1/63
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Enterprise Resource Planning (ERP) Systems
Cross-functional systems that support different business functions and facilitates integration of information across departments (accounting, customer management, finnance, HR, inventory management)
Facilitates real-time communication between systems, operating under a centralized database
Transaction-oriented
Accounting Information System (AIS)
System that collects, records, stores accounting information, then complies the information using accounting rules to report both financial and non-financial information to decision makers in an enterprise
More specific in nature than ERP system
3 Subsystems (Modules) ←- Helps achieve objectives
Transaction Processing System (TPS)
Financial Reporting System (FRS)
Management Reporting System (MRS)
5 Objectives:
Valid transactions
Properly classify transaction
Recorded at correct value
Recorded in correct accounting period
Properly presented in f/s
Transaction Processing System (TPS)
Subsystem of an AIS that converts economic events into financial transactions (journal entries) and distributes the information to support daily ioperations
Covers three transaction cycles = Sales cycle, conversion cycle, expenditure cycle
Financial Reporting System (FRS)
Subsystem of an AIS that aggregates daily financial information from the TPS and other sources for infrequent events such as mergers, lawsuit settlements, natural disasters to enable timely regulatory and financial reporting
Management Reporting System (MRS)
Subsystem of an AIS that provides internal financial information to solve day-to-day business problems, such as budgeting, variance analysis, or cost-volume-profit analysis
Transaction Cycles
Core functions within an accounting department
Revenue cycle, purchasing and disbursement cycle, other processes that involve the recognition/ facilitation of transactions
Automation
Area of process improvement that describes the process of using technology to perform tasks without human intervention
Must understand business process thoroughly to replace it with business process automation facilitated by IT systems
Repetitive tasks
Shared Services
Area of process improvement that seeks out redundant services, combines them, and then share services within a group or organization
Typically involves software that is designed to process large batches of data
Outsourcing
Area of process improvement that is defined as the contracting of services to an external provider
Contractual relationship between organization and service provider
Supporting functions or back-office services for a fee
Risks associated with quality of service, reduced productivity, information security:
Quality Risk ←- Produce/ service is defective
Quality of Service ←- Poorly designed service
Productivity ←- Not responsive
Staff Turnover ←- Experienced/ valued staff leave org
Language Skills ←- Offshoring = language barriers
Security ←- Information shared with 3rd party provider
Qualifications of Outsourcers ←- Credentials can be flawed
Labor Insecurity ←- Fear of employees jobs’ being outsourced
Offshore Operations
Area of process improvement that relate to outsourcing services/ business functions to an external party in a different country
IT support
Business processes (call centers, tax compliance)
Software R&D
Knowledge processes (Requiring advanced knowledge / specialized skills)
Robotic Process Automation
Specific form of a business process automation that refers to the use of programs capable of extracting information from a specific user interface that can then initiate further processes based on the data extracted; a refinement of web scraping tools that scour the interent looking for specific text to collect material surronding it
Perform repetitive tasks that do not require skilled human labor ←- Can mimic human interaction
Simple, rule-based processes
Light Detection and Ranging (LiDAR)
Involves emitting laser pulses toward a target and measuring the time it takes to return to the sensor; example of how AI and machine learning supercharged an old technology to allow it to be successful in the advancement of self-driving cars
NOT RPA technology
Natural Language Processing (NLP) Software
Involves technology developed and sued to encode, decode, and interpret human languages so technology can perform tasks, interact with other humans, or carry out commands on other technological devices
Needed to build network embedded in IoT devices
Accounting applications = Parsing text document/ speeches made by executives to extract and catalog data
Neural Network
Form of technology that is modeled after neurons that facilitate the function of human or animal memory; key technology used in machine learnign applications
Involve:
Input Layer: Different variables that feed into hidden layer
Hidden Layer: Series of weights applied based on inputs selected, which directs the algorithm toward a given output
Output (Results) Layer
Just as human responses’s change, its reactions is refined in the hidden layer by changes tp weights which yield differnt outcomes = Evidence of learning
Deep learning ←- Used to capture patterns in large volumes of data
Inference engines used in fraud detection
Artificial intelligence (AI)
Any system created to perform complex tasks that require human intelligence and judgement
Speech recognition, NLP, image recognition
Machine Learning (ML)
A subset of AI involving the use of algorithms and data sets supplied for computers to learn and make decisions
recommendation systems (e-commerce), auto-correct, predictive text input
Deep Learning
Subset of neural networks that is used to capture patterns in large volumes of data
Referred to as the “engine” of the hidden layer
Processing Integrity
System’s ability to initiate and complete transactions so that they are valid, accurate, completed timely, and authorized to meet a company’s objective
Integrity
Confidentiality and privacy of the details related to transactions involving data that identifies customers, patient health records, employees, or financial accounts
Deficiencies in Design
Defined by the AICPA in a SOC 2 engagement as a deficiency where necessary controls that are missing or existing controls that are not properly designed
Can identify of deficiency exists related to processing integrity by applying the Trust services Criteria
Evaluation:
Understand management’s risk assessment process
Evaluate link between controls in system description and Trust Services Criteria
Determine if controls are in place and are being implemented
Can identify deficiency by using SOC 2 Report and compare to organizations system design documentation
Trust Services Criteria
SOC 2 Report; Can be used to assess deficiencies in design
Security ← Can processes be circumvented?
Availability ←- Where is data not made available/ prevented?
Processing Integrity ←- Processes/ Methods that do not meet objectives
Confidentiality ←- Evaluate processes/ employees who handle confidential data to identify potential data leakage
Privacy ←- How is personal data used, stored, collected, disposed to identify potential data breaches
Controls are suitability designed if they meet criteria
Provide reasonable assurance that company’s system requirements & service commitments were achieved
ACIPA Description Criteria (SOC 2 Report)
Way to identify deficiencies in design related to processing integrity by comparing SOC 2 report to organization’s system design documentation
2 items recommended to review: ←- Supports understanding of the system, services provided, and design of controls that must be disclosed by management
Principle Service Commitment
Principle System requirements
Deficiency in Operation
Deficiency in a SOC 2 engagement where a properly designed control does not operate as designed or is performed by a person who lacks authority or competence to perform control effectively
Test of Controls
Performed to determine if controls are operating effectively; test operating effectiveness of controls based on the trust services criteria
Service auditor obtains proper evidence about controls applied, consistency of application, and personnel who apply controls
Responsible for designing & performing test of controls ←- Inquiry, Re-perform, Observation, Review documentation
Change in service organization ←- Test controls before and after change
Deficiencies already identified = NOT required to test controls
COSO Internal Controls (Relating to IT Controls )
Control Activities:
Principle 11 - General controls over technology in order to achieve organizational objectives
Information and Communication:
Principle 13 - Organizations should acquire, create, and use quality information to support internal controls
Principle 14 - Effective communication of information is needed to support internal controls
Blockchain
Control system designed to govern the creation and distribution of Bitcoin
Bitcoin must be “mined” to confirm transactions = People perform cryptography
Ensures validation of crypto transaction
Created to prevent Bitcoin from being replicated and to limit its creation so there is a finite number
Resists alteration, validates bitcoin transactions, and is decentralized in nature (Can see every transaction for particular bitcoin)
Built in audit trail
Challenge = Decentralization where no organization has complete control
CanNOT engage service auditor to assess controls
5 Components of COSO help evaluate risks associated with blockchain
Cryptography
Solving of complex mathematical equations
Avaliability
Being able to perform business functions or meet business objectives
System availability, human capital personnel availability
System Avaliability
An organization's strategic ability to recover from an incident; strategic ability to rebound
Having plans in place to support business resiliency, business continuity, system availability controls, crisis management, and disaster recovery.
The business resiliency component foc
Business Resiliency
Business Continuity
System Availability Controls
Crisis Management
Disaster Recovery
Physical and IT Infrastructure Controls
Uninterrupted Power Supply
Redundancy and Backup
Incident Response Plan
Business Resiliency
Integration of system availability controls, disaster recovery plans, business continuity plans, crisis management plans into a central set of procedures to consider whether a business can continue to operate or quickly return to operations without harm to people, information, assets; focuses on continuous operations and the ability to return to operations quickly
The overall integration of procedures implemented to keep operations running smoothly
Components
Disaster Recovery (IT infrastructure disruptions)
Business Continuity (Non-IT, operational, personnel functions
Crisis Management (Large-scale incidents)
Business Continuity Plans
Comprehensive plans that have contingency mitigation procedures for business processes such as relocating employees, continuing product manufacturing, or maintaining the ability to make sales to customers in the event of a disaster. In a SOC 2® engagement, service auditors typically verify that business continuity plans are current, relevant to the organization's continuity of core operations, and reviewed periodically to make updates as the company evolves; Ability to continue delivering products/ services; operation focused
Disaster Recovery (DR)
Consists of an entity’s plans for restoring and continuing its IT function in the event of the destruction of program and data files and computer processing capability
Major component of a business resiliency program
Needed if processing cannot be quickly reestablished at the original processing site
Excluded = Short-term problems / outages
5 Steps in DR plan:
Assess the risks
Identify mission-critical applications and data
Develop a plan for handling mission-critical applications
Determine the responsibilities of the personnel involved in disaster recovery
Test the disaster recovery plan
Cold Site
Warm Site
Hot Site
Business Impact Analysis (BIA)
Assessment that identifies business units, departments, and processes that are essential to the survival of an entity as well as the organizational impavt in the event of failute or disruption; Assessment performed to identify and assess risks in a business resiliency program
Identify how quickly essential business units/ processes can return to full operation
Identify resources needed to resume operations
High Impact (H)
Department…
Cannot operate without resource
Experiences a high recovery cost
Fail to meet organization’s objectives or maintain its reputation
Moderate/ Medium Impact (M)
Partially function temporarily
Experience some cost of recovery
Fail to meet organization’s objectives or maintain reputation
Low-Impact (L)
Operate for extended period of time
Effect on achieving objective’s or maintain reputation
Steps:
Establish BIA Approach
Identify Critical Resources
Define Disruption Impacts
Establish Losses (Assign threats probability of likelihood = ARO)
Establish Recovery Priorities
Create BIA Report
Implement BIA Recommendations
Crisis Management Plans
Plans in place to lessen impact of a crisis, prootect people, protect organizational reputation, and return to operations ASAP
Addresses:
Risk assessment of potential crises/ response
Procedures for implementing plan
Crisis response command center
Roles & responsibilities
Internal & external communication
Properly train employees
System Availability Risk
Largest risk an organization faces
Monitoring
Replication
Copying and transferinng data
Annualized Rate of Occurrence (ARO)
Expected frequency of occurrences in a year
If an event occurs once every 15 years, then it would be 1 ÷ 15 = 0.0667.
Exposure Factor (EF)
The damage in terms of dollars, expresses as a % of an asset’s value
Single Loss Expectency (SLE)
The cost of an individual loss
SLE = Damaged Likelihood (EF) * Average cost of asset
Annualized Loss Expectancy (ALE)
The cost of a specific loss in a given year
= ALE = SLE * ARO
Resilience
An information system's ability to maintain essential operational capabilities even when operating under adverse conditions or stress. This means the system can continue functioning, even if at a reduced capacity, during challenging circumstances.