6 Data processing in the order-to-cash process
Have you ever sat on a Herman Miller office chair?
No?
Ok, no problem, the story works without you having to sit on a Herman Miller chair.
There is a book called ‘The Oz principle’. The authors, Roger Connors, Tom Smith, and Craig Hickman, write about the concept of individual and organizational accountability. Their overall message is that, in order to be effective, people and organizations should realize they are in control of their actions and that they should get away from the victim mindset. They advocate that instead of thinking ‘it’s so unfair that this happened; we cannot do/achieve this because of these colleagues and because of this boss and because of this teacher!’ 😉, we should think more in terms of ‘what can I do to make the situation better?’.
One example that they use in the book (and this is an old book!) is the situation Herman Miller experienced with shipping their furniture. Basically, each shipment of Herman Miller furniture contained a text outlining that ‘Damage [to the furniture] received during transit is the responsibility of the transportation company’. This is the victim mindset and the finger-pointing-‘it’s the other guy’s fault’-attitude that the Oz principle authors advocate against. Nevertheless, shortly after, the company took control of their actions and distanced itself from the blame game by changing the shipping notice text to contain ‘Call your Herman Miller dealer immediately. […] We are fully committed to your complete satisfaction.’ and continued to inform the customers of ways in which Herman Miller can support the customer if furniture becomes damaged during transportation. This story links to the idea of not forgetting that we are always in control of something, even something as small as the smile on our faces.
Shipping is one part in the process of order-to-cash or, in order words, the sales process. In such a process, we start with a customer who wants to purchase something, we take these products from storage, we ship them, and we make sure we receive money for the sale. Let’s see this in a diagram!
6.1 Order-to-cash process
The order-to-cash process is exemplified in Figure 6.1 . In this diagram, the order-to-cash process starts with a customer making a request for goods. This triggers the creation of a sales order which contains the items ordered, their quantities and prices. With the information from the sales order, a warehouse picking ticket is created and the requested items are collected and packed for delivery. The goods to be delivered are transferred to the shipping department, or shipping company, which leads to the creation of a shipping note which will accompany the goods delivered to the customer. The goods are then shipped to the customer and an invoice is created for the sale. In the end, the customer pays for the goods, so cash is received through a cash receipt.
6.2 Accounts receivables
The accounting system, through its double entry bookkeeping, connects every sale transaction with either the cash account or the accounts receivables account. In principle, a movement in sales should see a movement in cash or accounts receivables. When this does not happen, people become suspicious and rightly so.
In a 2019 seekingaplha article and related Twitter post (Figure 6.2), Tesla is being accused of a weird pattern for accounts receivables. Specifically, even when revenue from sales drops, accounts receivable remain constant. This weird pattern is making stakeholders wonder if the financial numbers are correct.
To add to the complexity of accounts receivables is the reality that companies selling on credit have uncertain accounts receivable. This means that some accounts receivables might not be paid by customers. The financial statements balance of accounts receivable needs to show this uncertainty in collection. This is achieved by using a contra-asset accounts, the Allowance for Uncollectable Accounts Receivables, which diminishes the balance sheet value of accounts receivable.
Sales and accounts receivable accounts are substantial accounts for many companies and as such, auditors pay a great deal of attention to these accounts. Here, we’re interested in how to use analytics to process sales and accounts receivables information and make sure we have reliable information on these accounts.
But before we go into analysis, we’ll have to step back and think of the ‘glue’ that holds reliable information together: the internal control of a company. Let’s have a look at the main internal control frameworks and concepts.
6.3 The ´glue´ that holds reliable information together - internal control concepts
Let’s say you plan to go on a hiking expedition with friends. You’ll have to pack your luggage. Ideally, you would come up with some broad categories that will make your packing more efficient and effective. What can these categories be? Maybe something like ‘food’, ‘clothes’, ‘equipment’, ‘other’. This categorization would help you make the following list: food (water, crackers, protein bar), clothes (one full change-of-clothes, rain jacket), equipment (hiking shoes, trekking poles), other (first-aid kit, lighter, map). The broad categories that I describe, food-clothes-equipment-other can be seen as a framework that guides your list-making. Without using broad categories within a framework, you might have forgotten some items like the map or the rain jacket. Then, you would not have achieved your hiking goal of having and enjoyable hike.
Similarly, the internal control domain uses frameworks to guide organizations in the design of effective internal control systems. What follows in this chapter is the description of two important internal control frameworks, the COSO framework and the information-based framework for control.
6.4 Casa of COSO
In 1992 the Committee of Sponsoring Organizations of the Treadway Commission (COSO) released the Internal Control - Integrated Framework (Sponsoring Organizations of the Treadway Commission et al. (2013)), a framework which was to become one of the most used resources for designing and implementing internal control systems. As we all know, what gets defined, gets understood (actually, I just made that up). But one could argue that COSO had such a big impact because of the fact that it defined internal control. The definition of internal control given by COSO is as follows: ‘internal control is a process, effected by an entity’s board of directors, management and other personnel, designed to provide reasonable assurance regarding the achievement of objectives relating to operations, reporting and compliance’. Basically, every organizational objective within the area of operations (the effectiveness and efficiency of an organization’s operations), reporting (internal and external financial and non-financial reporting) and compliance (adherence to applicable laws and regulations) would become the playing ground of internal control. This lead some authors to decry that there is a control explosion (Maijoor (2000), Power (2004)). We’re not going to argue here whether the explosion is true or not. What I think is important for you to know is the fact that internal control appears in every organization. Knowing about internal control is relevant for your future professional career, be that of auditor, controller or entrepreneur.
Besides defining internal control, COSO also defines five interrelated components of internal control:
- Control environment. The control environment is the organization’s culture (e.g., ethical values, management philosophy) with respect to internal control. Whenever we see a bad control environment (e.g., ‘The Volkswagen Diesel Emissions Scandal and Accountability - Where Were the Auditors and Attorneys during the Sustainability Charade?’), we can be suspicious of internal control.
- Risk assessment. Risk assessment comprises three stages: risk identification (identify the future uncertain events that may have negative consequences), risk analysis (assess the likelihood and impact of each risk), and risk evaluation (categorize each risk so that appropriate action can be taken with respect to that risk). Adding a risk response to risk assessment leads to the wider concept of risk management. Risk responses can be to eliminate the underlying activity that leads to risk, to share the risk (e.g., insurance) or to reduce the risk by using control activities.
- Control activities. There are many classifications of control activities, from preventive controls (e.g., control the risk of hiring unqualified employees by setting procedures for hiring personnel) to detective controls (e.g., control the risk of fictitious sales by performing analytical reviews to estimate the expected sales number), and from direct controls (e.g., control the risk of employees making bad products by checking their work) to indirect checks (e.g., control the risk of offering low quality educational programs by using student evaluations).
- Information & communication. Being in control, or being able to achieve organizational objectives, is fundamentally intertwined with information & communication. Think of a chef in a restaurant, aiming to serve a delicious dinner to customers. In order to achieve her goal, the chef needs to communicate clear information to the kitchen staff (e.g., how should the dishes be assembled, how to adapt the dish to individual orders). For example, a restaurant can use a checklist to make sure every dish is prepared well. Using a checklist in a restaurant might sound strange but I’m not inventing this. If you want to see how checklists are used in restaurants to avoid mistakes, check the book of Atul Gawande ‘The Checklist Manifesto: How To Get Things Right’
- Monitoring. Monitoring fundamentally asks - are the controls functioning, are they operating effectively? Let’s take the example of a restaurant that, instead of using a checklist to make sure every dish is prepared well, uses verbal communication. So, the chef just shouts out instructions of how every dish should be prepared. Would the SHOUTING, as a communication medium, lead to the achievement of organizational goals? Maybe, but most likely not - some stressed junior might forget to put salt in the dish. Monitoring should be put in place (e.g., track how many dishes are returned) to see if control mechanisms (i.e., the procedure of shouting requirements for dishes) are functioning.
We can think of these five components as parts of a house Figure 6.3 . The foundation of the COSO house is the Control environment and the Monitoring is on its roof to make sure that the risk assessment, control activities, and information & communication function as expected. Information & Communication touches all the other four areas of internal control (like the walls of a house) and the Risk assessment is matched against the Control activities (like the windows of a house). By covering all the five areas delineated by the COSO framework, organizations can be more confident that they are implementing good systems of controls, that we have reliable information and that we can achieve organizational goals.
6.5 Information-based framework for control
A different framework aimed at the design of effective internal controls, uses an information-based perspective of control (Vaassen and Meuwissen (2021)). The information-based control framework aims to be more actionable, relative to the COSO framework, because it delineates specific domains where control is needed and specific goals for each domain (Figure 6.4).
According to the information-based control framework, the following domains of any organization need to be controlled:
the business domain. This domain refers to what a company does to create value (e.g., selling services)
the information & communication domain. This domain refers to the information that is provided to the business domain (e.g., how well is the company performing)
the data domain. This domain refers to the data used for information provision (e.g., sales transactions can be seen as data)
the information & communication technology (IT) domain. This domain refers to all the electronic media used (e.g., hardware, software) to input, process, store and provide data and to support and enable communication
The underlying theory behind the information-based control framework is that all four domains need to be aligned. If something changes in one domain, the other domains need to change too.
Let’s apply the information-based control framework to the fitness industry. The fitness industry moved completely online during the Covid pandemic. This industry changed its operations by moving from running activities in big gyms to online workouts. If the way the fitness business is operating changes, so do too the information needs. Let’s say that in the physical version, gym members would pay subscriptions for attending gym classes, while in the online version, gym members would pay per each class viewed and for the opportunity to socialize on the platform. While during the in-gym workouts, management would need information on how many customers pay subscriptions, after the online move, the information needs would focus on how much time customers interact with the sports platform (to watch the lessons or to socialize after lessons). The data collected from customers is also different; while in the gym-setting, data would be collected at enrolment and subscription payment, in the online environment data would be continuously collected. As expected, the IT infrastructure is much more important in the online setting.
Because of its strict delineation of domains where control is needed, the information-based control framework can readily indicate control goals related to each domain. For the business domain, goals can be set based on the balanced scorecard criteria: efficiency and effectiveness of internal processes, innovative power, customer satisfaction and financial performance. For a restaurant, performance indicators can be set for example, on the level of satisfaction of the customers visiting the restaurant (e.g., an average of 4 out of 5 stars).
Goals can be set for the quality of information along the following criteria:
Validity: information is valid if it is in accordance with reality (e.g., fictitious sales do not comply with the validity criteria)
Accuracy: information is free of error (e.g., there is no mathematical error in the calculation of a discount)
Completeness: every relevant information is recorded (e.g., we are not missing suppliers from our database)
Timeliness: information is provided in time for making a decision
Understandability: information is not ambiguous (e.g., ‘Profits increased satisfactorily’ is more understandable than ‘Profits increased by 5%’
Efficiency: information is produced at a reasonable cost (e.g., it is not very useful to put a complex system in place to track how much rice is returned per dish; it is more useful to track how many dishes are returned and of which type)
Effectiveness: information can be used (e.g., there is not need of providing information on vendors when we need information on customers)
Data can also have goals than can be met (e.g., data inputs should be valid, data inputs should be accurate, private data should be protected) and so does too the IT infrastructure (e.g., the IT infrastructure should allow for data to be made available on demand).
Without a strong internal control system, any data analysis is problematic. This is something auditors understood a long time ago: make sure the system producing the data is good, then look at the data.
6.6 Applications and questions:
Read pages 189-193 from the chapter Substantive Tests from Westland (2020). Work to reproduce the code and explore sales transactions with the
Hmisc::describe, andpsychR functions. Interpret the results.Read pages 194-198 from the chapter Substantive Tests from Westland (2020). Work to reproduce the code and create a trial balance from client transactions. Interpret the results.
Read pages 198-200 from the chapter Substantive Tests from Westland (2020). Work to reproduce the code and foot and agree the Accounts receivable. Interpret the results.
Read pages 212-216 from the chapter Substantive Tests from Westland (2020). Work to reproduce the code and estimate the Allowance for Uncorrectable Accounts Receivables. Interpret the results.
Can you think of examples for all the components of the COSO framework?
Can you apply the information-based control framework to a new situation besides the one described in the chapter (i.e., related to the fitness industry)?
Can you give examples of situations when the information quality criteria are not met (e.g., when is information not valid?)?