1/67
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What is Internal Control?
Internal Control: A process to provide reasonable assurance that organizational objectives are being met/achieved
What do Organizational objectives include?
Quality of data, which leads to the reliability of internal and external reporting
Effectiveness and efficiency of operations
Compliance with applicable laws and regulations
Who has the ultimate responsibility for internal controls?
the Chief Executive Officer (CEO)
What are the characteristics of Internal Control?
Internal is an ongoing process
the effectiveness of internal control is at a point in time
Effectiveness of internal controls depends on an understanding by…:
employees of their roles to the organization and how vital compliance with internal controls can be.
When a weakness is identified in internal control processes, it allows for…:
fraud and unintentional mistakes to occur
What parties are interested in internal controls?
stakeholders, legislators, auditors, and professional organizations
what internal controls to put in place
Several internal control frameworks assist companies with determining…:
What is the importance of Internal Control?
When internal controls are embedded into the organization, it supports achievement of the organization’s objectives
it is important to embed internal controls into the culture and activities of an organization
Stakeholders are defined as:
shareholders, customers, suppliers, employees, and creditors
Why are Stakeholder’s interested in Internal Controls?
Internal control is of interest to parties outside of the organization because it helps provide protection against erroneous or fraudulent financial reporting
All of the stakeholders mentioned use financial reports to make decisions, therefore there is a dependency on the accuracy of the financial reports.
Additionally, stakeholders worry that the external auditors will not detect issues. An example is:
Enron and Arthur Andersen collapsed after being convicted of obstruction of justice for shredding tons of documents related to its audit of the bankrupt energy giant Enron
Why are Legislators interested in Internal Controls?
all public companies are required to have internal control by law
Executive Management of an SEC registered company may be fined or imprisoned if the company intentionally fails to have adequate internal control
What is the Foreign Corrupt Practices Act (FCPA) of 1977?
established criminal liability for bribery of foreign officials by any US company.
established provisions for record keeping and internal controls for all companies registered with the SEC
What is the Sarbanes- Oxley Act of 2002 (SOX)?
established to protect investors by providing more transparency of corporate disclosures. Compliance is monitored by the Public Company Accounting Oversight Board (PCAOB), which is the governing body that sets auditing standards.
What does Section 302 entail?
CEO and CFO certify that the organization has internal controls and that the financial statements are free from misstatement
What does Section 404 entail?
Management and the external auditors' responsibilities with testing of internal controls
Why are External Auditor’s Interested in Internal Controls?
Internal controls play a role in the company's financial statements, which the external auditors express an opinion about. This opinion is reliant on the credibility of the financial statements produced from the accounting system.
What is the auditing standard SAS 94?
Auditors obtain an understanding of internal controls sufficient to plan the audit by understanding the design of the controls.
What is the auditing standard SASs 104-111?
require auditors to have an understanding of the IT environment as it relates to the financial information being stored, processed, and used in reporting.
What is the Impact of Internal Control Effectiveness:
when internal control is effective, the external auditors can place some reliance on the internal controls and reduce testing.
What is the impact of Internal Control INeffectiveness?
When internal control is ineffective, the external auditors have to do more extensive testing to express an opinion.
What is PCAOB Auditing Standard (AS) #2201?
Provides guidance over how to identify and audit key controls, detecting material misstatement, and material disclosures.
What does AS #2201 focus on?
Internal control environment (COSO 2013)
management override
risk assessment performed by the organization
centralized processing
monitoring of operation results
internal audit, audit committee, and self-assessment programs
period and reporting processes that result in financial reports
policies addressing significant business risks
What are Professional Organization’s Interests in Internal Controls?
refers to internal control framework concepts as published, which are followed by companies
focus is primarily on the COSO Internal Control- Integrated Framework
What is the COSO Internal Control- Integrated Framework?
originally established in 1992, updated in 2013 (COSO 2013)
defined internal control as a process that assists with the achievement of objectives
What are the COSO Internal Control- Integrated Framework objectives?
effectiveness and efficiency of operations
reliability of financial reporting
compliance with applicable laws and regulations
What did the 2013 Update do for COSO?
Added 17 principles to further define and explain the components while considering the effects of changes in the organizational environment (risk focus).
What does the fraud and the Fraud Triangle entail?
when internal control is lacking, there is a greater risk of fraud occurring
consists of 3 elements: pressure, opportunity, and rationalization
As a business, what of the 3 items in the Fraud Triangle do you have control over?
opportunity
What are the objectives of the COSO 2013 Framework?
effectiveness and efficicency of operations
reliability of both internal and external reporting
compliance with applicable laws and regulations
What Organizational Structure Relationships are Assessed in the COSO 2013 Framework?
entire organization/ entity-level
division
operating unit
function
What are the 5 components of COSO?
control environment
risk assessment
control activities
information & Communication
monitoring activities
What is Component #1: Control Environment about?
the foundation for controls within an organization
sets the tone of the organization and influences the behavior of employees
drives the level to which policies and procedures are followed, created, and written
What are the five principles of control environment?
commitment to integrity and ethical values
Board of Directors and the Audit Committee that are independent of Management
Organizational structure, including the assignment of authority and responsibility
human resource policies and practices that relate to hiring and development of competent personnel
individuals are accountable to uphold and maintain internal control responsibilities
What is Component #2: RIsk Assessment about?
the systematic identification and analysis of risk that can undermine the achievement of organizational objectives
should be performed on a regular basis, if not continuously, allowing organizations to continuously monitor risks that may impact them
What are the Four Principles of Risk Assessment?
An organization’s development of its objectives allows it to identify and assess risks that prevent the organization from meeting its objectives.
The identification of risk should be considered across the entire organization and management should consider how to manage these risks.
The organization must consider how the potential fraudulent activity could affect the achievement of organizational objectives.
The organization should periodically review the risk assessment to determine if there are any changes to the risks that might impact the internal control system.
What are the 4 Risk responses?
avoid
reduce/mitigate
share
accept
What is Avoid?
Stopping or quitting the activity to avoid the risk.
Example: If a company is trying to grow their business but realizes certain states, countries, or regions contain too much risk (economic, political, etc.), they would avoid those locations.
What is to reduce/mitigate?
Takes steps to reduce the likelihood and/or impact of the risk
Example: If a company is in a region prone to earthquakes, they may reduce the risk of losing data by having a backup of the data in a different location.
What is Share?
Transferring some of the risk
Example: Purchase insurance or find a partner.
What is Accept?
No action is taken and the company agrees to take on the risk.
Example: If a company can put in a control for $500 but the expected loss from a risk is only $200, then the organization will accept the risk.
As part of the risk response, an organization need to
evaluate the costs versus the benefits of implementing internal control
What is Component #3 Control Activities about?
policies and procedures that reduce risks that may undermine the achievement of management objectives.
What are policies?
Establish what should be done, often an expectation of behavior
What are procedures?
Prepared using the policy as the basis; details how compliance to the policy is achieved and is more task-focused.
What are the 3 Principles of Control Activities?
select control activities that will mitigate identified risks
control activities should include general controls over technology
management should establish actions to implement those activities
What is the process of Identifying Control Activities Flowchart?
Identify organizational objectives (operations, reporting, compliance)
Integrate into management of risk (based on risk/opportunity assessment)
identify appropriate types of control activities (preventive, detective, corrective, manual, and/or automatic)
set up policies (what should be done) and procedures (how to effect the policies)
What are the underlying concepts of Control Activities?
isolation
redundancy
comparison
assistance
oversight
accountability
What is isolation?
Data, programs, documentation, and information processing facilities should be isolated
What is redundancy?
Backup copies of programs and data should be maintained
What is comparison?
Comparisons between data provide a check on accuracy and may signal problems that need to be investigated.
What is assistance?
Providing help and assistance to employees, who in return will carry out internal control responsibilities.
What is oversight?
Supervision of employees, internal audits, and external audits encourage internal control compliance by employees. Independent reconciliation and verification also provide oversight.
What is accountability?
Holding employees accountable for their work promotes compliance to control activities.
True
control activities reduce the likelihood of fraud error, but will not price absolute assurance to limitations?
What are the limitations of Control Activities?
Collusion: When two or more people work together to perpetrate fraud.
Management Override: When Management uses their authority to override an internal control.
Reliance on humans: Humans tend to make mistakes due to a number of reasons.
What are the categories of control activities?
Preventive controls: Stop potential problems before they occur.
Detective controls: Find violations of non-compliance to internal controls.
Corrective controls: Remedy control violations detected.
What are performance reviews?
Performance reviews: Looking over performance and identifying where the company may not be operating effectively and efficiently (e.g., Budget to actual comparison).
What are physical controls?
Controls that protect assets and physical locations of a Company (e.g., Swipe card access at an entry point).
What are segregation of duties (SOD)?
Controls that prevent an individual from perpetrating and concealing fraud or an error
What is Information Processing?
Controls surrounding computer processing, classified as either General or Application controls.
What are the duties that should be segregated?
Authorization of transactions or other events
Custody of assets
Recordkeeping and modification of related data and program files
Information Processing- General Controls include:
Access security
Network and data service center operation controls
System software acquisition, implementation, and maintenance controls
Application software selection (or development), implementation, and maintenance controls
Information Processing- Application Controls Include:
Input controls: Authorization, entry, and verification of data entering the system.
Processing controls: Accurate and complete processing of transactions and other events.
Output controls: Providing output to the appropriate people and using the output appropriately.
Master file maintenance controls: Designed into the master file maintenance function which is used to add records, change the content of certain fields within records, and delete records.
What is Component #4: Information & Communication about?
The importance of relevant information to support functioning of internal controls.
The importance of communicating to external parties about the internal control system.
The importance of communicating information to support internal control.
What is Component #5: Monitoring about?
Internal control needs to be monitored to determine whether it is adequate and effective.
Monitoring also includes the modification of existing controls or the design of new ones to minimize risks where deficiencies in control have been discovered.
Focuses on the principle that:
-Monitoring can be conducted on an ongoing basis, as a separate project, or as a combination of both.
-Monitoring includes reporting and taking corrective action on any internal control violations noted.