Visible to the public Internal Control Framework for a Compliant ERP System

TitleInternal Control Framework for a Compliant ERP System
Publication TypeJournal Article
Year of Publication2014
AuthorsChang, She-I, Yen, David C., Chang, I-Cheng, Jan, Derek
JournalInf. Manage.
Volume51
Pagination187–205
ISSN0378-7206
Keywordsenterprise resource planning, Internal control framework, IT control
Abstract

After the occurrence of numerous worldwide financial scandals, the importance of related issues such as internal control and information security has greatly increased. This study develops an internal control framework that can be applied within an enterprise resource planning (ERP) system. A literature review is first conducted to examine the necessary forms of internal control in information technology (IT) systems. The control criteria for the establishment of the internal control framework are then constructed. A case study is conducted to verify the feasibility of the established framework. This study proposes a 12-dimensional framework with 37 control items aimed at helping auditors perform effective audits by inspecting essential internal control points in ERP systems. The proposed framework allows companies to enhance IT audit efficiency and mitigates control risk. Moreover, companies that refer to this framework and consider the limitations of their own IT management can establish a more robust IT management mechanism.

URLhttp://dx.doi.org/10.1016/j.im.2013.11.002
DOI10.1016/j.im.2013.11.002
Citation KeyChang:2014:ICF:2592290.2592340