Description I already finished the excel part. I just need you to write a paragraphsin the instruction. I already finished everything except the last part about write paragraphs.write a paragraph in a word document for each stream (one paragraph for each stream) explaining the reasons you chose the CRA levels for each stream. Base your CRA levels on your understanding of the IC structure as documented by:a.The accounting processes (Designed well to mitigate introduction of errors into accounting system)b.The control procedures and management assertions covered by each control (overall coverage)c.The key controls that are in place (# of key controls in each stream)d.The Missing key controlse.Separation of Duties 3 attachmentsSlide 1 of 3attachment_1attachment_1attachment_2attachment_2attachment_3attachment_3.slider-slide > img { width: 100%; display: block; } .slider-slide > img:focus { margin: auto; } Unformatted Attachment Preview COMPUTERIZED INTERNAL CONTROLS CASE OWNCO, INC. Objective: Part I Actual: Learn how to document and evaluate an entity’s internal control structure. Specifically, document and evaluate the accounting processes and controls and make a preliminary or planned Control Risk Assessment (CRA) Material: 1. 2. You will use and Excel Spreadsheet Ownco1.xlsx to document and complete your internal control evaluation assignments. Documentation for the sales stream in the revenue cycle is already mostly completed and found in the Excel Spreadsheet “Ownco1.xlsx.” Download ownco1.xlsx from the syllabus link on the class web page or from the assignment page. INSTRUCTIONS: 1. Read Handout 1 (attached below): The company background, computer processing overview, employee list, and narration of the processes and controls in the revenue cycle are provided. ICE step 1, evaluation of internal control environment, has been done. It has been determined that management override is not an issue and the computer processing for this small company provides enough foundation for reliance on computerized accounting controls. After reading the background information, relate the sales stream information to the documentation about the sales stream found on Ownco1.xlsx. The Sales stream is a model or pattern you can use to help you document the cash receipts stream. 2. Using the information in Handout 1 on the cash receipts stream document the accounting processes, controls, and make your preliminary Control Risk Assessment (CRA) using the excel file Ownco1.xlsx for the cash receipts stream. a. ICE Step 2: Document the accounting processes in the cash receipts stream: Using the flowchart screen and excel’s flowcharting tools, add the cash receipts stream process symbols to the revenue cycle overview flowchart you believe are necessary to adequately document the cash receipts accounting processes. (Use the sales stream flowchart as a model for how to complete the overview flowchart.) Document only the processes, not the controls. Also, in the process and control summary page fill out the columns about personnel performing each process and whether the process is manual or computerized. b. ICE Step 3: Document the controls in the cash receipts stream. Make sure to include the AR GL because it is in both the Sales and Cash Receipts stream. Using the Process and Controls Summary worksheet, fill in the table based on the narration concerning the controls. The columns are as follows: • • • • • • • Control name(s) (if any controls exist) for each process Management Assertion(s) for each control Person(s) performing control Is Control Preventive or Detective? How is control documented? Compensating control (if any)–A Compensating control is a control later in the overall processing that “compensates for” the lack of any controls at a particular process. Location of each compensating control–What accounting process does the compensating control protect. A list of controls and the list of management assertions and the related descriptions of the controls and assertions are found in other worksheet tabs. Make sure you complete all the columns for the controls. c. Make Preliminary CRA ICE Step 4a. Using the column for key controls in the Processes and Controls Summary worksheet tab, identify key controls for the cash receipts stream. Then review the key controls on the Sales Stream and make changes as you deem appropriate. Make sure you mark in the excel table Process and Control Summary sheet which controls you plan to rely on and test, that is, which controls you select as key controls. ICE Step 4b. Using the Control Risk Assessment worksheet tab, record the risk category you believe is appropriate given your documentation of the accounting processes and controls. Make a preliminary CRA on the cash receipts stream. The Sales stream is done, but review it and change it if you wish. Your CRA will include the management assertions Existence/Ocurrence, Completeness, Valuation-Gross, combined into a management assertion group. Finally, write a paragraph in a word document for each stream (one paragraph for each stream) explaining the reasons you chose the CRA levels for each stream. Base your CRA levels on your understanding of the IC structure as documented by: a. b. c. d. e. The accounting processes (Designed well to mitigate introduction of errors into accounting system) The control procedures and management assertions covered by each control (overall coverage) The key controls that are in place (# of key controls in each stream) The Missing key controls Separation of Duties Hand in Part I “Actual” Ownco documentation by uploading your excel and word files to the assignment in the course Online system. Save the file with an A and you’re your last name and first initial. (The A stands for Actual.”) Make sure your name is in the worksheet somewhere as the preparer. HANDOUT 1 INTERNAL CONTROL EVALAUTION OWNCO, INC. BACKGROUND, SALES STREAM AND CASH RECEIPTS STREAM Background – Understanding of the Control Environment Ownco Inc. Manufactures plastic fishing worms at one location (Running Water, Arkansas). Ed Jones, its sole owner, manages Ownco. Jones is responsible for marketing, purchasing, hiring and approving major transactions. He has a good understanding of the business and the industry in which it operates. Jones believes that hiring experienced personnel is particularly important because there are no layers of supervisory personnel and thus, because of limited segregation of duties, few independent checks of employees’ work. Jones has a moderate-to-conservative attitude toward business risks. The company has demonstrated consistent profitability, and because Jones considers lower taxes to be as important as financial results, he has a conservative attitude toward accounting estimates. Jones and Pat Willis, the bookkeeper, readily consult with our firm on routine accounting questions, including the preparation of accounting estimates (tax accrual, inventory obsolescence, or bad debts). Family members compose the company’s board of directors. The board does not monitor the business of the owner-manager’s activities Pat Willis and Chris Ross, Jones’ secretary, perform most of the significant accounting functions. The company hired Willis in 1990. She has a working knowledge of accounting basics, and we have no reason to question her competence. Willis regularly consults with our firm on unusual transactions, and history shows that it is rare for adjustments to arise from errors in the processing of routine transactions. The owner-manager carefully reviews computer-generated financial reports, such as reports on receivables aging, and compares revenues and expenses with prior years’ performance. He also monitors the terms of the long-term debt agreement that requires certain financial statement ratios and compensating balances. Our firm has determined that management override of internal controls is NOT a concern. Ownco uses late model microcomputers that are networked with windows. The company uses a basic accounting software package (Quickbooks) that provides for three users. The source code is not available for this software. A network printer was purchased with the computer. The network maintenance and setup is outsourced to Digital Tech, Inc. and is properly controlled so that only Willis, Ross and Jones have access to the accounting system. Digital Tech, Inc., provided our firm with a copy of their Type I SAS 70 Audit Report for their past year end. Our firm also has been granted “reports only” access (cannot change any transactions) to Ownco’s Quickbooks accounting system. The backup for the accounting and company files is also done automatically and regularly, and stored offsite by the Digital Tech., Inc. For the computer controls, Jones is set as the master administrator of the accounting system, with Willis as the company administrator. Ross only has access to cash receipts recording but does not have access to general ledger nor to cash disbursements or purchases. From an audit perspective, the computer environment is determined to be simple (not complex) and IT audit is not necessary. The IT environment does not provide any concerns from an audit perspective about the computer accounting software and related computerized accounting controls. Our completed Computer System Summary Evaluation is provided below. Computer Processing Overview: Company as a whole: Is a third part service organization used to process all transactions involving computer processing? No Are the client’s computers in a dedicated physical area or facility? No Is there a separate IT Department? No Can separate users access the system concurrently? Yes Is access control software used to restrict access to the production programs? Yes Is access control software used to restrict access to the data files? Yes Are reports generated by such software reviewed by management? Yes Revenue Accounting Cycle: Are transactions for this cycle processed by a third party service organization? No Is this application PC-based? Yes Does the client have the source code for the computer program used in this accounting cycle? No Do multiple applications share the same database files? No Are there real-time updates to files when transactions are entered? Yes Are telecommunications or networks used in this accounting cycle? Yes Is physical access to computers controlled? No Is the use of computers controlled by password? Yes Are passwords protected and changed on a regular basis? Yes Are system user rights transaction or application specific? Yes Does the software in this accounting cycle generate transactions or pass information to other transaction cycles? Yes Is there significant loss of visible audit trail in the accounting cycle? No Have there been any hardware or software malfunctions which resulted in a loss of data in this accounting cycle? No Ownco, Inc. Employees: Amos, John Warehouse picker Tanner, Jeff Shipping clerk Deal, Robert Warehouse picker Trout, Jack Warehouse Supervisor Jones, Ed Owner-manager Various Sales representatives Ross, Chris Secretary of Ed Jones Willis, Pat Bookkeeper Sales Stream in Revenue Cycle Sales in the current year ending September 30, 20XX were approximately $10,300,000. The number of transactions was approximately 35,000. At the time a sale is made, the sales representative enters information such as customer name and number, shipping and inventory description, stock number, and price on a fourpart, prenumbered sales order (SO) form. Written explanations of price variances are attached The owner-manager (Ed Jones) reviews each SO for prenumbered sequence and proper price, approves the extension of credit to the customer, and signs the sales order. The bookkeeper receives SO copy No. 1. The warehouse, the sales representative, and the customer receive the additional copies. Mr. Jones reviews sales orders after the fact on return from being away from the office. The bookkeeper receives approved SO copy No. 1 from the owner-manager and files them numerically, pending receipt of the shipping report. Upon receipt of SO copy No. 2, Jack Trout, the warehouse supervisor, ensures that the owner-manager has signed the SO and then has the warehouse pickers, John Amos or Robert Deal, pull the goods and prepares the shipping report. The shipping clerk, Jeff Tanner, receives the shipping report, SO copy No. 2, and the pulled goods from the warehouse. Jeff Tanner verifies that the goods agree with the SO and the shipping report, initials the shipping report, prepares the goods for shipment and ships the goods. The bookkeeper receives the shipping report and matches it with SO copy No. 1. Copies also go to the customer and to the warehouse supervisor (for filing in the warehouse department). The bookkeeper enters stock number, quantity, prices, and customer information into the microcomputer. The computer prints sales invoices. The bookkeeper matches computer-generated sales invoices with sales orders and shipping reports for completeness. The bookkeeper also investigates unmatched sales orders and shipping reports monthly. The customer receives the original sales invoice (including a breakaway remittance advice). The matched sales order, shipping report, and sales invoice are stapled together and filed by sales invoice number. At the end of the day, transactions are posted to the cumulative sales master file, the accounts receivable master file, and the general ledger. The owner-manager reviews sales reports and shipping reports weekly. The ownermanager reviews the aged trial balance twice monthly, and he follows up on past due accounts. The owner-manager pays particular attention to accounts over 30 days past due. Customers receive statements each month. The statements request the customers contract Mr. Jones, the Owner-manager, for any disputed balances. The bookkeeper reconciles the accounts receivable subsidiary ledger and cumulative sales master file with the appropriate general ledger accounts monthly. Cash Receipts Stream in Revenue Cycle Chris Ross, the secretary, receives all checks and remittance advices. She prepares a complete listing of all checks received. She retains the original list, and gives a copy to Pat Willis the bookkeeper) along with the checks and remittance advices. Willis prepares the bank deposit and adds the account code to each item listed on the listing of checks received. She makes the bank deposit, and then gives Ross a copy of the deposit slip, receipted by the bank. Ross Compares the deposit slip with the original list of checks. Willis enters customer and cash receipts information into the microcomputer using the listing of checks with account codes. Willis runs the program that updates the accounts receivable master file and cash receipts file daily. Transactions are posted to the general ledger at the same time. The cash receipts journal, subledgers, and general ledger are printed on demand. Willis compares the computer-generated accounts receivable subsidiary ledgers with the general ledger control account monthly. Willis also prepares the bank reconciliation monthly, which Jones reviews. ICE Step 1: Document and Evaluate Internal Control Environment (Management Override Potential and Computer Process This Step has already been done. It has been determined that management override is not an issue and the computer proces for this small company provides enough foundation for reliance on computerized accounting controls. ICE Step 2a: Complete the Overview Flowchart (Document Main Accounting Processes and Control Points) Using the Shapes inserts, complete the Overview flowchart for the Cash Receipts Stream Using the Process and Controls Narr for the Cash Receipts Stream. The Sales Stream is already completed for you. Just list the major steps or processes in the accounting sytem. Connect the processes with arrows showing the flow of data ICE Step 2a: Complete the Process section of the Process & Controls Summary (worksheet tab) Add the process names to the Process & Controls Summary Add whether each process is manual or computerized Add the name of the person performing the Process. ICE Step 3: Complete the Process & Controls Summary Using the Narration for the Ownco, Inc. internal controls case, complete the Process and Controls Summary worksheet The Sales Stream is already comleted for you. Use it as a general guide for completing the cash receipts transactions stream ICE Step 4a: Complete the Key control column and select which controls you want to select as key. A key control is a control that you as an auditor intend to rely on and one that you must test. Step 4b. Complete your Preliminary Control Risk assessment in the Control Risk Assessment worksheet tab. Select a risk category for each of the transaction streams. The sales stream preliminary CRA is already done, but you need to review it and change it if you believe the indicated risk category is too low. Potential and Computer Processing and Controls) Sales General Ledger Accounts Receivable General Ledger Invoice (Customer Bill) Account Receivable Master File (Subledger) Shipping Ticket Customer Sales Order Each Accounting process is the result of minor processes and also serves as a control point where controls are “located” or placed to prevent, detect, correct errors or irregularities. Think of each accounting process not as a document but as a set of necessary data for that accounting process. Processess Transaction Stream(s) Information Form (Accounting Process and Control Point) Match to names on overview Flowchart Manual or Computerized? Person(s) performing Process Sales Sales Order Manual Various Sales Reps Sales Sales Order Manual Various Sales Reps Sales Shipping Report Manual Sales Shipping Report Manual Amos & Deal Warehouse Pickers Amos & Deal Warehouse Pickers Sales Invoice Computerized Pat Willis, bookkeeper Sales Invoice Computerized Pat Willis, bookkeeper Sales Invoice Computerized Pat Willis, bookkeeper Sales Sales Invoice Sales GL Computerized Computerized Pat Willis, bookkeeper Pat Willis, bookkeeper Sales Sales & Cash Receipts Sales GL Accounts Receivable GL Computerized Computerized Pat Willis, bookkeeper Pat Willis, bookkeeper Sales & Cash Receipts Accounts Receivable GL Computerized Pat Willis, bookkeeper Sales & Cash Receipts Accounts Receivable GL Computerized Pat Willis, bookkeeper Sales & Cash Receipts Accounts Receivable GL Computerized Pat Willis, bookkeeper Sales & Cash Receipts Accounts Receivable GL Computerized Pat Willis, bookkeeper Controls Control Name(s) Can be more than one Control for each Accounting Process (If no controls exist for this accounting process type “none exist”) Mgt Assertion(s) Satisfied by Control (can be more than one) (Mark yes, no or na for no EO C Val G Val N O & AU Checking manually the numerical sequence n of a ydocument, journal or n report na n Other: Review sales for proper pricing and extention of credit n n y na y Matching to a previously validated document: authorized sales order and goods pulled y y n na n Reviewing Internal signatures n n n na y Software Access Controls n n n na y Interactive Feedback Edit n y y na y y y n na n y n y n y n na na n y y n y n y n na na na y y y na n y y na y y y na na y y na y Matching to a previously validated document: Sales order and the shipping report Review of Sales Reports and Shipping report weekly Software Access Controls Computer generation of Transactions Software Access Controls Balance GL with Subledgers: AR subledger or AR master file y Other: All customer disputes are directed to the Owner y Computer generation of Transactions y Monthly Review of Receivables y Mark yes, no or na for not P&D Is Control Preventive or Person(s) performing Control Detective? How is Control Documented? (If not documented, write “not documented”) na Ed Jones Owner/manager prevent not documented na Ed Jones Owner/manager detective not documented na Jeff Tanner, Shipping Clerk and Pat Willis, Bookkeeper prevent Jack Trout Jack Warehouse Supervisor prevent na Computer Program, Posting prevent auto na Pat Willis, Bookkeeper prevent not documented na Pat Willis, Bookkeeper prevent not documented na na Ed Jones Owner/manager Computer Program, Access detective prevent not documented auto na na Computer Program, Posting Computer Program, Access prevent prevent auto auto na Pat Willis, Bookkeeper detective not documented na Ed Jones Owner/manager detective not documented na Computer Program, Posting prevent auto na Ed Jones Owner/manager detective not documented na not documented not documented If no controls exist for this process, list compensating control(s) (if any) Location (Accounting Process) of compensating control (if any) Do you Select this control as a Key Control? (yes, no) Comments yes yes yes yes yes no Process & control by same person no Process & control by same person yes yes yes yes no yes yes yes Process & control by same person Select a CRA for each transaction stream (Mark an x for each column) indicating which risk category is appropriate for your preliminary Control Risk Assessment (CRA) Maximum Risk Slightly Below Maximum Risk Moderate Risk Limited Risk Your CRA applies to the Management assertions Existence/Ocurrence, Completeness, Valuation-Gross combined as a management assertion group. Sales Stream Cash Receipts Stream X Write a paragraph for each stream explaining the reasons you chose the CRA levels for each stream. Base your CRA a. The accounting processes b. The control procedures and management assertions covered by each control (overall coverage) c. The key controls that are in place including # of key controls for each stream d. The Missing key controls e. Separation of Duties tream. Base your CRA levels on your understanding of the IC structure as documented by: Name Amos & Deal Computer Program Computer Program Jones, Ed Ross, Christ Tanner, Jeff Trout, Jack Various Willis, Pat Title Warehourse Pickers Computer Posting Computer Access Onwer/Manager Ed Jones Secretary Shipping Clerk Warehouse Supervisor Sales Representatives Bookkeeper Name (A-Automated, M-Manual) Balancing receivables subledger (M , A) Balancing run to run control totals ( A) Balancing the G/L with the subledgers ( M , A ) Cancelling original documents ( M , A ) Checking by computer for duplicate entries ( A ) Checking by computer the numerical sequence of a file ( A ) Checking for a third party signature ( M , A ) Checking manually the numerical sequence of a document, journal or report ( M , A ) Checking one-to-one ( M , A ) Comparing batch totals ( M , A ) Comparison of budgeted amounts to actual amounts ( M , A ) Comparison of cash receipts listing to deposit slips ( M , A ) Computer generation of transactions ( A ) Dual control over cash receipts ( M , A ) Electronic authorization ( A ) Independent review of edit reports for data file changes ( M , A) Interactive dependency edit ( A ) Interactive document reconciliation ( A ) Interactive edit controls ( A ) Interactive existence edit ( A ) Interactive feedback edit ( A ) Interactive format edit ( A ) Interactive key verification ( A ) Interactive mathematical accuracy check ( A ) Interactive prior data matching ( A ) Interactive reasonableness edit ( A ) Interactive Range Check Edit ( A ) Interactive check digit ( A ) Matching to a previously validated document ( M , A ) Matching to a previously validated file ( A ) Matching to an authorized list ( M , A ) Monthly review of bank reconciliations ( M , A ) Monthly review of payables ( M , A ) Monthly review of payroll ( M , A ) Monthly review of receivables ( M , A ) Non-interactive format edit ( A ) Non-interactive mathematical accuracy check ( A ) Non-interactive edit controls ( A ) Non-interactive existence edit ( A ) Non-interactive dependency edit ( A ) Non-interactive range check edit ( A ) Non-interactive reasonableness edit ( A ) Non-interactive prior data matching ( A ) Non-interactive check digit ( A ) Other ( M ) Password and authorization table checks ( A ) Performance of analytical procedures and investigation of unusual items ( M , A ) Periodic reconciliation of books to physical ( M ) Periodic revision of budgeted amounts based on updated information ( M , A ) Physical access controls ( M , A ) Physical safeguards ( M , A ) Prior approval required for disbursements greater than a specified amount ( M , A ) Reconciliation of manual totals to run totals ( M , A ) Reconciliation of master file balance to control account ( A ) Reconciliation of master file balance to run totals ( A ) Reperformance ( M ) Restrictive endorsement on checks received ( M , A ) Reviewing adjustment transactions ( M , A ) Reviewing exception reports ( M , A ) Reviewing internal signatures ( M , A ) Reviewing reference file data ( M , A ) Review of supporting documents prior to check signing ( M , A) Software access controls ( A ) Use of a lockbox ( M , A ) Use of a surprise payoff ( A ) Use of prerecorded input (OCR, MICR, OMR) ( A ) Verifying mathematical accuracy ( M , A ) Description This control ensures that the receivables subsidiary ledger agrees with the day by day deposits and/or the daily invoice register. Balancing run to run control totals is a control method of determining completeness of update. The following are some examples of how this control may be implemented. A control total is established (field total, record count, etc) for each accepted transaction. The control total is recorded and subsequently agreed to a total of updated transactions. The total of accepted items is manually agreed to the total of items actually updated on the master file. The total of accepted items is reconciled by the computer with the total of items updated on the master file. Totals are accumulated at various stages in processing and reconciled to the updated transactions on the master file. This control helps to ensure that the posting sources to the subsidiary ledgers agree with the posting sources of the general ledger accounts. Any differences should be investigated. This control prevents duplicate recording of transactions. To work adequately, when recording transactions, original documents should be reviewed to ensure that no previously cancelled documents are re-recorded. This control is designed to ensure the completeness of a population by rejected data that has been previously entered. This control can either reject the duplicate transaction on input or the computer system may produce a duplicate transactions report which properly identifies duplicate transactions. If the latter type of control is being used, the method used in correcting the identified duplicate transactions is as important as the control itself. This control ensures the completeness of a population of pre-numbered items. As an automated control, the computer is actually checking to ensure that all numbers have been recorded. See “Checking manually for the numerical sequence of a document, journal or report” for the manual equivalent of this control. The presence of the third party signature on documents is evidence. Checking for this signature is a control to determine that performance has occurred prior to recording the transaction. This control ensures the completeness of a population of pre-numbered items. To be effective, policies should exist as to the procedures to follow in the case of missing documents. See “Checking by computer of numerical sequence of a file” for the automated equivalent of this control. This control consists of checking each individual document or source document with a detailed listing of those items which were processed by the computer. To rely on this technique it is necessary to determine that all documents have been submitted for processing. Completeness can be determined by checking output with retained copies by sequence checking or by reconciling the number of documents sent for processing with the number actually processed and accounting for all differences. To ensure that all transactions being put into the computer have been properly input. The control should ensure that all transactions are included in a batch and that all batches are processed. Rejects from the batch process must be properly controlled to ensure that they are reprocessed. Budgets, forecasts, performance reports and variance analysis reports are generally designed for control purposes to highlight unexpected results and problem areas. Results that differ from expectations should be investigated. This control should include reviewing the recorded cash receipts to bank validated deposit slips for amount and date. This ensures that the recorded cash receipts agree to those actually deposited in the bank. This control avoids the possibility of human error by having the computer generate transactions. For this control to be effective, the generation of the transactions should be outside of the user’s control. Additionally, some control should exist to ensure that the transactions generated were complete and accurate. For example, the transactions generated should be reviewed prior to production of the documents or control totals should be used. This control assumes that two persons are present when the cash on hand or current receipts are counted. Generally, a list is prepared of the amounts and this list is signed by both individuals. To permit the authorization of a transaction on a magnetic file. A password should exist for each supervisor who can carry out this type of transaction. Details of data file activity should be maintained in the form of an edit report. For example, an organization may maintain a log of date and time of last update, name of file which was used in update (if any), or unauthorized attempts to read to change records in the file. This log should be reviewed periodically by an individual independent of the individual who performed the process. This accuracy control determines whether the contents of two or more data elements (fields) on a transaction bear the correct logical relationship. For example, when entering the details of a loan agreement, there should be a logical relationship between the amount advanced, the number of payments to be made, and the payment amount. This control involves checking the mathematical accuracy of the entry of numeric data. Each transaction is treated as a batch. Prior to entry, a hash total is established for all important numeric data elements (quantity, unit cost, amount, etc.) for the document. The total is recorded on the document and entered into the system. Once information has been entered from the document, the program totals the numeric data elements and compares the result with the hash total. Transactions that do not balance are not accepted. These controls exist only in an EDP environment. They are automated controls to ensure the accuracy and completeness of data input into a system and/or the proper authorization of the transaction. An interactive control is a control that involves responses and prompts between the user and the application program. The objective of this control is to ensure that data entered agrees with valid data held on the file or in the program. As an example, when purchase invoices are processed, they require the allocation of general ledger account numbers and an accounts payable numbers. On input, the program checks that the numbers entered exist as valid account numbers in the general ledger and accounts payable ledgers. Items that do not match will not be accepted. This control uses one or more pieces of information input by the user to provide the user with more complete information, thus assuring the accuracy of the initial input. For example, the sales clerk inputs the customer number, product number, and quantity ordered into the sales order system. The customer name, customer address, product description, quantity ordered, unit price and total dollar value appear on the terminal. The clerk verifies the preceding information before releasing the information to the system. This completeness control checks the format (existence of expected numeric or alphanumeric characters) of a transaction to ensure that all required data is present. All numeric data should properly be subjected to format checks. However, since the edit is only checking for a certain format, it is unlikely that the control will be of much help in controlling the accuracy of the input. For example, a format edit on a date field on entry will determine that the format of the date is proper. It will not determine that date being used is correct. Key verification is a common technique for controlling the conversion of infor
Description
I already finished the excel part. I just need you to write a paragraphsin the instruction. I already finished everything except the last part about write paragraphs.write a paragraph in a word document for each stream (one paragraph for each stream) explaining the reasons you chose the CRA levels for each stream. Base your CRA levels on your understanding of the IC structure as documented by:a.The accounting processes (Designed well to mitigate introduction of errors into accounting system)b.The control procedures and management assertions covered by each control (overall coverage)c.The key controls that are in place (# of key controls in each stream)d.The Missing key controlse.Separation of Duties
3 attachmentsSlide 1 of 3attachment_1attachment_1attachment_2attachment_2attachment_3attachment_3.slider-slide > img { width: 100%; display: block; }
.slider-slide > img:focus { margin: auto; }
Unformatted Attachment Preview
COMPUTERIZED INTERNAL CONTROLS CASE
OWNCO, INC.
Objective: Part I Actual: Learn how to document and evaluate an entity’s internal
control structure. Specifically, document and evaluate the accounting processes and
controls and make a preliminary or planned Control Risk Assessment (CRA)
Material:
1.
2.
You will use and Excel Spreadsheet Ownco1.xlsx to document and
complete your internal control evaluation assignments.
Documentation for the sales stream in the revenue cycle is already mostly
completed and found in the Excel Spreadsheet “Ownco1.xlsx.” Download
ownco1.xlsx from the syllabus link on the class web page or from the
assignment page.
INSTRUCTIONS:
1.
Read Handout 1 (attached below): The company background,
computer processing overview, employee list, and narration of the
processes and controls in the revenue cycle are provided. ICE step
1, evaluation of internal control environment, has been done. It has
been determined that management override is not an issue and the
computer processing for this small company provides enough
foundation for reliance on computerized accounting controls. After
reading the background information, relate the sales stream
information to the documentation about the sales stream found on
Ownco1.xlsx. The Sales stream is a model or pattern you can use
to help you document the cash receipts stream.
2.
Using the information in Handout 1 on the cash receipts stream
document the accounting processes, controls, and make your
preliminary Control Risk Assessment (CRA) using the excel file
Ownco1.xlsx for the cash receipts stream.
a.
ICE Step 2: Document the accounting processes in the cash
receipts stream: Using the flowchart screen and excel’s
flowcharting tools, add the cash receipts stream process
symbols to the revenue cycle overview flowchart you
believe are necessary to adequately document the cash
receipts accounting processes. (Use the sales stream
flowchart as a model for how to complete the overview
flowchart.) Document only the processes, not the controls.
Also, in the process and control summary page fill out the
columns about personnel performing each process and
whether the process is manual or computerized.
b.
ICE Step 3: Document the controls in the cash receipts
stream. Make sure to include the AR GL because it is in
both the Sales and Cash Receipts stream. Using the
Process and Controls Summary worksheet, fill in the table
based on the narration concerning the controls. The
columns are as follows:
•
•
•
•
•
•
•
Control name(s) (if any controls exist) for each
process
Management Assertion(s) for each control
Person(s) performing control
Is Control Preventive or Detective?
How is control documented?
Compensating control (if any)–A Compensating
control is a control later in the overall processing
that “compensates for” the lack of any controls at a
particular process.
Location of each compensating control–What
accounting process does the compensating control
protect.
A list of controls and the list of management assertions and
the related descriptions of the controls and assertions are
found in other worksheet tabs. Make sure you complete all
the columns for the controls.
c.
Make Preliminary CRA
ICE Step 4a. Using the column for key controls in the
Processes and Controls Summary worksheet tab, identify
key controls for the cash receipts stream. Then review the
key controls on the Sales Stream and make changes as you
deem appropriate. Make sure you mark in the excel table
Process and Control Summary sheet which controls you
plan to rely on and test, that is, which controls you select as
key controls.
ICE Step 4b. Using the Control Risk Assessment
worksheet tab, record the risk category you believe is
appropriate given your documentation of the accounting
processes and controls. Make a preliminary CRA on the
cash receipts stream. The Sales stream is done, but
review it and change it if you wish. Your CRA will
include the management assertions Existence/Ocurrence,
Completeness, Valuation-Gross, combined into a
management assertion group. Finally, write a paragraph in
a word document for each stream (one paragraph for each
stream) explaining the reasons you chose the CRA levels
for each stream. Base your CRA levels on your
understanding of the IC structure as documented by:
a.
b.
c.
d.
e.
The accounting processes (Designed well to mitigate
introduction of errors into accounting system)
The control procedures and management assertions covered
by each control (overall coverage)
The key controls that are in place (# of key controls in each
stream)
The Missing key controls
Separation of Duties
Hand in Part I “Actual” Ownco documentation by uploading your excel and word files to the
assignment in the course Online system. Save the file with an A and you’re your last name and first
initial. (The A stands for Actual.”) Make sure your name is in the worksheet somewhere as the preparer.
HANDOUT 1
INTERNAL CONTROL EVALAUTION
OWNCO, INC.
BACKGROUND, SALES STREAM AND CASH RECEIPTS STREAM
Background – Understanding of the Control Environment
Ownco Inc. Manufactures plastic fishing worms at one location (Running Water,
Arkansas). Ed Jones, its sole owner, manages Ownco. Jones is responsible for marketing,
purchasing, hiring and approving major transactions. He has a good understanding of the
business and the industry in which it operates. Jones believes that hiring experienced
personnel is particularly important because there are no layers of supervisory personnel
and thus, because of limited segregation of duties, few independent checks of employees’
work. Jones has a moderate-to-conservative attitude toward business risks. The company
has demonstrated consistent profitability, and because Jones considers lower taxes to be
as important as financial results, he has a conservative attitude toward accounting
estimates.
Jones and Pat Willis, the bookkeeper, readily consult with our firm on routine accounting
questions, including the preparation of accounting estimates (tax accrual, inventory
obsolescence, or bad debts).
Family members compose the company’s board of directors. The board does not monitor
the business of the owner-manager’s activities
Pat Willis and Chris Ross, Jones’ secretary, perform most of the significant accounting
functions. The company hired Willis in 1990. She has a working knowledge of
accounting basics, and we have no reason to question her competence. Willis regularly
consults with our firm on unusual transactions, and history shows that it is rare for
adjustments to arise from errors in the processing of routine transactions.
The owner-manager carefully reviews computer-generated financial reports, such as
reports on receivables aging, and compares revenues and expenses with prior years’
performance. He also monitors the terms of the long-term debt agreement that requires
certain financial statement ratios and compensating balances. Our firm has determined
that management override of internal controls is NOT a concern.
Ownco uses late model microcomputers that are networked with windows. The company
uses a basic accounting software package (Quickbooks) that provides for three users. The
source code is not available for this software. A network printer was purchased with the
computer. The network maintenance and setup is outsourced to Digital Tech, Inc. and is
properly controlled so that only Willis, Ross and Jones have access to the accounting
system. Digital Tech, Inc., provided our firm with a copy of their Type I SAS 70 Audit
Report for their past year end. Our firm also has been granted “reports only” access
(cannot change any transactions) to Ownco’s Quickbooks accounting system. The backup
for the accounting and company files is also done automatically and regularly, and stored
offsite by the Digital Tech., Inc. For the computer controls, Jones is set as the master
administrator of the accounting system, with Willis as the company administrator. Ross
only has access to cash receipts recording but does not have access to general ledger nor
to cash disbursements or purchases. From an audit perspective, the computer
environment is determined to be simple (not complex) and IT audit is not necessary. The
IT environment does not provide any concerns from an audit perspective about the
computer accounting software and related computerized accounting controls. Our
completed Computer System Summary Evaluation is provided below.
Computer Processing Overview:
Company as a whole:
Is a third part service organization used to process all transactions involving computer
processing? No
Are the client’s computers in a dedicated physical area or facility? No
Is there a separate IT Department? No
Can separate users access the system concurrently? Yes
Is access control software used to restrict access to the production programs? Yes
Is access control software used to restrict access to the data files? Yes
Are reports generated by such software reviewed by management? Yes
Revenue Accounting Cycle:
Are transactions for this cycle processed by a third party service organization? No
Is this application PC-based? Yes
Does the client have the source code for the computer program used in this accounting
cycle? No
Do multiple applications share the same database files? No
Are there real-time updates to files when transactions are entered? Yes
Are telecommunications or networks used in this accounting cycle? Yes
Is physical access to computers controlled? No
Is the use of computers controlled by password? Yes
Are passwords protected and changed on a regular basis? Yes
Are system user rights transaction or application specific? Yes
Does the software in this accounting cycle generate transactions or pass information to
other transaction cycles? Yes
Is there significant loss of visible audit trail in the accounting cycle? No
Have there been any hardware or software malfunctions which resulted in a loss of data
in this accounting cycle? No
Ownco, Inc. Employees:
Amos, John
Warehouse picker
Tanner, Jeff
Shipping clerk
Deal, Robert Warehouse picker
Trout, Jack
Warehouse Supervisor
Jones, Ed
Owner-manager
Various
Sales representatives
Ross, Chris
Secretary of Ed Jones Willis, Pat
Bookkeeper
Sales Stream in Revenue Cycle
Sales in the current year ending September 30, 20XX were approximately $10,300,000.
The number of transactions was approximately 35,000.
At the time a sale is made, the sales representative enters information such as customer
name and number, shipping and inventory description, stock number, and price on a fourpart, prenumbered sales order (SO) form. Written explanations of price variances are
attached
The owner-manager (Ed Jones) reviews each SO for prenumbered sequence and proper
price, approves the extension of credit to the customer, and signs the sales order. The
bookkeeper receives SO copy No. 1. The warehouse, the sales representative, and the
customer receive the additional copies. Mr. Jones reviews sales orders after the fact on
return from being away from the office.
The bookkeeper receives approved SO copy No. 1 from the owner-manager and files
them numerically, pending receipt of the shipping report.
Upon receipt of SO copy No. 2, Jack Trout, the warehouse supervisor, ensures that the
owner-manager has signed the SO and then has the warehouse pickers, John Amos or
Robert Deal, pull the goods and prepares the shipping report.
The shipping clerk, Jeff Tanner, receives the shipping report, SO copy No. 2, and the
pulled goods from the warehouse. Jeff Tanner verifies that the goods agree with the SO
and the shipping report, initials the shipping report, prepares the goods for shipment and
ships the goods.
The bookkeeper receives the shipping report and matches it with SO copy No. 1. Copies
also go to the customer and to the warehouse supervisor (for filing in the warehouse
department).
The bookkeeper enters stock number, quantity, prices, and customer information into the
microcomputer.
The computer prints sales invoices. The bookkeeper matches computer-generated sales
invoices with sales orders and shipping reports for completeness. The bookkeeper also
investigates unmatched sales orders and shipping reports monthly. The customer receives
the original sales invoice (including a breakaway remittance advice).
The matched sales order, shipping report, and sales invoice are stapled together and filed
by sales invoice number.
At the end of the day, transactions are posted to the cumulative sales master file, the
accounts receivable master file, and the general ledger.
The owner-manager reviews sales reports and shipping reports weekly. The ownermanager reviews the aged trial balance twice monthly, and he follows up on past due
accounts. The owner-manager pays particular attention to accounts over 30 days past due.
Customers receive statements each month. The statements request the customers contract
Mr. Jones, the Owner-manager, for any disputed balances.
The bookkeeper reconciles the accounts receivable subsidiary ledger and cumulative
sales master file with the appropriate general ledger accounts monthly.
Cash Receipts Stream in Revenue Cycle
Chris Ross, the secretary, receives all checks and remittance advices. She prepares a
complete listing of all checks received. She retains the original list, and gives a copy to
Pat Willis the bookkeeper) along with the checks and remittance advices.
Willis prepares the bank deposit and adds the account code to each item listed on the
listing of checks received. She makes the bank deposit, and then gives Ross a copy of the
deposit slip, receipted by the bank.
Ross Compares the deposit slip with the original list of checks.
Willis enters customer and cash receipts information into the microcomputer using the
listing of checks with account codes. Willis runs the program that updates the accounts
receivable master file and cash receipts file daily. Transactions are posted to the general
ledger at the same time. The cash receipts journal, subledgers, and general ledger are
printed on demand.
Willis compares the computer-generated accounts receivable subsidiary ledgers with the
general ledger control account monthly. Willis also prepares the bank reconciliation
monthly, which Jones reviews.
ICE Step 1: Document and Evaluate Internal Control Environment (Management Override Potential and Computer Process
This Step has already been done. It has been determined that management override is not an issue and the computer proces
for this small company provides enough foundation for reliance on computerized accounting controls.
ICE Step 2a: Complete the Overview Flowchart (Document Main Accounting Processes and Control Points)
Using the Shapes inserts, complete the Overview flowchart for the Cash Receipts Stream Using the Process and Controls Narr
for the Cash Receipts Stream. The Sales Stream is already
completed for you. Just list the major steps or processes in the accounting sytem.
Connect the processes with arrows showing the flow of data
ICE Step 2a: Complete the Process section of the Process & Controls Summary (worksheet tab)
Add the process names to the Process & Controls Summary
Add whether each process is manual or computerized
Add the name of the person performing the Process.
ICE Step 3: Complete the Process & Controls Summary
Using the Narration for the Ownco, Inc. internal controls case, complete the Process and Controls Summary worksheet
The Sales Stream is already comleted for you. Use it as a general guide for completing the cash receipts transactions stream
ICE Step 4a: Complete the Key control column and select which controls you want to select as key.
A key control is a control that you as an auditor intend to rely on and one that you must test.
Step 4b. Complete your Preliminary Control Risk assessment in the Control Risk Assessment worksheet tab.
Select a risk category for each of the transaction streams. The sales stream preliminary CRA is already done, but
you need to review it and change it if you believe the indicated risk category is too low.
Potential and Computer Processing and Controls)
Sales General
Ledger
Accounts
Receivable
General
Ledger
Invoice
(Customer
Bill)
Account
Receivable
Master File
(Subledger)
Shipping
Ticket
Customer
Sales Order
Each Accounting process is the result of minor processes and
also serves as a control point where controls are “located” or
placed to prevent, detect, correct errors or irregularities.
Think of each accounting process not as a document but as
a set of necessary data for that accounting process.
Processess
Transaction Stream(s)
Information Form
(Accounting Process and
Control Point) Match to
names on overview
Flowchart
Manual or
Computerized?
Person(s) performing
Process
Sales
Sales Order
Manual
Various Sales Reps
Sales
Sales Order
Manual
Various Sales Reps
Sales
Shipping Report
Manual
Sales
Shipping Report
Manual
Amos & Deal Warehouse
Pickers
Amos & Deal Warehouse
Pickers
Sales
Invoice
Computerized
Pat Willis, bookkeeper
Sales
Invoice
Computerized
Pat Willis, bookkeeper
Sales
Invoice
Computerized
Pat Willis, bookkeeper
Sales
Sales
Invoice
Sales GL
Computerized
Computerized
Pat Willis, bookkeeper
Pat Willis, bookkeeper
Sales
Sales & Cash Receipts
Sales GL
Accounts Receivable GL
Computerized
Computerized
Pat Willis, bookkeeper
Pat Willis, bookkeeper
Sales & Cash Receipts
Accounts Receivable GL
Computerized
Pat Willis, bookkeeper
Sales & Cash Receipts
Accounts Receivable GL
Computerized
Pat Willis, bookkeeper
Sales & Cash Receipts
Accounts Receivable GL
Computerized
Pat Willis, bookkeeper
Sales & Cash Receipts
Accounts Receivable GL
Computerized
Pat Willis, bookkeeper
Controls
Control Name(s)
Can be more than one Control
for each Accounting Process
(If no controls exist for this
accounting process type “none
exist”)
Mgt Assertion(s) Satisfied by Control (can be more than one) (Mark yes, no or na for no
EO
C
Val G
Val N
O & AU
Checking manually the numerical sequence
n
of a ydocument, journal or
n report
na
n
Other: Review sales for proper
pricing and extention of credit
n
n
y
na
y
Matching to a previously
validated document: authorized
sales order and goods pulled
y
y
n
na
n
Reviewing Internal signatures
n
n
n
na
y
Software Access Controls
n
n
n
na
y
Interactive Feedback Edit
n
y
y
na
y
y
y
n
na
n
y
n
y
n
y
n
na
na
n
y
y
n
y
n
y
n
na
na
na
y
y
y
na
n
y
y
na
y
y
y
na
na
y
y
na
y
Matching to a previously
validated document: Sales order
and the shipping report
Review of Sales Reports and
Shipping report weekly
Software Access Controls
Computer generation of
Transactions
Software Access Controls
Balance GL with Subledgers: AR
subledger or AR master file
y
Other: All customer disputes are
directed to the Owner
y
Computer generation of
Transactions
y
Monthly Review of Receivables
y
Mark yes, no or na for not
P&D
Is Control
Preventive or
Person(s) performing Control Detective?
How is Control
Documented?
(If not
documented,
write “not
documented”)
na
Ed Jones Owner/manager
prevent
not documented
na
Ed Jones Owner/manager
detective
not documented
na
Jeff Tanner, Shipping Clerk and
Pat Willis, Bookkeeper
prevent
Jack Trout Jack Warehouse
Supervisor
prevent
na
Computer Program, Posting
prevent
auto
na
Pat Willis, Bookkeeper
prevent
not documented
na
Pat Willis, Bookkeeper
prevent
not documented
na
na
Ed Jones Owner/manager
Computer Program, Access
detective
prevent
not documented
auto
na
na
Computer Program, Posting
Computer Program, Access
prevent
prevent
auto
auto
na
Pat Willis, Bookkeeper
detective
not documented
na
Ed Jones Owner/manager
detective
not documented
na
Computer Program, Posting
prevent
auto
na
Ed Jones Owner/manager
detective
not documented
na
not documented
not documented
If no controls
exist for this
process, list
compensating
control(s) (if
any)
Location
(Accounting
Process) of
compensating
control (if any)
Do you
Select this
control as
a Key
Control?
(yes, no) Comments
yes
yes
yes
yes
yes
no
Process & control by same person
no
Process & control by same person
yes
yes
yes
yes
no
yes
yes
yes
Process & control by same person
Select a CRA for each transaction stream
(Mark an x for each column)
indicating which risk category
is appropriate for your preliminary
Control Risk Assessment (CRA)
Maximum Risk
Slightly Below Maximum Risk
Moderate Risk
Limited Risk
Your CRA applies to the Management assertions
Existence/Ocurrence, Completeness, Valuation-Gross
combined as a management assertion group.
Sales Stream
Cash Receipts Stream
X
Write a paragraph for each stream explaining the reasons you chose the CRA levels for each stream. Base your CRA
a.
The accounting processes
b.
The control procedures and management assertions covered by each control (overall coverage)
c.
The key controls that are in place including # of key controls for each stream
d.
The Missing key controls
e.
Separation of Duties
tream. Base your CRA levels on your understanding of the IC structure as documented by:
Name
Amos & Deal
Computer Program
Computer Program
Jones, Ed
Ross, Christ
Tanner, Jeff
Trout, Jack
Various
Willis, Pat
Title
Warehourse Pickers
Computer Posting
Computer Access
Onwer/Manager
Ed Jones Secretary
Shipping Clerk
Warehouse Supervisor
Sales Representatives
Bookkeeper
Name (A-Automated, M-Manual)
Balancing receivables subledger (M , A)
Balancing run to run control totals ( A)
Balancing the G/L with the subledgers ( M , A )
Cancelling original documents ( M , A )
Checking by computer for duplicate entries ( A )
Checking by computer the numerical sequence of a file ( A )
Checking for a third party signature ( M , A )
Checking manually the numerical sequence of a document,
journal or report ( M , A )
Checking one-to-one ( M , A )
Comparing batch totals ( M , A )
Comparison of budgeted amounts to actual amounts ( M , A )
Comparison of cash receipts listing to deposit slips ( M , A )
Computer generation of transactions ( A )
Dual control over cash receipts ( M , A )
Electronic authorization ( A )
Independent review of edit reports for data file changes ( M ,
A)
Interactive dependency edit ( A )
Interactive document reconciliation ( A )
Interactive edit controls ( A )
Interactive existence edit ( A )
Interactive feedback edit ( A )
Interactive format edit ( A )
Interactive key verification ( A )
Interactive mathematical accuracy check ( A )
Interactive prior data matching ( A )
Interactive reasonableness edit ( A )
Interactive Range Check Edit ( A )
Interactive check digit ( A )
Matching to a previously validated document ( M , A )
Matching to a previously validated file ( A )
Matching to an authorized list ( M , A )
Monthly review of bank reconciliations ( M , A )
Monthly review of payables ( M , A )
Monthly review of payroll ( M , A )
Monthly review of receivables ( M , A )
Non-interactive format edit ( A )
Non-interactive mathematical accuracy check ( A )
Non-interactive edit controls ( A )
Non-interactive existence edit ( A )
Non-interactive dependency edit ( A )
Non-interactive range check edit ( A )
Non-interactive reasonableness edit ( A )
Non-interactive prior data matching ( A )
Non-interactive check digit ( A )
Other ( M )
Password and authorization table checks ( A )
Performance of analytical procedures and investigation of
unusual items ( M , A )
Periodic reconciliation of books to physical ( M )
Periodic revision of budgeted amounts based on updated
information ( M , A )
Physical access controls ( M , A )
Physical safeguards ( M , A )
Prior approval required for disbursements greater than a
specified amount ( M , A )
Reconciliation of manual totals to run totals ( M , A )
Reconciliation of master file balance to control account ( A )
Reconciliation of master file balance to run totals ( A )
Reperformance ( M )
Restrictive endorsement on checks received ( M , A )
Reviewing adjustment transactions ( M , A )
Reviewing exception reports ( M , A )
Reviewing internal signatures ( M , A )
Reviewing reference file data ( M , A )
Review of supporting documents prior to check signing ( M ,
A)
Software access controls ( A )
Use of a lockbox ( M , A )
Use of a surprise payoff ( A )
Use of prerecorded input (OCR, MICR, OMR) ( A )
Verifying mathematical accuracy ( M , A )
Description
This control ensures that the receivables subsidiary ledger agrees with the day by day deposits and/or the
daily invoice register.
Balancing run to run control totals is a control method of determining completeness of update. The
following are some examples of how this control may be implemented. A control total is established
(field total, record count, etc) for each accepted transaction. The control total is recorded and
subsequently agreed to a total of updated transactions. The total of accepted items is manually agreed to
the total of items actually updated on the master file. The total of accepted items is reconciled by the
computer with the total of items updated on the master file. Totals are accumulated at various stages in
processing and reconciled to the updated transactions on the master file.
This control helps to ensure that the posting sources to the subsidiary ledgers agree with the posting
sources of the general ledger accounts. Any differences should be investigated.
This control prevents duplicate recording of transactions. To work adequately, when recording
transactions, original documents should be reviewed to ensure that no previously cancelled documents
are re-recorded.
This control is designed to ensure the completeness of a population by rejected data that has been
previously entered. This control can either reject the duplicate transaction on input or the computer
system may produce a duplicate transactions report which properly identifies duplicate transactions. If
the latter type of control is being used, the method used in correcting the identified duplicate
transactions is as important as the control itself.
This control ensures the completeness of a population of pre-numbered items. As an automated control,
the computer is actually checking to ensure that all numbers have been recorded. See “Checking
manually for the numerical sequence of a document, journal or report” for the manual equivalent of this
control.
The presence of the third party signature on documents is evidence. Checking for this signature is a
control to determine that performance has occurred prior to recording the transaction.
This control ensures the completeness of a population of pre-numbered items. To be effective, policies
should exist as to the procedures to follow in the case of missing documents. See “Checking by
computer of numerical sequence of a file” for the automated equivalent of this control.
This control consists of checking each individual document or source document with a detailed listing of
those items which were processed by the computer. To rely on this technique it is necessary to
determine that all documents have been submitted for processing. Completeness can be determined by
checking output with retained copies by sequence checking or by reconciling the number of documents
sent for processing with the number actually processed and accounting for all differences.
To ensure that all transactions being put into the computer have been properly input. The control should
ensure that all transactions are included in a batch and that all batches are processed. Rejects from the
batch process must be properly controlled to ensure that they are reprocessed.
Budgets, forecasts, performance reports and variance analysis reports are generally designed for control
purposes to highlight unexpected results and problem areas. Results that differ from expectations should
be investigated.
This control should include reviewing the recorded cash receipts to bank validated deposit slips for
amount and date. This ensures that the recorded cash receipts agree to those actually deposited in the
bank.
This control avoids the possibility of human error by having the computer generate transactions. For
this control to be effective, the generation of the transactions should be outside of the user’s control.
Additionally, some control should exist to ensure that the transactions generated were complete and
accurate. For example, the transactions generated should be reviewed prior to production of the
documents or control totals should be used.
This control assumes that two persons are present when the cash on hand or current receipts are counted.
Generally, a list is prepared of the amounts and this list is signed by both individuals.
To permit the authorization of a transaction on a magnetic file. A password should exist for each
supervisor who can carry out this type of transaction.
Details of data file activity should be maintained in the form of an edit report. For example, an
organization may maintain a log of date and time of last update, name of file which was used in update
(if any), or unauthorized attempts to read to change records in the file. This log should be reviewed
periodically by an individual independent of the individual who performed the process.
This accuracy control determines whether the contents of two or more data elements (fields) on a
transaction bear the correct logical relationship. For example, when entering the details of a loan
agreement, there should be a logical relationship between the amount advanced, the number of payments
to be made, and the payment amount.
This control involves checking the mathematical accuracy of the entry of numeric data. Each transaction
is treated as a batch. Prior to entry, a hash total is established for all important numeric data elements
(quantity, unit cost, amount, etc.) for the document. The total is recorded on the document and entered
into the system. Once information has been entered from the document, the program totals the numeric
data elements and compares the result with the hash total. Transactions that do not balance are not
accepted.
These controls exist only in an EDP environment. They are automated controls to ensure the accuracy
and completeness of data input into a system and/or the proper authorization of the transaction. An
interactive control is a control that involves responses and prompts between the user and the application
program.
The objective of this control is to ensure that data entered agrees with valid data held on the file or in
the program. As an example, when purchase invoices are processed, they require the allocation of
general ledger account numbers and an accounts payable numbers. On input, the program checks that
the numbers entered exist as valid account numbers in the general ledger and accounts payable ledgers.
Items that do not match will not be accepted.
This control uses one or more pieces of information input by the user to provide the user with more
complete information, thus assuring the accuracy of the initial input. For example, the sales clerk inputs
the customer number, product number, and quantity ordered into the sales order system. The customer
name, customer address, product description, quantity ordered, unit price and total dollar value appear
on the terminal. The clerk verifies the preceding information before releasing the information to the
system.
This completeness control checks the format (existence of expected numeric or alphanumeric characters)
of a transaction to ensure that all required data is present. All numeric data should properly be subjected
to format checks. However, since the edit is only checking for a certain format, it is unlikely that the
control will be of much help in controlling the accuracy of the input. For example, a format edit on a
date field on entry will determine that the format of the date is proper. It will not determine that date
being used is correct.
Key verification is a common technique for controlling the conversion of infor


