Skip to content
Back to BlogWriting Tips

ACC203: why do accounting students lose marks on a systems subject?

11 min read2,085 wordsNEW

Most students walk into Accounting Information Systems with two and a half years of double-entry behind them, and that training quietly works against them.

Most students walk into Accounting Information Systems with two and a half years of double-entry behind them, and that training quietly works against them. The subject looks like accounting, it sits inside an accounting degree, and its examples are all revenue cycles and purchase ledgers. But the marker is not checking whether your entries balance. They are checking whether you can look at a business process, say where it can go wrong, and name the control that would catch it. Those are different skills, and the gap between them is where most of the lost marks live. Below is how MAAS mentors read a subject with this shape, starting with a warning about the code.

Author: MAAS Editorial Team · Reviewed by a Senior Accounting mentor (PhD, Accounting)
Last updated: 2026-08-12
Category: writing-tips


First, check which ACC203 you are enrolled in

Direct answer: This code is unusually crowded, so confirm the institution before you trust any study material you find under it. At King's Own Institute in Sydney and Newcastle, ACC203 is Accounting Information Systems, sitting after ACC100 Introduction to Accounting, ACC101 Introduction to Financial Accounting and ACC201 Financial Accounting. The same five characters denote Managerial Accounting at the University of Tampa, Federal Income Taxation at Mercer County Community College, and Introduction to Financial Accounting I at the National Open University of Nigeria.

Evidence: Each institution publishes its own description openly, and course codes are internal to the university that issues them. Collisions like this are ordinary. Search engines have no reason to separate them, so a query on the bare code returns four unrelated syllabi mixed together.

Example: A student spent an evening working through depreciation and accruals exercises found under her own subject code before noticing her outline never mentioned preparing financial statements at all. The material was perfectly good. It belonged to a different country's degree.

This guide describes the KOI subject. If your outline is about tax returns or about preparing a balance sheet, you are reading the wrong page.


What is this subject actually asking of you?

Direct answer: It asks you to understand an accounting system as a system, not as a ledger. The published description runs in three parts: the basic concepts of AIS including its objectives, components and subsystems; emerging issues in computer crime, computer ethics and internal control within an organisation; and the common features of transaction processing systems such as purchases and accounts payable, revenue and accounts receivable, human resources, production, and general ledger and reporting. Practice with accounting software is integrated into the subject, and there is a specific focus on e-business and data security.

Evidence: Read that structure again and notice what it does not say. It does not ask you to prepare statements, and it does not ask you to compute anything difficult. Every one of the three sections is about how information moves, who touches it, and what stops it being wrong. The prerequisites do the accounting work; this subject sits on top of them.

Example: Given a case on a company's ordering process, one student described each step accurately and concluded that the process was well documented. A stronger answer described the same steps, then noted that the person who raised the purchase order also approved the invoice for payment, and identified that single fact as the weakness worth writing about.


Why does describing the process score so poorly?

Direct answer: Because description is the first half of the task, and markers in this subject read for the second half. A submission that walks through a cycle step by step has demonstrated comprehension. Marks separate when you turn each step into a question: what could go wrong here, how likely is it, what would it cost, and which control addresses it.

What the submission contains How it typically reads to a marker What lifts it
A narrative walk-through of the cycle Accurate, analytically silent Attach a specific risk to each step, not a general one
Narrative plus a list of generic controls Textbook recall Say which control addresses which risk, and why that one
Risks, matched controls, and a stated rationale Analytical Distinguish preventive from detective controls and say which the client needs here
All of the above, plus a limitation Genuinely critical Name what the control will not catch, and what would

Evidence: The subject's own middle section pairs computer crime and computer ethics with internal control, which is a deliberate ordering. Controls exist because of specific threats. A control listed without the threat it answers is an unattached fact, and unattached facts read as memorisation.

Example: Two students both recommended segregation of duties. The first stated it as a principle. The second said which two duties were currently combined in the case, named the specific fraud that combination permits, and added that a small firm may be unable to separate them, so a compensating control such as independent review of the payment run may be the realistic answer. The second student wrote three more sentences and moved up a band.


How do you write about internal control without sounding like a textbook?

Direct answer: By keeping the control tied to a consequence somebody can measure. The weakest submissions treat internal control as vocabulary to be reproduced. The strongest treat it as an argument about what a failure would cost.

Evidence: There is real research to draw on here, and it is more concrete than students expect. Studying auditor reports on internal control from 2014 to 2018, Mojtahedi and Zhou (2024) categorised information technology internal control material weaknesses and found the average number of weakness incidents per report rising from 2016 to 2018, with the categories themselves differing across industries. Haislip et al. (2015) looked at the consequences for individuals: executives dismissed from a firm reporting an IT-related material weakness were less likely to find an equivalent job than executives dismissed after a material weakness unrelated to IT, and the effect was strongest for the chief financial officer. Neither finding is decoration. Both let you say that control failure has a measurable cost, rather than asserting that controls matter.

Example: A submission arguing for stronger access controls closed by saying controls protect the integrity of financial information. That sentence is true of every control ever written. Replacing it with a reference to the documented rise in IT-related weakness reports, and to the career consequences that follow disclosure, converted a platitude into a claim with evidence behind it.


What is the software component really testing?

Direct answer: Not whether you can operate the package. It is testing whether you can see the control implications of what the package does automatically and what it leaves to a human.

Evidence: This is the subject's quiet link to the wider literature. Reviewing research on enterprise systems, Grabski et al. (2011) describe integrated systems as a transformative force on the accounting profession, and note that accounting expertise is increasingly called on to audit information systems and to implement management controls within them. They also observe that such systems support internal controls and audit trails to a greater extent than earlier departmental systems, while simultaneously enforcing business processes and restricting employee tasks. Both halves of that sentence are examinable. A system that enforces a process removes some risks and creates others, and the new risks tend to concentrate in who holds administrator rights.

Example: Asked to comment on a firm moving from spreadsheets to an integrated package, a weaker answer listed the benefits. A stronger one accepted the benefits, then pointed out that the audit trail is only as trustworthy as the access controls around it, and asked who in this small company would be able to edit configuration without review.


What does the e-business and data security focus expect?

Direct answer: It expects you to treat the boundary of the organisation as the risky part. Once transactions arrive from outside, controls that assumed an internal, trusted user stop being sufficient, and your answer should say so explicitly rather than importing internal-control language unchanged.

Evidence: The subject description names e-business and data security as a special focus alongside the transaction cycles, which signals that the cycles are expected to be discussed in a networked setting rather than an isolated one. In practical terms this means authentication, transmission integrity, and the question of what happens when a counterparty's system, not yours, is the one that fails.

Example: Discussing an online sales channel, one student applied the standard revenue-cycle controls and stopped. Another applied them, then noted that customer credit assessment cannot rely on the personal knowledge a counter salesperson would have had, and proposed what would replace it.


A practical order of work

There is no single correct method, but this sequence tends to keep students out of the description trap:

  1. Identify the cycle and its subsystem boundaries before writing anything. Know where the process starts and where it hands over.
  2. Map who does what. Most assignment weaknesses are visible in the allocation of duties alone.
  3. For each step, write the risk before you write the control. Reversing this order is what produces generic control lists.
  4. Classify each control as preventive, detective or corrective, and say why that mix suits this organisation's size.
  5. State one thing your recommendation will not fix. Markers read this as confidence, not weakness.
  6. Check your documentation conventions against your subject outline, not against an internet example, because notation standards differ between institutions.

Frequently asked questions

Do I need programming skills to pass ACC203?
No. The subject uses accounting software as a context for control questions, not as a development exercise. What you need is the discipline to ask, of every automated step, what it now guarantees and what it now assumes.

How much detail should a risk-and-control table contain?
Enough that each row is specific to the case in front of you. A row that could be copied into any assignment about any company is a row that earns little. Tie the risk to a named step and the control to a named person or system.

Is it acceptable to cite a textbook rather than journal articles?
Follow your subject outline. Textbooks are appropriate for definitions and frameworks, but a claim about how often control failures occur or what they cost is a claim about evidence, and it should be supported by a source that actually measured something.

My case study is a small business that cannot segregate duties. What do I write?
Say that directly, then propose compensating controls. Recognising a constraint and working within it demonstrates judgement, whereas recommending an impossible structure suggests you have not read the case.

Does this subject overlap with auditing?
It borders on it. Auditing asks whether controls operated effectively over a period; this subject asks whether the right controls exist and make sense for the process. Keeping that distinction visible in your writing helps, because it stops you drifting into audit procedures that were not asked for.


Where MAAS fits

MAAS mentors work alongside students on subjects like this rather than in place of them. A typical session on an AIS assignment involves reading the case together, testing whether the risks you have identified are specific enough to defend, and pressure-testing the control recommendations against the constraints in the scenario. The writing stays yours. What changes is that somebody who has read a few hundred of these tells you which paragraph a marker will stop at. If that is useful, our academic support service and our tutoring service are the two places to start.


References

Grabski, S. V., Leech, S. A., & Schmidt, P. J. (2011). A review of ERP research: A future agenda for accounting information systems. Journal of Information Systems, 25(1), 37–78. https://doi.org/10.2308/jis.2011.25.1.37

Haislip, J. Z., Masli, A., Richardson, V. J., & Watson, M. W. (2015). External reputational penalties for CEOs and CFOs following information technology material weaknesses. International Journal of Accounting Information Systems, 17, 1–15. https://doi.org/10.1016/j.accinf.2015.01.002

Mojtahedi, A., & Zhou, L. (2024). Information technology internal control material weaknesses in financial reporting: Categories, trends, associations, and industry effects. International Journal of Accounting Information Systems, 53, 100679. https://doi.org/10.1016/j.accinf.2024.100679

Tools & resources

King's Own Institute. (n.d.). ACC203 Accounting Information Systems subject description. https://koi.edu.au/subject_descriptions/acc203-accounting-information-systems/

Share this articleFacebookLinkedInZaloEmail
Want guidance like this?

From this article
to your dissertation.

A 15-minute discovery call: our PhD & Master experts translate this framework into your specific topic and supervisor expectations.