What does information-processing control mean on the CPA exam?
Information-processing control. A control over processing in an IT application or a manual information process that directly addresses a risk to the integrity of information. The standard's own alias is transaction control. It is not a rename of application control, which AU-C still uses for the automated subset.
Defined against AU-C 315.12 and .A7.
Which CPA exam sections use information-processing control?
Information-processing control appears in the ISC section of the CPA exam.
Other terms defined against AU-C 315
- application controls: Controls built into one business process or system, such as a validity check on an input field or a three-way match.
- assessed risk: The auditor's judgment about the risk of material misstatement at the assertion level, combining inherent and control risk.
- control environment: The governance and management functions and the attitudes, awareness, and actions of those charged with governance and management concerning the entity's system of internal control.
- general controls: Controls over the IT environment as a whole -- access, change management, operations -- that everything else depends on.
- general IT control: A control over the entity's IT processes that supports the continued effective functioning of information-processing controls and the integrity of information.
- information and communication: One of the five components of internal control: how an entity obtains the information it needs and gets it to the people who have to act on it.
- rights and obligations: The assertion that the entity genuinely owns the assets it reports and genuinely owes the liabilities.
- risk assessment procedures: The audit procedures designed and performed to identify and assess the risks of material misstatement at the financial statement and assertion levels.
Related terms
- access control: Deciding who may reach what, and enforcing it.
- internal control over financial reporting: A process designed to provide reasonable assurance regarding the preparation of reliable financial statements.
- online analytical processing: Processing optimized for querying accumulated data across many dimensions, as a data warehouse does.
- trust services criteria: The AICPA's control criteria for a SOC 2 engagement, in five categories: security, availability, processing integrity, confidentiality and privacy.
- processing integrity: One of the trust services categories: system processing is complete, valid, accurate, timely and authorized.
- PCI DSS: The Payment Card Industry Data Security Standard: contractual rules that anyone storing, processing or transmitting card data must follow.