Control and the AIS
Control and the Accounting Information System
This paper discusses the process of integrating controls into the accounting information system (AIS) using enterprise risk management (ERM) components. ERM is defined as "a process, effected by an entity's board of directors, management and other personnel, applied in strategy setting and across the enterprise, designed to identify potential events that may affect the entity, and manage risk to be within its risk appetite, to provide reasonable assurance regarding the achievement of entity objectives." (Committee of Sponsoring Organizations of the Treadway Commission, COSO, 2004, p.2).
According to COSO, ERM encompasses:
Aligning risk appetite and strategy
Enhancing risk response decisions
Reducing operational surprises and losses
Identifying and managing multiple and cross-enterprise risks
Seizing opportunities
Improving deployment of capital (COSO, 2004, p. 7).
ERM integrates concepts of internal control and the Sarbanes-Oxley Act. Internal controls of accounting systems are intended to protect a company from fraud, abuse, and inaccurate data recording, as well as to help organizations keep track of essential financial activities....
Our semester plans gives you unlimited, unrestricted access to our entire library of resources —writing tools, guides, example essays, tutorials, class notes, and more.
Get Started Now