, Inc., 2011-2015 34
Output Controls (3)
Balancing and reconciling – Assignment of process – Process for researching out-of-balance conditions – Correction of out-of-balance conditions
Monitoring and managing other output error conditions Master file changes Report distribution
– Distribution Lists – Special procedures for confidential and/or negotiable
instruments • Limits on forwarding or re-distribution
– Verification of receipt of reports
Output report retention
© CPE Interactive, Inc., 2011-2015 35
Outbound Transactions
Controls should ensure that only properly authorized outbound transactions are distributed
– Purchase orders
– Payments
– Auto-adjudicated transactions
© CPE Interactive, Inc., 2011-2015 36
Outbound Transactions (2)
The control considerations for outbound transactions: – Controlling the set up and change of trading
partner details
– Comparing transactions with trading partner transaction profiles
– Matching the trading partner number to the trading master file, prior to transmission
– Limiting the authority of users within the organization to initiate specific EDI transactions
© CPE Interactive, Inc., 2011-2015 37