• Log In
  • Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • HomePage
  • About
  • Syllabus
  • Schedule
    • First Half of the Semester
      • Week 1: Introduction
      • Week 2: Business Process; Assertions
      • Week 3: Fraud, P2P Controls
      • Week 4: OTC Process, Types of Controls
      • Week 5: Inventory & Shipping Controls
      • Week 6: Invoicing & Collection Controls
      • Week 7: IT vs. SAP Controls, Security 1
    • Second Half of the Semester
      • Week 8: Security: Roles, Finance Process & Controls
      • Week 9: Security: User Management, Segregation of Duties
      • Week 10: Data, SOD/SAT Review
      • Week 11: Change Management, Development
      • Week 12: Auditing, Table Security, Risk / Control Framework
      • Week 13: SAP Futures, Special System Access
      • Week 14: Character vs. Controls
  • Assignments
    • SAP GUI Installation
    • Exercise 1: Procure to Pay
    • Exercise 2: Order to Cash
    • Exercise 3: Journal Entries
    • Exercise 4: Segregation of Duties (SOD)
    • Final Exercise: Risk-Controls Framework
    • Extra Credit Assignment
  • Roster / Schedule / Teams
  • Gradebook

Auditing Controls in ERP Systems - 2018

Auditing Controls in ERP Systems - 2018

Week 12: Table Security, Control Framework

Week 12: Table Security, Risk/Control Framework Wrap-up

November 28, 2020 by Edward N Beaver

Continuing great job on the discussions. Keep up the good work.   You raised most of the important points but let me summarize my view.

Q1: Have you ever been involved with an internal audit or audit of your process / project?
Thanks for all the good examples shared – they remind me of the many audits I performed or was involved with (often as the subject of the audit).
In today’s world, there are audits of may kinds and someday I expect everyone will have some experience an and auditee or auditor. I note a lot oa consistency regardless of the subject of the audit: It starts with a defined procedure or expectation of how the process of activity should occur, there’s a methodical way to review how activities occur in the real world to measure vs. that expectation with a defined way to capture the alignment and gaps and address the gaps that are found.

Q2:How is independence maintained when working for the company as an internal auditor?
In my experience independence is taken very seriously. You noted common components: Defined Code of Ethics, organizational separation, Defined audit procedure with lots of documentation – there are even audits of audits. A very important but harder to measure component is the mindset of the auditors and those being audited – we’ll talk more about that in Week 14.

Q3:When is the cost of implementing a compliance control higher then the benefit obtained?  What should an organization do to ensure efficiency and profitability?
Organizations don’t exists just to perform business process controls, audits, etc. They have a responsibility to address their missions (be that making profit or some other defined goal). There can be discussion where the control implementation costs are higher than the benefit. It all starts as many of you noted by doing a good risk assessment (part of you Final Exercise). With this information available management can make better decisions and strike the correct balance of control vs. cost.

 

Week 12 Questions

November 9, 2018 by Xinteng Chen 52 Comments

  1. Have you ever been involved with an internal audit or audit of your process / project? Briefly describe.
  2. How is independence maintained when working for the company as an internal auditor?
  3. When is the cost of implementing a compliance control higher then the benefit obtained? What should an organization do to ensure efficiency and profitability?

Primary Sidebar

Weekly Discussions

  • Assignments (11)
  • Exams (7)
  • General (5)
  • Real World Control Failure Presentations (3)
  • Week 01: Introduction (2)
  • Week 02: Business Process; Assertions (4)
  • Week 03: Fraud, P2P Controls (2)
  • Week 04: OTC Process, Types of Controls (3)
  • Week 05: Inventory & Shipping Controls (3)
  • Week 06: Invoicing & Collection Controls (1)
  • Week 07: General IT vs. SAP Controls, Security 1 (2)
  • Week 08: Security 2, Finance 2 (3)
  • Week 09: Security: User Mgmt, Segregation of Duties (2)
  • Week 10: Data; SOD/SAT Review (2)
  • Week 11: Change Management, Development (3)
  • Week 12: Table Security, Control Framework (2)
  • Week 13: SAP Futures, Special System Access (2)
  • Week 14: Character vs. Controls (4)

Copyright © 2025 · Magazine Pro Theme on Genesis Framework · WordPress · Log in