ELLIOT BOOK CHAPTER 7 INTERNAL AUDIT AND CONTROL

Nature and Definitions of Internal Control

  • Internal control is a process designed to help an organization achieve operational, financial reporting, and compliance goals while identifying errors and fraud.

  • Three major organizations define internal control as follows:

    • Canadian Institute of Certified Public Accountants (CoCo): Elements like resources, culture, and structure that support people in achieving objectives.

    • Committee of Sponsoring Organizations of the Treadway Commission (COSO): A process effected by the board and management to provide reasonable assurance on operations, reporting, and compliance.

    • Institute of Internal Auditors (IIA): Actions taken by management to manage risk and increase the likelihood of meeting established goals.

  • Controls are categorized as either entity-level (broad organizational objectives) or direct (transactional level).

Legal and Regulatory Requirements

  • Sarbanes-Oxley Act of 2002 (SOX): A federal law focused on investor protection and internal control reporting.

    • Section 302302 requires officers to certify that internal controls ensure the accuracy of financial reports.

    • Section 404404 requires management and external auditors to report on the adequacy of financial reporting controls.

  • Public Company Accounting Oversight Board (PCAOB): Created by SOX to register public accounting firms, set auditing standards, and oversee audit quality.

  • Auditing Standard No. 5 (AS 5): Recommends a top-down, risk-based approach to auditing, focusing on material weaknesses and fraud risks.

Internal Control Activities and Fraud Deterrence

  • Preventive Controls: Designed to stop errors or inconsistencies before they occur. Examples include approvals, authorizations, and segregation of duties.

  • Detective Controls: Designed to identify errors after they have occurred. Examples include reconciliations and periodic asset counts.

  • Fraud Identification: Organizations seek to identify three standard conditions present in fraud: motivation, rationalization, and opportunity.

  • Management Controls: Systems of standards used to measure performance, coordinate resource allocation, and motivate employees.

Global Frameworks and Standards

  • COSO Internal Control—Integrated Framework (COSO Cube): Consists of five essential components:

    • Control environment (tone at the top).

    • Risk assessment.

    • Control activities.

    • Information and communication.

    • Monitoring.

  • ISO Series:

    • ISO 90009000 focuses on quality management and regulatory compliance.

    • ISO/IEC 2700027000 concentrates on information security management systems.

  • IIA Standards: Performance standard 21202120 requires the internal audit activity to evaluate the effectiveness of risk management.

  • Other Standards: Includes the UK Corporate Governance Code (for London Stock Exchange listings), the Basel Committee on Banking Supervision (for banking controls), and the Government Accountability Office (GAO) standards for the US federal government.

Risk-Based Auditing and Assurance

  • Risk-Based Auditing: Aligns audit resources with the highest organizational risks rather than just reviewing existing controls. It focuses on materiality and key threats to business objectives.

  • Risk Assurance: The level of confidence in the effectiveness of risk management practices. High levels of assurance reduce capital costs, insurance premiums, and regulatory compliance costs.

  • Control Risk Self-Assessment (CRSA): A process where business unit managers perform annual self-audits of their specific areas to evaluate process effectiveness and identify control gaps.

Collaboration and Professional Roles

  • Three Lines of Defense Model: A structural method to create checks and balances within an internal control system.

  • Three Categories of Internal Audit Activities (IIA):

    • Traditional Audit: Assuring the design and effectiveness of risk management and the reliability of reporting.

    • Consultative: Providing tools, coaching, and facilitation to support managers in treating risks.

    • Unsuitable: Internal auditors must not define risk appetite or manage risks themselves, as this compromises independence.

  • Tone at the Top: Senior executive leadership that encourages ethical behavior, transparency, and the expectation of following established standards.