Audit of Taxpayers Maintaining Computer-Based Accounting Records
Revenue Memorandum Circular No. 38-86 • Bureau of Internal Revenue (BIR) Issuances • Revenue Memorandum Circulars • Oct 30, 1986
Full text
October 30, 1986 REVENUE MEMORANDUM CIRCULAR NO. 38-86 SUBJECT : Audit of Taxpayers Maintaining Computer-Based Accounting Records TO : All Internal Revenue Officers and Others Concerned 1. BACKGROUND In the past, up to the present, emphasis has always been on the audit approach applicable to manual accounting system. The increased use of computerized accounting system by taxpayers renders imperative the need for familiarity by Revenue Enforcement Officers of Electronic Data Processing (EDP) System. The following discussion is an overview of the basic changes in audit approach as a result of the transition from manual to computer-based accounting system. cd 2. THE IMPACT OF ELECTRONIC DATA PROCESSING SYSTEMS (EDPS) ON AUDITING There is no distinction between the audit concepts applicable to EDP and those applicable to manual systems. When computers are introduced, generally accepted auditing standards and their interpretations, legal liability and the basic concepts or gathering evidence remain unchanged. However, the specific methods appropriate for implementing the basic audit concepts do change with the introduction of EDP systems. An understanding therefore, of the impact of EDP on auditing becomes increasingly important as the use of computers by profit-oriented companies increases. 3. CHANGE IN ORGANIZATIONAL SET-UP The most important effect of EDP on audit results from changes in the company's organization and the information available for auditors to examine. The establishment of an EDP unit brings the data-gathering activities of different segments of the organization into one department. Such change has the advantage of centralizing data. On the other hand, centralization eliminates the control provided by division of duties of independent persons performing related functions. For instance, in many manual systems, different individuals prepare the sales journal and subsidiary records. The accuracy of the results is tested by comparing the subsidiary ledger with the total balance in the general ledger. However, with the establishment of an EDP unit, both these records will be prepared simultaneously by EDP unit. Auditors must, therefore, use great care in evaluating inadequate segregation of duties for the possibility of both fraudulent and unintentional errors. 4. CHANGES IN THE TRADITIONAL AUDIT TRAIL The audit trail pertains to the accumulation of source documents and records maintained by the company which are the support for the transactions that occurred during the period. It includes such things as duplicate sales invoices, supplier's sales invoices, cancelled checks, general and subsidiary ledgers and all types of journal. Since the audit trail is a primary source of evidence, it is necessary that an adequate trail be available for verification purposes. The effect of EDP on the audit trail depends on the level of sophistication of the system. When the computer is used only as a high-speed calculator, the audit trail may not be affected, especially if management desires to maintain the traditional source documents and records. In highly integrated on line-systems, the traditional audit trail can be nearly eliminated unless specific provision is made for some detailed records. A common change that occurs in the audit trail is the elimination or reduction of some source documents. Even if they are not eliminated, they are frequently filed in a manner that makes them difficult to retrieve for audit purposes. A second change in the system is the transfer of data and activities into a form that is not visually observable by the auditors. For instance, the ledger summaries are included in master files in machine-language, the journals and records are not printed out but are retained on magnetic tapes or disks and the methods of processing records are not observable because they are done by the computer. 5. CHANGES IN THE METHOD OF PROCESSING TRANSACTIONS The most important effect of EDP on the processing of transactions is that it provides uniformity. Once information is fed into the system, the auditor can be confident it will be processed consistently with previous or subsequent information unless some changes are introduced in some aspect of the system. From an audit point of view, this means the system will process a particular type of transaction consistently correctly or consistently incorrectly. As a result, the emphasis in auditing EDP systems for processing is likely to be on testing for unusual transactions and on testing for changes in the system over time rather than on testing a large sample of similar transactions. 6. CHANGES IN THE APPROACH TO AUDITING Due to the loss of audit trails, auditors have to devise new methods for testing complex EDP system. For a while after the disappearance of audit trails, auditors insisted upon extensive special printouts, but the high cost to companies forced auditors to think about alternative approaches. It is necessary to distinguish between different levels of complexity in determining the impact of EDP systems in auditing methods. In some instances, the systems are so complex that the entire audit approach must be changed, whereas in others there is no significant change in audit approach. Consider the audit implications of the following type of systems: aisa dc 6.1. Simple Systems . Transactions are easily traced in a small computer system where the primary function performed is the sorting and manipulation of input data and the printing of output reports. There is no loss of audit trail. Audit of this type of system requires little training and background in EDP. Example of this type of system, shipping data are key-punched and processed throughout the system along with accounts receivable ledgers. The output is a multicopy sales invoice for each sale, updated subsidiary ledger and a sales journal. This type of system represents the bulk of systems in use today in the Philippines. 6.2. Complex Systems . This is characterized by the batch processing mode, the existence of one CPU (Central Processing Unit) and the extensive use of master files on magnetic tape in processing. In this type of system, processing is usually confined to calculations, extensions, summarizations and the like. There is some loss of audit trail but not significantly. The audit of such system can be done by auditors with limited specialized training in EDP auditing. Because of the extent of a printed audit trail, the auditors has the option of performing audit tests with or without the use of the computer based on his experience. An active involvement in evaluating the EDP system is necessary even though an audit trail exists since there are many opportunities for incompatible functions or other inadequate controls. 6.3. Sophisticated Systems . In this type of system, transactions are initiated within the computer, there is extensive data processing and consequently, a substantial loss of audit trail. Most of the output is in machine-readable form. Typical example is the input of shipping documents on remote or on-line teletype. He avy reliance must be placed on internal control in the audit of said system. Since many of these tests require EDP skills beyond the knowledge of most auditors, EDP specialists are usually called upon by the auditors. Careful advance planning is necessary because records needed in audit and the approach to be used in testing must be made before data are processed. cd i 7. AREAS OF CONCERN When a computer is used in the processing of financial data, two areas of concern must be carefully considered as part of the planning process before the bulk of the audit field work is begun, namely: evaluating internal accounting control and determining the desirability of using computer-assisted techniques. 7.1. Evaluating Internal Control in an EDP System The objective is the same as for a manual system, that is to determine on the basis of the adequacy of existing controls, the audit evidence that should be accumulated. Similarly, the technique of internal control evaluation for both EDP and non-EDP systems is to obtain information about the client's system, to evaluate its strengths and weaknesses and to ascertain that the system is actually operating in accordance with the plan. Evaluation of an EDP system is usually done by obtaining preliminary information from three major sources: Flowcharts, EDP questionnaires, and a study of the error listings generated by the system. The flowcharts and questionnaires have counterparts in non-EDP systems, but an error listing is unique to EDP systems. The flowcharts emphasize the organization of the company and the flow of information through the system, the questionnaires emphasize specific controls and the error listing supports both these approaches by showing the actual error reported by the EDP system. After obtaining a preliminary understanding of the EDP system, the auditor is in a position to decide on the extent to which he decides to rely on its controls. As in manual systems, the auditor may decide not to rely upon the EDP controls even if they are adequate. This approach is followed if the cost of an extensive or exhaustive study and test of the controls will exceed the reduction in the cost of the other procedures. 7.2. Auditing Around the Computer Then the auditor relies completely on the non-EDP aspect of a system, it is referred to as auditing around the computer. In this approach, the auditor reviews internal control and performs tests of transactions and account balances verification procedures in the same manner as in non-EDP systems, there is no attempt to test the client's EDP controls or to use the computer to perform audit procedures. cd To audit around the computer, the auditor must have access to source documents and a detailed output report in a readable form. This is possible only if all the foregoing conditions are satisfied: a. source documents are available in a non-machine language; b. documents are filed in such a way that it is convenient to locate them for auditing purposes; c. output is listed in detail to be able to trace individual transactions from the source documents to the output and vice-versa. If any of the above condition does not exist, the auditor will have to rely on computer-oriented controls and possibly the use of computer for carrying out his audit procedures. 7.3. Auditing with the Use of the Computer There are two ways wherein the auditor uses the computer to perform audit procedures: a. processing the auditor's test data on the client's computer system as a part of the review of internal control; b. testing the records maintained by the computer as a means of verifying the client's financial statements. casia 7.3.1. Test Data Approach The objective of the use of the test data approach is to determine whether the computer programs can correctly handle valid and invalid transactions as they arise. To achieve this objective, the auditor develops different types of transactions that are processed under this control using the client's computer programs on the client's EDP equipment. The test data used must include both valid and invalid transactions in order to check whether the client's system has properly processed the input. The auditor examines the error listing and the details of the output resulting from the test data. 7.3.2. Auditor's Computer Program Approach This approach is for the auditor to run his own program on a controlled basis to verify the client's data recorded in a machine language. When the auditor uses test data he is evaluating the ability of the client's system to handle different types of transactions, whereas in the auditor's computer program approach, the output of the program is being tested for correctness. Different kinds of tests and other functions can be performed with a computer program if the client's data are in a machine language, these include: a. Verifying Extensions and Footings . A computer program can be used to verify the accuracy of the client's computations by calculating the information independently. cd b. Selecting Audit Samples . The computer can be programmed to select samples from any machine-readable data in several ways including at random. It is also possible to use more than one criterion for sample selection. c. Comparing Data on Separate Files . When records on separate files should contain compatible information, a program can be used to determine if the information agrees. For example, change in accounts receivable balances between two dates can be compared with details of sales and cash receipts on transactions files and payroll details can be compared with personnel records. d. Using the Client's Program . This is acceptable and economical alternative when the client already has a program that the auditor can use, such as for footing or crossfooting. When using client's program, it is important to test the program for reliability before use. e. Using a Generalized Program . A generalized program consists of a series of computer programs which together perform various data processing functions. These functions for the most part can be described as data manipulations. Generalized programs have two important advantages, first, they are developed in such a manner that most of the audit staff can be quickly trained to use the program even though they have little formal EDP education. Second, they have a wide range of application, which can be made with a single program without having to incur the cost of developing an individualized program. But the high initial cost of their development and their relatively inefficient processing speed could be a setback. All internal revenue officials and others concerned are hereby enjoined to give this Revenue Memorandum Circular the widest publicity possible . acd BIENVENIDO A. TAN, JR. Commissioner of Internal Revenue
Ask what this means for your situation
The assistant quotes the passage it relies on and links the source, so you can check every figure it gives you.