Problem 10-21 Friggle Corp. is a leasing and property management company located in Alberta. It provides financing to organizations wishing to purchase.

Slides:



Advertisements
Similar presentations
OPERATING EFFECTIVELY AT WESD. What is Internal Control? A process designed to provide reasonable assurance the organizations objectives are achieved.
Advertisements

Red Flag Rules: What they are? & What you need to do
Bodnar/Hopwood AIS 7th Ed1 Chapter 5 u TRANSACTION PROCESSING AND INTERNAL CONTROL PROCESS.
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
Auditing Computer Systems
The Islamic University of Gaza
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
Chapter 4 IDENTIFYING RISKS AND CONTROLS IN BUSINESS PROCESSES
1 SYS366 Week 1 - Lecture 2 How Businesses Work. 2 Today How Businesses Work What is a System Types of Systems The Role of the Systems Analyst The Programmer/Analyst.
Presentation to CAREGROUP Board of Directors Governing Your Networked IT Organization Ken Peffers Applicable IT Research, Inc. November 21, 2002.
Chapter 4-1 The Islamic University of Gaza Accounting Information System The Expenditure Cycle : Purchases and Cash Disbursements Procedures Dr. Hisham.
Chapter 4 IDENTIFYING RISKS AND CONTROLS IN BUSINESS PROCESSES.
Auditing Auditing & Automated Systems Chapter 22 Auditing & Automated Systems Chapter 22.
Corporate Governance and Entity-Level Controls. Escalating Role of Board Members Corporate Fraud Qualifications of directors and management Governance-2.
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin 12-1 Chapter Twelve Auditing the Human Resource Management Process.
 What are some of the important benefits that Mountain View Community Hospital should seek in using databases? As much as possible, relate your response.
Chapter 13 Prepared by Richard J. Campbell Copyright 2011, Wiley and Sons Auditing Human Resources Processes: Personnel and Payroll in Service Industries.
Chapter 10 Cash and Financial Investments McGraw-Hill/Irwin
Solution Overview for NIPDEC- CDAP July 15, 2005.
Chapter 17: Computer Audits ACCT620 Internal Accounting Otto Chang Professor of Accounting.
University of Idaho Business 378 – Project Management Yoshi Pitkin.
Systems Development Life Cycle Dirt Sport Custom.
McGraw-Hill/Irwin © 2003 The McGraw-Hill Companies, Inc., All Rights Reserved
SANILAB THE LOGICAL INDUSTRY CHOICE. SANILAB Industry edition Risk management is costly and stressing for production, quality and any other people of.
Question 23 As an accountant of an organization, discuss why it might be necessary to initiate systems analysis. {6 marks} Giving reasons for your answer,
Copyright © 2007 Pearson Education Canada 1 Chapter 13: Audit of the Sales and Collection Cycle: Tests of Controls.
To start a new business, buy an existing business, or buy a Franchise
 Sana Riaz  Registration No  Saira Khalid  Registration No
Plan Design Analyze Develop Test Implement Maintain Systems Development Life Cycle MAT Dirtbikes.
Evaluation of Internal Control System
Fraud and Abuse Don Pursley, Col Ret. USAFA, BSE, MS, DBA The speaker does not have any relevant financial relationships with any commercial interests.
Internal Controls and Fraud Convery Describe an Internal Controls System and its elements Identify specific Internal Control issues in a NPO Consider.
ZHRC/HTI Financial Management Training Session 9: Stores and Supplies Management.
Information Security Governance and Risk Chapter 2 Part 3 Pages 100 to 141.
Ensuring the Integrity of Financial Information Ensuring the Integrity of Financial Information C H A P T E R 5.
Copyright © 2007 Pearson Education Canada 1 Chapter 24: Assurance Services: Internal Auditing and Government Auditing.
Copyright © 2007 Pearson Education Canada 5-1 Chapter 5: Audit Responsibilities and Objectives.
Business Functions, Processes, and Data Requirements
HIPAA LAWS.  Under the privacy rule, the patient must give consent to use his or her Protected Health Information.  Examples in which consent must be.
McGraw-Hill/Irwin © 2003 The McGraw-Hill Companies, Inc., All Rights Reserved. 6-1 Chapter 6 CHAPTER 6 INTERNAL CONTROL IN A FINANCIAL STATEMENT AUDIT.
Copyright © 2007 Pearson Education Canada 7-1 Chapter 7: Audit Planning and Documentation.
APA – Fundamentals of Payroll Chapter 2 – Payroll Systems March 10, 2012.
Implementing EHR in Home Health Care Component 11/Unit 9d An example on the Implementation of a Point of Care System.
Hall, Accounting Information Systems, 7e ©2011 Cengage Learning. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly.
Unit 7 Seminar.  According to Sanderson (2009), the problems with the current paper-based health record system have been well documented. The author.
Copyright © 2007 Pearson Education Canada 23-1 Chapter 23: Using Advanced Skills.
TAXCO BUSINESS SERVICES INC. Division of Des-Dawn Corporation BOOKKEEPING | PAYROLL | TAX FILING | TAX PLANNING | CONSULTING INTRODUCING TAXCO BILL PAY.
1 A Seminar On Pharmaceutical Outsourcing A Seminar On Pharmaceutical Outsourcing.
Copyright © 2007 Pearson Education Canada 9-1 Chapter 9: Internal Controls and Control Risk.
McGraw-Hill/Irwin © The McGraw-Hill Companies 2010 Auditing the Human Resource Management Process Chapter Twelve.
Security Issues and Ethics in Education Chapter 8 Brooke Blanscet, Morgan Chatman, Lynsey Turner, Bryan Howerton.
Cash Reconciliations and Cash Handling WASBO Accounting Conference March, 2016.
ADMINISTRATIVE AND CLINICAL HEALTH INFORMATION. Information System - can be define as the use of computer hardware and software to process data into information.
Lecture 5 Control and AIS Copyright © 2012 Pearson Education 7-1.
Chapter 12 Auditing the Human Resource Management Process McGraw-Hill/Irwin ©2008 The McGraw-Hill Companies, All Rights Reserved.
Auditing Concepts.
Accounts Receivable, Accounts Payable & Cash
Chapter 9 Non-Cash Assets.
General Ledger, Financial Reporting and Management Reporting Systems
Controlling Computer-Based Information Systems, Part II
Why did you choose us? To address and provide a solution to the many problems associated with your current manual filing system -Problems include: -Lack.
Health Supply Chain Management: Session 6: Facilities, Staffing and Procurement Ghana Nursing Schools.
Chapter 9 Non-Cash Assets.
Defining Internal Control
Problem DC 10-2, Page 547 What is K? The confidence factor
Purchases and Cash Disbursements Procedures
Internal controls 01-Nov-2017.
Chapter 21 Accounting Practices.
Database management systems
Presentation transcript:

Problem Friggle Corp. is a leasing and property management company located in Alberta. It provides financing to organizations wishing to purchase equipment or property and manages apartments and condominium properties. The company decided that it was time to upgrade its local area network. It decided to also purchase new accounting software but wanted to retain its old unit maintenance software, which, although 10 years old, had an easy-to-use interface that allowed maintenance personnel to track the maintenance work that they did in each unit. The controller, Joe, decided that the company should purchase the software from Midland Computers, which was owned by his brother-in-law, Tom. The prices were comparable with those of other computer networks that he priced, and Midland happened to be close by. Using materials from industry magazines, Joe decided that the best property management software to buy would be from Quebec; the software had received rave reviews about being easy to use. The implementation was scheduled for the weekend after the June month-end close so that systems could be up and running by the following Monday. To Joe’s horror, when he arrived at work on Monday, computers were still being unpacked and installed. Tom had difficulty following the installation instructions for the accounting software, which was not up and running until the end of the week. General ledger details had to be manually entered, since the software could not handle the structure of the old accounts. At the end of two weeks, Joe had the old system put back up so that Friggle could catch up on transactions and get some work out the door. It took three months of 12-hour days for all accounting staff to get the new system operational. Unfortunately, the old maintenance systems would not work with the new operating system, and a new maintenance system had to be evaluated and purchased. Required Assess the IT governance at Friggle Corp. For weaknesses that you identify, provide recommendations for improvement. Governance Solutions-1

Solution to There appears to be no information technology governance at all (assessed as “low”) for Friggle Corp. Following are specific weaknesses, with recommendations for improvement in brackets: 1.The controller was able to have a network installed by a relative, a clear conflict of interest. –All new acquisitions should be approved by an executive committee, and required independent tenders. 2.Software was purchased without a clear understanding of the organization’s needs –Any software should be purchased only after documenting the organization’s needs and matching the needs to the software 3.The old system could not function with the new operating system, so it could not be used –technical issues should be independently verified before purchasing new software 4.Software purchases and information systems acquisitions were not linked to the business strategy of the organization –develop an information systems strategy that is linked to the business strategy of the organization Governance Solutions-2

Problem Turner Valley Hospital plans to install a database management system, Hosp Info, that will maintain patient histories, including tests performed and their results, vital statistics, and medical diagnoses. The system will also manage personnel and payroll, medical and non-medical supplies, and patient and provincial health-care billings. The decision was taken by the board of the hospital on the advice of a consultant who was a former employee of Medical Data Services Inc., the developer of Hosp Info. Turner Valley Hospital’s chief information officer has come to your accounting firm to ask for advice on what general controls she should ask Medical Data Services Inc. to install to preserve the integrity of the information in the system and to deal with privacy issues. The system would permit data about patients to be entered by doctors, nurses, and medical technologists. Required a)Describe in general terms the controls you would suggest for the system as a whole. b)Considering the nature of Turner Valley Hospital, describe the potential risks the hospital should be concerned about with respect to Hosp Info. c)What are the advantages of such a database management system? d)How would the quality of general controls at the hospital affect your audit? Governance Solutions-3

Solution to Problem a.Following is a representative example of controls that could be put in place: –access to information such as payroll, medical records and medical data, personnel records, supplies  especially medical, accounts receivable, and accounts payable  limited by multiple and/or single passwords or access codes –each department with a password or access code and each person who has access to restricted files with their own password or code –the computer program automatically recording who accessed the file and when –access codes or passwords ceasing on termination of employment –access codes or passwords periodically changed –inability to alter or delete patient medical information without proper authorization, once it is entered and saved –programming that accepts only valid healthcare numbers –healthcare numbers that are used more than a certain number of times flagged and brought to someone’s attention –daily back-ups of all data –back-ups stored off site –segregation of duties, staff who enter data different from those who receive or issue payments –virus detection software –number all receivable and payable transactions, the system must identify missing or duplicated numbers Governance Solutions-4

b. Following is a representative example of risks: –contamination of confidential files from unauthorized access –viruses destroying or altering files –theft of supplies, especially medicine, due to altered or contaminated data files –unauthorized access to confidential patient medical information or accidental altering of information –fraudulent or expired healthcare numbers being used, which would result in incurred expenses with no financial compensation –fraudulent cheques being issued through the payroll system c.Advantages include: –information quickly and easily accessible to authorized personnel –large amounts of data kept organized and functional –paperless data storage and retrieval –efficient billing system that would result in speedier revenue collection –if the internal controls are adequate, decreased losses through theft or error –decreased costs to collect and maintain accurate information – d.If the quality of general controls are good, then the auditor may also be able to rely upon a number of controls that improve the quality of data and potentially the quality of the application controls. Examples of good general controls that would promote a lower control risk include: segregation of duties in information technology, well organized and documented systems development and maintenance process and access being enforced using well-organized password systems. Governance Solutions-5