UW Financial Reporting Conference May 5, 2016 4-0-FOUR! AVOIDING THE ICFR ROUGH.

Slides:



Advertisements
Similar presentations
Internal Control–Integrated Framework
Advertisements

Presented by YOUR NAME THE DATE
G L O B A L S E R V I C E / I N D U S T R Y A U D I T / T A X / A D V I S O R Y / L I N E O F B U S I N E S S SAS 112 Presentation California State University.
Auditing Concepts.
2007 Annual Meeting ● Assemblée annuelle 2007 Vancouver 2007 Annual Meeting ● Assemblée annuelle 2007 Vancouver Canadian Institute of Actuaries Canadian.
Audit Documentation PCAOB Auditing Standard no.3.
Finance at Microsoft.
Audit Guidance Using the Federal Information System Controls Audit Manual (FISCAM) to Achieve Audit Objectives in Financial and Performance Audits Mickie.
CAIB PRE-CONFERENCE TRAINING Audit Committees: Making Corporate Governance work in the Caribbean June 21, 2007 Risk Advisory Services.
SOX and IT Audit Programs John R. Robles Thursday, May 31, Tel:
Seminar in Accounting & Society SOX – Section 404 April 23, 2008.
Operational risk management Margaret Guerquin, FSA, FCIA Canadian Institute of Actuaries 2006 General Meeting Chicago Confidential © 2006 Swiss Re All.
Current Developments at the PCAOB Ensuring Integrity: 3 rd Annual Auditing Conference at Baruch College December 4, 2008.
COMPLYING WITH SARBANES- OXLEY SECTION 404: MANAGEMENT’S ASSESSMENT OF THE ACTUARIAL CONTROL ENVIRONMENT Brian Reilly, Senior Vice President & Chief Auditor.
18- 1 © 2006 The McGraw-Hill Companies, Inc., All Rights Reserved. Chapter 18 Integrated Audits of Internal Control (For Public Companies Under Sarbanes-Oxley.
Internal Control in a Financial Statement Audit
CHAPTER 2 FINANCIAL STATEMENT AUDITS AND AUDITORS’ RESPONSIBILITIES Fall 2007 u G enerally Accepted Auditing Standards u Assurance Provided by an Audit.
UCSD Office of the Controller1 SAS112 Implementation UCSD Status Update.
The Camp Audit “Keep your friends close and your auditor closer”
Information Systems Controls for System Reliability -Information Security-
Statement on Auditing Standards (SAS) 112 Communicating Internal Control Related Matters Identified in an Audit.
Auditing Internal Control over Financial Reporting
An Accountant’s Look at the Changing Horizons within SOX 404 Presented to Colorado Bar Association’s Securities Law Group Presented by Bill Evert Hein.
Basics of OHSAS Occupational Health & Safety Management System
Planning an Audit The Audit Process consists of the following phases:
Auditing Internal Control over Financial Reporting
Implementation Issues of Sarbanes-Oxley CASE Presentation September 23, 2004 By Denise Farnan.
Chapter 5 Internal Control over Financial Reporting
Page 1 Internal Audit Outsourcing The Moss Adams Approach to Internal Audit Outsourcing Proposed SOX 404 Changes.
Considering Internal Control
1 Conference on Accountants’ Liability ALI-ABA Zoe-Vonna Palmrose Deputy Chief Accountant Professional Practice Office of the Chief Accountant U.S. Securities.
Chapter 7 Auditing Internal Control over Financial Reporting McGraw-Hill/Irwin ©2008 The McGraw-Hill Companies, All Rights Reserved.
NO FRAUD LEFT BEHIND The Effect of New Risk Assessment Auditing Standards on Schools Runyon Kersteen Ouellette.
Internal Control in a Financial Statement Audit
Presented by: Meg Boyd The Blue Mountains Drinking Water System: DWQMS Overview.
Patient Protection and Affordable Care Act March 23, 2010.
Learning Objectives LO5 Illustrate how business risk analysis is used to assess the risk of material misstatement at the financial statement level and.
1 Today’s Presentation Sarbanes Oxley and Financial Reporting An NSTAR Perspective.
The views expressed in this presentation do not necessarily reflect those of the Federal Reserve Bank of New York or the Federal Reserve System Association.
Kashif Rasheed Manager Finance. Office of inspector General (OIG) Global Fund Secretariat Country Coordination Mechanism (CCM ) Principal Recipients (PR)
Chapter 7 Auditing Internal Control over Financial Reporting McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
PCAOB Inspection Findings PCAOB Audit Committee Dialogue Auditor Assessment Toolkit Doug Morally Senior Audit Manager September 14, 2015.
Casualty Loss Reserve Seminar General Session II September 9, 2003 Section 302/404 of Sarbanes-Oxley Act What Actuaries Need to Know Jan A. Lommele, FCAS,
McGraw-Hill/Irwin © 2003 The McGraw-Hill Companies, Inc., All Rights Reserved. 6-1 Chapter 6 CHAPTER 6 INTERNAL CONTROL IN A FINANCIAL STATEMENT AUDIT.
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin 7-1 Chapter Seven Auditing Internal Control over Financial Reporting.
Learning Objectives LO5 Document an accounting system to identify key controls and weaknesses in order to assess control risk. LO6 Write key control tests.
Learning Objectives LO5 Document an accounting system to identify key controls and weaknesses in order to assess control risk. LO6 Write key control tests.
McGraw-Hill/Irwin © The McGraw-Hill Companies 2010 Auditing Internal Control over Financial Reporting Chapter Seven.
Risk Management for Small & Medium Sized Enterprises
©2012 Prentice Hall Business Publishing, Auditing 14/e, Arens/Elder/Beasley Section 404 Audits of Internal Control and Control Risk Chapter.
Copyright © 2007 Pearson Education Canada 9-1 Chapter 9: Internal Controls and Control Risk.
1 Overview of PCAOB Auditing Standard No. 5 An Audit of Internal Control Over Financial Reporting that is Integrated with an Audit of Financial Statements.
18-1 Copyright © 2016 McGraw-Hill Education. All rights reserved. No reproduction or distribution without the prior written consent of McGraw-Hill Education.
©©2012 Pearson Education, Auditing 14/e, Arens/Elder/Beasley Considering Internal Control Chapter 10.
Copyright © 2014 Pearson Education, Inc. Publishing as Prentice Hall. Chapter
Building a Sound Security and Compliance Environment for Dynamics AX Frank Vukovits Dennis Christiansen Fastpath, Inc.
Improving Compliance with ISAs Presenters: Al Johnson & Pat Hayle.
Auditors’ Dilemma – reporting requirements on Internal Financial Controls under the Companies Act 2013 and Clause 49 of the Listing agreement V. Venkataramanan.
Internal Control Chapter 7. McGraw-Hill/Irwin © 2008 The McGraw-Hill Companies, Inc., All Rights Reserved. 7-2 Summary of Internal Control Definition.
IT Focus Areas- PCAOB Inspection
Auditing Concepts.
Pressure Cooker: Access Controls in New and Existing ERP Systems
Professional Standards
Accountability and Internal Controls – Best Practices
Defining Internal Control
The internal control failure of Magnum Hunter Resources Corporation
Internal Control Internal control is the process designed and affected by owners, management, and other personnel. It is implemented to address business.
An overview of Internal Controls Structure & Mechanism
Performance improvement observations
Presentation transcript:

UW Financial Reporting Conference May 5, FOUR! AVOIDING THE ICFR ROUGH

Panelists Frank Brod, Microsoft Brian Croteau, SEC John Fogarty, Deloitte Susan Insley, VMware 2

UW ICFR Panel Discussion Frank Brod CAO, Microsoft Corporation

$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$ $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$ $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$ $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$ $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$ $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$ $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$ $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$ $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$ $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$ $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$ $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$ $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$ SOX at Microsoft by the Numbers +$94B MS reported revenue 430+ worldwide SOX 404 Controls Auditor Scope 95%+ Revenue coverage 80+ IT systems and applications 390 Participants SOX 302 quarterly disclosure

SOX Program Goals Design Respond Improve Manage Prevent material weaknesses or significant deficiencies Anticipate and identify risks Rapid response to remediate deficiencies Provide leadership Ensure costs for compliance are appropriate Compliance above all else Encourage and maintain control vigilance culture throughout the organization

Involvement with Deloitte Work in tandem with Deloitte auditors and ensure transparency and open dialog Objective: Process: Include auditors in key close reviews Alignment of SOX plans Share managements 404 documentation Common process and control walkthroughs Testing designed to maximize auditor reliance

Best Practices Ensure ICFR coverage and compensating controls Controls to validate 10Q/10K and Earnings Release Ensure controls aligned with process changes and evolving risks Adopted FY ending June 30, 2014 Microsoft’s strong program minimized need for new controls Program designed to minimize risk of Material Weakness Standardized template and process to facilitate review individually and in aggregate COSO 2013 Early adoption    

Deficiency Evaluation Template IssueIssue #SubcycleRelated ControlRemediation StateRepeat Deficiency Order Tool User Access15031RevenueT1-XXXPendingNo Control Deficiency Description One user was provisioned 'super user' access to the Order tool without documented evidence of approval. Access was deemed to be appropriate. Related SOX Control T1-XXX - Super User access is only available to authorized internal Microsoft employees and cannot be self-granted. Another authorized Microsoft employee Super User must approve and grant this application access role through business process. Related Financial Statement Caption Revenue – Product X COSO Root Cause Control performer or owner didn’t fully understand or perform their roles and responsibilities Deficiency Assessment Likelihood of potential misstatement or omission: remote In summary - The deficiency does not rise above “control deficiency” given that the user access was deemed appropriate and has relevant mitigating controls that further reduce the severity of the control deficiency Compensating Controls T1-UAL: Quarterly review of users with access to high risk SAP Finance roles T1 XX2 - Super user access, which is limited to authorized Microsoft internal users is reviewed on a quarterly basis. The business unit perform a quarterly audit of users with Super Admin role access and request access removal if no longer needed. Remediation Develop and deliver training for users authorized to provision access in the Tool, including awareness of the SOX control requirements relating to retaining documentation of access approvals Conduct a review of users authorized to provision access in the tool to determine if number can be limited further to a small user provisioning group. Finalize the list of users who should continue to be authorized to provision such access. New monthly report for management’s detective review of users authorized to provision access in the tool. Ensure the report is reviewed to determine that there is no inappropriate access.

Thank You

4-0-Four! Avoiding the ICFR Rough Panel Discussion Frank Brod, Microsoft Brian Croteau, SEC John Fogarty, Deloitte Susan Insley, VMware 10

Material Weakness A material weakness is defined as:  A deficiency, or combination of deficiencies, in ICFR such that there is a reasonable possibility that a material misstatement of the registrant’s annual or interim financial statements will not be prevented or detected on a timely basis. 11

Management Review Controls “Reaching a Consensus on Management Review Controls” Recent article in CFO.com By John Fogarty, Partner, Deloitte & Touche LLP PDF copy of article available via Conference URL (printing a copy for personal use only permitted) 12

Evaluating Evidence of Operating Effectiveness of ICFR Determining the Sufficiency of Evidence Based on ICFR Risk Assessment High Misstatement Risk of Financial Reporting Element Medium Low MediumHigh Risk of Control Failure More Evidence

THANK YOU