COSO Internal Control s Framework

Slides:



Advertisements
Similar presentations
Internal Control–Integrated Framework
Advertisements

Federal Audit Executive Council (FAEC) June 2012 Bi-Monthly Meeting Heather I. Keister Doris G. Yanger June 14, 2012 Green Book Update.
Chapter 10 Accounting Information Systems and Internal Controls
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
Control and Accounting Information Systems
Internal Control.
1 Sarbanes-Oxley Section 404 June 29,  SOX 404 Background 3  SOX 404 Goals 4  SOX 404 Requirements 5  SOX 404 Assertions 6  SOX 404 Compliance.
Government Auditing Standards
Office of the Secretary of Defense – Comptroller Financial Improvement and Audit Readiness Directorate Unclassified 17 September 2014 GAO Revised “Green.
Standards for Internal Control in the Government Going Green Standards for Internal Control in the Federal Government 1.
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
Standar Pekerjaan Lapangan: Pemahaman Memadai atas Pengendalian Intern Pertemuan 5.
6-1 McGraw-Hill/Irwin ©2002 by The McGraw-Hill Companies, Inc. All rights reserved. Chapter 6 Internal Control Evaluation: Assessing Control Risk.
Internal Control. COSO’s Framework Committee of Sponsoring Organizations 1992 issued a white paper on internal control Since this time, this framework.
18- 1 © 2006 The McGraw-Hill Companies, Inc., All Rights Reserved. Chapter 18 Integrated Audits of Internal Control (For Public Companies Under Sarbanes-Oxley.
Internal Control. COSO’s Framework Committee of Sponsoring Organizations 1992 issued a white paper on internal control Since this time, this framework.
Purpose of the Standards
Sarbanes-Oxley Project Summary of COSO Framework Presented by Larry Dillehay & Scott Reitan Parkfield Group LLC.
COSO Framework Update IIA Columbus Chapter May 17, 2013
Chicagoland IASA Spring Conference
Internal Auditing and Outsourcing
Auditing Internal Control over Financial Reporting
Chapter 9: Introduction to Internal Control Systems
Chapter 3 Internal Controls.
Transitioning to the COSO 2013 Update.  Released on May 14, 2013  Designed to build upon the foundation of the 1992 Framework  Will supersede the 1992.
This Lecture Covers Review of Internal Control Definitions.
Chapter Three IT Risks and Controls.
Internal controls. Session objectives Define Internal Controls To understand components of Internal Controls, control environment and types of controls.
Chapter 5 Internal Control over Financial Reporting
Monitoring Internal Control Systems Johann Rieser Senior Auditor, Ministry of Finance, Vienna.
Introduction In 1992, the Committee Of Sponsoring Organizations of the Treadway Commission (COSO) published Internal Control-Integrated Framework (1992.
Internal Control in a Financial Statement Audit
Standards for Internal Control in the Government Going Green Standards for Internal Control in the Federal Government 1.
Learning Objectives LO5 Illustrate how business risk analysis is used to assess the risk of material misstatement at the financial statement level and.
Chapter 9: Introduction to Internal Control Systems
An Update of COSO’s Internal Control–Integrated Framework
Internal Control Systems
S5: Internal controls. What is Internal Control Internal control is a process Internal control is a process Internal control is effected by people Internal.
Copyright © 2007 Pearson Education Canada 9-1 Chapter 9: Internal Controls and Control Risk.
1 Overview of PCAOB Auditing Standard No. 5 An Audit of Internal Control Over Financial Reporting that is Integrated with an Audit of Financial Statements.
Meet the New ICIF: Revisions to COSO’s Internal Control Integrated Framework Dr. Sandra Richtermeyer COSO Board Member Associate Dean and Professor.
1 COSO ERM Framework Update Our Next Challenge and Opportunity September 2015.
Lecture 5 Control and AIS Copyright © 2012 Pearson Education 7-1.
Chapter 6 Internal Control in a Financial Statement Audit McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
©2005 Prentice Hall Business Publishing, Auditing and Assurance Services 10/e, Arens/Elder/Beasley Internal Control and Control Risk Chapter 10.
Auditors’ Dilemma – reporting requirements on Internal Financial Controls under the Companies Act 2013 and Clause 49 of the Listing agreement V. Venkataramanan.
Internal Control Chapter 7. McGraw-Hill/Irwin © 2008 The McGraw-Hill Companies, Inc., All Rights Reserved. 7-2 Summary of Internal Control Definition.
SUNY Maritime Internal Control Program. New York State Internal Control Act of 1987 Establish and maintain guidelines for a system of internal controls.
Modern Auditing: Assurance Services and the Integrity of Financial Reporting, 8th Edition William C. Boynton California Polytechnic State University at.
Internal Control Evaluation: Assessing Control Risk
Internal Control in a Financial Statement Audit
Understanding the Principles and Their Effect on the Audit
PEM PAL IA COP Internal Control Working Group COSO Principles
Internal control objectives
اطار الرقابة الداخلية و فقا للجنة دعم المنظمات COSO
Internal Audit & Enterprise Risk Management
Office of Internal Audits
A Framework for Control
Building the Foundation of Compliance
Internal Control–Integrated Framework
Building the Foundation of Compliance
Internal control - the IA perspective
Alignment of COBIT to Botswana IT Audit Methodology
Revision of the Internal Control Framework in the European Commission PEMPAL Internal Audit Community of Practice (IACOP) Brussels, 27th February 2017.
Internal Controls Policies and Procedures
The control environment
An Update of COSO’s Internal Control–Integrated Framework
Leveraging COSO across the three lines of defense
An overview of Internal Controls Structure & Mechanism
Presentation transcript:

COSO Internal Control s Framework Understanding COSO 2013 Key Principles for Auditing Internal Controls Based on Executive’s Guide to COSO Internal Controls By Robert Moeller 11/14/2018 COSO Internal Control s Framework

Objectives of this AGA Seminar Session To discuss the importance of internal controls for all manual and IT systems and processes To reintroduce the original 1992 COSO internal controls framework Describe the new, recently revised COSO Internal Controls Framework Outline COSO’s 17 internal control principles and why they are important for establishing internal controls. Using COSO internal controls in operational and financial internal audits. 11/14/2018 COSO Internal Controls Framework

Early Definitions of Internal Control -- A common internal and external audit expression, but there was no consistent definition. -- Things changed with financial scandals of the 1970’s, resulting in the FCPA and other attempts to better define the concept. -- After SEC moves to better define the process, the AICPA, IIA, FEI. AAA. And IMA pitched in. -- They formed the Committee of Sponsoring Organizations (COSO) of the Treadway Commission that released a definition or framework to define internal control in 1992. 11/14/2018 COSO Internal Controls Framework

COSO 1992 Definition of Internal Control Internal control is a process affected by an entity’s board of directors, management and other personnel, designed to provide reasonable assurance regarding the achievement of objectives in the following categories: -- Effectiveness and efficiency of operations -- Reliability of financial reporting -- Compliance with applicable laws and regulations. 11/14/2018 COSO Internal Controls Framework

Original 1992 Framework COSO Internal Controls 11/14/2018 COSO Internal Controls Framework

The 1992 COSO Framework Today COSO internal controls became a Sarbanes-Oxley requirement and has been accepted world-wide IT processes have changed considerably since 1992 – the original framework dates to the days of mainframe systems and no Internet Many changes and greater complexities in business operations with increased globalization of markets and operations Increased laws, rules and standards Original framework gave little attention to fraud detection, risk management, or enterprise governance. COSO is a Framework, not a standard or requirement. Serving as a measure for building effective internal control processes, the 1992 COSO Internal Controls framework was finally revised in 2014 11/14/2018 COSO Internal Controls Framework

December, 2014 Implementation Requirement The New, Revised COSO Internal Controls Framework Authored by PwC under direction of COSO Board Draft framework released in 2012 followed with extensive reviews Final release in May, 2013 with 3 companion elements. December, 2014 Implementation Requirement 11/14/2018 COSO Internal Control s Framework

COSO Internal Controls Framework The Revised COSO Internal Controls Framework Looks similar but with subtle changes. 11/14/2018 COSO Internal Controls Framework

The Revised COSO Framework What has Changed Emphasis on financial and nonfinancial controls Addresses internal and external financial reporting Focus on 17 internal control principles including the: Control Environment Risk Assessment Internal Control Activities Information and Communication Needs Internal Control Monitoring Activities Needs to better consider the three-dimensioned nature of overlapping internal controls Emphasis on Governance, Risk and Compliance (GRC) concepts. 11/14/2018 COSO Internal Controls Framework

COSO’s 17 Internal Control Principles Going beyond the general concepts in the original 1992 framework, an entity should demonstrate that they have effective internal controls in place for each of 17 identified principles areas. Each of these Principles should be operating and in place for the GRC internal control elements shown on the top of the COSO cube. The principles apply to all levels of business units from the overall entity to separate departments, as shown on the right side of the cube. 11/14/2018 COSO Internal Controls Framework

COSO Internal Control Relationships 11/14/2018 COSO Internal Controls Framework

COSO’s 17 Internal Control Principles The Control Environment 1. Commitment to integrity and ethical values 2. Independent board of directors oversight 3. Structures, reporting lines, authorities and responsibilities 4. Attract, develop and retain competent people 5. People held accountable for internal control 11/14/2018 COSO Internal Controls Framework

COSO’s 17 Internal Control Principles Risk Assessment 6. Clear objectives specified 7. Risks identified to achievement of objectives 8. Potential for fraud considered 9. Significant changes identified and assessed 11/14/2018 COSO Internal Controls Framework

COSO’s 17 Internal Control Principles Control Activities 10. Control activities selected and developed 11. General IT controls selected and developed 12. Controls developed through policies and procedures 11/14/2018 COSO Internal Controls Framework

COSO’s 17 Internal Control Principles Information and Communication 13. Quality information obtasined, generated and used 14. Internal control information internally communicated 15. Internal information externally communicated 11/14/2018 COSO Internal Controls Framework

COSO’s 17 Internal Control Principles Monitoring Activities 16. Ongoing and/or separate evaluations conducted 17. Internal control deficiencies evaluated and communicated. 11/14/2018 COSO Internal Controls Framework

COSO’s 17 Internal Control Principles and the ISACA Professional … COSO is more than financial reporting controls … Relate these principles, as appropriate, to IT securitz and internal control issues … Ascertain that all SOX intenal control reviews are consistent with these principles 11/14/2018 COSO Internal Controls Framework

The COSO Framework from a Different Perspective . 11/14/2018 COSO Internal Controls Framework

GRC Governance Elements An Important Part of COSO Internal Controls 11/14/2018 COSO Internal Controls Framework

COSO Internal Controls and Internal Audit Internal auditors should take a hard look at their existing audit processes to determine that internal controls are adequately authorized, installed and tested COSO’s 17 Principles are important. Make certain they are installed and effective as part of virtually all operational and financial internal audit reviews The COSO framework is integrated over three dimensions. Internal audit should plan audits that are not just focused on one narrow area or objective but should broaden audit scopes to reflect the COSO framework. I 11/14/2018 COSO Internal Controls Framework

COSO Internal Controls and Other Standards The revised internal controls does not impact COSO ERM (Enterprise Risk Management). The two frameworks will continue to exist in a parallel manner. The COSO internal control framework ’s 17 Principles are important. Make certain they are installed and effective as part of virtually all operational and financial internal audit reviews COBIT maps very well to the revised COSO framework. Consider using COBIT for internal control assessments. 11/14/2018 COSO Internal Controls Framework

COSO Internal Controls Framework 11/14/2018 COSO Internal Controls Framework

COSO Implementation Requirements Per COSO, enterprises should transition their applications and documentation to the 2013 framework “as soon as possible” Time is now short as the 1992 framework will be considered superseded after December 15, 2014 Compliance with the revised COSO framework is tied to an entity’s Sarbanes-Oxley internal control assertions Whether large or small, the new COSO framework will mean at least some additional work for internal auditors, their audit committees, and senior management. 11/14/2018 COSO Internal Controls Framework

Other COSO Implementation Issues The revised internal controls framework is closely aligned with ITIL Service Management best practices. The revised COSO framework presents a better fit to appropriate ISO standards. There have been no changes to the COSO Enterprise Risk Management (ERM) framework with the revised COSO Internal Controls. . 11/14/2018 COSO Internal Controls Framework

Updated COSO Framework Importance for Audit Professionals ... March 26 ISACA Press elease described the importance of integrating COSO with COBIT 5 ... The IIAs Career Compass March newsletter discussed the Importance of Rising to the Challenge for the new COSO framework Bottom Line ... Get up to Speed 11/14/2018 COSO Internal Control s Framework

Remember! COSO Enterprise Risk Management Framework Objectives Risk Components Entity & Unit Level Components

Questions and Comments Robert Moeller rmoelle@ameritech.net 11/14/2018 COSO Internal Controls Framework