General and Application Controls For Information System
General and Application Controls For Information System
General and Application Controls For Information System
CONTROLS FOR
INFORMATION SYSTEM
General controls are those that control the design, security, and use of
computer programs and the security of data files in general throughout the
organization. On the whole, general controls apply to all computerized
applications and consist of a combination of system software and manual
procedures that create an overall control environment.
1. INPUT CONTROLS
Input Controls - check data for accuracy and completeness when they enter the system.
There are specific input controls for input authorization, data conversion, data editing, and error
handling.
Input authorization. Input must be properly authorized, recorded, and monitored as
source documents flow to the computer.
Data conversion. Input must be properly converted into computer transactions, with no
errors as it is transcribed from one form to another.
Batch control totals can be established beforehand for transactions grouped in
batches.
Edit checks. Various routines can he performed to edit input data for errors before
they are processed.
2. PROCESSING CONTROLS
Processing controls establish that data are complete and accurate during updating.
Run control totals reconcile the input control totals with the totals of items that
have updated the file.
Computer matching matches the input data with information held on master or
suspense files, with unmatched items noted for investigation
3. OUTPUT CONTROLS
Typical output controls include the following:
• Balancing output totals with input and processing totals
• Reviews of the computer processing logs to determine that all of the
correct computer jobs were executed properly for processing
• Audits of output reports to make sure that totals, formats, and critical
details are correct and reconcilable with input