0% found this document useful (0 votes)
4 views7 pages

[OPAUD]Module 5 Control Frameworks

The document discusses the importance of internal control frameworks in managing organizational risks and complexities in today's business environment. It highlights the COSO framework and its 17 principles, emphasizing the role of a strong control environment, risk assessment, control activities, information communication, and monitoring in achieving effective internal controls. Additionally, it covers various IT frameworks that support organizational success, including COBIT, GTAG, ISO, and CMMI.

Uploaded by

Nikko Lucero
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
4 views7 pages

[OPAUD]Module 5 Control Frameworks

The document discusses the importance of internal control frameworks in managing organizational risks and complexities in today's business environment. It highlights the COSO framework and its 17 principles, emphasizing the role of a strong control environment, risk assessment, control activities, information communication, and monitoring in achieving effective internal controls. Additionally, it covers various IT frameworks that support organizational success, including COBIT, GTAG, ISO, and CMMI.

Uploaded by

Nikko Lucero
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

MODULE 5: Control Frameworks

Today's business environment has resulted in a proliferation of vulnerabilities, risks, stakeholders,


and activities much more complex than ever before.

Internal Control Frameworks


● These are structures that organize, categorize, and sometimes prioritize an organization's
internal controls.
● By definition, internal controls are practices put in place to create value for stakeholders
and minimize risks, so frameworks make it easier to manage these diverging dynamics and
evaluate the results more systematically.

● COSO's Internal Control Integrated Framework (IC-IF) – most widely known internal controls
framework
● Control Objectives for Information and Related Technology (COBIT) – IT control framework
● International Organization for Standardization (ISO) 17799 – IT control framework
● Information Technology Infrastructure Library (ITIL) – IT control framework
● Capability Maturity Model Integration (CMMI) – project management, process assessment,
and performance improvement environments

The COSO Frameworks: ICF and ERM


During the 1980s, a series of fraudulent acts affecting financial statements prompted the creation
of a commission to evaluate the causes of the problems and prepare recommendations for
corrective action.

Among the issues identified was the absence of a comprehensive internal controls framework
containing a widely agreed-upon language that auditors, business leaders, regulators, and
educational institutions could adopt. Consequently, among its recommendations was the need to
create such a framework of internal control.

Committee of Sponsoring Organizations of the Treadway


Commission (COSO)
● Private sector initiative formed in 1985 to sponsor this National Commission on Fraudulent
Financial Reporting
● Sponsors: The Institute of Internal Auditors (IIA), American Institute of Certified Public
Accountants (AICPA), American Accounting Association (AAA), Institute of Management
Accountants (IMA), and Financial Executives Institute (FEI)
● Included representatives from industry, public accounting, investment firms, and the New
York Stock Exchange (NYSE)

COSO's Internal Control Integrated Framework (IC-IF)


● Contains 17 principles representing the fundamental concepts associated with each
component
● States that an entity can achieve effective internal control by applying all principles, which
apply to operations, reporting, and compliance objectives

The 17 Principles
1. Commitment to integrity and ethical values
2. BOD exercises oversight responsibility
3. Establish structure, authority, and responsibility
4. Commitment to competence
5. Enforce accountability
6. Set suitable objectives
7. Identify and analyzes risks
8. Assess risk of fraud
9. Identify and analyze significant change
10. Select and develop control activities
11. Select and develop IT GCCs
12. Mobilize through policies and procedures
13. Use relevant information
14. Communicate internally
15. Communicate externally
16. Conduct ongoing/separate evaluations
17. Evaluate and communicate deficiencies

Control Environment
This refers to the workplace environment, characterized by the way the organization is structured,
the manner of leadership, the degree of openness, management's operating style, having and
practicing the tenets of its code of ethics and statement of values.

This also includes the tone at the top and the degree to which there is congruence between
management's “talk” and its “walk.” In other words, do managers practice what they preach?

Organizational culture is the collection of learned beliefs, traditions, and guides for behavior shared
among members of the organization.

A healthy culture and ethical environment advances employee morale, and it also helps to improve
productivity and efficiency.

The control environment also includes the activities related to the competence and development of
personnel, the assignment of authority and responsibility, and the organizational structure.

Another important aspect of the control environment is that management establishes a risk
management philosophy and the entity's risk appetite, forms a risk culture, and integrates ERM
with related initiatives.

Trompenaars' Three Key Elements of Organizational Culture


According to Trompenaars, organizational culture includes three key elements:

 The general relationship between employees and their organizations


 The vertical or hierarchical system of authority defining superiors and subordinates
 The general views of employees about the organization's destiny, purpose, and goals, and
their place in it

Examples of Companies with Fantastic Cultures


References: [Link] and
[Link]

Zappos
● Cultural fit interview
● New employees are offered $2,000 to quit after the first week of training if they decide the
job isn't for them
● Employee raises come from workers who pass skills tests and exhibit increased capability
● Portions of the budget are dedicated to employee team building and culture promotion

Warby Parker
● Making and selling prescription glasses online since 2010
● Own design, sells directly to customers
● Fun lunches, events and programs
● Sending random employees out to lunch together

Canva Philippines
● Free breakfast, lunch and coffee
● Employees can pursue their passions and hobbies through Canva funded clubs
● Monthly fitness budget for their chosen activity
● No formal dress code requirements in the office
● Every team has a monthly team budget
● Annual budget for professional growth
● Work-life balance; work stops at 4pm

Google
● Innovation, creativity, diversity, inclusivity, flexibility
● Hires for character and skills
● Fun workplace
● Pet-friendly

Examples of Unethical Behavior


While acting with integrity and fairness generally characterizes ethical behavior, the following are
some examples of unethical behavior that auditors should be on the lookout for:

● Undue emphasis on bottom-line performance


● High-pressure sales tactics
● Kickbacks or bribes

Communication, Consistency, and Belief in the Message


It is very important for management to communicate clearly, consistently, and often what is
allowed and what is not. By setting clear expectations there is a better chance that they will be
followed.

Having a code of ethics, code of conduct, and conflict of interest statement is very important to
formally establish the expectations for proper conduct.

New employees should receive these documents upon hire and sign-off indicating they agree to
abide by them. Training should also be required upon hire to make sure that employees
understand fully what the documents mean. These should be followed by annual refresher training.

Another useful activity that leading organizations practice is to have short articles, vignettes,
scenarios, and surveys that are distributed periodically to all staff. This can be done through the
company's newsletter, e-mail, and intranet posts.

Form over Substance


This consists of the management practices whereby on the surface it appears as though an
essential activity has been performed, when in fact that is not so.

Example: signatures, reconciliations

Principles underlying the control environment are:

 The organization should demonstrate a commitment to integrity and ethical values.


 The board of directors demonstrates independence from management and exercises
oversight of the development and performance of internal control.
 Management establishes, with board oversight, structures, reporting lines, and appropriate
authorities and responsibilities in the pursuit of objectives.
 The organization demonstrates a commitment to attract, develop, and retain competent
individuals in alignment with objectives.
 The organization holds individuals accountable for their internal control responsibilities in
the pursuit of objectives.

Entity Level Controls


Entity level controls are used to determine if an organization's values, systems, policies, and
processes would enable or dissuade fraud and encourage proper conduct. They refer to the entity's
management style, as reflected in the corporate culture, values, philosophy, and operating style,
the organizational structure, and policies and procedures in place.

Auditing the entity's framework requires the examination of tangibles (e.g., policies, procedures,
manuals, and rules) and intangibles (e.g., management philosophy, culture, and operating style).

Review items also include human resources (HR) policies, the reporting structure with the
assignment authority and responsibility, information flows, demonstration of a commitment to
competence, and other types of checks and balances in the organization.
Internal auditors are encouraged to remember that a person's behavior is determined by the
person and his or her environment. There are a number of different and competing forces that
combine to result in the situation the individual encounters. In other words, a person's behavior
may be different in unique situations, as the person acts in part in response to the environment.

Organizations need to work diligently to create, nurture, and indoctrinate employees on the
organizational culture through socialization, education, formal/informal systems, and
reinforcement. Creating a sense of family goes a long way toward creating a harmonious,
productive, and ethical environment.

Tone in the Middle


Deciding who becomes a manager is one of the most important organizational actions because
employees judge their organization as ethical or not based on what they think their boss does. So
when it comes to ethics, deciding who become managers is of critical importance. If employees
think that their bosses treat them ethically, honestly, and fairly, that is what they will think about
the company.

This means that the “tone in the middle” dictates workplace conditions leading to customer and
employee satisfaction, turnover, profits, and the achievement of goals and objectives.

The workplace environment is in many ways determined by the level of employee engagement.
There is a very big difference in results when workers are engaged, not engaged, or actively
disengaged.

Risk Assessment
The second component of the COSO framework relates to the identification, quantification,
analysis, and management of organizational risks. Risks are those events that can jeopardize the
organization's ability to achieve its objectives. In other words, they represent what can go wrong
while engaged in business activities in the pursuit of organizational goals.

Risks are typically assessed along two dimensions:

 Likelihood, or the probability that these events occur


 Impact, or the consequence if these events occurred
Establishing objectives is a precondition to risk assessment. A risk assessment is the process of
identifying, assessing, and measuring risks to the organization, program, or process under review.

Control Activities
Controls are actions established through policies and procedures that mitigate the likelihood and/or
impact of risks. Controls are performed at all levels of the organization, at various stages within
processes and over the technological infrastructure of the organization.

Manual vs. Automated Controls


● Manual controls – performed by individuals, often using “hard, tangible” items, such as
paper and locks
● Automated controls – performed by computer and electronic systems, often without direct
or exclusive human interaction

Categories of Control Activities


● Preventive
● Detective
● Directive
● Compensating

Preventive Controls
Preventive controls are those activities that act before the error or omission can occur and reduce
the likelihood and/or impact of the event.

Detective Controls
Detective controls identify errors or anomalies after they have occurred and alert the need for
corrective action.
Directive Controls
Directive controls are temporary controls that are implemented to redirect employee actions. They
are sometimes referred to as corrective controls, because they are put in place when an
undesirable action has occurred, even when there were preventive and detective controls in place.

Compensating Controls
Compensating or mitigating controls are those that are put in place when a control is not where it
is expected as proper design would stipulate.

Examples by Category
Preventive: Segregation of Duties, Authorizations, Access Passwords, Security Cameras, Competent
Employees

Detective: Supervisory Review, Exception Reports, Reconciliations, Security Cameras,


Confirmations

Directive: Training Programs, Policies and Procedures, Required Documentation

Mitigating: Supervisory Review When There is a Lack of Segregation of Duties

Generally speaking, preventive controls are preferable to detective controls because while
detective controls are important and useful, they identify issues after the fact.

Internal auditors are generally tasked with verifying that processes, programs, and their related
controls have been designed appropriately, and that those controls are operating as intended.
When confronted with nonperforming controls, the natural question to ask is “why?”

Reasons vary, but the following are some of the most common answers to that question:

● Inadequate knowledge
● Sabotage
● Emotional and physical reasons
When comparing risks and controls, there is always a need to find the appropriate equilibrium
between the two.

Excessive Risks vs. Excessive Controls


Excessive Risks may lead to:

● Loss of assets
● Loss of grants
● Poor business decisions
● Noncompliance
● Increased regulations
● Public scandals
● Inability to achieve objectives
Excessive Controls (Bureaucracy) may lead to:

● Reduced productivity
● Increased complexity
● Increased cycle time
● Increase in no-value activities

Information and Communication


The fourth component in the COSO IC/IF model refers to the flow of information in an organization.
Ideally, there are clear, consistent, timely, and purposeful directions emanating from the top of the
organization providing direction and establishing the criteria to measure performance results.

There should also be information flowing up in the organization, providing feedback about results
and any issues or unaddressed challenges employees are facing. This forms the foundation for
management operating and financial reports.

Lastly, there should also be lateral flows of information between individuals and operating units to
ensure cooperation and coordination among them. Effective, timely, and clear lateral
communication can prevent confusion, duplication of efforts, and the purchase of assets already in
place in the organization.
Monitoring Activities
Monitoring activities consist of ongoing, separate or a combination of evaluations used to
determine whether each of the five components of internal control is present and functioning.
Ongoing evaluations are built into business processes at different levels of the organization and
provide timely information on how well or poorly these activities are performing.

Separate or cyclical evaluations will vary in terms of scope and frequency based on the risk
assessment performed and the results of previous evaluations.

The review themselves and the criteria used during these reviews, will be based on internal
requirements and other criteria established by external parties, such as regulators, recognized
standard-setting bodies (e.g., ISO), management, and the board of directors. All deficiencies should
be communicated to management and the board of directors as appropriate. In some instances,
deficiencies should be communicated to regulators.

IT and Its Impact on Organizational Success


IT increasingly plays a pivotal role in organizational success. Organizations should think of, or
transform it if it isn't yet, to be a business service partner, instead of just a back-end support unit.

It is important to align IT actions and expenses to business needs and revise them as the business
grows or changes direction.

Following is an examination of several IT frameworks that expand on the previous discussion about
IT in the COSO framework:

● COBIT
● GTAG
● ISO
● CMMI

COBIT
● Control Objectives for Information and Related Technology
● Framework created by the ISACA (Information Systems Audit and Control Association)
● IT governance and management
● Ensures quality, control, and reliability of information systems in an organization, which is
also the most important aspect of every modern business
● First published COBIT framework in 1996
● Latest COBIT version 5 came out in April 2012
Four specific domains:

● Planning & Organization


● Delivering and Support
● Acquiring & Implementation
● Monitoring & Evaluating

GTAG
● Global Technology Audit Guide
● Prepared by The Institute of Internal Auditors (IIA)
● Written in straightforward business language to address a timely issue related to IT
management, control, and security, the GTAG series serves as a ready resource for chief
audit executives on different technology-associated risks and recommended practices
ISO
● International Organization for Standardization
● Independent, non-governmental international organization
● With a membership of 167 national standards bodies
● Has published more than 19,000 international standards and related documents
● Derived from the Greek 'isos', meaning equal

ISO 9000: Quality Management


Address various aspects of quality management and provides guidance and tools for organizations
that want to ensure that their products and services consistently meet customer's requirements,
and that quality is improved continuously.

ISO 17799 and 27001: Setting the Standards for Information Security
● Provide a set of best practices and a certification standard for information security
● Provide best practice recommendations for initiating, implementing, or maintaining
information security management systems

CMMI
● Capability Maturity Model Integration
● Administered by the CMMI Institute, a subsidiary of ISACA
● Developed at Carnegie Mellon University (CMU)
● Widely used in project management, software development, process assessment, and
performance improvement within a project, division, or an entire organization

Characteristics of the Maturity Levels


Level 1 – Initial: Processes unpredictable, poorly controlled and reactive
Level 2 – Managed: Processes characterized for projects and is often reactive.
Level 3 – Defined: Processes characterized for the organization and is proactive. (Projects tailor
their processes from organization's standards)
Level 4 – Quantitatively Managed: Processes measured and controlled
Level 5 – Optimizing: Focus on process improvement

You might also like