ACCA Applied Skills · Audit and Assurance
The use and evaluation of systems of internal control by auditors: formula sheet
Key formulas
- Five components of internal control
- Control environment + Risk assessment + Information system + Control activities + Monitoring
- Use this as a checklist. Name each component and tie it to the scenario.
- Control objectives
- Efficiency + Safeguarding assets + Preventing and detecting fraud and error + Reliable records + Timely reliable information
- Use these to say what a control is for.
- Main limitations
- Human error + Collusion + Management override + Cost versus benefit + Unusual transactions + Outdated controls
- Controls give reasonable assurance only, never absolute.
- Two questions on each control
- Understanding = Design (is it suitable?) + Implementation (is it in use?)
- Operating effectiveness over the period is a separate matter, tested by tests of controls.
- Walkthrough test
- One transaction traced from initiation → recording → reporting
- Used to confirm understanding and that controls are implemented. It is not enough on its own to prove controls operate effectively.
- ICQ vs ICE
- ICQ: "Is the control there?" | ICE: "Is the objective met, and what control is missing?"
- Both highlight weaknesses. ICE is aimed at the control objectives.
- Documentation methods
- Narrative notes | Flowcharts | ICQ | ICE
- Choose by system size and complexity. Often more than one is combined.
- Control objective to activity link
- Risk (what could go wrong) → Control objective → Control activity → Test of control
- Use this chain to structure any answer. Never give a control without the risk it addresses.
- Core segregation of duties
- Authorisation ≠ Recording ≠ Custody (independent reconciliation or review is added good practice, not a required fourth person)
- If one person does two of these, there is a risk that fraud or error goes unnoticed. It may be a deficiency unless compensating controls exist, for example close management review in a small entity. Independent reconciliation or review strengthens the control but does not need a separate fourth person.
- Types of control
- Preventive (stop it happening) vs Detective (find it afterwards)
- Examiners often ask which type a control is. A bank reconciliation is detective; an approval before payment is preventive.
- Sales cycle key controls
- Order → credit check → despatch (GDN) → invoice → record → receipt → reconcile
- Match documents at each step and sequence check them to check completeness.
- Purchases cycle key controls
- Requisition → authorised order → goods received note → match order, GRN and invoice → approve → pay
- The three-way match is the key control against paying for goods not ordered or not received.
- Payroll cycle key controls
- HR approves joiners and leavers → hours authorised → payroll prepared → independent review → payment
- Targets fictitious employees, wrong rates and unauthorised changes.
- Three-column test for each point
- Deficiency → Consequence → Recommendation
- Each row must link: the recommendation fixes the stated deficiency, and the consequence follows from it.
- Significant deficiency (ISA 265)
- Significant deficiency = important enough, in the auditor's judgement, to merit the attention of those charged with governance
- Consider likelihood, potential size of misstatement, fraud risk and compensating controls.
- Who is told
- Significant deficiencies: in writing to those charged with governance. Other deficiencies: to management.
- Communicate on a timely basis. Management are also told of significant ones.
- Content of written report
- Description + potential effects + statement that the audit was not designed to find all deficiencies
- Management responses can be included.
- Controls effective
- Controls operate effectively → lower control risk → higher detection risk acceptable → less substantive work
- Detection risk is the part of audit risk the auditor controls through substantive work. Higher acceptable detection risk means fewer or lighter substantive procedures.
- Controls ineffective
- Controls fail → higher control risk → lower detection risk required → more substantive work
- Do more, larger and later tests, nearer the year end.
- Audit risk model
- Audit risk = Risk of material misstatement × Detection risk
- Risk of material misstatement = inherent risk × control risk. Used as a conceptual model, not a calculation.
- Effect on substantive work
- Nature, timing and extent
- Use these three words to structure any answer on how control test results change the audit.
- Two types of substantive procedure
- Substantive procedures = tests of detail + substantive analytical procedures
- Tests of controls are not substantive procedures.
- General IT controls (areas)
- Access + Program changes + Development/acquisition + Operations + Backup/recovery
- Apply to the whole IT environment. Use these as headings when a question asks for general controls.
- Application controls (stages)
- Input + Processing + Output + Master file/standing data
- Specific to one application. Aim: complete, accurate, authorised.
- Dependency rule
- Weak general controls → application controls cannot be relied on
- Always state this link when explaining why general controls matter.
- CAAT types
- Audit software (tests the client's data) and test data (tests the client's program)
- Name the type and say what it tests.
- External auditor's assessment of internal audit (ISA 610)
- Reliance depends on: objectivity + technical competence + a systematic and disciplined approach (due professional care, including quality control)
- Use these three factors as your checklist. Communication with the external auditor is a practical consideration, not a separate ISA 610 test.
- Responsibility rule
- External auditor's responsibility for the opinion = sole; not reduced by use of internal audit
- Never say reliance shifts responsibility to internal audit. Do not refer to internal audit's work in the audit report unless law or regulation requires it. Even then, the reference does not reduce the auditor's responsibility.
- Direct assistance
- Direct assistance is allowed only if law permits and the internal auditors are objective and competent, and the work is directed, supervised and reviewed by the external auditor
- Direct assistance is internal auditors performing audit procedures under the external auditor's supervision. Do not assign procedures that involve significant judgement, or that relate to higher assessed risks of material misstatement where more than limited judgement is needed. For other work, limit what is assigned according to the judgement involved and the assessed risk.
- Reliance judgement
- Higher risk or more judgement = less reliance and more own work
- Use internal audit more for low-risk areas such as routine controls. Do not use it for key judgements such as estimates.
Quick revision
- Internal control is the process designed and maintained to give reasonable assurance on reliable reporting, effective operations and compliance.
- Controls give reasonable, not absolute, assurance because of limitations such as human error, collusion and management override.
- The auditor must understand controls relevant to the audit, whether or not they plan to rely on them.
- Understanding controls means evaluating design and checking implementation.
- Key control activities include authorisation, segregation of duties, reconciliations, physical controls and performance reviews.
- A deficiency answer has three parts: weakness, consequence, recommendation.
- Tests of controls check operating effectiveness; substantive procedures address misstatements in figures and disclosures.
- If controls are effective, substantive work can be reduced; if not, it must be increased.
- Significant deficiencies must be communicated to those charged with governance in writing on a timely basis.
- General IT controls cover access, program changes and operations; application controls work within individual programs.
- Internal audit is part of the monitoring of controls, and the external auditor can only use its work after assessing it.
- Objective questions are all or nothing, so read each option against the exact definition.
Common mistakes
- Treating internal control as only accounting procedures such as reconciliations. Fix: Remember all five components. Culture and oversight form the control environment.
- Confusing control environment with control activities. Fix: Control environment is the overall tone and governance. Control activities are specific procedures such as authorisation or reconciliations.
- Saying a walkthrough test proves controls operated effectively all year. Fix: State that a walkthrough confirms understanding, design and implementation for one transaction. Operating effectiveness needs tests of controls on a sample.
- Treating ICQ and ICE as the same thing. Fix: Say an ICQ asks whether specific controls exist, while an ICE asks whether control objectives are met and what controls are missing.
- Listing controls without linking them to a risk in the scenario. Fix: Start each point with the problem in the scenario, then give the control and explain how it addresses that problem.
- Confusing tests of control with substantive procedures. Fix: A test of control checks that a control operated (for example, inspecting evidence of approval). A substantive procedure checks the balance or transaction itself (for example, recalculating an invoice total).
- Writing a recommendation that does not match the deficiency. Fix: Reread the deficiency and write the specific control that would have stopped it.
- Giving the consequence as 'fraud or error may occur' with no detail. Fix: State what could be misstated or lost, for example overstated receivables or payment of fictitious wages.
- Calling a test of detail a test of controls because it uses a sample of transactions. Fix: Ask what the sample proves. If it proves the control operated, it is a test of controls. If it proves the amount is right, it is substantive.
- Saying enquiry alone is a sufficient test of controls. Fix: Combine enquiry with inspection, observation or re-performance. Enquiry on its own does not give enough evidence.
Exam tips
- Name components using the standard terms. Markers look for them.
- In scenarios, quote the fact that points to the component or limitation.
- Always end limitation answers with the effect on the audit approach.
- Do not confuse management's responsibility for controls with the auditor's work in understanding them.
- For small entity scenarios, think first of segregation of duties and owner-manager override.
- In Section C, give a point for each technique and each documentation method, then link it to the scenario to earn the mark.
- In Section A and B objective questions, watch the wording: walkthrough confirms design and implementation, not operating effectiveness.
- If asked to recommend a documentation method, always justify with the system's size and complexity.