Skip to content

CA Intermediate · Auditing and Ethics · Risk Assessment and Internal Control

While planning the audit of Sundaram Textiles Ltd, the auditor finds that the company's sales staff can create customer master records and also approve credit limits for those customers in the ERP. Under SA 315 (Revised), how should the auditor view this feature of the control environment and system?

The auditor treats it as a control deficiency in segregation of duties that raises the risk of material misstatement. The assessment of risk must reflect this weakness, and further audit procedures should be designed accordingly. Segregation of duties matters equally in computerised environments, so the feature cannot be ignored.

  1. AA deficiency in segregation of duties that increases the risk of material misstatement and must be considered in designing further audit proceduresCorrect
  2. BA matter that can be ignored because segregation of duties is relevant only to manual systems
  3. CA reason for the auditor to withdraw from the engagement immediately
  4. DA matter to be reported only to the tax authorities and not to management

Explanation

Allowing the same persons to create customers and approve their credit limits weakens segregation of duties, so fraud or error may go undetected. SA 315 requires the auditor to assess this risk and design responsive procedures. Treating it as irrelevant for automated systems is wrong because IT controls need segregation too.

Did you get it right without looking?

One question tells you little. A timed set on Risk Assessment and Internal Control shows your real accuracy, how long you take and where you lose marks.

More Risk Assessment and Internal Control questions