Presentation is loading. Please wait.

Presentation is loading. Please wait.

Internal Control in a Financial Statement Audit

Similar presentations


Presentation on theme: "Internal Control in a Financial Statement Audit"— Presentation transcript:

1 Internal Control in a Financial Statement Audit
Chapter 6 Internal Control in a Financial Statement Audit McGraw-Hill/Irwin Copyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.

2 Internal Control The auditor uses risk assessment procedures to
LO# 1 The auditor uses risk assessment procedures to -obtain an understanding of the entity’s internal control -identify the types of potential misstatements -ascertain factors that affect the risk of material misstatement -design tests of controls and substantive procedures The auditor’s understanding of the internal control is a major factor in determining the overall audit strategy. The auditor has a responsibility to: (1) obtain an understanding of internal control and (2) assess control risk. 6-2

3 COSO’s Internal Control – Integrated Framework
LO# 2 COSO’s Internal Control – Integrated Framework Reliability of Financial Reporting Effectiveness and Efficiency of Operations Compliance with Laws and Regulations Objectives 6-3

4 The Effect of Information Technology on Internal Control
6-4

5 Components of Internal Control
LO# 5 Components of Internal Control 6-5

6 LO# 6 Planning an Audit Strategy Figure 6-3 Flowchart of the Auditor’s Consideration of Internal Control and Its Relation to Substantive Procedures 6-6

7 Obtain an Understanding of Internal Control
LO# 7 Obtain an Understanding of Internal Control The auditor should obtain an understanding of each of the five components of internal control in order to plan the audit. This knowledge is used to: Identify types of potential misstatement Pinpoint the factors that affect the risk of material misstatement Design tests of controls and substantive procedures 6-7

8 Documenting the Understanding of Internal Control
LO# 8 Documenting the Understanding of Internal Control Procedure Manuals and Organizational Charts Flowcharts Internal Control Questionnaires Narrative Description 6-8

9 The Limitations of an Entity’s Internal Control
LO# 8 The Limitations of an Entity’s Internal Control Override of Internal Control by Management Human Errors or Mistakes Collusion 6-9

10 Assessing Control Risk
LO# 9 Identify specific controls that will be relied upon. Perform tests of controls. Conclude on the achieved level of control risk. 6-10

11 Interim Audit Procedures
LO# 12 Interim Audit Procedures Interim Tests of Controls Assertion being tested not significant Control has been effective in prior audits Efficient use of staff time Interim Substantive Procedures Assertion probably has low control risk May increase the risk of material misstatements Still requires some year-end testing 6-11

12 Auditing Accounting Applications Processed by Service Organizations
LO# 13 Auditing Accounting Applications Processed by Service Organizations In some instances, a client may have some or all of its accounting transactions processed by an outside service organization. Because the client’s transactions are subjected to the controls of the service organization, one of the auditor’s concerns is the internal control system in place at the service organization. It is not uncommon for service organizations to have an auditor issue one of two types of reports on their operations. 6-12

13 Communication of Internal Control-Related Matters
LO# 14 Communication of Internal Control-Related Matters A material weakness is a deficiency, or combination of deficiencies, in internal control, such that there is a reasonable possibility that a material misstatement of the financial statements will not be prevented, or detected and corrected. Material Weakness A Significant deficiency is a deficiency, or a combination of deficiencies, in internal control that is less severe than a material weakness, yet important enough to merit attention by those charged with governance. Significant Deficiency 6-13

14 Types of Controls in an IT Environment
LO# 15 Types of Controls in an IT Environment General Controls Data center and network operations System software acquisition, change, and maintenance Access security Application system acquisition, development, and maintenance Application Controls Data capture controls Data validation controls Processing controls Output controls Error controls 6-14

15 LO# 16 Flowcharting Symbols 6-15

16 End of Chapter 6 6-16


Download ppt "Internal Control in a Financial Statement Audit"

Similar presentations


Ads by Google