Exam CISA All QuestionsBrowse all questions from this exam
Question 389

Which of the following controls BEST ensures appropriate segregation of duties within an accounts payable department?

    Correct Answer: D

    Segregation of duties is an essential control mechanism to ensure that no single individual has control over all aspects of any financial transaction, reducing the risk of errors or fraud. Restricting program functionality according to user security profiles ensures that users can only access functions necessary for their specific job roles. This helps delineate responsibilities clearly, ensuring that the person creating transactions cannot also approve them, thereby ensuring appropriate segregation of duties within the accounts payable department.

Discussion
DeeplaxmiOption: D

D is correct.. A is incorrect bcos just mentioning the user name against the transaction, might hold that person responsible/accoutable but will not stop an unrelated employee from making changes. will not solve. SOD primarily required that the jobs are performed by appropriate / relevant individuals.

Yejide03Option: C

C. Restricting access to update programs to accounts payable staff only This control limits the access to update programs to only those staff members who are responsible for accounts payable activities. By restricting access in this manner, the organization can prevent unauthorized personnel from making changes to transaction records, thereby ensuring that the segregation of duties principle is maintained. Other staff members, such as those responsible for creating transaction records or reviewing/approving payments, would have different access privileges tailored to their respective roles, further enforcing segregation of duties.

swmasindeOption: D

D. Rokeby based

SwallowsOption: D

Segregation of duties is a fundamental principle of internal controls aimed at preventing errors and fraud by dividing responsibilities among different individuals or roles. By restricting program functionality according to user security profiles, the organization can control access to specific functions or actions within the accounts payable system based on the roles and responsibilities of individual users. This ensures that users only have access to the functionalities necessary for their job roles, preventing unauthorized or inappropriate access to sensitive functions and data.

a84nOption: C

Answer: C Option D, restricting program functionality according to user security profiles, contributes to access control and limits users' abilities based on their roles. However, it does not ensure strict segregation of duties within the accounts payable department. While it helps prevent unauthorized access to certain functions, it doesn't inherently prevent a single user from having conflicting duties, such as being able to both create and approve payments. Restricting access to update programs specifically to accounts payable staff ensures a clearer segregation of duties by limiting who can perform specific tasks within the department.

3008Option: D

`d' is answer