| Course | ACC 542 Accounting Information Systems (ACC/542) |
|---|---|
| Week | 5 |
| Paper type | Information system audit paper |
| Length | about 1,166 words, 4 double-spaced pages plus title page and references |
| Format | APA 7 student paper |
| School | University of Phoenix |
| Program | MS in Accounting |
| Updated | September 2026 |
Free sample paper for ACC 542 Week 5
Testing the Controls Behind the Numbers: IT General Controls, a Cloud Provider's SOC 1 Report and Application Controls in the Audit of a Composite Meal Kit Subscription Company
[Student Name]
University of Phoenix
ACC/542: Accounting Information Systems
Week 5 Assignment
[Instructor Name]
[Date]
The company, its systems and all figures are composites written for a model paper; standards and research findings come from the sources listed.
A composite company delivers meal kits weekly to about 210,000 subscribers. Customers choose meals online, and the platform charges their cards each week, applies promotional credits and records revenue when boxes ship. Annual revenue is $310 million. The company's e-commerce platform and data warehouse are hosted by a major cloud provider, and its accounting system receives daily summaries from the platform. In a business where no person issues an invoice, the auditor's evidence about revenue starts with evidence about the systems that issue them. This paper describes how the audit team evaluated those systems.
Scoping the Relevant Systems
The team identified the systems that affect significant accounts and assertions. The e-commerce platform determines prices, applies discounts and triggers charges; the payment processor settles card transactions; the warehouse management system records shipments; the interface posts daily revenue and deferred revenue to the general ledger. The cloud provider hosts the platform's servers and databases. Systems that do not affect financial data, such as the recipe content system, were excluded. The team documented the scoping decision with a diagram of data flows from customer checkout to the general ledger, so each system's role in producing revenue was visible and the exclusions could be reviewed by the engagement partner.
IT General Controls
IT general controls support the continued operation of application controls. The team tested three areas over the full year.
For access, it obtained a list of all users with the ability to change prices or promotional rules on the platform and compared it with job roles, then tested quarterly access reviews and the removal of access for a sample of 25 employees who left during the year. Two former employees retained access for more than 30 days, though logs showed no activity after their departure.
For program change, it selected 25 changes to the platform's billing and pricing code from the change log and inspected each for a ticket, testing evidence, approval by a manager other than the developer and deployment by an operations engineer rather than the developer. It also compared the production code log with the ticket system to confirm that no changes bypassed the process. All 25 followed the process.
For operations, it tested monitoring of the daily interface to the general ledger, confirming that failed jobs generated alerts and were resolved and rerun.
The Cloud Provider's SOC 1 Report
The cloud provider's infrastructure, physical security and database operations are outside the company's direct control. The team obtained the provider's SOC 1 Type 2 report, prepared under the attestation standard for reporting on controls at a service organization (American Institute of Certified Public Accountants, 2016). It confirmed that the report covered nine months of the company's fiscal year and obtained a bridge letter from the provider for the remaining three months. It read the opinion, which was unmodified, and the tests and results, which noted one exception in the provider's logging of administrative access, remediated during the period and not relevant to the company's services.
The report lists complementary user entity controls, which the provider assumes customers perform. Two applied: customers must manage their own user access to their cloud accounts and must review provider notifications of changes. The team tested both at the company, finding that cloud account access was reviewed quarterly by the head of engineering.
Application Controls
With IT general controls largely effective, the team tested key automated controls. It tested pricing by selecting test orders across meal plans and promotions in the production environment and comparing charges with the approved price and promotion tables. It tested the revenue deferral logic, which records revenue on shipment rather than on charge, by tracing a sample of orders charged in the last week of the year and shipped in the first week of the next into deferred revenue. It tested the completeness of the daily interface by reconciling platform totals with the general ledger for 20 days. All tests agreed. Because the controls are automated and change management was effective, a test of one instance of each control, combined with the general controls, was sufficient.
The Access Exception
The two former employees who retained access represented a deficiency in the access control. The team considered whether it undermined reliance on the pricing control. Because logs showed no activity by those accounts and the pricing tables were compared with approved rates at year end, the team concluded that the deficiency did not affect the reliability of pricing during the year, reported it to management and performed an additional review of all pricing table changes made during the year.
Effect on Substantive Testing
Because the team could rely on automated controls, it performed analytical procedures on weekly revenue by plan, comparing subscribers, average order value and discounts with expectations built from platform data, rather than vouching thousands of individual transactions. It still tested cash settlements from the payment processor and cutoff at year end, since neither depends on the platform's controls.
Data Reliability for Analytics
The analytical procedures depended on subscriber counts and order values drawn from the platform's data warehouse. Before using those data, the team tested their completeness and accuracy by reconciling warehouse totals with the general ledger for each month and by agreeing a sample of warehouse records back to individual orders in the platform. Auditors must evaluate the reliability of information produced by the entity before using it as evidence, and the IT general controls tested earlier supported that evaluation.
If the Company Were Public
The company is privately held, so the audit is of its financial statements only. If it became public and large enough, its auditors would also have to report on internal control over financial reporting in an integrated audit, testing controls to support an opinion on their effectiveness rather than only to reduce substantive work (Public Company Accounting Oversight Board, 2007). The access exception would then be evaluated for whether it amounted to a deficiency requiring communication, and the testing of IT general controls would expand to cover all systems supporting financial reporting.
Research on Technology in the Audit
Janvrin et al. (2008) surveyed auditors and found that audit applications of information technology, such as analytical tools and electronic workpapers, were widely used, while more specialized techniques were used less often than their importance suggested. This audit applied several such techniques, including log comparisons and full-population reconciliations of the interface, because the company's revenue exists only in electronic form.
Conclusion
The team scoped the systems that produce revenue, tested access, change management and operations over the year, relied on the cloud provider's SOC 1 report after confirming its coverage and the company's complementary controls and tested automated pricing, deferral and interface controls. One access exception was evaluated and did not undermine reliance. The results allowed the team to use analytical procedures for revenue while still testing cash and cutoff directly.
References
American Institute of Certified Public Accountants. (2016). Attestation standards: Clarification and recodification (Statement on Standards for Attestation Engagements No. 18).
Janvrin, D., Bierstaker, J., & Lowe, D. J. (2008). An examination of audit information technology use and perceived importance. Accounting Horizons, 22(1), 1-21. https://doi.org/10.2308/acch.2008.22.1.1
Public Company Accounting Oversight Board. (2007). An audit of internal control over financial reporting that is integrated with an audit of financial statements (Auditing Standard No. 5).
What the ACC 542 Week 5 instructions ask
The ACC 542 Week 5 task generally asks graduate students to explain how auditors evaluate information systems. Typical requirements include identifying systems relevant to financial reporting, testing IT general controls over access, change management and computer operations, using service organization control reports and complementary user entity controls, testing application controls such as input, processing and output controls and deciding how control results affect substantive testing. Some prompts include computer-assisted audit techniques, the reliability of data used in analytics or the audit of cybersecurity risks. Apply each step to one organization, give the reasoning behind every test and reference the attestation and auditing standards and supporting research in APA form.
How this ACC 542 Week 5 example is built
A subscription business that bills customers automatically each week is a clear case in which the numbers are only as reliable as the systems that produce them. The paper begins by scoping: which systems and data flows matter to revenue and receivables. IT general controls are tested next, because application controls cannot be relied on without them. The cloud provider's SOC 1 report is read carefully for its period, scope, exceptions and the user controls it assumes. Application controls over pricing, billing and revenue deferral are then tested. The final sections show how the results changed the substantive plan, how the data used for analytics were validated and what research says about how auditors use technology.
ACC 542 Week 5 grading rubric: where the points go
Instructors grading this week look for correct scoping, appropriate tests of IT general and application controls, correct use of service organization reports and a clear link between control results and the audit plan. Faculty check that access, change management and operations controls are tested over the period, that SOC 1 reports are evaluated for type, period, scope, exceptions and complementary user entity controls and that application controls are tested in a way consistent with their automated nature. The effect on substantive procedures should be stated. Accurate use of auditing and attestation standards and research, plus a clear account of any exception, complete the grade.
ACC 542 Week 5 help: mistakes to avoid
Many ACC 542 Week 5 drafts test automated application controls before showing that IT general controls are effective. If program changes are not controlled, a control tested once may not have worked all year. Another is accepting a SOC 1 report without reading it; check whether it is Type 2, whether its period covers the year, whether exceptions were noted and which user controls the company must perform. Students also describe computer-assisted techniques without saying what they test, which leaves the grader guessing about the assertion. Link every test to a risk and an assertion, and keep the tests in the order an auditor would perform them. Finally, spell out which substantive procedures shrink, which stay and why.
Related ACC 542 sample papers
Other ACC 542 week samples
- ACC 542 Week 1: Business Information Systems
- ACC 542 Week 2: Business Processes and Data Flows
- ACC 542 Week 3: Database Concepts and Tools
- ACC 542 Week 4: Information System Risks and Controls
- ACC 542 Week 6: Using the System for Audit Functions
More MS in Accounting sample papers
ACC 542 Week 5 questions, answered
What does ACC/542 Week 5 usually cover?
It usually covers auditing information systems: scoping relevant systems, testing IT general and application controls, using SOC reports and deciding how control results affect substantive testing.
Where can I find a free ACC 542 Week 5 sample paper?
A meal kit subscription company's IT audit, with general controls, a SOC 1 review and application controls, appears on this page with margin notes free of charge. Send your case and we will prepare the first graduate draft at no cost.
What is a SOC 1 Type 2 report?
A service auditor's report on a service organization's controls relevant to user entities' financial reporting, covering both design and operating effectiveness over a period.
What are complementary user entity controls?
Controls that a service organization assumes its customers will perform, such as reviewing user access, which must be in place for the service organization's controls to achieve their objectives.
Why must IT general controls be tested before application controls?
Because application controls depend on IT general controls; without controlled access and program changes, an automated control tested once cannot be assumed to have worked all year.
Write yours, or have the desk draft it
This paper is an original model document written by our desk, not a submitted student paper and not an official University of Phoenix document. Read it for the moves, then write your own to the instructions in your classroom. If you want one built to your exact prompt and rubric, the first custom sample is free and arrives in 24 to 48 hours.
Request this one custom, free · All ACC 542 week samples · All courses