Acct 315-Ch 6
Dr. Devine-Accounting Information Systems
Terms
undefined, object
copy deck
- Auditing Standard No. 5 areas of emphasis in regards to internal control
- alignment with mgmt guidance, top-down approach, emphasis on fraud controls, entity-level controls, walk-throughs, evaluation and communication of deficiencies, scaling the audit, use of the work of others
- Factors contributing to a company's internal control environment
- management's philosophy, operating style, and risk appetite; the board of directors; commitment to integritiy, ethical values, and competence; organizational structure; methods of assigning authority and repsonsibility; human resource standard; external influences
- preventive control
- have the objective of preventing errors or fraud that could result in a misstatement of the financial statements from occurring
- How does an auditor address the risk of fraud
- company has entity-level controls, then other preventive and detective controls, ask basic questions: 1. Do the company's controls adequately address identified risks of material misstatement due to fraud? 2.Does the company have controls/policies in place to address the risk of mgmt override of other conrols?
- Auditing Standard No. 5 definition of internal control
- A process designed by, or under the supervision of, the company's principal executive and principal financial officers, or persons performing similar functions, and effected by the company's board of directors, mgmt, and other personnel, to provide reasonable assurance regarding the reliability of financial reporting and preparation of financial statements for external purposes in accordance with GAAP and includes those policies and procedures that...
- Why can Complexity factor into the likelihood that fraud may exist
- complex structures may unintentionally impede communication and clear assignment of responsibility, making fraud easier to commit or conceal OR structure may be intentionally complex to facilitate fraud
- SOX implications for auditors
- Report to the audit committee. Audit partners must be rotated periodically. Cannot perform bookeeping, IS design and implementation, internal audit outsourcing services, mgmt functions, HR services. Permissible nonaudit service must be approved by board and disclosed to investors. Audit fimrs cannot provide services to publicly held companies if top mgmt was previously employed by the auditing firm & worked the company's audit in the past 12 months.
- Why is it important to achieve adequate security and control over information resources?
- keep information and data available only to the sources who need it
- material weakness
- a deficiency, or combination of deficiencies, in internal control over financial reporting, such that there is a reasonable possibility that a material misstatement of the company's annual or interim financial statements will not be prevented or detected on a timely basis
- Basic Financial Statement assertions made by management
- existence or occurrence, completeness, valuation or allocation, rights and obligations, presentation and disclosure
- Why AIS threats are increasing
- there are computers and servers everywhere and information is available to an unprecedented # of workers; distributed computer networks make data available to many users and these networks are harder to control than centralized mainframe systems; wide area networs are giving customers and suppliers access to each other's systems and data making confidentiality a major concern.
- likelihood of threat
- probability that the threat will occur
- 4 Categories of control activities
- 1. proper authorization of transactions & activities 2. segregation of duties 3. safeguarding 4. asset accountability
- Factors/Circumstances that cause risk to change
- changes in operating environment, new personnel, new or revamped information systems, rapid growth, new technology, new products/activities, corporate restructurings, expanded foreign operations, new accounting pronouncements
- How does the Sarbanes-Oxley Act of 2002 relate to internal control
- it has the intent to prevent financial statement fraud, make financial reports more transparent, protect investors, strengthen internal controls in publicly-held companies, punish executives who perpetrate fraud
- examples of preventive controls
- hiring highly qualified accounting personnel, appropriately segregating employy duties, effectively controlling physical access to assets, facilities, and informations
- Exposure/Impact of threat
- potential dollar loss that would occur if the threat becomes a reality
- Threat
- any potential adverse occurrence or unwanted event that could injure the AIS or the organixation
- Role computers play in the increasing AIS threats
- The increasing number of computers and the data they contain as well as who has access to them
- SOX implications for management
- CEO and CFO must certify that financial statements and disclosures are fairly presented, were reviewed by mgmt, and are not misleading. They are responsible for internal controls. If they violate certification, they can face up to 20 years in prision and fined $5,000,000. Mgmt & directors cannot receive loans that those outside the company cannot get. Companies must disclose material changes to their financial condition on a current, rapid basis.
- Auditing Standard No. 5 entity-level controls
- controls related to the control environment, controls over mgmt override, company's risk assessment process, centralized processing controls including shared service environments, controls to monitor the results of operations, controls to monitor other controls, controls over the period-end financial reporting process, policies that address significant business control and risk mgmt practices
- SOX implications for board of directors/audit committees
- Audit committee members must be on the company's board of directors and be independent of the company. One member must be a financial expert. They hire, compensate, and oversee the auditors who report directly to them
- examples of detective controls
- duplicate checking of calculations, preparing bank reconciliations and monthly trial balances
- detective control
- have the objective of detecting or fraud that has already occurred that could result in a misstatement of the financial statements
- Key Provisions of the Foreign Corrupt Practices Act
- purpose of act was to prevent the bribery of foreign officials to obtain business. required corporations to maintain good systems of internal accounting control. interest among management, accountants, and auditors in designing and evaluating internal control systems
- 4 potential control frameworks that are used to explain internal control
- COBIT framework, COSO internal control framework, COSO's Enterprise Risk Management framework (ERM), Auditing Standard No. 5