Internal Control
1 Recording the client’s accounting system
One of the first things that the auditor has to do in a new audit is to record the client’s accounting system and internal control processes
This will provide a basis for evaluating the design of internal controls.
Where it’s a repeat audit, the auditor must ensure that their records of the client system are updated and remain accurate.
Commonly used ways of recording the system include:
Narrative notes
Flowcharts
Questionnaires.
Narrative notes explain, for example, exactly what happens to a supplier’s invoice when it’s received: how it may be matched with goods received notes, how the calculations are checked, how it is filed, how it is posted to the trade payables account, and how the amount is eventually paid.
Narrative notes can be relatively quick to prepare. Typically you observe what happens, you ask the client what happens, and you may also look at the accounting procedures which they have established more formally.
The main problem that arises with narrative notes is the lack of structure or discipline. It’s very easy for documents to appear in narratives and then not be mentioned again and the audit team is then wondering what happens to these documents, and where they can be found.
A flowchart is a diagram that shows the documents, the files, the calculations, and the checks that are performed. Flowcharts can be somewhat slower to produce and are certainly more difficult to amend (though nowadays, flowcharting has been helped greatly by computer graphics systems). Flowcharting imposes a great discipline on how systems are recorded as it has very specific rules about how flowcharts are to be drawn. In addition, there is usually a special symbol which is reserved to show where checks are performed. Auditors are particularly interested where checks are performed because this is helping the client to reduce control risk.
Questionnaires can be used to record the accounting system, and can also help evaluate the design of internal controls.
Questionnaires can take many forms, for example:
Internal Control Questionnaire (ICQ).
Internal Control Evaluation Questionnaire (ICEQ)
An ICQ asks whether specific controls are in place, for example: “Are suppliers’ invoices cancelled when they are paid?” The answer “Yes” is good, the answer “No” is bad because it means that those invoices could be inadvertently paid a second time.
However, there are other controls that would meet the control objective that suppliers' invoices should not be paid twice. For example, they could simply be moved from one file to another, from an unpaid invoice file to a paid invoice file.
ICEQs focus on identifying the controls that meet a control objective that can be expressed in different ways, for example:
To ensure that suppliers cannot be paid for goods not received; or
To ensure that suppliers are only paid for goods received.
ICEQs will almost certainly require greater skill from the auditor. Instead of simply having to find out if invoices are cancelled, the auditor has to assess whether or not invoices could be paid twice.
2 Components of internal control
These are the five components of internal control:
The control environment provides the foundation for the other components of the system of internal control. It includes:
How management’s oversight responsibilities are carried out (e.g. organisational culture and management’s commitment to integrity and ethical values)
Oversight by TCWG (where separate from management)
The assignment of authority and responsibility
How competent individuals are attracted, developed and retained
How individuals are held accountable for their responsibilities relating to the system of internal control.
The risk assessment process relevant to the preparation of the financial statements concerns how management identifies, assesses and addresses risks. It has to determine the significance of those risks and the likelihood that they are occurring. Having identified a risk, having assessed the likelihood of its occurring, management has to decide what to do about it. What controls would address the risks identified?
The information system and communication. Information processing activities include:
How transactions are initiated, recorded, processed, corrected as necessary, incorporated in the general ledger and reported in the financial statements
How information about events and conditions, other than transactions, is captured, processed and disclosed in the financial statements
The accounting records, financial reporting process and relevant resources, including the IT environment.
Communication channels may be structured in larger entities (e.g. policy and financial reporting manuals).
Control activities are defined as "those policies and procedures, that help ensure that management directives are carried out" (see later).
Monitoring process. How the entity monitors the effectiveness of controls and identifies and remedies control deficiencies may include the internal audit function, if any (see Chapter 23). In less complex entities, management's involvement in operations and/or periodic review of accounting information may be the only monitoring activities to help prevent or detect misstatements.
3 Control activities
The auditor must identify the control activities that address risks of material misstatement at the assertion level.
Examples of control activities include the following:
Segregation of duties. This means separating the responsibilities for authorising transactions, recording transactions and having custody of assets. So, for example, a person cannot make a sale, omit to record it and pocket the cash. Where, especially in smaller entities, there is less scope for segregation there will be a greater need for independent checks and management supervision.
Authorisation and approval. The authorisation or approval and control of documents is very important. Transactions should be authorised (i.e. confirmed to be valid) by an appropriate level of management. For example the purchase of non-current assets, agreeing credit terms, the writing off of a bad debt, and employees’ overtime. Approval may be automated (e.g. invoices less than a pre-established monetary amount and matched to a purchase order are automatically approved for payment).
Verifications. Verifications may compare two or more items or an item with a policy, and typically involve a follow-up action if items do not match/are not consistent with policy. Comparing, for example, goods received notes with the original purchase orders to make sure that what has been received was, in fact, what was ordered. Verifications generally address the completeness, accuracy, or validity of processing transactions.
Accounting reconciliations. Reconciliation is the process of ensuring that two sets of records from different sources agree. For example comparing the cash balance with a bank statement or comparing a payables balance with the supplier statement. If the balances do not agree, they must be reconciled (i.e. the differences identified and properly accounted for). Reconciliations generally address the completeness and/or accuracy of processing transactions, including cut-off.
Physical or logical controls. There should be physical safeguards established over certain assets particularly inventories and cash. These assets can often be desirable, portable and valuable. If they are not safeguarded, they are more likely to go missing. Physical controls include periodic counting (e.g. of inventory) and comparison with recorded amounts. Access to records may be safeguarded through physical controls or logical controls (e.g. authorised access to computer programs and data files).
The auditor must also identify the relevant information technology (IT) applications, the risks arising from the use of IT and the entity’s general IT controls that address such risks (see Chapter 14).
4 Inherent limitations of internal control
No matter how effective a system of internal control it cannot eliminate the risk of material misstatement in the financial statements.
Cost v benefit. The cost of establishing a system of internal control may be greater than the benefits. To take a ridiculous example, it’s very unlikely that anyone is going to establish a system of internal control over the issue of paperclips or envelopes. The amount of management time taken up with authorising trivial amounts of expenditure simply makes it uneconomic. At some stage however the benefits may outweigh the costs and, for example, when it comes to photocopying many organisations do have some sort of authorisation or at least accounting system to track who uses most of the photocopying resource.
Human error. For example, one person makes out an invoice using the wrong selling price and another one checks it and doesn’t see the error. This is always a possibility even in the best regulated circumstances.
Collusion. Where two or more employees cooperate to get around (circumvent) the internal control system. The collusion might be to carry out a fraud or it might be to cover up some error that was made. The greater the segregation of duties, the greater the number of people who would need to collude.
Management override ('bypass'). Say someone has forgotten to order a vital piece of equipment. To speed matters up, instead of going through the formal procedure (say getting a quote from an approved supplier before placing the order), a manager orders it from a supplier who can deliver it tomorrow, but is not on the approved suppliers list. Such 'management override' or bypass of controls may be with the best possible intentions but, if it is a common occurrence, essentially the controls are not operating (increasing the risk of error and fraud).
Non-routine transactions. These relatively rare transactions fall outside routine transactions (which may be highly automated). An example can be the disposal of non-current assets. Many of these assets are scrapped when they are disposed of, and to establish a system of internal control might not have been thought worthwhile. However, occasionally an asset with a substantial value might be disposed of, and if there is no system for getting the right price and for ensuring that the proceeds come to the business, there is a possibility that those transactions are not properly recorded.
5 A reminder of the audit approach
Keep four ideas separate. A control objective states what the system should achieve. A control procedure is an action by the entity. A test of control evaluates whether that action operated effectively. A substantive procedure detects material misstatement in transactions, balances or disclosures.
Let’s just review again how audits are carried out.
First of all, evaluate the design of the system. If suitable controls appear to exist, the audit will tend to proceed by testing those controls to evaluate whether the controls are indeed operating effectively.
If however, internal controls are absent or not operating effectively, evidence must be obtained from substantive procedures alone. This means examining transactions for direct verification rather than relying on the operation of controls.
When controls operate effectively, the audit will usually be more efficient and cost effective if the auditor tests the operation of controls and reduces the extent of substantive procedures. However, some substantive procedures will always be required (for each material class of transactions, account balance and disclosure) due to inherent limitations of internal control.
In some audit areas it may actually be more efficient to perform only substantive procedures to a relatively small number of actual transactions (e.g. additions to/disposals of non-current assets).
6 Tests of controls
6.1 Direct v indirect controls
The auditor may plan to test:
direct controls (i.e. that are sufficiently precise to prevent, detect or correct misstatements);
indirect controls (i.e. that support direct controls) including general IT controls (see Chapter 14).
Controls in the control environment, risk assessment process and monitoring process are primarily indirect controls (but may also be direct). Controls in the information system and communication and control activities are primarily direct controls (but may also be indirect).
6.2 Audit procedures
Internal controls can be tested using the following procedures:
Inspection Look at evidence of internal control procedures. For example, inspect the file of paid supplier invoices to see if they have indeed been stamped or initialed to indicate that they had been paid.
Observation Watch employees as they carry out certain transactions and procedures. Of course, employees would be on their best behaviour if they knew they were being observed.
Reperformance For example, reperform what the employees have done to make sure that they have done it correctly.
* IMPORTANT note: Enquiry is required as a risk assessment procedure but is never sufficient to test the operating effectiveness of controls. Therefore other audit procedures must always be performed in combination with enquiry. Enquiry + inspection or reperformance is better than enquiry + observation (at a point in time).
7 Reporting on internal control
Control deficiencies related to financial reporting identified in the system of internal control should be communicated appropriately to TCWG and management. Such written communications are often referred to as "management letters" or "letters of weakness".
A deficiency (weakness) in internal control exists when:
A control is designed, implemented, or operated in such a way that it is unable to prevent (or detect and correct) misstatements on a timely basis; or
Such a control is missing.
'Significant deficiencies' are those which the auditor considers to be of sufficient importance to merit the attention of TCWG and must be communicated in writing, on a timely basis. A deficiency may be regarded as significant if, for example:
It requires prompt corrective action
It is likely to result in material misstatement
Assets are susceptible to loss or fraud
It raises doubts about management's integrity (e.g. suspicion of fraud) or competence (e.g. failure to take corrective action).
Other deficiencies should be communicated to an appropriate level of management.
A written communication will usually be structured as follows:
Say what the problem is.
Say what the implications, potential effects or consequences of those problems might be.
Recommend how the problem can be fixed.
So the problem might be that supplier invoices are not cancelled when paid; the consequence of that could be that supplier invoices are paid more than once; the way to prevent that is that you mark or stamp invoices ‘Paid’.
Auditors will normally also say that they may not have found all control weaknesses and that others may exist and that is duty of the board of directors, to ensure that there is an adequate system of internal control operating within the company.
Internal control
10 questionsAnswer the questions one at a time. Your progress is saved so you can leave and come back.
Open chapter practice

