An evidential reasoning approach to Sarbanes-Oxley mandated internal control risk assessment |
| |
Authors: | Theodore J. Mock Lili Sun Rajendra P. Srivastava Miklos Vasarhelyi |
| |
Affiliation: | 1. Anderson Graduate School of Management, University of California, Riverside, CA, 92521, USA;2. Department of Accounting and Information Systems, Rutgers University-Newark, NJ, 07102, USA;3. School of Business, The University of Kansas, Lawrence, KS, 66045, USA |
| |
Abstract: | In response to the enactment of the Sarbanes-Oxley Act 2002 and of the release of the Public Company Accounting Oversight Board (PCAOB) Auditing Standard No. 5, this study develops a risk-based evidential reasoning approach for assessing the effectiveness of internal controls over financial reporting (ICoFR). This approach provides a structured methodology for assessing the effectiveness of ICoFR by considering relevant factors and their interrelationships. The Dempster-Shafer theory of belief functions is utilized for representing risk.First, we develop a generic ICoFR assessment model based upon a Big 4 audit firm's approach and apply it to a real-world example. Then, based on this model, we develop a quantitative representation of various levels of ICoFR effectiveness and related risk-assessment as defined by the PCAOB and contrast these representations with levels implied by Auditing Standard No. 5. In doing so, we demonstrate the potential value of formal risk assessment models in both facilitating the assessment of risks in an individual engagement and in assessing the effects of different regulations. |
| |
Keywords: | |
本文献已被 ScienceDirect 等数据库收录! |
|