ACT501 Chap.10 Internal Control and Auditing the Transaction Cycles
Internal Control and Auditing the Transaction Cycles
Five weeks of the term in one framework
The published teaching schedule gives week five to understanding the entity's system of internal control, week six to the auditor's responses to assessed risks together with the revenue cycle, week seven to the purchase cycle, week eight to cash balances and week nine to the production cycle.
The syllabus covers the same ground in its indicative content: the basic concepts of internal control, fraud, and the theory and practice of auditing, together with the usual work done on the main accounts and transaction cycles.
What internal control is, and why an auditor cares
It is not a department and not a manual.
It is the system by which an entity obtains reasonable assurance about the reliability of its reporting, the effectiveness of its operations and its compliance with law. The auditor is interested for one reason: it changes how likely a material error in the accounts is, and therefore how much testing has to be done.
The standards group the system into components covering the control environment set by those in charge; the entity's own process for identifying and dealing with risks to its reporting; the information system and communication, through which transactions are initiated, recorded, processed and reported; control activities, the specific acts of authorisation, reconciliation, segregation, physical safeguarding and checking; and monitoring, by which the entity evaluates whether its controls still work.
The walkthrough
The way an auditor first gets to know a system is by taking one transaction of a given type and following it through every stage of processing, from initiation to its appearance in the statements, asking at each step who does what and what evidence they leave.
It has two outputs: confirmation that the auditor's understanding matches the system that exists, and identification of the points at which a control is supposed to bite, which are the only points worth testing later.
Preventive and detective
A preventive control stops an error or fraud entering the records: a credit limit blocking an order, a system refusing payment without a matching purchase order, a division of duties.
A detective control finds an error already in: a bank reconciliation, a sequence check on pre-numbered documents, a review of unusual ledger items. The difference changes what can be concluded. A preventive control that operated all year supports the assertion directly.
A detective control supports it only if the detection actually happened and was acted on, which is why testing a reconciliation means examining the reconciling items and their resolution rather than confirming that the reconciliation exists.
Two routes, one with a gate
After the risk assessment the auditor either tests the controls, which is permitted only where a control is well designed and expected to have operated, or goes straight to substantive procedures.
Reliance reduces substantive work; it never removes it. A failed test of controls sends the whole caption down the substantive route.
Four cycles, four characteristic failures
Each cycle has a direction of risk that follows from the assertion analysis.
The revenue chain runs from customer order through despatch note and invoice into the sales journal and is tested primarily against overstatement, which means vouching from the journal back to despatch evidence and testing cutoff either side of the year end.
The purchase chain runs from requisition through purchase order, goods received note and supplier invoice into the payables ledger and is tested primarily against understatement, which means starting outside the ledger with goods received notes near the year end, supplier statements, and payments made after the year end.
Cash is confirmable directly with the bank, so the interesting work concerns restrictions, security and accounts the entity may not have listed.
Production is the valuation cycle: which costs have legitimately been absorbed into stock, and whether that value is still recoverable.
The pattern behind the table
A cycle bringing money and assets in is tested against the possibility that it brought in more than it should, because that is what flatters the statements.
A cycle taking money and value out is tested against the possibility that some of it was never recorded. Cash and production do not fit that division neatly, which is why they are taught separately rather than as variations on the first two.
What this chapter covers
- 01
Where the five weeks sit in the published schedule
- 02
Internal control as a system rather than a department
- 03
The components the standards group the system into
- 04
The walkthrough, and its two outputs
- 05
Preventive against detective controls
- 06
Why a detective control needs evidence of the detection
- 07
Segregation of duties as a control over people
- 08
Testing controls against going straight to substantive work
- 09
Revenue and purchases as mirror images
- 10
Cash and production, and why they are taught separately
Four controls, three questions each
- 4Classify each control as preventive or detective.
- 4Attach each to the assertion it actually supports.
- 4Choose a test that would establish operation over the period.
Key terms
- Preventive Control
- A control that stops an error or a fraud from entering the accounting records, such as a system block or a division of duties.
- Detective Control
- A control that identifies an error or fraud after it has entered the records, such as a reconciliation or a sequence check.
- Segregation of Duties
- An arrangement ensuring that the person able to cause an error or misappropriation is not the person able to conceal it.
- Control Environment
- The tone, structure, competence and attitude to control set by those in charge, on which the effectiveness of every specific control depends.
- Transaction Cycle
- A chain of linked business activities and documents, such as order to despatch to invoice to receipt, that generates a class of transactions.
- Reliance Approach
- An audit approach in which tests of controls reduce the extent of substantive procedures, available only where controls are well designed and expected to have operated.
Internal Control and Auditing the Transaction Cycles FAQ
Why do auditors spend so long on controls they may not rely on?
Because understanding the system is required whether or not reliance follows. The purpose of that understanding is to identify where misstatement could arise, which is what the risk assessment is built on, and to decide whether reliance is even available. Only when a control is well designed and expected to have operated can testing it reduce substantive work.
Where it is not, the understanding still earns its cost by telling the team where to concentrate substantive procedures instead.
How is testing a detective control different from testing a preventive one?
A preventive control that operated across the period supports the assertion directly, because the error could not have entered the records. A detective control only supports it if the detection actually occurred and was acted on, so the test has to reach the outcome rather than the existence of the routine.
Examining a reconciliation means examining what the reconciling items were and what was done about them; examining a sequence report means examining the gaps and their investigation.
Why are revenue and purchases tested in opposite directions?
Because the incentive and the structure both point that way. A cycle bringing revenue and assets in is tested against the possibility that it brought in more than it should, so the work starts inside the records and vouches back to despatch evidence.
A cycle taking value out is tested against the possibility that something was never recorded, so the work starts outside the records, with goods received notes, supplier statements and post-year-end payments, and traces forward. The direction of the test follows the direction of the risk.
What does a walkthrough actually produce?
Two things that are useful later and nothing that is useful on its own. It confirms that the system described to the auditor is the system that exists, which protects against building a risk assessment on a flow chart nobody has followed. And it locates the specific points at which a control is supposed to bite, which are the only points worth testing.
A walkthrough of one transaction is not a test of controls and cannot support reliance by itself.
Exam move
Draw each of the four cycles as a chain of documents on one page, then mark on the chain where you would start a test for overstatement and where for understatement. Two arrows per cycle. When a question describes a control, find it on your chain first: the position tells you the assertion, and the assertion tells you the test, which is faster and more reliable than working from the description alone.
Working through Internal Control and Auditing the Transaction Cycles in ACT501? Sia is AskSia’s AI Accounting tutor — ask any ACT501 Internal Control and Auditing the Transaction Cycles question and get a clear, step-by-step explanation grounded in how ACT501 is taught and assessed. Read this chapter free, then take your hardest questions to Sia.