22.3 Understanding the Entity & Internal Control Evaluation
Key Takeaways
PSA 315 (Revised 2019) mandates that the auditor obtain an in-depth understanding of the entity, its regulatory and operating environment, applicable reporting framework, and the five components of internal control to identify and assess risks of material misstatement.
The five internal control components under the COSO Integrated Framework are Control Environment (tone at the top), Entity's Risk Assessment Process, Control Activities, Information System and Communication, and Monitoring of Controls.
Segregation of duties enforces strict operational separation among Custody of assets, Authorization of transactions, Recording in accounting records, and periodic Reconciliation (CAR), preventing a single employee from both perpetrating and concealing errors or fraud.
Tests of controls evaluate operating effectiveness and are mandatory when the auditor's risk assessment includes an expectation of control effectiveness or when substantive procedures alone cannot provide sufficient appropriate audit evidence (such as highly automated, paperless environments).
Under PSA 265, deficiencies in internal control must be evaluated for severity; a significant deficiency or material weakness warrants formal written communication to Those Charged with Governance (TCWG) and management on a timely basis.
Understanding the Entity & Internal Control Evaluation
Under Philippine Standard on Auditing (PSA) 315 (Revised 2019) - Identifying and Assessing the Risks of Material Misstatement, obtaining an understanding of the audited entity, its operating environment, and its internal control system is not an optional procedure—it is a mandatory prerequisite for every audit. The auditor's understanding provides the operational basis for establishing planning materiality, identifying areas where special audit consideration is required (significant risks), and designing the nature, timing, and extent of further audit procedures under PSA 330 (The Auditor's Responses to Assessed Risks).
1. PSA 315 (Revised 2019): Risk Assessment Procedures
The auditor performs risk assessment procedures to provide a basis for the identification and assessment of risks of material misstatement at the financial statement and assertion levels.
Risk Assessment Procedures (PSA 315)
│
┌─────────────────────────┬───────────┴───────────┬─────────────────────────┐
▼ ▼ ▼ ▼
Inquiries of Analytical Observation & Inspecting
Management & Personnel Procedures Walkthroughs Documents
(Governance, internal (Plausible financial (Tracing transactions (Board minutes, manuals,
audit, IT, legal) & non-financial trends) through entire system) contracts, org charts)
Core Risk Assessment Techniques
- Inquiries of Management and Others within the Entity: Inquiries must not be confined to executive management alone. Auditors interview internal auditors (regarding control monitoring), operational personnel (regarding process bottlenecks), IT personnel (regarding systems changes and outages), and in-house legal counsel (regarding litigation and compliance).
- Analytical Procedures (Preliminary / Planning Analytics): Evaluating financial information by studying plausible relationships among both financial and non-financial data (e.g., comparing current-period gross profit margins against prior periods and industry averages, or comparing recorded payroll expense against employee headcount figures). Preliminary analytical procedures assist in identifying unusual transactions, unexpected ratios, or balances requiring focused audit attention.
- Observation and Inspection: Inspecting the entity's premises, plant operations, warehouse facilities, written internal control manuals, business plans, corporate bylaws, and minutes of board of directors' meetings.
Important Standard Rule: Risk assessment procedures provide audit evidence to support the auditor's risk assessments; however, risk assessment procedures alone do not provide sufficient appropriate audit evidence upon which to base an audit opinion. They must be followed by further audit procedures (tests of controls and/or substantive procedures).
2. The Five Components of Internal Control (COSO Framework)
PSA 315 (Revised 2019) describes internal control through five components that correspond to the Committee of Sponsoring Organizations of the Treadway Commission (COSO) Internal Control - Integrated Framework. Internal control is defined as:
The process designed, implemented, and maintained by those charged with governance, management, and other personnel to provide reasonable assurance about the achievement of an entity's objectives with regard to reliability of financial reporting, effectiveness and efficiency of operations, and compliance with applicable laws and regulations.
The Five COSO Components
│
┌───────────────────────┴───────────────────────┐
▼ ▼
1. Control Environment 2. Risk Assessment Process
(Tone at the Top / Ethics) (Identifying Business Risks)
│ │
└───────────────────────┬───────────────────────┘
▼
3. Control Activities
(Policies, Approvals, CAR SOD)
│
┌───────────────────────┴───────────────────────┐
▼ ▼
4. Information & Communication 5. Monitoring of Controls
(Accounting Systems & Flow) (Internal Audit & Ongoing Checks)
1. Control Environment (The Foundation / "Tone at the Top")
The control environment sets the tone of an organization, influencing the control consciousness of its people. It is the foundation for all other components of internal control, providing discipline and structure.
- Elements of the Control Environment:
- Communication and Enforcement of Integrity and Ethical Values: Essential elements that influence the effectiveness of the design, administration, and monitoring of controls. Includes corporate codes of conduct and whistleblower hotlines.
- Commitment to Competence: Management's specification of required competence levels for particular jobs and translating those levels into knowledge and skills.
- Participation by Those Charged with Governance: Independence from management, experience and stature of board members, and active involvement of the Audit Committee.
- Management's Philosophy and Operating Style: Management's approach to taking and managing business risks, attitudes toward financial reporting, and conservatism versus aggressiveness in selecting accounting policies.
- Organizational Structure: The framework within which an entity's activities for achieving its objectives are planned, executed, controlled, and reviewed.
- Assignment of Authority and Responsibility: How authority and responsibility for operating activities are assigned and how reporting relationships and authorization hierarchies are established.
- Human Resource Policies and Practices: Standards for recruiting, hiring, orientation, training, evaluating, counseling, promoting, and compensating personnel.
Pervasive Effect: A deficient control environment (e.g., an autocratic CEO who overrides controls and exhibits contempt for accounting rules) undermines even technically sophisticated control activities. If the control environment is weak, the auditor must assess RMM as high and expand substantive testing at year-end.
2. The Entity's Risk Assessment Process
This component refers to the entity's internal process for identifying, analyzing, and managing risks relevant to the preparation of financial statements in conformity with PFRS. Business risks can arise from:
- Rapid changes in the operating environment (e.g., supply chain disruption).
- New personnel entering key accounting positions.
- New or revamped information systems.
- Rapid corporate expansion or entry into unfamiliar foreign markets.
- New accounting pronouncements (e.g., implementation of PFRS 15, 16, or 17).
If the entity fails to identify a significant business risk that the auditor subsequently identifies, the auditor considers why the entity's risk assessment process failed and evaluates whether a significant deficiency in internal control exists.
3. Control Activities
Control activities are the specific policies and procedures that help ensure that management directives are carried out. They operate at all levels of the entity across various stages of transaction processing.
- Major Categories of Control Activities:
- Performance Reviews: Comparing actual performance against budgets, forecasts, and prior-period metrics; relating different sets of data (operational vs financial).
- Information Processing Controls: Verifying transaction accuracy, completeness, and authorization within IT systems (comprising General IT Controls and Application Controls).
- Physical Controls: Physical security of assets (locked storerooms, safe deposit boxes, security guards, dual-key authorizations) and periodic physical counts matched against accounting records (e.g., cash counts, physical inventory counts).
- Segregation of Duties (SOD): Assigning different people the responsibilities of authoring transactions, recording transactions, and maintaining custody of assets.
4. Information System and Communication
The information system relevant to financial reporting objectives consists of the procedures and records established to:
- Initiate, record, process, and report entity transactions (as well as events and conditions) and to maintain accountability for the related assets, liabilities, and equity.
- Resolve incorrect processing of transactions (e.g., suspense accounts and exception logs).
- Capture information relevant to financial reporting beyond journal entries, such as depreciation schedules, pension liability estimates, and lease discount rates.
- Ensure open communication channels so employees understand how their roles relate to the work of others and how exceptions should be reported to senior leadership.
5. Monitoring of Controls
Monitoring of controls is a process to assess the effectiveness of internal control performance over time. It involves assessing the design and operation of controls on a timely basis and taking necessary corrective actions.
- Ongoing Activities: Routine operational reviews built into normal recurring activities (e.g., managers reviewing monthly store variance reports).
- Separate Evaluations: Periodic audits conducted by an independent Internal Audit Function or external technical consultants.
3. Segregation of Duties: The CAR Framework & Conflict Matrix
Segregation of duties (SOD) is the most critical preventative control in transaction processing. The fundamental rule states that no single individual should be in a position to both perpetrate an error or fraud and conceal it in the normal course of their duties.
The CAR Segregation Rule
│
┌───────────────────────┼───────────────────────┐
▼ ▼ ▼
C - Custody A - Authorization R - Recording
(Physical possession, (Approving orders, (Posting ledgers,
check signing, cash) credit, write-offs) journal entries)
│ │ │
└───────────────────────┼───────────────────────┘
▼
Plus: Independent Reconciliation
(Bank recs, physical inventory counts)
The CAR Framework: Core Segregated Functions
- C - Custody of Assets: Having direct physical or electronic possession of, or access to, company assets (e.g., receiving cash at the counter, holding checkbooks, having custody of inventory in the warehouse, holding negotiable securities).
- A - Authorization of Transactions: Holding the formal managerial authority to approve transactions or commit company resources (e.g., approving customer credit limits, approving purchase orders, authorizing bad debt write-offs, signing vendor contracts).
- R - Recording of Transactions: Preparing, entering, or posting journal entries, maintaining general ledgers, subsidiary ledgers, or preparing financial statements.
- Independent Reconciliation: Comparing recorded book assets with physical assets or external third-party records (e.g., preparing monthly bank reconciliations, conducting physical inventory counts, reconciling accounts receivable subsidiary ledgers to the general ledger control account). Reconciliations must be performed by someone independent of Custody, Authorization, and Recording.
Comprehensive SOD Violation & Conflict Matrix
| Combined (Violative) Duties | Fraud / Concealment Risk Enabled | Real-World Exam Scenario |
|---|---|---|
| Custody + Recording | The employee can steal company assets and falsify the accounting records to conceal the theft (e.g., writing off stolen inventory as normal scrap, or debiting an expense account for stolen cash). | The accounts receivable bookkeeper who also receives customer cash collections can steal cash receipts and conceal it via lapping or posting unauthorized credit memos. |
| Authorization + Custody | The individual can authorize fictitious or excessive transactions and then appropriate the resulting assets directly for personal gain. | A purchasing manager who can authorize purchase orders and also receives and inspects inbound goods at the loading dock can order goods for personal use and sign off on their receipt. |
| Authorization + Recording | An employee can authorize fictitious transactions and record false entries, creating fictitious assets or masking operational losses without independent check. | An accounting supervisor who has authority to write off bad debts and also posts entries to the accounts receivable control account can write off debts of friends or related parties. |
| Custody + Reconciliation | An individual holding asset custody can disguise shortages during the reconciliation process by fabricating reconciling items or altered balances. | A cashier who handles daily cash deposits and also prepares the monthly bank reconciliation can hide stolen cash by recording fictitious deposits in transit. |
4. Documenting Internal Control & Walkthrough Tests
Pursuant to PSA 315, the auditor must document the understanding obtained regarding the entity's internal control components. Common documentation methodologies include:
Internal Control Documentation Methods
│
┌─────────────────────────┬───────┴─────────┬─────────────────────────┐
▼ ▼ ▼ ▼
Narrative Flowcharts Internal Control Checklists
Descriptions (Diagrammatic) Questionnaires (Standardized step
(Detailed step-by-step (Clear document flow (ICQs: Yes/No lists; verifications)
prose of processes) & departmental lines) "No" = weakness)
- Narrative Descriptions: A detailed, written step-by-step narrative of the system. Best suited for simple, straightforward transaction cycles with few automated interfaces.
- Flowcharts: A symbolic, diagrammatic depiction of the flow of documents, operations, and data across departments from initiation to general ledger posting. Flowcharts provide superior visualization of departmental handoffs and segregation of duties boundaries.
- Internal Control Questionnaires (ICQs): A structured series of questions regarding internal control operations, typically answered with "Yes," "No," or "N/A." A "No" answer immediately highlights a potential internal control deficiency.
Walkthrough Tests (Tracing a Single Transaction)
A walkthrough test involves tracing one or a few transactions through the entire financial reporting system from origination, through authorization, recording, processing, and reporting in the general ledger and financial statements.
- Objective of a Walkthrough: Confirms the auditor's understanding of the design and implementation of the controls. It allows the auditor to verify that the workflow described in flowcharts or narratives actually exists in practice.
- Crucial Distinction: A walkthrough test confirms design and implementation; it does NOT constitute a test of operating effectiveness over time, because a sample of one or two transactions cannot prove that the control operated consistently across the entire 12-month period.
5. Tests of Controls vs. Substantive Procedures
Further Audit Procedures
│
┌───────────────────────┴───────────────────────┐
▼ ▼
Tests of Controls Substantive Procedures
(Evaluating Operating Effectiveness) (Detecting Material Misstatements)
│ │
┌───────────┴───────────┐ ┌───────────┴───────────┐
▼ ▼ ▼ ▼
Mandatory Scenario 1 Mandatory Scenario 2 Substantive Tests of Substantive
(Auditor intends to (Substantive tests alone Details Analytics
rely on controls to insufficient: highly (Invoices, counts, (Ratios, trends,
reduce substantive tests) automated systems) confirmations) plausible models)
Dual Hierarchy of Audit Procedures
- Tests of Controls: Audit procedures designed to evaluate the operating effectiveness of controls in preventing, or detecting and correcting, material misstatements at the assertion level throughout the period under audit.
- Methods: Inquiry, observation, inspection of documentation (e.g., initials indicating approval), and reperformance of the control.
- Substantive Procedures: Audit procedures designed to detect material misstatements at the assertion level.
- Comprises: (a) Substantive tests of details (of classes of transactions, account balances, and disclosures); and (b) Substantive analytical procedures.
When Tests of Controls are Mandatory
Under PSA 330, the auditor must perform tests of controls in only two circumstances:
- When the Auditor's Risk Assessment Includes an Expectation of the Operating Effectiveness of Controls: When the auditor intends to rely on controls to assess Control Risk below the maximum, thereby reducing the extent of substantive procedures.
- When Substantive Procedures Alone Cannot Provide Sufficient Appropriate Audit Evidence at the Assertion Level: When an entity conducts its business using highly automated, paperless IT systems (e.g., e-commerce platforms, electronic fund transfers [EFT], or automated inventory replenishment systems where sales orders, deliveries, and billings are initiated and processed without manual paper trails). In such systems, evidence of transaction validity exists solely within electronic system logs, making tests of automated controls legally and practically mandatory.
6. Information Technology (IT) Controls: GITC vs. Application Controls
In modern computerized accounting systems, internal control evaluation divides into General IT Controls (GITC) and Automated Application Controls.
IT Control Architecture
│
┌────────────────────────┴────────────────────────┐
▼ ▼
General IT Controls (GITC) Automated Application Controls
(Pervasive Environment Security) (Individual Program Business Logic)
├─ Access Security (User rights, passwords) ├─ Input Controls (Field, limit, validity)
├─ Program Changes (Change management) ├─ Processing Controls (Run-to-run totals)
├─ Program Development (Testing, implementation) └─ Output Controls (Exception reports)
└─ Computer Operations (Backups, disaster recovery)
General IT Controls (GITC)
GITCs are policies and procedures that relate to many applications and support the effective functioning of application controls by helping to ensure the continued proper operation of information systems. GITCs operate across four domains:
- Access Security: User access management, multi-factor authentication, firewalls, role-based security profiles, and segregation of duties within IT (e.g., separating system developers from production database operators).
- Program Changes (Change Management): Structured testing, documentation, and formal managerial sign-offs before any modifications or software patches are moved from the development/testing environment into the live production environment.
- Program Development / Acquisition: Evaluating, designing, testing, and installing new enterprise resource planning (ERP) packages.
- Computer Operations: Routine automated batch scheduling, daily off-site data backups, uninterruptible power supply (UPS) systems, and disaster recovery / business continuity plans.
Automated Application Controls
Application controls are automated procedures embedded within individual computer application software (e.g., billing, payroll, inventory) that operate at the transaction level:
- Input Controls: Designed to provide reasonable assurance that data received for processing have been properly authorized and converted into machine-readable form without error:
- Field Check (Format Check): Ensures only appropriate character types appear in a field (e.g., zip codes or employee ID numbers contain only digits, no alphabet letters).
- Limit Check / Range Check: Tests numerical amounts against predefined upper and lower boundaries (e.g., payroll hours in a weekly batch cannot exceed 84 hours per employee).
- Validity Check: Compares entered data against master file records (e.g., vendor code entered on a purchase order must match an approved vendor code in the active vendor master file).
- Reasonableness Check: Evaluates logical relationships between data fields (e.g., a junior clerical employee cannot have a base salary of PHP 500,000 per month).
- Check Digit: An extra mathematical verification digit appended to an identification number (e.g., bank account number or Tax Identification Number [TIN]).
- Processing Controls: Run-to-run totals, file record counts, and automated balance verifications.
- Output Controls: Reconciling batch totals to control sheets and ensuring printed checks or electronic payment files are distributed only to authorized personnel.
The Foundational Interrelationship: Application controls depend on effective GITCs. If General IT Controls are weak (for example, programmers have unrestricted administrative access to alter production programs at will), the auditor cannot rely on automated application controls, even if those application controls appear properly designed.
7. Evaluating and Communicating Control Deficiencies under PSA 265
Pursuant to PSA 265 (Communicating Deficiencies in Internal Control to Those Charged with Governance and Management), the auditor must evaluate the severity of identified internal control deficiencies.
Hierarchy of Internal Control Deficiencies
│
┌─────────────────────────┼─────────────────────────┐
▼ ▼ ▼
Control Deficiency Significant Deficiency Material Weakness
- Control missing or failed - Merits the attention of - Reasonable possibility that
- Minor operational impact governance (TCWG) material misstatement will
- Communicate to management - Written communication to not be prevented or detected
(oral or written) TCWG and Management - Written communication to TCWG
Deficiency Classifications
- Deficiency in Internal Control: Exists when:
- A control is designed, implemented, or operated in such a way that it is unable to prevent, or detect and correct, misstatements in the financial statements on a timely basis; or
- A control necessary to prevent, or detect and correct, misstatements in the financial statements on a timely basis is missing.
- Significant Deficiency: A deficiency or a combination of deficiencies in internal control that, in the auditor's professional judgment, is of sufficient importance to merit the attention of those charged with governance.
- Material Weakness: A severe significant deficiency (or combination of significant deficiencies) such that there is a reasonable possibility that a material misstatement of the financial statements will not be prevented, or detected and corrected, on a timely basis.
PSA 265 Communication Protocol
| Classification | Recipient of Communication | Format | Timing Required |
|---|---|---|---|
| Significant Deficiencies | Those Charged with Governance (Audit Committee / Board) and appropriate senior management | Strictly in Writing | On a timely basis; because the written communication forms part of the final audit file, it is completed no later than file assembly (ordinarily within 60 days after the auditor's report date). |
| Other Control Deficiencies | Appropriate level of management | Written or Oral | Timely basis, during the engagement. |
Mandatory Contents of Written Communication (PSA 265)
The auditor's formal written report on significant deficiencies must include:
- A detailed description of the deficiencies and an explanation of their potential effects.
- Sufficient information to enable Those Charged with Governance and management to understand the context of the communication, explicitly explaining that:
- The purpose of the audit was for the auditor to express an opinion on the financial statements.
- The audit included consideration of internal control relevant to the preparation of the financial statements in order to design audit procedures that are appropriate in the circumstances, but not for the purpose of expressing an opinion on the effectiveness of internal control.
- The matters being reported are limited to those deficiencies that the auditor has identified during the audit and that the auditor has concluded are of sufficient importance to merit being reported to Those Charged with Governance.
In a mid-sized wholesale distribution enterprise in Cebu City, an audit senior identifies several internal control procedures across various operational departments. Which of the following work assignments represents an irreconcilable conflict of segregation of duties under the CAR framework?
The warehouse receiving dock manager inspects incoming raw materials, signs vendor bills of lading, and forwards signed receiving reports to accounts payable.
The billing clerk generates customer sales invoices based on authorized price lists, mails the invoices to customers, and logs total sales into the sales journal.
The cashier receives cash and checks from customers at the payment counter, records the daily customer receipts in the accounts receivable subsidiary ledger, and prepares the bank deposit slip.
The independent internal auditor reviews monthly bank reconciliations prepared by the general accountant and conducts unannounced cash counts.
Under PSA 315 (Revised 2019) and PSA 330, in which operational circumstance is an external auditor legally and professionally mandated to perform Tests of Controls rather than relying solely on substantive testing procedures?
When the audited entity operates as a newly formed sole proprietorship with completely manual paper-based journal entries.
When the entity conducts its business transactions using highly automated IT systems where transaction authorization and processing occur electronically without generating manual documentary trails.
When the engagement partner decides to assess Inherent Risk and Control Risk at maximum across all material balance sheet assertions.
When the client's board of directors explicitly requests the external auditor to perform a full management consultancy review.
While conducting an audit of a regional commercial bank, the audit team discovers that IT software programmers have unrestricted administrative write access to both the development environment and the live production financial database, allowing them to alter core accounting programs without independent testing or supervisory approval. Furthermore, the bank lacks an automated reconciliation control for interbank wire transfers exceeding PHP 50,000,000. How should the auditor classify and communicate these findings pursuant to PSA 265?
Classify the findings as significant deficiencies or material weaknesses, and issue a formal written communication to Those Charged with Governance (TCWG) and senior management no later than 60 days following the audit report date.
Classify the findings as minor internal control anomalies, communicate them verbally to the chief information officer, and omit them from any written audit reports.
Immediately withdraw from the audit engagement and file a formal criminal petition with the Bangko Sentral ng Pilipinas without notifying the board.
Issue an immediate adverse audit opinion on the bank's financial statements without conducting any substantive audit testing on cash balances.
Sections you finish are checked off in the contents.