Preview

Information Technology, Internal Control, and Financial Statement Audits

Powerful Essays
Open Document
Open Document
2188 Words
Grammar
Grammar
Plagiarism
Plagiarism
Writing
Writing
Score
Score
Information Technology, Internal Control, and Financial Statement Audits
Information Technology, Internal Control,and Financial Statement Audits

By Thomas A. Ratcliffe and Paul Munter

In Brief

ASB Tackles IT System Control Risk

Modern data processing systems pose new, risk-laden challenges to the traditional audit process. Whereas it was once possible to conduct a financial statement audit by assessing and monitoring the controls over paper-based transaction and accounting systems, businesses have increasingly turned to electronic transaction and accounting systems. SAS 94 offers guidance on collecting sufficient, competent evidence in an electronic processing environment. It pays particular attention to identifying circumstances when the system of control over electronic processing must be accessed.

Becognizing that it is increasingly difficult for auditors to rely on traditional (paper) audit evidence to acquire sufficient competent evidence, the Auditing Standards Board (ASB) issued SAS 94, The Effect of Information Technology on the Auditor’s Consideration of Internal Control in a Financial Statement Audit, in May 2001. SAS 94 is effective for audits of financial statements for periods beginning on or after June 1, 2001. Early application is permitted.

SAS 94 amends SAS 55, Consideration of Internal Control in a Financial Statement Audit, as previously amended by SAS No. 78, Consideration of Internal Control in a Financial Statement Audit: An Amendment to Statement on Auditing Standards No. 55. Specifically, SAS 94 addresses the effect of information technology (IT) on internal controls and on the auditor’s understanding of internal controls, including the required assessment of control risk.

Background

In December 1996, the ASB issued SAS 80, entitled Amendment to Statement on Auditing Standards No. 31, Evidential Matter, in order to address questions about the validity, completeness, and integrity of electronic evidence. When entities transmit, process, maintain, or access information electronically, it may

You May Also Find These Documents Helpful

  • Good Essays

    Information technology and financial audits primary objectives are to ensure data integrity, safety, secure and operational effectiveness for Kudler’s business processes. Internal audit will provide an opinion on the accuracy and fairness of the financial statements. “This fairness evaluation is conducted in the context of generally accepted accounting principles (GAAP) and requires application of generalized auditing standards” (Bargranoff, 2008).…

    • 986 Words
    • 4 Pages
    Good Essays
  • Good Essays

    The three strategies for testing internal controls would first be to assess a control risk based on user controls. This can be done by comparing computer-generated output with the source documents that can support the transactions. The second strategy would be by planning for a low control risk assessment based on application controls. This means that the auditor should test the computer application controls, test the computer general controls, and test the manual follow up of the exceptions noted by the application controls. The last strategy would be planning for a high control risk assessment based on general controls and manual follow up. When an auditor test the general controls they can usually learn about the effectiveness of the design and testing application controls.…

    • 627 Words
    • 3 Pages
    Good Essays
  • Satisfactory Essays

    SSAE 16, just like SAS 70, does not outline the controls that must be covered in the assessment of IT controls. It is for the service provider to decide which controls are essential to the services being provided. And, the service auditor still issues a Type I or Type II report. Both report types rely on management’s description of controls, and the scope of each report is similar to that under SAS…

    • 480 Words
    • 2 Pages
    Satisfactory Essays
  • Good Essays

    Case Study

    • 625 Words
    • 3 Pages

    Accounting today is much more complex and difficult to understand than it has been in the past. Due to the increasing complexity Accounting Information Systems have been created to alleviate some of the pressures facing accountants. According to Frederick Jones and Dasaratha Rama (2006), Enterprise Resource Planning (ERP) systems are moving businesses from the functional approach to an integrated approach for managing transactions (p.684). Having knowledge and experience with the technological advances will help the accountant become more successful. Companies, such as CBU from the case study, must be able to effectively use technology to their advantage if they want to be successful in the future. The accounting staff of CBU must be able to develop more timely and effective system controls for future financial statement purposes and inventory audits.…

    • 625 Words
    • 3 Pages
    Good Essays
  • Satisfactory Essays

    References: AU 9504. AICPA Statement on Auditing Standards. Retrieved on March 13, 2013 from: http://www.aicpa.org/research/standards/auditattest/pages/sas.aspx…

    • 326 Words
    • 2 Pages
    Satisfactory Essays
  • Powerful Essays

    the runershop

    • 2264 Words
    • 10 Pages

    To illustrate the linkage of management assertions to audit evidence in the context of auditing Notes Payable.…

    • 2264 Words
    • 10 Pages
    Powerful Essays
  • Good Essays

    c. What should an audit team consider when seeking to reduce the planned assessed level of control risk below the maximum?…

    • 1065 Words
    • 5 Pages
    Good Essays
  • Powerful Essays

    Foamex International Inc.

    • 1340 Words
    • 6 Pages

    The final responsibility for the integrity of an SEC registrant’s internal controls lies on the management team. U.S. companies need to refer to a comprehensive framework of internal control when assessing the quality of financial reporting to determine that financial statements are being presented under General Accepted Accounting Principles, GAAP. The widely used framework is referred as COSO, Committee of Sponsoring Organizations of the Treadway Commission, sponsored by the following organizations American Accounting Association, the American Institute of CPA’s, Financial Executives International, the Institute of Internal Auditors, and the Institute of Management Accountants. COSO’s defines internal control as:…

    • 1340 Words
    • 6 Pages
    Powerful Essays
  • Satisfactory Essays

    In regard to the new SAS 112 regulation and its impact for accounting auditors; it is important that we closely examine the challenges of communicating accounting changes effectively with different groups, and understand the problems that may occur from poor communication and impact the productivity of workers. This memo will first present some background on communicating accounting changes, and then analyze the consequences of poor communication.…

    • 385 Words
    • 2 Pages
    Satisfactory Essays
  • Powerful Essays

    AICPA, (2010, September). Employee Benefit Plan Audit Quality Center. Statement of Auditing Standards (SAS) No. 115 Communicating Internal Control Related Matters Identified in an Audit, Frequently Asked Questions. Retrieved from…

    • 498 Words
    • 2 Pages
    Powerful Essays
  • Good Essays

    The Sarbanes-Oxley Act

    • 635 Words
    • 3 Pages

    effectiveness of the internal control. In addition, they must write an formal evaluation on the effectiveness as company’s recent fiscal year. Finally, an auditor has issued an attestation report on management’s assessment (SEC, 2013). Although initially the compliance costs and efforts of this act were burdensome but after many years companies feel that compliance of the act outweight the costs as well as a great improvement in internal control over 10 years (GARP, 2013).…

    • 635 Words
    • 3 Pages
    Good Essays
  • Better Essays

    Audit Proposal

    • 1321 Words
    • 6 Pages

    A SAS 70 audit is generally to provide assurance about the existence and effectiveness of the company’s internal controls around a service provided to others. Kudler is not a service provider. However, Kudler does transmit data to the Electronic Payment Clearing House for automatic submission of the credit card transactions to the applicable financial institutions. A SAS 70 could be beneficial to…

    • 1321 Words
    • 6 Pages
    Better Essays
  • Better Essays

    The Committee of Sponsoring Organizations (COSO), consisting of many accounting regulation bodies, issued a report defining internal control as:…

    • 1198 Words
    • 5 Pages
    Better Essays
  • Satisfactory Essays

    Binoy Study

    • 751 Words
    • 4 Pages

    with the goals (Pathak, 2005). 4.0 Changing Roles of the auditors The impact of information technology on Organisations audit processes, 2012 Page | 2…

    • 751 Words
    • 4 Pages
    Satisfactory Essays
  • Good Essays

    Increasingly evidence is in digital form and rules of evidence are evolving to accommodate this change. A company's computerized accounting records are generally admissible if they were kept in the normal course of business and can be authenticated (i.e., shown that they have not been tampered with).True…

    • 864 Words
    • 4 Pages
    Good Essays

Related Topics