Governance & Control in ERP Systems

Slides:



Advertisements
Similar presentations
Internal Control–Integrated Framework
Advertisements

Chapter 10 Accounting Information Systems and Internal Controls
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
Control and Accounting Information Systems
Control and Accounting Information Systems
Internal Control.
The Islamic University of Gaza
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
Standar Pekerjaan Lapangan: Pemahaman Memadai atas Pengendalian Intern Pertemuan 5.
6-1 McGraw-Hill/Irwin ©2002 by The McGraw-Hill Companies, Inc. All rights reserved. Chapter 6 Internal Control Evaluation: Assessing Control Risk.
IDENTIFYING RISKS AND CONTROLS IN BUSINESS PROCESS
Internal Control in a Financial Statement Audit
Sarbanes-Oxley Project Summary of COSO Framework Presented by Larry Dillehay & Scott Reitan Parkfield Group LLC.
Information Systems Controls for System Reliability -Information Security-
Control environment and control activities. Day II Session III and IV.
Internal Auditing and Outsourcing
Control and Accounting Information Systems
An Educational Computer Based Training Program CBTCBT.
Chapter 3 Internal Controls.
Presented to President’s Cabinet. INTERNAL CONTROLS are the integration of the activities, plans, attitudes, policies and efforts of the people of an.
Chapter 07 Internal Control McGraw-Hill/IrwinCopyright © 2014 by The McGraw-Hill Companies, Inc. All rights reserved.
Introduction to Internal Control Systems
Chapter 3 Ethics, Fraud, and Internal Control Accounting Information Systems, 5 th edition James A. Hall COPYRIGHT © 2007 Thomson South-Western, a part.
Chapter Three IT Risks and Controls.
Internal controls. Session objectives Define Internal Controls To understand components of Internal Controls, control environment and types of controls.
Chapter 5 Internal Control over Financial Reporting
Monitoring Internal Control Systems Johann Rieser Senior Auditor, Ministry of Finance, Vienna.
Internal Control in a Financial Statement Audit
Internal Control in a Financial Statement Audit
Learning Objectives LO5 Illustrate how business risk analysis is used to assess the risk of material misstatement at the financial statement level and.
Evaluation of Internal Control System
The Connection between Risk Management and Internal Control in Organizations Mag. Norbert Wagner Budapest,
Fundamentals I: Accounting Information Systems McGraw-Hill/Irwin Copyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
[Hayes, Dassen, Schilder and Wallage, Principles of Auditing An Introduction to ISAs, edition 2.1] © Pearson Education Limited 2007 Slide 7.1 Internal.
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin 6-1 Chapter Six Internal Control in a Financial Statement Audit.
IT Risks and Controls Revised on Content Internal Control  What is internal control?  Objectives of internal controls  Types of internal controls.
Chapter 9: Introduction to Internal Control Systems
Presented to Managers. INTERNAL CONTROLS are the integration of the activities, plans, attitudes, policies and efforts of the people of an organization.
S5: Internal controls. What is Internal Control Internal control is a process Internal control is a process Internal control is effected by people Internal.
McGraw-Hill/Irwin © The McGraw-Hill Companies 2010 Auditing Internal Control over Financial Reporting Chapter Seven.
Control and Security Frameworks Chapter Three Prepared by: Raval, Fichadia Raval Fichadia John Wiley & Sons, Inc
Copyright © 2007 Pearson Education Canada 9-1 Chapter 9: Internal Controls and Control Risk.
Deck 5 Accounting Information Systems Romney and Steinbart Linda Batch February 2012.
F8: Audit and Assurance. 2 Audit and Assurance Designed to give you knowledge and application of: Section A: Audit Framework and Regulation Section B:
Collaboration Process 1. IC Objectives and Risk Tolerances Define, document, and implement top-down internal control objectives and risk tolerances: 
Company LOGO Chapter4 Internal control systems. Internal control  It is any action taken by management to enhance the likelihood that established objectives.
Lecture 5 Control and AIS Copyright © 2012 Pearson Education 7-1.
Governance, risk and ethics. 2 Section A: Governance and responsibility Section B: Internal control and review Section C: Identifying and assessing risk.
McGraw-Hill/Irwin © The McGraw-Hill Companies 2010 Internal Control in a Financial Statement Audit Chapter Six.
Chapter 6 Internal Control in a Financial Statement Audit McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
©2005 Prentice Hall Business Publishing, Auditing and Assurance Services 10/e, Arens/Elder/Beasley Internal Control and Control Risk Chapter 10.
Auditors’ Dilemma – reporting requirements on Internal Financial Controls under the Companies Act 2013 and Clause 49 of the Listing agreement V. Venkataramanan.
Internal Control Chapter 7. McGraw-Hill/Irwin © 2008 The McGraw-Hill Companies, Inc., All Rights Reserved. 7-2 Summary of Internal Control Definition.
8 INTERNAL CONTROL. Definition Duty  mgt (CEO)  Board  Internal auditor  Employee  External person.
SUNY Maritime Internal Control Program. New York State Internal Control Act of 1987 Establish and maintain guidelines for a system of internal controls.
Governance, Risk and Ethics. 2 Section A: Governance and responsibility Section B: Internal control and review Section C: Identifying and assessing risk.
Internal Control Principles
Internal Control.
Internal and Governmental Financial Auditing and Operational Auditing
Audit & Risk Management
Chapter 9 Control, security and audit
PEM PAL IA COP Internal Control Working Group COSO Principles
Internal control objectives
COSO Internal Control s Framework
Internal control - the IA perspective
INTRODUCTION TO PUBLIC FINANCE MANAGEMENT
Unit 11 October 22, 2017.
Internal Control Internal control is the process designed and affected by owners, management, and other personnel. It is implemented to address business.
An overview of Internal Controls Structure & Mechanism
Presentation transcript:

Governance & Control in ERP Systems

Corporate Governance An enterprise’s “Rules of Engagement” Framework – The conduct ethics and values, laws, policies, standards, procedural guidelines and other compliance requirements every person in an organisation must respect, follow and uphold when working in an enterprise In work behaviours When carrying out work duties and performing work activities Example http://www.anz.com/about-us/corporate-sustainability/governance-risk/ https://www.jpmorganchase.com/corporate/About-JPMC/ab-corporate-governance-principles.htm

Corporate Governance Standards / Best Practice Guidelines Sarbanes Oxley Act – US 2002: Basic precepts of good corporate governance and ethical business practices ASX Corporate governance principles and recommendations (consistent with the OECD guidelines): 2003: Ten principles for listed companies 2007: 2nd edition containing eight principles 2010: An amended version was released 2014: 3rd edition was released

Corporate Governance Standards / Best Practice Guidelines Sarbanes Oxley Act – US 2002: Basic precepts of good corporate governance and ethical business practices ASX Corporate governance principles and recommendations (consistent with the OECD guidelines): 2014: 3rd edition

IT Governance Can follow: ISO/IEC 38500:2015 Information technology - Governance of IT for the Organisation: Guiding principles for those responsible in organisations (owners, directors, partners, executive managers and others) for the effective, efficient and acceptable use of information technology within their organisations COBIT Framework A business framework for the governance and management of enterprise IT Enterprise IT Policies, standards, etc Are part of internal controls to ensure efficiency and effective use, development & management of ICT resources Subset of Corporate Governance Rules applicable for IT Operations, Project & Management work

Are part of an enterprise Corporate Governance Framework Internal controls Internal Control: The measures an organisation employs to help attain the objectives of efficient operations, reliable reporting and compliance with relevant laws Essential to an organisation’s corporate governance structure Internal control involves the processes that an organisation implements to: safeguard assets provide accurate and reliable information promote operational efficiency enforce prescribed managerial policies and comply with applicable laws and regulations Are part of an enterprise Corporate Governance Framework

Classification of Internal Controls Preventive Controls Detective Controls Corrective Controls PREVENT problems before they arise Require compliance with preferred procedures to stop undesirable events from happening Alert system users of likely occurrence of & arising errors and anomalies Procedures and techniques designed to identify undesirable events after they have already occurred Correct/fix identified problems Classification of Internal Controls General (Commonly used through the enterprise) or Application Specific Controls  usually via IT Application Controls (via process & data models)

Internal Control Development Approaches & Standards Control Processes For the three control objectives to be achieved, there are five integrated control components: Internal control is a process, affected by an entity's board of directors, management and other personnel, designed to provide "reasonable assurance" regarding the achievement of the three key control objectives: Operations objectives: Effectiveness and efficiency of business operations Reporting objectives: Internal and external financial and non-financial reporting obligations Compliance objectives: Adherence to applicable laws and regulations

Internal Control Development Approaches & Standards Environment Control The Australian Standard on Assurance Engagements ASAE 3150 Assurance Engagements on Controls outlines two key areas for assessing the control environment in an organisation: Management: Culture of honesty and ethical behaviour Strengths in the control environment elements If control environment is weak, the internal control system is less reliable

Internal Control Development Approaches & Standards Risks Control The ASAE 3150 risk assessment process includes whether the enterprise has processes for: Identifying risks which threaten achievement of control objectives Estimating the significance of the risks Assessing the likelihood of their occurrence Deciding about actions to address those risks

IT Environment Controls IT Operations Management Controls IT System Controls IT Environment Controls IT Access Controls eg login, input, processing & output controls IT Change Management Controls IT Project Management Controls IT Operations Management Controls IT System Acquisition Controls eg SDLC Mgt Chapter 10 has more details & Examples by ERP Functions

Financial Analysis via Excel Modelling Lect 7 – Read through all good practice guideline when using Excel to perform financial analysis work Functions you must know: See URL to explain these logical functions used in IF statements: https://www.bing.com/videos/search?q=explanation+of+excel+logical+opertors&&view=detail&mid=66E174BC10A327A168D266E174BC10A327A168D2&FORM=VRDGAR Example 1 – see below Example 2 : http://www.excel-easy.com/vba/examples/logical-operators.html

Next Week – Specialised IT Risks Concepts Security & Fraud …. {Privacy}