Skip to content
SmartStudy

Internal Control and Systems Evaluation

Planning

Internal Control and Systems Evaluation

Syllabus tag: KASNEB CPA | Intermediate Level | CA24 Auditing and Assurance | Topic 5 Internal Control and Systems Evaluation

Lesson objectives

By the end of this topic, you will be able to:

  • Identify the five components of internal control
  • Recognise common control activities and what each prevents
  • Distinguish tests of control from substantive procedures
  • Explain the inherent limitations of any control system
  • Report deficiencies appropriately

Why this matters

Where controls work, the auditor can do less substantive testing. Where they do not, everything must be tested directly. Evaluating the system therefore decides the shape and cost of the whole audit.

The five components

C-R-I-M-E is the standard aid:

  • Control environment — the tone at the top: integrity, ethical values, competence, and the attention of those charged with governance
  • Risk assessment process — how the entity identifies and responds to business risks
  • Information system — the accounting system and how transactions are recorded and reported
  • Monitoring of controls — how the entity checks its controls still work, including internal audit
  • Existing control activities — the specific procedures themselves

The control environment comes first for a reason. Detailed controls designed by a management that has no interest in enforcing them will not operate. Where the environment is weak, the auditor should be sceptical of every control below it.

Common control activities

ActivityPrevents
Segregation of dutiesOne person authorising, recording and holding an asset
Authorisation limitsTransactions committed beyond delegated authority
Physical controlsTheft of cash, inventory and records
ReconciliationsErrors and omissions going undetected
Arithmetic and accounting checksRecording errors
Supervision and reviewPoor work passing unnoticed
Information processing controlsInvalid or incomplete data entry

Segregation of duties is the single most examined control. The three functions that must be separated are authorising a transaction, recording it, and holding custody of the related asset. One person holding two of the three creates the opportunity for fraud to be concealed.

In a small entity segregation is often impossible, and the answer is not to pretend otherwise. Compensating controls — close owner involvement, review of bank statements by the proprietor — become the relevant control, and the auditor is likely to rely more on substantive testing.

Tests of control and substantive procedures

Tests of controlSubstantive procedures
TestsWhether the control operatedWhether the figure is right
ExampleInspect invoices for evidence of authorisationConfirm the balance with the customer
Result if it failsIncrease substantive testingThe figure may be misstated

The relationship matters. A test of control that fails does not itself prove the accounts are wrong. It tells the auditor the control cannot be relied on, so more direct testing is needed.

Substantive procedures can never be dispensed with entirely. However strong the controls, ISA requires substantive procedures for each material class of transactions, balance and disclosure. Controls reduce the extent of substantive work; they do not remove it.

:::checkpoint An auditor tests fifty purchase orders and finds four lacking the required authorisation signature. State what the auditor concludes, and what changes in the remainder of the audit. :::

Inherent limitations

No system, however well designed, gives more than reasonable assurance. Every system is limited by:

  • Human error — mistakes, misunderstanding, fatigue
  • Collusion — two or more people defeating segregation of duties together
  • Management override — the people who designed the controls can set them aside
  • Cost versus benefit — controls are not implemented where they cost more than the risk
  • Non-routine transactions — controls are designed for the usual, and unusual transactions escape them

Management override is the most serious, because it is the one limitation no amount of control design can fix. It is also why ISA treats management override as a presumed fraud risk on every audit, requiring specific procedures such as testing journal entries and reviewing accounting estimates for bias.

Documenting the system

Narrative notes, flowcharts, questionnaires and checklists are all acceptable. A walkthrough test — following one transaction from beginning to end — confirms the system operates as described, and is the standard way of verifying that the documentation is accurate before relying on it.

Reporting deficiencies

Deficiencies are communicated in writing to those charged with governance — the management letter. Significant deficiencies must be reported; other matters may be.

The report is most useful when each point sets out the deficiency, its implication, and a practical recommendation. A list of faults without consequences or remedies is of little use to a board.

Note the limitation the letter itself should state: the auditor examined controls only so far as necessary to plan the audit, not to express an opinion on the system as a whole.

:::checkpoint A company's managing director personally approves every payment and also signs the cheques, saying this gives tight control. Identify the control weakness, name the limitation of internal control it illustrates, and suggest a compensating control. :::

Next in Auditing and AssuranceAudit Evidence and Procedures