Chapter 3 Internal Control Consideration and Responses To Assessed Risks
Chapter 3 Internal Control Consideration and Responses To Assessed Risks
TOPIC OVERVIEW:
This chapter discusses internal controls, assessment of control risk and how will it affect audit procedures.
LEARNING OBJECTIVES:
The auditor should obtain an understanding of the accounting and internal control systems sufficient to plan the
audit and develop an effective audit approach.
The auditor uses the understanding of internal control to identify types of potential misstatement, consider factors
that affect the risks of material misstatement, and design the nature, timing, and extent of further audit procedures.
Accounting system is a series of tasks and records of an entity by which transactions are processed as a means of
maintaining financial records. Such systems identify, assemble, analyze, calculate, classify, record, summarize and
report transactions and other events.
Internal Control System means all the policies and procedures (internal controls) adopted by the management of
an entity to assist in achieving management’s objective of ensuring, as far as practicable:
orderly and efficient conduct of its business, including adherence to management policies;
safeguarding of assets;
prevention and detection of fraud and error;
accuracy and completeness of the accounting records; and
timely preparation of reliable financial information.
The internal control system extends beyond those matters which relate directly to the functions of the accounting
system.
Internal control is a process, effected by those charged with governance, management, and other personnel,
designed to provide reasonable assurance regarding the achievement of objectives in the following categories:
There is a direct relationship between an entity’s objectives and the controls which are implemented to provide
assurance of their achievement. However, no matter how well designed and operated, internal control can only
provide reasonable assurance.
The internal control can only provide reasonable assurance because of inherent limitations that may affect the
effectiveness of internal controls. Such limitations include: (COC CHA)
1
The possibility that procedures may become inadequate due to Changes in condition and compliance with
procedures may deteriorate;
The potential for Human error due to carelessness, distraction, mistakes of judgment or the
misunderstanding of instructions; and
The fact that most controls tend to be directed at Anticipates types (routine) of transactions and not at
unusual (non-routine) transactions.
Areas of internal control can be classified as either administrative control or accounting control.
Administrative control includes, but is not limited to, plan of organization and the procedures and records that are
concerned with the decision processes leading to management’s authorization of transactions. Administrative
controls promote operational efficiency and adherence to managerial policies.
On the other hand, accounting control comprises the plan of organization and the procedures and records that are
concerned with the safeguarding of assets and the reliability of financial records. It involves systems of authorization
and approval controls over assets, internal audit and all other financial matters.
The auditor’s risk assessment process relates to controls pertaining to the entity’s objective of preparing financial
statements for external purposes and the management risk that may give rise to a material misstatement in those
financial statements.
It is a matter of professional judgment, subject to the requirements of PSA, whether a control, individually or in
combination with others, is relevant to the auditor’s considerations in assessing the risks of material misstatement
and designing and performing further procedures in response to assessed risks. In exercising that judgment, the
auditor considers the applicable component and factors such as the following:
Internal control, as discussed in PSA 315 (Redrafted), consists of the following components: (CRIME)
a. Control Environment
b. Entity’s Risk assessment process
c. Information and communication systems
d. Control Activities
e. Monitoring of Controls
The control environment includes the governance and management functions and the attitudes, awareness, and
actions of those charged with governance and management concerning the entity’s internal control and its
importance in the entity.
An entity’s risk assessment process is the process of identifying and responding to business risks and the results
thereof.
2
For financial reporting purposes, the entity’s risk assessment process includes how management identifies risks
relevant to the preparation of financial statements that are presented fairly, in all material respects in accordance
with the entity’s applicable financial reporting framework, estimates their significance, assesses the likelihood of
their occurrence, and decides upon actions to manage them.
The auditor shall obtain an understanding of whether the entity has a process for: (IAM)
C. The information system, including the related business processes relevant to financial reporting, and
communication.
NOTE: Infrastructure and software will be absent, or have less significance in systems that are exclusively or
primarily manual.
The information system relevant to financial reporting objectives, such as the financial reporting system, consists of
the procedures and records established to initiate, record, process and report entity transactions (as well as events
and conditions) and to maintain accountability for the related assets, liabilities, and equity.
Communication of financial reporting roles and responsibilities and significant matters relating to financial reporting
includes:
Control activities are the policies and procedures to help ensure that management directives are carried out.
a. Authorization
Specific authorization (for unusual, material, or infrequent projects)
General authorization (for regular transactions)
b. Performance reviews (actual performance versus budget, forecasts, and prior period performance)
c. Information processing (form initiation up to the eventual inclusion of transaction in financial reports)
d. Physical controls (for both assets and documents)
e. Segregation of duties
To achieve optimum segregation of responsibilities, the following functions shoul be performed by
different employees: (I CARE)
Independent checks
Custody of assets
Authorization of transactions
Execution of transactions
E. Monitoring of controls.
3
Monitoring is the process of assessing the quality of internal control performance over time. It involves assessing the
design and operations of controls on a timely basis and taking necessary corrective actions. Monitoring is done to
ensure that controls continue to operate effectively.
a. Ongoing monitoring activities (performed by persons within the same line function)
b. Separate evaluations (performed by internal auditors, audit committee, and/or external auditors
c. Combination of the two.
The auditor shall design and implement overall responses to address the assessed risks of material misstatement at
the financial statement level.
Moreover, the auditor shall design and perform further audit procedures whose nature, timing, and extent are based
on and are responsive to the assessed risks of material misstatement at the assertion level.
a. Consider the reasons for the assessment given to the risk of material misstatement at the assertion level for
each class of transactions, account balance, and disclosure, including:
i. The likelihood of material misstatement due to the particular characteristics of the relevant class of
transactions, account balance, or disclosure (i.e., the inherent risk); and
ii. Whether the risk assessment takes account of relevant controls (i.e., the control risk), thereby
requiring the auditor to obtain audit evidence to determine whether the controls are operating
effectively (i.e., the auditor intends to rely on the operating effectiveness of controls in
determining the nature timing and extent of substantive procedures); and
b. Obtain more persuasive audit evidence, the higher the auditor’s assessment of risk.
TESTS OF CONTROLS
The auditor should give adequate consideration to controls relevant to the audit. The quality of the entity’s internal
control can have a significant impact in determining the nature, timing and extent of the audit procedures in
gathering audit evidence related to class of transactions, account balances and disclosures.
The auditor shall design and perform test of controls to obtain sufficient appropriate audit evidence as to the
operating effectiveness of relevant controls when:
a. The auditor’s assessment of risks of material misstatement at the assertion level includes an expectation
that the controls are operating effectively (i.e., the auditor intends to rely on the operating effectiveness of
controls in determining the nature, timing and extent of substantive procedures); or
b. Substantive procedures alone cannot provide sufficient appropriate audit evidence at the assertion level.
Tests of controls over the design of a policy or procedure include Inquiry, Observation, Inspection, Reperformance
and Walk-through tests.
SUBSTANTIVE PROCEDURES
Irrespective of the assessed risks of material misstatement, the auditor shall design and perform substantive
procedures for each material class of transactions, account balance, and disclosure.
Documentation requirements
Control Risk Assessment Understanding of Control risk assessment Basis for the control risk
internal control assessment
High Yes Yes No
Less than high Yes Yes Yes