Podcast
Questions and Answers
Which type of controls are implemented at the time of installing the ERP?
Which type of controls are implemented at the time of installing the ERP?
Which options are commonly known as processing controls?
Which options are commonly known as processing controls?
What is a fundamental aspect of inherent controls?
What is a fundamental aspect of inherent controls?
What must an auditor do if they find ineffective General IT Controls (GITC)?
What must an auditor do if they find ineffective General IT Controls (GITC)?
Signup and view all the answers
Should an auditor report deficiencies that were present in prior audit periods?
Should an auditor report deficiencies that were present in prior audit periods?
Signup and view all the answers
What is the nature of the audit procedures required for companies?
What is the nature of the audit procedures required for companies?
Signup and view all the answers
Which term best describes a system where all modules are seamlessly connected?
Which term best describes a system where all modules are seamlessly connected?
Signup and view all the answers
In an ERP system, how many primary sets of Books typically exist?
In an ERP system, how many primary sets of Books typically exist?
Signup and view all the answers
Which of the following is not a possible reason why substantive procedures may not be feasible in ERP?
Which of the following is not a possible reason why substantive procedures may not be feasible in ERP?
Signup and view all the answers
Which of these best characterizes the flow of transactions in an integrated ERP system?
Which of these best characterizes the flow of transactions in an integrated ERP system?
Signup and view all the answers
What does an integrated Enterprise Resource Planning system imply about its modules?
What does an integrated Enterprise Resource Planning system imply about its modules?
Signup and view all the answers
In the context of ERP systems, what is a characteristic trait of transactions?
In the context of ERP systems, what is a characteristic trait of transactions?
Signup and view all the answers
What is implied by a 'high volume of transactions' in ERP systems?
What is implied by a 'high volume of transactions' in ERP systems?
Signup and view all the answers
What can be utilized to extract payroll information such as leaves available per employee?
What can be utilized to extract payroll information such as leaves available per employee?
Signup and view all the answers
Which of the following is not considered an element for determining the testing strategy for reports?
Which of the following is not considered an element for determining the testing strategy for reports?
Signup and view all the answers
What is included in the validation of reports?
What is included in the validation of reports?
Signup and view all the answers
Before planning to understand the types of reports, the auditor checks the ____________ of the data.
Before planning to understand the types of reports, the auditor checks the ____________ of the data.
Signup and view all the answers
When may the auditor limit test procedures to validate or test the reports?
When may the auditor limit test procedures to validate or test the reports?
Signup and view all the answers
Which indicative commands are used by companies in SAP to generate reports?
Which indicative commands are used by companies in SAP to generate reports?
Signup and view all the answers
What aspect of report validation ensures that all necessary data is included?
What aspect of report validation ensures that all necessary data is included?
Signup and view all the answers
Which of the following would NOT typically be checked for during data validation?
Which of the following would NOT typically be checked for during data validation?
Signup and view all the answers
What does NSJE stand for?
What does NSJE stand for?
Signup and view all the answers
Where can unusual, non-recurring transactions typically be directly entered?
Where can unusual, non-recurring transactions typically be directly entered?
Signup and view all the answers
Estimates and impairments are generally categorized as what type of journal?
Estimates and impairments are generally categorized as what type of journal?
Signup and view all the answers
What should be noted while understanding IT/ERP systems that record entries?
What should be noted while understanding IT/ERP systems that record entries?
Signup and view all the answers
Which of the following are considered fraud risk factors leading to unusual transactions?
Which of the following are considered fraud risk factors leading to unusual transactions?
Signup and view all the answers
In which type of entries are unusual transactions for non-recurring events typically recorded?
In which type of entries are unusual transactions for non-recurring events typically recorded?
Signup and view all the answers
What does PCI-DSS stand for?
What does PCI-DSS stand for?
Signup and view all the answers
Which of the following best describes non-standard journal entries?
Which of the following best describes non-standard journal entries?
Signup and view all the answers
What could lead to non-standard journal entries besides impairments?
What could lead to non-standard journal entries besides impairments?
Signup and view all the answers
Which of the following is NOT a key aspect of SA 300?
Which of the following is NOT a key aspect of SA 300?
Signup and view all the answers
Which of the following standards is related to assurance engagements?
Which of the following standards is related to assurance engagements?
Signup and view all the answers
What area does PCI-DSS primarily address?
What area does PCI-DSS primarily address?
Signup and view all the answers
Which of the following terms is associated with ISAE?
Which of the following terms is associated with ISAE?
Signup and view all the answers
Payment Card Industry Data Security Standard is developed to ensure what?
Payment Card Industry Data Security Standard is developed to ensure what?
Signup and view all the answers
How does ISAE benefit auditors?
How does ISAE benefit auditors?
Signup and view all the answers
Which of the following is part of the goals of PCI-DSS?
Which of the following is part of the goals of PCI-DSS?
Signup and view all the answers
The main focus of SA 300 is primarily on which aspect?
The main focus of SA 300 is primarily on which aspect?
Signup and view all the answers
What must be tested annually for completeness and accuracy?
What must be tested annually for completeness and accuracy?
Signup and view all the answers
Who needs to be verified by the auditor when testing custom reports?
Who needs to be verified by the auditor when testing custom reports?
Signup and view all the answers
What should be verified if changes occurred to a custom report before an audit?
What should be verified if changes occurred to a custom report before an audit?
Signup and view all the answers
What type of access do users with critical business activity capabilities have in an ERP?
What type of access do users with critical business activity capabilities have in an ERP?
Signup and view all the answers
What is the purpose of segregation of duties?
What is the purpose of segregation of duties?
Signup and view all the answers
What generally defines the relationship between ERP roles and users?
What generally defines the relationship between ERP roles and users?
Signup and view all the answers
What group typically consists of regular employees who perform daily tasks in an ERP?
What group typically consists of regular employees who perform daily tasks in an ERP?
Signup and view all the answers
What represents a designation within a company and not an individual?
What represents a designation within a company and not an individual?
Signup and view all the answers
What type of errors may occur when deficiencies are present in a tested report?
What type of errors may occur when deficiencies are present in a tested report?
Signup and view all the answers
What distinguishes privileged users in an ERP system?
What distinguishes privileged users in an ERP system?
Signup and view all the answers
Internal users of the ERP system that perform automated operations are known as?
Internal users of the ERP system that perform automated operations are known as?
Signup and view all the answers
What kind of users do not belong to the company?
What kind of users do not belong to the company?
Signup and view all the answers
What is an effective access control feature in an ERP?
What is an effective access control feature in an ERP?
Signup and view all the answers
What are controls established to manage data manipulation in the context of databases?
What are controls established to manage data manipulation in the context of databases?
Signup and view all the answers
Study Notes
ERP Systems
- ERP systems (Enterprise Resource Planning) are integrated management systems encompassing various business functions.
- Examples include SAP and Oracle.
Internal Control Risk Assessment (SA 315)
- Auditors aim to identify and assess material misstatement risks, including fraud.
- Understanding the entity and internal control environment, including relevant information systems.
- Auditor's responsibility is to design and implement responses in audit procedures in response to SA315.
- Assessing the effectiveness of internal controls for reporting.
Governance Framework
- The business team is the owner of data residing within application.
- Ownership is transferred to the IT team in charge of application
- Communication channels are crucial between Chief Information Officer and Chief Financial Officer for effective data management
Automated Environment Risks
- Automated environments present numerous risks due to the complexity and interconnectedness of applications.
- Risks are influenced by the number and location of applications within the system.
Reporting from ERP Systems
- Standard generated reports are provided by ERP systems to businesses
- Customised reports are developed for business use within the ERP system.
- Database queries are used to retrieve information in a structured format from the database.
Controls in ERP
- Inherent controls ensure the accuracy, completeness, and validity of transactions, present in ERP.
- Configurable controls are those implemented during ERP installation in an organization.
- Input controls are the first point of control within ERP.
Sensitive Access and Segregation of Duties (SOD)
- Sensitive access in an ERP system grants extensive or unrestricted access to carry out various activities.
- Role-based access control (RBAC) involves grouping related access rights into roles for streamlined user management.
- Segregation of Duties is the distribution of job roles among employees to avoid conflicts and ensure accountability.
User Roles and Access
- Normal users perform daily operations within the ERP system.
- System users execute automated operations and transactions.
- Privileged users possess extensive or unlimited access for key activities.
- Default users come embedded with the ERP software
- Generic users are positions or designations, not specific people
- Temporary users are granted access for a limited time.
- External users represent individuals/entities outside the company
- Multiple roles and users can interact in a "many-to-many" relationship.
User and Access Control Deficiencies
- Auditors must document and report control deficiencies to management, following standards.
- The deficiencies relating to user access controls should be evaluated in order to understand the impact of the deficiencies on audit.
- Understanding the business environment and IT environment is a crucial starting point for audits on segregation of duties.
- The business rules for the implementation and review of SOD and sensitive access should focus on the company rules, policies and procedure.
ERP Migration and Data Procedures
- ERP migration involves planning, system design, data conversion/configuration, testing, and go-live stages.
- Rollback procedures are for managing potential errors during the process.
- During migration, sensitive access, SOD, and related controls must be considered.
- Internal auditors can provide valuable experience regarding ERP changes.
- Documentation is essential to effectively manage any ERP implementation.
Financial Data Records (Journal Entries)
- Standard journal entries record regular transactions.
- Non-standard journal entries capture unusual and non-recurring transactions, adjustments, and corrections.
- Non-standard entries are often not subject to normal internal controls.
- The extraction and analysis of JE data can be enhanced using software scripts.
Query Creation and Usage in ERP
- Subqueries can be used within queries to filter specific output values.
- Access uses a variety of queries ranging from simple to complex, capable of extracting aggregated results.
- Joins in Access can connect data from different tables.
- Aggregate functions summarise numerical values.
- A wide arrange of filters are available for further refinement.
Working with and Summarizing Data
- Using Pivot Tables helps users quickly summarize and analyze data in a spreadsheet.
- Calculations can be run on existing data using expressions and functions.
- Conditional formatting highlights cells containing specific values, a powerful method to track and refine data during analyses.
Statistical and Probability Concepts
- Benford's Law is useful for identifying potential data irregularities when a specific numerical pattern appears significantly off from the expected value.
- Hypothesis testing involves comparing observed data to a predicted outcome, using calculated probabilities to determine whether to accept or reject those probabilities.
- Statistical analysis is crucial for drawing meaningful conclusions from data sets.
Data Mining and Warehousing
- Data Mining is used to uncover patterns from a database.
- Data Warehousing is a repository for storing and organizing historical data, for analysis.
- OLAP is the technique and tool to query complex multi-dimensional databases.
- Operational Data Stores are used for detailed data for processes.
Accounting and Financial Concepts
- Financial Planning involves establishing financial targets.
- Depreciation is the accounting process for spreading the cost of using an asset over its useful life.
- Cash budgets and capital budgeting are used to manage and model monetary flow in a business.
- Various financial ratios help in comparison analysis.
Excel Functions
- Specific Excel functions are used to generate and manage financial/accounting data
- Excel functions help in performing various calculations on financial data.
- There are tools in Excel suited for various data management activities.
Studying That Suits You
Use AI to generate personalized quizzes and flashcards to suit your learning preferences.
Related Documents
Description
Test your knowledge on Enterprise Resource Planning (ERP) systems with this quiz. Explore key concepts such as controls, audit procedures, and transaction characteristics within ERP environments. Ideal for students and professionals looking to enhance their understanding of ERP.