ACCA Applied Skills · Audit and Assurance
Systems of Internal Control for ACCA Audit and Assurance
A system of internal control is the set of policies and procedures management uses to safeguard assets, keep reliable records, and comply with laws. In AA you identify controls in a scenario, spot deficiencies, suggest fixes, and design tests of control. Always link each point to a business risk and an audit assertion.
What this chapter covers
This chapter covers how an entity controls its own operations and reporting. You study the components of internal control: the control environment, the entity's risk assessment process, control activities, the information system, and monitoring of controls. You then look at specific controls, IT controls, the role of internal audit, how to evaluate deficiencies, and how auditors document and test systems.
The chapter sits at the centre of the Audit and Assurance paper. Risk assessment depends on it, because the auditor must understand the entity's controls to assess the risks of material misstatement. Audit procedures depend on it too. If controls look reliable, the auditor can test them and reduce substantive work. If they look weak, the auditor must do more substantive testing.
The chapter also feeds reporting. Control deficiencies found during the audit must be communicated to those charged with governance, usually in a written report to management. Controls are tested in two places: Section A OT cases, where a business process scenario is followed by five two-mark questions, and Section B constructed response questions, where you must identify deficiencies, explain the risk, recommend improvements, or describe tests of control.
Internal control is a core area of the AA syllabus and can be examined in both Section A and Section B. It also carries over into almost every other topic. A typical written question gives you a scenario with several weaknesses and asks for the deficiency, its consequence and a recommendation, and these marks are very achievable if you have a method. The same knowledge also supports your answers on risk assessment, audit procedures and reporting, so time spent here pays back across the whole paper. Remember that objective test questions are marked all or nothing, so you need precise definitions as well as application skills.
Systems of internal control: topics in the order to study them
- 1Internal Control Systems and Their ComponentsStart here because it gives you the framework (the five components) and the vocabulary every later topic uses.
- 2Control Environment and Corporate Governance BasicsThis is the first component and sets the tone; it links governance structures to how reliable all other controls are likely to be.
- 3Control Activities and Types of ControlNext you learn the specific controls, such as authorisation, segregation of duties, reconciliations and physical controls, which you will need to spot in scenarios.
- 4Information Systems and IT ControlsBuild on control activities by learning general and application controls, since most modern systems are computerised.
- 5Internal Audit Function and Monitoring of ControlsMonitoring completes the components, and you need to know how internal audit works before considering whether the external auditor can rely on it.
- 6Evaluating Controls: Deficiencies and ReportingOnce you know what good controls look like, you can judge weak ones and practise the deficiency, consequence and recommendation format.
- 7Documenting and Testing Systems; Tests of ControlFinish with how the auditor records systems and tests whether controls operate, which pulls the whole chapter together into audit procedures.
How to prepare Systems of internal control
Aim to be able to do two things: recognise controls and weaknesses in a scenario, and write them up in a clear, structured way. Practise with scenarios, not only notes.
- Learn the five components of internal control and the purpose of a system in your own words, so you can answer definition-style objective questions precisely.
- For each control type, write what it prevents or detects. For example, segregation of duties reduces the risk of fraud and error because it makes it harder for one person to commit and conceal it, although collusion can still defeat it.
- Practise a three-part answer for every weakness: the deficiency, the possible consequence for the business or the financial statements, and a specific recommendation.
- Study general IT controls and application controls separately, with one example of each, and learn what each is meant to protect.
- Learn to match tests of control to a control: inspection of evidence, observation, re-performance and enquiry. Remember that enquiry alone is not enough evidence.
- Work through a full process, such as sales or purchases, from order to payment. List the controls expected at each stage and the tests you would perform.
- Finish with timed scenario questions and review your answers: did you use the facts in the scenario, and was each recommendation practical?
Common mistakes in Systems of internal control
Listing generic controls instead of using the scenario facts.
Fix: Quote or paraphrase the specific weakness from the scenario first, then explain why it matters and what to change.
Giving a deficiency without explaining the consequence.
Fix: Always state what could go wrong, such as fraud, misstatement or loss of assets, before giving the recommendation.
Confusing tests of control with substantive procedures.
Fix: Ask what you are testing. If it is whether a control worked, it is a test of control. If it is an account balance or transaction amount, it is substantive.
Recommending vague fixes such as 'improve controls' or 'hire more staff'.
Fix: Name a specific action, such as a second person approving purchase orders above a set limit.
Mixing up general IT controls and application controls.
Fix: General controls cover the IT environment as a whole. Application controls are built into one process, such as payroll or sales.
Treating management as responsible for controls but forgetting the auditor's role in reporting deficiencies.
Fix: Remember that the auditor reports significant deficiencies to those charged with governance, usually in writing and in a timely manner.
Last-day revision: Systems of internal control
- Internal control components: control environment, risk assessment process, information system, control activities, monitoring of controls.
- Controls provide reasonable assurance, not absolute assurance, because of inherent limits such as human error, collusion and management override.
- Preventive controls stop errors happening; detective controls find them afterwards; corrective controls fix them.
- Segregation of duties separates authorisation, custody of assets and recording of transactions.
- General IT controls cover access, program changes, development and operations; application controls work within a specific process.
- Examples of application controls include input validation, sequence checks, and exception reports.
- Internal audit is part of monitoring; the external auditor decides independently how much to rely on it.
- A significant deficiency should be communicated in writing to those charged with governance on a timely basis.
- Deficiency, consequence, recommendation: use this three-part structure in every written answer.
- Tests of control check that a control operated effectively; substantive procedures check amounts and disclosures.
- Methods of testing controls: inspection, observation, re-performance and enquiry combined with other evidence.
- Auditors record systems using narrative notes, flowcharts and questionnaires.
Systems of internal control in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Systems of internal control: frequently asked questions
What is a system of internal control in ACCA Audit and Assurance?
It is the set of policies and procedures management puts in place to run the business, safeguard assets, keep reliable records and comply with laws. In AA it is described through five components. You need to know them and apply them to scenarios.
How is this chapter tested in the AA exam?
It is tested in Section A OT cases, where each case has five two-mark questions based on a scenario such as a business process. It is also tested in Section B constructed response questions. Written questions usually ask you to identify deficiencies, explain their effects, recommend improvements or describe tests of control.
What is the difference between tests of control and substantive procedures?
Tests of control gather evidence that a control operated effectively during the period. Substantive procedures gather evidence about the figures and disclosures themselves. Auditors often combine both, depending on how reliable the controls appear.
How should I answer a question on control deficiencies?
Use three parts for each point: the deficiency, the consequence and the recommendation. Base each one on facts in the scenario. A clear, specific recommendation earns marks that a generic one does not.