Preview

edp audit

Better Essays
Open Document
Open Document
8484 Words
Grammar
Grammar
Plagiarism
Plagiarism
Writing
Writing
Score
Score
edp audit
123
AUDITING AND EDP

I. AUDITOR’S CONSIDERATION OF INTERNAL CONTROLS IN AN EDP ENVIRONMENT

The second standard of field work requires that we obtain a sufficient understanding of the client’s internal controls (I/C) to plan the audit and assess control risk. We hope that our assessment of control risk shows it to be low so that we can reduce substantive testing, thereby reducing audit costs. When EDP is used in significant accounting applications, then you must consider the effects the computer has when evaluating the internal controls. The auditor’s approach to considering I/C is the same in a computerized environment as in a manual environment:

--Obtain and document understanding of the internal controls --Assess control risk --Perform tests of controls --Reassess control risk

A. Obtain and document an understanding of the I/C

1. The extent to which the auditor needs to understand the computer system is dependent upon the preliminary audit strategy selected:

a. Primarily substantive approach--treat computer as a black number crunching box and just audit the inputs and outputs (auditing around the computer)

b. Lower assessment of control risk--you rely on the computer’s controls (audit through the computer)

B. Assess Control Risk

1. The auditor needs to assess the risk that the internal controls (including EDP controls) will not prevent or detect material errors or irregularities that will effect the financial statements.

a. CONSIDER THE STRENGTHS AND WEAKNESSES OF THE GENERAL CONTROLS FIRST

Example of this in the payables cycle--one of the application (programmed) controls requires that the computer match the voucher with appropriate supporting documentation before a check is issued. However, if the general controls over changes to programs cannot be relied on, then the payables program could be modified to allow an unauthorized check. Thus, the application control could not be relied on either.

b. Identify

You May Also Find These Documents Helpful

  • Good Essays

    External audits will assess computer-base accounting systems. The purpose of the audit is to determine how the computerized system impacts Kudler’s financial statements. Substantive test will be done to ensure proficiency; and it will begin with a preliminary test. A risk assessment will be another objective of the audit. “Risks of material misstatement can arise from a variety of sources, including external factors, such as conditions in the company 's industry and environment, and company-specific factors, such as the nature of the company, its activities, and internal control over financial reporting” (Audited No.12, 2012). The risk must be evaluated because the system controls strengths and weakness affects the scope of the audit. “The risk-base audit approach provides auditors with a good understanding…

    • 986 Words
    • 4 Pages
    Good Essays
  • Satisfactory Essays

    Understanding internal controls is necessary to plan and complete the audit. The audit is not designed to obtain any type of reasonable assurance about these controls. If any significant deficiencies within the internal control system are discovered during the audit we will express concern to management, and the audit team will be made aware our findings.…

    • 483 Words
    • 2 Pages
    Satisfactory Essays
  • Good Essays

    The three strategies for testing internal controls would first be to assess a control risk based on user controls. This can be done by comparing computer-generated output with the source documents that can support the transactions. The second strategy would be by planning for a low control risk assessment based on application controls. This means that the auditor should test the computer application controls, test the computer general controls, and test the manual follow up of the exceptions noted by the application controls. The last strategy would be planning for a high control risk assessment based on general controls and manual follow up. When an auditor test the general controls they can usually learn about the effectiveness of the design and testing application controls.…

    • 627 Words
    • 3 Pages
    Good Essays
  • Good Essays

    The auditor must obtain a sufficient understanding of the entity and its environment, including its internal control, to assess the risk of material misstatement of the financial statements whether due to error or fraud, and to design the nature, timing, and extent of further audit procedures. | The students were told by Jones not to spend time reviewing the controls and to simply concentrate on mathematical errors. |…

    • 547 Words
    • 3 Pages
    Good Essays
  • Satisfactory Essays

    11-6 a. Briefly describe three strategies for testing internal controls when information technology is used for significant accounting processing.…

    • 6750 Words
    • 23 Pages
    Satisfactory Essays
  • Better Essays

    In identifying and assessing the risks of material misstatement, the auditor shall evaluate the degree of estimation uncertainty associated with an accounting estimate. The auditor shall determine whether, in the auditor's judgment, any of those…

    • 1596 Words
    • 5 Pages
    Better Essays
  • Good Essays

    Au Section 316

    • 681 Words
    • 3 Pages

    They must be skeptical of management no matter how much the auditors may believe in the integrity of management. The auditors cannot let their guard down when performing an audit otherwise they run the risk of missing fraud and material…

    • 681 Words
    • 3 Pages
    Good Essays
  • Satisfactory Essays

    MADOFF CASE

    • 341 Words
    • 2 Pages

    Use the understanding of the client and its environment to consider inherent risks, including fraud risk related to financial investments.…

    • 341 Words
    • 2 Pages
    Satisfactory Essays
  • Powerful Essays

    Unit 4

    • 1878 Words
    • 8 Pages

    To be well defined and timely, an auditing strategy must provide useful tracking data on an organization's most important resources, critical behaviors, and potential risks. In a growing number of organizations, it must also provide absolute proof that IT operations comply with corporate and regulatory requirements.…

    • 1878 Words
    • 8 Pages
    Powerful Essays
  • Powerful Essays

    Audit

    • 2218 Words
    • 9 Pages

    This part of the audit case illustrates the manner in which the auditors design substantive tests of balances. The substantive tests are illustrated for two accounts—receivables and revenue. This aspect of the audit is illustrated with the following audit documentation: • ABC’s risk assessment working paper that combines the auditors’ assessments of inherent and control risks into an overall risk of material misstatement for the assertions. • The substantive audit program of accounts receivable and revenue. • The audit sampling plan for the confirmation of accounts receivable. Adams, Barnes & Cos. assessment of control risk is described in Part II of the audit case on pages 441 through 454. To refresh your knowledge of the case, review that part as well as Part I on pages 213 through 220 of Chapter 6.…

    • 2218 Words
    • 9 Pages
    Powerful Essays
  • Good Essays

    Internal controls are all measures taken by an organization for the purposes of protecting its resources against waste, fraud, or inefficient use; ensuring the reliability of accounting data; securing compliance with management policies; and evaluating the performance of all employees, managers and departments within the organization. The accounting system depends upon internal control procedures to ensure the reliability of accounting data. Many internal control procedures on the other hand make use of accounting data in keeping track of assets and monitoring the performance of departments. Internal control is looked upon more and more as a solution to a variety of potential problems. The effectiveness and efficiency of operations as a technique relates to performance and profitability goals and safeguarding of resources.…

    • 371 Words
    • 2 Pages
    Good Essays
  • Good Essays

    The Sarbanes-Oxley Act

    • 635 Words
    • 3 Pages

    effectiveness of the internal control. In addition, they must write an formal evaluation on the effectiveness as company’s recent fiscal year. Finally, an auditor has issued an attestation report on management’s assessment (SEC, 2013). Although initially the compliance costs and efforts of this act were burdensome but after many years companies feel that compliance of the act outweight the costs as well as a great improvement in internal control over 10 years (GARP, 2013).…

    • 635 Words
    • 3 Pages
    Good Essays
  • Better Essays

    352) to verify controls are working and accurate data processing. However, certain events might prevent reliance on auditing through the computer. For instance, auditing through the computer assumes that the computer hardware is functioning properly. Improper function may prevent auditing through the computer. Similarly, if computer controls are weak or nonexistent, Kudler cannot rely on auditing through the computer. The auditor must review information system controls by assessing risks and identifying control procedures designed to prevent these threats before choosing to audit through the…

    • 1118 Words
    • 5 Pages
    Better Essays
  • Good Essays

    The Sarbanes-Oxley Act

    • 642 Words
    • 3 Pages

    The maintenance of internal control by management ensures that material information is not being provided for reports. This is essential when being assessed by our side auditors in compliance with Section 404 of Sox. It requires top management or audit committee and outside auditors to review on internal controls and whether or not they are adequate enough. This can be costly for entities to implement because samples of documentation, testing of internal controls, review of manual, and automated systems implemented by entity which enormous maintenance and time. Assessing internal control is design efficiency, outside auditors relate to specific accounts and relevant information in context of material mistake can prevent fraudulent financials being provided to the…

    • 642 Words
    • 3 Pages
    Good Essays
  • Best Essays

    Bibliography: American Institute of Certified Public Accountants (2005), The AICPA audit committee toolkit: not for…

    • 3945 Words
    • 16 Pages
    Best Essays