Arising Importance of Audit due to Present Economic Developments Korcan DEMİRCİOĞLU, Ph-D Supervisor Auditor, Garanti Bank.

Slides:



Advertisements
Similar presentations
PRESENTATION ON MONDAY 7 TH AUGUST, 2006 BY SUDHIR VARMA FCA; CIA(USA) FOR THE INSTITUTE OF INTERNAL AUDITORS – INDIA, DELHI CHAPTER.
Advertisements

Control and Accounting Information Systems
Sodexo.com Group Internal Audit. page 2 helps an organization accomplish its objectives by bringing a systematic, disciplined approach to evaluate and.
Welcome! Internal Auditing CHAPTER 1. Definition Internal auditing is an independent, objective, assurance and consulting activity designed to add value.
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
Institute of Municipal Finance Officers & Related Professions
9.401 Auditing Chapter 1 Introduction. Definition of Auditing The accumulation and evaluation The accumulation and evaluation Of evidence about information.
6-1 McGraw-Hill/Irwin ©2002 by The McGraw-Hill Companies, Inc. All rights reserved. Chapter 6 Internal Control Evaluation: Assessing Control Risk.
Internal Control. COSO’s Framework Committee of Sponsoring Organizations 1992 issued a white paper on internal control Since this time, this framework.
18- 1 © 2006 The McGraw-Hill Companies, Inc., All Rights Reserved. Chapter 18 Integrated Audits of Internal Control (For Public Companies Under Sarbanes-Oxley.
Quality evaluation and improvement for Internal Audit
Office of Inspector General (OIG) Internal Audit
Internal Audits, Governmental Audits, and Fraud Examinations
Internal Control and Internal Audit
Purpose of the Standards
Nature of an Integrated Audit
ISA 220 – Quality Control for Audits of Historical Financial Information
The Role of Risk Management and Assurance in Effective Organizational Governance Urton Anderson The University of Texas at Austin.
Arising Importance of Audit due to Present Economic Developments
Risk Based Internal Audit in Banks
Auditing Standards IFTA\IRP Audit Guidance Government Auditing Standards (GAO) Generally Accepted Auditing Standards (GAAS) International Standards on.
Internal Auditing and Outsourcing
Compliance & Internal Auditing By David N. Ricchiute
Central Piedmont Community College Internal Audit.
D-1 McGraw-Hill/Irwin ©2005 by the McGraw-Hill Companies, Inc. All rights reserved. Module D Internal, Governmental, and Fraud Audits “I predict that audit.
Internal Auditing & Management Control ACCT 620 Otto Chang Professor of Accounting.
C. P. Mansoor S. Ahmed M. Com, PGDBA.  Not confined to Independent Audit  Systematic Examination of  Records  Procedures  Systems  Operations.
The Institute of Internal Auditors
Chapter 3 Internal Controls.
Session 3 & 4. Institute of Internal Auditors Inc (IIA) was created for internal auditors in 1941 Generally accepted criteria of a profession are: –Adopting.
Internal Audit Role in Order to Develop an Ethical Corporate Culture as a Competitiveness Factor A.I.I.A. - Internal Auditing body Università degli Studi.
Planning an Audit The Audit Process consists of the following phases:
CDS Operational Risk Management - October 28, 2005 Existing Methodologies for Operational Risk Mitigation - CDS’s ERM Program ACSDA Seminar - October 26.
Internal Control in a Financial Statement Audit
Chapter 14 Internal auditing 14-1 Copyright  2010 McGraw-Hill Australia Pty Ltd PPTs t/a Auditing and Assurance Services in Australia 4e by Grant Gay.
NO FRAUD LEFT BEHIND The Effect of New Risk Assessment Auditing Standards on Schools Runyon Kersteen Ouellette.
1 Today’s Presentation Sarbanes Oxley and Financial Reporting An NSTAR Perspective.
Private & Confidential1 (SIA) 13 Enterprise Risk Management The Standard should be read in the conjunction with the "Preface to the Standards on Internal.
The Connection between Risk Management and Internal Control in Organizations Mag. Norbert Wagner Budapest,
Practice Management Quality Control
Copyright © 2007 Pearson Education Canada 1 Chapter 1: The Demand for Auditing and Assurance Services.
Copyright © 2007 Pearson Education Canada 1 Chapter 24: Assurance Services: Internal Auditing and Government Auditing.
Chapter 21 Internal, Operational, and Compliance Auditing McGraw-Hill/IrwinCopyright © 2014 by The McGraw-Hill Companies, Inc. All rights reserved.
1 Internal Audit. 2 Definition Is an independent activity established by management to examine and evaluate the organization’s risk management processes.
Risk Management & Corporate Governance 1. What is Risk?  Risk arises from uncertainty; but all uncertainties do not carry risk.  Possibility of an unfavorable.
Copyright © 2013 by The McGraw-Hill Companies, Inc. All rights reserved.McGraw-Hill/Irwin.
McGraw-Hill/Irwin © 2003 The McGraw-Hill Companies, Inc., All Rights Reserved. 6-1 Chapter 6 CHAPTER 6 INTERNAL CONTROL IN A FINANCIAL STATEMENT AUDIT.
International Security Management Standards. BS ISO/IEC 17799:2005 BS ISO/IEC 27001:2005 First edition – ISO/IEC 17799:2000 Second edition ISO/IEC 17799:2005.
Internal/External Audit and Internal Controls February 23, 2000 David Dudley Federal Reserve Bank of NY.
McGraw-Hill/Irwin © The McGraw-Hill Companies 2010 Auditing Internal Control over Financial Reporting Chapter Seven.
Copyright © 2007 Pearson Education Canada 9-1 Chapter 9: Internal Controls and Control Risk.
18-1 Copyright © 2016 McGraw-Hill Education. All rights reserved. No reproduction or distribution without the prior written consent of McGraw-Hill Education.
Copyright © 2015 McGraw-Hill Education. All rights reserved. No reproduction or distribution without the prior written consent of McGraw-Hill Education.
Deck 5 Accounting Information Systems Romney and Steinbart Linda Batch February 2012.
Internal Audit Section. Authorized in Section , Florida Statutes Section , Florida Statutes (F.S.), authorizes the Inspector General to review.
1 Vereniging van Compliance Officers The Compliance Function in Banks Amsterdam, 10 June 2004 Marc Pickeur CBFA CBFA.
Lecture 5 Control and AIS Copyright © 2012 Pearson Education 7-1.
Chapter 6 Internal Control in a Financial Statement Audit McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
Auditors’ Dilemma – reporting requirements on Internal Financial Controls under the Companies Act 2013 and Clause 49 of the Listing agreement V. Venkataramanan.
Internal Control Principles
The Demand for Audit and Other Assurance Services
Internal and Governmental Financial Auditing and Operational Auditing
Kode Etik dan IA Standard Dr Rilla Gantino, SE., AK., MM
Following Up on Internal Audit Reports Workshop on IIA Standard 2500
Internal control - the IA perspective
Adding Value Across the Board
Taking the STANDARDS Seriously
Internal Audit’s Role in Preventing Fraud and Corruption
An overview of Internal Controls Structure & Mechanism
Presentation transcript:

Arising Importance of Audit due to Present Economic Developments Korcan DEMİRCİOĞLU, Ph-D Supervisor Auditor, Garanti Bank

2 Agenda 1.Definition and Components of Internal Audit 2.International Standards and Regulations about Internal Audit 3.Effects of Economic Crisis and Technological Improvements 4.New Trends and Changing Role of Internal Audit

Definition and Components of Internal Audit

4 Definition of Internal Audit Internal audit helps an organization to accomplish its objectives by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of risk management, control, governance processes. Internal Audit is an independent, objective assurance and consulting activity designed to add value and improve an organization's operations.

5 Corporate Governance Corporate governance is a general system which promotes enterprise orientation and control structure. As generally accepted international corporate governance understanding involves; Equality, Transparency, Accountability and Liability.

6 Risk Management Risk management is a process which satisfies appropriate transition or exchange between risk and yield and adds “value” to the organization. Risk management concerns all departments. IDENTIFICATION OF RISKS PRIORITIZATION OF RISKS TAKING NECESSARY ACTIONS 1. Identification of Risks Defining the risks Measuring the risks Analysis the risks Reporting 3. Taking Necessary Actions Acceptance Transferring Controlling 2. Prioritization of Risk Probability of the Risk Severity of the Risk

7 Internal Control Control is one of the actions which are taken to mitigate the effects of the risks in terms of;  Safeguarding of assets,  Compliance with laws, regulations, and aggrements,  Reliability and integrity of financial and operational information,  Effectiveness and efficiency of operations. Basic Control Activity Examples are;  Authorization Methods  Limit Applications  Decompositions of Tasks  Policy and Procedures  Task Descriptions and Responsibilities  Reconcilement Methods

International Standards and Regulations about Internal Audit

9 Regulations about Internal Audit Regulations in Turkey numbered Banking Law - Arrangements of BRSA - Arrangements of Capital Markets Boards Of Turkey International Regulations - Regulations by Basel Committee - Regulations by Professional Associations (IFAC, IICPA, etc.)

10 Standards of Internal Audit A. ATTRIBUTE STANDARDS Purpose, Authority and Responsibilities Independency and Objectiveness Proficiency and Due Professional Care Quality, Assurance and Improvement Program B. PERFORMANCE STANDARDS Management of Internal Audit Activities Quality of Work Engagement Planning Performing Engagement Reporting Results Observing Developments Acceptance of Residual Risks by Management

11 Purpose, Authority and Responsibilities Purpose, authority and responsibilities of internal audit activities should be obviously declared in the charter. Independence and Objectivity  Organizational Independence  Individual Objectivity  Impairment to Independence or Objectivity Proficiency and Due Professional Care  Proficiency Requires the knowledge, skills and other competencies needed to perform individual responsibilities.  Due Professional Care The care and the skill expected of a reasonably prudent and competent internal auditor. Due professional care does not imply infallibility.  Continuing Professional Development Enhancement of knowledge, skills, and other competencies through continuing professional development. Attribute Standards

12 The Internal Audit Activity Management The chief audit executive must effectively manage the internal audit activity to ensure it adds value to the organization.  Planning  Communication and Approval  Resource Management  Policies and Procedures  Coordination  The Board of Directors, Internal Audit Committee and Reporting to Top Management Performance Standards

13 Engagement Planning Engagement Objectives: Setting the engagement objectives, internal auditors should: Identify and assess risks relevant to the activity under review and the engagement objectives must reflect the results of this assessment, Consider the probability of significant errors, fraud, noncompliance, and other exposures when developing the engagement objectives. Consulting engagement objectives should address risks, controls and governance processes to the extent agreed upon with the client. Scope of Engagement: The established scope must be sufficient to satisfy the objectives of the engagement. The scope of the engagement must include consideration of relevant systems, records, personnel, and physical properties, including those under the control of third parties. Engagement Resource Allocation: Internal auditors must determine appropriate and sufficient resources to achieve engagement objectives based on a plan regarding the below mentioned issues: -an evaluation of the nature of engagement, -complexity of engagement, -time constraints, -available resources. Performance Standards

14 Performing the Engagement Internal auditors must identify, analyze, evaluate, and document sufficient information to achieve the engagement's objectives. Recording Information Internal auditors must document the relevant information to support the conclusions and engagement results. Thus, it would be beneficial that the Internal auditors prepare working papers. Performance Standards

15 Communication of the Engagement Results CHIEF AUDIT EXECUTIVE (CAE) BRSA (BDDK) AUDIT COMMITTEE BOARD OF DIRECTORS Periodic Activity Report Informative Memos about the Annual Activities of the Internal Audit Annual Report and Informative Memo Performance Standards

16 Monitoring Progress The chief audit executive,  Must establish and maintain a system to monitor the disposition of results communicated to management,  Must establish a follow-up process to monitor and ensure that management actions have been effectively implemented,  Or that senior management has accepted the risk of not taking action (namely, residual risk). Performance Standards

Effects of Economic Crisis and Technological Developments

18 Important Corporations Which are Negatively Affected or Failed During the Last Crisis October 07 January 08 June 08 September 08

19 Developments After Crisis What's Expected?  Reconstruction of the Global Banking System,  Regulated Market Economy instead of Free Market Economy– Establishing New Audit/Control System,  Elimination of Weaknesses of Risk Management,  Improvement in the Credit Rating Agencies’ Applications,  New Regulations and Regulatory Institutions in Financial Markets.

20 Developments After Crisis Increasing Importance of Audit  Differentiation in Audit Methodologies  Monitoring Audit Results  Attributions and Adequacy of Auditors Lessons to Take  Risk must be “respected”. Risk management function should be seen equally important as the other functions in Banks, and not be described as a ‘back office’ function.  Risk analysis is an important part of modern risk management. On the other hand, models all alone are not sufficient.  There is limit to regulations.  If the level of exaggerated debts seem to be good in an unbelievable way, then it is really unbelievable. The U.S. banks owned tools which they used mainly to remove their credits from their balance-sheets, their leverage ratios were as much as 600 to 1.  Accounting change everything. The accounting methodology of the credit assets according to the market value (mark to market) increased the volatility in reported losses nearly 50% during the depression period. Accounting must be accounting. There should not be any creative accountancy.  Audit activity should be as much effective as its results are considered.  Volume based promotion redoubles the risk appetite.

21 Queries Rating Agencies  What are the standard method for working and decision-making?  How transparent and accountable they are ?  How much their approach and reviews are objective?  These organizations and their reports on global and local base who checks?  The scale of grading the company reflex (reaction time) what should it be?

22 Queries Risk Management and Risk Management Models  How risk management is proactive ?  Did the Risk management was located in the right position within the bank ?  Risk Management Models How applicable it is ? How accurate it is ? Are control and measurement methods sufficient? Market Risk Credit Risk Operational Risk The Basel II Banking capital rules did not produce the needed effect on Banks having enough liquidity. Northern Rock and Bradford & Bingley did cover the requirements related to “capital” but it did not prevent them from bankruptcy. (The Independent)

23 Queries Audit Principles  Internal Audit Independency Sanction Power Risk Oriented Qualitative Adequacy  External Audit Regulations Standards

24 Queries Board of Directors and Top Management  Volume Focused and Premiums  Audit Committee Acts  Functions of Independent Administrative Board  Corporate Governance

New Trends and Changing Role of Internal Audit

26 New Trends in Audit Risk Oriented Audit Continuous Audit and Supervision Information System(IT) Audit

27 Risk Oriented Audit The reasons which are below have changed working concept of audit departments. Also risk oriented audit has found acceptance due to those reasons;  Control resources are not unlimited.  Controlled activities face different risks.  Controlled unit activities has relatively different severity levels. Identification Specify Resources Evaluation Prioritizing AUDIT PLAN RISK Risk Oriented Audit Concept Purpose: Transferring Resources of Audit to Most Risky Areas!

28 Continuous Audit and Supervision Deriving benefits from IT, Continuous supervision of processes, Checking immediately afterwards the process, Warning system before the process

29 IT Audit  Information Systems provide more effective works with less errors, so it causes more addiction to IS. Important processes are done by using Information Systems.  IT systems are vulnerable to many risks. Authentication Non-deniable Data Integrity/Consistency Data Confidentiality (Privacy) Business Continuity Accordance of Legal Arrangements  Regulations to suggest some requirements about IT Audits.

30 Standards of IT Audit COBIT is an IT Management and Audit Model and legislatively accepted standard in IT Audits in Turkey. CMMI: Software Development Process Standards Service/Service Management Standards ISO: Service/Service Management Standards ITIL: Information/System Security Standards

31 Changing Approaches in Audit TRADITIONAL Detection Functional Including whole Once Partial MODERN  Prevention  Process based  Risk oriented  Continuous  Integrated

32 Audit Certifications

33