Chapter7:InternalcontrolandcontrolriskLearningObjectivesAppreciatetheimportanceofinternalcontrolDescribethecomponentsofinternalcontrolStatetheinherentlimitationsoftheinternalcontrolsystemIndicatetheproceduresusedtoobtainanddocumentanunderstandingofinternalcontrolExplainthepurposeofmakingapreliminaryassessmentofcontrolriskLearningObjectivesDescribetheapproachtoevaluatingthedesigneffectivenessofcontrolactivitiesStatethepurposeoftestsofcontrolandthenatureofsuchtestsDescribehowtheworkofinternalauditingmaybeusedintestsofcontrolExplaintheprocessofassessingcontrolriskRiskAssessmentNatureandextentofrisksfacingthecompanyExtentandcategoriesofriskdeemedokayLikelihoodofrisksmaterialisingCompany’sabilitytoreducetheincidenceandimpactoftheriskonthebusinessThecostsofoperatingparticularcontrolsRiskAssessmentHighimpactMediumimpactLowimpactHighlikelihoodSignific.controlsMediumlikelihoodAveragecontrolsLowlikelihoodFewcontrolsKeyTerms&ConceptsControlriskDual-purposetestFlowchartInformationsystemInherentlimitationsNarrativememorandumNecessarycontrolsPhysicalcontrolsSegregationofdutiesTestsofcontrolWalk-throughreviewDefinitionandConceptsofInternalControl(Turnbull)Aninternalcontrolsystemencompassesthepolicies,processes,tasks,behaviourandotheraspectsofacompanythat,takentogether:facilitateitseffectiveandefficientoperationbyenablingittorespondappropriatelytosignificantbusiness,operational,financial,complianceandotherriskstoachievingthecompany’sobjectives.Thisincludesthesafeguardingofassetsfrominappropriateuseorfromlossandfraud,andensuringthatliabilitiesareidentifiedandmanaged;DefinitionandConceptsofInternalControl(Turnbull)helpensurethequalityofinternalandindependentreporting.Thisrequiresthemaintenanceofproperrecordsandprocessesthatgenerateaflowoftimely,relevantandreliableinformationfromwithinandoutsidetheorganisation;helpensurecompliancewithapplicablelawsandregulations,andalsowithinternalpolicieswithrespecttotheconductofbusiness.ComponentsofInternalControlThecontrolenvironmentTheentity’sriskassessmentprocessTheinformationsystemControlactivitiesMonitoringofcontrolsControlEnvironmentRelevantfactorsIntegrityandethicalvaluesCommitmenttocompetenceManagement’sphilosophy&operatingstyleOrganisationalstructureAssignmentofauthorityandresponsibilityControlEnvironmentRelevantfactors(cont.)InternalauditUseofinformationtechnologyhumanresourcepoliciesandpracticeBoardofdirectorsandauditcommitteeHumanResourcePolicies(riskenvironment)RelevantfactorsDevelopingappropriaterecruitmentpoliciesScreeningprospectiveemployeesOrientingnewpersonnelDevelopingtrainingpoliciesExercisingdisciplinaryactionEvaluating,counsellingandpromotingImplementingcompensationprogrammesBoardofDirectors(riskassessment+environment)RelevantfactorsProportionofnon-executivedirectorsExperienceandstatureofdirectorsExtentofinvolvementinrunningthebusinessandmonitoringthemanagersStrategicawarenessBusinessacumenInteractionwithinternalandexternalauditorsConfidencetoraiseandpursuedifficultquestionsInformationsystemIdentifiesandrecordstransactionsandothereventssuchthatall,butonly,validtransactionsarerecordedrecordedassetsandliabilitiesarisefromtransactionsproducingrightsandobligationstransactionsareproperlymeasuredandrecordedinthecorrectperiodandinsufficientdetailMaintainsaccountabilityforassetsandliabilitiesControlActivitiesInformationprocessingcontrols-generalvapplicationproperauthorisationdocumentsandrecordsindependentchecksSegregationofdutiesbetweenexecuting,recordingandcustodyofassetsresultingfromtransactionbetweenstepsinexecutingatransactionbetweencertainaccountingoperationsPhysicalcontrolsPerformancereviewsMonitoringTypesofInternalControlOrganisationSegregationofDutiesPhysicalAuthorisationandApprovalArithmeticandAccountingTypesofInternalControlPersonnelSupervisionManagementAcknowledgementofPerformanceBudgetingTypesofInternalControlOAPSPASMOrganisation,authorisationPersonnel,supervisionPhysical,arithmeticSegregation,managementLimitationsOnlyprovidesreasonableassurancebecauseof:costsversusbenefitsmanagementoverridemistakesinjudgementcollusionbreakdownsLimitationsOnlyprovidesreasonableassurancebecauseof:Tendnottobeasstrongonone-offtransactions.Potentialforhumanerror.Abuseofresponsibility.Managementover-rideofcontrols.Changesintheenvironment.Humaningenuity.InternalControlSECONDSESSIONInternalControlApplicationtosmallerentitiesControlincomputerinformationsystemsPotentialtobothincreaseanddecreaseriskoferrorsControlinComputerSystemsConsistentlyapplypredefinedcontrolsFacilitateadditionalanalysisEnhancetheabilitytomonitorReduceriskcontrolswillbecircumventedGreaterchanceofsegregationofdutiesProceduretoObtainanUnderstandingObtaininganunderstandingReviewingpreviousexperienceInquiringInspectingdocumentsandrecordsObservationandwalkthroughWalkthroughTeststoensurethattheauditorhasacorrectunderstandingoftheinternalcontrolandaccountingsystemsinplacewithinthebusiness.Oncetheauditorhasdiscov