Internal Control and Systems Evaluation
Planning
Internal Control and Systems Evaluation
Syllabus tag: KASNEB CPA | Intermediate Level | CA24 Auditing and Assurance | Topic 5 Internal Control and Systems Evaluation
Lesson objectives
By the end of this topic, you will be able to:
- Identify the five components of internal control
- Recognise common control activities and what each prevents
- Distinguish tests of control from substantive procedures
- Explain the inherent limitations of any control system
- Report deficiencies appropriately
Why this matters
Where controls work, the auditor can do less substantive testing. Where they do not, everything must be tested directly. Evaluating the system therefore decides the shape and cost of the whole audit.
The five components
C-R-I-M-E is the standard aid:
- Control environment — the tone at the top: integrity, ethical values, competence, and the attention of those charged with governance
- Risk assessment process — how the entity identifies and responds to business risks
- Information system — the accounting system and how transactions are recorded and reported
- Monitoring of controls — how the entity checks its controls still work, including internal audit
- Existing control activities — the specific procedures themselves
The control environment comes first for a reason. Detailed controls designed by a management that has no interest in enforcing them will not operate. Where the environment is weak, the auditor should be sceptical of every control below it.
Common control activities
| Activity | Prevents |
|---|---|
| Segregation of duties | One person authorising, recording and holding an asset |
| Authorisation limits | Transactions committed beyond delegated authority |
| Physical controls | Theft of cash, inventory and records |
| Reconciliations | Errors and omissions going undetected |
| Arithmetic and accounting checks | Recording errors |
| Supervision and review | Poor work passing unnoticed |
| Information processing controls | Invalid or incomplete data entry |
Segregation of duties is the single most examined control. The three functions that must be separated are authorising a transaction, recording it, and holding custody of the related asset. One person holding two of the three creates the opportunity for fraud to be concealed.
In a small entity segregation is often impossible, and the answer is not to pretend otherwise. Compensating controls — close owner involvement, review of bank statements by the proprietor — become the relevant control, and the auditor is likely to rely more on substantive testing.
Tests of control and substantive procedures
| Tests of control | Substantive procedures | |
|---|---|---|
| Tests | Whether the control operated | Whether the figure is right |
| Example | Inspect invoices for evidence of authorisation | Confirm the balance with the customer |
| Result if it fails | Increase substantive testing | The figure may be misstated |
The relationship matters. A test of control that fails does not itself prove the accounts are wrong. It tells the auditor the control cannot be relied on, so more direct testing is needed.
Substantive procedures can never be dispensed with entirely. However strong the controls, ISA requires substantive procedures for each material class of transactions, balance and disclosure. Controls reduce the extent of substantive work; they do not remove it.
:::checkpoint An auditor tests fifty purchase orders and finds four lacking the required authorisation signature. State what the auditor concludes, and what changes in the remainder of the audit. :::
Inherent limitations
No system, however well designed, gives more than reasonable assurance. Every system is limited by:
- Human error — mistakes, misunderstanding, fatigue
- Collusion — two or more people defeating segregation of duties together
- Management override — the people who designed the controls can set them aside
- Cost versus benefit — controls are not implemented where they cost more than the risk
- Non-routine transactions — controls are designed for the usual, and unusual transactions escape them
Management override is the most serious, because it is the one limitation no amount of control design can fix. It is also why ISA treats management override as a presumed fraud risk on every audit, requiring specific procedures such as testing journal entries and reviewing accounting estimates for bias.
Documenting the system
Narrative notes, flowcharts, questionnaires and checklists are all acceptable. A walkthrough test — following one transaction from beginning to end — confirms the system operates as described, and is the standard way of verifying that the documentation is accurate before relying on it.
Reporting deficiencies
Deficiencies are communicated in writing to those charged with governance — the management letter. Significant deficiencies must be reported; other matters may be.
The report is most useful when each point sets out the deficiency, its implication, and a practical recommendation. A list of faults without consequences or remedies is of little use to a board.
Note the limitation the letter itself should state: the auditor examined controls only so far as necessary to plan the audit, not to express an opinion on the system as a whole.
:::checkpoint A company's managing director personally approves every payment and also signs the cheques, saying this gives tight control. Identify the control weakness, name the limitation of internal control it illustrates, and suggest a compensating control. :::