Wednesday, January 29, 2020
Evaluating Internal Controls Essay Example for Free
Evaluating Internal Controls Essay An organizationââ¬â¢s internal controls are comprised of five components, which include: the control environment, risk assessment, control activities, monitoring, and information and communication. The five components of internal control are considered to be criteria for evaluating an organizationââ¬â¢s financial reporting controls and the bases for auditorsââ¬â¢ assessment of control risk as it relates to an organizationââ¬â¢s financial statements (Lowers, et. al., 2007). ââ¬Å"Thus, auditors must consider the five components in terms of (1) understanding a clientââ¬â¢s financial reporting controls and documenting that understanding, (2) preliminarily assessing the control risk, and (3) testing the controls, reassessing control risk, and using that assessment to plan the remainder of the audit workâ⬠(Lowers, et. al., 2007, p. 161). Phase I ââ¬â Understanding Throughout the course of Phase I an audit team will work to obtain a clear understanding of a companyââ¬â¢s internal control environment and managementââ¬â¢s risk assessment. The audit team will review the flow of transactions through the companyââ¬â¢s accounting system, and the design of some client controlà procedures (Lowers, et.al., 2007). In this step the audit team will perform their assessments in a top-down risk-based manner that first examines company-level controls (CLCs) and then controls of significant business units within the company (Lowers, et.al., 2007). Controls within the control environment and companywide programs include: â⬠¢ Managementââ¬â¢s risk assessment â⬠¢ Centralized processing and controls including shared service environments â⬠¢ Period-end financial reporting process â⬠¢ Controls to monitor results of operations â⬠¢ Controls to monitor other controls â⬠¢ Board-approved policies that address significant business control and risk management practices (Lowers, et. al., 2007, p. 161). Once the audit team has completed their examination of CLCs the audit team will then document their understanding through the use of narrative descriptions or flowcharts. The audit team will then use one of those tools to design a preliminary program of substantive procedures for auditing assertions related to the companyââ¬â¢s account balances, which is conducted in Phase II (Lowers, et. al., 2007). Phase II ââ¬â Assessment After the audit team has completed Phase I the audit team will move into Phase II or the preliminary assessment of the companyââ¬â¢s control risks. Throughout the course of Phase II the audit team will analyze the control strengths and weaknesses of the company. A companyââ¬â¢s strengths are considered as specific features of good general and application controls while its weaknesses are considered as a lack of controls in particular areas (Lowers, et. al., 2007). The audit teamââ¬â¢s findings and preliminary conclusions should then be written up and documented in audit files known as the bridge workpapers. In Phase II the audit team will seek to answer the following questions through its assessment. Can control risk be low or less than maximum? Is reduction of the control risk assessment cost-effective? Once the audit team arrives at the answers of those questions it will then specify the controls to be tested and the degree of compliance required. ââ¬Å"The distinction between the understanding and documenting phase and the preliminary control risk assessment phase is useful for understanding theà audit work. However, most auditors in practice do the two together, not as separate and distinct audit tasksâ⬠(Lowers, et. al., 2007). Phase III ââ¬â Testing In the third and final phase the audit team will then perform tests of controls of the specified controls and reassess control risk. During the testing phase the audit team will seek to answer the question of how the actual degree of company compliance compares with the required degree of compliance with the companyââ¬â¢s control policies and procedures. The audit team will then document the basis for assessing the companyââ¬â¢s control risks, which are less than 100% or assess the companyââ¬â¢s high or maximum control risk and design an audit program for the company with more effective substantive procedures. The audit team will then perform a test on the planned or revised substantive procedures. Conclusion An effective evaluation of a companyââ¬â¢s internal controls will provide the company with a reasonable assurance regarding the achievement of its objectives in the following three categories: reliability of financial reporting; effectiveness and efficiency of its operations; and compliance with applicable laws and regulations. References Lowers, T.J., Ramsay, R.J., Sinason, D. H., Strawser, J.R. (2007). Internal Control and Evaluation. Auditing and Assurance Services. 2nd ed. The McGraw-Hill Companies. New York City, NY.
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.