ACC 491 Week 4 Internal Control and Information Systems Example

Reviewed by Davina Cresswell, MBA · University of Phoenix · Updated

This ACC 491 Week 4 example evaluates a company's internal control, including the controls in its information systems, and decides how the results affect the audit. In University of Phoenix ACC 491, internal control and information systems come up in week four, where ACC/491 students in the BS in Accounting connect the controls a company runs every day with the evidence an auditor relies on. The paper follows a composite online and store retailer of outdoor gear. It applies the five components of the COSO framework, performs a walkthrough of the online order-to-cash process, tests an automated application control and the IT general controls it depends on, evaluates two deficiencies found, excessive system access and an unreviewed price override, as a significant deficiency and a control deficiency and explains the effect on substantive testing and required communications.

CourseACC 491 Contemporary Auditing I (ACC/491)
Week4
Paper typeInternal control and IT audit paper
Lengthabout 1,041 words, 4 double-spaced pages plus title page and references
FormatAPA 7 student paper
SchoolUniversity of Phoenix
ProgramBS in Accounting
UpdatedSeptember 2026

Free sample paper for ACC 491 Week 4

1

Controls Around an Online Checkout: Understanding, Walking Through and Testing Internal Control and IT General Controls at a Composite Outdoor Gear Retailer, and Grading Two Deficiencies

[Student Name]

University of Phoenix

ACC/491: Contemporary Auditing I

Week 4 Assignment

[Instructor Name]

[Date]

The retailer, its systems and all figures are composites written for a model paper; frameworks, standards and research findings come from the sources listed.

What this part is doingThe title follows the auditor's sequence, understanding, walking through, testing and grading, which is the structure of the paper.
2

A composite retailer sells tents, packs, climbing gear and apparel through its website, which produces about 70% of revenue, and three stores. Its annual revenue is $84 million, most of it processed by an e-commerce platform that feeds orders into its accounting system each night. For the audit, the question is whether the team can rely on the company's controls over revenue, which would allow less detailed substantive testing. When most revenue is recorded by software rather than people, the auditor must audit the controls in the software and the controls over the software. This paper evaluates those controls.

The COSO Framework

The Committee of Sponsoring Organizations framework defines internal control as a process designed to provide reasonable assurance about operations, reporting and compliance, and it has five components (Committee of Sponsoring Organizations of the Treadway Commission, 2013). At this retailer, the control environment includes an audit committee with a CPA member and a code of conduct signed annually. Risk assessment includes a yearly review of fraud risks by the controller. Control activities include approvals, reconciliations and automated controls. Information and communication include the order management and accounting systems and reports. Monitoring includes internal audit reviews by an outsourced firm twice a year.

Walking Through an Online Order

The team traced one order from start to finish. A customer placed an order for a tent and stove. The e-commerce platform applied the price from the product master file, calculated sales tax using a third-party tax engine and authorized the card through the payment processor. The warehouse system generated a pick ticket, the order shipped and shipment confirmation triggered revenue recognition. Each night an interface posted orders to the general ledger, and the next morning an accounting clerk reconciled total orders shipped in the platform with revenue posted in the ledger and investigated any difference over $500. The processor's settlement reports were reconciled to cash weekly.

The walkthrough confirmed that the controls exist and are implemented. It is not a test of whether they operated all year.

What this part is doingStating the limit of a walkthrough prevents the most common confusion between understanding controls and testing them.
3

Testing an Automated Control

Pricing and tax calculation are automated application controls. An automated control performs the same way every time as long as the program has not changed, so the team tested it once: it placed test orders for items in several tax jurisdictions and compared the charged prices and taxes with the approved price list and statutory rates. All were correct. The team also tested the daily reconciliation, a manual control, by selecting 25 days during the year and examining the clerk's reconciliation and follow-up for each; all were performed and reviewed.

IT General Controls

Reliance on an automated control depends on IT general controls, which ensure that the program and its data are protected from unauthorized change. The team tested access controls, reviewing who could change the product master file and pricing, and change management, examining a sample of program changes for approval and testing before release. Change management was effective. Access was not: eleven users could change prices, including two marketing staff whose jobs did not require it and one former employee whose account had not been disabled.

Two Deficiencies

The access weakness means that unauthorized price changes could be made and would flow into revenue automatically. Deficiencies are evaluated by the likelihood that they could result in a misstatement and the magnitude of the potential misstatement. The team found no evidence that access was misused, but the potential effect on revenue is large, and no compensating control reviews price changes after they are made. The team classified it as a significant deficiency, less severe than a material weakness because store sales and gross margin reviews by management would likely detect large unauthorized changes.

In the stores, managers can override prices at the register, and the override report is supposed to be reviewed weekly. The team found that two of the stores' managers did not document their reviews for several months. Store sales are small and overrides averaged under $2,000 a month, so the team classified this as a control deficiency, not a significant one, and reported it to management.

What this part is doingExplaining why one deficiency is significant and the other is not, using likelihood and magnitude, shows the evaluation rather than the label.
4

Service Organizations

The retailer relies on two outside providers for parts of the process: the payment processor and the tax engine. The team cannot test their internal controls directly, so it obtained each provider's service organization controls report, which describes the provider's controls and an independent auditor's tests of them. The team read the reports, confirmed that the periods covered the retailer's fiscal year and noted the complementary controls the retailer itself must perform, such as reviewing the processor's settlement reports. The weekly settlement reconciliation meets that requirement. If a report had identified exceptions in the provider's controls, the team would have assessed whether they affected the retailer's revenue or cash.

Management's Response

Management agreed to remove unnecessary access, disable the former employee's account immediately and add a monthly review of price change logs by the controller. The team will test the new review next year. Correcting a deficiency after year end does not change this year's evaluation, since the weakness existed during the period audited.

Effect on the Audit

Because the access weakness undermines reliance on the automated pricing control, the team increased substantive testing of revenue: it compared prices on a sample of 60 online orders with the approved price list and analyzed gross margin by product category by month to look for unusual changes. Doyle et al. (2007) found that control weaknesses were associated with lower accrual quality, a finding that supports more substantive work where controls are weak. The team will communicate the significant deficiency in writing to the audit committee, as the standard on communicating control matters requires, and the control deficiency to management (American Institute of Certified Public Accountants, 2009).

Conclusion

The retailer's control environment and most controls were effective, and the automated pricing and tax control worked as designed. But excessive access to price changes weakened the IT general controls that the automated control depends on, and the team classified it as a significant deficiency, increased substantive testing of revenue and reported the finding to the audit committee.

5

References

American Institute of Certified Public Accountants. (2009). Communicating internal control related matters identified in an audit (Statement on Auditing Standards No. 115).

Committee of Sponsoring Organizations of the Treadway Commission. (2013). Internal control, integrated framework.

Doyle, J. T., Ge, W., & McVay, S. (2007). Accruals quality and internal control over financial reporting. The Accounting Review, 82(5), 1141-1170. https://doi.org/10.2308/accr.2007.82.5.1141

What the ACC 491 Week 4 instructions ask

For ACC 491 Week 4, the core task is explaining internal control and how an auditor evaluates it. Common requirements include the COSO framework's components and principles, obtaining an understanding of controls through inquiry, observation, inspection and walkthroughs, the difference between tests of controls and substantive procedures, IT general controls and application controls, assessing control risk and classifying deficiencies as control deficiencies, significant deficiencies or material weaknesses. Some prompts ask for a flowchart or narrative of a business process or for the written communication of deficiencies to management and those charged with governance. Tie every idea to one process at one company, and cite COSO and the auditing standards in APA form.

How this ACC 491 Week 4 example is built

An outdoor gear retailer that sells mostly online makes the week concrete, because its revenue passes through automated systems that the auditor must understand before relying on them. The paper first frames the company's control environment and risk assessment using COSO. It then follows one online order from checkout to cash in a walkthrough, identifying the key controls at each step. The automated pricing and tax calculation control is tested once, and the IT general controls that keep it working are tested over the year. Two deficiencies are described with the reasoning behind their classification, and the final section shows how the results change the auditor's substantive work and communications.

ACC 491 Week 4 grading rubric: where the points go

The rubric for this topic tends to reward accurate use of the COSO framework, a correct distinction between understanding controls and testing them, correct treatment of IT general and application controls and correct classification of deficiencies. Faculty check that walkthroughs trace a transaction through the whole process, that automated controls are tested with reliance on IT general controls, that deficiencies are evaluated by likelihood and magnitude of potential misstatement and that the effect on control risk and substantive procedures is stated. Written communication of significant deficiencies to governance is required. Clear process descriptions, named control owners and cited frameworks and standards complete the evaluation.

ACC 491 Week 4 help: mistakes to avoid

A common ACC 491 Week 4 error is treating a walkthrough as a test of controls. A walkthrough confirms understanding; testing whether a control operated throughout the year requires a sample or, for automated controls, a test plus reliance on IT general controls. Another is ignoring IT general controls altogether; if access and change management are weak, automated controls cannot be relied on. Students also classify every deficiency as a material weakness. Evaluate likelihood and magnitude, and consider compensating controls. Describe the process in order, from initiation to recording. Name who performs each control and how often. Finally, state what the auditor will now do differently in substantive testing and whom the findings go to.

Related ACC 491 sample papers

Other ACC 491 week samples

More BS in Accounting sample papers

ACC 491 Week 4 questions, answered

What does ACC/491 Week 4 usually cover?

It usually covers internal control in an audit: the COSO framework, understanding controls through walkthroughs, tests of controls, IT general and application controls, control risk and deficiency classification.

Where can I find a free ACC 491 Week 4 sample paper?

Our outdoor gear retailer example walks through the online checkout process, tests IT controls and grades two deficiencies with margin notes, and it is free. We will draft your first paper on your own case at no charge.

What are the five components of the COSO framework?

The control environment, risk assessment, control activities, information and communication and monitoring activities.

What are IT general controls?

Controls over the IT environment as a whole, such as access to programs and data, program changes, program development and computer operations, that support the continued functioning of automated controls.

What is a significant deficiency?

A deficiency or combination of deficiencies in internal control that is less severe than a material weakness but important enough to merit the attention of those charged with governance.

Write yours, or have the desk draft it

This paper is an original model document written by our desk, not a submitted student paper and not an official University of Phoenix document. Read it for the moves, then write your own to the instructions in your classroom. If you want one built to your exact prompt and rubric, the first custom sample is free and arrives in 24 to 48 hours.