
Paper P7 INT: Advanced audit and assurance
464 Go to www.emilewoolfpublishing.com for Q/As, Notes & Study Guides © EWP
(1) Internet operation – quality/non-delivery
Risks Expected controls
Employment of appropriate skilled
technical resource.
Failure to deliver all requested items
could result in customer
dissatisfaction and a switch away
from using the internet service.
Checks on deliveries.
Reconciliation of orders and against
payments.
Inventories checks and controls.
Poor quality of deliveries could arise
from a lack of commitment to the
internet service by the local
supermarkets responsible for delivery
or delays in delivery. This could result
in:
customer dissatisfaction, customer
complaints and unwillingness of
customers to continue with the
service
a need to compensate customers
for poor quality/delayed goods
Clear, documented procedures for
deliveries.
Quality standards and control for
goods deliveries.
Monitoring of complaints received.
Monitoring of trends in use and
identification and review of potential
problem stores.
(2) Internet operation – systems problems
Risks Expected controls
System breakdown resulting in poor
customer service, loss of sales and
financial loss.
System logs.
Regular back-up of data.
Disaster recovery and business
continuity plans in place and subject
to regular testing and review.
Service standards for system
maintenance.
IT expertise.
If the internet ordering continues to
grow at a rapid rate, then continued
interruption of services could
ultimately affect profitability and
viability of the company.
Forecast of levels of ordering with
plans for maintenance of service to
achieve desired levels of service.
QPS sensitive information may be
obtainable by hackers through the
internet capability.
Data encryption.
Access controls.
Unauthorised access to customer
information obtained through the
internet resulting in customer
dissatisfaction, complaint and ‘lack of
trust’. Potential to lose customers.
Access and security controls –
restriction of access, access logs.
Access reporting and monitoring.
Data may become corrupted or lost,
System maintenance controls.