ACC 542 Week 4 Internal Control and Risks in Information Systems Example

Reviewed by Davina Cresswell, MBA · University of Phoenix · Updated

This ACC 542 Week 4 example assesses the risks in a company's information systems and designs controls using two frameworks accountants rely on. Internal control and information system risk anchor week four of University of Phoenix ACC 542, and the ACC/542 graduate student in the MS in Accounting connects the COSO components with the IT governance practices in COBIT. The paper follows a composite title and escrow company that holds client funds for real estate closings and recently lost a $186,000 wire to a spoofed email. It identifies risks to confidentiality, integrity and availability of its systems, maps them to COSO components and COBIT objectives, evaluates existing controls, designs preventive, detective and corrective controls for wire fraud, ransomware and access, classifies the deficiency behind the lost wire and draws on research about IT control weaknesses.

CourseACC 542 Accounting Information Systems (ACC/542)
Week4
Paper typeInformation system risk and control paper
Lengthabout 1,182 words, 4 double-spaced pages plus title page and references
FormatAPA 7 student paper
SchoolUniversity of Phoenix
ProgramMS in Accounting
UpdatedSeptember 2026

Free sample paper for ACC 542 Week 4

1

A Spoofed Email, a Changed Wire and a Locked Server: Assessing Information System Risks and Controls at a Composite Title and Escrow Company Using COSO and COBIT

[Student Name]

University of Phoenix

ACC/542: Accounting Information Systems

Week 4 Assignment

[Instructor Name]

[Date]

The company, its incidents and all figures are composites written for a model paper; frameworks and research findings come from the sources listed.

What this part is doingThe title names three incidents that frame the risk assessment, so the analysis starts from real threats.
2

A composite title and escrow company handles about 4,200 residential and commercial closings a year across two states. On a typical day, its escrow accounts hold $30 to $60 million of buyers' deposits, lenders' funds and sellers' proceeds, and it sends dozens of wires. Last spring, an escrow officer got a message, seemingly from a seller, with new wire instructions for $186,000 of proceeds. The officer changed the instructions and sent the wire. The seller's email had been spoofed, and most of the money was never recovered. The loss did not come from a failure of technology alone; it came from a process that let an email change where money went. This paper assesses the company's information system risks and designs controls.

The Company's Systems and Data

The company uses a title production system to manage closings, an escrow accounting system that tracks every dollar held for each file, a banking portal for wires, email for communication with parties and a document system storing nonpublic personal information such as Social Security and bank account numbers. Staff work at eight offices and from home.

Risks by Security Objective

Risks can be organized by the objectives they threaten. Confidentiality is threatened by theft of client data through phishing or lost devices. Integrity is threatened by unauthorized changes to wire instructions or escrow records, as in the spring incident. Availability is threatened by ransomware that could lock the title production system and stop closings. Processing integrity is threatened by errors in disbursement calculations or reconciliation.

Mapping to COSO and COBIT

The COSO framework's five components, control environment, risk assessment, control activities, information and communication and monitoring, provide the overall structure (Committee of Sponsoring Organizations of the Treadway Commission, 2013). Its principle on technology general controls calls for control activities over technology infrastructure, security and acquisition and maintenance. COBIT 2019 provides more specific governance and management objectives for information and technology, such as managing security services, managing changes and managing continuity (ISACA, 2018). Wire instruction changes fall under COSO control activities and COBIT's objectives for managing business process controls and security services; ransomware falls under continuity and security.

What this part is doingMapping each risk to both frameworks shows how they work together rather than as competing checklists.
3

Existing Controls

The company already requires dual approval for wires over $500,000, uses email filtering, reconciles each escrow account daily to the bank and backs up the title system nightly. Those controls address large wires, some phishing and reconciliation errors. But the spring wire was below the dual approval threshold, the spoofed email passed the filter because it came from a lookalike domain and the backups were stored on the same network as production systems.

Preventive Controls

The company will require that any change in payment instructions be verified by calling the party at a phone number already on file from the opening of the file, never one in the email. It will require dual approval for all outgoing wires, with the second approver reviewing the callback record. It will enable multifactor authentication on email and the banking portal, block lookalike domains and mark external emails. It will limit who can edit wire instructions in the escrow system and review that access quarterly.

Detective Controls

Daily escrow reconciliations will be supplemented by a report of every change to payee or bank information, reviewed each afternoon by the escrow manager. Email and system logs will be monitored by an outside security provider, with alerts for logins from unusual locations. Customers will receive a notice at file opening that the company never changes wire instructions by email, so they can report suspicious messages.

Corrective Controls

Backups will be copied daily to storage disconnected from the network and tested quarterly by restoring the title system in a test environment. The company will adopt an incident response plan naming who contacts the bank to attempt a wire recall, who notifies law enforcement and clients and how closings continue manually if systems are down. Its cyber insurance will be reviewed to confirm coverage for social engineering losses.

What this part is doingGrouping recommendations by type ensures the design does not depend on prevention alone, which the spring incident showed can fail.
4

People and Training

Most attacks on title companies begin with a person, not a server. The company will require quarterly training for all staff on recognizing phishing and payment fraud, with simulated phishing emails and follow-up coaching for anyone who clicks. Escrow officers will receive additional training on the callback procedure and on the pressure tactics fraudsters use, such as urgent requests on the day of closing. New hires will complete training before they receive access to the escrow system. The owners will sign an annual statement reaffirming that no one, including them, may bypass the callback procedure, which strengthens the control environment component of COSO.

Vendors and Remote Work

The title production system and the banking portal are hosted by vendors. The company will obtain each vendor's service organization controls report annually, review it for exceptions and confirm that it performs the complementary controls the reports assign to customers, such as reviewing user access. Staff working from home will use company laptops with disk encryption and a virtual private network, and personal devices will not be allowed to access client data.

Cost and Practicality

The callback procedure costs staff time, about five minutes per wire, and may delay some closings. Multifactor authentication and monitoring cost about $60,000 a year. Offline backups and testing cost about $25,000 a year. Against a single loss of $186,000 and the reputational harm of losing client funds, the costs are justified.

Evaluating the Deficiency

The lost wire revealed a deficiency: no control required independent verification of changed payment instructions. Given the frequency of wires and the size of possible losses, the likelihood and magnitude of a material loss of client funds are both significant. For the company's auditors, who audit its financial statements and escrow accounts, the deficiency would be at least a significant deficiency. Li et al. (2012) found that companies reporting IT control weaknesses also showed lower quality in management's own forecasts, evidence that such weaknesses affect the information managers rely on, not only the financial statements.

Regulatory and Contractual Duties

Beyond its own losses, the company has duties to others. State insurance regulators oversee title agents, lenders impose security requirements in their closing instructions and federal privacy rules require safeguards for customers' nonpublic personal information, including a written information security program. The new controls also help the company meet those obligations and document that it has done so.

Monitoring

The controller will report quarterly to the owners on wire exceptions, access reviews, backup tests and training completion, and an outside firm will perform an annual assessment against COBIT objectives.

Conclusion

The title and escrow company's systems face risks to confidentiality, integrity and availability, with wire fraud and ransomware the most severe. Existing controls covered large wires and reconciliations but not changed instructions or offline recovery. Preventive callbacks and dual approval, detective change reports and monitoring and corrective offline backups and an incident plan, mapped to COSO and COBIT, address the risks at a cost well below the loss already suffered.

5

References

Committee of Sponsoring Organizations of the Treadway Commission. (2013). Internal control, integrated framework.

ISACA. (2018). COBIT 2019 framework: Introduction and methodology.

Li, C., Peters, G. F., Richardson, V. J., & Watson, M. W. (2012). The consequences of information technology control weaknesses on management information systems: The case of Sarbanes-Oxley internal control reports. MIS Quarterly, 36(1), 179-203. https://doi.org/10.2307/41410413

What the ACC 542 Week 4 instructions ask

ACC 542 Week 4 typically asks graduate students to identify risks in information systems and evaluate or design controls. Typical requirements include COSO's five components and seventeen principles, IT governance frameworks such as COBIT, the distinction between general and application controls, preventive, detective and corrective controls, security, confidentiality, processing integrity and availability, and specific threats such as fraud, cyberattacks and system failures. Many prompts present an organization, sometimes with a recent incident or known weakness, and ask for a risk assessment, recommended controls and an evaluation of their cost and effectiveness. Students should support recommendations with frameworks and research cited in APA style.

How this ACC 542 Week 4 example is built

A title and escrow company holds millions of dollars of other people's money on any given day and moves it by wire, which makes it an attractive target and a vivid setting for information system risk. The paper opens with the incident, then steps back to inventory the company's systems and data. Risks are organized by the security objectives they threaten and mapped to COSO and COBIT so each has a framework home. Existing controls are described before new ones are proposed. Recommendations are grouped as preventive, detective and corrective, then costed and tested against the actual incident. The lost wire is then evaluated as a control deficiency, and research on the consequences of IT control weaknesses closes the paper.

ACC 542 Week 4 grading rubric: where the points go

The graduate rubric for this topic usually rewards a thorough, well-organized risk assessment, correct use of COSO and COBIT, a balanced mix of preventive, detective and corrective controls and a reasoned evaluation of deficiencies. Faculty check that risks are specific to the organization's systems and data, that controls address identified risks rather than generic lists, that general and application controls are distinguished and that cost and practicality are considered. Using an actual incident to test the control design adds depth, and so does a plan for monitoring whether new controls keep working. Support from frameworks and peer-reviewed research, graduate writing and APA citations complete the evaluation.

ACC 542 Week 4 help: mistakes to avoid

A frequent ACC 542 Week 4 weakness is a generic list of cybersecurity tips with no link to the organization's processes. Start from what the company does, which data and funds it holds and how they move. Another is relying only on preventive controls; detective and corrective controls matter when prevention fails. Students also treat COSO and COBIT as alternatives; COSO frames internal control broadly, and COBIT provides detailed IT governance and management objectives. Tie each control to a risk and a framework element. Consider people and process controls, such as callbacks, not just technology. Finally, evaluate any incident as a deficiency, not only as a loss, and say who should be told.

Related ACC 542 sample papers

Other ACC 542 week samples

More MS in Accounting sample papers

ACC 542 Week 4 questions, answered

What does ACC/542 Week 4 usually cover?

It usually covers internal control and risks in information systems, including COSO, COBIT, general and application controls, security and specific threats such as fraud and cyberattacks.

Where can I find a free ACC 542 Week 4 sample paper?

The title and escrow company risk assessment on this page, with controls mapped to COSO and COBIT, is open on this page with comments in the margin. Send your organization's facts and the opening graduate draft costs you nothing.

How does COBIT relate to COSO?

COSO provides a general framework for internal control, while COBIT provides governance and management objectives specific to information and technology that help implement IT-related controls.

What are preventive, detective and corrective controls?

Preventive controls stop problems before they occur, detective controls discover problems that occur and corrective controls fix problems and restore operations.

How can companies prevent wire fraud from email compromise?

By verifying any change in payment instructions with a callback to a known phone number, requiring dual approval for wires, training staff and using multifactor authentication on email.

Write yours, or have the desk draft it

This paper is an original model document written by our desk, not a submitted student paper and not an official University of Phoenix document. Read it for the moves, then write your own to the instructions in your classroom. If you want one built to your exact prompt and rubric, the first custom sample is free and arrives in 24 to 48 hours.