13.5 Use Table 13-2 to create a questionnaire checklist that can be used to evaluate
controls for each of the basic activities in the expenditure cycle (ordering goods,
receiving, approving supplier invoices, and cash disbursements).
a. For each control issue, write a Yes/No question such that a “No” answer
represents a control weakness. For example, one question might be “Are
supporting documents, such as purchase orders and receiving reports, marked
“paid” when a check is issued to the vendor?”
A wide variety of questions is possible. Below is a sample list:
Question Yes No
1. Is access to supplier master data restricted?
2. Are additions to supplier master data regularly reviewed and all changes
investigated?
3. Is sensitive data encrypted while stored in the database?
4. Does a backup and disaster recovery plan exist?
5. Have backup procedures been tested within the past year?
6. Are appropriate data entry edit controls used?
7. Is a perpetual inventory maintained?
8. Are physical counts of inventory taken regularly and used to adjust the
perpetual inventory records?
9. Are competitive bids used when ordering expensive items?
10. Are purchasing agents required to disclose financial interests in
suppliers?
11. Are budgets set for service expenses and are variances investigated?
12. Is the system configured to generate purchase orders only to suppliers
listed in the database?
13. Are receiving dock employees trained to accept deliveries only when an
approved purchase order exists?
14. Are receiving dock employees trained about the importance of
accurately counting all items delivered?
15. Do receiving dock employees inspect all deliveries for quality?
16. Do both receiving dock employees and inventory control employees
sign off on the transfer of items?
17. Is physical access to inventory restricted?
18. Are invoices only approved for payment when accompanied by both a
purchase order and receiving report?
19. Is supporting documentation cancelled or marked “Paid” when a check
is generated?
20. Are invoices filed by due date (adjusted for any discounts for early
payment)?
21. Is access to blank checks restricted?
22. Is access to the EFT system restricted?
23. Is the bank account regularly reconciled by someone not involved in
issuing checks?