INTERNAL CONTROL OVER FINANCIAL REPORTING

Slides:



Advertisements
Similar presentations
Internal Control and Control Risk
Advertisements

Bodnar/Hopwood AIS 7th Ed1 Chapter 5 u TRANSACTION PROCESSING AND INTERNAL CONTROL PROCESS.
Auditing Concepts.
Internal Control.
The Islamic University of Gaza
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
INTERNAL CONTROL. INTERNAL CONTROL DEFINED  INTERNAL CONTROL IS A PROCESS - EFFECTED BY AN ENTITY'S BOARD OF DIRECTORS, MANAGEMENT, AND OTHER PERSONNEL.
Standar Pekerjaan Lapangan: Pemahaman Memadai atas Pengendalian Intern Pertemuan 5.
CHAPTER 9 UNDERSTANDING INTERNAL CONTROLS Winter 2004
6-1 McGraw-Hill/Irwin ©2002 by The McGraw-Hill Companies, Inc. All rights reserved. Chapter 6 Internal Control Evaluation: Assessing Control Risk.
Internal Control. COSO’s Framework Committee of Sponsoring Organizations 1992 issued a white paper on internal control Since this time, this framework.
Auditing A Risk-Based Approach To Conducting A Quality Audit
18- 1 © 2006 The McGraw-Hill Companies, Inc., All Rights Reserved. Chapter 18 Integrated Audits of Internal Control (For Public Companies Under Sarbanes-Oxley.
Internal Control in a Financial Statement Audit
Internal Control. COSO’s Framework Committee of Sponsoring Organizations 1992 issued a white paper on internal control Since this time, this framework.
Section 404 Audits of Internal Control and Control Risk
Sarbanes-Oxley Project Summary of COSO Framework Presented by Larry Dillehay & Scott Reitan Parkfield Group LLC.
Control environment and control activities. Day II Session III and IV.
Chapter 10 Internal control and Control Risk.
Auditing Internal Control over Financial Reporting
5-1 McGraw-Hill/Irwin ©2005 by the McGraw-Hill Companies, Inc. All rights reserved. Chapter 5 Internal Control Evaluation: Assessing Control Risk “If everything.
Auditing Internal Control over Financial Reporting
Chapter 07 Internal Control McGraw-Hill/IrwinCopyright © 2014 by The McGraw-Hill Companies, Inc. All rights reserved.
INTERNAL CONTROL OVER FINANCIAL REPORTING
Implementation Issues of Sarbanes-Oxley CASE Presentation September 23, 2004 By Denise Farnan.
Chapter 5 Internal Control over Financial Reporting
Page 1 Internal Audit Outsourcing The Moss Adams Approach to Internal Audit Outsourcing Proposed SOX 404 Changes.
Considering Internal Control
Internal Control in a Financial Statement Audit
Chapter 7 Auditing Internal Control over Financial Reporting McGraw-Hill/Irwin ©2008 The McGraw-Hill Companies, All Rights Reserved.
NO FRAUD LEFT BEHIND The Effect of New Risk Assessment Auditing Standards on Schools Runyon Kersteen Ouellette.
Internal Control in a Financial Statement Audit
9 - 1 ©2003 Prentice Hall Business Publishing, Essentials of Auditing 1/e, Arens/Elder/Beasley Internal Control and Control Risk Chapter 9.
SAS Update GFOA Western Pa – January 2008 Presented by Rob Lent, CPA, CGFM.
©2003 Prentice Hall Business Publishing, Auditing and Assurance Services 9/e, Arens/Elder/Beasley Internal Control and Control Risk Chapter 10.
Learning Objectives LO5 Illustrate how business risk analysis is used to assess the risk of material misstatement at the financial statement level and.
Evaluation of Internal Control System
5-1 McGraw-Hill/Irwin ©2007 by the McGraw-Hill Companies, Inc. All rights reserved. Chapter 5 Internal Control Evaluation: Assessing Control Risk.
Evaluation of Internal Control System. Learning Objective 1 Contrast management’s need for internal control with the auditor’s need to consider internal.
[Hayes, Dassen, Schilder and Wallage, Principles of Auditing An Introduction to ISAs, edition 2.1] © Pearson Education Limited 2007 Slide 7.1 Internal.
CHAPTER 5 INTERNAL CONTROL OVER FINANCIAL REPORTING.
McGraw-Hill/Irwin © 2003 The McGraw-Hill Companies, Inc., All Rights Reserved. 6-1 Chapter 6 CHAPTER 6 INTERNAL CONTROL IN A FINANCIAL STATEMENT AUDIT.
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin 6-1 Chapter Six Internal Control in a Financial Statement Audit.
Chapter 9: Introduction to Internal Control Systems
Auditing Internal Control Studies & Risk Assessment Chapter 9 Internal Control Studies & Risk Assessment Chapter 9.
BA 427 – Assurance and Attestation Services Lecture 21 Tests of Controls.
A Guide for Management. Overview Benefits of entity-level controls Nature of entity-level controls Types of entity-level controls, control objectives,
McGraw-Hill/Irwin © The McGraw-Hill Companies 2010 Auditing Internal Control over Financial Reporting Chapter Seven.
Internal Control Chapter 7. McGraw-Hill/Irwin © 2006 The McGraw-Hill Companies, Inc., All Rights Reserved. 7-2 Summary of Internal Control Definition.
©2012 Prentice Hall Business Publishing, Auditing 14/e, Arens/Elder/Beasley Section 404 Audits of Internal Control and Control Risk Chapter.
Copyright © 2007 Pearson Education Canada 9-1 Chapter 9: Internal Controls and Control Risk.
Chapter 5 Evaluating the Integrity and Effectiveness of the Client’s Control Systems.
1 CHAPTER 5 - b INTERNAL CONTROL OVER FINANCIAL REPORTING.
©2008 Prentice Hall Business Publishing, Auditing 12/e, Arens/Beasley/Elder Section 404 Audits of Internal Control and Control Risk Chapter 10.
©©2012 Pearson Education, Auditing 14/e, Arens/Elder/Beasley Considering Internal Control Chapter 10.
Copyright © 2014 Pearson Education, Inc. Publishing as Prentice Hall. Chapter
McGraw-Hill/Irwin © The McGraw-Hill Companies 2010 Internal Control in a Financial Statement Audit Chapter Six.
Internal Control. McGraw-Hill/Irwin © 2004 The McGraw-Hill Companies, Inc., All Rights Reserved. 7-2 Summary of Internal Control Definition A process...designed.
Chapter 6 Internal Control in a Financial Statement Audit McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
©2005 Prentice Hall Business Publishing, Auditing and Assurance Services 10/e, Arens/Elder/Beasley Internal Control and Control Risk Chapter 10.
Internal Control Chapter 7. McGraw-Hill/Irwin © 2008 The McGraw-Hill Companies, Inc., All Rights Reserved. 7-2 Summary of Internal Control Definition.
8 INTERNAL CONTROL. Definition Duty  mgt (CEO)  Board  Internal auditor  Employee  External person.
Section 404 Audits of Internal Control and Control Risk
Modern Auditing: Assurance Services and the Integrity of Financial Reporting, 8th Edition William C. Boynton California Polytechnic State University at.
Auditing Concepts.
Internal Control Evaluation: Assessing Control Risk
Internal Control in a Financial Statement Audit
Internal control objectives
Internal Control Internal control is the process designed and affected by owners, management, and other personnel. It is implemented to address business.
Presentation transcript:

INTERNAL CONTROL OVER FINANCIAL REPORTING CHAPTER 5 INTERNAL CONTROL OVER FINANCIAL REPORTING

Define Internal Controls - COSO Internal controls is a process designed to provide reasonable assurance of achieving the following: Generating reliable financial accounting information Safeguarding assets Complying with applicable laws and regulations Operating efficiently and effectively

The Need for Control Control is part of corporate governance whereby the owners and creditors of an organization exert control and require accountability for its resources Governance begins with stockholders, who delegate certain responsibilities to the board of directors and in turn to management That delegation must occur within a framework of control and accountability The control system exists to ensure that Responsibilities are properly identified Tasks are assigned in accordance with responsibilities and accountability

The Integrated Audit The Sarbanes-Oxley Act of 2002 requires publicly held companies to report on the effectiveness of their internal controls over financial reporting The Public Company Accounting Oversight Board requires external auditors to perform an integrated audit of the effectiveness of internal controls and financial reporting In essence, the auditor must attest to both the financial statements and management's assertions regarding the effectiveness of internal controls over financial reporting

LO2 - The components of an internal control system An internal control system consists of five components Control environment: overall attitude, awareness, and actions of significant internal groups to maintain a well-controlled organization (tone at the top) Risk assessment: process designed to identify and manage risks that may affect its ability to achieve its objectives Control activities: policies and procedures established by management to help ensure that internal control objectives are achieved and risks mitigated Information and communication: process of identifying, capturing, and exchanging information in a timely fashion to enable the organization to achieve its objectives Monitoring: process that assesses the quality of internal controls over time

Internal Control Components MONITORING Information & Communication CONTROL ACTIVITIES RISK ASSESSMENT CONTROL ENVIRONMENT

LO4 - Understanding & Assessing the Control Environment – The most pervasive of them all There are a number of factors an auditor should look at when evaluating an organization's control environment: Management's philosophy and operating style Organizational structure, including assignment of authority and responsibility Board of directors and audit committee Human resource policies and practices Integrity and ethical values Commitment to competence Compensation and evaluation programs Effectiveness of the internal audit function

LO6 - Audit Reporting on Internal Control External auditors of non-public companies must report to management significant internal control deficiencies in the design or operation of internal controls that are identified in the normal course of a financial audit. Such reports are for management's use and are not intended to be distributed to the public External auditors of public companies must go beyond the report to management and also report on management's assertion regarding the effectiveness of internal controls over financial reporting Includes an opinion on the client's internal controls Included in the company's annual report

LO7 Audit Reporting on Internal Control (continued) The PCAOB's proposed report on internal controls would include a(n): Description of internal control, its objectives, and inherent limitations Definition of material deficiency in internal control Description of all material deficiencies found Opinion regarding effectiveness of company's internal controls

Audit Reporting on Internal Control (continued) According to the Sarbanes-Oxley Act, if an auditor identifies significant or material deficiencies in internal control, Those deficiencies must be reported to both management and the audit committee Deficiencies must be reported to the audit committee even if management has addressed the deficiency and implemented new controls The stated intent of the Sarbanes-Oxley Act is to ensure boards of directors understand they have a responsibility to improve the governance of the organization

INTERNAL CONTROL OVER FINANCIAL REPORTING CHAPTER 5 - b INTERNAL CONTROL OVER FINANCIAL REPORTING

Account Balance Assertions & Related Objectives Presentation & Disclosure – an item is disclosed, classified, and described in accordance with the applicable financial reporting framework Existence - an asset or a liability exists at a given date; Rights and obligations - an asset or a liability pertains to the entity at a given date.. Completeness - there are no unrecorded assets, liabilities, transactions or events, or undisclosed items Valuation - an asset or liability is recorded at an appropriate carrying value

Transaction Assertions & Related Control Objectives Occurrence – Recorded transactions and events have occurred and pertain to the entity Completeness – All transactions and events that should have been recorded have been recorded Accuracy – Amounts and other data have been recorded accurately Cutoff – Transactions and events have been recorded in the correct accounting period Classification – Transactions and events have been recorded in the proper accounts

Overview of Controls Testing - Pervasive Control Activities (types of) Some control procedures are found in almost all accounting systems: Segregation of duties Authorization procedures Documented transaction trail Physical controls to limit access to assets Independent reconciliation Competent, trustworthy employees

(a) Segregation of Duties Very fundamental, should always separate: Authorization Record keeping Custody (Physical)

(b) Authorization Procedures These ensure that only authorized Transactions take place Activities take place Access to records are permitted

(c) Documentation Documentation must be such that a proper audit trail exists This will obviously be more difficult in a computerized environment, but still can be achieved.

(d) Physical Controls to Assets Security locks Fences Keys Password etc Vaults, safes

(e) Reconciliation Comparisons must always be done between what was submitted and what was processed What physically exists and what is recorded Internal records and external records

(f) Competent & Trustworthy employees These employees help to make controls work

Overview of Controls Testing – Integrated Audit (per PCAOB) vs Overview of Controls Testing – Integrated Audit (per PCAOB) vs. Normal Audit Compare Exhibit 5.11 and Exhibit 5.12 on page 168 & 169

Control Effectiveness and Control Risk Assessment Process for evaluating controls: Obtain an understanding of risks and internal controls Make a preliminary assessment of control risk and decide whether to test operation of control procedures Test operating effectiveness of controls Based on the results of testing, determine whether to revise the assessment of control risk and incorporate this revision into the substantive testing

Obtain an Understanding Auditor needs to gain understanding of each significant accounting application operates and the control procedures used The auditor gathers evidence by Performing walkthroughs of the accounting system and processing procedures and document via narrative memo and/or flowchart Making inquires of management, and accounting and operational employees Taking plant and operational tours Reviewing client documentation including accounting manuals and program and system descriptions Reviewing prior year audit work papers and then focus on changes The auditor documents his/her understanding using flowcharts (visio), questionnaires, and narratives (see pages 176 & 177)

Make Preliminary Assessment of Control Risk After gaining an understanding, the auditor makes a preliminary assessment of control risk - this assessment is crucial because it drives the planning for the rest of the audit The relationship between the assessed level of control risk and the rigor of the subsequent substantive testing is inverse: If control risk is assessed as high, No reliance is placed on the client's internal controls The amount and rigor of substantive testing must be increased If control risk is assessed as low The auditor would like to rely on the client's internal controls The amount and rigor of substantive testing may not have to be increased However, the auditor must test the controls to make sure they are operating effectively (and document it)

Perform Tests of Controls The preliminary assessment of control risk is based on the auditor's understanding of the control system and how it has operated in the past When control risk is assessed low, and the auditor intends to rely on the client's controls, the auditor may reduce (or not increase) the amount of substantive testing To ensure that the auditor's reliance on the client's control is warranted, the auditor must test the control to make sure it is operating effectively Guidance on Sample Size for Testing Controls (Ch 9) Testing Controls Across Multiple Locations Dual Purpose Tests (transaction & substantive) Assessing Control Risk as Moderate (see next slide)

Update Assessment of Control Risk & Need for Substantive Testing If testing indicates the control is not operating effectively, the auditor will revise the preliminary assessment of control risk and incorporate this revision into the subsequent substantive testing