Sarbanes Section 404 Readiness

Slides:



Advertisements
Similar presentations
Gary R. McGuire, CIA, CPA Vice President, Group Audit Services Alcatel Americas.
Advertisements

Garrett L. Stauffer, CPA Partner PricewaterhouseCoopers LLP.
IT Considerations in Integrated Audit By: Yusuf Musaji.
Development of internal control: methodology and responsibility
Dave Richards, CIA, CPA Director, Internal Auditing FirstEnergy Corporation.
1 Introduction of Panel Members Sarbanes-Oxley Section 404 Overview Insert Worlds Image / Client Specific Image Here Scott Henderson
ProCognis SOX 404 & COSO Implementation Presentation
COMPLYING WITH SARBANES- OXLEY SECTION 404: MANAGEMENT’S ASSESSMENT OF THE ACTUARIAL CONTROL ENVIRONMENT Brian Reilly, Senior Vice President & Chief Auditor.
Internal Control. COSO’s Framework Committee of Sponsoring Organizations 1992 issued a white paper on internal control Since this time, this framework.
Internal Control in a Financial Statement Audit
Internal Control. COSO’s Framework Committee of Sponsoring Organizations 1992 issued a white paper on internal control Since this time, this framework.
1 What is Internal Audit’s Role in Management’s Assertion The Institute of Internal Auditors May 11, 2004 Xenia Ley Parker, CIA, CISA, CFSA Principal XLP.
INTERNAL CONTROL OVER FINANCIAL REPORTING
® SOX Overview MTAC Meeting August 7, The Sarbanes-Oxley Act  Enacted in 2002 as a result of a series of large corporate financial scandals  Improves.
Vendor Risk: Effective Management is Essential
Chicagoland IASA Spring Conference
BIS310: Structured Analysis and Design Introduction and Systems Planning Week 1.
Service Organization Control (SOC) Reporting Options and Information
The Sarbanes-Oxley Act of PricewaterhouseCoopers Introduction of Panel Members The Sarbanes-Oxley Act of 2002 What Companies Should Be Doing Now.
PwC Internal Control Reports: Facts, Myths and Best Practices FIRMA National Risk Management Training Conference – San Francisco, CA Wednesday March 31,
INTERNAL CONTROL OVER FINANCIAL REPORTING
Implementation Issues of Sarbanes-Oxley CASE Presentation September 23, 2004 By Denise Farnan.
Chapter 5 Internal Control over Financial Reporting
Page 1 Internal Audit Outsourcing The Moss Adams Approach to Internal Audit Outsourcing Proposed SOX 404 Changes.
CDS Operational Risk Management - October 28, 2005 Existing Methodologies for Operational Risk Mitigation - CDS’s ERM Program ACSDA Seminar - October 26.
Internal Control in a Financial Statement Audit
Learning Objectives LO5 Illustrate how business risk analysis is used to assess the risk of material misstatement at the financial statement level and.
Scandals (in the public and private sector)  Enron  Worldcom  Livent  Nortel  HRDC  Sponsorship Scandal.
1 Today’s Presentation Sarbanes Oxley and Financial Reporting An NSTAR Perspective.
Richard F. Chambers, CIA, CGAP Vice President, IIA Learning Center The Institute of Internal Auditors.
Introduce yourself Explain fire procedures etc.
SVP and General Auditor
CHAPTER 5 INTERNAL CONTROL OVER FINANCIAL REPORTING.
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin 7-1 Chapter Seven Auditing Internal Control over Financial Reporting.
ISMS Implementation Workshop Adaptive Processes Consulting Pvt. Ltd.
Acumen insight ideas attention reach expertise depth agility talent SAS 70 – Readiness Kick-off Presented by Rod Walsh.
Primary Steps for Achieving ISO Certification.
Internal Control. McGraw-Hill/Irwin © 2004 The McGraw-Hill Companies, Inc., All Rights Reserved. 7-2 Summary of Internal Control Definition A process...designed.
Chapter 6 Internal Control in a Financial Statement Audit McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
Auditors’ Dilemma – reporting requirements on Internal Financial Controls under the Companies Act 2013 and Clause 49 of the Listing agreement V. Venkataramanan.
IMS Implementation Project
Modern Auditing: Assurance Services and the Integrity of Financial Reporting, 8th Edition William C. Boynton California Polytechnic State University at.
Kick starting your due diligence programme
Internal Control in a Financial Statement Audit
CPA Gilberto Rivera, VP Compliance and Operational Risk
Audit of predetermined objectives
ACG 4671 Internal Auditing.
14th CAS meeting Performance reporting Presentation by SAI-SA
Quality Management in Business and Manufacturing Sectors
IIASA Governance Review
Internal Control in a Financial Statement Audit
Internal control objectives
Chapter 4 Systems Planning and Selection
Chapter 13 Overall Audit Plan and Audit Program
Building the Foundation of Compliance
Understanding the entity
INTRODUCTION TO Compliance audit METHODOLGY and CAM
Internal Control & Sarbanes-Oxley Act
Building the Foundation of Compliance
COSO Internal Control s Framework
Sarbanes-Oxley Act (404) An IT Viewpoint
Chapter 13 Overall Audit Plan and Audit Program
SVP and General Auditor
Quality Management in Business and Manufacturing Sectors
An IT Viewpoint Darin Kreimeyer, Senior Manager Newel Linford, Manager
An overview of Internal Controls Structure & Mechanism
Good practices for risk assessment and control activities
Process and Procedure Documentation
Audit.
Presentation transcript:

Sarbanes Section 404 Readiness Building a Sustainable Internal Control Assessment Process

Methodology Plan the Project Make Key Scope Decisions Assess Your Control Environment Build a Controls Repository Perform Initial and Ongoing Tests Monitor Make Key Scope Decisions Plan the Project Assess Your Control Environment Make Key Scope Decisions Build a Controls Repository Perform Initial and Ongoing Tests Monitor Make key sope decisions consists of: Project planning, prioritize, map key components

Planning - Start with the End in Mind Consider a process that will support both Section 302 and 404 certifications Key Activities: Perform an informal assessment of your current state Decentralized vs. centralized operations Existing control conditions Support from the top? Form a Steering Committee Gain Audit Committee/Board support Questions to Consider: What are the education and training needs of your company? Will a self-assessment process be successful in your environment? What technology will support your recurring internal control assessments?

Key Scoping Decisions Project Approach: Prioritize Activities: SWAT Team or Delegated Responsibility? Resources, Internal and/or External Phased approach or simultaneous coverage? Define Deliverables Cost and Timetable Prioritize Activities: Defining “Materiality” or “key business processes” Assess current stage of control reliability Identify and inventory relevant risks

Defining Critical Business Processes Material financial statement line item or large $ spend Business Process Yes No Critical to achievement of major goals and objectives of the business Yes Key Business Process ! No Process not selected for review Relates specifically to compliance or disclosure under GAAP, SEC, or laws The focus of the Auditing Services project was the identification and documentation of existing control activities and gaps within the AWS baseline internal control structure. Baseline controls represent the bare minimum set of procedures required for an effective internal control system. The baseline control activities identified by this project should not be considered an all inclusive list of controls. Additional control activities may be warranted to improve the effectiveness and efficiency of a given business process. The methodology outlined below was applied to select the key business processes to be reviewed in this project. The same methodology was applied to identify baseline control activities and gaps within the key business processes. Yes No No Critical to achievement of financial control assertions Yes

Build Controls Repository Define key control objectives Map existing control activities against control objectives Conclude – Is control objective satisfied? Flowcharts, process maps or process descriptions – tying the pieces together Do flowcharts, process maps or process descriptions exist? Are they required?

Controls Repository Work may be required at the individual business process or sub-process level Control objectives identification is a Critical step for auditor buy-in Control activities – integrating both manual and automated/application controls in documentation exercise

Agenda 1:00 - 1:10 Introduction & Overview of Annual Certification of Controls - Dave Richards 1:10 - 1:17 Methodology - Sheryl Hildebrand 1:17 - 1:24 Testing the Controls - Gary McGuire 1:24 - 1:30 FDIC Certification Experience - Brian Szabo 1:30 - 1:45 External Auditor Attestation - Gary Stauffer 1:45 - 1:50 Break 1:50 - 2:25 Questions & Answers - Panel 2:25 - 2:30 Concluding Remarks - Dave Richards