BT Kiem Toan
BT Kiem Toan
ID: 31221021691
Fundamental of Auditing - Exercise Topic 2-3 – Ethics & Internal Controls
Required: Indicate which of the five COSO internal control components is best represented by each
internal control. (Control environment, Risk assessment, Control activities, Information and
communication, and Monitoring)
1. The company’s computer systems track individual transactions and automatically accumulate
transactions to create a trial balance.
Information and communication
2. On a monthly basis, department heads compare a budget to actual performance report and investigate
unusual differences.
Control activities
3. The company must receive university transcripts documenting all college degrees earned before an
individual can begin his or her first day of employment with the company.
Control environment
4. Senior management obtains data about external events that might affect the entity and evaluates the
impact of that information on its existing accounting processes.
Risk assessment
5. Each quarter, department managers are required to perform a self-assessment of the department’s
compliance with company policies. Reports summarizing the results are to be submitted to the senior
executive overseeing that department.
Monitoring
6. Before a cash disbursement can be processed, all payee information must be verified by matching the
payee to the company’s approved vendor listing.
Control activities
7. The system automatically reconciles the detailed accounts receivable subsidiary ledger to the accounts
receivable general ledger account on a daily basis.
Information and communication
8. The company has developed a detailed series of accounting policy and procedures manuals to help
provide detailed instructions to employees about how controls are to be performed.
Control activities
9. The company has an organizational chart that establishes the formal lines of reporting and authorization
protocols.
Control environment
10. The compensation committee reviews compensation plans for senior executives to determine if those
plans create unintended pressures that might lead to distorted financial statements.
Risk assessment
BT 7.16
- Making note that "order received" without adding any information about the quantity and condition of the
goods. This may result in missing or damaged goods.
Therefore, the receiving department needs to carefully count and check the received goods.
- Simply checking for purchase requisitions, orders and receiving reports for each purchase without
checking other details can lead to incorrect payment execution.
The accounts payable department must check that there is a match between the date, description, amount,
price and reference number, then approve the payment.
- There is a lack of segregation of duties in that the financial accountant has cash payments duties and
performs the bank reconciliation. Therefore, the financial accountant may be able to misappropriate funds
without being discovered.
Therefore, the bank reconciliation should be performed by someone independent of payments and
receipts functions to provide a cross-check on these functions.
Group discussions:
1. Please differentiate Test of control (TOC) and Control activities. Give examples.
Test of control Control activities
Purpose Evaluate the effectiveness of Preventive and detective
control activities controls, reduce the risk of
management
When CR is assessed at less than a high If the management chooses to
Substantive procedures alone is accept or avoid the risk based on
not sufficient risk assessment
How If an audit trail does exist: Encompass a range of manual
- Inspect documentation and automated activities:
associated with the - Segregation of duties
transaction for evidence - Authorization and
of the control approvals
When no audit trail exists - Verification
- Verified - Physical control
- Observation - Control data
- Inquiry of the control - Reconciliations
- Re-performance - Supervisory
Objects Control activities Risk
Example Look for evidence of new orders All purchase orders for inventory
being rejected if they would and supplies must be approved
breach the credit limit. This by a designated manager before
could be tested by inspecting they are submitted to suppliers.
copies of notifications sent to This ensures that the company
customers. The auditor might only orders necessary items and
also consider using test data prevents unauthorized or
to observe if an order exceeding unnecessary purchases.
the credit limit is actually
rejected.
1
2. Please differentiate Test of control (TOC) and Sustantive Test. Give example.
Test of control Substantive test
Components Is the testing tool for Is the control mechanism of
assessing control risk controlling detection risk
Step It is the second step in audit It is the third step in audit
testing testing
Types Can be classified 2 types: Can be classified 3 types
concurrent test and planned
test of control
Basic TOC is the police end It is done on the basic of
procedures monetary error
Determination Effectiveness and efficiency Fairness of FS
of internal control
Timing TOC are done on interim date The Substantive test is done
on the balance sheet date
Example The auditor just documents Watch the physical inventory
about purchasing system of count as it happens for each
the client as the purchase is ending period.
part of the significant process
in the operating expenses,
inventories as well as fixed
assets sections.