Skip to content

Accountancy · Ch 7 — Computerised Accounting System

Data Security and Internal Controls

7

Data Security and Internal Controls

Because a computerised accounting system stores an entire business's financial history in electronic form, protecting that data from loss, corruption, or unauthorised access is just as important as recording it accurately in the first place. Data security in this context means the set of measures taken to prevent accidental loss, deliberate tampering, or unauthorised viewing of accounting data.

Common controls used to protect accounting data:

  • Access controls (user ID and password). Every user is given a unique login, and the system is configured so a user can only view or alter the parts of the data relevant to their role — for example, a data-entry operator may be allowed to create vouchers but not to alter an already-approved trial balance.
  • Authorisation limits. Transactions above a certain value require a second, more senior, person's approval before they are recorded, reducing the chance of an error or a fraudulent entry going unchecked.
  • Audit trail. A well-designed system automatically records who created or altered each entry, and when — so that any change to the accounts can always be traced back to a specific user and time.
  • Regular backup. Copies of the data are taken at regular intervals and stored separately (ideally off-site or on a separate device) so that a hardware failure, fire, or virus attack does not destroy the only copy of the business's records.
  • Physical controls. Restricting who can physically access the server or the computers on which the accounting data is stored — for instance, keeping the server in a locked room.
  • Anti-virus and firewall protection. Guarding the system against malicious software that could corrupt or steal data.
  • Disaster-recovery planning. A documented plan for restoring the accounting system and its data quickly after a major failure, so the business is not left without its records for an extended period. …
Definition 1Audit Trail

A chronological record, maintained automatically by the system, of who created or modified each account …

Definition 2Backup

A duplicate copy of accounting data stored separately from the original, so that the data can be restored if the original is lost …