internal controls
process affected by entities directors, managers and others
goals of internal controls
safeguard assets
ensure accuracy of fin states
promote efficiency
comply with law and regulations
managers are
responsible for financial statements and controls
reasonable assurance
controls systems cant 100% be perfect
- human error
- colussion : 2 or more people working together
- management override
- cost-benefit
exposure
area where system is vulnuerable
–> if theres exposure it doesnt always mean theres a mistatement
preventative controls
techniques designed to detect errors and not allow them to enter the system
*most effective than detective and corrective
detective controls
finds misstatements which were inputted into the system
corrective controls
fixes misstatements
–> not always obvious about what went wrong
COSO makes rules for…
audit standards and SOX backup COSO
internal control framework (5 components)
risk assessment
proactively identify risks and threats before they become a problem
control environment
tone and attitude of management will ripple down the org
aka culture
quality of information
the design of an accounting system
monitoring
periodically check what people are doing
control activities
specific actions taken like:
- seperation of duties
- 2 people signing off checks
IT controls
related to computer environment
general and application controls
general control
entity wide IT concerns, relate to operating system as a whole
application controls
ensure integrity of system. audit concerned with application controls
physical controls
input control
prevent mistatement to even occur
- check digit
- missing data check
- numeric alphabetic check
- limit checks
- range checks
- reasonableness checks
- validity checks
processing controls
procedures to ensure applications logic is functioning properly
ex: batch totals
audit trail controls
follow transaction from beginning to end or end to beginning
- every transaction system process should be recorded in transaction log
transaction log
list of successfully processed transactions
error log
all transactions that werent successful