Skip to content

Accountancy · Ch 8 — Computerised Accounting System

Data Security and Internal Controls in a Computerised Accounting System

9

Data Security and Internal Controls in a Computerised Accounting System

Because accounting data in a computerised system is stored electronically and can, in principle, be accessed, copied or altered far more quickly than a bound manual ledger, data security and internal control measures are an essential part of running a Computerised Accounting System responsibly — a point directly connected to the "risk of unauthorised access" limitation studied earlier in this chapter.

1. Password protection

Access to the accounting software, and often to specific parts of it, should be protected by passwords issued individually to authorised users. This ensures that only people who are supposed to view or alter accounting data can log in and do so, and that any action taken in the system can, if needed, be traced back to the individual whose password was used.

2. Access rights (levels of authorisation)

Not every user of the system needs, or should have, the same level of access. A well-controlled system assigns access rights so that, for example, a data-entry clerk may be permitted only to enter vouchers, a supervisor may be permitted to review and approve entries, and only a senior accountant or the business owner may be permitted to alter closed periods or view certain sensitive reports. Restricting access rights in this way is a basic internal control that limits the damage any single error or dishonest act can cause.

3. Backup of data

A regular, disciplined routine of taking backup copies of the accounting data — onto a separate storage medium, ideally kept at a different physical location — protects the business against the loss of its entire accounting record due to a hardware failure, a virus, accidental deletion, or physical damage such as fire or theft. Backup is the single most important safeguard against the "risk of data loss" limitation of computerised accounting, and a business should decide, and follow, a clear schedule (daily, weekly, or as transaction volume requires) for taking it.

4. Audit trail

Good accounting software maintains an internal record of who entered or altered which piece of data, and when — an audit trail — so that any later dispute or suspected error/fraud can be traced back to its source, much as a manual system relies on signed vouchers and initialled corrections.

5. Other internal controls …

Definition 1Access rights

The specific permissions given to each user of a computerised accounting system, defining what data or functions (e.g., entering vouchers, approving entries, viewing reports, altering closed periods) that …

Definition 2Audit trail

A record maintained by accounting software of who entered or altered a piece of accounting data, and when, allowing any later query, error or suspected fraud to …