Consideration of Risks and Internal Controls in Business Process Modelling



Journal of Information System Security
Volume 5, Number 3 (2009)
Pages 2341
ISSN 1551-0123
Rosalyn Mansour — University of South Florida, USA
Uday S. Murthy — University of South Florida, USA
Information Institute Publishing, Washington DC, USA




Given the myriad risks facing organizations these days, information systems and more importantly the data underlying the systems are susceptible to material errors, irregularities, or even fraud. It is therefore critically important to ensure that proper controls are built into organizational information systems. This paper describes a methodology for identifying risks and internal controls on a business process model. Using McCarthy's (1982) Resources, Events, Agents (REA) model as the basis for business process modeling, the methodology is aimed at the identification and documentation of internal controls at the business process level. With a focus on accounting information systems, we first show how the basic REA framework is used to model revenue cycle business processes. We then identify illustrative risks, the corresponding audit objectives, and related internal control procedures for the sales order processing subsystem. A UML diagram of the sales order processing subsystem entities is shown, with specific table and field level controls indicated. Future directions in this line of research aimed at developing an internal control ontology are also discussed.




Resources Events Agents Model, Business Process Modeling, Internal Controls, Risks, Audit Objectives




