Auditing, 12e Chapter 3: Internal Control Over Financial Reporting: Responsibilities of Management and the External Auditor Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 1 Learning Objectives (1 of 2) LO 1 Articulate the importance of internal control over financial reporting. LO 2 Discuss the definition and components of internal control based on COSO’s 2013 Internal Control–Integrated Framework. LO 3 Explain the control environment component of internal control. LO 4 Explain the risk assessment component of internal control. LO 5 Explain the control activities component of internal control. Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 2 Learning Objectives (2 of 2) LO 6 Explain the information and communication component of internal control. LO 7 Explain the monitoring component of internal control. LO 8 Identify management’s responsibilities related to internal control over financial reporting. LO 9 Distinguish between material weaknesses, significant deficiencies, and control deficiencies in internal control over financial reporting. LO 10 Identify the external auditor’s responsibilities related to internal control over financial reporting. Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 3 Why It Matters Companies with Repeated Instances of ICMWs • The SEC made an example of four companies that had failed to remediate (i.e., correct) very important problems with their internal controls over a long period − Cytoden, Inc. - Biotech; 9 years of ICMWs; penalty = $35,000 − Digital Turbine - Technology services; 7 years of ICMWs; penalty = $100,000 − Grupo Simec - Iron and steel; 10 years of ICMWs; penalty = $200,000 − Lifeway Foods - Cultured dairy product; 9 years of ICMWs; penalty = $100,000 • The SEC was making a point: “Inadequate internal controls are the first line of defense in detecting and preventing material errors or fraud ... when internal control deficiencies are left unaddressed, financial reporting quality can suffer” (see https://www.sec.gov/news/pressrelease/2019-6) Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 4 LO 1: Importance of Internal Control Over Financial Reporting • Internal control helps an organization mitigate the risks of not achieving its objectives. • Examples of objectives include − Achieving profitability − Ensuring efficient operations − Manufacturing high-quality products/providing high-quality services − Conducting operations and employee relations in a socially responsible manner Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 5 What Do You Think? (p. 127) • Evaluate the following potential rationalizations that companies in the Why It Matters feature might have used to explain delays in remediating ICMWs, and provide counterarguments: − I’m trying to run a business, not set up a system of internal controls. Remediation is a distraction from my goal of earning a profit. − Remediating internal control material weaknesses is really expensive. Any potential SEC fine will surely cost less than remediation. − Worrying about internal controls is the auditor’s problem, not mine. − Nobody but regulators and auditors care about internal controls. Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 6 Check Your Basic Knowledge (3-1 and 3-2) 3-1 Effective internal control over financial reporting allows users to make informed decisions about financial disclosures. (T/F) T 3-2 Management needs to understand risks to reliable financial reporting before determining the internal controls that would be helpful to achieving reliable financial reporting. (T/F) T Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 7 Check Your Basic Knowledge (3-3) 3-3 Which of the following are affected by the quality of an organization’s internal controls? a. Reliability of financial data. b. Ability of management to make informed business decisions. c. Ability of the organization to remain in business. d. All of the above. d e. Only a and c. Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 8 Check Your Basic Knowledge (3-4) 3-4 Which of the following creates an opportunity for committing fraudulent financial reporting in an organization? a. Management demands financial success. b. Poor internal control. c. Commitments tied to debt covenants. b d. Management is aggressive in its application of accounting rules. Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 9 LO2: Defining Internal Control • Internal control - A process designed to provide reasonable assurance regarding the achievement of operations, reporting, and compliance objectives • Components of internal control − Control environment − Risk assessment − Control activities − Information and communication − Monitoring Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 10 Exhibit 3.1 - COSO Framework for Internal Control Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 11 Entity-Wide Controls • Entity-wide controls: Affect multiple processes, transactions, accounts, and assertions • Controls related to the control environment • Controls over management override • The organization’s risk assessment process • Centralized processing and controls • Controls to monitor results of operations and to monitor other controls • Controls over the period-end financial reporting process • Policies related to business control and risk management practices Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 12 Transaction Controls • Transaction controls: Control activities that typically affect only certain processes, transactions, accounts, and assertions • Common examples − Segregation of duties over cash receipts and recording − Authorization procedures for purchasing − Adequately documented transaction trail for all sales transactions − Physical controls to safeguard assets such as inventory − Reconciliations of bank accounts Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 13 What Do You Think? (p. 130) • Of the five components of internal control in the COSO Framework, which two, in your opinion, are the most important? • Explain your rationale, along with explaining how a weakness in that component could result in either misappropriation of assets or fraudulent financial reporting. Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 14 Check Your Basic Knowledge (3-5 and 3-6) 3-5 The purpose of internal control is to provide absolute assurance that an organization will achieve its objective of reliable financial reporting. (T/F) 3-6 Organizations F use the GAAP framework of internal control as a benchmark when assessing the effectiveness of internal control over financial reporting. (T/F) F Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 15 Check Your Basic Knowledge (3-7) 3-7 What are the components of internal control per COSO’s Internal Control– Integrated Framework? a. Organizational structure, management philosophy, planning, risk assessment, and control activities. b. Control environment, risk assessment, control activities, information and communication, and monitoring. c. Risk assessment, control structure, backup facilities, responsibility accounting, and natural laws. b d. Legal environment of the firm, management philosophy, organizational structure, control activities, and control assessment. Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 16 Check Your Basic Knowledge (3-8) 3-8 Which of the statements regarding internal control is false? a. Internal control is a process consisting of ongoing tasks and activities. b. Internal control is primarily about policy manuals, forms, and procedures. c. Internal control is geared toward the achievement of multiple objectives. d. A limitation of internal control is faulty human judgment. e. All of the above statements are true. b Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 17 LO 3: Control Environment • Control environment: The set of standards, processes, and structures that provides the basis for carrying out internal controls across the organization • Foundation for all other components of internal control • Leadership culture of the organization—tone at the top − Importance of internal control and expected standards of conduct − Reinforced throughout the organization • Strong control environment is important line of defense against the risks related to financial statement reliability • Deficiencies in the control environment are associated with many financial frauds Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 18 Exhibit 3.2 - Control Environment— COSO Principles 1. Commitment to integrity and ethical values 2. The board of directors exercises oversight responsibility 3. Management establishes structure, authority, and responsibility 4. The organization demonstrates commitment to competence 5. The organization enforces accountability Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 19 Indicators of a Weak Control Environment • An ineffective board of directors that top management dominates • Management teams that focus on increasing the stock price as a basis for either expanding the organization or personally enriching themselves through stock compensation • An audit committee that does not have independent members or sufficient power • The absence of an ethics policy or lack of reinforcement of ethical behavior • A management team that overrides controls or acts unethically • Personnel who do not have the expertise necessary to carry out their assigned tasks • A lack of understanding within the organization about the importance of controls Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 20 Check Your Basic Knowledge (3-9 and 3-10) 3-9 The control environment component of internal control is a pervasive or entity-wide control because it affects multiple processes and multiple types of transactions. (T/F) T 3-10 Corporate culture is an element of the monitoring component of the COSO Framework. (T/F) F Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 21 Check Your Basic Knowledge (3-11) 3-11 Which of the following is not a principle of an organization’s control environment? a. Independence and competence of the board. b. Competence of accounting personnel. c. Structures, reporting lines, and authorities and responsibilities. d. Commitment to integrity and ethical values. e e. The organization considers the potential for fraud in assessing risks to the achievement of objectives. Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 22 Check Your Basic Knowledge (3-12) 3-12 Which one of the following is false regarding kickbacks? a. A kickback is an illegal payment made by a customer to a supplier giving the customer preferential treatment from the supplier. b. A kickback is an illegal payment made by a supplier to a customer giving the supplier preferential treatment from the customer. c. A kickback is typically paid in the form of cash or merchandise but can also be paid in the form of stock options. d. A kickback is a type of bribery. a e. Two of the above (a-d) are false. Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 23 LO 4: Risk Assessment • Risk assessment: The process for identifying the risks that may affect an organization from achieving its objectives • Risk is the possibility that an event will adversely affect the organization’s achievement of its objectives. Risk comes from both internal and external sources • Examples of internal risks: − Changes in management responsibilities − Changes in information technology − Poorly conceived business model • Examples of external risks: − Economic recessions − Increases in competition − Development of substitute products or services − Changes in regulation Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 24 Exhibit 3.3 - Risk Assessment— COSO Principles 6. The organization specifies objectives with sufficient clarity to enable the identification and assessment of risks relating to objectives 7. The organization identifies risks to the achievement of its objectives across the entity and analyzes risks as a basis for determining how the risks should be managed 8. The organization considers the potential for fraud in assessing risks to the achievement of objectives 9. The organization identifies and assesses changes that could significantly impact the system of internal control Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 25 Check Your Basic Knowledge (3-13 and 3-14) 3-13 Auditors will judge a misstatement as material if they can prove that it affected economic decisions of users. (T/F) F 3-14 An organization’s risk assessment process should identify risks to reliable financial reporting from both internal and external sources. (T/F) T Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 26 Check Your Basic Knowledge (3-15) 3-15 Which of the following statements is false regarding the risk assessment component of internal control? a. Risk assessment includes assessing fraud risk. b. Risk assessment includes assessing internal and external sources of risk. c. Risk assessment includes the identification and analysis of significant changes. d d. Economic changes would not be considered a risk that needs to be analyzed as part of the risk assessment process. Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 27 Check Your Basic Knowledge (3-16) 3-16 Which of the following is not part of management’s fraud risk assessment process? a. The assessment considers ways the fraud could occur. b. The assessment considers the role of the external auditor in preventing fraud. c. Fraud risk assessments serve as an important basis for determining the control activities needed to mitigate fraud risks. b d. The assessment considers pressures that might lead to fraud in the financial statements. Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 28 LO 5: Control Activities • Control activities: The actions that have been established by policies and procedures. • Actions established through policies and procedures that help ensure that management’s directives regarding controls are accomplished • Performed within processes (e.g., segregation of duties required in processing cash receipt transactions) and over the technology environment • Preventive or detective • Manual or automated Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 29 Exhibit 3.4 - Control Activities— COSO Principles 10. The organization selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels 11. The organization selects and develops general control activities over technology to support the achievement of objectives 12. The organization deploys control activities through policies that establish what is expected and in procedures that put policies into action Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 30 Implications of Weak Controls - Money Laundering (including Exhibit 3.6) • Money laundering: The criminal activity of processing illegally obtained proceeds in order to disguise the source of their origination in order to then use the money openly without alerting authorities Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 31 Check Your Basic Knowledge (3-17 and 3-18) 3-17 Top management is responsible for conducting a daily monitoring of any attempts to compromise the internal control system. (T/F) F 3-18 Money laundering occurs when the criminal completes the following processes after obtaining “dirty money”: placement, layering, and integration. (T/F) T Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 32 Check Your Basic Knowledge (3-19) 3-19 Which of the following scenarios provides the best example of segregation of duties? a. Employees perform multiple jobs and have access to related records. b. The internal audit function performs an independent test of transactions throughout the year and reports any errors to departmental managers. c. The person responsible for reconciling the bank account is responsible for cash disbursements but not for cash receipts. d d. The payroll department cannot add employees to the payroll or change pay rates without the explicit authorization of the Human Resources Department. Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 33 Check Your Basic Knowledge (3-20) 3-20 Which of the following statements about application controls is true? a. Organizations can have manual application controls or automated application controls, but not a combination of the two. b. Application controls are intended to mitigate risks associated with data input, data processing, and data output. c. Application controls are a part of the monitoring component of internal control. d. Self-checking digits are an output control. b Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 34 LO 6: Information and Communication • Information and communication: Recognizes that information is necessary for an organization to carry out its internal control responsibilities • Refers to the process of identifying, capturing, and exchanging information in a timely fashion to enable accomplishment of the organization’s objectives • Includes the organization’s accounting system and methods for recording and reporting on transactions, as well as other communications such as key policies, code of conduct, and strategies Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 35 Exhibit 3.7 - Information and Communication—COSO Principles 13. The organization obtains or generates and uses relevant, quality information to support the function of internal control 14. The organization internally communicates information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control 15. The organization communicates with external parties regarding matters affecting the functioning of internal control Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 36 What Do You Think? (p. 149) • The SEC has been actively trying to incentivize people who know about financial misreporting to disclose that information to the SEC. • Learn more about the SEC’s whistle-blowing function by visiting the following link: https://www.sec.gov/whistleblower − Be prepared to discuss any recent whistle-blowing activities described on the SEC website. • The SEC website makes it clear that the SEC will provide financial rewards to whistle-blowers. − What are some potential downside risks to whistle-blowing? Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 37 Check Your Basic Knowledge (3-21 and 3-22) 3-21 An organization’s accounting system is part of its information and communication component of internal control. (T/F) T 3-22 A whistle-blower is a governmental organization that exposes information or activity about an individual who is committing illegal, immoral, illicit, unsafe, or fraudulent activities. (T/F) F Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 38 Check Your Basic Knowledge (3-23) 3-23 Which of the following is an effective implementation of the information and communication component of COSO’s Internal Control–Integrated Framework? a. The organization has one-way communication with parties external to the organization. b. The organization has a whistle-blower function that allows parties internal and external to the organization to communicate concerns about possible inappropriate actions in the organization’s operations. c. The organization has a robust process for assessing risks internal and external to the organization. d. The organization builds in edit checks to determine whether all purchases are made from authorized vendors. e. All of the above. b Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 39 Check Your Basic Knowledge (3-24) 3-24 Which of the following is not a principle of the information and communication component of COSO’s Internal Control–Integrated Framework? a. The organization identifies, obtains, and uses relevant information. b. The organization communicates internally. c. The organization communicates externally. d d. All of the above are principles of the information and communication component of COSO’s Internal Control–Integrated Framework. Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 40 LO 7: Monitoring • Monitoring: A necessary function to determine whether the controls, including all five components of the COSO Framework, are present and continuing to function effectively • Monitoring is a process that provides feedback on the effectiveness of each of the five components of internal control. • Management selects a mix of ongoing evaluations, separate evaluations, or some combination of the two to accomplish monitoring. • Monitoring requires that identified deficiencies in internal control are communicated to appropriate personnel and follow-up action be taken. Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 41 Exhibit 3.8 - Monitoring—COSO Principles 16. The organization selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning 17. The organization evaluates and communicates internal control deficiencies in a timely manner to those parties responsible for taking corrective action, including senior management and the board of directors, as appropriate Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 42 Check Your Basic Knowledge (3-25 and 3-26) 3-25 As part of monitoring, an organization will select either ongoing evaluations or separate evaluations, but not both. (T/F) F 3-26 Communicating identified control deficiencies is a principle of monitoring. (T/F) T Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 43 Check Your Basic Knowledge (3-27) 3-27 Which of the following is not an effective implementation of the monitoring component of COSO’s Internal Control–Integrated Framework? a. Internal audit periodically works to improve internal controls. b. Management reviews current economic performance against expectations and investigates to determine causes of significant deviations from the expectations. c. The organization implements software that captures all instances in which the underlying program identifies processed transactions that exceed company-authorized limits. d. The organization builds in edit checks to determine whether all purchases are made from authorized vendors, and flags those that are not. a Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 44 Check Your Basic Knowledge (3-28) 3-28 Which of the following is the most accurate statement related to the monitoring component of COSO’s Internal Control–Integrated Framework? a. Monitoring is a process that is relevant only to the control activities component of COSO’s Internal Control–Integrated Framework. b. Separate evaluations are more timely than ongoing evaluations in identifying control deficiencies. c. Monitoring is a process that provides feedback on the effectiveness of each component of internal control. c d. Monitoring includes automated edit checks to determine whether all purchases are made from authorized vendors. Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 45 LO 8: Management’s Responsibilities for Internal Control Over Financial Reporting • Management is the primary party responsible for achieving reliable financial reporting. • Management accomplishes this by − Overseeing the design, implementation, and maintenance of effective internal control over financial reporting − Maintaining adequate documentation relating to these internal controls − For US public companies, reporting on the effectiveness of the organization’s internal control over financial reporting Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 46 Management’s Responsibilities Under the Foreign Corrupt Practices Act (FCPA) • The FCPA prohibits paying bribes to foreigners to obtain or retain business; companies doing business outside the US need to have controls in place to comply with the FCPA. • Typical controls management implements to ensure compliance − Individuals who have the power to initiate payments for expenses have the authority to do so − Internal control system ensures accurate recording of transactions and monitors for unusual transactions or unauthorized changes in approved vendor list − Approvals for transactions include supporting documentation − Management tests processes routinely and in a timely manner − Records of individual or organizations who receive assets or cash are maintained − Proper payroll controls are maintained and management monitors changes to payroll amounts and processes for adding employees Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 47 Management’s Responsibilities Under Section 302 of the Sarbanes-Oxley Act • Section 302 applies to US publicly traded companies • Articulates management’s responsibilities for internal control • Places specific requirements on the officers of the company who sign the financial statements, usually including the CEO and CFO Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 48 Evaluating Internal Control Over Financial Reporting • SEC’s guidance for management − Encourages a risk-based approach to evaluation • Steps in management’s evaluation − Identify financial reporting risks and controls implemented to mitigate those risks − Evaluate the operating effectiveness of internal control over financial reporting − Provide report on effectiveness of internal control over financial reporting Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 49 Exhibit 3.9 - Evaluating Internal Control Over Financial Reporting Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 50 Exhibit 3.10 - Approaches to Management Test of Operating Effectiveness of Controls Control to Be Tested Possible Management Test Approach Formal forecasts are prepared and updated during the year to reflect changes in conditions, estimates, or current knowledge Review most recent corporate budget and current forecasts; inquire of those responsible for preparing and updating forecasts The organization’s written and approved disaster Review plan and third-party vendor contract; confirm recovery plan includes off-site storage controlled by a off-site storage arrangement with vendor; obtain third-party vendor evidence of approval of plan Organization policy requires a revenue recognition review before revenue from complex contracts is recorded Review policy; for selected transactions review documentation or reperform the review Surveys assess internal user satisfaction with the reliability and timeliness of reporting Obtain and review user surveys; interview users Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 51 Management Documentation of Internal Control • Guidelines for developing reliable paper and electronic documentation related to internal control include − Prenumbered paper or computer-generated documents facilitate the control of, and accountability for, transactions and are crucial to the completion assertion − Timely preparation improves credibility and accountability of documents − Evidence of authorization of transactions − A transaction trail that allows a user, or auditor, to trace a transaction from origination to final disposition or vice versa Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 52 Exhibit 3.11 - Important Aspects of an Electronic Transaction Trail • Unique identification of transaction • Date and time of transaction • Individual responsible for the transaction • Location from which the transaction originated • Details of the transaction • Cross-reference to other transactions • Authorization or approval of the transaction Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 53 Check Your Basic Knowledge (3-29 and 3-30) 3-29 Management of US public companies may provide a public report on the effectiveness of their organization’s internal control over financial reporting, but management is not required to do so. (T/F) F 3-30 As part of a walkthrough, management will follow a transaction from origination to when it is reflected in the financial records to determine whether the controls are effectively designed and have been implemented. (T/F) T Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 54 Check Your Basic Knowledge (3-31) 3-31 Which of the following statements is false regarding management’s documentation of internal control over financial reporting? a. Management needs to maintain sufficient and appropriate documentation of the internal controls they have designed and implemented to achieve the objective of reliable financial reporting. b. Internal control documentation is useful in training new personnel or serving as a reference tool for all employees. c. Management only needs to maintain documentation if the company’s auditors will be providing an opinion on internal control effectiveness. c d. Documentation provides evidence that the controls are operating. Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 55 Check Your Basic Knowledge (3-32) 3-32 Which of the following is not included in management’s report on internal control? a. A statement that management is responsible for internal control. b. A definition of internal control. c. A discussion of the limitations of internal control. d. The criteria used in assessing internal control. e e. A description of the work that the internal auditors performed. Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 56 LO 9: Assessing Deficiencies in Internal Control Over Financial Reporting • Control deficiency: a shortcoming in internal control such that the objective of reliable financial reporting may not be achieved • Significant deficiency: important enough that it should be brought to the attention of management and the audit committee, but it does not need to be reported to external users • Material weakness: a deficiency in internal control over financial reporting for which there is a reasonable possibility that a material misstatement of the company’s annual or interim financial statements will not be prevented or detected on a timely basis (ICMW) Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 57 Exhibit 3.13 - Assessing Likelihood and Magnitude of Potential Misstatements (1 of 2) • Factors affecting the likelihood that a deficiency, or a combination of deficiencies, will result in a misstatement include: − Nature of the financial statement accounts, disclosures, and assertions involved − Susceptibility of the related asset or liability to loss or fraud − Subjectivity, complexity, or extent of judgment required to determine the amount involved − Interaction or relationship of the control with other controls, including whether they are interdependent or redundant − Interaction of the deficiencies − Possible future consequences of the deficiency Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 58 Exhibit 3.13 - Assessing Likelihood and Magnitude of Potential Misstatements (2 of 2) • Factors affecting the magnitude of a potential misstatement resulting from a deficiency or a combination of deficiencies include: − Financial statement amounts or total of transactions exposed to the deficiency − Volume of activity in the account balance or class of transactions exposed to the deficiency that has occurred in the current period or that is expected in future periods Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 59 Exhibit 3.14 – Examples of Material Weaknesses in Internal Control Over Financial Reporting (1 of 3) • Weaknesses in the design of controls − Absence of appropriate segregation of duties over important processes − Absence of appropriate reviews and approvals of transactions, accounting entries, or systems output − Inadequate controls to safeguard assets − Absence of controls to ensure that all items in a population are recorded − Inadequate processes to develop significant estimates affecting the financial statements; for example, estimates for pensions, warranties, and other reserves − Undue complexity in the design of the processing system that obfuscates an understanding of the system by key personnel − Inadequate controls over access to computer systems, data, and files Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 60 Exhibit 3.14 – Examples of Material Weaknesses in Internal Control Over Financial Reporting (2 of 3) • Weaknesses in the design of control − Inadequate controls over computer processing − Inadequate controls built into computer processing • Weaknesses in the operation of controls − Independent tests of controls at a division level indicate that the control activities are not working properly; for example, purchases have been made outside of the approved purchasing function − Controls fail to prevent or detect significant misstatements of accounting information − Misapplication of accounting principles − Testing reveals evidence that accounting records have been manipulated or altered Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 61 Exhibit 3.14 – Examples of Material Weaknesses in Internal Control Over Financial Reporting (3 of 3) • Weaknesses in the operation of controls − Credit authorization processes overridden by the sales manager to achieve sales performance goals − Reconciliations (1) not performed on a timely basis or (2) performed by someone independent of the underlying process − Evidence of misrepresentation by accounting personnel − Computerized controls leading to items identified for nonprocessing that are systematically overridden by employees to process the transactions − The completeness of a population—for example, prenumbered documents or reconciling items logged on to the computer with those processed—not accounted for on a regular basis Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 62 What Do You Think? (p. 161) • If a deficiency is significant, shouldn’t users of the financial statements know about it? • Why do you think the PCAOB decided not to require significant deficiencies to be transparent to the market and users? • How do you think that auditors and management would react to requiring that significant deficiencies be transparent (i.e., disclosed to users of the financial statements)? Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 63 What Do You Think? (pp. 162-163) • Refer to the What Do You Think feature about Newell Brands on pages 162-163. − Would the internal control material weaknesses that management describes affect your decision to invest in the company? − Do you think that management’s remediation plan will be effective? Why or why not? − Search www.sec.gov for Newell’s 2021 annual report to see if the material weaknesses that they report in 2020 are now remediated. If they are not yet remediated, check to see if the same material weaknesses exist, or if new material weaknesses have emerged. − Investigate Newell’s stock price over the past five years and comment on the trends. Speculate as to how the trends may relate, in part, to the existence of internal control material weaknesses. Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 64 Check Your Basic Knowledge (3-33 and 3-34) 3-33 If management identifies even one material weakness in internal control, then management will conclude that the organization’s internal control over financial reporting is not effective. (T/F) T 3-34 Management will classify a control deficiency as a material weakness only if there has been a material misstatement in the financial statements that will result in a restatement. (T/F) F Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 65 Check Your Basic Knowledge (3-35) 3-35 Assume that an organization sells software. The sales contracts with the customers often have nonstandard terms that impact the timing of revenue recognition. Thus, there is a risk that revenue may be recorded inappropriately. To mitigate that risk, the organization has implemented a policy that requires all nonstandard contracts greater than $1 million to be reviewed on a timely basis by an experienced and competent revenue accountant for appropriate accounting, prior to the recording of revenue. Management has classified this deficiency as a material weakness. Which of the following best describes the conclusion made by management? a. There is more than a remote possibility that a material misstatement could occur. b. The likelihood of misstatement is reasonably possible. c. There is more than a remote possibility that a misstatement could occur. d. There is a reasonable possibility that a material misstatement could occur. e. There is a reasonable possibility that a misstatement could occur. d Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 66 Check Your Basic Knowledge (3-36) 3-36 Which of the following scenarios represents a control deficiency? a. A missing control that is required for achieving objectives. b. A control that operates as designed. c. A control that provides reasonable, but not absolute assurance, about the reliability of financial reporting. d. An immaterial individual misstatement in internal. a e. None of the above. Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 67 LO 10: The External Auditor’s Responsibilities for Internal Control Over Financial Reporting • The auditor needs to understand a client’s internal controls in order to: − Anticipate the types of material misstatements that may occur − Develop appropriate audit procedures to determine whether those misstatements exist in the financial statements • Ineffective internal controls − If a client has ineffective internal controls, the auditor will plan the audit with this in mind Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 68 Additional Auditor Responsibilities • Under Section 404 of Sarbanes-Oxley, auditors of large public companies − Perform an integrated audit (an audit of the financial statements and of internal controls) − Must provide an opinion on the effectiveness of the client’s internal control over financial reporting in addition to the opinion on the financial statements • Under ASB (US private companies) and IAASB (International) standards − Do not have to express an opinion on the effectiveness of internal control Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 69 Check Your Basic Knowledge (3-37 and 3-38) 3-37 Under PCAOB standards, public company auditors will issue a report on internal controls, but under IAASB standards, public company auditors will not do so. (T/F) T 3-38 If the auditor concludes that there exists one or more material weaknesses in internal control over financial reporting, the auditor will automatically conclude that they cannot issue an unqualified opinion on the financial statements. (T/F) F Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 70 Check Your Basic Knowledge (3-39) 3-39 Which of the following is a reason that the auditor obtains an understanding of the client’s internal control over financial reporting? a. This understanding is required by professional auditing standards. b. Understanding of internal control is needed to properly plan the audit. c. This understanding helps an auditor assess a client’s risk of material misstatement. d d. All of the above are reasons why the auditor obtains an understanding of the client’s internal control over financial reporting. Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 71 Check Your Basic Knowledge (3-40) 3-40 Which of the following statements is true regarding the auditor’s assessment of a client’s internal control over financial reporting? a. The auditor reviews management’s documentation of its internal control and management’s evaluation and findings related to internal control effectiveness. b. The auditor’s assessments of control deficiencies will be the same as management’s assessment of the same deficiencies. c. In testing controls, the auditor is only concerned about the client’s control environment and risk assessment. d. All of the above are true. a Zehms/Gramling/Rittenberg, Auditing: A Risk-Based Approach, 12th Edition. ©2024 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 72
0
You can add this document to your study collection(s)
Sign in Available only to authorized usersYou can add this document to your saved list
Sign in Available only to authorized users(For complaints, use another form )