Accounting Information System Mini Case - Internal Controls

profileUsernameyyy
internal_controls_supplemental_slides.pdf

Summarizing Our Knowledge of the Application

Reports created

(standard and exception)

Report distribution

Review

Reconciliation

Output interfaces to

other applications

Output

Audit trails

Error reporting

Internal controls

Frequency of application

processes

Dependency of application on

processing cycles and

other applications

Processing Cycle

Initial edits

Data correction

Maintenance of master files

Data Edits

How data enters the processing

cycle

Input interfaces for

other applications

Source Data

© CPE Interactive, Inc., 2011-2015 2

Application Processes

Source Data Preparation & Authorization

Source Data Collection and

Entry

Data Processing

Output Review, Reconciliation, &

Error Handling

© CPE Interactive, Inc., 2011-2015 3

Data Between Other Apps

Authentication Completeness

Accuracy Integrity

Application Transaction Cycle

© CPE Interactive, Inc., 2011-2015 4

Data Origination

Data Preparation

Data Processing

Data Output

Internal or external

• Internal • Customer via

extranet or Web browser

• Interfacing application

• Edits • Calculation

s • Lookups • Logical

processes

• Report Distribution

• Document Distribution

• Reconciliation s

INPUT CONTROLS

© CPE Interactive, Inc., 2011-2015 5

Application Input Control Objectives

 Input Controls – controls to ensure that transactions are: – Correctly input to the system

– Received by the system

– Accepted by the system

– Properly recorded and stored by the system

– Processed only once

– Are authorized

– Errors are identified, segregated from valid transactions, corrected in a timely manner

© CPE Interactive, Inc., 2011-2015 6

Source Data Preparation and Authorization

 Control Objective (AC1) – Ensure that documents are prepared by authorized and qualified personnel following established procedures, taking into account segregation of duties regarding the origination and approval of these documents. Minimize errors and omissions through good input form design. Detect errors and irregularities so they can be reported and corrected.

© CPE Interactive, Inc., 2011-2015 7

Initial Data Conversion

Source Document

Web Input eCommerce

Partners

Process

© CPE Interactive, Inc., 2011-2015 8

Internal Source Data Preparation and Authorization – User Data Entry

 Source documents and data entry form aligned  Source documents accepted from specific departments aligned with

segregation of duties  Documents are authorized according to a bill of authority, with

examples of signatures  Source documents are uniquely numbered  Source documents are batched and transmitted, with transmittal

documents and logs to ensure completeness  Data preparation procedures are documented, followed, and

monitored, with appropriate training  Cutoff times are established and maintained  Erroneous source documents are uniquely numbered, returned to

originator, and followed-up for re-entry

© CPE Interactive, Inc., 2011-2015 9

Transaction Processing Internal Control

Objectives Description Specific Example (using accounts receivable/sales cycles)

Occurrence Recorded transactions are valid and documented

Recorded sales are supported by invoices, shipping documents, and customer order

Completeness All valid transactions are recorded, and none are omitted

All shipping documents are prenumbered and matched with sales invoices daily

Authorization Transactions are authorized according to company policy

Credit sales over $00 receive prior approval by a credit supervisor; credit sales over $,000 receive prior approval by cred manager

© CPE Interactive, Inc., 2011-2015 10

Transaction Processing Internal Control (2)

Objectives Description Specific Example (using accounts receivable/sales cycles)

Accuracy Transaction dollar amounts are properly calculated

Sales invoices contain correct quantities and are mathematically correct

Classification Transactions are properly classified in the account

• Sales to subsidiaries and affiliates are classified as intercompany transactions

• All sales on credit are charged to customers’ individual accounts

Cutoff Transactions are recorded in the proper period

Sales of the current period are charged to customers in the appropriate period, and sales in the succeeding period are charged in that period

© CPE Interactive, Inc., 2011-2015 11

Source Data Collection and Entry

 Objectives – Ensure all transactions prepared for entry are entered

– Only authorized users are entering transactions

– Separation of duties is in place for mutually exclusive processes

– Transactions are validated to ensure accuracy

– Error re-entry processed as transactions are entered, if possible

– Transactions not passing edit, are identified, monitored and re-entered

© CPE Interactive, Inc., 2011-2015 12

Source Data Collection and Entry

TRX

Online Update Process

© CPE Interactive, Inc., 2011-2015 13

Source Data Collection and Entry Controls

 Ensure all transactions prepared for entry are entered – Batch control

• Batch headers or trailers with transaction counts, financial totals, and/or has totals

• Reconciliation of batch totals at end of entry

– Entry of single entry with confirmation number that must be entered on source document

– After the fact batch control • System generates totals

• Data entered is totaled

– None • Rely on customer to complain

© CPE Interactive, Inc., 2011-2015 14

Only Authorized Users Are Entering Transactions

 Identity Management (IdM) and Access Controls – Role-based IdM and Access Control

– Unique user id’s and no sharing of id’s

– Minimize system administration user id’s and limit privileges if possible

– Monitor user access

– Require manager review and recertification of users having privileges to their assigned data ownership

 Unique id of user entering transaction is entered and maintained in the record

 Date and time of transaction is recorded in the record

© CPE Interactive, Inc., 2011-2015 15

Separation of Duties

 Transaction assignment based upon job function

 Transactions aggregated into roles

 Mutually exclusive roles for transactions that require separation of duties

 Special attention to master table/file transactions

 Exception reporting for unusual transactions, access, and other identifiable activities

© CPE Interactive, Inc., 2011-2015 16

Transaction Validation / Editing

 Pull-down fields or displayed valid value selection  Field formatting

– Telephone numbers – Postal Code – Social insurance number – Internal codes with defined formats

 Check digits  Item counts

– Invoice has x lines

 Valid character tests  Missing data – verify no data missing before accepting the

transaction  Sequence tests

© CPE Interactive, Inc., 2011-2015 17

Transaction Validation / Editing (2)

 Limit tests – Type of transaction – Value within the transaction

• Payroll class • Vendor payment plan

 Reasonableness test – Require double entry for unusual amounts – Dialog -> ARE YOU SURE?

 Lookup and verification  Double entry with masking previous entry

– Similar to password entry

 Suspension of records not passing validation / editing

© CPE Interactive, Inc., 2011-2015 18

Transaction Authorization

 Reliance on IdM

 Authority levels assigned by role

 Secondary authorization established to achieve separation of duties, or satisfy validation / editing processes

 Secondary authorization recorded in transaction record (date, time, id)

 Suspension of record if immediate secondary authorization is not possible

© CPE Interactive, Inc., 2011-2015 19

Error Processing

 All errors that can be identified as entered are identified and require correction prior to acceptance

 All errors that are identified after entry and all suspended records are subject to “issue monitoring”

 Issue Monitoring process includes: – Aging of suspended or erroneous record – Timely reporting of issues to appropriate management and

staff – Escalation of issues remaining open – Summary reporting of issues, identify

• Systemic issues • Additional training requirements • System modifications

© CPE Interactive, Inc., 2011-2015 20

Special Considerations

 Client/Server

– Client on the workstation has to be the same version as the server

– Verification of version levels during connection

 Web Applications

– Browser Cache emptied after each use

– All input is recalculated after entry

– Data in the URL of the browser is unreconizable

© CPE Interactive, Inc., 2011-2015 21

Special Considerations (2)

 Data Received from External Source

– Defining External Source

• SaaS vendor

• Trading partner

– Encryption

• Symmetric Keys

• Public Keys

– Header/Trailer Batch Totals

© CPE Interactive, Inc., 2011-2015 22

PROCESSING CONTROLS

© CPE Interactive, Inc., 2011-2015 23

Processing Controls

 Objectives:

– Ensure accuracy and completeness of processed data

– Ensure data at rest (on a file/database) remains accurate and complete until it is changed as a result of authorized processing or modification

© CPE Interactive, Inc., 2011-2015 24

Processing Controls (2)

 Completeness – Batch

• Reconciliation - Transaction file totals compared to master file totals before and after process – Three-way match:

» master file = transaction file + old_masterfile

» Transaction file = batch totals of data entry forms

• Control totals: – Transaction monetary amount

– Item count

– Documents count

– Hash total of numeric field

© CPE Interactive, Inc., 2011-2015 25

Processing Controls (3)

 Completeness (Continued)

– Batch and online

• Reliance on database management system – Test for DBMS verification of processing success

» Return_code = Addrec or chgrec

» Return_code must equal 0 (as defined by DBMS) to indicate successful add or change

» Test return_code after each transaction and report to user disposition

© CPE Interactive, Inc., 2011-2015 26

Processing Controls (4)

 Accuracy

– Reliance on change management and testing

 Occurrence

– Matching transaction to another source

• Three way purchase cycle match – invoice/purchase order/receiving document

© CPE Interactive, Inc., 2011-2015 27

Processing Controls (5)

 Classification

– Valid classifications based on record type (Chart of Accounts, customer, employee HR level)

 Cutoff

– Date established by system at time of entry or processing, not editable

– Date defined in process in accordance with accounting rules

– Processes started once all data is available

© CPE Interactive, Inc., 2011-2015 28

Error Processing

 Objective:

– Ensure that all transactions not completing the processing cycle are identified, researched, and either corrected or removed from the processing cycle

– Ensure that all transactions with errors are disposed of on a timely basis

© CPE Interactive, Inc., 2011-2015 29

Error Processing

 Batch error handling (legacy systems) and interfacing system: – Rejecting only transactions with errors – Rejecting the whole batch of transactions – Holding the batch in suspense – Accepting the batch and flagging error transactions

 Batch re-entry controls – Notification of pending batches – Aging of open batches

 Online – Immediate operator notification – Prohibit transaction to continue prior to correction – Suspense transactions that can’t be completed

• Unique ID • Follow-up process

© CPE Interactive, Inc., 2011-2015 30

Data File or Data Base Tables

 Encryption of key data fields

 Limitation of table and column access

– Only via authorized programs

– Limiting ODBC access

 Monitoring SA (super user) or equivalent user IDs

© CPE Interactive, Inc., 2011-2015 31

OUTPUT CONTROLS

© CPE Interactive, Inc., 2011-2015 32

Output Controls

 Provide assurance that data and information delivered to users and other systems will be:

– Relevant and reliable

– Presented and formatted to help ensure understandability

– Consistent and secure

– Available when needed

© CPE Interactive, Inc., 2011-2015 33

Output Controls (2)

 Logging and storage of negotiable, sensitive and critical forms in a secure place – Checks

– Certificates

 Computer generation of negotiable instruments, forms and signatures – Control of signature plate

– Limit access to the print queue

– Sequential numbering

– Inventory of forms

© CPE Interactive, Inc., 2011-2015 34

Output Controls (3)

 Balancing and reconciling – Assignment of process – Process for researching out-of-balance conditions – Correction of out-of-balance conditions

 Monitoring and managing other output error conditions  Master file changes  Report distribution

– Distribution Lists – Special procedures for confidential and/or negotiable

instruments • Limits on forwarding or re-distribution

– Verification of receipt of reports

 Output report retention

© CPE Interactive, Inc., 2011-2015 35

Outbound Transactions

 Controls should ensure that only properly authorized outbound transactions are distributed

– Purchase orders

– Payments

– Auto-adjudicated transactions

© CPE Interactive, Inc., 2011-2015 36

Outbound Transactions (2)

 The control considerations for outbound transactions: – Controlling the set up and change of trading

partner details

– Comparing transactions with trading partner transaction profiles

– Matching the trading partner number to the trading master file, prior to transmission

– Limiting the authority of users within the organization to initiate specific EDI transactions

© CPE Interactive, Inc., 2011-2015 37