Internal Controls: Authorizations
An auditor tests the design and implementation of relevant automated and manual transaction-level internal controls involving authorizations to determine whether these controls are appropriately designed and have been implemented effectively. This helps the auditor assess the risks of material misstatements and plan further audit procedures. The following steps outline how to test the design and implementation of these controls:
- Identify relevant controls: Determine the key automated and manual transaction-level internal controls involving authorizations, such as approval of purchase orders, authorization of journal entries, or approval of payroll changes.
- Understand the control design: Gain an understanding of the design of each identified control, including the purpose, process flow, and control objectives. Determine whether the control is preventive or detective and assess the adequacy of the control design in addressing the associated risks.
- Evaluate segregation of duties: Assess whether there is an appropriate segregation of duties within the control process, ensuring that no single individual has the ability to initiate, approve, and record transactions without independent review or oversight.
- Perform walkthroughs: Conduct walkthroughs of the identified controls, tracing sample transactions from initiation to completion, and observe the control activities in action. This helps in understanding the control process and assessing whether it operates as designed.
- Inspect documentation: Review documentation related to the identified controls, such as policy and procedure manuals, system configurations, or access control settings. Evaluate the documentation to determine whether it supports the proper design and implementation of the controls.
- Test control effectiveness: Test the effectiveness of the controls by selecting a sample of transactions that have undergone the authorization process. For manual controls, review supporting documentation, such as approved purchase orders or authorized journal entries, to verify that the transactions were properly authorized. For automated controls, test the application’s configuration settings or perform computer-assisted audit techniques (CAATs) to verify that the authorization process is functioning as intended.
- Interview key personnel: Interview personnel involved in the control process, such as employees responsible for initiating transactions, approvers, and reviewers. Obtain insights into the control activities, their understanding of the control objectives, and any known issues or challenges.
- Document test results: Create clear and comprehensive documentation of the tests performed, including the sample transactions tested, the procedures performed, and the results obtained. Highlight any identified control deficiencies or deviations and assess their potential impact on the financial statements.
- Assess control deficiencies: Based on the test results, assess the identified control deficiencies and determine whether they represent significant deficiencies or material weaknesses in the entity’s internal control over financial reporting. This information will be used to plan further audit procedures, including additional tests of controls or substantive procedures, as necessary.
By following these steps, auditors can test the design and implementation of relevant automated and manual transaction-level internal controls involving authorizations, providing valuable insights into the effectiveness of the entity’s internal control over financial reporting.