CHAPTER 1 Auditing and Internal Control

You might also like

Download as pptx, pdf, or txt
Download as pptx, pdf, or txt
You are on page 1of 13

IMPLICATIONS

FOR INTERNAL
CONTROL AND
AUDITING
Raquel R. Vergara
BSA 4-1
 A key benefit of an ERP system is its
tightly integrated architecture of modules.
 The challenge for auditors in
verifying transaction authorization is to
gain a detailed knowledge of the ERP
system configuration.
 Operational decisions in ERP-based
organizations are pushed down to a point
as close as possible to the source of the
event.
 Organizations using ERP systems
must establish new security, audit, and
control tools to ensure duties are properly
segregated.
SUPERVISION
 The employee-empowered
philosophy of ERP should not eliminate
supervision as an internal control.

 Supervisors should have more time


to manage the shop floor and, through
improved monitoring capability, increase
their span of control.
INDEPENDENT VERIFICATION
 The focus of independent
verification thus needs to be redirected
from the individual transaction level to
one that views overall performance.
 ERP systems come with canned
controls and can be configured to produce
performance reports that should be used
as assessment tools.
ACCOUNTING RECORDS
 ERP systems have the ability to
streamline the entire financial reporting
process.
 In spite of ERP technology, some risk
to accounting record accuracy may still
exist.
ACCESS CONTROLS
 Access security is one of the most
critical control issues in an ERP
environment.
 The goal of ERP access control is
to maintain data confidentiality,
integrity, and availability.
ACCESS
CONTROL LIST
vs RBAC
INTERNAL
CONTROL
ISSUES RELATED
TO ERP ROLES
The following points highlight the
key concerns:
1.The creation of unnecessary roles

2. The rule of least access should apply to


permission assignments

3. Monitor role creation and permission-


granting activities
CONTINGENCY
PLANNING
 Organization needs an effective
contingency plan that can be
invoked quickly in the event of a
disaster.

You might also like