Skip to content

CA Final · Advanced Auditing, Assurance and Professional Ethics · Digital Auditing & Assurance

CA Rohan, auditor of Bharat Logistics Ltd, notices that a database administrator of the company also has the access rights to post journal entries in the accounting module and to modify the audit log settings. Management says the person is trusted and has never made an error. Which conclusion is most appropriate?

This is a segregation of duties and access control deficiency. Rohan should assess the risk of control override, extend substantive testing of journal entries, and communicate the deficiency to those charged with governance. Past absence of errors does not remove the risk created by privileged access.

  1. ANo concern arises since no error has been detected historically
  2. BThis is a deficiency in logical access and segregation of duties, so Rohan should assess the risk of override of controls and extend substantive procedures on journal entriesCorrect
  3. COnly an internal auditor can report on this issue, not the statutory auditor
  4. DThe matter is relevant only to the secretarial auditor under the Companies Act

Explanation

Conflicting access to journal posting and log settings undermines segregation of duties and enables management or privileged override without trace. The auditor must evaluate the effect on risk assessment, extend journal entry testing and communicate the deficiency to those charged with governance. Absence of past errors does not remove the risk.

Did you get it right without looking?

One question tells you little. A timed set on Digital Auditing & Assurance shows your real accuracy, how long you take and where you lose marks.

More Digital Auditing & Assurance questions