Lingnan University · FACULTY OF ACCOUNTING

ACT501 Chap.10 Internal Control and Auditing the Transaction Cycles

- one subject, every graph, every model, every mark
10 Chapters5-page Bible
Our own words - no uploaded lecturer files
Updated for this semester
Chapter 10 of 12 · ACT501

Internal Control and Auditing the Transaction Cycles

Five weeks of the term in one framework

The published teaching schedule gives week five to understanding the entity's system of internal control, week six to the auditor's responses to assessed risks together with the revenue cycle, week seven to the purchase cycle, week eight to cash balances and week nine to the production cycle.

The syllabus covers the same ground in its indicative content: the basic concepts of internal control, fraud, and the theory and practice of auditing, together with the usual work done on the main accounts and transaction cycles.

What internal control is, and why an auditor cares

It is not a department and not a manual.

It is the system by which an entity obtains reasonable assurance about the reliability of its reporting, the effectiveness of its operations and its compliance with law. The auditor is interested for one reason: it changes how likely a material error in the accounts is, and therefore how much testing has to be done.

The standards group the system into components covering the control environment set by those in charge; the entity's own process for identifying and dealing with risks to its reporting; the information system and communication, through which transactions are initiated, recorded, processed and reported; control activities, the specific acts of authorisation, reconciliation, segregation, physical safeguarding and checking; and monitoring, by which the entity evaluates whether its controls still work.

The walkthrough

The way an auditor first gets to know a system is by taking one transaction of a given type and following it through every stage of processing, from initiation to its appearance in the statements, asking at each step who does what and what evidence they leave.

It has two outputs: confirmation that the auditor's understanding matches the system that exists, and identification of the points at which a control is supposed to bite, which are the only points worth testing later.

Preventive and detective

A preventive control stops an error or fraud entering the records: a credit limit blocking an order, a system refusing payment without a matching purchase order, a division of duties.

A detective control finds an error already in: a bank reconciliation, a sequence check on pre-numbered documents, a review of unusual ledger items. The difference changes what can be concluded. A preventive control that operated all year supports the assertion directly.

A detective control supports it only if the detection actually happened and was acted on, which is why testing a reconciliation means examining the reconciling items and their resolution rather than confirming that the reconciliation exists.

Two routes, one with a gate

After the risk assessment the auditor either tests the controls, which is permitted only where a control is well designed and expected to have operated, or goes straight to substantive procedures.

Reliance reduces substantive work; it never removes it. A failed test of controls sends the whole caption down the substantive route.

Four cycles, four characteristic failures

Each cycle has a direction of risk that follows from the assertion analysis.

The revenue chain runs from customer order through despatch note and invoice into the sales journal and is tested primarily against overstatement, which means vouching from the journal back to despatch evidence and testing cutoff either side of the year end.

The purchase chain runs from requisition through purchase order, goods received note and supplier invoice into the payables ledger and is tested primarily against understatement, which means starting outside the ledger with goods received notes near the year end, supplier statements, and payments made after the year end.

Cash is confirmable directly with the bank, so the interesting work concerns restrictions, security and accounts the entity may not have listed.

Production is the valuation cycle: which costs have legitimately been absorbed into stock, and whether that value is still recoverable.

The pattern behind the table

A cycle bringing money and assets in is tested against the possibility that it brought in more than it should, because that is what flatters the statements.

A cycle taking money and value out is tested against the possibility that some of it was never recorded. Cash and production do not fit that division neatly, which is why they are taught separately rather than as variations on the first two.

In this chapter

What this chapter covers

  • 01

    Where the five weeks sit in the published schedule

  • 02

    Internal control as a system rather than a department

  • 03

    The components the standards group the system into

  • 04

    The walkthrough, and its two outputs

  • 05

    Preventive against detective controls

  • 06

    Why a detective control needs evidence of the detection

  • 07

    Segregation of duties as a control over people

  • 08

    Testing controls against going straight to substantive work

  • 09

    Revenue and purchases as mirror images

  • 10

    Cash and production, and why they are taught separately

Worked example · free

Four controls, three questions each

Q [12 marks]. AskSia-authored practice. A walkthrough of the revenue cycle at a food distributor records four controls. Orders above a stated credit limit are blocked by the system until the credit controller releases them. Despatch notes are pre-numbered and a weekly report lists gaps in the sequence. The sales manager reviews monthly margin by product line and investigates movements beyond a stated percentage. A second person checks every invoice against the price list before it is sent. For each, say what it prevents or detects, which assertion it supports, and how the team would test whether it operated. The marks shown are an AskSia study allocation and not a University marking scheme.
  • 4Classify each control as preventive or detective.
  • 4Attach each to the assertion it actually supports.
  • 4Choose a test that would establish operation over the period.
The credit block is preventive and supports valuation over receivables rather than existence, since it bears on collectability; test it by attempting to process an order above the limit and by inspecting the release log for the year. The sequence report is detective and supports completeness of revenue, because a missing despatch number is a despatch that may never have been invoiced; test it by inspecting the reports for evidence of investigation and reperforming the check for a sample of weeks. The margin review is detective and high level, which also makes it the weakest to rely on, since a review catching only large movements cannot be relied on for a material one that happens to be smooth; test it by inspecting the review documentation for questions raised and resolved. The price check is preventive and supports accuracy; test it by inspecting initials and reperforming the check on a sample, remembering that initials record that someone signed rather than that anyone looked.
Sia tip — For each control ask what it would have stopped. If you cannot name a specific error it would have caught, you have described an office routine rather than a control.
Glossary

Key terms

Preventive Control
A control that stops an error or a fraud from entering the accounting records, such as a system block or a division of duties.
Detective Control
A control that identifies an error or fraud after it has entered the records, such as a reconciliation or a sequence check.
Segregation of Duties
An arrangement ensuring that the person able to cause an error or misappropriation is not the person able to conceal it.
Control Environment
The tone, structure, competence and attitude to control set by those in charge, on which the effectiveness of every specific control depends.
Transaction Cycle
A chain of linked business activities and documents, such as order to despatch to invoice to receipt, that generates a class of transactions.
Reliance Approach
An audit approach in which tests of controls reduce the extent of substantive procedures, available only where controls are well designed and expected to have operated.
FAQ

Internal Control and Auditing the Transaction Cycles FAQ

Why do auditors spend so long on controls they may not rely on?

Because understanding the system is required whether or not reliance follows. The purpose of that understanding is to identify where misstatement could arise, which is what the risk assessment is built on, and to decide whether reliance is even available. Only when a control is well designed and expected to have operated can testing it reduce substantive work.

Where it is not, the understanding still earns its cost by telling the team where to concentrate substantive procedures instead.

How is testing a detective control different from testing a preventive one?

A preventive control that operated across the period supports the assertion directly, because the error could not have entered the records. A detective control only supports it if the detection actually occurred and was acted on, so the test has to reach the outcome rather than the existence of the routine.

Examining a reconciliation means examining what the reconciling items were and what was done about them; examining a sequence report means examining the gaps and their investigation.

Why are revenue and purchases tested in opposite directions?

Because the incentive and the structure both point that way. A cycle bringing revenue and assets in is tested against the possibility that it brought in more than it should, so the work starts inside the records and vouches back to despatch evidence.

A cycle taking value out is tested against the possibility that something was never recorded, so the work starts outside the records, with goods received notes, supplier statements and post-year-end payments, and traces forward. The direction of the test follows the direction of the risk.

What does a walkthrough actually produce?

Two things that are useful later and nothing that is useful on its own. It confirms that the system described to the auditor is the system that exists, which protects against building a risk assessment on a flow chart nobody has followed. And it locates the specific points at which a control is supposed to bite, which are the only points worth testing.

A walkthrough of one transaction is not a test of controls and cannot support reliance by itself.

Study strategy

Exam move

Draw each of the four cycles as a chain of documents on one page, then mark on the chain where you would start a test for overstatement and where for understatement. Two arrows per cycle. When a question describes a control, find it on your chain first: the position tells you the assertion, and the assertion tells you the test, which is faster and more reliable than working from the description alone.

Working through Internal Control and Auditing the Transaction Cycles in ACT501? Sia is AskSia’s AI Accounting tutor — ask any ACT501 Internal Control and Auditing the Transaction Cycles question and get a clear, step-by-step explanation grounded in how ACT501 is taught and assessed. Read this chapter free, then take your hardest questions to Sia.

A+Everything unlocked
Unlocks this Bible + all 2 of your Lingnan University subjects - and 1,000+ Bibles across every Australian university.
Sia - your ACT501 tutor, unlimited, worked the way the exam marks it
The full 5-page Bible + practice bank with worked solutions
Chrome extension - sync your LMS so Sia knows your deadlines
Bilingual EN / Chinese on every Bible and every Sia answer
$0.99 Trial
30-day money-back · cancel in one tap · how it works