Download presentation
Presentation is loading. Please wait.
1
Internal Controls Assessment
Ruchi Shah Director, Risk Assessment & Mitigation & Deb McEndaffer Director, Compliance Monitoring
2
Agenda Internal controls assessment framework
Benefits of Internal Controls Internal Controls Evaluation (ICE) process & Timelines New Initiative for Internal Controls Expectations regarding Internal Controls during audit Internal Controls at audit without ICE Frequently Asked Questions
3
Internal Controls Assessment Framework
4
Benefits of Internal Controls
Helps identify the gaps in the existing process. WECC gets reasonable assurance of future compliance. Helps determine frequency of monitoring and the type of monitoring. Less Area of Concern and more recommendation for further strengthening the controls.
5
ICE Process & Timelines
RAM accepts the request RAM identifies the scope of ICE 150 days prior to the audit Entity provides Internal Controls summary 120 days prior to audit RAM performs design review of Internal Controls 30 days prior to audit Audit team performs implementation review. During Audit RAM drafts the report and shares with the Entity 60 days after the audit WECC Finalizes the Report 30 days after entity comments
6
Expectation from Entity
During Internal Controls summary submission Provide summary of Risk and Controls for Standard and Requirement in scope of ICE Provide general controls to explain you Internal Controls Program During Design Review Allow your SMEs responsible for control design to participate during phone conversation Be prepared to share/show support documentation that describes the control design in detail
7
Expectation from Entity
During Implementation Review Interviews with SMEs to verify the implementation of designed controls Occasional walkthroughs to check for automated controls During Draft report Review If there is additional detail that was not discussed/requested, please provide that Focus on the considerations provided for future improvements
8
New Initiative for Internal Controls
9
New Initiative for Internal Controls
Internal controls practice group
10
Highlights – Internal controls practice group
Purpose Serve as an industry platform to have WECC and industry thought leaders share good practices regarding development and sustainability of internal controls program, specifically for the NERC Reliability Standards. Targeted outreach specific to Internal Controls SME participation and peer share Hosted quarterly (depending on participation)
11
Highlights – Internal controls practice group
Key Objectives To facilitate/offer specific guidance on the implementation of Internal Controls Program. To increase industry knowledge of the NERC Internal Controls Guide To build a common understanding of Internal Controls terminology To build a catalogue of industry good practices of internal controls suitable to reduce operational risk
13
Expectations of Internal Controls during audit
Required by GAGAS Since it is possible for an entity to be compliant with the Standards and requirements without the implementation of effective internal controls, there will not be any non-compliance if an entity fails to show implementation of the designed controls.
14
Internal Controls at Audit without ICE
Auditors may conduct interviews, walk throughs or ask for specific documentation to check the implementation of controls when there is an Area of Concern (AoC). The objective is to understand if the controls will help you ensure you meet your compliance objectives or what recommendations to make. Likewise if strong internal controls are demonstrated to be repeatable and sustainable they could be considered in future COP.
15
FAQ Why was I audited on a particular Standard and Requirement even though WECC informed me that I had strong internal controls? High Inherent Risk Changes to the Standard and Requirement Reginal Risk identified for that Standard and Requirement Why does audit team ask about internal controls if I did not volunteer for ICE? GAGAS. To determine if there are areas they could make recommendation in for better reliability or security. To learn best practices that can be shared with other WECC Entities and reinforced your good practices.
16
Ruchi Shah Ph: 801-883-6881 rshah@wecc.biz
Thank You Ruchi Shah Ph: Deb McEndaffer Ph:
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.