0% found this document useful (0 votes)
2 views15 pages

Internal Control Academy

The document outlines the Internal Controls Assurance (ICA) Academy's general module, covering essential topics such as internal controls, the Sarbanes-Oxley Act, risk and control management, and standard operating procedures. It emphasizes the importance of internal controls in ensuring financial integrity, accountability, and compliance while dispelling common myths about their function. Additionally, it discusses fraud prevention and detection strategies, the use of a Risk and Control Matrix (RACM), and the significance of standard operating procedures in organizational efficiency.

Uploaded by

pks1124
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
2 views15 pages

Internal Control Academy

The document outlines the Internal Controls Assurance (ICA) Academy's general module, covering essential topics such as internal controls, the Sarbanes-Oxley Act, risk and control management, and standard operating procedures. It emphasizes the importance of internal controls in ensuring financial integrity, accountability, and compliance while dispelling common myths about their function. Additionally, it discusses fraud prevention and detection strategies, the use of a Risk and Control Matrix (RACM), and the significance of standard operating procedures in organizational efficiency.

Uploaded by

pks1124
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Internal Controls Assurance

(ICA) Academy

General Module
Table of Content
Chapters Particulars
1 Internal controls
2 Sarbanes Oxley Act
3 Risk & Control
4 Standard Operating Procedures
5 Internal Compliance Framework
6 RACI Matrix
7 Four lines of Defense
8 Statutory Audit
Chapter 1 – Internal controls
Introduction
Internal controls are the mechanisms, rules, and procedures implemented by a company to ensure
a. Integrity of financial and accounting information
b. Promote accountability and prevent fraud
c. Ensure compliance with laws and regulations
d. Helps improve operational efficiency by improving the accuracy and timeliness of reporting

Responsibility for implementing internal controls


a. Management is responsible for establishing and maintaining the control environment.
b. Internal compliance team plays an important role by performing evaluations and making
recommendations for improving controls.
c. Furthermore, every employee plays a role in either strengthening or weakening the Institution’s
internal control system. Therefore, all employees need to be aware of the concept and purpose of
internal controls.

Internal Controls Myth


Part of the educational process is to dispel the myths about internal controls.
Here are a few myths and the corresponding facts
Myth Fact
Internal controls result from a strong set of policies Internal controls are based on a strong control environment
and procedures and solid business practices that, in most cases, will be
(i.e., “If a policy doesn't exist, we don’t have to do supported by policies; however, lack of formal policies does
it”). not preclude good business practices.
Internal controls? Management and departmental personnel are the owners
That’s why we have internal auditors. of internal controls.
Internal controls are all about finance and Internal controls are integral to every aspect of business.
accounting.
We do what the Office of Financial Affairs or the
Department of Finance tells us to do.
Internal controls are essentially negative, like a list Internal controls make the right thing happen the first time.
consisting only of “thou shall not" statements.
Internal controls are a necessary evil. They take Internal controls should be built into, not onto, business
time away from our core activities and processes.
responsibilities.
If controls are strong enough, we can be sure that Internal controls provide reasonable, but not absolute,
errors and irregularities will always be detected. assurance that the organization’s objectives will be
achieved.
Chapter 2 - Sarbanes-Oxley Act (SOX)

Introduction

The Sarbanes-Oxley Act of 2002 is a federal law that established sweeping auditing and financial regulations
for public companies.
The act was named for its sponsors: U.S. Sen. Paul Sarbanes, D-Md., and U.S. Rep. Michael Oxley, R-
Ohio.
Lawmakers created the legislation to help protect shareholders, employees and the public from accounting errors
and fraudulent financial practices.

Former U.S. President George W. Bush, who signed the act into law on July 30, 2002, called the act "the
most far-reaching reforms of American business practices since the time of Franklin Delano
Roosevelt."
SOX primarily sought to regulate financial reporting and other business practices at publicly traded companies.
However, some provisions apply to all enterprises, including private companies and not-for-profit organizations.
Additionally, SOX established penalties for noncompliance with its provisions.
The Securities and Exchange Commission (SEC) enforces SOX.

History

Federal lawmakers enacted SOX in large part due to corporate scandals at the start of the 21 st century.
One such scandal involved energy firm Enron Corp. Enron, considered one of the largest, most successful and
innovative companies in the United States around 2000, unraveled in less than two years as both the company's
fraudulent practices and its executives' criminal activities came to light.

Similarly, the telecommunications giant WorldCom became embroiled in scandal as its own fraudulent
accounting practices made the news. After filing for bankruptcy in 2002, the company was hit with a $750 million
SEC fine. Its chief executive officer (CEO) was sentenced to 25 years in prison, and the chief financial officer
(CFO)received a five-year jail sentence as a result of criminal charges in the case.

The financial scandal at Tyco International also preceded SOX. In this case, the company's former CEO and CFO
were convicted of stealing hundreds of millions of dollars from the company, falsifying business records and
violating other business laws.

Key provisions

The Sarbanes-Oxley Act is arranged into 11 sections, or titles. Two sections of particular note are Section 302
and Section 404 & 906
.
Section 302 pertains to "Corporate Responsibility for Financial Reports."
It established, in part, that CEOs and CFOs must review all financial reports and that the reports are "fairly
presented" and don't contain misrepresentations. This section also established that CEOs and CFOs are responsible
for the internal accounting controls.

Section 404 deals with "Management Assessment of Internal Controls" and requires companies to publish details
about their internal accounting controls and their procedures for financial reporting as part of their annual
financial reports. Section 404 requires corporate executives to personally certify the accuracy of their company's
financial statements and makes them individually liable if the SEC finds violations.

Section 906 Section 906 addresses criminal penalties for certifying a misleading or fraudulent financial report.
Under SOX 906, penalties can be upwards of $5 million in fines and 20 years in prison

Benefits of SOX
1. SOX could spur better financial practices that would benefit companies and their stakeholders.
2. SOX helped businesses improve their financial management by strengthening controls, standardizing
processes, improving documentation and creating stronger board oversight.
3. Studies also have found that SOX increased investor confidence.

Information provided by Entity


What is it?

a. Information provided by the entity (IPE) is any information that is produced by the company and
provided as audit evidence, whether it be for your controls testing or substantive procedures performed
by external audit.
b. When information is used in the performance of controls, it must be evaluated whether the information is
sufficiently reliable for both completeness and accuracy.
c. RELIABILITY OF INFORMATION FROM ANY SOURCE IS NOT ASSUMED

What should I consider?


a. What data do I use to evaluate the numbers?
b. Where is the data coming from?
c. Is it an in scope system for SOX and effective throughout this fiscal?
d. How do I know its complete and accurate?
Chapter 3 – Risk & Controls
Fraud
The term ‘fraud’ commonly includes activities such as theft, corruption, conspiracy, embezzlement,
money laundering, bribery and extortion.
There are three main categories of fraud that affect organizations.
a. The first of these is asset misappropriations, which involves the theft or misuse of an organization’s
assets.
Examples include theft of plant, inventory or cash, false invoicing, accounts receivable fraud
b. The second category of fraud is fraudulent statements. This is usually in the form of falsification of
financial statements in order to obtain some form of improper benefit.
c. The final of the three fraud categories is corruption. This includes activities such as the use of bribes or
acceptance of ‘kickbacks’, improper use of confidential information, conflicts of interest and collusive
tendering.

Fraud doesn’t just involve money. Counterfeiting is one example of fraud that can have extremely
serious consequences

In 2006, a counterfeit product did result in more tragic consequences. At least 100 children died after
ingesting cough syrup that had been mixed with counterfeit glycerin. The counterfeit compound, actually
a dangerous solvent, had been used in place of more expensive glycerin. The manufacturing process had
been sourced to China and the syrup passed through trading companies in Beijing and Barcelona before
reaching its final destination in Panama. The certificate attesting to the product’s purity was falsified and
not one of the trading companies tested the syrup to confirm its contents along the way. It is thought that
the number of deaths is likely to be much higher than the 100 cases that have been confirmed.

Fraud prevention

In the case of deliberate acts of fraud, the aim of preventative controls is to reduce opportunity and
remove temptation from potential offenders.
Prevention techniques include the introduction of policies, procedures and controls, and activities such as
training and fraud awareness to stop fraud from occurring.

Fraud detection

As fraud prevention techniques may not stop all potential perpetrators, organizations should ensure that
systems are in place that will highlight occurrences of fraud in a timely manner. This is achieved through
fraud detection.
A fraud detection strategy should involve use of analytical and other procedures to highlight anomalies,
and the introduction of reporting mechanisms that provide for communication of suspected fraudulent
acts.
Key elements of a comprehensive fraud detection system would include exception reporting, data mining,
trend analysis and ongoing risk assessment.

Fraud prevention and fraud detection both have a role to play and it is unlikely that either will fully
succeed without the other.

Therefore, it is important that organizations consider both fraud prevention and fraud
detection in designing an effective strategy to manage the risk of fraud .

Examples of common types of internal fraud


Cash
Skimming of cash before recording revenues or receivables (understating sales or receivables)
Employee creating false payment instruction with forged signatures and submitting it for processing.
Stealing passwords to payment systems and inputting series of payments to own account.
Non-cash
Theft or abuse of proprietary or confidential information (customer information, intellectual property,
pricing schedules, business plans, etc. ).
Improper changes to supplier payment terms or other supplier details
Marked up invoices from contracts awarded to supplier associated with an employee.
RACM – Risk & Controls Matrix

A Risk and Control Matrix (RACM) is a powerful tool that can help an organization
identify, rank, and implement control measures to mitigate risks.
A RACM is a repository of risks that pose a threat to an organization’s operations, as well as the controls
in place to mitigate those risks.
Simply, a RACM serves as a snapshot of an organization’s risk profile, measuring the organization’s risks
against the formalized actions taken to prevent negative events from occurring.

Assess Risks and Controls


Before assessing risks, an organization needs to understand
1. the definition of risk,
2. the difference between inherent and residual risk, and
3. the criteria used to rank each risk. The Committee of Sponsoring Organizations of the Treadway Commission
(COSO) provides the following definitions in its 2017 update to the Integrated Framework:
1. Defining Risk: Risk is defined as “the possibility that events will occur and affect the achievement of
strategy and business objectives”.
2. Inherent vs. Residual Risk: Within a RACM, each risk has both an inherent and residual risk ranking.

Inherent risk is the risk to an entity in the absence of any direct or focused actions by management
to alter its severity. Each risk or event identified in a RACM is ranked on a scale to determine
the likelihood that the event will take place and the impact, or potential damage, that would occur
if that risk materialized and occurred.
o For example, the likelihood of a power outage bringing down a network is extremely low, but the
impact the outage would have on business operations is extremely high. Based on the likelihood
and impact ranking, each risk is assigned an overall inherent risk ranking.

Residual risk is the risk remaining after management has taken action to alter its severity. Residual
risk can be thought of as a weighted risk ranking, considering both the inherent risk, and the impact
of implemented controls in addressing the risk.
o Using the above example, the residual risk would be the remaining chance of a power
outage occurring after implementing controls such as a universal power supply or battery
backups to address the risk of an outage occurring.

Benefits of a RACM for Your Organization


1. RACM will identify and highlight gaps that pose a threat to an organization that may not have been
previously considered.
2. The exercise of documenting the full environment of risks related to an organization provides a valuable
opportunity to properly consider the organization’s risk appetite and ensure that the organization has a
plan to mitigate risks that it’s not prepared to accept.
3. Additionally, a RACM can allow management to effectively prioritize risks that need to be addressed.

Mitigating all risks that could affect an organization is impractical. However, applying a resource like a RACM
will offer management information to allocate resources toward those risks that pose the greatest, or more
immediate, threats.
Controls

Preventative Internal Controls

Preventative internal controls are put into place to keep errors and irregularities from happening.
While detective controls usually occur irregularly, preventative controls usually occur on a regular basis.
They range from locking the building before leaving to entering a password before completing a
transaction. Other preventative controls include testing for clerical accuracy, backing up computer data,
drug testing of employees, employee screening and training programs, segregation of duties.

Detective Internal Controls

Detective internal controls are designed to find errors after they have occurred. They serve as part of a
checks-and-balances system and to determine how efficient policies are.
Examples include surprise cash counts, taking inventory, review and approval of accounting work,
internal audits,

Corrective Internal Controls

As the name suggests, corrective internal controls are put into place to correct any errors that were
found by the detective internal controls. When an error is made, employees should follow whatever
procedures have been put into place to correct the error, such as reporting the problem to a supervisor.
Training programs and progressive discipline for errors are other examples of corrective internal
controls.

Limitations

It is important to keep in mind that internal controls, while effective, are not a guarantee that a
company's objectives will be met.
Human errors and computer errors are not accounted for by internal controls.
In addition, internal controls assume employees are honest and that they would not bypass guidelines
or alter data to benefit themselves.

Sampling

Audit sampling is the use of an audit procedure on a selection of the items within an account balance or
class of transactions.

The sampling method used should yield an equal probability that each unit in the sample could be
selected. The intent behind doing so is to evaluate some aspect of the information.

Audit sampling is needed when population sizes are large, since examining the entire population would
be highly inefficient. There are multiple ways to engage in audit sampling, including the following:

Stratified sampling. The population is divided into strata based on the characteristics. A consecutive
series of items are selected for review. Though this approach may be efficient, there is a risk that a block
of items will not reflect the characteristics of the entire population.
Haphazard sampling. There is no structured approach to how items are selected. However, the person
doing the selections will probably skew the selections (even if inadvertently), so the selections are not
truly random.
Random sampling. A random number generator is used to make selections. This approach is the most
theoretically correct but can require more time to make selections.
Monetary sampling. It is a statistical sampling method that is used to determine if the account balances
or monetary amounts in a population contain any misstatements
Systematic sampling. Selections are taken from the population at fixed intervals, such as every
20th item. This tends to be a relatively efficient sampling technique

Advantages of sampling
1. Low cost of sampling
2. Less time consuming in sampling
3. Organization of convenience
4. Suitable in limited resources

Disadvantages of sampling
1. Chances of bias
2. Difficulties in selecting a truly representative sample
3. In adequate knowledge in the subject
4. Impossibility of sampling

Concept of materiality
Materiality is one of the basic and major concepts of auditing. Auditing and Assurance Standard (AAS)
(hitherto known as Standard Auditing Practices (SAPs))-13, “Audit Materiality”, states that the concept of
materiality recognises that some matters, either individually or in the aggregate, are relatively important for
true and fair presentation of the financial information in conformity with recognised accounting policies and
practices
Materiality depends on following considerations
1. Legal & regulatory requirement - Regulations as per SOX act 2002
2. Abnormal transactions - Transactions of exceptional nature
3. Previous Year’s Figures - Value significance of specific item against its PY value
4. Percentage Comparison – Defined percentage of total revenue
5. Relative Significance - Relative significance of an accounting item against its
Accounting Head
6. Difference in Calculations - Errors in calculations identified
Chapter 4 - SOP – Standard operating procedures

A standard operating procedure (SOP) is a set of step-by-step instructions compiled by an organization to help
employees carry out complex routine operations.
SOPs aim to achieve efficiency, quality output and uniformity of performance, while
reducing miscommunication and failure to comply with industry regulations..

Benefits
 They save time and money
 They provide consistency
 They improve communication
 They allow you to hold your employees accountable
 They create a safer work environment

One of the biggest misconceptions about standard operating procedures is that they will cause businesses to
become rigid and inflexible.
Chapter 5 – Internal Compliance Framework
Policies

Policies are general statements of how an organization want to behave and procedures define exactly how to do a
task or perform step by step .
Example: Organization can have a policy to implement physical security and prevent unauthorized access inside the
office premise.

Some of the benefits of formal policies include:

 Helping staff to make decisions more efficiently .


 Providing instruction on how to do tasks
 Creating confidence and reduce bias in decision-making
 Protecting staff from acting in a manner that might endanger their employment.
 Protecting staff from acting in a manner that might endanger the safety of themselves and others.
 Help staff to initiate actions and take responsibility without constant reference to management.
 Increase the accountability of business or organisation's and its staff

The creation of policies is actually good evidence of proactive or forward-thinking management

Delegation of authority is the base of superior-subordinate relationship, it involves following steps:-

1. Assignment of Duties - The delegator first tries to define the task and duties to the subordinate. He also
has to define the result expected from the subordinates. Clarity of duty as well as result expected has to
be the first step in delegation.
2. Granting of authority - Subdivision of authority takes place when a superior divides and shares his
authority with the subordinate. It is for this reason, every subordinate should be given enough
independence to carry the task given to him by his superiors. The managers at all levels delegate authority
and power which is attached to their job positions. The subdivision of powers is very important to get
effective results.
3. Creating Responsibility and Accountability - The delegation process does not end once powers are
granted to the subordinates. They at the same time have to be obligatory towards the duties assigned to
them. Responsibility is said to be the factor or obligation of an individual to carry out his duties in best of
his ability as per the directions of superior. Therefore, it is that which gives effectiveness to authority. At
the same time, responsibility is absolute and cannot be shifted. Accountability, on the others hand, is the
obligation of the individual to carry out his duties as per the standards of performance.

Therefore, it is said that authority is delegated, responsibility is created, and


accountability is imposed.

Example: Requiring multiple signatories on high value transactions (e.g. within a finance or procurement
department)
Chapter 6 - RACI – Responsible, Accountable, Consulted, Informed
RACI helps organizations prioritize team members’ actions, so everyone knows precisely what they’re
responsible for.
Below we'll break down the RACI acronym and give you an example of how it works in practice:

Responsible
Who is responsible for the work on a particular element of the project or process?
Consider a fast food company with a drive-through window. When considering all of the processes of the
restaurant, you will need to identify one person or multiple people responsible for serving food items through the
drive through. These employees will be assigned as “Rs”.

Accountable
Who is accountable for the process or project working well?
If an operational issue with the drive-through arises, it isn’t the job of the employee sitting at the drive-through
window to fix this issue—it’s the responsibility of someone higher up the ladder who likely helped create the
process. (In this example, this may be a manager.) The individual accountable for this operational issue has
ultimate authority over the project—so, as a best practice, there should only be one “A” assigned to a given
project or process.

Consulted
Who needs to be consulted if there is a problem with this process?
When changes need to be made to a project or process, do you know who to consult to resolve the issue (and not
make it worse)? In our hypothetical drive-through restaurant, a “C” might be someone who is in the Health and
Safety department who can explain how long food can sit out before it has to be thrown away.

Informed
Who must stay informed about a project if a change has been made?
If any changes are made during a project or process, the “Is” need to be informed. These individuals don’t
necessarily provide feedback, but they do have to stay up-to-date with developments throughout the process
lifecycle. For example, the training department needs to know if any changes are made so they can update the
documentation and processes for the next shift or the next restaurant.

Benefits of a RACI matrix


1. It enables employees to be more engaged.
2. It assists with employee training.
3. It decreases frustration with management.
4. It helps save time in meetings.
5. It aligns with your organizational strategy.
Chapter 7 - The four lines of defense

Assurance can come from many sources. The ‘four lines of defense’ model is a concept for helping to identify and
understand the different contributions the various sources can provide.
ICAEW's Audit and Assurance Faculty provides this definition of the model to help practitioners.
 First line: the way risks are managed and controlled day-to-day. Assurance comes directly from those responsible
for delivering specific objectives or processes. It may lack independence, but its value is that it comes from those
who know the business, culture and day-to-day challenges.
 Second line: the way the organization oversees the control framework so that it operates effectively. The
assurance provided is separate from those responsible for delivery, but not independent of the management
chain, such as risk and compliance functions.
 Third line: objective and independent assurance, e.g. internal audit, providing reasonable (not absolute)
assurance of the overall effectiveness of governance, risk management and controls.
 Fourth line: assurance from external independent bodies such as the external auditors and other external
bodies. External bodies may not have the existing familiarity with the organization that an internal audit function
has, but they can bring a new and valuable perspective. Additionally, their outsider status is clearly visible to third
parties, so that they can not only be independent but be seen to be independent.
Each line of defense has a purpose and can provide robust assurance. There is no one line which provides better
quality assurance than any of the others. A range of assurance activities from across all lines of defense will
provide a rich and value add assurance picture.
Chapter 8 - Statutory Audit & Reporting

Audits are conducted to express a true and fair view of a company’s financial statements. Therefore, the auditor’s
opinion expressed in the ultimate report is based on the information reviewed and analyzed during the verification
of financial statements. Upon completing the report, the auditor may express one of the following four opinions:

Unqualified opinion
When an independent auditor concludes that the financial records and statements of a company are present fairly
and appropriately, in accordance with the financial reporting framework, the judgment is called an unqualified
opinion.
Qualified opinion
An auditor expresses a qualified opinion when according to him or her, the financial statements of the company –
as a whole – are not free from material misstatements, and the misstatements are material but not pervasive in
nature.
Disclaimer of opinion
A disclaimer of opinion is expressed when the possible effect of a limitation on scope is material and pervasive to
the extent that the auditor is unable to obtain sufficient appropriate audit evidence.
As a result, the auditor is unable to express an opinion on the financial statements.
Adverse opinion
An adverse opinion is issued when there are limitations on the scope of the auditor’s work.
It is also issued when there is disagreement with management regarding the acceptability of the accounting
policies selected, the method of their application, or the adequacy of the financial statement disclosure. When an
auditor expresses an adverse opinion, a clear description of all the substantive reasons is included in the audit
report.

You might also like