CPA Exam — AUDAssessing Risk and Developing a Planned ResponseMedium

An auditor is planning the audit for a client that has recently transitioned to a new, highly customized Enterprise Resource Planning (ERP) system. The new system integrates financial, operational, and supply chain functions. Which aspect of the client's internal control over financial reporting would the auditor primarily focus on during the risk assessment phase regarding this system change?

  1. AThe cost-benefit analysis performed by management for the ERP implementation.
  2. BThe frequency of data backups and disaster recovery plans.
  3. CThe physical security of the ERP servers.
  4. DThe effectiveness of user access controls and data migration processes.
Show answer & explanation

Correct answer: D. The effectiveness of user access controls and data migration processes.

When a client implements a new, highly customized ERP system, the primary concerns for the auditor related to internal control over financial reporting are ensuring that only authorized users can access and modify financial data (user access controls) and that financial data was accurately and completely transferred from the old system to the new (data migration processes). These areas directly impact the integrity and reliability of financial reporting.

Why the other options are wrong

  • A. The cost-benefit analysis is a management decision and not directly an internal control over financial reporting that the auditor would primarily focus on in assessing risk.
  • B. Data backups and disaster recovery are important general IT controls, but less specific to the unique risks of a new ERP system implementation and its impact on financial reporting processes.
  • C. Physical security is important but less directly impacts the accuracy of financial transactions after a system transition compared to logical access and data integrity.

Control Risk - System Implementation

The risk that a material misstatement will not be prevented or detected on a timely basis by the entity's internal controls due to weaknesses arising from the implementation of new or significantly changed IT systems.

  • New systems introduce unique risks (e.g., data conversion, interface errors).
  • Focus on controls over data integrity and system configuration.
  • User access and change management controls are critical.

Memory trick: New System, New Access, New Data Flow.

More Assessing Risk and Developing a Planned Response questions