Chapter 9: Introduction to Internal Control Systems

Slides:



Advertisements
Similar presentations
Internal Control–Integrated Framework
Advertisements

Federal Audit Executive Council (FAEC) June 2012 Bi-Monthly Meeting Heather I. Keister Doris G. Yanger June 14, 2012 Green Book Update.
Chapter 10 Accounting Information Systems and Internal Controls
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
Control and Accounting Information Systems
Control and Accounting Information Systems
Internal Control.
The Islamic University of Gaza
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
Standar Pekerjaan Lapangan: Pemahaman Memadai atas Pengendalian Intern Pertemuan 5.
Internal Control. COSO’s Framework Committee of Sponsoring Organizations 1992 issued a white paper on internal control Since this time, this framework.
18- 1 © 2006 The McGraw-Hill Companies, Inc., All Rights Reserved. Chapter 18 Integrated Audits of Internal Control (For Public Companies Under Sarbanes-Oxley.
Internal Control. COSO’s Framework Committee of Sponsoring Organizations 1992 issued a white paper on internal control Since this time, this framework.
Section 404 Audits of Internal Control and Control Risk
Chapter 4 IDENTIFYING RISKS AND CONTROLS IN BUSINESS PROCESSES.
Sarbanes-Oxley Project Summary of COSO Framework Presented by Larry Dillehay & Scott Reitan Parkfield Group LLC.
INTERNAL CONTROL OVER FINANCIAL REPORTING
COSO Framework Update IIA Columbus Chapter May 17, 2013
Chapter 4 Internal Controls McGraw-Hill/Irwin
Internal Auditing and Outsourcing
Control and Accounting Information Systems
Chapter 8 Introduction to Internal Control Systems
ACCOUNTING INFORMATION SYSTEMS
Chapter 3 Internal Controls.
Chapter 07 Internal Control McGraw-Hill/IrwinCopyright © 2014 by The McGraw-Hill Companies, Inc. All rights reserved.
Introduction to Internal Control Systems
INTERNAL CONTROL OVER FINANCIAL REPORTING
Chapter 5 Internal Control over Financial Reporting
Considering Internal Control
Introduction In 1992, the Committee Of Sponsoring Organizations of the Treadway Commission (COSO) published Internal Control-Integrated Framework (1992.
Internal Control in a Financial Statement Audit
BusinessAllstars.com 1 BusinessAllstars.com Presents Copyright © 2004 by Gainbridge Associates All right reserved This material may not be used or reproduced.
NO FRAUD LEFT BEHIND The Effect of New Risk Assessment Auditing Standards on Schools Runyon Kersteen Ouellette.
9 - 1 ©2003 Prentice Hall Business Publishing, Essentials of Auditing 1/e, Arens/Elder/Beasley Internal Control and Control Risk Chapter 9.
©2003 Prentice Hall Business Publishing, Auditing and Assurance Services 9/e, Arens/Elder/Beasley Internal Control and Control Risk Chapter 10.
1 Chapter Three IT Risks and Controls. 2 The Risk Management Process Identify IT Risks Assess IT Risks Identify IT Controls Document IT Controls Monitor.
Learning Objectives LO5 Illustrate how business risk analysis is used to assess the risk of material misstatement at the financial statement level and.
Risk Management. IT Controls Risk management process Risk management process IT controls IT controls IT Governance Frameworks IT Governance Frameworks.
Evaluation of Internal Control System. Learning Objective 1 Contrast management’s need for internal control with the auditor’s need to consider internal.
Bank Audit. Internal Audit Internal audit is an independent, objective assurance activity and can give valuable insight in providing assurance that major.
Risk Management & Corporate Governance 1. What is Risk?  Risk arises from uncertainty; but all uncertainties do not carry risk.  Possibility of an unfavorable.
[Hayes, Dassen, Schilder and Wallage, Principles of Auditing An Introduction to ISAs, edition 2.1] © Pearson Education Limited 2007 Slide 7.1 Internal.
McGraw-Hill/Irwin © 2003 The McGraw-Hill Companies, Inc., All Rights Reserved. 6-1 Chapter 6 CHAPTER 6 INTERNAL CONTROL IN A FINANCIAL STATEMENT AUDIT.
Chapter 9: Introduction to Internal Control Systems
An Update of COSO’s Internal Control–Integrated Framework
A Guide for Management. Overview Benefits of entity-level controls Nature of entity-level controls Types of entity-level controls, control objectives,
Internal Control Systems
Internal Control Chapter 7. McGraw-Hill/Irwin © 2006 The McGraw-Hill Companies, Inc., All Rights Reserved. 7-2 Summary of Internal Control Definition.
©2012 Prentice Hall Business Publishing, Auditing 14/e, Arens/Elder/Beasley Section 404 Audits of Internal Control and Control Risk Chapter.
Copyright © 2007 Pearson Education Canada 9-1 Chapter 9: Internal Controls and Control Risk.
Deck 5 Accounting Information Systems Romney and Steinbart Linda Batch February 2012.
©©2012 Pearson Education, Auditing 14/e, Arens/Elder/Beasley Considering Internal Control Chapter 10.
Copyright © 2014 Pearson Education, Inc. Publishing as Prentice Hall. Chapter
Lecture 5 Control and AIS Copyright © 2012 Pearson Education 7-1.
Chapter 6 Internal Control in a Financial Statement Audit McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
©2005 Prentice Hall Business Publishing, Auditing and Assurance Services 10/e, Arens/Elder/Beasley Internal Control and Control Risk Chapter 10.
Auditors’ Dilemma – reporting requirements on Internal Financial Controls under the Companies Act 2013 and Clause 49 of the Listing agreement V. Venkataramanan.
Internal Control Chapter 7. McGraw-Hill/Irwin © 2008 The McGraw-Hill Companies, Inc., All Rights Reserved. 7-2 Summary of Internal Control Definition.
Risk Management Dr. Clive Vlieland-Boddy. Managements Responsibilities Strategy – Hopefully sustainable! Control – Hopefully maximising profits! Risk.
SUNY Maritime Internal Control Program. New York State Internal Control Act of 1987 Establish and maintain guidelines for a system of internal controls.
Modern Auditing: Assurance Services and the Integrity of Financial Reporting, 8th Edition William C. Boynton California Polytechnic State University at.
Errors, Fraud, Risk Management, and Internal Controls
Understanding the Principles and Their Effect on the Audit
PEM PAL IA COP Internal Control Working Group COSO Principles
COSO Internal Control s Framework
Internal control - the IA perspective
Internal Controls Policies and Procedures
An Update of COSO’s Internal Control–Integrated Framework
Internal Control Internal control is the process designed and affected by owners, management, and other personnel. It is implemented to address business.
An overview of Internal Controls Structure & Mechanism
Presentation transcript:

Chapter 9: Introduction to Internal Control Systems 1992 COSO Report Updates on Risk Assessment & 2013 Update Examples of Control Activities 2011 COBIT, Version 5 Types of Controls Evaluating Controls

Introduction – Fraud (Ch 11) & Errors Errors may be the result of many factors Distractions – Concurrent tasks, work environment, personal situations, Complexity – It’s easier to complete a simple task than a hard one. Limitations – Fatigue, cognitive limitations, etc. Errors

Internal Control Systems Definition Policies, plans, and procedures Implemented to protect a firms assets People Involved Board of directors Management Other key personnel

Internal Control Systems Provides reasonable assurance Effectiveness and efficiency of operations Reliability of financial reporting Protection of Assets Compliance with applicable laws and regulations Important Guidance Statement on Auditing Standard No. 94 Sarbanes-Oxley Act of 2002

Risk Control Strategies Avoidance- Policy, Training and Education, or Technology Transference – shifting the risk to other assets, processes, or organizations (insurance, outsourcing, etc.) Mitigation – reducing the impact through planning and preparation Acceptance – doing nothing if the cost of protection does not justify the expense of the control

Internal Control System Objectives Safeguard assets Check the accuracy and reliability of accounting data Promote operational efficiency Enforce prescribed managerial policies

Information System Goals – CIA Triangle Confidentiality Integrity Availability

CIA Triangle Confidentiality – Insuring that information is accessible only by those who are properly authorized Integrity – Insuring that data has not be modified without authorization Availability – Insuring that systems are operational when needed for use

Background Information on Internal Controls

Background Information on Internal Controls

Background Information on Internal Controls

1992 COSO Report Defines internal control and components Presents criteria to evaluate internal control systems Provides guidance for public reporting on internal controls Offers materials to evaluate an internal control system

Components of Internal Control – COSO 1992 Control Environment Management’s oversight , integrity, and ethical principles Attention and direction by board of directors Management’s philosophy and operating style Method of assigning authority and responsibility Method of organizing and developing employees

Components of Internal Control – COSO 1992 Risk Assessment Identify organizational risks Analyze potential of risks (cost and occurrence) Cost-benefit analysis Control Activities Policies and procedures Manual and automated

Components of Internal Control – COSO 1992 Information and Communication Inform employees Roles and responsibilities Importance of good working relationships Monitoring Evaluation of internal controls Initiate corrective action when necessary

2004 COSO Enterprise Risk Management Framework Emphasizes enterprise risk management Includes COSO (1992) control components Three new components Objective setting Event identification Risk response

2004 COSO Enterprise Risk Management Framework

Components of Internal Control – COSO 2004 Objective Setting Strategic – high level goals and mission Operations – day-to-day efficiency, performance, and profitability Reporting – internal and external Compliance – laws and regulations

Components of Internal Control – COSO 2004 Event Identification and Risk Response Identify threats Analyze risks Implement cost-effective countermeasures Additional considerations Risk tolerance Cost-benefit trade-offs

COSO 2013 Objectives Update Content - Reflect changes in business & operating environments Broaden Application - Expand operations and reporting objectives Clarify Requirements - Articulate principles to facilitate effective internal control

COSO 1992, 2004, 2013

Update considers changes in business and operating environments Environments changes... …have driven Framework updates Expectations for governance oversight Globalization of markets and operations Changes and greater complexity in business Demands and complexities in laws, rules, regulations, and standards Expectations for competencies and accountabilities Use of, and reliance on, evolving technologies Expectations relating to preventing and detecting fraud COSO Cube (2013 Edition)

Update articulates principles of effective internal control Control Environment Demonstrates commitment to integrity and ethical values Exercises oversight responsibility Establishes structure, authority and responsibility Demonstrates commitment to competence Enforces accountability Risk Assessment Specifies suitable objectives Identifies and analyzes risk Assesses fraud risk Identifies and analyzes significant change Control Activities Selects and develops control activities 11. Selects and develops general controls over technology Deploys through policies and procedures Information & Communication Uses relevant information Communicates internally Communicates externally Monitoring Activities Conducts ongoing and/or separate evaluations Evaluates and communicates deficiencies

Update describes important characteristics of principles, e.g., Control Environment The organization demonstrates a commitment to integrity and ethical values. Points of Focus: Sets the Tone at the Top Establishes Standards of Conduct Evaluates Adherence to Standards of Conduct Addresses Deviations in a Timely Manner Points of focus may not be suitable or relevant, and others may be identified Points of focus may facilitate designing, implementing, and conducting internal control There is no requirement to separately assess whether points of focus are in place

Risk Assessment Worksheet

Study Break #4 Which of the following is not one of the three additional components that was added in the 2004 COSO Report? Objective setting Risk assessment Event identification Risk response

Examples of Control Activities Good Audit Trail Sound Personnel Policies and Practices Separation of Duties Physical Protection of Assets Reviews of Operating Performance

Good Audit Trail Use of Audit Trail Purpose of Audit Trail Follow path of data recorded in transaction Initial source documents to final disposition of data Data on reports back to source documents Purpose of Audit Trail Verify accuracy of recorded transactions Detect errors and irregularities

Sound Personnel Policies Retain as is (except for bold) - Prathima

Separation of Duties Purpose Separate Related Activities Structure of work assignments One employee’s work checks the work of another Separate Related Activities Authorizing transactions Recording transactions Maintaining custody of assets

Physical Protection of Assets Inventory Controls Stored in safe location with limited access Utilization of Receiving Report Document Controls Protecting valuable organizational documents Corporate charter, major contracts, blank checks, and SEC registration statements

Physical Protection of Assets Cash Control Most susceptible to theft and human error Fidelity bond coverage Use checks for cash disbursements Deposit the daily cash receipts intact

Reviews of Operating Performance Internal Audit Function Reports to Audit Committee of Board of Directors Independent of other subsystems Enhances objectivity Duties of Internal Auditors Operational audits Regular reviews of internal control systems

Study Break #5 Separation of duties is an important control activity. If possible, managers should assign which of the following three functions to different employees? Analysis, authorizing, transactions Custody, monitoring, detecting Recording, authorizing, custody Analysis, recording, transactions

2011 COBIT, Version 5 Control Objectives for Information and related Technology (COBIT) Strategic alignment Realization of expected benefits of IT Continual assessment of IT investment Determine risk appetite Measure and assess performance of IT resources

COBIT and Val IT Integration

Types of Controls Preventive Controls Detective Controls Prevent problems from occurring Detective Controls Alert managers when preventive controls fail Corrective controls Solve or correct a problem

Evaluating Controls Requirements of Sarbanes-Oxley Act Statement of management responsibility for internal control structure Assessment of effectiveness of internal control structure Attestation of auditor on accuracy of management’s assessment

Cost-Benefit Analysis

Risk assessments are tricky Choose between two treatments for 600 people affected by a deadly disease "Saves 200 lives“

Risk assessments are tricky Choose between two treatments for 600 people affected by a deadly disease "400 people will die"

A Risk Matrix

Chapter 9

The Risk Management Process Identify IT Assets Assess IT Risks Identify IT Controls Document IT Controls monitor

Risk Management – Asset Identification Processes People Hardware Software Cash Inventory Data Facilities

Assets Valuation - What do we stand to lose? Assets: People, Data, Hardware, Software, Facilities, (Procedures) Valuation Methods Criticality to the organization’s success Revenue generated Profitability Cost to replace Cost to protect Embarrassment/Liability