Pharmaceutical Regulatory and Compliance Congress and Best Practices Forum Special Program for Internal/Compliance Audit Professionals: Enterprise Risk.

Slides:



Advertisements
Similar presentations
1 K P M G L L P A D V I S O R Y Changes in the IT Audit Profession Stephen G. Hasty, Jr. National Partner in Charge IT Advisory Savannah, GA January 4,
Advertisements

Module N° 4 – ICAO SSP framework
It’s Time to Talk About Risk and Control
Tax Risk Management Keeping Up with the Ever-Changing World of Corporate Tax March 27, 2007 Tax Services Bryan Slone March 27, 2007.
Chapter © 2009 Pearson Education, Inc. Publishing as Prentice Hall.
Audit Planning and Analytical Procedures Chapter 8.
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
Current Developments at the PCAOB Ensuring Integrity: 3 rd Annual Auditing Conference at Baruch College December 4, 2008.
Standar Pekerjaan Lapangan: Pemahaman Memadai atas Pengendalian Intern Pertemuan 5.
IS Audit Function Knowledge
6-1 McGraw-Hill/Irwin ©2002 by The McGraw-Hill Companies, Inc. All rights reserved. Chapter 6 Internal Control Evaluation: Assessing Control Risk.
Purpose of the Standards
Sarbanes-Oxley Project Summary of COSO Framework Presented by Larry Dillehay & Scott Reitan Parkfield Group LLC.
Elements of Internal Controls Preventing Fraud, Waste, and Abuse in Urban and Rural Transit Systems.
Control environment and control activities. Day II Session III and IV.
Chapter 4 Risk Assessment.
Internal Auditing and Outsourcing
An Educational Computer Based Training Program CBTCBT.
D-1 McGraw-Hill/Irwin ©2005 by the McGraw-Hill Companies, Inc. All rights reserved. Module D Internal, Governmental, and Fraud Audits “I predict that audit.
Planning an Audit The Audit Process consists of the following phases:
Stephen Vink Senior Vice President Group Risk Management and Internal Audit Lessons learned from ERM.
Establishing A Compliance Program: It Makes Sense
How to Develop Internal Monitoring Programs SEVENTH ANNUAL PHARMACEUTICAL REGULATORY AND COMPLIANCE CONGRESS AND BEST PRACTICES FORUM Stephen F. Mohr Global.
Internal Control in a Financial Statement Audit
Agency Risk Management & Internal Control Standards (ARMICS)
Learning Objectives LO5 Illustrate how business risk analysis is used to assess the risk of material misstatement at the financial statement level and.
Issues in Corporate Governance: Board Structures and Functions Based on a Student Presentation by Joshua Shullaw and Matthew Domeyer.
1 Today’s Presentation Sarbanes Oxley and Financial Reporting An NSTAR Perspective.
Chapter 3 Audit Planning, Types of Audit Tests, and Materiality McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
Private & Confidential1 (SIA) 13 Enterprise Risk Management The Standard should be read in the conjunction with the "Preface to the Standards on Internal.
The Connection between Risk Management and Internal Control in Organizations Mag. Norbert Wagner Budapest,
A Focus on CME and Grants Nancy Coddington, PhD Senior Director, Compliance Operations AstraZeneca Pharmaceuticals LP And Terry Hisey Deputy Managing Principal.
Pre-Conference III: Auditing, Monitoring and Effective Internal Investigations Pharmaceutical Regulatory and Compliance Congress and Best Practices Forum.
McGraw-Hill/Irwin © The McGraw-Hill Companies 2010 Audit Planning and Types of Audit Tests Chapter Five.
Enterprise Risk Management Chapter One Prepared by: Raval, Fichadia Raval Fichadia John Wiley & Sons, Inc
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin 5-1 Chapter Five Audit Planning and Types of Audit Tests Chapter.
1 Internal Audit. 2 Definition Is an independent activity established by management to examine and evaluate the organization’s risk management processes.
Copyright © 2013 by The McGraw-Hill Companies, Inc. All rights reserved.McGraw-Hill/Irwin.
[Hayes, Dassen, Schilder and Wallage, Principles of Auditing An Introduction to ISAs, edition 2.1] © Pearson Education Limited 2007 Slide 7.1 Internal.
Compliance Reporting and Auditing: Best Practice Exchange Tony Farino, Partner Peter Claude, Sr. Manager PricewaterhouseCoopers LLP November 14, 2002.
Agenda for Session Compliance in Clinical Research
A Guide for Management. Overview Benefits of entity-level controls Nature of entity-level controls Types of entity-level controls, control objectives,
RECOMMENDATIONS OF THE GOVERNOR ’ S TASK FORCE ON CONTRACTING AND PROCUREMENT REVIEW Report Overview PD Customer Forum September 2002.
Chapter 8 Auditing in an E-commerce Environment
Internal Control Chapter 7. McGraw-Hill/Irwin © 2006 The McGraw-Hill Companies, Inc., All Rights Reserved. 7-2 Summary of Internal Control Definition.
©2012 Prentice Hall Business Publishing, Auditing 14/e, Arens/Elder/Beasley Section 404 Audits of Internal Control and Control Risk Chapter.
Copyright © 2007 Pearson Education Canada 9-1 Chapter 9: Internal Controls and Control Risk.
An Overview THE AUDIT PROCESS. MAJOR PHASES IN AN AUDIT Client acceptance and retention Establish terms of the engagement Plan the audit Consider internal.
0 Due Diligence Monitoring and Auditing of Third Party Vendors October 28, 2008 Pharmaceutical Regulatory and Compliance Congress and Best Practices Forum.
Chapter 5 Evaluating the Integrity and Effectiveness of the Client’s Control Systems.
© 2003 by the AICPA SAS 99: Consideration of Fraud in a Financial Statement Audit.
Copyright © 2015 McGraw-Hill Education. All rights reserved. No reproduction or distribution without the prior written consent of McGraw-Hill Education.
ICAJ/PAB - Improving Compliance with International Standards on Auditing Planning an audit of financial statements 19 July 2014.
©©2012 Pearson Education, Auditing 14/e, Arens/Elder/Beasley Considering Internal Control Chapter 10.
Lecture 5 Control and AIS Copyright © 2012 Pearson Education 7-1.
#327 – Legal and Regulatory Risk: Silent and Possibly Deadly Deborah Frazer, CPA CISA CISSP Senior Director, Internal Audit PalmSource, Inc.
Chapter 3 Audit Planning, Types of Audit Tests, and Materiality McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
Improving Compliance with ISAs Presenters: Al Johnson & Pat Hayle.
AUDIT STAFF TRAINING WORKSHOP 13 TH – 14 TH NOVEMBER 2014, HILTON HOTEL NAIROBI AUDIT PLANNING 1.
Internal Control. McGraw-Hill/Irwin © 2004 The McGraw-Hill Companies, Inc., All Rights Reserved. 7-2 Summary of Internal Control Definition A process...designed.
Chapter 6 Internal Control in a Financial Statement Audit McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
Illinois Office of the Comptroller Financial Training Workshop 2016.
ENTERPRISE RISK MANAGEMENT IN THE CASE OF THE FINANCIAL SERVICE SECTOR
Audit Planning, Types of Audit Tests and Materiality
Построение культуры integrity в компании Aнар Каримов партнёр «ЭКВИТА»
Audit Planning, Types of Audit Tests, and Materiality
COSO Internal Control s Framework
AU-C Section 240 Consideration of fraud in a financial statement
Internal Audit’s Role in Preventing Fraud and Corruption
Presentation transcript:

Pharmaceutical Regulatory and Compliance Congress and Best Practices Forum Special Program for Internal/Compliance Audit Professionals: Enterprise Risk Management; Tactical Audit Considerations; Reporting; Key Issues Noted in Compliance Audits

Using Enterprise-wide Risk Management to establish the compliance audit plan Tactical Audit Matters/Best Practices Sharing  Organizational Considerations  Auditor Competencies  Integrating Compliance Audits into SOX  Audit Cycle  Reporting Considerations Key Compliance Audit Issues and Findings Agenda

The Need for a Focused Approach Internal Audit groups under resource and time pressures  Sarbox 404 Testing/Involvement  Greater emphasis on systems  Qualified personnel in high demand Boards/Audit Committees focused on effectiveness of organizational risk management Compliance risks continue to multiply with increasing regulation and regulatory dicta.

Why ERM? Pharmaceutical and Biotech industries are among the most highly regulated industries. Risks arise from all aspects of the value chain. “Proactive” approach necessary to identify and manage risk before problems occur. Comprehensive, to improve efficiency and effectiveness.

Using ERM to Focus the Audit Plan Enterprise Risk Management is a process, effected by an entity’s board of directors and other personnel, applied in strategy setting and across the enterprise, designed to identify potential events that may affect the entity and manage risk to be within its risk appetite, to provide reasonable assurance regarding the achievement of entity objectives

Using ERM and Risk Profiling 1. Identify and categorise risks Category 1 Risk A Category 2 Category 3 Risk B Risk C Risk F Risk G Risk I Risk J Risk K Risk Category Risk Type Risk H Category 1 Risk A Category 2 Category 3 Risk B Risk C Risk F Risk G Risk I Risk J Risk K Risk Category Risk Type Risk H 2. Prioritise Risks and Generate Risk Profile 4. Adjust for comfort obtained from other groups, and prioritize rotation plan. 3. Adjust audit universe

Selecting Risks to Audit Highest control weighted risk Controls with greatest control benefit Uncontrolled risks Based on dollar exposure Focus of testing will differ between these risks Priority will be driven by judgement.

Possible Audit Areas Discretionary Spending Speaker programs Other local events Consulting agreements and advisory boards Grants Phase IV studies Contracting PBM/GPO relationships Adverse Events Reporting Government pricing CME/ME Samples Value-added services Advertising/professional communication agencies Third party sales forces Off-label “promotion” Executive education Off-contract discounts and concessions Training/Education Exception reporting Disciplinary action Privacy Human Subject Protection Clinical trials (GCP) CFR Part 11 Animal rights Relationships with clinical investigators

Audit Committee Considerations Present the Top 10/20/25 risks and how they are:  Addressed/covered by the organization and  Reflected in the audit plan/rotation Review “legacy” audits for continued relevance  Is that aircraft usage audit worth risk 21 falling off the audit rotation? Reporting: As many right answers as there are boards.

Organizational Considerations Where should compliance auditors reside in an organization?  Internal Audit?  Compliance Office?  Legal?  Functions (Regulatory, QA)?  Other? Where are your compliance auditors located?

Auditor Competencies Independent of function audited Industry knowledge Knowledge of the laws and regulations Skepticism Process Excellence Use of specialists (internal or external) How are your auditors being trained in compliance subject matters?

Interaction with Sarbanes-Oxley Time allocated to compliance auditing.  What % of time can you spend on compliance auditing vs 404? Integrating compliance auditing into 404 work.  Taking the next step to maximize efficiency Assessing compliance controls during financial controls transaction testing Maintaining compliance focus during 404 testing Testing of company level controls

Changes to the Audit Cycle Training Risk Assessment Scheduling Planning Execution Reporting Risk Re-assessment and Planning Laws and Regulations Use of ERM/Cross-function Prioritization from weighting Process vs Transaction Process Improvement Privilege/Care in Drafting Risks need to be re- assessed each year.

Reporting Considerations 4 Things to Consider: 1.Evaluate your findings to assess if they can be reasonably implemented 2.Always discuss your findings with senior management prior to developing the report 3.Solicit management’s support for your findings 4.Simplify your reporting format Use an Executive Summary

Reporting Considerations Work-Product Privilege  Should your audit be performed under privilege? Planning phase What is your expectation that your findings may have legal implications? Privilege applies only if in anticipation of litigation. Execution Procedures and work-product should reflect the appropriate approvals by legal counsel and be documented to indicate such Reporting Discuss with counsel the method and level of detail for your findings

Reporting Considerations Self-evaluation Privilege  Applies to certain types of reviews performed either within the company or on its behalf that are designed to detect or prevent wrongdoing. Adopted by legislation in 5 states New Jersey, Illinois, North Dakota, Oregon, and Michigan Each of these states has adopted its own interpretation of this privilege The weakest of all privileged communication Discuss with your general counsel applicability in your state Significant distinction is that it cannot be used as protection from the government, only from private litigants

Key Issues to Consider Have you evaluated your audit plans to assess the risk with business partners or contractors?  Do your contracts provide for audit rights?  Have you developed an audit plan for assessing both compliance and financial risks? Have you considered ways in which your partners or contractors may be violating your agreement? Are their compliance standards adequate? Are they appropriately meeting the financial terms of the contract?

Results of Recent Compliance Audits Speaker programs Speaker training programs Advisory boards CME Discretionary spending Vendors Other

Questions? NameGreg Crouse CompanyErnst & Young LLP Phone # address NamePeter J. Claude CompanyPricewaterhouseCoopers LLP Phone #