ISC CPA Practice Questions: Blockchain and COSO

ISC 1 Blockchain and COSO

Share This...

In this video, we walk through 5 ISC practice questions on blockchain and COSO. These questions are from ISC content area 1 on the AICPA CPA exam blueprints: Information Systems and Data Management.

The best way to use this video is to pause each time we get to a new question in the video, and then make your own attempt at the question before watching us go through it.

Also be sure to watch one of our free webinars on the 6 “key ingredients” to an extremely effective & efficient CPA study process here…

Click here to watch the video on YouTube…

Blockchain and COSO

Blockchain changes how transaction records are created and stored, but it doesn’t remove the need for internal control. The COSO internal control framework still applies, and it gives a structure for identifying what can go wrong and building controls around it.

How a Blockchain Works

A blockchain is a ledger shared among many participants, with each keeping an identical copy. Transactions are grouped into blocks, and each block has a digital fingerprint called a Hash calculated from the information inside it. Every new block stores the hash of the block before it, which links the blocks into a chain.

If someone changes a recorded transaction, the information in that block changes, so its hash changes too. The next block still holds the original hash, so the link breaks. On top of that, the altered copy no longer matches the copies held by everyone else, so the other participants reject it.

This is also why two companies recording on the same chain have nothing to reconcile. Instead of each keeping a separate set of books, they share one record of each transaction.

Immutability Doesn’t Equal Correctness

Once a transaction is on the chain, it can’t be edited or deleted. This is called immutability. An error should be fixed the same way an accountant fixes a posted journal entry, by recording a separate correcting entry. The original error stays on the chain permanently.

Immutability shows that a record hasn’t changed since it was entered. It does not show that the record was correct when it was entered. If an employee enters a $48,000 sale as $84,000, the blockchain preserves that amount exactly as typed. That’s why controls over what goes into the chain matter more than controls that catch problems afterward.

Public and Private Chains

Public blockchains, such as Bitcoin, are open to anyone who wants to join and view transactions. Private blockchains restrict who can join, view, and approve entries, which is how most businesses use them.

Keys and Smart contracts

Private keys are secret codes that control assets on a blockchain. Whoever holds the key can move the asset, and a lost or stolen key generally can’t be recovered. Smart contracts are programs stored on the chain that carry out agreements automatically, such as releasing payment to a vendor once a shipment is marked as received.

Evaluating the Risks Under Risk Assessment

Under COSO’s Risk Assessment component, management identifies each place the company uses blockchain and links the risk to the financial statements.

Holding digital assets raises existence and rights and obligations concerns. If a private key is lost or stolen, the company may report an asset it no longer has or controls. Recording transactions raises accuracy and occurrence concerns, since an incorrect entry is locked in once recorded. Smart contracts raise accuracy and completeness concerns, because flawed code executes automatically. Using a third-party custodian doesn’t move the risk off the financial statements, since the company still reports the assets.

Designing Controls

Control Environment establishes the foundation: board oversight of blockchain use, staff with the right expertise, and agreements among participants defining who validates entries and who is responsible when records are wrong.

Control Activities are the specific controls. These include reviewing and approving transactions before they’re recorded, storing private keys securely offline, requiring multiple approvers to move assets, testing smart contract code before use, restricting access on private chains, obtaining SOC reports from custodians, and reconciling on-chain records to the general ledger.

Information and Communication covers the reliability of data feeding the chain and whether blockchain information is captured completely in the records used to prepare the financial statements.

Monitoring Activities covers periodic review confirming that controls still operate and that the risks identified originally are still the right ones, especially as participants change and new smart contracts are added.

Other Posts You'll Like...

Want to Pass as Fast as Possible?

(and avoid failing sections?)

Watch one of our free "Study Hacks" trainings for a free walkthrough of the SuperfastCPA study methods that have helped so many candidates pass their sections faster and avoid failing scores...