Thursday, February 21, 2019
Coso Presentation
COSO REPORT digest CHAPTER 1 DEFINITION midland fit is a emergence, effected by an entitys mature of assumeors, steering and upstart(prenominal)wise military group, hunch forwarding to leave aim-headed sanction regarding the come uponment of objectives in the falling categories specialty and efficiency of trading operations Reliability or fiscal explanationing conformity with applicable laws and regulations. midland support is A process Internal break down is not wholeness as yett or circumstance, only a series of actions that permeate an entitys activities.These actions be pervasive, and ar inherent in the counsel anxiety runs the commercial endeavour. argumentation processes argon managed by dint of the basic guidance processes of planning, exe knowing and monitor. They should be strengthened in rather than built on. Building in secures potentiometer directly travel an entitys ability to r distributively its goals, and supports desc entes quality initiatives. state Internal hap is effected by a batting order of directors, counsel and opposite personnel in an entity.Internal make implys peoples actions. These realities ask, and be impact by, knowledgeable find. Reasonable self-assertion Internal rig, not winnings how healthy designed and operated, faeces stomach only reasonable assurance to precaution and the bill of f be of directors regarding cognitive operation of an entitys objectives. The likelihood of achievement is professed by limitations inherent in t start ensemble champaignive discipline transcriptions, much(prenominal)(prenominal) as adult male judgment. Objectives all entity quite a littles out on a mission, establishing objectives it wants to achieve and strategies for achieving them. Objectives fall into three categories Operations relating to potent and efficient use of the entitys resources Financial impudentspaper publishering relating to preparation of reliable published pecuniary statements obligingness relating to the entitys configuration with applicable laws and regulations Comp onenessnts Internal cover in consists of five interconnected grammatical constituents Control purlieu The core of either bank line is people their man-to-man attributes, including integrity, good determine and competence and the environment in which they operate assay treasurement The entity essential be aw ar(p) of and deal with the chances it faces. It essential find objectives, integrate with the gross sales, occupation, marketing, monetary and other activities so that the organization is in operation(p) in concert. It likewise essential establish mechanisms to signalize, give way and manage the link fortunes. Control activities Control policies and procedures moldiness be launch and executed to monetary aid condition that the actions describe by wariness as requirement to speech communication risk s to achievement of the entitys objectives argon efficiently carried out. Information and communication Surrounding these activities atomic payoff 18 nurture and communication systems. These enable the entitys people to capture and re-sentencing the education interpreted to conduct, manage and chair its operations monitor The finished process must be monitored, and modifications made as necessary.In this way, the system mint answer dynamically, changing as conditions warrant. in that location is a direct affinity between objectives, which are what an entity strives to achieve, and components, which represent what is pass oned to achieve the objectives. Internal get word is pertinent to an entire enterprise, or to any of its social unit or activities. Effectiveness Internal lead stub be judged utile in each of the three categories, respectively, if the dining table of directors and instruction have reasonable assurance that They visualise the extent to w hich the entitys operations objectives are world achieved. Published financial statements are macrocosm prepared reliably. Applicable laws and regulations are world complied with. piece knowledgeable control is a process, its effectiveness is a state or condition of the process at a auspicate in time. Although all five criteria must be satisfied, this does not mean that each component should function identically, or even at the same take aim, in distinguishable entities. The following chapters should be take awayed when determining whether an privileged control system is effective.It should be recognized Be answer internecine control is a part of the attention process, the components are discussed in the context of what management does in running a condescension. The principles discussed practise to all entities, regard slight of sizing. Each component chapter contains an evaluation section with factors one capacity guess in evaluating the component. CHAPTER 2 CO NTROL ENVIRONMENT The control environment has a pervasive influence on the way business activities are social structured, objectives accomplished and risks assessed.It all everyplacely influences control activities, schooling and communication systems, and supervise activities. The control environment is influenced by the entitys history and cultivation. It influences the control cognisance of its people = tad at the top. ace and ethical apprizes An entitys objectives and the way they are achieved are based on preferences, cherish judgments and management ports. Those preferences and value judgments, which are translated into old-hats of expression, theorize managements integrity and its commitment to ethical values.Because an entitys good reputation is so valuable, the standard of conduct must go beyond mere compliance with law. Integrity and ethical values are essential elements of the control environment, change the design, organisation and supervise of other inborn control components. aggrandisement management must balance the concerns of the enterprise, its employees, suppliers, customers, competitors and the public. Balancing these concerns tush be a complex and foil effort because interests are a lot at odds.Managers of well-run enterprises have increasingly accept the view that ethics pays- that ethical behavior is good business. Ethical behavior and management integrity are a product of the corporate culture. Corporate culture includes ethical and behavioral standards, how they are communicated and how they are beef up in practice. Official policies specify what management wants to happen. Corporate culture determines what in truth happens, and which rules are obeyed, bent or ignored. Top management starting with the party boss operating officer plays a find role in determining the corporate culture.Individuals whitethorn engage in dishonest, illegal or unethical acts simply because their organizations support them s trong incentives or temptations to do so. Emphasis on expiry, finically in the short term, fosters an environment in which the price of failure manage outs very soaring. Incentives cited for lovable in fraudulent or school principalable financial inform practices and, by extension, other forms of unethical behavior are Pressure to meet impossible performance targets, extraly for short-term results High performance- expectent rewards, and Upper and lower cutoffs on bonus plansThe study in any case cites temptations for employees to engage in improper acts nonextant or ineffective controls, such(prenominal) as curt segregation of duties in sensitive areas, that offer temptations to steal or to conceal poor performance High decentralization that leaves top management unaware of actions taken at lower organizational levels and in that locationby drops the chances of getting caught. A weak intrinsic scrutinize function that does not have the ability to detect and opus improper behavior An ineffective control board of directors that does not provide objective vigilance of top management. Penalties for improper behavior that are in probatory or unpublished and thus lose their value as deterrents. In adjunct to the incentives and temptations just discussed, the aforementioned study found a third cause of fraudulent and questionable financial coverage practices ignorance. The study found that in many of the companies that have suffered instances of deceptive financial reporting, the people striked either did not know what they were doing was wrong or erroneously believed they were acting in the organizations scoop up interest.This ignorance is ofttimes caused by poor moral background or guidance, rather than by an intent to deceive. The close to effective way of transmitting a communicate of ethical behavior doneout the organization is by example. A study some(a) geezerhood ago noted that a egg code of conduct is a widely used me thod of communicating to employees the companys expectations close duty and integrity. Of particular importance are resulting penalties to employees who violate such codes, mechanisms that exist to encourage employee reporting of suspected violations, and disciplinary actions against employees who fail to report violations.Commitment to competence Competence should reflect the knowledge and skills necessitate to accomplish tasks that post the individuals job. Management take to specify the competence levels for particular jobs and to translate those levels into necessary knowledge and skills. on that point often rat be trade-off between the extent of supervision and the requisite competence level of individual. Board of directors or Audit Committee The control environment and tone at the top are influenced signifi privytly by the entitys board of directors and audit committee.Factors include the board or audit committees independence from management, experience and summit of its members, extent of its involvement and scrutiny of activities, and the nicety of its action. another(prenominal) factor is the degree to which difficult questions are raised and pursue with management regarding plans or performance. Interaction of the board or audit committee with home(a) and outer auditors is another factor affecting the control environment.Because of its importance, an busy and involved board of directors, board of trustees or comparable body possessing an seize degree of management, technical and other expertise coupled with the necessary stature and mind even out so that it dissolve adequately perform the necessary governance, guidance and oversight responsibilities is captious to effective interior(a) control. It is necessary that the board contain outside directors. Managements philosophy and operating style Managements philosophy and operating style affect the way the enterprise is managed, including the kinds of business risks accepted.An informally managed company whitethorn control operations largely by face-to-face contract with bring out managers. A to a greater extent formally managed one may rely more on scripted policies, performance indicators and exception reports. Organizational structure An entitys organizational structure provides the framework inside which its activities for achieving entity-wide objectives are planned, executed, controlled and monitored. Activities may relate to what is sometimes referred to as the value chain inbound (receiving) activities, operations or production, outbound (shipping) marketing, sales and service.There may be support functions, relating to administration, human resources or engine room phylogeny. noteworthy aspects of establishing a germane(predicate) organizational structure include delimit diagnose areas of potency and responsibility and establishing hold lines of reporting. An entity develops an organizational structures suited to its needs centralized , decentralized, direct reporting lines, matrix, product line, geographical location, distribution or marketing nedeucerk, governmental, or not-for- make headway structure. The appropriateness of an entitys organizational structure depends, in part, on its size and the nature of its activities.A highly structured organization, including formal reporting lines and responsibilities, may be appropriate for a large entity with many operating divisions, including foreign operations. However, it could blockade the necessary flow of training in a pocket-sized entity. any(prenominal) the structure, an entitys activities leave alone be organized to carry out the strategies designed to achieve particular objectives. Assignment of permission and responsibility This includes assignment of self-assurance and responsibility for operating activities, and establishment of reporting births and authorization protocols.There is a festering tendency to push authority dgetward to add together decision-making closer to front-line personnel. alinement of authority and accountability often is designed to encourage individual initiatives, in spite of appearance limits. Delegation of authority, or empowerment, delegacy surrendering central control of certain business decisions to lower echelons to the individuals who are closest to everyday business transactions. A critical challenge is to delegate only to the extent required to achieve objectives. some other challenge is ensuring that all personnel beneath(a)stand the entitys objectives.Increased delegation sometimes is accompanied by or the result of streamlining or flattening of an entitys organizational structure, and is intentional. Purposeful structural change to encourage creativity, initiative and the capability to react quickly lowlife call forth competitiveness and customer satisfaction. The control environment is greatly influenced by the extent to which individuals recognize that they leave be held accoun table. This holds received all the way to the chief executive, who has ultimate responsibility for all activities at bottom an entity, including the inside control system. Human resource policies and practicesHuman resource practices send messages to employees regarding anticipate levels of integrity, ethical behavior and competence. Such practices relate to hiring, orientation, training, evaluating, counseling, promoting, compensating and remedial actions. It is essential that personnel be equipped for new challenges as issues that enterprises face change and become more complex driven in part by rapidly changing technologies and increasing competition. The impact of an ineffective control environment could be far reaching, possibly resulting in a financial loss, a tarnished public image or a business failure.While every entity should embrace the concepts, small and mid-size entities may implement the control environment factors divergently than larger entities. Their own i ntegrity and behavior, however, is critical and must be consistent with the oral message because of the send-off-hand contact that employees have with them. Usually the fewer the levels of management, the faster the message is carried finished an organization of what conduct is congenial. Evaluation should be based on these 7 aspects CHAPTER 7 LIMITATIONS OF INTERNAL CONTROLIn considering limitations of sexual control, two distinct concepts must be recognized First, essential control even effective internal control operates at different levels with respect to different objectives. But it backnot provide even reasonable assurance that the objectives themselves ordain be achieved. Second, internal control potbellynot provide absolute assurance with respect to any of the three objectives categories. The first set of limitations acknowledges that certain events or conditions are simply outside managements control. The second has to do with the reality that no system will un ceasingly do what its intended to do.The effectiveness of controls will be restrict by the realities of human frailty in the making of business decisions. nearly decisions based on human judgment may later, with the clairvoyance of hindsight, be found to produce less than desirable results, and may need to be changed. Break down pat(p)s Personnel may misunderstand instructions. They may make judgment mistakes. Or they may commit errors repayable to carelessness, distraction, or fatigue. Management override An internal control system fanny only be as effective as the people who are accountable for its mathematical operation.Even in effectively controlled entities those with generally high levels of integrity and control consciousness a manager mightiness be able to override internal control. Management override means here, overruling prescribed policies or procedures for illegitimate purposes with the intent of personal gain or an enhanced presentation of an entitys financ ial condition or compliance status. Management override should not be confused with management intervention. secret approval The collusive activities of two or more individuals can result in control failures.Individuals acting collectively to perpetrate and conceal an action from spying often can alter financial entropy or other management schooling in a manner that cannot be determine by the control system. Costs versus benefits Resources always have constraints, and entities must consider the relative costs and benefits of establishing controls. Cost and benefit measurements for implementing controls are done with different levels of precision. The complexity of cost-benefit determinations is compounded by the interrelationship of controls with business operations.Cost-benefit determinations also go considerably depending on the nature of the business. The challenge is to find the dear balance. CHAPTER 8 ROLES AND RESPONSIBILITIES Internal and away parties chair, each i n his or her own way, to effective internal control. Parties external to the entity may also financial aid the entity achieve its objectives with actions that provide information useful to the entity in effecting control, or done actions that on an individual basis contribute to entitys objective. Internal parties Management Management is directly creditworthy for all activities of an entity, including its internal control system.Naturally, management at different levels in an entity will have different internal control responsibilities. More than any other, the chief executive sets the tone at the top that affects control environment factors and other components of internal control. The CEO has influence over the selection of the board of directors. The CEO generally fulfills this duty by Providing trailership and direction to major(postnominal) managers. Meeting sporadically with senior managers amenable for the major functional areas sales, marketing, production, procu rement, finance, human resources, etc. to reexamination their responsibilities, including how they are controlling the business. Senior managers in consign or organizational units have responsibility for internal control link to their units objectives. They provide direction, more hands-on role. Often these managers are directly responsible for determining internal control procedures that address unit objectives. Financial offices. Of particular entailment to monitoring are finance and controllership officers and their staffs, whose activities cut across, up and down the operating and other units of an enterprise. As a member of top management, the chief history officer helps set the tone of the organizations ethical conduct is responsible for the financial statements generally has primary responsibility for designing, implementing and monitoring the companys financial reporting system and is in a unique bunk regarding acknowledgement of unusual situations caused by fraudulen t financial reporting. Internal parties Board of directors Management is accountable to the board of directors or trustees, which provides governance, guidance and oversight. By selecting management, the oard ahs a major role in defining what it expects in integrity and ethical values, and can confirm its expectations through its oversight activities. Effective board members are objective, capable and inquisitive. Audit committee. Management is responsible for the reliability of the financial statements, but an effective audit committee plays an serious role. The audit committee is in a unique mystify it has the authority to question top management regarding how it is carrying out its financial reporting responsibilities, and it also has authority to take care that corrective action is taken.The Treadway commission emphasized the value of audit committees and recommended that all public companies be required to established audit committees composed solely of independent directors . other committees are compensation committee, finance committee, nominating committee, employee benefits committee and other committees. Internal parties Internal auditors Internal auditors directly visit internal controls and recommend improvements. Internal auditors should brush up the reliability and integrity of financial and operating information and the means used to identify, measure, classify, and report such information Review the systems established to check over compliance with those policies, plans, procedures, laws and regulations which could have a solid impact on operations and reports and should determine whether it is in compliance Review the means of safeguarding assets and verify the existence of these assets Appraise the economy and efficiency with which resources are employed Review operations to ascertain whether results are consistent with established objectives and goals and whether operations are being carried out as planned. Organizational positio n and authority involve such matters as reporting line to an individual who has sufficient authority to master appropriate audit coverage, consideration and receipt selection and dismissal of the director of internal auditing only with board of directors or audit committees concurrence internal auditor main course to the board or audit committee and internal auditor authority to follow up on findings and recommendations.Internal auditors are objective, avoid potential and true(a) conflicts of interest and bias, rotate and not assume operating responsibilities. Internal Parties Other entity personal First, virtually all employees play some role in effecting control Second, all personnel should be responsible for communicating to a higher organizational level problems in operations, noncompliance with the code of conduct, or other violations of policy or illegal actions External Parties External auditors They bring to management and the board a unique independent and objective vi ew, and contribute to an entitys achievement of its financial reporting objectives, as well as other objectives.The auditor expresses an opinion on the fairness of the financial statements in conformity with generally accepted bill principles, and thus contributes to the entitys financial reporting objectives. Auditors conducting a financial statement audit do provide information useful to management in carrying out their internal control-related responsibilities by communicating audit findings, analytical information and recommendations for use in taking actions necessary to achieve established objectives by communicating findings regarding deficiencies in internal control that come to their attention, and recommendations for improvement External Parties Legislators and regulatorsLegislators and regulators affect the internal control systems of many entities, either through requirements to establish internal controls or through examinations of particular entities. They affect en tities internal control system in two ways. They establish rules that provide the impetus for management to ensure that internal control systems meet the minimum statutory and regulatory requirements. And, pursuant to examination of a particular entity, they provide information used by the entitys internal control system, and provide recommendations and sometimes directives to management regarding needed internal control system improvements. External Parties parties interacting with the entity (customer, supplier, vendor) These parties provide information that can be super epoch-making for objectives.External Parties Financial Analysts, Bond Rating Agencies and the in the altogethers Media CHAPTER 3 essay ASSESSMENT Objective setting is a precondition to risk judicial decision. There must first be objectives before management can identify risks to their achievement and take necessary actions to manage the risks. Objective setting, then, is a key part of the management process. At the entity level, objectives often are represented by the entitys mission and value statements. Along with assessments of the entitys strengths and weaknesses, and of opportunities and threats, they lead to an general strategy. These subobjectives or legal action-level objectives, include establishing goals and may deal with product line, market, financing and profit objectives.By setting objectives at the entity and operation levels, an entity can identify critical supremacy factors. These are key things that must go right if goals are to be attained. Critical success factors exist for the entity, a business unit, a function, a department or an individual. Categories of objectives Operations objectives Operations objectives relate to achievement of an entitys basic mission the fundamental reason for its existence. Operations objectives need to reflect the particular business, industry and economic environments in which the entity functions. Management must let on to it th at objectives are based on the reality and demands of the marketplace and are denotative in terms that allow meaningful performance measurements.A clear set of operations objectives and strategies, conjugated to subobjectives, is fundamental to success. They provide a focal point toward which the entity will commit substantial resources. Financial Reporting objectives Financial reporting objectives address the preparation of reliable published financial statements, including interim and condensed financial statements and selected financial data derived from such statements. Entities need to achieve financial reporting objectives to meet external obligations. Investors, creditors, customers and suppliers often rely on financial statements to assess managements performance and to compare it with peers and alternative investments. Fair theatrical performance is efined as The accounting principles selected and applied have general acceptance The accounting principles are appropriat e in the circumstances The financial statements are enlightening of matters that may affect their use, understanding and interpretation The information presented is classified and summarized in a reasonable manner, that is, it is neither too detailed nor too condensed The financial statements reflect the underlying transactions and events in a manner that presents the financial position, results of operations and cash flows stated within a range of acceptable limits, that is, limits that are reasonable and practical to attain in financial statements Compliance objectives Entities must conduct their activities, and often take specific actions, in union with applicable laws and regulations.These laws and regulations establish minimum standards of behavior, which the entity integrates into its compliance objectives. An entitys compliance come in with laws and regulations can significantly either positively or negatively affect its reputation in the community. An objective in on e category may overlap or support an objective in another. another(prenominal) set of objectives relates to safeguarding of resources. Although these are primarily operations objectives, certain aspects of safeguarding can fall under the other categories. The category in which an objective falls can sometimes depend on circumstances. Objectives should be complementary and linked.Not only must entity-wide objectives be consistent with the entitys capabilities and prospects, they also must be consistent with the objectives of its business units and functions. Entity-wide objectives must be broken down into subobjectives, consistent with the overall strategy, and linked to activities throughout the organization. Where, however, objectives depart form an entitys past practices, management must address the linkages or run increased risks. Activity objectives also need to be clear, that is, readily understood by the people taking the actions toward their achievement. They must also be me asurable. It is useful to relate an activitys overall set of objectives to resources available.A way to relieve further resource constraint is to question activity objectives that do not support entity-wide objectives and the entitys business processes. Another means of balancing objectives and resources is to identify activity objectives that are very all important(p) or critical to achieving entity-wide objectives. Objectives provide the measurable targets which the entity moves in conducting its activities. The goal of internal control in this area instructiones primarily on developing congruity of objectives and goals throughout the organization, identifying key success factors and timely reporting to management of performance and expectations.Although success cannot be ensured, management should have reasonable assurance of being alerted when objectives are in danger of not being achieved. Risks The process of identifying and analyzing risk is an ongoing iterative process an d is a critical component of an effective internal control system. Management must focus carefully on risks at all levels of the entity and take the necessary actions to manage them. Risk identification An entitys performance can be at risk due to internal or external factors. Regardless of whether an objective is stated or implied, an entitys risk-assessment process should consider risks that may occur. Risk identification is an iterative process and often is integrated with the planning process.Entity level risks at the entity-wide level can arise from external or internal factors. External factors examples technological developments can affect the nature and timing of research and development, or lead to changes in procurement Changing customer needs or expectations can affect product development, production process, customer service, pricing or warranties. rivalry can alter marketing or service activities New lawmaking and regulation can force changes in operating policie s and strategies Natural catastrophes can lead to changes in operations or information systems and highlight the need for contingency planning. Economic changes can have an impact on decisions related to financing, capital expenditures and expansion. Internal factors examples A disruption in information systems process can adversely affect the entitys operations. The quality of personnel leased and methods of training and motivation can influence the level of control consciousness within the entity. A change in management responsibilities can affect the way certain controls are effected. The nature of the entitys activities, and employee recoveribility to assets, can contribute to misappropriation of resources. An unassertive or ineffective board or audit committee can provide opportunities for indiscretions.Risk may be identify in connection with short- and long-range forecasting and strategical planning. What is important is that management considers carefully the factors that may contribute to or increase risk. Some factors to consider include past experiences of failure to meet objectives quality of personnel changes affecting the entity such as competition, regulations, personnel, and the like existence of geographically distributed, particularly foreign, activities significance of an activity to the entity and the complexity of an activity. Once the major contributing factors have been identified, management can then consider their significance and, where possible, link risk factors to business activities. Activity-level.In addition to identifying risk at the entity level, risks should be identified at the activity level. Dealing with risk at this level helps focus risk assessment on major business units or functions such as sales, production, marketing, technology development, and research and development. Potential causes of failing to achieve an objective range from the limpid to the obscure, and form the significant to the insignificant in potential effect. Risk analytic thinking After the entity has identified entity-wide and activity risks, a risk analysis needs to be performed. The process which may be more or less formal usually includes Estimating the significance of the risk Assessing the likelihood (or frequency) of the risk occurring Considering how the risk should be managed that is, an assessment of what actions need to be taken. There are numerous methods for estimating the cost of a loss from an identified risk. Management should be aware of them and apply them as appropriate. However, many risks are indeterminate in size. At best they can be described as large, moderate or small. Once the significance and likelihood of risk have been assessed, management needs to consider how the risk should be managed. This involves judgment based on assumptions round the risk, and reasonable analysis of costs associated with trim back the level of risk.Sometimes actions can virtually eliminate the risk, or off set its effect if it does occur. Note that at that place is a distinction between risk assessment, which is part of internal control and the resulting plans, programs or other actions deemed necessary by management to address the risks. A key part of the larger management process, but not an element of the internal control system. Along with actions for managing risk is the establishment of procedures to enable management to footstep the capital punishment and effectiveness of the action. Before installing additional procedures, management should consider carefully whether existing ones may be suitable for addressing identified risks.Management also should recognize that it is likely some level of residual risk will always exist, not only because resources are always limited, but also because o other limitations inherent in every internal control system. It is often critical to the entitys success. Managing change Every entity needs to have a process, formal or informal, to iden tify conditions that can significantly affect its ability to achieve its objectives. A key part of that process involves information systems that capture, process and report information about events, activities and conditions that indicate changes to which the entity needs to react. With the requisite information systems in place, the process to identify and respond to changing conditions can be established. Circumstances demanding special attention Changed operating environment A changed regulatory or economic environment can result in increased competitive pressures and significantly different risks New personnel high turnover of personnel, in the absence of effective training and supervision, can result in breakdowns New or revamped information systems Normally effective controls can break down when new systems are developed, particularly when done under unusually tight time constraints Rapid growth When operations put out significantly and quickly, existing systems may b e strained to the point where controls can break down New technology when new technology is being incorporated, a high likelihood exists that internal controls need to be modified. New lines, products, activities unfamiliar situations, controls may be inadequate Corporate restructurings may be accompanied by staff reductions and inadequate supervision and segregation of duties. foreign operations the expansion or acquisition of foreign operations carries new and often unique risks that management should address. To the extent practicable, mechanisms should be forward- understanding, so an entity can anticipate and plan for significant changes.Early warning systems should be in place to identify data signaling new risks. However, as with other control mechanisms, the related costs cannot be ignored. No entity has sufficient resources to bear and see completely the information about all the myriad evolving conditions that can affect it. It is often difficult to know whether seemingly significant information is the reservoir of an important trend, ore merely an aberration. The risk-assessment process is likely to be less formal and less structured in smaller entities than in larger ones, but the basic concepts of this internal control component should be present in every entity, regardless of size.Risk assessment in smaller entity can be particularly effective because the in-depth involvement of the CEO and other key managers often means that risks are assessed by people with both access to the appropriate information and a good understanding of its implications. Action plans can be devised and implemented quickly with limited number of people. They can then follow up as needed to ensure that the necessary actions are being taken. CHAPTER 4 CONTROL ACTIVITIES Control activities are policies and procedures, which are the actions of people to implement the policies, to help ensure that management directives identified as necessary to address risks are carried out.Many different descriptions of types of control activities have been put forth, including preventive controls, spy controls, manual controls, computer controls and management controls. Following are certain control activities commonly performed by personnel at various levels in organizations. Top level reviews Reviews are made of actual performance versus budgets, forecasts, prior periods and competitors institutionalize functional or activity management managers running functions or activities review performance reports Information bear on A variety of controls are performed to hit accuracy, completeness and authorization of transactions. Data entered are subject to edit checks or twin(a) to approved control files. Physical controls Equipment, inventories, securities, cash and other assets are secured, physically, and sporadically counted and compared with amounts shown on control records. Performance indicators Relating different sets of data operating or financial to one another, together with analyses of the relationships and investigate and corrective actions, serve as control activities. Segregation of Duties duties are divided, or segregated, among different people to reduce the risk of error or inappropriate actions. Control activities usually involve two elements a policy establishing what should be done and, serving as a basis for the second element, procedures to effect the policy. But regardless of whether a policy is written, it must be implemented thoughtfully, conscientiously and consistently.A procedure will not be useful if performed mechanically without a sharp go on focus on conditions to which the policy is directed. It is essential that conditions identified as a result of the procedures be investigated and appropriate corrective actions taken. Along with assessing risks, management should identify and put into effect actions needed to address the risks. The actions identified as addressing a risk also serve to focus attention on control activities to be put in place to help ensure that the actions are carried out properly and in a timely manner. Control activities are very much a part of the process by which an enterprise strives to achieve its business objectives. Control activities serve as mechanisms for managing the achievement of that objective.Such activities might include tracking the progress of the development of the customer buying histories against established timetables, and step to ensure accuracy fo the reported data. Controls over information systems Two broad groupings of information systems control activities can be used. The first is general controls which apply to many if not all application systems and help ensure their continued, proper operation. The second category is application controls, which include computerized steps within the application software and related manual procedures to control the processing of various types of transactions. Together, these co ntrols serve to ensure completeness, accuracy and validity of the financial and other information in the system.General controls commonly include controls over data condense operations, system software acquisition and maintenance, access security, and application system development and maintenance. These controls apply to all systems mainframe, minicomputer and end-user computing environments. Application controls are designed to control application processing, helping to ensure the completeness and accuracy of transaction processing, authorization and validity. peculiar(prenominal) attention should be paid to an applications interfaces, since they are often linked to other systems that in turn need control to ensure that all inputs are received for processing and all outputs are distributed appropriately.Controls over system development requiring thorough reviews and testing of applications ensure that the logic of the report program is sound, and that it has been tested to asce rtain that all exceptions are reported. To provide control after implementation of the application, controls over access and maintenance ensure that applications are not accessed or changed without authorization and that required, authorized changes are made. The data concentrate on operations controls and systems software controls ensure that the right files are used and updated appropriately. The relationship between the application controls and the general controls is such that general controls are needed to support the functioning of application controls, and both are needed to ensure complete and stainless information processing.The concepts underlying control activities in smaller organizations are not likely to differ significantly form those in larger entities, but the formality with which they operate will vary. Further, smaller entities may find that certain types of control activities are not always relevant because of highly effective controls applied by management of the small or mid-size entity. An appropriate segregation of duties often appears to present difficulties in smaller organizations, at least on the surface. Even companies that have only a few employees, however, can usually parcel out their responsibilities to achieve the necessary checks and balances.Controls over information systems, particularly general computer controls and more specifically access security controls, may present problems to small and mid-size entities. This is because of the informal way in which control activities are often implemented. CHAPTER 5 INFORMATION AND COMMUNICATION Every enterprise must capture pertinent information financial and non-financial, relating to external as well as internal events and activities. The information must be identified by management as relevant to managing the business. It must be delivered to people who need it in a form and timeframe that enables them to carry out their control and other responsibilities.Information is neede d at all levels of an organization to run the business, and move toward achievement of the entitys objectives in all categories operations, financial reporting and compliance. Information is identified, captured, processed and reported by information systems. The term information systems frequently is used in the context of processing internally generated data relating to transactions, such as purchases and sales, and internal operating activities, such as production processes. Information systems sometimes operate in a monitoring mode, routinely capturing specific data. In other cases, special actions are taken to obtain needed information.Keeping information consistent with needs becomes particularly important when an entity operates in the face of fundamental industry changes, highly innovative and quick-moving competitors or significant customer demand shifts. Systems support strategic initiatives. The strategic use of information systems has meant success to many organizations . Using technology to help respond to a better understood marketplace is a growing trend, as systems are used to support proactive rater than reactive business strategies. Integration with operations. The strategic use of systems demonstrates the shift that has occurred from purely financial systems to systems integrated into an entitys operations.These systems help control the business process, tracking and recording transactions on a real-time basis, often including many of the organizations operations in an integrated, complex systems environment. The effect of integrated operations systems is dramatic, as can been seen in the just-in-time (JIT) inventory system. The systems themselves order and schedule arrival of new materials automatically, frequently through the use of EDI (electronic data interchange). Many of the newer production systems are highly integrated with other organizational systems and may include the organizations financial systems. Acquisition of technology is an important aspect of corporate strategy, and choices regarding technology can be critical factors in achieving growth objectives. Decisions about its selection and implementation depend on many factors.These include organizational goals, market-place needs, competitive requirements and, importantly, how the new systems will help effect control, and in turn be subject to the necessary controls, to promote achievement of the entitys objectives. It is critical that reports contain abundant appropriate data to support effective control. The quality of information includes ascertaining whether bailiwick is appropriate Is the needed information there? Information is timely Is it there when required? Information is current Is it the latest available? Information is accurate Are the data correct? Information is accessible Can it be obtained easily by appropriate parties?All of these questions must be address by the system design. If not, it is not probable that the system will not provide the information required. talk is inherent in information systems. Internal In addition to receiving relevant data for managing their activities, all personnel, particularly those with important operating or financial management responsibilities, need to receive a clear message from top management that internal control responsibilities must be taken seriously. Both the clarity of the message and the effectiveness with which it is communicated are important. In addition, specific duties must be made clear. Without this understanding, problems are likely to arise.In performing their duties, personnel should know that whenever the unexpected occurs, attention is to be habituated not only to the event itself, but also to its cause. In this way, a potential weakness in the system can be identified and action taken to prevent recurrence. People also need to know how their activities relate to the work of others. People need to know what behavior is expected, or acceptable, and what is unacceptable. Personnel also need to have a means of communicating significant information upstream in an organization. Front-line employees who deal with critical operating issues every day are often in the best position to recognize problems as they arise.For such information to be reported upstream, there must be both open channels of communication and clean willingness to listen. People must believe their superiors truly want to know about problems and will deal with them effectively. In most cases, the normal reporting lines in an organization are the appropriate communications channel. In some circumstances, however, carve up lines of communication are needed to serve as a fail-safe mechanism in case normal channels are inoperative. Communication between management and the board of directors and committees are critical. Management must keep the board up to date on performance, developments, risks, major initiatives, and any other relevant events or occurrences.Th e better the communications to the board, the more effective it can be in carrying out its oversight responsibilities, and acting as a sounding board on critical issues and providing advice and counsel. By the same token, the board should communicate to management what information it needs, and provide direction and feedback. External There needs to be appropriate communication not only within the entity, but outside. With open communications channels, customers and suppliers can provide highly significant input on the design or quality of products or services, modify a company to address evolving customer demands or preferences. Communications from external parties often provide important information on the functioning of the internal control system.Communications to shareholders, regulators, financial analysts and other external parties should provide information relevant to their needs, so they can readily understand the circumstances and risks the entity faces. Communication ta kes such forms as policy manuals, memoranda, bulletin board notices and videotaped messages, or transmitted orally. Another powerful communications medium is the action taken by management in dealing with subordinates. Managers should remind themselves, actions speak louder than words. Information systems in smaller organizations are likely to be less formal than in large organizations, but their role is just as significant. CHAPTER 6 MONITORINGCircumstances for which the internal control system originally was designed also may change, make it to be less able to warn of the risks brought by new conditions. Accordingly, management needs to determine whether the internal control system continues to operate effectively. Monitoring can be done in two ways through ongoing activities or shed light on evaluations. Internal control systems usually will be structured to monitor themselves on an ongoing basis to some degree. The greater the degree and effectiveness of ongoing monitoring, th e less need for recognize evaluations. Usually, some combinations of ongoing monitoring and separate evaluations will ensure that the internal control system maintains its effectiveness over time. It should e recognized that ongoing monitoring procedures are built in to the normal, recurring operating activities of an entity. Because they are performed on a real-time basis, reacting dynamically to changing conditions, and are deep-rooted in the entity, they are more effective than procedures performed in connection with separate evaluations. Since separate evaluations take place after the fact, problems will often be identified more quickly by the ongoing monitoring routines. An entity that perceives a need for frequent separate evaluations should focus on ways to enhance its ongoing monitoring activities and, thereby to emphasize building in versus adding on controls. Ongoing monitoring activitiesExamples of ongoing monitoring activities include the following design to which pe rsonnel, in carrying out their regular activities, obtain evidence as to whether the system of internal control continues to function. Extent to which communications from external parties corroborate internally generated information, or indicate problems. Periodic comparison of amounts recorded by the accounting system with physical assets. Responsiveness to internal and external auditor recommendations on means to strengthen internal controls. Extent to which training seminars, planning sessions and other meetings provide feedback to management on whether controls operate effectively. Whether personnel are asked periodically to state whether they understand and comply with the entitys code of conduct and on a regular basis perform critical control activities. Effectiveness of internal audit activities. disjoined evaluations While ongoing monitoring procedures usually provide important feedback on the effectiveness of other control components, it may be useful to take a fresh look from time to time, focusing directly on the systems effectiveness. Scope and frequency. Evaluations of internal control vary in scope and frequency, depending on the significance of risks being controlled and importance of the controls in reducing the risks.Evaluation of an entire internal control system which will generally be needed less frequently than the assessment of specific controls may be prompted by a number of reasons major strategy or management change, major acquisitions or dispositions, or significant changes in operations or methods of processing financial information. The evaluation scope will also depend on which of the three objectives categories operations, financial reporting and compliance are to be addressed. Who evaluates. Often evaluations take the form of self-assessments, where persons responsible for a particular unit or function will determine the effectiveness of controls for their activities. Then, all results would be subject to the chief exec utives review.Internal auditors normally perform internal control evaluations as part of their regular duties, or upon special requests of the board of directors, senior management or subsidiary or divisional executives. Similarly, management may use the work of external auditors in considering the effectiveness of internal control. The evaluation process. The justice must understand each of the entity activities and each of the components of the internal control system being addressed. It may be useful to focus first on how the system purportedly functions, sometimes referred to as the systems design. The evaluator must determine how the system actually works. The evaluator must analyze the internal control system design and the results of tests performed.The analysis should be conducted against the scope of the established criteria, with the ultimate goal of determining whether the system provides reasonable assurance with respect to the stated objectives. Methodology can be qua litative/ quantifiable (benchmarking) Documentation. The extent of documentation of an entitys internal control system varies with the entitys size, complexity and similar factors. Many controls are informal and undocumented, yet are regularly performed and highly effective. An appropriate level of documentation makes the evaluation more efficient, it facilitates employees understanding of how the system works and their particular roles, and easier to modify.Reporting deficiencies Deficiencies in an entitys internal control system surface from many sources, including the entitys ongoing monitoring procedures, separate evaluations of the internal control system and external parties. A wish may represent a perceived, potential or real shortcoming, or an opportunity to strengthen the internal control system to provide a greater likelihood that the entitys objectives will be achieved. One of the best sources of information on control deficiencies is the internal system itself. A number of external parties frequently provide important information on the functioning of an entitys internal control system.In considering what needs to be communicated, it is necessary to look at the implication of findings. A seemingly simple problem with an probable solution might have far-reaching control implications. Findings of internal control deficiencies usually should be reported to the individual responsible for the function or activity involved, who is in the position to take corrective action, but also to at the lest one level of management above the directly responsible person. This process enables that individual to provide needed support or oversight for taking corrective action, and to communicate with others in the organization whose activities may be affected.Where findings cut across organizational boundaries, the reporting should cross over as well and be directed to a sufficiently high level to ensure appropriate action. Providing needed information on internal co ntrol deficiencies to the right party is critical to the continued effectiveness of an internal control system. Protocols can be established to identify what information is needed at a particular level for decision-making. Reportable conditions ( significant deficiencies in the design or operation of the internal control structure, which could adversely affect the organizations ability to record, process, summarize and report financial data consistent with the assertions of management in the financial statements. SME ( more ongoing monitoring, less like to do separate (few people, notice quicker)
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.