How To Conduct a Control Self-Assessment

Slides:



Advertisements
Similar presentations
1 AUDIT AND AUDIT RESOLUTION Peg Rosenberry, Director of Grants Management Claire Moreno, Audit Liaison, Office of Grants Management 9/18/2009 AMERICORPS.
Advertisements

1 INTERNAL CONTROLS A PRACTICAL GUIDE TO HELP ENSURE FINANCIAL INTEGRITY.
The Islamic University of Gaza
Internal Control. COSO’s Framework Committee of Sponsoring Organizations 1992 issued a white paper on internal control Since this time, this framework.
Internal Control in a Financial Statement Audit
Presented By: Donna Denker, CPA Donna Denker & Associates.
Achieving our mission Presented to Line Staff. INTERNAL CONTROLS What are they?
Guidelines for constructing a Compliance Program for Medicaid Managed Care Organizations and PrePaid Health Plans As provided by the Medicaid Alliance.
Elements of Internal Controls Preventing Fraud, Waste, and Abuse in Urban and Rural Transit Systems.
Control environment and control activities. Day II Session III and IV.
Control and Accounting Information Systems
Central Piedmont Community College Internal Audit.
INTERNAL AUDIT vis-à-vis INTERNAL CONTROL
An Educational Computer Based Training Program CBTCBT.
Internal Controls Will Save You! (Or Save Your Money!)
Presented to President’s Cabinet. INTERNAL CONTROLS are the integration of the activities, plans, attitudes, policies and efforts of the people of an.
ARMICS Randy Sherrod, Internal Audit Manager – Department of Behavioral Health and Developmental Services.
Chapter 5 Internal Control over Financial Reporting
Internal Control in a Financial Statement Audit
Omni Circular Key Area #7: New Responsibilities of the Pass- Through Agency By Michael Brustein, Esq. Brustein & Manasevit, PLLC Spring.
Internal Control in a Financial Statement Audit
Subrecipient Monitoring and Common Findings By USDE Kristen Tosh Cowan, EsquireTiffany R. Winters, Esquire
The Audit as a Management Tool Vermont State Auditor’s Office – April 2009.
Brette Kaplan, Esq. Erin Auerbach, Esq. Brustein & Manasevit, PLLC Spring Forum 2013
Webinar for FY 2011 i3 Grantees February 9, 2012 Fiscal Oversight of i3 Grants Erin McHughJames Evans, CPA, CGFM, CGMA Office of Innovation and Improvement.
What Laws Apply to Federal Grants: A Historical Perspective Leigh M. Manasevit, Esq. Brustein & Manasevit, PLLC Fall Forum 2011.
Timeliness, Indirect Costs and Other Requirements Under Part 75 Leigh Manasevit, Esq. Brustein & Manasevit, PLLC Spring Forum 2015.
Risk Management & Corporate Governance 1. What is Risk?  Risk arises from uncertainty; but all uncertainties do not carry risk.  Possibility of an unfavorable.
College Reviews An Overview Presented by Howard Lutwak, CIA Director of Internal Audit January 2004.
DEVELOPING POLICIES AND PROCEDURES Brette Kaplan, Esq. Erin Auerbach, Esq. Brustein & Manasevit, PLLC Fall Forum.
A Guide for Management. Overview Benefits of entity-level controls Nature of entity-level controls Types of entity-level controls, control objectives,
Leigh Manasevit, Esq. Brustein & Manasevit, PLLC Fall Forum
Copyright © 2007 Pearson Education Canada 9-1 Chapter 9: Internal Controls and Control Risk.
Internal Controls For Municipalities Vermont State Auditor’s Office – August 2008.
McGraw-Hill/Irwin © The McGraw-Hill Companies 2010 Internal Control in a Financial Statement Audit Chapter Six.
Chapter 6 Internal Control in a Financial Statement Audit McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
Illinois Office of the Comptroller Financial Training Workshop 2016.
SUNY Maritime Internal Control Program. New York State Internal Control Act of 1987 Establish and maintain guidelines for a system of internal controls.
SUNY Maritime College Internal Control Program. New York State Internal Control Act of 1987 Establish and maintain guidelines for a system of internal.
Audit Findings.
Internal Control Principles
Internal Control.
Grants Management Test for State and Local Educational Agencies
THE FUNDAMENTALS OF FEDERAL GRANTS MANAGEMENT AND AUDIT RESOLUTION
Internal Control in a Financial Statement Audit
Understanding the Principles and Their Effect on the Audit
Allowability, Time & Effort Under the New EDGAR
How to Draft & Update Compliant Policies & Procedures
“Are You Ready for WIOA?”
Time and Effort Documentation Flexibility
Your Policies and Procedures are Compliant
The Importance of Subrecipient Monitoring
Defining Internal Control
Audits under the New EDGAR Uniform Grants Guidance
“The Georgia and Maine Stories” Impact on Recent Judicial Precedent on Federal Grants Management Michael Brustein, Esq. Bonnie Graham,
EDGAR OVERVIEW Michael L. Brustein, Esq.
Internal control - the IA perspective
Policies & Procedures A How-To Guide Bonnie Graham, Esq.
To Accountability…and Beyond
Internal controls 01-Nov-2017.
How to Conduct a Control Self- Assessment
Internal Controls Policies and Procedures
The Elements of appropriate Internal Controls
Managing Federal grants
EDGAR 201 Steven A. Spillan, Esq.
A Tutorial on Grants Management Rules Under EDGAR
What Laws Apply to Federal Grants: A Historical Perspective
Internal Control Internal control is the process designed and affected by owners, management, and other personnel. It is implemented to address business.
Good practices for risk assessment and control activities
Presentation transcript:

How To Conduct a Control Self-Assessment www.bruman.com Tiffany Kesslar, Esq., tkesslar@bruman.com

Brustein & Manasevit, PLLC © 2018. All rights reserved. In the News Jan 2018 Brustein & Manasevit, PLLC © 2018. All rights reserved.

Brustein & Manasevit, PLLC © 2018. All rights reserved. In the News Oct 2017 Brustein & Manasevit, PLLC © 2018. All rights reserved.

Brustein & Manasevit, PLLC © 2018. All rights reserved. In the News Oct 2017 Brustein & Manasevit, PLLC © 2018. All rights reserved.

Brustein & Manasevit, PLLC © 2018. All rights reserved.

What is a Control Self-Assessment? A management technique that reviews whether an organization's internal controls system is reliable. That is, an individual within an organization performs effectiveness testing to verify that key controls are functioning properly, resulting in the detection or elimination of weaknesses. Brustein & Manasevit, PLLC © 2018. All rights reserved.

Brustein & Manasevit, PLLC © 2018. All rights reserved. Back to Basics At what level of risk is your agency? Brustein & Manasevit, PLLC © 2018. All rights reserved.

Brustein & Manasevit, PLLC © 2018. All rights reserved. Keep It SIMPLE! Brustein & Manasevit, PLLC © 2018. All rights reserved.

Brustein & Manasevit, PLLC © 2018. All rights reserved. S – Set the Stage for Compliance (Control Environment) I – Inform Staff (and Others) of the Requirements (Information and Communications) M – Make Certain Problem Areas are Identified (Risk Analysis) P – Prioritize and Improve Weaknesses (Control Activities) L – Learn the Law E – Enforce the Rules (Monitoring) Brustein & Manasevit, PLLC © 2018. All rights reserved.

Set the Stage for Compliance Set tone that compliance is important and critical for success. Identify key goals and objectives that are specific, measurable, achievable, results-focused, and timely Includes policies re: how the agency wants to operate. Ensure you have an updated and accurate organizational chart. Each unit/office has identified mission, objectives, responsibilities. For example: budget planning, grant writing, payroll, program, etc. Clear job descriptions for staff within each office. Procedures for how each office operates. Make certain you have the proper people involved.  Brustein & Manasevit, PLLC © 2018. All rights reserved.

Set the Stage for Compliance Checklist Yes  No Management sets a good example and regularly communicates high expectations regarding integrity and ethical values. Management understands the policies covering potential conflicts of interest. The office has an updated organizational chart that clearly identifies lines of reporting.   The office has updated written policies and procedures related to all significant administrative processes specific to its operations. All employees are aware of their job responsibilities. Management holds personnel accountable for performing internal control responsibilities through mechanisms such as performance appraisals and disciplinary actions. Brustein & Manasevit, PLLC © 2018. All rights reserved.

Inform Staff (and Others) of the Requirements Ensure personnel receive relevant, reliable and timely information that enables them to carry out their responsibilities. or To communicate the right information to the right people at the right time! Include internal and external communications. Develop procedures for identifying pertinent information and distributing it in a form and timeframe that permits people to perform their duties efficiently. Clear message from top down. The single biggest problem with communication is the illusion that it has taken place.

Inform Staff (and Others) of the Requirements Checklist Yes  No Management obtains the relevant data from reliable internal and external sources in a timely manner.   Management communicates information throughout the entity using established reporting lines, ensuring that communication flows to all levels of the organization (down, across, up, and around). Management selects the appropriate method for communicating internally after considering the relevant factors (i.e., audience, nature of the information, etc.). Management selects the appropriate method for communicating externally after considering the relevant factors (i.e., audience, nature of the information, cost, etc.) Brustein & Manasevit, PLLC © 2018. All rights reserved.

Make Certain Problem Areas are Identified What can go wrong? How could we fail? How do we know whether we are achieving our objectives? On what information do we rely most heavily? What is our greatest legal exposure? Does past experience highlight any areas of particular concern (e.g., audit findings, fraud, in the news, etc.)? How do we currently handle these concerns, or do we?? Brustein & Manasevit, PLLC © 2018. All rights reserved.

Brustein & Manasevit, PLLC © 2018. All rights reserved.

Be Honest With Yourself! Brustein & Manasevit, PLLC © 2018. All rights reserved.

Make Certain Problem Areas are Identified Checklist Yes  No Management has a process for analyzing risks, including both inherent and residual risk, and considers internal and external risk factors. Management considers the types of fraud that can occur (e.g., fraudulent financial reporting, misappropriation of assets, corruption), as well as other forms of misconduct (such as waste and abuse).   Management identifies significant changes to internal and external conditions that have already occurred, or are expected to occur, and that could significantly impact the internal control system. Management analyzes and responds to identified changes and related risks in order to maintain an effective internal control system. Brustein & Manasevit, PLLC © 2018. All rights reserved.

Prioritize and Improve Weaknesses What do we currently have in place to prevent identified weaknesses? Training Approvals Authorizations Verifications Reconciliations Performance reviews Segregated duties Security measures Maintenance of appropriate documentation. To Improve the Weakness, the Control MUST Address the risk in question; Be required by the organization (i.e., addressed in policies and procedures); and Be embedded in the operational functions (e.g., has occurred within the last 12 months). Brustein & Manasevit, PLLC © 2018. All rights reserved.

Prioritize and Improve Weaknesses Checklist Yes  No Management promotes continuous improvement and solicits input and feedback from employees at all levels regarding issues that may impact the entire office. Policies exist that document the control activities utilized by the office.   Management considers segregation of duties in designing control activity responsibilities to help prevent fraud, waste, and abuse in the internal control system. Assets (e.g., equipment) are physically secured and periodically counted. All employees understand which records they must maintain and the required retention period. Management periodically reviews the control activities for effectiveness. Brustein & Manasevit, PLLC © 2018. All rights reserved.

Brustein & Manasevit, PLLC © 2018. All rights reserved. Learn the Law Training for Staff Certification/Grants Testing Legal Requirements EDGAR / Uniform Grants Guidance 2 CFR Part 200 USDE’s Internal Control Website: https://www2.ed.gov/policy/fund/guid/uniform-guidance/internal- controls.html Program Statutes, Regulations, and Rules State and Local Law Brustein & Manasevit, PLLC © 2018. All rights reserved.

Brustein & Manasevit, PLLC © 2018. All rights reserved. Learn the Law Checklist Yes  No Staff obtain training in areas relevant to their position to ensure an understanding of the rules and regulations applicable to their position. The agency conducts training on internal policies and procedures.   The agency obtains feedback from staff on professional development needs and considers feedback in decision-making. Brustein & Manasevit, PLLC © 2018. All rights reserved.

Brustein & Manasevit, PLLC © 2018. All rights reserved. Enforce the Rules Self-evaluations can be routine, periodic, or random. Regular oversight by supervisors Spot Checks Record reconciliation Ongoing program and fiscal monitoring Formal program reviews/audits Annual single audits If any review reveals that control activities do not satisfy the weakness, the severity of the problem should be described as well as the action steps being undertaken to resolve the issue(s). Brustein & Manasevit, PLLC © 2018. All rights reserved.

Brustein & Manasevit, PLLC © 2018. All rights reserved. Enforce the Rules Checklist Yes  No Management routinely spot-checks transactions, monitoring files, records, and reconciliations to ensure compliance. Budgets are compared to actual results and deviations are followed up on a timely basis.   Management periodically assesses the effectiveness of the organization structure and evaluates the appropriateness of policies and procedures. Management completes and documents corrective actions to remediate internal control deficiencies on a timely basis. Brustein & Manasevit, PLLC © 2018. All rights reserved.

Brustein & Manasevit, PLLC © 2018. All rights reserved. Documentation Brustein & Manasevit, PLLC © 2018. All rights reserved.

Brustein & Manasevit, PLLC © 2018. All rights reserved. Documentation is Key! Audits and Monitors only have the documentation to tell the story Reviewer can not reconstruct what has happened without documentation. Brustein & Manasevit, PLLC © 2018. All rights reserved.

Brustein & Manasevit, PLLC © 2018. All rights reserved. How Long? Retention Requirements For Records EDGAR – 2 CFR 200.333 Financial records, supporting documents, statistical records, and all other non-Federal entity records pertinent to a Federal award must be retained for a period of three years from the date of submission of the final expenditure report. GEPA - Statute of Limitations 34 CFR 81.31(c) 5 year Statute of Limitations Timeline runs from the date of obligation. (Appeal of the State of Michigan) Brustein & Manasevit, PLLC © 2018. All rights reserved.

How Maintain Documentation? Electronic records do not need to be printed. UGG Section 200.335 Paper records may be made electronic, provided: They are subject to periodic quality control reviews; There are reasonable safeguards against alteration; and The documents remain readable. Brustein & Manasevit, PLLC © 2018. All rights reserved.

Know Where your Documents Are?

Documentation HOT BUTTON Issues Are records kept by school, grant, fiscal year? Do you backup documentation? Where and how often? What happens when staff retire or voluntarily leave? What happens when staff are fired? What happens when a school closes? Staff keep documentation at home? Brustein & Manasevit, PLLC © 2018. All rights reserved.

Brustein & Manasevit, PLLC © 2018. All rights reserved. How Would You Score? Brustein & Manasevit, PLLC © 2018. All rights reserved.

Brustein & Manasevit, PLLC © 2018. All rights reserved. Disclaimer This presentation is intended solely to provide general information and does not constitute legal advice or a legal service.  This presentation does not create a client-lawyer relationship with Brustein & Manasevit, PLLC and, therefore, carries none of the protections under the D.C. Rules of Professional Conduct.  Attendance at this presentation, a later review of any printed or electronic materials, or any follow-up questions or communications arising out of this presentation with any attorney at Brustein & Manasevit, PLLC does not create an attorney-client relationship with Brustein & Manasevit, PLLC.  You should not take any action based upon any information in this presentation without first consulting legal counsel familiar with your particular circumstances. Brustein & Manasevit, PLLC © 2018. All rights reserved.