SlideShare a Scribd company logo
2
Most read
17
Most read
18
Most read
Internal Controls in
an IT Environment
What are Internal Controls?
• It is comprised of policies, practices and
procedures employed by the organization to
achieve four (4) broad objectives:
– To safeguard assets of the firm
– To ensure the accuracy and reliability of accounting
records and information
– To promote efficiency of the firm’s operations
– To measure compliance with management’s
prescribed policies and procedures
Modifying Principles of Internal Control
•
•
•
•

Management Responsibility
Methods of Data Processing
Limitations
Reasonable Assurance
Limitations of Internal Control
1.
2.
3.
4.

Possibility of error
Circumventions
Management Override
Changing conditions
PDC Model
Preventive, Detective and
Corrective Controls
Preventive Controls
• First line of defense
• Passive techniques designed to reduce the
frequency of occurrence of undesirable events.
• Example is a well-designed data screen – only
valid entries and user-defined fields are entered.
Detective Controls
• Are devices, techniques and procedures designed
to identify and expose undesirable events that
elude preventive controls.
• Example – alert that the amount entered as
DEBIT in the system does not equal the CREDIT
entered, vice versa
Corrective Control
• The “fix.”
• Example – adjusting entries to erroneous
accounts used in entering in the journal entry.
COSO INTERNAL
CONTROL FRAMEWORK
What is COSO?
• Stands for “Committee of Sponsoring
Organizations of the Treadway Commission.”
• Included the following organizations:
– Financial Executives International (FEI)
– Institute of Management Accountants (IMA)
– American Accounting Association (AAA)
– AICPA
– IIA
THE COSO INTERNAL
FRAMEWORK
The Control Environment
– Integrity and ethical values of management
– Organizational structure
– BOD and Audit Committee participation
– Management philosophy and operating style
– External influences
– HR policies and practices
Risk Assessment
– Changes in operating environment
– New personnel
– New/re-engineered systems
– Significant and rapid growth
– Introduction of new product lines or activities
– Organizational restructuring
– Entrance to foreign markets
– Adoption of new accounting principle(s)
Information and Communication
– Identify and record all valid financial information.
– Provide timely information about transactions in
sufficient detail to permit proper classification and
financial reporting.
– Accurately measure the financial value of
transactions so their effects can be recorded in
financial statements.
– Accurately record transactions in the proper time
period.
Monitoring
– Process by which the quality of internal control
design and operation can be assessed.
Control Activities
• Physical controls
 relates primarily to the human activities employed in
accounting systems.
 the six (6) categories of physical controls are:







Transaction authorization
Segregation of duties
Supervision
Accounting records
Access control
Independent verification
• IT Controls
– Application
 Ensures validity, completeness, and accuracy of financial
transactions.
 Examples include: limit checks, check digits, batch
balancing techniques.
– General
 Also known as General Computer Controls, Information
Technology Controls
 Include controls over IT governance, IT infrastructure,
security and access to operating systems and databases,
application acquisition and development and program
change procedures

More Related Content

PPT
James hall ch 1
PPTX
Generalized audit-software
PPT
The Revenue Cycle
PPTX
Chapter 3 security part i auditing operating systems and networks
PPT
James hall ch 2
PPTX
Lecture 1 accounting information system, an overview
PPT
Technology Auditing, Assurance, Internal Control
James hall ch 1
Generalized audit-software
The Revenue Cycle
Chapter 3 security part i auditing operating systems and networks
James hall ch 2
Lecture 1 accounting information system, an overview
Technology Auditing, Assurance, Internal Control

What's hot (20)

PPTX
Chapter 2 auditing it governance controls
PPTX
Conceptual Framework in Accounting
PPTX
Chapter 4 security part ii auditing database systems
PPT
Auditing In Computer Environment Presentation
PPTX
Auditing the expenditure cycle
PPT
Completing the audit
PPTX
Accounting information system (AIS)
PDF
Accounting information system
PPTX
Audit & Assurance
PPT
Chapter#10 analyzing financial performance repots
PPT
audit sampling notes
PPT
James hall ch 7
PPTX
Internal Audit
PDF
Internal Control
DOC
Audit & Assurance
PPTX
Computer-Assisted Audit Tools and Techniques
PPT
Understanding Financial Statement fraud- Forensic Accounting Perspective
PPTX
Chapter 1 auditing and internal control
PPSX
Internal controls
PDF
Chapter 7 Payroll & Personnel Cycle
Chapter 2 auditing it governance controls
Conceptual Framework in Accounting
Chapter 4 security part ii auditing database systems
Auditing In Computer Environment Presentation
Auditing the expenditure cycle
Completing the audit
Accounting information system (AIS)
Accounting information system
Audit & Assurance
Chapter#10 analyzing financial performance repots
audit sampling notes
James hall ch 7
Internal Audit
Internal Control
Audit & Assurance
Computer-Assisted Audit Tools and Techniques
Understanding Financial Statement fraud- Forensic Accounting Perspective
Chapter 1 auditing and internal control
Internal controls
Chapter 7 Payroll & Personnel Cycle
Ad

Similar to Internal controls in an IT environment (20)

PPTX
topic 3 internal controls..audit.pptx
PPTX
CONTROL AND AUDIT
PDF
Chapter 7
PDF
Chapter 7
PPTX
Lecture 17 sas framework internal control - james a. hall book chapter 3
PDF
Core Concepts of Accounting Information Systems Canadian 1st Edition SimKin S...
PDF
Internal control
PDF
Control and audit of information System (hendri eka saputra)
PPT
PPT
Internal control 1_ricc_revised
PPTX
Chapter 2 internal control
PPT
batas opisyal.ppt
PPTX
Fraud, internal control & cash
PPTX
PPT
Financial Management for Business Associations
PPT
Ais Romney 2006 Slides 06 Control And Ais
PPT
Ais Romney 2006 Slides 06 Control And Ais Part 1
PPT
Ais Romney 2006 Slides 06 Control And Ais
PPT
Ais Romney 2006 Slides 06 Control And Ais Part 1
PPTX
01.1. Internal Control System_Oct'21.pptx
topic 3 internal controls..audit.pptx
CONTROL AND AUDIT
Chapter 7
Chapter 7
Lecture 17 sas framework internal control - james a. hall book chapter 3
Core Concepts of Accounting Information Systems Canadian 1st Edition SimKin S...
Internal control
Control and audit of information System (hendri eka saputra)
Internal control 1_ricc_revised
Chapter 2 internal control
batas opisyal.ppt
Fraud, internal control & cash
Financial Management for Business Associations
Ais Romney 2006 Slides 06 Control And Ais
Ais Romney 2006 Slides 06 Control And Ais Part 1
Ais Romney 2006 Slides 06 Control And Ais
Ais Romney 2006 Slides 06 Control And Ais Part 1
01.1. Internal Control System_Oct'21.pptx
Ad

Recently uploaded (20)

PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PDF
Modernizing your data center with Dell and AMD
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PPTX
Cloud computing and distributed systems.
PDF
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
Encapsulation theory and applications.pdf
PDF
Machine learning based COVID-19 study performance prediction
PDF
Review of recent advances in non-invasive hemoglobin estimation
PPTX
MYSQL Presentation for SQL database connectivity
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
Spectral efficient network and resource selection model in 5G networks
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PPTX
A Presentation on Artificial Intelligence
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Dropbox Q2 2025 Financial Results & Investor Presentation
Modernizing your data center with Dell and AMD
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Cloud computing and distributed systems.
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
Diabetes mellitus diagnosis method based random forest with bat algorithm
Advanced methodologies resolving dimensionality complications for autism neur...
The AUB Centre for AI in Media Proposal.docx
Encapsulation theory and applications.pdf
Machine learning based COVID-19 study performance prediction
Review of recent advances in non-invasive hemoglobin estimation
MYSQL Presentation for SQL database connectivity
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
NewMind AI Weekly Chronicles - August'25 Week I
Spectral efficient network and resource selection model in 5G networks
“AI and Expert System Decision Support & Business Intelligence Systems”
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
20250228 LYD VKU AI Blended-Learning.pptx
A Presentation on Artificial Intelligence

Internal controls in an IT environment

  • 1. Internal Controls in an IT Environment
  • 2. What are Internal Controls? • It is comprised of policies, practices and procedures employed by the organization to achieve four (4) broad objectives: – To safeguard assets of the firm – To ensure the accuracy and reliability of accounting records and information – To promote efficiency of the firm’s operations – To measure compliance with management’s prescribed policies and procedures
  • 3. Modifying Principles of Internal Control • • • • Management Responsibility Methods of Data Processing Limitations Reasonable Assurance
  • 4. Limitations of Internal Control 1. 2. 3. 4. Possibility of error Circumventions Management Override Changing conditions
  • 5. PDC Model Preventive, Detective and Corrective Controls
  • 6. Preventive Controls • First line of defense • Passive techniques designed to reduce the frequency of occurrence of undesirable events. • Example is a well-designed data screen – only valid entries and user-defined fields are entered.
  • 7. Detective Controls • Are devices, techniques and procedures designed to identify and expose undesirable events that elude preventive controls. • Example – alert that the amount entered as DEBIT in the system does not equal the CREDIT entered, vice versa
  • 8. Corrective Control • The “fix.” • Example – adjusting entries to erroneous accounts used in entering in the journal entry.
  • 10. What is COSO? • Stands for “Committee of Sponsoring Organizations of the Treadway Commission.” • Included the following organizations: – Financial Executives International (FEI) – Institute of Management Accountants (IMA) – American Accounting Association (AAA) – AICPA – IIA
  • 12. The Control Environment – Integrity and ethical values of management – Organizational structure – BOD and Audit Committee participation – Management philosophy and operating style – External influences – HR policies and practices
  • 13. Risk Assessment – Changes in operating environment – New personnel – New/re-engineered systems – Significant and rapid growth – Introduction of new product lines or activities – Organizational restructuring – Entrance to foreign markets – Adoption of new accounting principle(s)
  • 14. Information and Communication – Identify and record all valid financial information. – Provide timely information about transactions in sufficient detail to permit proper classification and financial reporting. – Accurately measure the financial value of transactions so their effects can be recorded in financial statements. – Accurately record transactions in the proper time period.
  • 15. Monitoring – Process by which the quality of internal control design and operation can be assessed.
  • 16. Control Activities • Physical controls  relates primarily to the human activities employed in accounting systems.  the six (6) categories of physical controls are:       Transaction authorization Segregation of duties Supervision Accounting records Access control Independent verification
  • 17. • IT Controls – Application  Ensures validity, completeness, and accuracy of financial transactions.  Examples include: limit checks, check digits, batch balancing techniques.
  • 18. – General  Also known as General Computer Controls, Information Technology Controls  Include controls over IT governance, IT infrastructure, security and access to operating systems and databases, application acquisition and development and program change procedures