Control and Accounting Information Systems
Control and accounting information systems (AIS) are the backbone of modern business management. They help organizations safeguard assets, ensure data integrity, and comply with regulations.…

In a textile mill, which control activity would most directly prevent the "Ghost Inventory" fraud described?
A bank's system reduces the probability of a hack from 50% to 5% after installing MFA. What type of control is this?
Which of the following best illustrates a segregation of duties violation in a small retail store?
When a payroll system blocks a salary entry exceeding Rs. 500,000 for a junior clerk, which control type is being applied?
Which control activity directly addresses the risk of a power failure corrupting transaction data mid‑process?
In the three‑way match process, which document provides evidence of what was actually received?
A bank detects an employee accessing server settings at 3 am. Which general IT control is being exercised?
Which of the following is a detective control in the AIS framework?
A company uses a check digit algorithm (Modulus 11) to validate CNIC numbers. Which control principle does this exemplify?
Understanding Control and Accounting Information Systems
Control and accounting information systems (AIS) are the backbone of modern business management. They help organizations safeguard assets, ensure data integrity, and comply with regulations. This course explores the key concepts tested in a typical quiz, providing in‑depth explanations, real‑world examples, and best‑practice recommendations. By the end of the module, you will be able to identify critical control components, apply segregation of duties, and evaluate various control types such as preventive, detective, and corrective controls.
1. The COSO Framework and the Control Environment
The Committee of Sponsoring Organizations of the Treadway Commission (COSO) defines five interrelated components of internal control: Control Environment, Risk Assessment, Control Activities, Information & Communication, and Monitoring. Among these, the Control Environment sets the ethical tone and establishes the foundation for all other components.
- Key elements of the control environment include integrity, ethical values, competence of personnel, and the board’s oversight.
- Senior management demonstrates commitment through policies, codes of conduct, and leading by example.
- When the control environment is weak, even well‑designed controls may be bypassed or ignored.
In quiz question 1, the correct answer is Control Environment because it directly addresses the ethical atmosphere set by senior management.
2. Segregation of Duties (SoD) – A Core Control Activity
Segregation of duties is a fundamental control activity that prevents a single individual from having the ability to both perpetrate and conceal errors or fraud. The classic SoD matrix separates responsibilities into three categories:
- Authorization – approving transactions.
- Custody – handling assets or data.
- Record‑keeping – documenting transactions.
Violations occur when one person performs two or more of these functions. For example, in a small retail store, a cashier who both collects cash and reconciles the cash drawer (quiz question 4) violates SoD, increasing the risk of misappropriation.
3. Types of Controls: Preventive, Detective, Corrective, and Compensating
Controls can be classified by the point at which they act in the risk‑management cycle:
- Preventive controls aim to stop errors or fraud before they occur. Example: Multi‑Factor Authentication (MFA) that reduces a hack probability from 50% to 5% (quiz question 3).
- Detective controls identify incidents after they have happened, such as intrusion detection systems (IDS) that flag unusual login times (quiz question 8).
- Corrective controls remediate the effects of an incident, like restoring data from backups after a power failure.
- Compensating controls provide alternative safeguards when a primary control is not feasible.
Understanding the distinction helps managers design layered defenses that address both likelihood and impact.
4. Control Activities in Practice
4.1. Independent Verification of Inventory
In a textile mill, the "Ghost Inventory" fraud—where fictitious inventory is recorded to conceal theft—can be prevented by an independent verification of physical stock against system records. This activity creates a tangible check that the ERP data reflects reality, aligning with the preventive control principle.
4.2. Limit/Range Checks in Data Entry
Automated validation rules, such as a limit or range check, stop inappropriate entries at the source. For instance, a payroll system that blocks salary entries exceeding Rs. 500,000 for a junior clerk (quiz question 5) enforces a business rule and reduces the chance of unauthorized overpayments.
4.3. Backup and Recovery for Power‑Failure Risks
Power failures can corrupt transaction data mid‑process. Implementing automated backup and recovery systems ensures that any lost or damaged data can be restored quickly, representing a preventive control against data loss and a corrective control for recovery.
4.4. The Three‑Way Match Process
The three‑way match is a cornerstone of accounts payable. It compares three documents:
- Purchase Order (PO) – the request.
- Receiving Report (or Goods Received Note) – evidence of what was actually received.
- Vendor Invoice – the request for payment.
In quiz question 7, the Receiving Report provides proof of receipt, confirming that the goods listed on the PO were indeed delivered.
5. General IT Controls (GITC) and Their Role in AIS
General IT controls support the reliability of information systems across the organization. Key GITCs include:
- Access controls – ensuring only authorized users can perform specific actions.
- Change management – governing modifications to system configurations.
- Backup and recovery – protecting data integrity.
- Security monitoring – using tools like IDS and firewalls to detect and prevent threats.
When a bank detects an employee accessing server settings at 3 am, the alert is generated by an Intrusion Detection System (IDS), illustrating a detective IT control (quiz question 8).
6. Designing an Effective Control System
To build a robust control environment, follow these steps:
- Assess Risks – Identify threats such as fraud, data loss, or unauthorized access.
- Define Control Objectives – Clarify what each control should achieve (e.g., prevent ghost inventory).
- Select Control Types – Choose preventive, detective, or corrective controls based on risk severity.
- Implement Segregation of Duties – Design workflows that separate authorization, custody, and recording.
- Automate Validation Rules – Use limit/range checks, input masks, and business rule engines.
- Monitor Continuously – Deploy IDS, log analysis, and periodic audits.
- Review and Update – Conduct regular monitoring and adapt controls to emerging threats.
By integrating these elements, organizations can achieve a balanced control system that aligns with COSO principles and modern IT governance.
7. Frequently Asked Questions (FAQ)
What is the difference between a preventive and a detective control?
A preventive control stops an undesirable event before it occurs (e.g., MFA, segregation of duties). A detective control identifies an event after it has happened (e.g., IDS alerts, reconciliations).
How often should inventory verification be performed?
Best practice recommends at least quarterly physical counts, supplemented by cycle counts for high‑value or high‑risk items.
Can a single control serve multiple purposes?
Yes. For example, an automated backup system acts as a preventive control (protecting against data loss) and a corrective control (enabling recovery).
8. Key Takeaways
- The Control Environment is the ethical foundation of COSO.
- Segregation of duties prevents individuals from both committing and concealing fraud.
- Identify the appropriate control type—preventive, detective, corrective, or compensating—for each risk.
- Use limit/range checks to enforce business rules at the data‑entry level.
- Implement robust backup and recovery solutions to mitigate power‑failure risks.
- Apply the three‑way match process to ensure accurate payments.
- Leverage general IT controls like IDS to monitor and protect information systems.
Mastering these concepts equips managers, auditors, and IT professionals to design and maintain resilient accounting information systems that protect assets, ensure data integrity, and support strategic decision‑making.
