Ch. 7: Control and Accounting Information Systems
7.6 Some restaurants use customer checks with prenumbered sequence codes. Each food
server uses these checks to write up customer orders. Food servers are told not to
destroy any customer checks; if a mistake is made, they are to void that check and
write a new one. All voided checks are to be turned in to the manager daily. How
does this policy help the restaurant control cash receipts?
The fact that all documents are prenumbered provides a means for accounting for their use
and for detecting unrecorded transactions. Thus, a missing check indicates a meal for
which a customer did not pay. Since each server has his or her own set of checks, it is easy
to identify which server was responsible for that customer.
This policy may help to deter theft (e.g., serving friends and not requiring them to pay for
the meal, or pocketing the customer’s payment and destroying the check) because a
reconciliation of all checks will reveal that one or more are missing.
7.7 Compare and contrast the following three frameworks: COBIT, COSO Integrated
Control, and ERM.
The COBIT Framework consolidates systems security and control standards into a single
framework. This allows management to benchmark security and control practices of IT
environments, users to be assured that adequate IT security and control exist, and auditors
to substantiate their internal control opinions and to advise on IT security and control
matters. The framework addresses control from three vantage points:
1. Business objectives, to ensure information conforms to and maps into business
objectives.
2. IT resources, including people, application systems, technology, facilities, and data.
3. IT processes, including planning and organization, acquisition and implementation,
delivery and support, and monitoring and evaluation.
COSO’s Internal Control Framework is widely accepted as the authority on internal
controls and is incorporated into policies and regulations that control business activities.
However, it examines controls without looking at the purposes and risks of business
processes and provides little context for evaluating the results. It makes it hard to know
which control systems are most important, whether they adequately deal with risk, and
whether important controls are missing. In addition, it does not adequately address
Information Technology issues.
It has five components:
1. Control environment, which are the individual attributes, (integrity, ethical values,
competence, etc.) of the people in the organization and and the environment in which