Auditing Concepts.

Slides:



Advertisements
Similar presentations
Bodnar/Hopwood AIS 7th Ed1 Chapter 5 u TRANSACTION PROCESSING AND INTERNAL CONTROL PROCESS.
Advertisements

Auditing Concepts.
Learning Objectives LO5 Document an accounting system to identify key controls and weaknesses in order to assess control risk. LO6 Write key control tests.
Internal Control.
Auditing Computer-Based Information Systems
The Islamic University of Gaza
©2008 Prentice Hall Business Publishing, Auditing 12/e, Arens/Beasley/Elder The Demand for Audit and Other Assurance Services Chapter 1.
Internal Control Structure. Learning Objectives l To understand the components of an organization’s internal control structure l To know the objectives.
Review of Introduction to Auditing
Standar Pekerjaan Lapangan: Pemahaman Memadai atas Pengendalian Intern Pertemuan 5.
9.401 Auditing Chapter 1 Introduction. Definition of Auditing The accumulation and evaluation The accumulation and evaluation Of evidence about information.
CHAPTER 9 UNDERSTANDING INTERNAL CONTROLS Winter 2004
Chapter 9 The Study of Internal Control and Assessment of Control Risk
Chapter 12 Auditing the Human Resource Management Process McGraw-Hill/Irwin ©2008 The McGraw-Hill Companies, All Rights Reserved.
18- 1 © 2006 The McGraw-Hill Companies, Inc., All Rights Reserved. Chapter 18 Integrated Audits of Internal Control (For Public Companies Under Sarbanes-Oxley.
Internal Control in a Financial Statement Audit
Sarbanes-Oxley Project Summary of COSO Framework Presented by Larry Dillehay & Scott Reitan Parkfield Group LLC.
INTERNAL CONTROL OVER FINANCIAL REPORTING
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin 12-1 Chapter Twelve Auditing the Human Resource Management Process.
Audit objectives, Planning The Audit
Chapter 07 Internal Control McGraw-Hill/IrwinCopyright © 2014 by The McGraw-Hill Companies, Inc. All rights reserved.
INTERNAL CONTROL OVER FINANCIAL REPORTING
Chapter 5 Internal Control over Financial Reporting
Considering Internal Control
Internal Control in a Financial Statement Audit
 2004 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, by Bodnar/Hopwood 4 – 1 Transaction Processing and the Internal Control.
Chapter 7 Auditing Internal Control over Financial Reporting McGraw-Hill/Irwin ©2008 The McGraw-Hill Companies, All Rights Reserved.
NO FRAUD LEFT BEHIND The Effect of New Risk Assessment Auditing Standards on Schools Runyon Kersteen Ouellette.
Internal Control in a Financial Statement Audit
9 - 1 ©2003 Prentice Hall Business Publishing, Essentials of Auditing 1/e, Arens/Elder/Beasley Internal Control and Control Risk Chapter 9.
©2003 Prentice Hall Business Publishing, Auditing and Assurance Services 9/e, Arens/Elder/Beasley Internal Control and Control Risk Chapter 10.
Learning Objectives LO5 Illustrate how business risk analysis is used to assess the risk of material misstatement at the financial statement level and.
Evaluation of Internal Control System
Ensuring the Integrity of Financial Information Ensuring the Integrity of Financial Information C H A P T E R 5.
Evaluation of Internal Control System. Learning Objective 1 Contrast management’s need for internal control with the auditor’s need to consider internal.
[Hayes, Dassen, Schilder and Wallage, Principles of Auditing An Introduction to ISAs, edition 2.1] © Pearson Education Limited 2007 Slide 7.1 Internal.
McGraw-Hill/Irwin © 2003 The McGraw-Hill Companies, Inc., All Rights Reserved. 6-1 Chapter 6 CHAPTER 6 INTERNAL CONTROL IN A FINANCIAL STATEMENT AUDIT.
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin 6-1 Chapter Six Internal Control in a Financial Statement Audit.
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin 7-1 Chapter Seven Auditing Internal Control over Financial Reporting.
Auditing Internal Control Studies & Risk Assessment Chapter 9 Internal Control Studies & Risk Assessment Chapter 9.
BA 427 – Assurance and Attestation Services Lecture 21 Tests of Controls.
IS 630 : Accounting Information Systems Auditing Computer-based Information Systems Lecture 10.
McGraw-Hill/Irwin © The McGraw-Hill Companies 2010 Auditing Internal Control over Financial Reporting Chapter Seven.
Pertemuan 15 Business and Information Process Rules, Risks, and Controls Matakuliah: M0034 /Informasi dan Proses Bisnis Tahun: 2005 Versi: 01/05.
Copyright © 2007 Pearson Education Canada 9-1 Chapter 9: Internal Controls and Control Risk.
McGraw-Hill/Irwin © The McGraw-Hill Companies 2010 Auditing the Human Resource Management Process Chapter Twelve.
Chapter 3-Auditing Computer-based Information Systems.
18-1 Copyright © 2016 McGraw-Hill Education. All rights reserved. No reproduction or distribution without the prior written consent of McGraw-Hill Education.
Copyright © 2014 Pearson Education, Inc. Publishing as Prentice Hall. Chapter
McGraw-Hill/Irwin © The McGraw-Hill Companies 2010 Internal Control in a Financial Statement Audit Chapter Six.
Internal Control. McGraw-Hill/Irwin © 2004 The McGraw-Hill Companies, Inc., All Rights Reserved. 7-2 Summary of Internal Control Definition A process...designed.
Chapter 6 Internal Control in a Financial Statement Audit McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
©2005 Prentice Hall Business Publishing, Auditing and Assurance Services 10/e, Arens/Elder/Beasley Internal Control and Control Risk Chapter 10.
Internal Control Chapter 7. McGraw-Hill/Irwin © 2008 The McGraw-Hill Companies, Inc., All Rights Reserved. 7-2 Summary of Internal Control Definition.
AUDIT EVIDENCE AND FINANCIAL STATEMENT ASSERTIONS 1.
Chapter 12 Auditing the Human Resource Management Process McGraw-Hill/Irwin ©2008 The McGraw-Hill Companies, All Rights Reserved.
8 INTERNAL CONTROL. Definition Duty  mgt (CEO)  Board  Internal auditor  Employee  External person.
1 - 1 The Demand for Audit and Other Assurance Services Chapter 1.
ACC 403 Something Great For More Tutorials
The Demand for Audit and Other Assurance Services
Question 4-1 Which of the following statements concerning noncompliance by clients is correct?    A.  An auditor's responsibility to detect noncompliance.
PLANNING, MATERIALITY AND ASSESSING THE RISK OF MISSTATEMENT
The Demand for Audit and Other Assurance Services
Internal Control in a Financial Statement Audit
Defining Internal Control
INTERNAL CONTROLS AND THE ASSESSMENT OF CONTROL RISK
AUDIT TESTS.
Internal Control Internal control is the process designed and affected by owners, management, and other personnel. It is implemented to address business.
Presentation transcript:

Auditing Concepts

The Auditing Process Definition: American Accounting Association (AAA) Auditing is a systematic process of objectively obtaining and evaluating evidence regarding assertions about economic actions and events to ascertain the degree of correspondence between those assertions and established criteria , and communicating the results to interested users.

Explanation of the Definition Systematic process structured as a dynamic activity in a logical manner an unplanned approach to computer auditing may result in by- passing important segments of processing or the related files Obtaining and evaluating evidence reliability of the control structure tests to verify whether the control function is working as prescribed contents of the files substantive testing coherency between files and company transactions Ascertain correspondence between assertion and established criteria Communicating results to interested users other members of audit team , client

Security Audit and general Audit Schema Security Manager External Auditor Security Audit Company Audit - security and privacy - availability - confidentiality - accessibility Accounting system Internal Control System - verification audit approach - controls within IT-system - IT systems audit approach IT-Audit

IT auditing Problems specific for computer auditing : Concentration of the data processing Data consultancy via computer or IT-personnel Data can be erased Data are very much compacted ( can be lost , stolen , ... ) Basic documents disappear ( telephone , EDI , ... ) Automated decisions More complexity More vulnerable ( network ) IT-audit: high degree of specialization , fast evolution

Understanding internal control structure Necessary to plan the audit identify the types of potential misstatements that could occur consider the factors that affect the risk of material misstatements design substantive tests The auditor must understand the three elements of the internal control structure the control environment the accounting system the control procedures

Assessment of Control Risk Purpose The purpose of control risk assessment is to evaluate the effectiveness of an entity’s internal control structure policies in preventing or detecting material misstatements in the financial statements. Control Risk the likelihood that misstatements in accounting data will not be prevented or detected and corrected Control structure those policies and procedures established by the entity to provide reasonable assurance that its established objectives will be achieved

The Control Environment The collective effect of various factors on establishing , enhancing, or mitigating the effectiveness of specific policies and procedures. managers philosophy and operating style entity’s organizational structure functioning BoD and its committees (audit committee) methods of assigning authority and responsibility performance control and internal auditing methods personnel policies and practices various external factors Reflects overall attitude, awareness and actions concerning the importance of control

The Accounting System The accounting system consists of the methods and records established to identify , assemble, analyze, classify , record and report an entity’s transactions and to maintain accountability for the related assets and liabilities. It includes an ability to: identify and record all valid transactions describe the transactions in sufficient detail to permit proper classification of transactions for financial reporting measure the value of transactions in a manner that permits recording their proper monetary value determine the time period in which transactions occurred present properly the transactions and related disclosures in financial statements

The Control Procedures Those policies and procedures that management has established to provide reasonable assurance that specific entity objectives will be achieved. It includes provision for: proper authorization of transactions and activities segregation of duties design of adequate safeguards over access to and use of assets and records independent checks on performance and proper valuation of recorded amounts

Understand the Control Structure In order to obtain an understanding of the control structure , the auditor needs information about: the classes of transactions that are significant how the transactions are initiated the accounting records, supporting documents, machine-readable information and specific accounts involved in the processing and reporting of transactions the accounting processing involved from the initiation of transactions, including how the computer is used to process data the financial reporting process used to prepare the financial statements , including accounting estimates and disclosures

Control Risk Assessment Conclusions If Control structure is weak additional audit effort in control structure area is inappropriate control risk is high significant substantive testing will be necessary If Control structure seems to be strong efficiency of audit might be improved if control risk can be as- sessed at a low level , allowing reliance on the control structure tests of controls might demonstrate that they are functioning properly and substantive testing can be reduced tests of controls might demonstrate that they are not functioning properly and substantive testing cannot be reduced

Effects of IT on Accounting Control Examples of effects: decentralized activities performed by several clerks may be centralized into one computer program, omitting internal control with lack of documentation the audit trail may disappear although the total number of employees increases , there is typically a decrease in human involvement in the actual processing of accounting data invoking the loss of visual checking instead of random errors there are systematic errors specialized knowledge needed to audit effectively the IT-auditor must be involved in the early stages of system design in order to build-in accounting controls problems for the auditor sometimes worse in smaller companies computer fraud ( unauthorized checks or policies, ... )

Audit Trail in an IT System The audit trail are those records that enable a transaction to be traced from its source forward to a summarized total in a financial statement or the other way around. The IT system can affect the audit trail in several ways: source documents filed in a difficult-to-access manner traditional source documents may be eliminated ledger summaries replaced by master files not showing summarized values sometimes no standard transaction listing or journal paper reports only for exceptions always computer and programs needed to read data sequence of data and activities difficult to observe