Unit 2 of 4 · M.Com Sem 4

Unit 2: EDI and risk management

E-Commerce notes · PTU syllabus (MCOPGE401-18)

3 min read5 topics10 exam questions
On this page
  1. Unit summary
  2. Traditional EDI systems
  3. Value-added networks and financial EDI
  4. EDI–internet integration and impact on accounting
  5. Risks of internet and intranet transactions
  6. Control weakness vs control risk
  7. Key terms
  8. Quick revision
  9. Important questions

Unit summary

Before the web, businesses exchanged documents electronically through EDI — and internet trade brings its own risks. This unit covers traditional EDI systems, value-added networks, financial EDI, EDI–internet integration, the impact on the accounting profession, risks of internet and intranet transactions, social engineering, risks to confidential archival data, and control weakness vs control risk.

After this unit you can

  • Explain EDI, value-added networks and financial EDI
  • Explain EDI–internet integration and the impact on accounting
  • Identify risks of internet transactions including social engineering
  • Distinguish control weakness and control risk

PTU syllabus topics

  • Traditional EDI systems
  • value-added networks
  • financial EDI
  • EDI-internet integration
  • impact on the accounting profession
  • risks associated with internet/intranet transactions
  • social engineering
  • risks to confidential archival data
  • control weakness vs control risk
ProcessHow EDI works
  1. 1Buyer system creates a purchase order
  2. 2Translate into a standard EDI format
  3. 3Send via VAN or internet
  4. 4Supplier receives and translates
  5. 5Order processed automatically
1

Topic 1

Traditional EDI systems

Electronic Data Interchange (EDI) is the computer-to-computer exchange of business documents (purchase orders, invoices, shipping notices) in a standard format between trading partners.

ProcessEDI process
  1. 1

    Buyer's application creates a purchase order

  2. 2

    EDI translator converts it to a standard format

    ANSI X12, UN/EDIFACT

  3. 3

    Transmission through a VAN or direct link

  4. 4

    Supplier's translator converts it to its format

  5. 5

    Supplier's application processes the order

  6. 6

    Functional acknowledgement sent back

  • Benefits: speed, fewer errors (no re-keying), lower paper and processing costs, better inventory management (JIT), stronger partner relationships.
  • Limitations: high set-up costs, standards complexity, need for trading-partner agreements.
2

Topic 2

Value-added networks and financial EDI

  • Value-added network (VAN): a private network provider acting as an electronic post office — mailboxes, translation, security, audit trails, store-and-forward; charges per transaction.
  • Financial EDI (FEDI): electronic exchange of payment-related information between businesses and banks — payment orders, remittance advice, bank statements; links with EFT (NEFT/RTGS) for straight-through processing.
3

Topic 3

EDI–internet integration and impact on accounting

  • Internet EDI: EDI over the internet using AS2 protocol, web EDI forms, XML/JSON and APIs — lower cost, accessible to small firms; e-invoicing under GST is a modern government-mandated EDI.
  • Impact on accounting profession: fewer paper documents, automated audit trails, continuous auditing, need for IT audit skills, controls over data integrity and authorisation, electronic evidence (Section 65B, Evidence Act / Bharatiya Sakshya Adhiniyam 2023), real-time reporting.
4

Topic 4

Risks of internet and intranet transactions

ClassificationRisks in internet commerce
Risks
  • Interception

    Data captured in transit

  • Spoofing and impersonation

    Fake websites and identities

  • Unauthorised access

    Hacking, weak passwords

  • Malware

    Viruses, ransomware, trojans

  • Denial of service

    Overloading servers

  • Repudiation

    Parties deny transactions

  • Intranet risks

    Insider misuse, excessive privileges, unpatched internal systems

  • Social engineering: manipulating people into revealing confidential information or bypassing controls — phishing, pretexting, baiting, tailgating, vishing; the human weakness behind many breaches; countered by awareness training, verification procedures, least-privilege access.
  • Risks to confidential archival data: stored data (backups, archives) may be stolen, corrupted or lost; media obsolescence; inadequate encryption; insider access; retention law compliance — controls: encryption at rest, access controls, secure off-site/cloud backup, data retention and disposal policies.
5

Topic 5

Control weakness vs control risk

ComparisonControl weakness vs control risk
Control weakness
Control risk

Meaning

A deficiency in the design or operation of a control

Risk that a material misstatement will not be prevented or detected by controls

Nature

A specific gap (no password policy)

Overall assessment by the auditor

Effect

Increases control risk

Determines extent of substantive testing

Response

Fix the control

Plan audit procedures accordingly

  • Audit risk = Inherent risk × Control risk × Detection risk.

Key terms

EDI
Computer-to-computer exchange of standard business documents
VAN
Value-added network offering EDI services
Financial EDI
Electronic exchange of payment information
Social engineering
Manipulating people to gain information or access
Control risk
Risk that controls fail to prevent or detect misstatements

Quick revision

  • EDI: standards (ANSI X12, EDIFACT), translators, VANs.
  • FEDI with banks; internet EDI (AS2, APIs); GST e-invoicing.
  • Accounting impact: electronic evidence, continuous audit, IT controls.
  • Risks: interception, spoofing, malware, DoS; social engineering; archival data risks.
  • Control weakness vs control risk; audit risk model.

Important exam questions

Practice questions written to the PTU exam pattern for this unit's syllabus: short answers (Section A style) and long answers (Sections B and C style).

Short-answer questions

  1. Q1.What is EDI?
  2. Q2.What is a value-added network?
  3. Q3.What is financial EDI?
  4. Q4.What is social engineering?
  5. Q5.State two risks to archival data.
  6. Q6.Distinguish control weakness and control risk.

Long-answer questions

  1. Q1.Explain traditional EDI systems and value-added networks.
  2. Q2.Explain financial EDI and EDI–internet integration and their impact on accounting.
  3. Q3.Explain the risks associated with internet and intranet transactions.
  4. Q4.Explain control weakness and control risk in an e-commerce environment.

Stuck on this unit?

Message SBS on WhatsApp for help with E-Commerce, or to ask about studying M.Com at Synetic.

WhatsApp us