ACC306 Chapter 10

Threats and Risks in Accounting Information Systems

  • Threat: Any potential adverse occurrence harming the accounting information system or organization.

  • Exposure/Impact: Potential dollar loss if the threat occurs.

  • Likelihood: Probability of the threat happening.

Importance of Control and Security

  • Accountants must understand IT capabilities and risks.

  • Computer-based AIS requires distinct internal control policies.

  • Objectives:

    • Achieve enterprise objectives.

    • Proactively eliminate system threats and manage recovery.

Internal Control Concepts

  • Internal Control Process: Ensures control objectives such as safeguarding assets and compliance with laws.

  • Control Objectives:

    1. Safeguarding assets.

    2. Accurate and reliable record maintenance.

    3. Compliance with management policies and regulations.

  • Control Functions:

    • Preventive: Deter issues before they arise.

    • Detective: Identify problems as they occur.

    • Corrective: Fix issues and modify systems to reduce future problems.

Types of Internal Controls

  • General Controls: Ensure a stable control environment. Includes management, security, IT infrastructure, and software controls.

  • Application Controls: Ensure accuracy, completeness, and authorization of data transactions.

Regulatory Frameworks

  • Foreign Corrupt Practices Act (1977): Prevents bribery of foreign officials.

  • Sarbanes-Oxley Act (2002): Aims to prevent financial fraud and enhance transparency.

    • Requires CEO/CFO certifications of financial statements.

    • Establishes internal control reporting requirements.

Control Frameworks Comparison

  • COBIT: Framework for IT control practices.

  • COSO: Defines internal controls and evaluation guidance.

    • Components include risk management and control environments.

Control Environment Elements

  • Includes management philosophy, board of directors, commitment to ethics, organizational structure, and external influences.

Risk Assessment and Response in ERM

  • Inherent Risks: Exist before controls; Residual Risks: Remain after implementing controls.

  • Risk Response Strategies:

    1. Reduce risk through internal controls.

    2. Accept risk without action.

    3. Share or transfer risk.

    4. Avoid engaging in risky activities.

  • Cost-Benefit Analysis: Control benefits must exceed costs.

Control Activities

  • Common Procedures:

    1. Authorization: Empower employees to perform transactions.

    2. Segregation of Duties: Prevent collusion by separating responsibilities.

    3. Segregation of Systems Duties: Separate roles in data entry, programming, and operations.

Information and Communication

  • Objectives of Accounting Information Systems:

    1. Identify and record valid transactions.

    2. Classify and record transactions accurately.

    3. Present transactions correctly in financial statements.

  • Monitoring Techniques: Conduct evaluations, audits, and employ security measures.