Internal Auditing and Outsourcing

Slides:



Advertisements
Similar presentations
PRESENTATION ON MONDAY 7 TH AUGUST, 2006 BY SUDHIR VARMA FCA; CIA(USA) FOR THE INSTITUTE OF INTERNAL AUDITORS – INDIA, DELHI CHAPTER.
Advertisements

Auditing, Assurance and Governance in Local Government
©2010 Prentice Hall Business Publishing, Auditing 13/e, Arens/Elder/Beasley The CPA Profession Chapter 2.
The Audit Standards’ Setting Process
It’s Time to Talk About Risk and Control
Sodexo.com Group Internal Audit. page 2 helps an organization accomplish its objectives by bringing a systematic, disciplined approach to evaluate and.
QUALITY ASSURANCE AND IMPROVEMENT PROGRAM (QAIP)
Welcome! Internal Auditing CHAPTER 1. Definition Internal auditing is an independent, objective, assurance and consulting activity designed to add value.
Assurance, Attestation, and Internal Auditing Services
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
Standar Pekerjaan Lapangan: Pemahaman Memadai atas Pengendalian Intern Pertemuan 5.
9.401 Auditing Chapter 1 Introduction. Definition of Auditing The accumulation and evaluation The accumulation and evaluation Of evidence about information.
IS Audit Function Knowledge
1 Pertemuan 9 Department Organization Matakuliah:A0274/Pengelolaan Fungsi Audit Sistem Informasi Tahun: 2005 Versi: 1/1.
Quality evaluation and improvement for Internal Audit
Internal Audits, Governmental Audits, and Fraud Examinations
Implementing and Auditing Ethics Programs
The CPA Profession Chapter 2.
Purpose of the Standards
ISA 220 – Quality Control for Audits of Historical Financial Information
Auditing Standards IFTA\IRP Audit Guidance Government Auditing Standards (GAO) Generally Accepted Auditing Standards (GAAS) International Standards on.
Compliance & Internal Auditing By David N. Ricchiute
Central Piedmont Community College Internal Audit.
D-1 McGraw-Hill/Irwin ©2005 by the McGraw-Hill Companies, Inc. All rights reserved. Module D Internal, Governmental, and Fraud Audits “I predict that audit.
C. P. Mansoor S. Ahmed M. Com, PGDBA.  Not confined to Independent Audit  Systematic Examination of  Records  Procedures  Systems  Operations.
The Institute of Internal Auditors
Importance of Auditing
Improving Corporate Governance in Malaysian Capital Markets – The Role of the Audit Committee Role of the Audit Committee in Assessing Audit Quality.
Session 3 & 4. Institute of Internal Auditors Inc (IIA) was created for internal auditors in 1941 Generally accepted criteria of a profession are: –Adopting.
The CPA Profession Chapter 2 By Arens et. al. Learning Objective 1 Describe the nature of CPA firms, what they do, and their structure.
Chapter 5 Internal Control over Financial Reporting
Internal Control in a Financial Statement Audit
© 2013 Cengage Learning. All Rights Reserved. 1 Part Four: Implementing Business Ethics in a Global Economy Chapter 9: Managing and Controlling Ethics.
Chapter 1 Assurance Services. Need for Assurance Why do you need assurance? Potential bias in providing information. Remoteness between a user and the.
©2006 Prentice Hall Business Publishing, Auditing 11/e, Arens/Beasley/Elder Internal and Governmental Financial Auditing and Operational Auditing.
©2010 Prentice Hall Business Publishing, Auditing 13/e, Arens/Elder/Beasley Internal and Governmental Financial Auditing and Operational Auditing.
Implementing and Auditing Ethics Programs
Practice Management Quality Control
Copyright © 2007 Pearson Education Canada 1 Chapter 1: The Demand for Auditing and Assurance Services.
Audit Committee Roles & Responsibilities Audit Committee July 20, 2004.
Chapter 21 Internal, Operational, and Compliance Auditing McGraw-Hill/IrwinCopyright © 2014 by The McGraw-Hill Companies, Inc. All rights reserved.
1 Internal Audit. 2 Definition Is an independent activity established by management to examine and evaluate the organization’s risk management processes.
The UNIVERSITY of GREENWICH 1 October 2009 L8a Audit and assurance J. E. Spencer-Wood Auditing and assurance Lecture 8a Internal audit.
Copyright © 2013 by The McGraw-Hill Companies, Inc. All rights reserved.McGraw-Hill/Irwin.
Copyright © 2007 Pearson Education Canada 7-1 Chapter 7: Audit Planning and Documentation.
Chapter 3 Governance.
International Security Management Standards. BS ISO/IEC 17799:2005 BS ISO/IEC 27001:2005 First edition – ISO/IEC 17799:2000 Second edition ISO/IEC 17799:2005.
Chapter 17 Internal and Value-Added Auditing. Internal Auditing DEFINED Internal auditing is an independent and objective assurance and consulting activity.
Internal/External Audit Corporate Governance part 5.
Copyright: Internal Auditing: Assurance and Consulting Services, by The Institute of Internal Auditors Research Foundation, 247 Maitland Avenue, Altamonte.
Copyright © 2007 Pearson Education Canada 9-1 Chapter 9: Internal Controls and Control Risk.
An Overview THE AUDIT PROCESS. MAJOR PHASES IN AN AUDIT Client acceptance and retention Establish terms of the engagement Plan the audit Consider internal.
Copyright © 2015 McGraw-Hill Education. All rights reserved. No reproduction or distribution without the prior written consent of McGraw-Hill Education.
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin 20-1 Chapter Twenty Assurance, Related Services and Internal.
F8: Audit and Assurance. 2 Audit and Assurance Designed to give you knowledge and application of: Section A: Audit Framework and Regulation Section B:
Lecture 5 Control and AIS Copyright © 2012 Pearson Education 7-1.
Internal Audit Quality Assessment Guide
The CPA Profession Chapter 2.
Assurance, Related Services and Internal Auditing
Internal and Governmental Financial Auditing and Operational Auditing
Modern Auditing: Assurance Services and the Integrity of Financial Reporting, 8th Edition William C. Boynton California Polytechnic State University at.
A Framework for Control
Following Up on Internal Audit Reports Workshop on IIA Standard 2500
The CPA Profession Chapter 2.
Adding Value Across the Board
Modern Auditing: Assurance Services and the Integrity of Financial Reporting, 8th Edition William C. Boynton California Polytechnic State University at.
Taking the STANDARDS Seriously
Internal Audit Who? What? When? How? Why? In brief . . .
Presentation transcript:

Internal Auditing and Outsourcing Chapter 18 Internal Auditing and Outsourcing

Define Internal Auditing Internal auditing is an independent and objective assurance and consulting activity that is designed to add value to improve an organization's operations. It helps an organization accomplish its objectives by bringing a systematic, discipline approach to evaluate and improve the effectiveness of risk management, control, and governance processes.

Discuss Internal Auditing Exists only because it adds value to the organization Must change as organizations change Proves objective assurance to top management and the board Reports problems, and also offers advice on needed improvements Encompasses all the important operations of an organization

Assurance & Consulting Activity Assurance services - objective services that improve the Quality of information about processes Effectiveness of controls Reliability of information Compliance with company, regulatory, or governmental procedures Effectiveness and efficiency of operations Consulting services: Advisory or partnering activities that add value and improve operations Both parties must agree on nature and scope of services Identifies problems and potential solutions Advisory; does not include decision making

Discuss Assurance & Consulting Activity Systematic and Disciplined Approach Internal auditing standards are designed to ensure objective, relevant, and sufficient evidence is gathered and evaluated Internal auditors identify risks, gather evidence, evaluate findings, and suggest improvements Elements of the systematic and disciplined approach: Defined audit objectives Risk analysis Audit work plan Defined audit procedures Use of technology Independent review of audit work Review of conclusions with management

Assurance & Consulting Activity (Continued) Corporate Governance, Risk Management, and Control Good governance requires organizations implement processes and controls designed to ensure Decisions are made at the appropriate level of the organization Processes comply with organization policies and government regulations Processes are efficient and effective Risks are identified and factored into decisions Controls are properly designed and implemented Effective whistle-blowing function is implemented

Review Internal Auditing & Corporate Governance Internal auditors should: Understand key governance issues, stakeholders, and accountability to those stakeholders Provide analysis to determine that top management understands risks and have processes in place to address such risks Ensure the organization has controls to address such risks, and that such controls are operating effectively Evaluate organization's processes for determining operating efficiency Determine that operations comply with organization policies as well as contracts, laws, and regulations Determine that an effective whistle-blowing function is in place

What is the internal audit charter? Statement of the internal audit's role in an organization, the charter accomplishes two important objectives: Defines the scope of the internal audit activity including access to company records Defines the reporting relationships that exist between the audit activity and others within the organization such as audit committee members, senior management, and operating management Important issues that should be noted in the charter: Statement of the mission of the activity defined in terms of governance, risk, control, and operating efficiency Identification of audit accountabilities Defined responsibility to provide periodic reports Prohibition against performing operational tasks Identification of standards by which to judge performance of internal audit work

Review Internal Auditing & the Audit Committee Internal auditors assist the audit committee in a number of ways: Review the quality of internal controls over financial reporting Provide an independent viewpoint on major accounting issues Provide feedback on the efficiency of operations and compliance with company and regulatory policies Facilitate information flow to the audit committee Perform special projects or investigations as requested

Review Internal Auditing & the Audit Committee Monitor effectiveness of whistle-blowing activities Evaluate whether the company has met its reporting objectives Assess the "quality" of financial reporting Evaluate the effectiveness of risk management processes Provide independent assessments of risk Provide information to facilitate monitoring of key risks

Discuss Internal Audit Outsourcing Recent trend for companies to outsource their internal audit function to public accounting or other specialize firms This trend may slow as the SEC prohibits a CPA from providing both internal and external audit services for the same company Possible advantages of outsourcing internal audit function. Service provider may: Have greater expertise or specialized talents Be able to provide service at lower cost Have global presence and be able to provide service without language or cultural problems Provide greater flexibility in staffing and budgeting Possible disadvantages of outsourcing internal audit function: Employees may have greater knowledge of the company and its operations Loss of internal audit as a training ground to develop new managers

What is value added internal auditing? Internal audit activities can be classified as: Risk analysis Organizations take risks to accomplish their objectives Organizations need processes to recognize risk and institute controls to minimize adverse outcomes Risk analysis examines whether processes are adequate to manage risks Information reliability Organizations need accurate, reliable, and timely information Information must also be protected Internal auditors perform periodic reviews of security and controls

What is value added internal auditing? (Continued) Control effectiveness Controls exist to address risks Internal auditors provide objective assessment as to whether Controls are adequate to manage risk Controls are operating effectively Operational effectiveness and efficiency Conformance with company policies and procedures Fraud investigations

What are operational audits? Evaluate organization's activities, systems, and controls Assess quality and efficiency of performance Identify opportunities and develop recommendations for improvement Criteria for evaluation of performance Past operations Best practices for similar operations Stated management objectives

Further Discussion of Operational Audits Every operational audit follows the same ten step process: Understanding the operational area and management's interest in having the area audited Develop background information about the audit area Develop objective criteria regarding operational efficiency Perform preliminary analysis of the audit area Perform detailed risk analysis Develop and analyze data that might indicate problems Perform inquiry and testing to identify source of problems Performed detailed tests of operating activities and controls Summarize findings - prepare report and discuss with management Develop mechanism to follow-up on recommendations

More Operational Audits Detailed considerations: Establish criteria Objective criteria should be established prior to the audit Criteria should include both performance and control measures Perform preliminary risk analysis for all operational audit areas To determine whether organization has effective risk management process To identify important controls Perform analytical analysis To identify existence and source of potential operating problems Test controls and operations Every operational audit will have compliance testing component To determine whether operations follow company policies and meet company standards

Discuss Compliance Audits Performed to determine whether operations are being conducted in compliance with contracts, management's policies, or applicable laws and regulations Add value because they can Improve operational efficiency Provide assurance that organization is operating within applicable laws and regulations

Internal Auditing and Sarbanes-Oxley Internal auditors are an integral part of assisting organizations to implement provisions of the Sarbanes-Oxley Act Internal audit may assist in facilitating a control self-assessment by management assisting operating personnel understand controls and documentation

Review Internal Audit Standards Standards for the Professional Practice of Internal Auditing (IIA): Attribute Standards Purpose, Authority, and Responsibility Independence and Objectivity Proficiency and Due Professional Care Quality Assurance and Improvement Program Performance Standards Managing the Internal Audit Activity Nature of Work

Review Internal Audit Standards (Continued) Performance Standards Engagement Planning Performing the Engagement Communicating Results Monitoring Progress Management's Acceptance of Risks Implementation Standards There may be multiple implementation standards derived from the concepts in the attribute and performance standards

What is the IIA Code of Ethics? Focuses on broad-based Principles and Rules of Conduct regarding: Integrity Objectivity Confidentiality Competence

Comment on Reporting Fraud The IIA's Code of Ethics makes it clear that an internal auditor should "Observe the law and make disclosures expected by the law and the profession" "Not knowingly be a party to any illegal activity, nor engage in acts that are discreditable to the profession of internal auditing or to the organization"

Comment on Reporting Fraud If an internal auditor uncovers evidence of fraud, the auditor should: Document the findings and include them in an audit report Report findings to the board of directors, the audit committee, and appropriate members of top management Consult with an attorney on actions appropriate to the particular case Consider the need for any additional action to disassociate from the fraud