| Course | ACC 660 Controllership |
|---|---|
| Module | Module 7 |
| Paper type | graduate discussion post on internal control in decentralized operations |
| Length | About 360 words, 3 pages |
| Format | APA 7 student paper |
| School | Southern New Hampshire University |
| Program | MS Accounting |
| Updated | October 2026 |
Free sample paper for ACC 660 Module 7
Module Seven Discussion
Fourteen Front Desks
Each of the group's 14 hospitals operates with considerable independence. At a typical site, two or three front-desk staff check clients in, take payments, apply discounts and process refunds; a pharmacy technician orders, receives and dispenses drugs, including controlled substances; and staff record their own time in the scheduling system, approved by a hospital manager who also works shifts. The corporate team of nine in accounting cannot watch each site, and the sponsor does not want to add staff at every hospital.
Segregation of duties, the textbook answer, is not possible with two people at a desk. So the question is which risks matter most and what can be done centrally. I would rank three. First, discounts and refunds: an employee could take a cash or card payment, then record a large discount or refund to cover it. Second, controlled drugs: diversion is both a financial loss and a regulatory and safety issue. Third, time entry: hours recorded without work.
For each, a monitoring control performed outside the site can compensate. The controller's team can produce a weekly report of discounts and refunds by employee and hospital, with any employee above twice the group average reviewed by the regional director. The medical director, not the pharmacy technician, can reconcile controlled drug logs to purchases and dispensing records monthly, with spot counts by a regional manager. Payroll analytics can compare recorded hours with logins to the practice system and door access records. Roehl-Anderson (2013) emphasizes that the controller's role in control includes designing such monitoring, not only performing transaction-level checks.
Research suggests the stakes. Doyle et al. (2007) linked material weaknesses to complexity, such as having more segments and operations to oversee, while Ashbaugh-Skaife et al. (2008) report better accrual quality after companies fixed their control problems. Central monitoring will not catch everything, and it costs analyst time, about a quarter of one position here, but it preserves the local autonomy that lets hospitals serve clients quickly.
For classmates: with time to address only one of the three risks this quarter, which gets your attention, and what would make you reorder the list if drug enforcement in the state tightened?
References
Ashbaugh-Skaife, H., Collins, D. W., Kinney, W. R., & LaFond, R. (2008). The effect of SOX internal control deficiencies and their remediation on accrual quality. The Accounting Review, 83(1), 217-250. https://doi.org/10.2308/accr.2008.83.1.217
Doyle, J., Ge, W., & McVay, S. (2007). Determinants of weaknesses in internal control over financial reporting. Journal of Accounting and Economics, 44(1-2), 193-223. https://doi.org/10.1016/j.jacceco.2006.10.003
Roehl-Anderson, J. M. (2013). Controllership: The work of the managerial accountant (9th ed.). Wiley.
What the ACC 660 Module 7 instructions ask for
The Module Seven discussion in ACC 660 usually asks about internal control in a setting that strains traditional controls: decentralized operations, small sites, rapid growth or new technology. Expect a post of moderate length built on the COSO framework, the textbook and a study or two, then replies. Good posts identify the specific risks in the setting, explain why standard controls such as segregation of duties fail there, and propose compensating controls, often monitoring and analytics, with their costs and limits. Some prompts ask about the controller's role in fostering a control culture, which fits the same structure of risk, control and trade-off. Ranking the risks before proposing controls shows judgment.
How this ACC 660 Module 7 discussion example is built
The post describes hospitals where two front-desk staff take payments, apply discounts and process refunds, and where a pharmacy technician both receives and dispenses controlled drugs. It ranks the risks: discounts and refunds used to divert payments, diversion of controlled drugs and padded time entries. It proposes central monitoring: weekly reports of discounts and refunds by employee, reconciliation of controlled drug logs to purchases by the medical director, and payroll analytics comparing hours with system logins. It cites Doyle, Ge and McVay on weaknesses in complex, decentralized firms and Ashbaugh-Skaife and colleagues on remediation, then asks classmates which risk they would address first if time allowed only one this quarter.
Where the ACC 660 Module 7 rubric puts the points
Scoring for the decentralized control discussion typically weighs identification of setting-specific risks, explanation of why standard controls fail, the quality of compensating controls, attention to cost and autonomy, the research cited and the replies. The better posts rank risks rather than listing them, propose controls that a small site could run and explain what the central team monitors and how often. Posts that recommend full segregation of duties at a site with two employees, or that ignore the cost of control, score lower. Replies that test a classmate's compensating control for a gap or suggest a cheaper alternative count for more than simple agreement. Naming the COSO component each control serves adds structure, and an estimate of the monitoring time needed shows the plan is realistic.
ACC 660 Module 7 help: the mistakes that cost points
Students sometimes recommend hiring more staff to segregate duties, which a small site cannot afford, when the realistic answer is monitoring by someone outside the site. Others list controls without ranking risks, so a minor risk gets as much attention as the one most likely to cause loss. If your prompt concerns a single large site instead, segregation of duties becomes feasible and the emphasis shifts to process controls. Say what report the central team would review and how often; that detail shows the control would actually operate. Then estimate its cost in staff time and say what it would not catch.
Get ACC 660 Module 7 written to your instructions
Send the ACC 660 Module 7 prompt. The post will analyze the control problem in a concrete setting, propose specific controls with their trade-offs and support its view with research, closing with a question for replies. Turnaround is about two days, and your first one is free. The paper above is an original model document written by our desk, not a submitted student paper and not an official Southern New Hampshire University document.
More ACC 660 papers and related MS Accounting samples
- ACC 660 Module 1 Discussion: The Controller Under a Private Equity Owner
- ACC 660 Module 2 Close Process Assignment: From a 12-Day Close to Five
- ACC 660 Module 3 Milestone One: A Driver-Based Budget for 14 Hospitals
- ACC 660 Module 4 Discussion: Which EBITDA Add-Backs Should a Controller Sign?
- ACC 660 Module 5 Cash Management Assignment: A 13-Week Cash Forecast and Covenant Headroom
- ACC 660 Module 6 Milestone Two: A KPI Dashboard for Hospital Leaders
- ACC 660 Module 8 Acquisition Integration Assignment: The First 100 Days of a New Hospital
- ACC 660 Module 9 Milestone Three: The Lender and Board Reporting Package
- ACC 660 Module 10 Final Project: A Roadmap for the Finance Function
- ACC 646 Module 1 Discussion: What a Forensic Accountant Does That an Auditor Does Not
- ACC 640 Module 1 Discussion: Who Audits the Auditors?
- MBA 687 Module 8 Final Project Change Management Plan
- ACC 550 Module 3 Milestone One: Evaluating the Current Costing System
ACC 660 Module 7 questions, answered
Where can I find a free ACC 660 Module 7 Discussion sample?
This page includes the full ACC 660 Module 7 post on internal control across many small, autonomous hospital sites.
Why does segregation of duties fail at small sites?
There are too few employees to separate authorization, custody and recording, so one person often performs incompatible duties.
What is a compensating control?
A control that reduces risk when a primary control, such as segregation of duties, is not feasible, often a review or monitoring performed by someone independent of the activity.
How can analytics help control decentralized operations?
By flagging unusual patterns centrally, such as high discounts by one employee or hours recorded without system activity, so reviews can focus where risk appears.
Does more control always reduce risk efficiently?
No. Controls have costs, including staff time and slower service, so they should be matched to the size and likelihood of the risks they address.