Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Information Systems

A Mumbai firm's accounts clerk can both create vendor master records and approve payments to those vendors in its ERP. Which control principle is being violated, and what is the main risk?

The firm violates segregation of duties. One person can create a vendor and also approve payments to it, so a fictitious vendor could be set up and paid without any independent check. Separating the two functions between different people reduces this fraud risk.

  1. ASegregation of duties; the clerk could create a fictitious vendor and pay itCorrect
  2. BData encryption; payment data could be read in transit
  3. CBusiness continuity; the ERP may be unavailable after a disaster
  4. DInput validation; wrong date formats may be accepted

Explanation

Segregation of duties requires that incompatible functions, such as creating masters and authorising payments, be held by different persons. Combining them enables fraud through fictitious vendors without a second person's check. The other options concern different control objectives.

Did you get it right without looking?

One question tells you little. A timed set on Information Systems shows your real accuracy, how long you take and where you lose marks.

More Information Systems questions