Tests of Controls
Tests of Controls
Risk Assessment
CHAPTER ELEVEN
UNDERSTANDING OF INTERNAL
CONTORL AND CONTROL
RISK ASSESSMENT
ICAP'S STUDY TEXT
LO # LEARNING OBJCTIVE
REFERENCE*
UNDERSTANDING AND TESTING OF INTERNAL
PART A CONTROLS
LO 1 DEFINITION AND LIMITATIONS OF INTERNAL
CONTROL 5.1.2, 5.3.1
5.2.1, 5.2.3,
LO 2 OBTAINING UNDERSTANDING OF INTERNAL 5.2.4,
CONTROL 5.2.5, 5.2.6, 5.2.9
LO 3 7.2.1, 7.2.2, 7.2.3,
CONTROLS OVER THE SALES SYSTEM 7.2.4
LO 4 7.3.1, 7.3.2, 7.3.3,
CONTROLS OVER THE PURCHASES SYSTEM 7.3.4
LO 5 7.4.1, 7.4.2, 7.4.3,
CONTROLS OVER THE PAYROLL SYSTEM 7.4.4, 7.4.5, 7.4.6
LO 6
CONTROLS OVER BANK AND CASH SYSTEM 7.5.1, 7.5.2, 7.5.3
CONTROLS OVER INVENTORY AND NON-
LO 7 CURRENT
7.6.1, 7.6.2
ASSETS SYSTEM
PART B DOCUMENTATION OF UNDERSTANDING OF ENTITY AND INTERNAL
CONTROL
LO 8
METHODS OF DOCUMENTATION OF A SYSTEM 6.1.1, 6.1.2, 6.1.3
LO 9
DIFFERENCE BETWEEN ICQ AND ICEQ 6.1.3
LO 10 CHECKING THE ACCURACY OF PREVIOUS
YEARS ICQ 6.1.3
PART C ADDITIONAL CONCEPTS
LO 11
MANAGEMENT LETTER AND ITS CONTENTS 5.4.3
LO 12
AUDIT CORRESPONDENCE N/A
*Explan
at on of Ref rence:
First digit in Study Texts Reference represents chapter number, second and third
digits represents
section and sub- section number. Contents in brackets (if any) represent part of the
sub-section
2
Auditing Study Notes Chapter 11 Understanding of Controls and Control
Risk Assessment
:
ntrolof entity. This understanding shall cover following elements:
Control Environment:
Auditor shall
evaluate whether entity has a strong control environment.
Control environment includes attitude, awareness and actions of TCWG and
management regarding
entitys internal control and its importance in the entity.
Inevaluating the control environment, auditor considers the following matters:
Audit committee and board of directors have significant influence in the
organization and
actively participate in business.
Management actions and attitudes show character, integrity, and ethics.
toFinancial Statements:
means processes bywhich entity obtains, process and records transactions
Auditor should consider following aspects of information system:
Briefly explain the components of internal control as referred to in the International Standards on
Auditing. (09 marks)
OBJECTIVES, ACTIVITIES
ofdutiesbetween Sales
prepare GRN), Invoicing Department (to prepare invoice) and Accounts Department (to post invoices
into Sales Journal & Ledgers).
Order Department
Control
Objectives Control Activities Tests of Controls
set rate list and discount policy for authorized rate list approved by
every appropriate
Orders are approved product. authority (e.g. CFO/BOD).
on the basis of Order department should approve
authorized Rates and sales with authorized rate list and discounts.
Discounts. order only at authorized rates and -Use "Test Data" to check that an order at
unauthorized rate or discount is rejected
discounts. (if IT
system is used).
5
Auditing Study Notes Chapter 11 Understanding of Controls and Control
Risk Assessment
Despatch
Department
Control
Control Objectives Activities Tests of Controls
Invoicing/Billing Department
Control
Control Objectives Activities Tests of Controls
and authorized Sales Order (to be used whether it includes reference to relevant
in GDN
Invoice preparing sales
s are correctly invoices) and authorized Sales Order.
prepare
d (using
correct quantity,
price independent person.
and -Alternatively, there should be strong and inspect evidence for rechecking of
discount) IT accuracy.
-Auditor should test controls over IT
controls over accuracy of invoices, if IT system to
ensure accuracy of invoices, if IT system is
system is used. used.
6
Auditing Study Notes Chapter 11 Understanding of Controls and Control
Risk Assessment
Accounting Department
credit-Sales
of source documents should be and inspect whether Transaction Counts
invoicesnotes) (andare compared and
correctl Control Totals of source documents have
y and with recorded transactions. been
completely recorded
in performed on recorded transactions.
Sales Journal. monthly and exceptions are followed customers and inspect evidence of
-Sales invoices (and up. its
credit notes) are preparation, review and follow-up of exceptions.
correctl poste -Debtors' Control Account and Sales between Debtors' Control Account and
y d in Ledger Sales
relevan Ledger; and inspect evidence of its
t customers' are reconciled monthly. preparation,
account
. review and follow-up of exceptions.
promptl in books of and posted in accounts daily. Daybook and compare date of recording
y
State internal control procedures in respect of the following with
account date of GDN.
s.
functions: - Dispatches and invoice preparation for sales
CONCEPT
describe tothe
REVIEW QUESTION
management about the necessary internal control that should be in place to strengthen the sales
system of the company over the receipt, processing and recording of orders. (07 marks)
(ICMAP - 2015
August)
(05
marks) (CA Inter
-Autumn 2004)
Accounts Department.
Order Department
ensure that
-Company should have standard inspect documentation standard
operating procedures to approve operating procedures
a to approve a supplier
supplier and should maintain a list
of operate as intended.
ar approved suppliers. Access rights to controls over master file of
Orders e given to this -Test approved
list should be restricted (in IT suppliers
approved suppliers system). .
-Select a sample of purchase orders,
only. -Purchase Orders should include inspect
"approved supplier reference approved reference number and compare
number" to with
ensure that orders are given only
to list of approved suppliers.
suppliers on approved -Use test data to check orders to
list. unauthorized
suppliers are rejected (in IT
system)
Receiving Department
Control
Objectives Control Activities Tests of Controls
prepared for every receipt of goods; GRNs. Any break (identified by auditor
and or
matche sequentiall produced by system) should be
against all purchase are d with y investigated to
orders prenumbered Purchase Orders. explain reason.
Invoicing/Billing
Department
Control
Objectives Control Activities Tests of Controls
processed only if with sequentially prenumbered GRN for evidence that they are matched with
goods and relevant
are received from purchase GRN and Purchase
them. orders. Orders.
For purchases returns, which should Sele sample of credit notes and inspect
goods returned to be ct for
sequentially prenumbered and numeric sequence, and cross reference
suppliers, credit must matched al to
be suppliers' credit
taken. with suppliers' credit note when it is note.
received.
8
Auditing Study Chapter 11 Understanding of Controls and Control Risk
Notes Assessment
Accounts Department
Control
Objectives Control Activities Tests of Controls
(b) Controls that you expect to see to address the above risks (10 marks)
(c) Audit procedures that you need to perform to test the controls (CA Inter -Spring 2015)
Your senior has asked you to carry out an internal control review of the purchasing department of a
manufacturing
company. What control procedures would you expect in the following functions of the
department: (05 marks)
a) Ordering of goods (05 marks)
b) Receipts of goods (05 marks)
State FOUR objectives of the internal controls that should be exercised over the purchases and trade
payables system of
Control
Objectives Control Activities Tests of Controls
-New resigned should check
Payroll is calculated only for real employees. (i.e. no employeesdocum
employees. (i.e. no
overtime if monitored so that a worker cannot clock-in
employees maintained and monitored. for
did not work) multiple workers.
and inspect that they are properly
calculated and
approved by appropriate authority. authorized.
use Authorized Time Sheet and inspect that hours worked and rates of
Approved pay are in
accordance with Time-sheet and approved
Rates of Pay. rates.
payroll expense is not excessive, and signature/initial of appropriate authority
Payroll should be should as
calculated correctly. approve payroll sheet. evidence of approval of payroll.
generated for wages beyond pre-set
limits.
should be produced for wages beyond -Inspect exception reports (of salaries &
pre- wages
set limits, and it should be followed up beyond pre-set limits) as evidence
by of
an independent person. preparation and follow-up.
be ed -Voluntary (e.g. pension contributions)
-Statutoryfrompay
calc Calculation
correctly of tax and
deduction other
should deductions
be authorized by
ulat . s from pay employee.
deductions (e.g.Tax) should
Control Objectives Control Activities Tests of Controls
ensure that tax deduction is correctly
-Payroll procedures should provide made.
deduction of tax using up-to-date -Use Test- data for calculation of tax and
rates of compare
results with independently calculated
tax. amount (if
IT system is used).
authorized by employee in writing; written consent of employee
and this regarding
consent should be kept in file of
employee. voluntary deductions and their amounts.
of total deductions is reasonable, signature/initial of authority
and appropriate as
evidence of approval of
should approve it. deductions.
10
Auditing Study Notes Chapter 11 Understanding of Controls and Control
Risk Assessment
Control Tests of
Objectives Control Activities Controls
between person who prepares payroll duties exist between the person who
Wages are paid only and prepares
to person who distributes payroll. payroll and person who distributes payroll.
whether identification of employee if
genuine employee. confirmed
of employee before making payment. before making payment.
properly and
accurately recorded in
strict deadline. timescale.
payroll has been used to record wages
the accounts. in
record wages in accounts. accounts.
(07
marks) (CA Inter -
Autumn 2015)
CONCEPT
You have been assigned to plan the test of controls in (05
REVIEW QUESTION marks) (CAT -
respect of salariesand wages. In this regard you are required to June 2008)
identify the following:
(04 marks)
(a) Possible control weaknesses in overtime payments (ICMAP - 2014
(b) Principal controls over payment of overtime May )
State FIVE objectives of the internal controls that should be exercised over a wages
system.
Discuss any four (04) audit procedures for M/s. Farooq Enterprise for the test of
control of Payroll.
11
Auditing Study Notes Chapter 11 Understanding of Controls and Control
Risk Assessment
Cash Receiving
Control
Control Objectives Activities Tests of Controls
mail.
-There should be segregation of
duties
Receiving Recordin
between , g and
Reconciliatio
n functions.
-Only a restricted number of -Observe whether segregation of duties
employees exist
should be receiv between receiving, recording and
authorised to e cash. reconciliation.
-Cash should be kept in locked-boxes -Observe whether authority to receive
and in cash is
are
secured a until it is deposited. limited.
sequential prenumbere -Check whether cash is kept in locked
All money received is -Till- Roll (or ly d boxes in
cash- should be used to
recorded. receipts) record secured area.
cash sales; and a copy should be -Check for evidence that till roll totals (or
retained. cash-
-At day end, till roll totals (or cash- receipts totals) are checked against
receipts cash
totals) should be balanced with received by an independent
cash person.
received an independent
, by person.
-Surprise cash counts are conducted
by
persons independent of custodian of cash.
Cont rols ov er Cash r eceived through
donation
(e .g. in ):
-Boxes should be numerically
sequenced.
-Boxes should be appropriately sealed -Inspect a sample of boxes for
so numerical
that opening prior to recording is
apparent. sequence and appropriate sealing.
-There should be process for -Observe the process of collection,
regular opening box
collectio an recording boxe and
n d of cash s. recording.
-Process of opening boxes should
be
monitore
d.
12
Auditing Study Notes Chapter 11 Understanding of Controls and Control
Risk Assessment
Cash Payments
Control
Objectives Control Activities Tests of Controls
for
ures
should
-Select a sample of
be paid cheques and
All payments should be properly authorised, made to
required
cheque inspect:
the correct person and are properly recorded bemade (a) supporting
documents are
available and
backedt signing
forcheques
(usu
(b) supporting
hrough documents are duly
cancelled.
ally two
crossby above a certain (c) signatories
are
cheques amount) authorized.
(d) entry into
upportin
oncepaym
bank statements
ent)cheque
. is
prepared
(to avoid and creditors'
duplicate
levels
signat
account.
List six key controls over cash sales and cash handling. (CA Inter - Spring 2016) (1 0 mar ks)
Describe and explain the purpose of the internal controls you might expect to see in the sales system at
audit client over
the collection of cash. F8 (ACCA - December 2002)
Discuss any four (04) audit procedures for M/s. Farooq Enterprise for the test of control of Cash
payment.
(04
marks)
(ICMAP - 2014
May)
INVENTORY
stock count.
14
Auditing Study Notes Chapter 11 Understanding of Controls and Control
Risk Assessment
m inventory
balancesmaximu
There
Appropriate levels of inventory should be held at
levels for all mare below
minimum level or
all times.
should
recorded properl
disposalin accounting y
NON-CURRENT
current system. capitalexpenditures
or 15
ASSETS
properl revenue.
should
y expenditure be properly
and correctly All s are recorded.
Control ObjectivesAll
Auditing Study Notes Chapter 11 Understanding of Controls and Control
Risk Assessment
(04 marks)
State FOUR objectives of the internal controls that should be exercised over non-
current assets. (CAT - June 2005) (1 0 mar ks)
List and explain the reason for the audit procedures used in obtaining evidence in relation to the
inventory count of
List the internal controls that a small printing company with office equipment, motor vehicles and plant
and machinery
F8 (ACCA - June
should have in place to achieve the objectives described above. 2003)
In
Exam Tips
exam1.Stateifconceptcontrolreviewobjectivesquestionforwholeisset systemfrom Controls,orforaspecificyoumaydepartmentberequire
d. to:
they would detail what occurs asses existenc is processed in different steps.
in s about e Lines
the system at each stage effectivenes usually demonstrate the sequence
and and s of of
would include any controls control events and standard symbols are
which s. used to
operate at each stage. signify controls or documents.
discussions with client are quick to
easily prepare. presented together in one diagram.
Due to the use of standard
Advantages written up as notes.
easily understandab le for al l
As they emphasize on symbols for
contro ls; hence missing contro ls, they are easy to spot as a re any
16
Auditing Study Chapter 11 Understanding of Controls and Control Risk
Notes Assessment
too lengthy and time to overstate the level amend, as any amendments may
consuming. of require
This method can make it
more the controls. the whole flowchart to be redrawn.
Disadvantages difficult
interna l cont rols as the notes
to
identify missing A standard list of questions may miss out
There is still the need for narrative
notes to accompany the flowchart and
effectiveness of controls.
assessment procedures (after of controls (after obtaining
obtaining understanding of
understanding of entity). entity and its Internal Control)
CONCEPT REVIEW QUESTION
(1) State THREE methods by which your firm mayrecord theinternal control
system of Palm Co.
(2)Explain how an Internal Control Questionnaire (ICQ) differs in nature and design from an Internal
(03 marks)
Control Evaluation Questionnaire (ICEQ). (06 marks)
(CAT - June 2007)
client:
this to identify any changes since last year.
3. quire :
Interview client staff to ascertain whether systems have changed this
year and to ensure that the internal control questionnaires produced last year
are correct and relevant.
17
Auditing Study Notes Chapter 11 Understanding of Controls and Control
Risk Assessment
Peform walk -through tests.
4.
During walk -through checks, ensure that the controls
documented in the system notes are actually working, for example, verifying that documents
are signed as indicated in the notes.
Explain the steps necessary to check the accuracy of the previous years internal control
questionnaires.
CONCEPT REVIEW QUESTION
(04
marks)
F8 (ACCA - June
2008)
Management Letter to its board of directors within 45 days of the da te of audit report. However,
What is a Management Letter? What is the most appropriate time for issuing a Management Letter?
(05
marks)
(CA Inter -Autumn
2000)
18
Auditing Study Notes Chapter 11 Understanding of Controls and Control Risk
Assessment
CONCEPT REVIEW
QUESTION (03
(ICAP CA Inte r, Autumn 20 02 )
marks)
State the difference between an Engagement Letter and a Professional
Clearance Letter.
19