Internal Control
Process designed, implemented, and maintained by those charged with governance, management and other personnel to provide reasonable assurance about the achievement of an entity’s objectives with regard to
a. reliability of finacial reporting
b. Effectiveness and efficiency of operations
c. Compliance with applicable laws and regulations
Characteristics of Internal Control
Inherent limitations that may affect effectiveness of internal controls (COC CHA)
Controls
Policies or procedures that an entity establishes to achieve the control objectives of management or those charged with governance.
Areas of Internal Control
Accounting System
Series of tasks and records of an entity by which transactions are processed as a means of maintaining financial records
Internal Control System
All the policies and procedures adopted by management of an entity to assist in achieving management objectives
Parties Responsible for Internal Control
Component of Internal Control (CRIME)
Direct vs Indirect Controls
Direct- controls that are precise enough to address the risk of material misstatements.
(Information and Communication Systems and Control Activities)
Indirect- Controls that are not sufficiently precise to prevent, detect, or correct misstatements at the assertion level
(Control Environment, Entity’s Risk Assessment Procedures, and Monitoring of Controls)
Control Environment
Set of standards, processes and structures that provide a basis for carrying out of internal control. Also the foundation on which an effective system of internal control is built and operated in an organization
Elements of Control Environment (OLD)
Elements of Control Environment (NEW)
What are the Entity’s Risk Assessment Procedures
Monitoring of Controls
Process of assessing the quality of internal control performance over time which includes assessing the design and operations of controls on a timely basis and takin necessary corrective actions
Direct vs Indirect Controls
Direct Controls- controls that are precise enough to address the risk of material misstatement at the assertion level
Indirect Controls- Controls that are not sufficiently precise to prevent, detect or correct misstatements at the assertion level
Components of Information System
Control Activities
Actions that help management mitigate risks in order to ensure the achievement of objectives.
Examples of Control Activities (OLD)(APIPS)
Examples of Control Activities (NEW) (PARVS)