Auditing — Internal Control and Internal Control over Financial Reporting: Understanding Controls and Testing Them
A company whose internal controls work well makes fewer errors and catches them quickly when they occur. If the auditor obtains evidence that controls are effective, it can assess the control risk of chapter 2 as low and reduce substantive procedures. In Korea, the External Audit Act requires an internal control over financial reporting (ICFR) system by law and has auditors express an audit opinion on its operation for listed companies.
1. The COSO framework
The Internal Control — Integrated Framework revised by COSO in the United States in 2013 underlies the Korean conceptual framework for designing and operating ICFR. It has five components.
| Component | Content | Examples |
|---|---|---|
| Control environment | Management's ethics, organizational structure, oversight by the board and audit committee | Code of ethics, independent audit committee |
| Risk assessment | Identifying and analyzing risks to achieving objectives | Risk review for new businesses or system changes |
| Control activities | Policies and procedures that respond to risks | Authorization, segregation of duties, reconciliations, access controls |
| Information and communication | Generating and communicating necessary information | Closing and reporting system, whistleblowing channel |
| Monitoring | Checking that controls keep working | Internal audit, self-assessment |
2. Types of control
- Preventive and detective controls: preventive controls stop errors beforehand (purchase approval); detective controls find errors that have occurred (month-end bank reconciliation).
- Manual and automated controls: an automated control (the system blocks orders above a limit) works consistently once properly designed. But the IT general controls it relies on (program change management, access management, operations) must be effective.
- Segregation of duties: no single person should authorize transactions, record them and hold the assets. If the person receiving cash also keeps the receivables ledger, they can divert receipts and alter the records.
3. Internal control over financial reporting in Korea
Article 8 of the External Audit Act requires companies subject to external audit to establish and operate an ICFR system. The CEO reports on its operation to the shareholders’ meeting, the board and the auditor or audit committee, and the audit committee evaluates its operation and reports to the board. For listed companies, the auditor performs an audit, not a review, of ICFR; this has been phased in by asset size. ICFR on a consolidated basis is also being introduced in stages, starting with large listed companies.
4. Tests of controls
To rely on a control, the auditor must obtain evidence through tests of controls that it operated effectively throughout the period under audit. The methods are inquiry, observation, inspection of documents and reperformance. Inquiry alone is not enough.
Testing a sample of 60 items of AG’s purchase approval control found 3 processed without approval, a sample deviation rate of 5%. If the tolerable rate is 5%, the upper deviation limit allowing for sampling risk exceeds 5% (about 13% at a 95% confidence level), so the control cannot be relied on. Control risk is assessed as high and substantive procedures on purchases are increased. Sample sizes and the calculation of upper deviation limits are covered in chapter 5.
5. Evaluating deficiencies
| Classification | Meaning |
|---|---|
| Deficiency | A control is not designed or operated so as to prevent or detect misstatements on a timely basis |
| Significant deficiency | Less severe than a material weakness but important enough to merit the attention of those charged with governance |
| Material weakness | A reasonable possibility that a material misstatement of the financial statements will not be prevented or detected on a timely basis |
In an ICFR audit, a material weakness leads the auditor to issue an adverse opinion. For listed companies, consecutive adverse ICFR opinions can bring penalties such as designation as an administrative issue.
Check your understanding
At AH, one employee registers suppliers, approves payments for purchases and records the payables ledger. What risk does this create, and what controls can reduce it? If the auditor assesses control risk in this area at 100%, inherent risk at 50% and target audit risk at 5%, what is the acceptable detection risk?
One person could register a fictitious supplier, pay it and then adjust the ledger, so the risk of misappropriation is high. Split supplier registration, payment approval and recording among different people, have an independent department verify the business registration of new suppliers, and require payments to be approved by two or more people. Acceptable detection risk is , so strong substantive procedures on purchases and payables are needed.
References
- Act on External Audit of Stock Companies, etc., Article 8 (operation of internal control over financial reporting) — Korea Law Information Center
- Committee of Sponsoring Organizations of the Treadway Commission (COSO), Internal Control — Integrated Framework (2013)
- Korean Institute of CPAs, Korean Standards on Auditing, KSA 265 Communicating Deficiencies in Internal Control to Those Charged with Governance and Management
Oiyo
Editorial DeskThe OIYO editorial desk researches money, law, lifestyle, and self-understanding topics against primary sources and public statistics. Every piece carries source notes and is reviewed on a regular cycle for accuracy and usefulness.