Internal Controls are the policies and procedures that a company implements to ensure efficiency of business operations, reliability of financial reporting, compliance with laws & regulations, safeguarding of assets and prevention of frauds.
Objectives of Internal Control
A. Transactions are executed in accordance with management’s general or specific authorization;
B. all transactions are promptly recorded in the correct amount in the appropriate accounts and in the accounting period in which executed so as to permit preparation of financial information within a framework of recognized accounting policies and practices and relevant statutory requirements, if any, and to maintain
accountability for assets;
C. assets are safeguarded from unauthorised access, use or disposition; and
D. The recorded assets are compared with the existing assets at reasonable intervals and appropriate action is taken with regard to any differences.
Benefits of Understanding of Internal Control
An understanding of internal control assists the auditor in:
i. identifying types of potential misstatements;
ii. identifying factors that affect the risks of material misstatement, and iii. designing the nature, timing, and extent of further audit procedures.
Limitations of Internal Control:
1. Internal control can provide only reasonable assurance: Internal control, no matter how effective, can provide an entity with only reasonable assurance about achieving the entity’s financial reporting objectives. The likelihood of their achievement is affected by inherent limitations of internal control.
2. Human judgment in decision-making: Realities that human judgment in decision-making can be faulty and that breakdowns in internal control can occur because of human error. Example There may be an error in the design of, or in the change to, a control.
3. Lack of understanding the purpose: Equally, the operation of a control may not be effective, such as where information produced for the purposes of internal control (for example, an exception report) is not effectively used because the individual responsible for reviewing the information does not understand its purpose or fails to take appropriate action.
4. Collusion among People: Additionally, controls can be circumvented by the collusion of two or more people or inappropriate management override of internal control. For example, management may enter into side agreements with customers that alter the terms and conditions of the entity’s standard sales contracts, which may result in improper revenue recognition. Also, edit checks in a software program that are designed to identify and report transactions that exceed specified credit limits may be overridden or disabled.
5. Judgements by Management: Further, in designing and implementing controls, management may make judgments on the nature and extent of the controls it chooses to implement, and the nature and extent of the risks it chooses to assume.
6. Limitations in case of Small Entities: Smaller entities often have fewer employees due to which segregation of duties is not practicable. However, in a small owner-managed entity, the owner-manager may be able to exercise more effective oversight than in a larger entity. This oversight may compensate for the generally more limited opportunities for segregation of duties. On the other hand, the owner-manager may be more able to override controls because the system of internal control is less structured. This is taken into account by the auditor when identifying the risks of material misstatement due to fraud.
