Вы находитесь на странице: 1из 8

information system has many components, as

explained further in the next section.


MODULE 1: OVERVIEW TO ACCOUNTING
INFORMATION SYSTEM (AIS)
ACCOUNTING INFORMATION SYSTEM

BUSINESS PROCESSES
An accounting information system must capture, The accounting information system comprises the
record, and process all financial transactions. No processes, procedures, and systems that capture
matter the form of those business transactions, the accounting data from business processes; record the
accounting information system must identify the accounting data in the appropriate records; process
transactions to record, capture all the important the detailed accounting data by classifying,
details of the transaction, properly process the summarizing, and consolidating; and report the
transaction details into the correct accounts, and summarized accounting data to internal and external
provide reports externally and internally. Many types users.
of transactions that result from business processes
must be captured, recorded, and reported.
IT ENABLEMENT OF BUSINESS PROCESSES

Business Process is a prescribed sequence of work


steps performed in order to produce a desired result Information technology is defined as the
for the organization. A business process is initiated computers, ancillary equipment, software,
by a particular kind of event and has a well-defined services, and related resources as applied to
beginning and end. support business processes.

FOUR GENERAL TYPES OF BUSINESS PROCESSES IT usage to support business processes


1. Revenue processes accomplishes one or more of the following
objectives:
a. Sales processes
1. Increased efficiency of business
b. Sales return processes
processes
c. Cash collection processes
2. Expenditure processes 2. Reduced cost of business processes
3. Increased accuracy of the data related
a. Purchasing processes
to business processes
b. Purchase return processes
c. Cash disbursement processes
d. Payroll processes Business process reengineering (BPR) is
e. Fixed asset processes the purposeful and organized changing of
3. Conversion processes business processes to make them more
a. Planning processes efficient. BPR not only aligns business
b. Resource management processes processes with the IT systems used to record
c. Logistics processes processes, it also improves efficiency and
4. Administrative processes effectiveness of these processes.
a. Capital processes
b. Investment processes BASIC COMPUTER AND IT CONCEPTS
c. General ledger processes Nearly all accounting information systems rely on
computer hardware and software to track business
processes and to record accounting data. Therefore,
Internal controls are the set of procedures and it is important to have some understanding of basic
policies adopted within an organization to safeguard computer terminology and concepts.
its assets, check the accuracy and reliability of its
data, promote operational efficiency, and encourage
adherence to prescribed managerial practices. Basic Computer Data Structures
Accounting data is stored in computer files,
and an accountant should have some
For example, McDonald’s probably requires that at understanding of data structures in IT
the end of every day, a manager close each cash systems. Data is organized in a data hierarchy
register and reconcile the cash in the register to the in computer systems, as follows:
recorded total sold at that register. This is an internal
1. Bit, or binary digit
control process to prevent and detect errors in cash
2. Byte
amounts and to discourage employees from stealing
3. Field
cash. Reconciliation of cash to cash register records is
4. Record
a business process designed to control other
5. File
processes. Thus, we begin to see that the accounting
6. Database
record of each employee’s relatively
permanent information necessary to process
A bit is a shortened reference to binary digit. payroll transactions such as name, address,
The bit is the smallest unit of information in a pay rate, and year-to-date amounts. Thus, the
computer system. A bit can have only one of master file is much like a subsidiary ledger.
two values: zero or one. All data in a The transaction file is the set of relatively
computer system is reduced to a set of bits, or temporary records that will be processed to
zeros and ones. A byte is a unit of storage that update the master file. A payroll transaction
represents one character. In most computer file would contain the set of hours worked by
systems, a byte is made up of eight bits. For each employee for a particular pay period.
example, the character “A” would be The transaction file is processed against the
represented in a computer system by a set of master file, and employee year-to-date
eight bits. Every character, including letters, balances are updated in the master file.
numbers, and symbols, are represented by a
byte.
Not all modern IT systems and accounting
software use master files and transaction
A field is one item within a record. For files. Some systems use a database approach
example, last name is a field in a payroll to processing and storing accounting data,
record, and description is a field in an whereby the many details of financial
inventory record. A record is a set of related transactions are stored in huge databases.
fields for the same entity. All fields for a given These systems do not necessarily maintain
employee form a payroll record. Such fields computerized ledgers and journals. Because
would be employee number, last name, first all transaction data is stored in databases, the
name, Social Security number, pay rate, and transactions can be organized or summarized
year-to-date gross pay. The entire set of by the important dimension requested. For
related records forms a file. example, the sales transactions that meet
The set of all employee records forms a certain criteria can be extracted from the
payroll file. database when needed—it is not necessary to
construct or review a sales ledger.
Thus, the data structure hierarchy is as
File Access
follows: Eight bits are a byte, a collection of
related bytes is a field, a set of related fields is
a record, and a set of related records is a file. 1. Sequential access files store records in
The entire collection of files is called a sequence, with one record stored
database. A database is a collection of data immediately after another. The sequence is
stored on the computer in a form that allows usually based on a key field such as employee
the data to be easily accessed, retrieved, number or customer number. Sequential files
manipulated, and stored. The term database are read and written in sequence. This means
usually implies a shared database within the that for the user to access record number
organization. Rather than each computer 500, the previous 499 records must first be
application having its own files, a database read by the computer.
implies a single set of files that is shared by
each application that uses the data. A
relational database stores data in several 2. Random access files (sometimes called
small two dimensional tables that can be direct access files) are not written or read in
joined together in many varying ways to sequential order; rather, their records are
represent many different kinds of stored in random order on a disk media. Since
relationships among the data. An example of a records are distributed randomly on the disk
relationship in data is a single customer surface, an underlying system enables the
having more than one order. A relational computer to find a record among the random
database is intended to allow flexibility in records, using either a formula or a hashing
queries. This means that managers or users scheme to assign a specific address to each
can query the database for information or record. When a record is requested, the
reports as needed. formula can be recalculated to find the
address of the requested record. If records
are to be accessed randomly, then random
The computer files of traditional accounting access is a more efficient access method than
software systems use master files and sequential access.
transaction files. The master files are the
relatively permanent files that maintain the
detailed data for each major process. For 3. Indexed sequential access method (ISAM)
example, a payroll master file contains a where the same files may sometimes be
accessed either way, sequentially or
randomly. ISAM files are stored sequentially,
but can also be accessed randomly because an Structured, Unstructured, and Big Data
index allows random access to specific
records.
Structured data easily fits into rows and
columns. These columns usually are fields of
Two modes of processing transactions in fixed length. An example would be 10 digits
accounting systems for a phone number. Customer name, credit
card number, and total dollar amount of sales
are other examples of data that easily fits into
1. Batch processing requires that all similar rows and columns. Companies also collect
transactions be grouped together for a unstructured data.
specified time; then this group of transactions
is processed as a batch. Batch processing is
best suited to applications having large Unstructured data does not easily fit into
volumes of similar transactions that can be rows and columns of fixed length. An example
processed at regular intervals. Payroll of unstructured data would be the freeform
processing is a good example of a system well text of a customer’s online review of a
suited for batch processing. All time cards can product. It might include Facebook posts,
be grouped together for a two-week pay tweets, video, and other freeform types of
period, and all payroll processing takes place data.
on the entire set of time cards.
Big Data is known as high-volume, highspeed
2. Online processing is the opposite of batch information that may
processing. Transactions are not grouped into be so large and diverse that it demands
batches, but each transaction is entered and innovative forms of IT processing. It is
processed one at a time. Some online generally considered too large in size and
processing systems are also real-time scope to be analyzed with traditional
processing systems, meaning that the database tools.
transaction is processed immediately, and in
real time, so that the output is available Networks and the Internet
immediately. Online processing is best suited
to applications in which there is a large
volume of records, but only a few records are A computer network is two or more
needed to process any individual transaction. computers linked together to share
information and/or resources.
Data Warehouse and Data Mining
There are several types of computer
networks, but the types most important to
Data warehouse is an integrated collection the topic of accounting information systems
of enterprise-wide data that generally are local area network (LAN), the Internet,
includes several years of nonvolatile data, extranet, and intranet.
used to support management in decision
making and planning.
A LAN is a computer network that spans a
relatively small area. Most LANs are confined
An operational database contains the data to a single building or group of buildings and
that is continually updated as transactions are intended to connect computers within an
are processed. Usually, the operational organization. However, one LAN can be
database includes data for the current fiscal connected to other LANs over any distance
year and supports day-to-day operations and via other network connections. A system of
record keeping for the transaction processing LANs connected in this way is called a WAN,
systems. Each time a new transaction is or wide area network.
completed, parts of the operational database
must be updated.
The Internet is the global computer network,
or “information superhighway.” The Internet
Data mining is the process of searching data developed from a variety of university and
within the data warehouse for identifiable government-sponsored computer networks
patterns that can be used to predict future that have evolved and are now made up of
behavior. millions upon millions of computers and
subnetworks throughout the world. The
Internet is the network that serves as the
backbone for the World Wide Web (WWW). Electronic data interchange (EDI) is the
intercompany, computer-to-computer
transfer of business documents in a standard
An intranet is a company’s private network business format. Three parts of this definition
accessible only to the employees of that highlight the important characteristics of EDI:
company. The intranet uses the common (1) “Intercompany” refers to two or more
standards and protocols of the Internet. companies conducting business
However, the computer servers of the electronically. For example, a buyer of parts
intranet are accessible only from internal may use EDI to purchase parts from its
computers within the company. The purposes supplier. (2) The computer to-computer
of an intranet are to distribute data or aspect of the definition indicates that each
information to employees, to make shared company’s computers are connected via a
data or files available, and to manage projects network. (3) A standard business format is
within the company. necessary so that various companies,
vendors, and sellers can interact and trade
electronically by means of EDI software. EDI
An extranet is similar to an intranet except is used to transmit purchase orders, invoices,
that it offers access to selected outsiders, such and payments electronically between trading
as buyers, suppliers, distributors, and partners.
wholesalers in the supply chain. Extranets
allow business partners to exchange
information. These business partners may be A point of sale system (POS) is a system of
given limited access to company servers and hardware and software that captures retail
access only to the data necessary to conduct sales transactions by standard bar coding.
supply chain exchanges with the company. Nearly all large retail and grocery stores use
For example, suppliers may need access to POS systems that are integrated into the cash
data pertaining to raw material inventory register. As a customer checks out through
levels of their customers, but they would not the cash register, the bar codes are scanned
need access to customers’ finished product on the items purchased, prices are
inventory levels. Conversely, a wholesaler determined by access to inventory and price
within the supply chain may need access to list data, sales revenue is recorded, and
the manufacturer’s finished product inventory values are updated. All of these
inventory, but it would not need access to raw processes occur in real time, and through POS
material inventory levels. captured data the store can provide to its
managers or home office daily summaries of
sales by cash register or by product. Many
Examples of IT Enablement companies adopt POS systems because they
The examples that follow are systems applied by enhance customer satisfaction by enabling
companies today that use IT-enabled business faster and more accurate sales processing.
processes.

Enterprise resource planning (ERP) is a


E-business is the use of electronic means to multimodule software system designed to
enhance business processes. E-business manage all aspects of an enterprise. ERP
encompasses all forms of online electronic systems are usually broken down into
trading—consumer-based ecommerce and modules such as financials, sales, purchasing,
business-to-business transactions, as well as inventory management, manufacturing, and
the use of IT for process integration inside human resources. The modules are designed
organizations. E-business is therefore a very to work seamlessly with the rest of the
broad concept that includes not only system and to provide a consistent user
electronic trading with customers, but also interface between modules. These systems
servicing customers and vendors, swapping usually have extensive setup options that
information with customers and vendors, and allow some flexibility in the customizing of
electronic recording and control of internal functionality to specific business needs. ERP
processes. IT systems, Internet and websites, systems are based on a relational database
as well as wireless networks, are the common system.
means of enabling E-business to occur.
Ecommerce is the type of E-business that we
are familiar with as consumers. Buying a book THE INTERNAL CONTROL STRUCTURE OF
at Amazon.com and clothes at Patagonia.com ORGANIZATIONS
are examples of engaging in ecommerce.
All organizations face risks in both day-to-day and manage risk to be within its risk appetite,
operations and longterm management. Some risks to provide reasonable assurance regarding
may be beyond the control of management. For the achievement of entity objectives.
example, management would be unable to reduce the
risk of an earthquake, which could interrupt
operations or destroy buildings and equipment. This definition has several critical
However, managers can take steps to lessen the components. First, notice that ERM is put into
negative impact of an earthquake. For example, they place by top management and the board of
can ensure that buildings are designed to be resistant directors. This emphasizes that ERM is the
to earthquake damage. In fact, management has the responsibility of management. Second, ERM is
ability and responsibility to take action to reduce an ongoing process. Therefore, it is not
risks or to lessen the impact of nearly all risks that something that occurs once and is forgotten—
the organization faces. These processes are called it is the continuous assessment of risks,
controls. determination of acceptable levels of risk, and
management of risks to that acceptable level.
Finally, ERM must involve not only
Accountants have a long history of being the management, but also personnel across the
professionals within the organization who help enterprise.
design and implement controls to lessen risks that
have an impact on the financial standing of the
organization. Accountants are usually experts in ERM requires that management set policies
controls that can reduce risks in the following broad and procedures related to:
categories:
1. The risk that assets will be stolen or misused Internal Environment—The internal
2. The risk of errors in accounting data or environment encompasses the tone of
information an organization that sets the basis for
3. The risk of fraudulent activity by employees, how risk is viewed and addressed by
managers, customers, or vendors an entity’s people, including risk
4. The risks inherent in IT systems, such as management philosophy and risk
a. Erroneous input of data appetite, integrity and ethical values,
b. Erroneous processing of data and the operational environment.
c. Computer fraud
d. Computer security breaches
e. Hardware or software failure Objective Setting—Objectives must
exist before management can identify
f. Natural disasters that can interrupt
potential events affecting their
computer system operations
achievement. ERM ensures that
management has in place a process to
Although management has the ultimate responsibility set objectives that support and align
to establish a control environment to mitigate these with the entity’s mission and are
risks to the extent to which it can reasonably do so, consistent with its risk appetite.
accountants are heavily involved in assisting
management in the creation, implementation, and
Event Identification—Internal and
ongoing monitoring of the control environment.
external events affecting achievement
of an entity’s objectives must be
Management should ensure that the following types identified, with distinction made
of controls exist: between risks and opportunities.
Opportunities are channeled back to
management’s strategy or objective-
1. Enterprise risk management setting processes.
2. Code of ethics
3. COSO accounting internal control structure
4. IT system control structure Risk Assessment—Risks are analyzed
5. Corporate governance structure by likelihood and impact, as a basis
6. IT governance structure for determining how they should be
managed. Risks are assessed on both
an inherent and a residual basis,
1. Enterprise risk management (ERM) is meaning that the likelihood of errors
defined as a process, effected by an entity’s is considered both before and after
board of directors, management and other the application of controls.
personnel, applied in strategy setting and
across the enterprise, designed to identify
potential events that may affect the entity,
Risk Response—Management selects these five components of internal control in
risk responses— its enterprise risk management processes.
avoiding, accepting, reducing, or
sharing risk—by developing
a set of actions to align risks with the COSO - Committee of Sponsoring
entity’s risk tolerances and risk Organizations
appetite. It is a voluntary, private sector organization
that was originally formed in 1985 to sponsor
the National Commission on Fraudulent
Control Activities—Policies and Financial Reporting. It sponsors and
procedures are established and disseminates frameworks and guidance based
implemented to help ensure that the on in-depth research, analysis, and best
risk responses are effectively carried practices in the areas of enterprise risk
out. management, internal controls, and fraud
deterrence.

Information and Communication—


Relevant information is identified,
captured, and communicated in a
4. IT Controls
form and a time frame that enable
people to carry out their Threats and risks that interrupt or stop
responsibilities. Effective computer operations can be severely
communication also occurs in a damaging to the organization. Not only can
broader sense, flowing down, across, they halt or disrupt normal operations, they
and up the entity. can lead to incorrect or incomplete
accounting information. In addition,
Monitoring—The entirety of ERM is computer processing of accounting data leads
monitored and modified as necessary. to the risks of erroneous accounting data due
Monitoring is accomplished through to flawed or incomplete input or processing
ongoing management activities of data, computer fraud, and computer
(including internal auditing), separate security breaches. An organization must
evaluations (such as those performed institute controls to limit these risks in IT
by external auditors), or both. systems.

IT controls can be divided into two categories:


2. Code of Ethics general controls and application controls.
A company’s developing and adhering to a
code of ethics should reduce opportunities
for managers or employees to conduct fraud. General controls apply overall to the
This will only be true, however, if top IT accounting system; they are not
management emphasizes this code of ethics restricted to any particular
and disciplines or discharges those who accounting application. An example of
violate it. Managers who emphasize and a general control is the use of
model ethical behavior are more likely to passwords to allow only authorized
encourage ethical behavior in their users to log into an IT-based
employees. accounting system. Without regard to
processing data in any specific
application, passwords should be
employed in the IT system.
3. COSO Accounting Internal Control
Structure
In addition to its ERM guidance, COSO is well Application controls are used
known for its “Internal Controls— Integrated specifically in accounting applications
Framework,” which explains what has to control inputs, processing, and
become the standard accepted by the output. Application controls are
accounting and business community as the intended to ensure that inputs are
definition and description of internal control. accurate and complete, processing is
According to this framework, there are five accurate and complete, and outputs
interrelated components of internal control: are properly distributed, controlled,
the control environment, risk assessment, and disposed of.
control activities, information and
communication, and monitoring. Notice that
to achieve ERM, an organization must include
5. Corporate Governance
Design or Implementation Team
Accountants are usually part of a multiple-
Corporate governance is an elaborate system discipline team that designs and/or
of checks and balances whereby a company’s implements accounting information systems.
leadership is held accountable for building When an organization considers a change to
shareholder value and creating confidence in its AIS, accountants must be involved in
the financial reporting processes. This system decisions related to such matters as
of checks and balances includes several evaluating which software to purchase, how
interrelated corporate functions within the to design software or systems, and the
corporate governance system, including implementation of software or systems.
management oversight, internal controls and
compliance, financial stewardship, and ethical
conduct. Auditors of the AIS
Auditors conduct assurance services such as a
financial audit. To conduct an audit, the
6. IT Governance auditor must collect evidence and make
IT Governance is known as the proper judgments regarding the completeness and
management, control, and use of IT systems. accuracy of accounting information. The
auditor cannot make informed decisions
necessary to complete the audit without an
The board of directors and top-level, understanding of the accounting information
executive managers must take responsibility system. The auditor cannot judge the
to ensure that the organization uses reliability of accounting data without
processes that align IT systems to the understanding how the data is entered,
strategies and objectives of the organization. processed, and reported in the accounting
IT systems should be chosen and information system.
implemented to support the attainment of
strategies and objectives.
THE RELATION OF ETHICS TO ACCOUNTING
INFORMATION SYSTEMS
THE IMPORTANCE OF ACCOUNTING
INFORMATION SYSTEMS TO ACCOUNTANTS
Unfortunately, there are many opportunities for
unethical or fraudulent behavior related to
Anyone pursuing an accounting career must study accounting information systems. Accounting
and understand accounting information systems information systems can be misused to assist in
(AIS) and the related concepts. Any career path committing or concealing unethical acts. That is, the
within accounting will in some manner involve the AIS is often the tool used to commit or cover up
use of an accounting information system. unethical behavior.
Accountants have several possible roles related to
accounting information systems: They may be users
of the AIS, part of the design or implementation team Examples of some potential unethical behaviors, to
of an AIS, and/or auditors of an AIS. name a few, are as follows:

Users of the AIS • Fraudulent financial reporting


Accountants within any organization must • Revenue inflation
use the accounting information system to • Expense account fraud
accomplish the functions of accounting, • Inflating hours worked for payroll
generating and using accounting reports. For purposes
example, a controller in an organization must • Computer fraud
oversee a staff of accountants who record all • Hacking
accounting transactions, do the monthly • Browsing confidential data
closing of the accounting records, and
generate the reports needed by management
and external users. The accounting In many cases, unethical acts have also been made
information system is the mechanism that illegal. For example, fraudulent financial reporting is
allows the accounting staff to accomplish unethical, and it is also illegal. However, using a 3
those functions. Accountants must therefore percent bad debt percentage as opposed to a more
understand AIS concepts in order to perform realistic 4 percent rate to “fudge the numbers” may
these accounting jobs. not be criminal; yet it is unethical. For many reasons,
accountants must become aware of the potential
unethical behaviors. Some of those reasons are that
accountants

1. Assist in developing and implementing


internal control structures that should lessen
the chance of unethical actions. Those in this
role must understand the nature of the
various kinds of unethical actions before they
can design a system to lessen the risk.
2. Are often pressured to assist in, or cover up,
unethical actions. Therefore, accountants
must understand what actions are ethical and
unethical so that they can avoid being
coerced into unethical actions.
3. Deal with assets or records that could easily
tempt accountants to engage in unethical
behavior. For example, someone who handles
cash every day may be tempted to steal some
of the cash. Accountants have control over or
recording responsibilities for many assets.
When professional accountants face ongoing
temptation, having a better understanding of
which actions are unethical may help them to
resist temptation to commit unethical acts.

Вам также может понравиться