Unit 2: EDI and risk management
E-Commerce notes · PTU syllabus (MCOPGE401-18)
On this page
Unit summary
Before the web, businesses exchanged documents electronically through EDI — and internet trade brings its own risks. This unit covers traditional EDI systems, value-added networks, financial EDI, EDI–internet integration, the impact on the accounting profession, risks of internet and intranet transactions, social engineering, risks to confidential archival data, and control weakness vs control risk.
After this unit you can
- Explain EDI, value-added networks and financial EDI
- Explain EDI–internet integration and the impact on accounting
- Identify risks of internet transactions including social engineering
- Distinguish control weakness and control risk
PTU syllabus topics
- Traditional EDI systems
- value-added networks
- financial EDI
- EDI-internet integration
- impact on the accounting profession
- risks associated with internet/intranet transactions
- social engineering
- risks to confidential archival data
- control weakness vs control risk
- 1Buyer system creates a purchase order
- 2Translate into a standard EDI format
- 3Send via VAN or internet
- 4Supplier receives and translates
- 5Order processed automatically
Topic 1
Traditional EDI systems
Electronic Data Interchange (EDI) is the computer-to-computer exchange of business documents (purchase orders, invoices, shipping notices) in a standard format between trading partners.
- 1
Buyer's application creates a purchase order
- 2
EDI translator converts it to a standard format
ANSI X12, UN/EDIFACT
- 3
Transmission through a VAN or direct link
- 4
Supplier's translator converts it to its format
- 5
Supplier's application processes the order
- 6
Functional acknowledgement sent back
- Benefits: speed, fewer errors (no re-keying), lower paper and processing costs, better inventory management (JIT), stronger partner relationships.
- Limitations: high set-up costs, standards complexity, need for trading-partner agreements.
Topic 2
Value-added networks and financial EDI
- Value-added network (VAN): a private network provider acting as an electronic post office — mailboxes, translation, security, audit trails, store-and-forward; charges per transaction.
- Financial EDI (FEDI): electronic exchange of payment-related information between businesses and banks — payment orders, remittance advice, bank statements; links with EFT (NEFT/RTGS) for straight-through processing.
Topic 3
EDI–internet integration and impact on accounting
- Internet EDI: EDI over the internet using AS2 protocol, web EDI forms, XML/JSON and APIs — lower cost, accessible to small firms; e-invoicing under GST is a modern government-mandated EDI.
- Impact on accounting profession: fewer paper documents, automated audit trails, continuous auditing, need for IT audit skills, controls over data integrity and authorisation, electronic evidence (Section 65B, Evidence Act / Bharatiya Sakshya Adhiniyam 2023), real-time reporting.
Topic 4
Risks of internet and intranet transactions
Interception
Data captured in transit
Spoofing and impersonation
Fake websites and identities
Unauthorised access
Hacking, weak passwords
Malware
Viruses, ransomware, trojans
Denial of service
Overloading servers
Repudiation
Parties deny transactions
Intranet risks
Insider misuse, excessive privileges, unpatched internal systems
- Social engineering: manipulating people into revealing confidential information or bypassing controls — phishing, pretexting, baiting, tailgating, vishing; the human weakness behind many breaches; countered by awareness training, verification procedures, least-privilege access.
- Risks to confidential archival data: stored data (backups, archives) may be stolen, corrupted or lost; media obsolescence; inadequate encryption; insider access; retention law compliance — controls: encryption at rest, access controls, secure off-site/cloud backup, data retention and disposal policies.
Topic 5
Control weakness vs control risk
Meaning
A deficiency in the design or operation of a control
Risk that a material misstatement will not be prevented or detected by controls
Nature
A specific gap (no password policy)
Overall assessment by the auditor
Effect
Increases control risk
Determines extent of substantive testing
Response
Fix the control
Plan audit procedures accordingly
- Audit risk = Inherent risk × Control risk × Detection risk.
Key terms
- EDI
- Computer-to-computer exchange of standard business documents
- VAN
- Value-added network offering EDI services
- Financial EDI
- Electronic exchange of payment information
- Social engineering
- Manipulating people to gain information or access
- Control risk
- Risk that controls fail to prevent or detect misstatements
Quick revision
- EDI: standards (ANSI X12, EDIFACT), translators, VANs.
- FEDI with banks; internet EDI (AS2, APIs); GST e-invoicing.
- Accounting impact: electronic evidence, continuous audit, IT controls.
- Risks: interception, spoofing, malware, DoS; social engineering; archival data risks.
- Control weakness vs control risk; audit risk model.
Important exam questions
Practice questions written to the PTU exam pattern for this unit's syllabus: short answers (Section A style) and long answers (Sections B and C style).
Short-answer questions
- Q1.What is EDI?
- Q2.What is a value-added network?
- Q3.What is financial EDI?
- Q4.What is social engineering?
- Q5.State two risks to archival data.
- Q6.Distinguish control weakness and control risk.
Long-answer questions
- Q1.Explain traditional EDI systems and value-added networks.
- Q2.Explain financial EDI and EDI–internet integration and their impact on accounting.
- Q3.Explain the risks associated with internet and intranet transactions.
- Q4.Explain control weakness and control risk in an e-commerce environment.
Stuck on this unit?
Message SBS on WhatsApp for help with E-Commerce, or to ask about studying M.Com at Synetic.
