SlideShare une entreprise Scribd logo
1  sur  46
C HAPTER 6 
Control and Accounting 
Information Systems 
© 2006 Prentice Hall Business Publishing Accounting Information Systems, 10/e Romney/Steinbart 1 of 314
OVERVIEW OF CONTROL CONCEPTS 
• Internal control is the process implemented by the 
board of directors, management, and those under their 
direction to provide reasonable assurance that the 
following control objectives are achieved: 
– Assets (including data) are safeguarded. 
– Records are maintained in sufficient detail to accurately and 
fairly reflect company assets. 
– Accurate and reliable information is provided. 
– There is reasonable assurance that financial reports are 
prepared in accordance with GAAP. 
– Operational efficiency is promoted and improved. 
– Adherence to prescribed managerial policies is encouraged. 
– The organization complies with applicable laws and regulations.
OVERVIEW OF CONTROL CONCEPTS 
• Internal controls are often classified as: 
– General controls 
• e.g. software acquisition/installation controls, that 
apply to all size of systems. 
– Application controls 
• Completeness Check 
• Accuracy Check
Legislative Reaction to Fraud: 
THE FOREIGN CORRUPT PRACTICES ACT 
• In 1977, Congress passed the Foreign Corrupt 
Practices Act. 
• The primary purpose of the act was to prevent the 
bribery of foreign officials to obtain business. 
• A significant effect was to require that corporations 
maintain good systems of internal accounting control.
Legislative Reaction to Fraud: 
SOX 
– The impact on financial markets was 
substantial, and Congress responded with 
passage of the Sarbanes-Oxley Act of 2002 
(aka, SOX).
Legislative Reaction to Fraud: 
SOX 
• The intent of SOX is to: 
– Prevent financial statement fraud 
– Make financial reports more transparent 
– Protect investors 
– Strengthen internal controls in publicly-held 
companies 
– Punish executives who perpetrate fraud 
• SOX has had a material impact on the 
way boards of directors, management, 
and accountants operate.
Legislative Reaction to Fraud: 
SOX 
• Important aspects of SOX include: 
– Creation of the Public Company Accounting Oversight 
Board (PCAOB) to oversee the auditing profession. 
– New rules for auditors 
– New rules for audit committees 
– New rules for management 
– New internal control requirements
Legislative Reaction to Fraud: 
SOX 
• After the passage of SOX, the SEC further 
mandated that: 
– Management must base its evaluation on a 
recognized control framework, developed using a 
due-process procedure that allows for public 
comment. The most likely framework is the COSO 
model discussed later in the chapter. 
– The report must contain a statement identifying the 
framework used. 
– Management must disclose any and all material 
internal control weaknesses. 
– Management cannot conclude that the company has 
effective internal control if there are any material 
weaknesses.
• Levers of Control (pp 194 -195)  skip
CONTROL FRAMEWORKS 
• A number of frameworks have been 
developed to help companies develop 
good internal control systems. Three of 
the most important are: 
– The COBIT framework 
– The COSO internal control framework 
– COSO’s Enterprise Risk Management 
framework (ERM) 
• An enhanced corporate governance document. 
• Expands on elements of preceding framework. 
• Provides a focus on the broader subject of enterprise risk 
management.
COSO’S ERM 
• COSO developed a 
model to illustrate 
the elements of 
ERM.
INTERNAL ENVIRONMENT 
• The most critical component 
of the ERM and the internal 
control framework. 
• Is the foundation on which the 
other seven components rest. 
• Influences how organizations: 
– Establish strategies and 
objectives 
– Structure business activities 
– Identify, access, and respond 
to risk 
• A deficient internal control 
environment often results in 
risk management and control 
breakdowns.
INTERNAL ENVIRONMENT 
• Internal environment consists of the following: 
– Management’s attitude toward risk 
– Commitment to integrity, ethical values, and 
competence 
– Organizational structure 
– Methods of assigning authority and responsibility 
– Human resource standards (Background Check) 
ROBA = Risk, Organizational structure, Background 
check, Assigning Responsibility.
OBJECTIVE SETTING 
• The objective of the 
Sarbanes-Oxley Act is 
to strengthen internal 
controls in public 
companies. 
• AICPA’s five objectives 
for accounting 
information systems.
EVENT IDENTIFICATION 
• Events are: 
– Incidents or occurrences 
that emanate from 
internal or external 
sources 
– Impact can be positive, 
negative, or both. 
– System design should 
identify all potential 
events.
RISK ASSESSMENT AND RISK 
RESPONSE 
– Inherent risk: 
• The risk before 
internal controls 
– Residual risk 
• The risk after 
management 
implements internal 
controls.
RISK ASSESSMENT 
AND RISK RESPONSE 
Identify the events or threats 
that confront the company 
Estimate the likelihood or 
probability of each event occurring 
Estimate the impact of potential 
loss from each threat 
Identify set of controls to 
guard against threat 
Estimate costs and benefits 
from instituting controls 
Is it 
cost-beneficia 
l 
to protect 
system 
Avoid, 
share, or 
accept 
risk 
Yes 
No 
Reduce risk by implementing set of 
controls to guard against threat 
Threats 
Probability 
Impact of 
Loss 
Identify 
Controls 
Cost and 
Benefits
CONTROL ACTIVITIES 
• The sixth component of 
COSO’s ERM model. 
• Control activities are 
policies, procedures, 
and rules that provide 
reasonable assurance 
that management’s 
control objectives are 
met and their risk 
responses are carried 
out.
CONTROL ACTIVITIES 
• Generally, control procedures fall into one 
of the following categories: 
-Proper authorization of transaction 
-Segregation of duties 
-Change management controls 
• Design and use of documents and records 
– Documents that initiate a transaction should contain a 
space for authorization 
• Safeguard assets, records, and data 
• Independent checks on performance
CONTROL ACTIVITIES 
• To learn a little about segregation of 
duties, let’s first meet Bill.
CONTROL ACTIVITIES 
• Bill has charge of a pile of the 
organization’s money—let’s say $1,000.
CONTROL ACTIVITIES 
Ledger 
$1,000 
• Bill also keeps the books for that 
money.
CONTROL ACTIVITIES 
Ledger 
$1,000 
• Bill has a date tonight, and he’s a little desperate to 
impress that special someone, so he takes $100 of 
the cash. (Thinks he’s only borrowing it, you know.)
CONTROL ACTIVITIES 
Ledger 
$1,000 
• Bill has a date tonight, and he’s a little desperate to 
impress that special someone, so he takes $100 of 
the cash. (Thinks he’s only borrowing it, you know.)
CONTROL ACTIVITIES 
Ledger 
$1,000 
• Bill also records an entry in the books to show that 
$100 was spent for some “legitimate” purpose. Now 
the balance in the books is $900.
CONTROL ACTIVITIES 
Ledger 
$900 
• How will Bill ever get caught at his 
theft?
CONTROL ACTIVITIES 
• Now let’s change the story. Bill has 
charge of the pile of cash.
CONTROL ACTIVITIES 
Ledger 
$1,000 
• But Mary keeps the books. 
• This arrangement is a form of segregation of duties.
CONTROL ACTIVITIES 
• Bill gets in a pinch again and takes 
$100 of the organization’s cash. 
Ledger 
$1,000
CONTROL ACTIVITIES 
• How will Bill get caught? 
Ledger 
$1,000
CONTROL ACTIVITIES 
• Segregation of Accounting Duties 
– Effective segregation of accounting duties is achieved 
when the following functions are separated: 
• Authorization—approving transactions and decisions. 
• Recording—Preparing source documents; maintaining 
journals, ledgers, or other files; preparing reconciliations; and 
preparing performance reports. 
• Custody—Handling cash, maintaining an inventory 
storeroom, receiving incoming customer checks, writing 
checks on the organization’s bank account. 
– If any two of the preceding functions are the 
responsibility of one person, then problems can arise.
CONTROL ACTIVITIES 
CUSTODIAL FUNCTIONS 
• Handling cash 
• Handling inventories, tools, 
or fixed assets 
• Writing checks 
• Receiving checks in mail 
RECORDING FUNCTIONS 
• Preparing source 
AUTHORIZATION 
FUNCTIONS 
• General Authorization 
• Specific authorization 
documents 
• Maintaining journals, 
ledgers, or other files 
• Preparing reconciliations 
• Preparing performance 
reports
Can you tell me what seems wrong? 
• An employee receiving checks in the mail and 
records receipts in the Cash Receipts journal 
• An employee authorizes credit sales and has 
custody of Finished Goods Inventory 
• An employee enters sales transactions into the 
accounting system and has custody of Finished 
Goods inventory. 
• An employee receives checks in the mail and 
has access to the Petty Cash Fund.
CONTROL ACTIVITIES 
• In a system that incorporates an effective 
separation of duties, it should be difficult 
for any single employee to commit 
embezzlement successfully. 
• But when two or more people collude, 
then segregation of duties becomes 
impotent and controls are overridden.
CONTROL ACTIVITIES 
• If this happens . . . 
Ledger 
$1,000
CONTROL ACTIVITIES 
Ledger 
$1,000 
• Then segregation of duties is out the window. 
Collusion overrides segregation.
CONTROL ACTIVITIES 
• Generally, control procedures fall into one of the 
following categories: 
– Proper authorization of transactions and activities 
– Segregation of duties 
– Project development and acquisition controls 
• Strategic master plan 
– Change management controls 
– Design and use of documents and records 
– Safeguard assets, records, and data 
– Independent checks on performance
CONTROL ACTIVITIES 
Ledger 
$1,000 
• Let’s look at Bill and Mary again. Assume that Bill 
stole cash but Mary did NOT alter the books.
CONTROL ACTIVITIES 
Ledger 
$1,000 
• Can Bill’s theft be discovered if an independent 
party doesn’t compare a count of the cash to what’s 
recorded on the books?
CONTROL ACTIVITIES 
Ledger 
$1,000 
• Segregation of duties only has value when 
supplemented by independent checks.
CONTROL ACTIVITIES 
• The following independent checks are 
typically used: 
– Top-level reviews 
– Analytical reviews 
– Reconciliation of independently maintained 
sets of records 
– Comparison of actual quantities with recorded 
amounts
CONTROL ACTIVITIES 
• The following independent checks are 
typically used: 
– Top-level reviews 
– Analytical reviews 
• Examinations of relationships between different sets of 
data. 
• EXAMPLE: If credit sales increased significantly during 
the period and there were no changes in credit policy, 
then bad debt expense should probably have increased 
also. 
• Management should periodically analyze and review 
data relationships to detect fraud and other business 
problems.
INFORMATION AND COMMUNICATION 
• The seventh component of 
COSO’s ERM model. 
• The primary purpose of the AIS is 
to gather, record, process, store, 
summarize, and communicate 
information about an organization. 
• So accountants must understand 
how: 
– Transactions are initiated 
– Data are captured in or 
converted to machine-readable 
form 
– Computer files are accessed 
and updated 
– Data are processed 
– Information is reported to 
internal and external parties
INFORMATION AND COMMUNICATION 
• According to the AICPA, an AIS has five 
primary objectives: 
– Identify and record all valid transactions. 
– Properly classify transactions. 
– Record transactions at their proper monetary 
value. 
– Record transactions in the proper accounting 
period. 
– Properly present transactions and related 
disclosures in the financial statements.
MONITORING 
• Internal Monitoring 
• When independent 
auditors come to 
clients’ site, it is an 
independent review, 
not an operation 
monitoring.
MONITORING 
• Key methods of monitoring performance include: 
– Implement effective supervision 
– Monitor system activities 
– Track purchased software licenses. 
– Employ internal auditors to review the system 
– Employ a computer security officer 
– Install fraud detection software 
– Implement a fraud hotline

Contenu connexe

Tendances

Internal control system
Internal control systemInternal control system
Internal control systemHina Varshney
 
Unit 3 internal control
Unit 3 internal controlUnit 3 internal control
Unit 3 internal controlRadhika Gohel
 
Chapter 1 auditing and internal control
Chapter 1 auditing and internal controlChapter 1 auditing and internal control
Chapter 1 auditing and internal controlTommy Zul Hidayat
 
Managerial accounting
Managerial accountingManagerial accounting
Managerial accountingKhalid Aziz
 
Internal Control
Internal ControlInternal Control
Internal ControlSalih Islam
 
Auditing in Computerized Environment
Auditing in Computerized EnvironmentAuditing in Computerized Environment
Auditing in Computerized EnvironmentDr. Sushil Bansode
 
Lecture 22 expenditure cycle part ii - payroll processing accounting informa...
Lecture 22  expenditure cycle part ii - payroll processing accounting informa...Lecture 22  expenditure cycle part ii - payroll processing accounting informa...
Lecture 22 expenditure cycle part ii - payroll processing accounting informa...Habib Ullah Qamar
 
International Auditing Standards (ISA)
International Auditing Standards (ISA)International Auditing Standards (ISA)
International Auditing Standards (ISA)Manon Cuylits
 
Chapter 2 auditing it governance controls
Chapter 2 auditing it governance controlsChapter 2 auditing it governance controls
Chapter 2 auditing it governance controlsjayussuryawan
 
INTERNATIONAL AUDITING STANDARDS -PPT.pptx
INTERNATIONAL AUDITING STANDARDS -PPT.pptxINTERNATIONAL AUDITING STANDARDS -PPT.pptx
INTERNATIONAL AUDITING STANDARDS -PPT.pptxHeldaMaryA
 
Chapter 1 - The Information System: An Accountant's Perspective
Chapter 1 - The Information System: An Accountant's PerspectiveChapter 1 - The Information System: An Accountant's Perspective
Chapter 1 - The Information System: An Accountant's Perspectiveermin08
 
Internal audit ratings guide
Internal audit ratings guideInternal audit ratings guide
Internal audit ratings guideCenapSerdarolu
 
Introduction to Accounting by Dr. Suresh Vadde
Introduction to Accounting by Dr. Suresh VaddeIntroduction to Accounting by Dr. Suresh Vadde
Introduction to Accounting by Dr. Suresh VaddeSuresh Vadde
 
governmental and Non profit Accounting chapter 1
governmental and Non profit Accounting chapter 1governmental and Non profit Accounting chapter 1
governmental and Non profit Accounting chapter 1NeveenJamal
 
Lecture 10, chap 16, Chapter 16, Auditing Inventories and property, plant an...
Lecture 10,  chap 16, Chapter 16, Auditing Inventories and property, plant an...Lecture 10,  chap 16, Chapter 16, Auditing Inventories and property, plant an...
Lecture 10, chap 16, Chapter 16, Auditing Inventories and property, plant an...Sazzad Hossain, ITP, MBA, CSCA™
 

Tendances (20)

AIS-CHAPTER-1.ppt
AIS-CHAPTER-1.pptAIS-CHAPTER-1.ppt
AIS-CHAPTER-1.ppt
 
Internal control system
Internal control systemInternal control system
Internal control system
 
Unit 3 internal control
Unit 3 internal controlUnit 3 internal control
Unit 3 internal control
 
Chapter 1 auditing and internal control
Chapter 1 auditing and internal controlChapter 1 auditing and internal control
Chapter 1 auditing and internal control
 
Managerial accounting
Managerial accountingManagerial accounting
Managerial accounting
 
Internal Control
Internal ControlInternal Control
Internal Control
 
Auditing in Computerized Environment
Auditing in Computerized EnvironmentAuditing in Computerized Environment
Auditing in Computerized Environment
 
Internal controls
Internal controlsInternal controls
Internal controls
 
Lecture 22 expenditure cycle part ii - payroll processing accounting informa...
Lecture 22  expenditure cycle part ii - payroll processing accounting informa...Lecture 22  expenditure cycle part ii - payroll processing accounting informa...
Lecture 22 expenditure cycle part ii - payroll processing accounting informa...
 
International Auditing Standards (ISA)
International Auditing Standards (ISA)International Auditing Standards (ISA)
International Auditing Standards (ISA)
 
Chapter 2 auditing it governance controls
Chapter 2 auditing it governance controlsChapter 2 auditing it governance controls
Chapter 2 auditing it governance controls
 
INTERNATIONAL AUDITING STANDARDS -PPT.pptx
INTERNATIONAL AUDITING STANDARDS -PPT.pptxINTERNATIONAL AUDITING STANDARDS -PPT.pptx
INTERNATIONAL AUDITING STANDARDS -PPT.pptx
 
Chapter 1 - The Information System: An Accountant's Perspective
Chapter 1 - The Information System: An Accountant's PerspectiveChapter 1 - The Information System: An Accountant's Perspective
Chapter 1 - The Information System: An Accountant's Perspective
 
Internal audit ratings guide
Internal audit ratings guideInternal audit ratings guide
Internal audit ratings guide
 
Ch06
Ch06Ch06
Ch06
 
History of Accounting Thought
History of Accounting ThoughtHistory of Accounting Thought
History of Accounting Thought
 
Introduction to Accounting by Dr. Suresh Vadde
Introduction to Accounting by Dr. Suresh VaddeIntroduction to Accounting by Dr. Suresh Vadde
Introduction to Accounting by Dr. Suresh Vadde
 
governmental and Non profit Accounting chapter 1
governmental and Non profit Accounting chapter 1governmental and Non profit Accounting chapter 1
governmental and Non profit Accounting chapter 1
 
04 Audit documentation
04  Audit documentation 04  Audit documentation
04 Audit documentation
 
Lecture 10, chap 16, Chapter 16, Auditing Inventories and property, plant an...
Lecture 10,  chap 16, Chapter 16, Auditing Inventories and property, plant an...Lecture 10,  chap 16, Chapter 16, Auditing Inventories and property, plant an...
Lecture 10, chap 16, Chapter 16, Auditing Inventories and property, plant an...
 

En vedette

Accounting information system introduction
Accounting information system introductionAccounting information system introduction
Accounting information system introductionsellyhood
 
Accounting information system
Accounting information systemAccounting information system
Accounting information systemsellyhood
 
Mc leod9e ch07 systems development
Mc leod9e ch07 systems developmentMc leod9e ch07 systems development
Mc leod9e ch07 systems developmentsellyhood
 
Bab 5 - Testing dan Seleksi Pegawai
Bab 5 - Testing dan Seleksi PegawaiBab 5 - Testing dan Seleksi Pegawai
Bab 5 - Testing dan Seleksi Pegawaimsahuleka
 
Multinational accounting
Multinational accountingMultinational accounting
Multinational accountingsellyhood
 
Acc6ch07.ders
Acc6ch07.dersAcc6ch07.ders
Acc6ch07.dersalper
 
Bab 9 - Inventories, Additional Valuation Issues
Bab 9 - Inventories, Additional Valuation IssuesBab 9 - Inventories, Additional Valuation Issues
Bab 9 - Inventories, Additional Valuation Issuesmsahuleka
 
Bab 8 - Mengelola SDM dan Hubungan Tenaga Kerja
Bab 8 - Mengelola SDM dan Hubungan Tenaga KerjaBab 8 - Mengelola SDM dan Hubungan Tenaga Kerja
Bab 8 - Mengelola SDM dan Hubungan Tenaga Kerjamsahuleka
 
Ais Romney 2006 Slides 05 Computer Fraud And Abuse
Ais Romney 2006 Slides 05 Computer Fraud And AbuseAis Romney 2006 Slides 05 Computer Fraud And Abuse
Ais Romney 2006 Slides 05 Computer Fraud And Abusesharing notes123
 
Bab 7 - Strategi pemasaran yang digerakkan oleh pelanggan menciptakan nilai b...
Bab 7 - Strategi pemasaran yang digerakkan oleh pelanggan menciptakan nilai b...Bab 7 - Strategi pemasaran yang digerakkan oleh pelanggan menciptakan nilai b...
Bab 7 - Strategi pemasaran yang digerakkan oleh pelanggan menciptakan nilai b...msahuleka
 
Bab 3 - The Accounting Information System
Bab 3 - The Accounting Information SystemBab 3 - The Accounting Information System
Bab 3 - The Accounting Information Systemmsahuleka
 
Accounting information system
Accounting information systemAccounting information system
Accounting information systemSAKET KASHYAP
 
Bab 6 - Accounting and the Time Value of Money
Bab 6 - Accounting and the Time Value of MoneyBab 6 - Accounting and the Time Value of Money
Bab 6 - Accounting and the Time Value of Moneymsahuleka
 

En vedette (16)

Accounting information system introduction
Accounting information system introductionAccounting information system introduction
Accounting information system introduction
 
Accounting information system
Accounting information systemAccounting information system
Accounting information system
 
Mc leod9e ch07 systems development
Mc leod9e ch07 systems developmentMc leod9e ch07 systems development
Mc leod9e ch07 systems development
 
Bab 5 - Testing dan Seleksi Pegawai
Bab 5 - Testing dan Seleksi PegawaiBab 5 - Testing dan Seleksi Pegawai
Bab 5 - Testing dan Seleksi Pegawai
 
Multinational accounting
Multinational accountingMultinational accounting
Multinational accounting
 
Jyotigram yojana
Jyotigram yojanaJyotigram yojana
Jyotigram yojana
 
Acc6ch07.ders
Acc6ch07.dersAcc6ch07.ders
Acc6ch07.ders
 
Bab 9 - Inventories, Additional Valuation Issues
Bab 9 - Inventories, Additional Valuation IssuesBab 9 - Inventories, Additional Valuation Issues
Bab 9 - Inventories, Additional Valuation Issues
 
Bab 8 - Mengelola SDM dan Hubungan Tenaga Kerja
Bab 8 - Mengelola SDM dan Hubungan Tenaga KerjaBab 8 - Mengelola SDM dan Hubungan Tenaga Kerja
Bab 8 - Mengelola SDM dan Hubungan Tenaga Kerja
 
Ais Romney 2006 Slides 05 Computer Fraud And Abuse
Ais Romney 2006 Slides 05 Computer Fraud And AbuseAis Romney 2006 Slides 05 Computer Fraud And Abuse
Ais Romney 2006 Slides 05 Computer Fraud And Abuse
 
Bab 7 - Strategi pemasaran yang digerakkan oleh pelanggan menciptakan nilai b...
Bab 7 - Strategi pemasaran yang digerakkan oleh pelanggan menciptakan nilai b...Bab 7 - Strategi pemasaran yang digerakkan oleh pelanggan menciptakan nilai b...
Bab 7 - Strategi pemasaran yang digerakkan oleh pelanggan menciptakan nilai b...
 
Bab 3 - The Accounting Information System
Bab 3 - The Accounting Information SystemBab 3 - The Accounting Information System
Bab 3 - The Accounting Information System
 
Accounting information system
Accounting information systemAccounting information system
Accounting information system
 
Bab 6 - Accounting and the Time Value of Money
Bab 6 - Accounting and the Time Value of MoneyBab 6 - Accounting and the Time Value of Money
Bab 6 - Accounting and the Time Value of Money
 
Cost Accounting
Cost AccountingCost Accounting
Cost Accounting
 
Chapter 6
Chapter 6Chapter 6
Chapter 6
 

Similaire à Control&accounting information system

Internal control system
Internal control systemInternal control system
Internal control systemMadiha Hassan
 
Internal control system
Internal control systemInternal control system
Internal control systemMadiha Hassan
 
Internal Financial Controls
Internal Financial ControlsInternal Financial Controls
Internal Financial Controlstarunmallappa
 
El-Paso SOX TestingTraining- June 2007
El-Paso SOX TestingTraining- June 2007El-Paso SOX TestingTraining- June 2007
El-Paso SOX TestingTraining- June 2007Danial Khan
 
Akmen 1 Introduction.pptx.pdf
Akmen 1 Introduction.pptx.pdfAkmen 1 Introduction.pptx.pdf
Akmen 1 Introduction.pptx.pdfAuliaHestiShofani
 
Brief overview on Internal control (Audit)
Brief overview on Internal control (Audit)Brief overview on Internal control (Audit)
Brief overview on Internal control (Audit)Hisyam
 
Internal Control over Financial Reporting.pptx
Internal Control over Financial Reporting.pptxInternal Control over Financial Reporting.pptx
Internal Control over Financial Reporting.pptxAavyaSidhu
 
12.12.2011, Internal audit role and functions in corporate governance, Scott ...
12.12.2011, Internal audit role and functions in corporate governance, Scott ...12.12.2011, Internal audit role and functions in corporate governance, Scott ...
12.12.2011, Internal audit role and functions in corporate governance, Scott ...The Business Council of Mongolia
 
List of control (soap spam ir)
List of control (soap spam ir)List of control (soap spam ir)
List of control (soap spam ir)AdamRice38
 
Financial Management for Business Associations
Financial Management for Business AssociationsFinancial Management for Business Associations
Financial Management for Business AssociationsHammad Siddiqui
 
UNCCInternalControls.pptx
UNCCInternalControls.pptxUNCCInternalControls.pptx
UNCCInternalControls.pptxAral20101
 
The Importance of Internal Controls in Fraud Prevention
The Importance of Internal Controls in Fraud Prevention The Importance of Internal Controls in Fraud Prevention
The Importance of Internal Controls in Fraud Prevention Rea & Associates
 
Introduction to COSO 2013 - Corporate Compliance Seminars
Introduction to COSO 2013 - Corporate Compliance SeminarsIntroduction to COSO 2013 - Corporate Compliance Seminars
Introduction to COSO 2013 - Corporate Compliance SeminarsCorporate Compliance Seminars
 

Similaire à Control&accounting information system (20)

Internal controls & ai ss
Internal controls & ai ssInternal controls & ai ss
Internal controls & ai ss
 
Internal control system
Internal control systemInternal control system
Internal control system
 
Internal control system
Internal control systemInternal control system
Internal control system
 
Internal Financial Controls
Internal Financial ControlsInternal Financial Controls
Internal Financial Controls
 
Advance audit
Advance auditAdvance audit
Advance audit
 
El-Paso SOX TestingTraining- June 2007
El-Paso SOX TestingTraining- June 2007El-Paso SOX TestingTraining- June 2007
El-Paso SOX TestingTraining- June 2007
 
Internal controls in an IT environment
Internal controls in an IT environment Internal controls in an IT environment
Internal controls in an IT environment
 
Akmen 1 Introduction.pptx.pdf
Akmen 1 Introduction.pptx.pdfAkmen 1 Introduction.pptx.pdf
Akmen 1 Introduction.pptx.pdf
 
COSO 2013 and The Auditor
COSO 2013 and The AuditorCOSO 2013 and The Auditor
COSO 2013 and The Auditor
 
Brief overview on Internal control (Audit)
Brief overview on Internal control (Audit)Brief overview on Internal control (Audit)
Brief overview on Internal control (Audit)
 
Internal Control over Financial Reporting.pptx
Internal Control over Financial Reporting.pptxInternal Control over Financial Reporting.pptx
Internal Control over Financial Reporting.pptx
 
12.12.2011, Internal audit role and functions in corporate governance, Scott ...
12.12.2011, Internal audit role and functions in corporate governance, Scott ...12.12.2011, Internal audit role and functions in corporate governance, Scott ...
12.12.2011, Internal audit role and functions in corporate governance, Scott ...
 
List of control (soap spam ir)
List of control (soap spam ir)List of control (soap spam ir)
List of control (soap spam ir)
 
Financial Management for Business Associations
Financial Management for Business AssociationsFinancial Management for Business Associations
Financial Management for Business Associations
 
UNCCInternalControls.pptx
UNCCInternalControls.pptxUNCCInternalControls.pptx
UNCCInternalControls.pptx
 
Internal control
Internal controlInternal control
Internal control
 
Romney ch06
Romney ch06Romney ch06
Romney ch06
 
The Importance of Internal Controls in Fraud Prevention
The Importance of Internal Controls in Fraud Prevention The Importance of Internal Controls in Fraud Prevention
The Importance of Internal Controls in Fraud Prevention
 
Introduction to COSO 2013 - Corporate Compliance Seminars
Introduction to COSO 2013 - Corporate Compliance SeminarsIntroduction to COSO 2013 - Corporate Compliance Seminars
Introduction to COSO 2013 - Corporate Compliance Seminars
 
Internal audit
Internal auditInternal audit
Internal audit
 

Plus de sellyhood

Not for-profit entities
Not for-profit entitiesNot for-profit entities
Not for-profit entitiessellyhood
 
Governmental entities special funds and government wide financial statements
Governmental entities special funds and government wide financial statementsGovernmental entities special funds and government wide financial statements
Governmental entities special funds and government wide financial statementssellyhood
 
Governmental entities introduction and general fund accounting
Governmental entities introduction and general fund accountingGovernmental entities introduction and general fund accounting
Governmental entities introduction and general fund accountingsellyhood
 
Corporations in financial difficulty
Corporations in financial difficultyCorporations in financial difficulty
Corporations in financial difficultysellyhood
 
Completing the tests in the sales and collection cycle accounts receivable
Completing the tests in the sales and collection cycle accounts receivableCompleting the tests in the sales and collection cycle accounts receivable
Completing the tests in the sales and collection cycle accounts receivablesellyhood
 
Completing the audit
Completing the auditCompleting the audit
Completing the auditsellyhood
 
Audit sampling for tests of details of balances
Audit sampling for tests of details of balancesAudit sampling for tests of details of balances
Audit sampling for tests of details of balancessellyhood
 
Audit sampling for tests of controls and substantive tests of transactions
Audit sampling for tests of controls and substantive tests of transactionsAudit sampling for tests of controls and substantive tests of transactions
Audit sampling for tests of controls and substantive tests of transactionssellyhood
 
Audit of the sales and collection cycle
Audit of the sales and collection cycleAudit of the sales and collection cycle
Audit of the sales and collection cyclesellyhood
 
Audit of the payroll and personnel cycle
Audit of the payroll and personnel cycleAudit of the payroll and personnel cycle
Audit of the payroll and personnel cyclesellyhood
 
Audit of the inventory and warehousing cycle
Audit of the inventory and warehousing cycleAudit of the inventory and warehousing cycle
Audit of the inventory and warehousing cyclesellyhood
 
Audit of the acquisition and payment cycle
Audit of the acquisition and payment cycleAudit of the acquisition and payment cycle
Audit of the acquisition and payment cyclesellyhood
 
Audit of the acquisition and payment cycle
Audit of the acquisition and payment cycleAudit of the acquisition and payment cycle
Audit of the acquisition and payment cyclesellyhood
 
Mc leod9e ch06 database management systems
Mc leod9e ch06 database management systemsMc leod9e ch06 database management systems
Mc leod9e ch06 database management systemssellyhood
 
Mc leod9e ch08 information in action
Mc leod9e ch08 information in actionMc leod9e ch08 information in action
Mc leod9e ch08 information in actionsellyhood
 
Struktur teori akuntansi
Struktur teori akuntansiStruktur teori akuntansi
Struktur teori akuntansisellyhood
 
Kerangka konseptual akuntansi
Kerangka konseptual akuntansiKerangka konseptual akuntansi
Kerangka konseptual akuntansisellyhood
 
Akuntansi pajak penghasilan
Akuntansi pajak penghasilanAkuntansi pajak penghasilan
Akuntansi pajak penghasilansellyhood
 

Plus de sellyhood (19)

Not for-profit entities
Not for-profit entitiesNot for-profit entities
Not for-profit entities
 
Governmental entities special funds and government wide financial statements
Governmental entities special funds and government wide financial statementsGovernmental entities special funds and government wide financial statements
Governmental entities special funds and government wide financial statements
 
Governmental entities introduction and general fund accounting
Governmental entities introduction and general fund accountingGovernmental entities introduction and general fund accounting
Governmental entities introduction and general fund accounting
 
Corporations in financial difficulty
Corporations in financial difficultyCorporations in financial difficulty
Corporations in financial difficulty
 
Completing the tests in the sales and collection cycle accounts receivable
Completing the tests in the sales and collection cycle accounts receivableCompleting the tests in the sales and collection cycle accounts receivable
Completing the tests in the sales and collection cycle accounts receivable
 
Completing the audit
Completing the auditCompleting the audit
Completing the audit
 
Audit sampling for tests of details of balances
Audit sampling for tests of details of balancesAudit sampling for tests of details of balances
Audit sampling for tests of details of balances
 
Audit sampling for tests of controls and substantive tests of transactions
Audit sampling for tests of controls and substantive tests of transactionsAudit sampling for tests of controls and substantive tests of transactions
Audit sampling for tests of controls and substantive tests of transactions
 
Audit of the sales and collection cycle
Audit of the sales and collection cycleAudit of the sales and collection cycle
Audit of the sales and collection cycle
 
Audit of the payroll and personnel cycle
Audit of the payroll and personnel cycleAudit of the payroll and personnel cycle
Audit of the payroll and personnel cycle
 
Audit of the inventory and warehousing cycle
Audit of the inventory and warehousing cycleAudit of the inventory and warehousing cycle
Audit of the inventory and warehousing cycle
 
Audit of the acquisition and payment cycle
Audit of the acquisition and payment cycleAudit of the acquisition and payment cycle
Audit of the acquisition and payment cycle
 
Audit of the acquisition and payment cycle
Audit of the acquisition and payment cycleAudit of the acquisition and payment cycle
Audit of the acquisition and payment cycle
 
Mc leod9e ch06 database management systems
Mc leod9e ch06 database management systemsMc leod9e ch06 database management systems
Mc leod9e ch06 database management systems
 
Mc leod9e ch08 information in action
Mc leod9e ch08 information in actionMc leod9e ch08 information in action
Mc leod9e ch08 information in action
 
Struktur teori akuntansi
Struktur teori akuntansiStruktur teori akuntansi
Struktur teori akuntansi
 
Laba
LabaLaba
Laba
 
Kerangka konseptual akuntansi
Kerangka konseptual akuntansiKerangka konseptual akuntansi
Kerangka konseptual akuntansi
 
Akuntansi pajak penghasilan
Akuntansi pajak penghasilanAkuntansi pajak penghasilan
Akuntansi pajak penghasilan
 

Dernier

Economic Risk Factor Update: April 2024 [SlideShare]
Economic Risk Factor Update: April 2024 [SlideShare]Economic Risk Factor Update: April 2024 [SlideShare]
Economic Risk Factor Update: April 2024 [SlideShare]Commonwealth
 
The AES Investment Code - the go-to counsel for the most well-informed, wise...
The AES Investment Code -  the go-to counsel for the most well-informed, wise...The AES Investment Code -  the go-to counsel for the most well-informed, wise...
The AES Investment Code - the go-to counsel for the most well-informed, wise...AES International
 
(中央兰开夏大学毕业证学位证成绩单-案例)
(中央兰开夏大学毕业证学位证成绩单-案例)(中央兰开夏大学毕业证学位证成绩单-案例)
(中央兰开夏大学毕业证学位证成绩单-案例)twfkn8xj
 
Call Girls Near Me WhatsApp:+91-9833363713
Call Girls Near Me WhatsApp:+91-9833363713Call Girls Near Me WhatsApp:+91-9833363713
Call Girls Near Me WhatsApp:+91-9833363713Sonam Pathan
 
(办理学位证)加拿大萨省大学毕业证成绩单原版一比一
(办理学位证)加拿大萨省大学毕业证成绩单原版一比一(办理学位证)加拿大萨省大学毕业证成绩单原版一比一
(办理学位证)加拿大萨省大学毕业证成绩单原版一比一S SDS
 
The Core Functions of the Bangko Sentral ng Pilipinas
The Core Functions of the Bangko Sentral ng PilipinasThe Core Functions of the Bangko Sentral ng Pilipinas
The Core Functions of the Bangko Sentral ng PilipinasCherylouCamus
 
212MTAMount Durham University Bachelor's Diploma in Technology
212MTAMount Durham University Bachelor's Diploma in Technology212MTAMount Durham University Bachelor's Diploma in Technology
212MTAMount Durham University Bachelor's Diploma in Technologyz xss
 
原版1:1复刻温哥华岛大学毕业证Vancouver毕业证留信学历认证
原版1:1复刻温哥华岛大学毕业证Vancouver毕业证留信学历认证原版1:1复刻温哥华岛大学毕业证Vancouver毕业证留信学历认证
原版1:1复刻温哥华岛大学毕业证Vancouver毕业证留信学历认证rjrjkk
 
NO1 WorldWide Genuine vashikaran specialist Vashikaran baba near Lahore Vashi...
NO1 WorldWide Genuine vashikaran specialist Vashikaran baba near Lahore Vashi...NO1 WorldWide Genuine vashikaran specialist Vashikaran baba near Lahore Vashi...
NO1 WorldWide Genuine vashikaran specialist Vashikaran baba near Lahore Vashi...Amil baba
 
(办理原版一样)QUT毕业证昆士兰科技大学毕业证学位证留信学历认证成绩单补办
(办理原版一样)QUT毕业证昆士兰科技大学毕业证学位证留信学历认证成绩单补办(办理原版一样)QUT毕业证昆士兰科技大学毕业证学位证留信学历认证成绩单补办
(办理原版一样)QUT毕业证昆士兰科技大学毕业证学位证留信学历认证成绩单补办fqiuho152
 
magnetic-pensions-a-new-blueprint-for-the-dc-landscape.pdf
magnetic-pensions-a-new-blueprint-for-the-dc-landscape.pdfmagnetic-pensions-a-new-blueprint-for-the-dc-landscape.pdf
magnetic-pensions-a-new-blueprint-for-the-dc-landscape.pdfHenry Tapper
 
call girls in Nand Nagri (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
call girls in  Nand Nagri (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️call girls in  Nand Nagri (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
call girls in Nand Nagri (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️9953056974 Low Rate Call Girls In Saket, Delhi NCR
 
GOODSANDSERVICETAX IN INDIAN ECONOMY IMPACT
GOODSANDSERVICETAX IN INDIAN ECONOMY IMPACTGOODSANDSERVICETAX IN INDIAN ECONOMY IMPACT
GOODSANDSERVICETAX IN INDIAN ECONOMY IMPACTharshitverma1762
 
原版1:1复刻堪萨斯大学毕业证KU毕业证留信学历认证
原版1:1复刻堪萨斯大学毕业证KU毕业证留信学历认证原版1:1复刻堪萨斯大学毕业证KU毕业证留信学历认证
原版1:1复刻堪萨斯大学毕业证KU毕业证留信学历认证jdkhjh
 
Tenets of Physiocracy History of Economic
Tenets of Physiocracy History of EconomicTenets of Physiocracy History of Economic
Tenets of Physiocracy History of Economiccinemoviesu
 
fca-bsps-decision-letter-redacted (1).pdf
fca-bsps-decision-letter-redacted (1).pdffca-bsps-decision-letter-redacted (1).pdf
fca-bsps-decision-letter-redacted (1).pdfHenry Tapper
 
Authentic No 1 Amil Baba In Pakistan Authentic No 1 Amil Baba In Karachi No 1...
Authentic No 1 Amil Baba In Pakistan Authentic No 1 Amil Baba In Karachi No 1...Authentic No 1 Amil Baba In Pakistan Authentic No 1 Amil Baba In Karachi No 1...
Authentic No 1 Amil Baba In Pakistan Authentic No 1 Amil Baba In Karachi No 1...First NO1 World Amil baba in Faisalabad
 
Stock Market Brief Deck FOR 4/17 video.pdf
Stock Market Brief Deck FOR 4/17 video.pdfStock Market Brief Deck FOR 4/17 video.pdf
Stock Market Brief Deck FOR 4/17 video.pdfMichael Silva
 
《加拿大本地办假证-寻找办理Dalhousie毕业证和达尔豪斯大学毕业证书的中介代理》
《加拿大本地办假证-寻找办理Dalhousie毕业证和达尔豪斯大学毕业证书的中介代理》《加拿大本地办假证-寻找办理Dalhousie毕业证和达尔豪斯大学毕业证书的中介代理》
《加拿大本地办假证-寻找办理Dalhousie毕业证和达尔豪斯大学毕业证书的中介代理》rnrncn29
 

Dernier (20)

Economic Risk Factor Update: April 2024 [SlideShare]
Economic Risk Factor Update: April 2024 [SlideShare]Economic Risk Factor Update: April 2024 [SlideShare]
Economic Risk Factor Update: April 2024 [SlideShare]
 
Q1 2024 Newsletter | Financial Synergies Wealth Advisors
Q1 2024 Newsletter | Financial Synergies Wealth AdvisorsQ1 2024 Newsletter | Financial Synergies Wealth Advisors
Q1 2024 Newsletter | Financial Synergies Wealth Advisors
 
The AES Investment Code - the go-to counsel for the most well-informed, wise...
The AES Investment Code -  the go-to counsel for the most well-informed, wise...The AES Investment Code -  the go-to counsel for the most well-informed, wise...
The AES Investment Code - the go-to counsel for the most well-informed, wise...
 
(中央兰开夏大学毕业证学位证成绩单-案例)
(中央兰开夏大学毕业证学位证成绩单-案例)(中央兰开夏大学毕业证学位证成绩单-案例)
(中央兰开夏大学毕业证学位证成绩单-案例)
 
Call Girls Near Me WhatsApp:+91-9833363713
Call Girls Near Me WhatsApp:+91-9833363713Call Girls Near Me WhatsApp:+91-9833363713
Call Girls Near Me WhatsApp:+91-9833363713
 
(办理学位证)加拿大萨省大学毕业证成绩单原版一比一
(办理学位证)加拿大萨省大学毕业证成绩单原版一比一(办理学位证)加拿大萨省大学毕业证成绩单原版一比一
(办理学位证)加拿大萨省大学毕业证成绩单原版一比一
 
The Core Functions of the Bangko Sentral ng Pilipinas
The Core Functions of the Bangko Sentral ng PilipinasThe Core Functions of the Bangko Sentral ng Pilipinas
The Core Functions of the Bangko Sentral ng Pilipinas
 
212MTAMount Durham University Bachelor's Diploma in Technology
212MTAMount Durham University Bachelor's Diploma in Technology212MTAMount Durham University Bachelor's Diploma in Technology
212MTAMount Durham University Bachelor's Diploma in Technology
 
原版1:1复刻温哥华岛大学毕业证Vancouver毕业证留信学历认证
原版1:1复刻温哥华岛大学毕业证Vancouver毕业证留信学历认证原版1:1复刻温哥华岛大学毕业证Vancouver毕业证留信学历认证
原版1:1复刻温哥华岛大学毕业证Vancouver毕业证留信学历认证
 
NO1 WorldWide Genuine vashikaran specialist Vashikaran baba near Lahore Vashi...
NO1 WorldWide Genuine vashikaran specialist Vashikaran baba near Lahore Vashi...NO1 WorldWide Genuine vashikaran specialist Vashikaran baba near Lahore Vashi...
NO1 WorldWide Genuine vashikaran specialist Vashikaran baba near Lahore Vashi...
 
(办理原版一样)QUT毕业证昆士兰科技大学毕业证学位证留信学历认证成绩单补办
(办理原版一样)QUT毕业证昆士兰科技大学毕业证学位证留信学历认证成绩单补办(办理原版一样)QUT毕业证昆士兰科技大学毕业证学位证留信学历认证成绩单补办
(办理原版一样)QUT毕业证昆士兰科技大学毕业证学位证留信学历认证成绩单补办
 
magnetic-pensions-a-new-blueprint-for-the-dc-landscape.pdf
magnetic-pensions-a-new-blueprint-for-the-dc-landscape.pdfmagnetic-pensions-a-new-blueprint-for-the-dc-landscape.pdf
magnetic-pensions-a-new-blueprint-for-the-dc-landscape.pdf
 
call girls in Nand Nagri (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
call girls in  Nand Nagri (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️call girls in  Nand Nagri (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
call girls in Nand Nagri (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
 
GOODSANDSERVICETAX IN INDIAN ECONOMY IMPACT
GOODSANDSERVICETAX IN INDIAN ECONOMY IMPACTGOODSANDSERVICETAX IN INDIAN ECONOMY IMPACT
GOODSANDSERVICETAX IN INDIAN ECONOMY IMPACT
 
原版1:1复刻堪萨斯大学毕业证KU毕业证留信学历认证
原版1:1复刻堪萨斯大学毕业证KU毕业证留信学历认证原版1:1复刻堪萨斯大学毕业证KU毕业证留信学历认证
原版1:1复刻堪萨斯大学毕业证KU毕业证留信学历认证
 
Tenets of Physiocracy History of Economic
Tenets of Physiocracy History of EconomicTenets of Physiocracy History of Economic
Tenets of Physiocracy History of Economic
 
fca-bsps-decision-letter-redacted (1).pdf
fca-bsps-decision-letter-redacted (1).pdffca-bsps-decision-letter-redacted (1).pdf
fca-bsps-decision-letter-redacted (1).pdf
 
Authentic No 1 Amil Baba In Pakistan Authentic No 1 Amil Baba In Karachi No 1...
Authentic No 1 Amil Baba In Pakistan Authentic No 1 Amil Baba In Karachi No 1...Authentic No 1 Amil Baba In Pakistan Authentic No 1 Amil Baba In Karachi No 1...
Authentic No 1 Amil Baba In Pakistan Authentic No 1 Amil Baba In Karachi No 1...
 
Stock Market Brief Deck FOR 4/17 video.pdf
Stock Market Brief Deck FOR 4/17 video.pdfStock Market Brief Deck FOR 4/17 video.pdf
Stock Market Brief Deck FOR 4/17 video.pdf
 
《加拿大本地办假证-寻找办理Dalhousie毕业证和达尔豪斯大学毕业证书的中介代理》
《加拿大本地办假证-寻找办理Dalhousie毕业证和达尔豪斯大学毕业证书的中介代理》《加拿大本地办假证-寻找办理Dalhousie毕业证和达尔豪斯大学毕业证书的中介代理》
《加拿大本地办假证-寻找办理Dalhousie毕业证和达尔豪斯大学毕业证书的中介代理》
 

Control&accounting information system

  • 1. C HAPTER 6 Control and Accounting Information Systems © 2006 Prentice Hall Business Publishing Accounting Information Systems, 10/e Romney/Steinbart 1 of 314
  • 2. OVERVIEW OF CONTROL CONCEPTS • Internal control is the process implemented by the board of directors, management, and those under their direction to provide reasonable assurance that the following control objectives are achieved: – Assets (including data) are safeguarded. – Records are maintained in sufficient detail to accurately and fairly reflect company assets. – Accurate and reliable information is provided. – There is reasonable assurance that financial reports are prepared in accordance with GAAP. – Operational efficiency is promoted and improved. – Adherence to prescribed managerial policies is encouraged. – The organization complies with applicable laws and regulations.
  • 3. OVERVIEW OF CONTROL CONCEPTS • Internal controls are often classified as: – General controls • e.g. software acquisition/installation controls, that apply to all size of systems. – Application controls • Completeness Check • Accuracy Check
  • 4. Legislative Reaction to Fraud: THE FOREIGN CORRUPT PRACTICES ACT • In 1977, Congress passed the Foreign Corrupt Practices Act. • The primary purpose of the act was to prevent the bribery of foreign officials to obtain business. • A significant effect was to require that corporations maintain good systems of internal accounting control.
  • 5. Legislative Reaction to Fraud: SOX – The impact on financial markets was substantial, and Congress responded with passage of the Sarbanes-Oxley Act of 2002 (aka, SOX).
  • 6. Legislative Reaction to Fraud: SOX • The intent of SOX is to: – Prevent financial statement fraud – Make financial reports more transparent – Protect investors – Strengthen internal controls in publicly-held companies – Punish executives who perpetrate fraud • SOX has had a material impact on the way boards of directors, management, and accountants operate.
  • 7. Legislative Reaction to Fraud: SOX • Important aspects of SOX include: – Creation of the Public Company Accounting Oversight Board (PCAOB) to oversee the auditing profession. – New rules for auditors – New rules for audit committees – New rules for management – New internal control requirements
  • 8. Legislative Reaction to Fraud: SOX • After the passage of SOX, the SEC further mandated that: – Management must base its evaluation on a recognized control framework, developed using a due-process procedure that allows for public comment. The most likely framework is the COSO model discussed later in the chapter. – The report must contain a statement identifying the framework used. – Management must disclose any and all material internal control weaknesses. – Management cannot conclude that the company has effective internal control if there are any material weaknesses.
  • 9. • Levers of Control (pp 194 -195)  skip
  • 10. CONTROL FRAMEWORKS • A number of frameworks have been developed to help companies develop good internal control systems. Three of the most important are: – The COBIT framework – The COSO internal control framework – COSO’s Enterprise Risk Management framework (ERM) • An enhanced corporate governance document. • Expands on elements of preceding framework. • Provides a focus on the broader subject of enterprise risk management.
  • 11. COSO’S ERM • COSO developed a model to illustrate the elements of ERM.
  • 12. INTERNAL ENVIRONMENT • The most critical component of the ERM and the internal control framework. • Is the foundation on which the other seven components rest. • Influences how organizations: – Establish strategies and objectives – Structure business activities – Identify, access, and respond to risk • A deficient internal control environment often results in risk management and control breakdowns.
  • 13. INTERNAL ENVIRONMENT • Internal environment consists of the following: – Management’s attitude toward risk – Commitment to integrity, ethical values, and competence – Organizational structure – Methods of assigning authority and responsibility – Human resource standards (Background Check) ROBA = Risk, Organizational structure, Background check, Assigning Responsibility.
  • 14. OBJECTIVE SETTING • The objective of the Sarbanes-Oxley Act is to strengthen internal controls in public companies. • AICPA’s five objectives for accounting information systems.
  • 15. EVENT IDENTIFICATION • Events are: – Incidents or occurrences that emanate from internal or external sources – Impact can be positive, negative, or both. – System design should identify all potential events.
  • 16. RISK ASSESSMENT AND RISK RESPONSE – Inherent risk: • The risk before internal controls – Residual risk • The risk after management implements internal controls.
  • 17. RISK ASSESSMENT AND RISK RESPONSE Identify the events or threats that confront the company Estimate the likelihood or probability of each event occurring Estimate the impact of potential loss from each threat Identify set of controls to guard against threat Estimate costs and benefits from instituting controls Is it cost-beneficia l to protect system Avoid, share, or accept risk Yes No Reduce risk by implementing set of controls to guard against threat Threats Probability Impact of Loss Identify Controls Cost and Benefits
  • 18. CONTROL ACTIVITIES • The sixth component of COSO’s ERM model. • Control activities are policies, procedures, and rules that provide reasonable assurance that management’s control objectives are met and their risk responses are carried out.
  • 19. CONTROL ACTIVITIES • Generally, control procedures fall into one of the following categories: -Proper authorization of transaction -Segregation of duties -Change management controls • Design and use of documents and records – Documents that initiate a transaction should contain a space for authorization • Safeguard assets, records, and data • Independent checks on performance
  • 20. CONTROL ACTIVITIES • To learn a little about segregation of duties, let’s first meet Bill.
  • 21. CONTROL ACTIVITIES • Bill has charge of a pile of the organization’s money—let’s say $1,000.
  • 22. CONTROL ACTIVITIES Ledger $1,000 • Bill also keeps the books for that money.
  • 23. CONTROL ACTIVITIES Ledger $1,000 • Bill has a date tonight, and he’s a little desperate to impress that special someone, so he takes $100 of the cash. (Thinks he’s only borrowing it, you know.)
  • 24. CONTROL ACTIVITIES Ledger $1,000 • Bill has a date tonight, and he’s a little desperate to impress that special someone, so he takes $100 of the cash. (Thinks he’s only borrowing it, you know.)
  • 25. CONTROL ACTIVITIES Ledger $1,000 • Bill also records an entry in the books to show that $100 was spent for some “legitimate” purpose. Now the balance in the books is $900.
  • 26. CONTROL ACTIVITIES Ledger $900 • How will Bill ever get caught at his theft?
  • 27. CONTROL ACTIVITIES • Now let’s change the story. Bill has charge of the pile of cash.
  • 28. CONTROL ACTIVITIES Ledger $1,000 • But Mary keeps the books. • This arrangement is a form of segregation of duties.
  • 29. CONTROL ACTIVITIES • Bill gets in a pinch again and takes $100 of the organization’s cash. Ledger $1,000
  • 30. CONTROL ACTIVITIES • How will Bill get caught? Ledger $1,000
  • 31. CONTROL ACTIVITIES • Segregation of Accounting Duties – Effective segregation of accounting duties is achieved when the following functions are separated: • Authorization—approving transactions and decisions. • Recording—Preparing source documents; maintaining journals, ledgers, or other files; preparing reconciliations; and preparing performance reports. • Custody—Handling cash, maintaining an inventory storeroom, receiving incoming customer checks, writing checks on the organization’s bank account. – If any two of the preceding functions are the responsibility of one person, then problems can arise.
  • 32. CONTROL ACTIVITIES CUSTODIAL FUNCTIONS • Handling cash • Handling inventories, tools, or fixed assets • Writing checks • Receiving checks in mail RECORDING FUNCTIONS • Preparing source AUTHORIZATION FUNCTIONS • General Authorization • Specific authorization documents • Maintaining journals, ledgers, or other files • Preparing reconciliations • Preparing performance reports
  • 33. Can you tell me what seems wrong? • An employee receiving checks in the mail and records receipts in the Cash Receipts journal • An employee authorizes credit sales and has custody of Finished Goods Inventory • An employee enters sales transactions into the accounting system and has custody of Finished Goods inventory. • An employee receives checks in the mail and has access to the Petty Cash Fund.
  • 34. CONTROL ACTIVITIES • In a system that incorporates an effective separation of duties, it should be difficult for any single employee to commit embezzlement successfully. • But when two or more people collude, then segregation of duties becomes impotent and controls are overridden.
  • 35. CONTROL ACTIVITIES • If this happens . . . Ledger $1,000
  • 36. CONTROL ACTIVITIES Ledger $1,000 • Then segregation of duties is out the window. Collusion overrides segregation.
  • 37. CONTROL ACTIVITIES • Generally, control procedures fall into one of the following categories: – Proper authorization of transactions and activities – Segregation of duties – Project development and acquisition controls • Strategic master plan – Change management controls – Design and use of documents and records – Safeguard assets, records, and data – Independent checks on performance
  • 38. CONTROL ACTIVITIES Ledger $1,000 • Let’s look at Bill and Mary again. Assume that Bill stole cash but Mary did NOT alter the books.
  • 39. CONTROL ACTIVITIES Ledger $1,000 • Can Bill’s theft be discovered if an independent party doesn’t compare a count of the cash to what’s recorded on the books?
  • 40. CONTROL ACTIVITIES Ledger $1,000 • Segregation of duties only has value when supplemented by independent checks.
  • 41. CONTROL ACTIVITIES • The following independent checks are typically used: – Top-level reviews – Analytical reviews – Reconciliation of independently maintained sets of records – Comparison of actual quantities with recorded amounts
  • 42. CONTROL ACTIVITIES • The following independent checks are typically used: – Top-level reviews – Analytical reviews • Examinations of relationships between different sets of data. • EXAMPLE: If credit sales increased significantly during the period and there were no changes in credit policy, then bad debt expense should probably have increased also. • Management should periodically analyze and review data relationships to detect fraud and other business problems.
  • 43. INFORMATION AND COMMUNICATION • The seventh component of COSO’s ERM model. • The primary purpose of the AIS is to gather, record, process, store, summarize, and communicate information about an organization. • So accountants must understand how: – Transactions are initiated – Data are captured in or converted to machine-readable form – Computer files are accessed and updated – Data are processed – Information is reported to internal and external parties
  • 44. INFORMATION AND COMMUNICATION • According to the AICPA, an AIS has five primary objectives: – Identify and record all valid transactions. – Properly classify transactions. – Record transactions at their proper monetary value. – Record transactions in the proper accounting period. – Properly present transactions and related disclosures in the financial statements.
  • 45. MONITORING • Internal Monitoring • When independent auditors come to clients’ site, it is an independent review, not an operation monitoring.
  • 46. MONITORING • Key methods of monitoring performance include: – Implement effective supervision – Monitor system activities – Track purchased software licenses. – Employ internal auditors to review the system – Employ a computer security officer – Install fraud detection software – Implement a fraud hotline