0% found this document useful (0 votes)
55 views6 pages

COSO 2013 Internal Control Summary

Internal control is a process put in place by a company's management and board of directors to reasonably ensure that a company achieves its objectives. It helps ensure effective and efficient operations, reliable financial reporting, and compliance with laws and regulations. An internal control system has five components - control environment, risk assessment, control activities, information and communication, and monitoring. It provides reasonable but not absolute assurance regarding achievement of objectives. It cannot ensure a company's success or survival.

Uploaded by

JASEEMLAL
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOC, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
55 views6 pages

COSO 2013 Internal Control Summary

Internal control is a process put in place by a company's management and board of directors to reasonably ensure that a company achieves its objectives. It helps ensure effective and efficient operations, reliable financial reporting, and compliance with laws and regulations. An internal control system has five components - control environment, risk assessment, control activities, information and communication, and monitoring. It provides reasonable but not absolute assurance regarding achievement of objectives. It cannot ensure a company's success or survival.

Uploaded by

JASEEMLAL
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOC, PDF, TXT or read online on Scribd

Internal Control - Integrated Framework

Executive Summary
Senior executives have long sought ways to better control the enterprises they run. Internal controls
are put in place to keep the company on course toward profitability goals and achievement of its
mission, and to minimize surprises along the way. They enable management to deal with rapidly
changing economic and competitive environments, shifting customer demands and priorities, and
restructuring for future growth. Internal controls promote efficiency, reduce risk of asset loss, and help
ensure the reliability of financial statements and compliance with laws and regulations.
Because internal control serves many important purposes, there are increasing calls for better internal
control systems and report cards on them. Internal control is looked upon more and more as a solution
to a variety of potential problems.
What Internal Control Is
Internal control means different things to different people. This causes confusion among
businesspeople, legislators, regulators and others. esulting miscommunication and different
expectations cause problems within an enterprise. !roblems are compounded when the term, if not
clearly defined, is written into law, regulation or rule.
This report deals with the needs and expectations of management and others. It defines and describes
internal control to"
#stablish a common definition serving the needs of different parties.
!rovide a standard against which business and other entities$$large or small, in the public or
private sector, for profit or not$$can assess their control systems and determine how to
improve them.
Internal control is broadly defined as a process, effected by an entity%s board of directors, management
and other personnel, designed to provide reasonable assurance regarding the achievement of
ob&ectives in the following categories"
#ffectiveness and efficiency of operations.
eliability of financial reporting.
'ompliance with applicable laws and regulations.
The first category addresses an entity%s basic business ob&ectives, including performance and
profitability goals and safeguarding of resources. The second relates to the preparation of reliable
published financial statements, including interim and condensed financial statements and selected
financial data derived from such statements, such as earnings releases, reported publicly. The third
deals with complying with those laws and regulations to which the entity is sub&ect. These distinct but
overlapping categories address different needs and allow a directed focus to meet the separate needs.
Internal control systems operate at different levels of effectiveness. Internal control can be &udged
effective in each of the three categories, respectively, if the board of directors and management have
reasonable assurance that"
They understand the extent to which the entity%s operations ob&ectives are being achieved.
!ublished financial statements are being prepared reliably.
(pplicable laws and regulations are being complied with.
)hile internal control is a process, its effectiveness is a state or condition of the process at one or
more points in time.
Internal control consists of five interrelated components. These are derived from the way management
runs a business, and are integrated with the management process. (lthough the components apply to
all entities, small and mid$size companies may implement them differently than large ones. Its controls
may be less formal and less structured, yet a small company can still have effective internal control.
The components are"
Control Environment
$$The control environment sets the tone of an organization, influencing the control consciousness of its
people. It is the foundation for all other components of internal control, providing discipline and
structure. 'ontrol environment factors include the integrity, ethical values and competence of the
entity%s people* management%s philosophy and operating style* the way management assigns authority
and responsibility, and organizes and develops its people* and the attention and direction provided by
the board of directors.
Risk Assessment
$$#very entity faces a variety of risks from external and internal sources that must be assessed. (
precondition to risk assessment is establishment of ob&ectives, linked at different levels and internally
consistent. isk assessment is the identification and analysis of relevant risks to achievement of the
ob&ectives, forming a basis for determining how the risks should be managed. Because economic,
industry, regulatory and operating conditions will continue to change, mechanisms are needed to
identify and deal with the special risks associated with change.
Control Activities
$$'ontrol activities are the policies and procedures that help ensure management directives are carried
out. They help ensure that necessary actions are taken to address risks to achievement of the entity%s
ob&ectives. 'ontrol activities occur throughout the organization, at all levels and in all functions. They
include a range of activities as diverse as approvals, authorizations, verifications, reconciliations,
reviews of operating performance, security of assets and segregation of duties.
Information and Communication
$$!ertinent information must be identified, captured and communicated in a form and timeframe that
enable people to carry out their responsibilities. Information systems produce reports, containing
operational, financial and compliance$related information, that make it possible to run and control the
business. They deal not only with internally generated data, but also information about external
events, activities and conditions necessary to informed business decision$making and external
reporting. #ffective communication also must occur in a broader sense, flowing down, across and up
the organization. (ll personnel must receive a clear message from top management that control
responsibilities must be taken seriously. They must understand their own role in the internal control
system, as well as how individual activities relate to the work of others. They must have a means of
communicating significant information upstream. There also needs to be effective communication with
external parties, such as customers, suppliers, regulators and shareholders.
onitoring
$$Internal control systems need to be monitored$$a process that assesses the +uality of the system%s
performance over time. This is accomplished through ongoing monitoring activities, separate
evaluations or a combination of the two. ,ngoing monitoring occurs in the course of operations. It
includes regular management and supervisory activities, and other actions personnel take in
performing their duties. The scope and fre+uency of separate evaluations will depend primarily on an
assessment of risks and the effectiveness of ongoing monitoring procedures. Internal control
deficiencies should be reported upstream, with serious matters reported to top management and the
board.
There is synergy and linkage among these components, forming an integrated system that reacts
dynamically to changing conditions. The internal control system is intertwined with the entity%s
operating activities and exists for fundamental business reasons. Internal control is most effective
when controls are built into the entity%s infrastructure and are a part of the essence of the enterprise.
-Built in- controls support +uality and empowerment initiatives, avoid unnecessary costs and enable
+uick response to changing conditions.
There is a direct relationship between the three categories of ob&ectives, which are what an entity
strives to achieve, and components, which represent what is needed to achieve the ob&ectives. (ll
components are relevant to each ob&ectives category. )hen looking at any one category$$the
effectiveness and efficiency of operations, for instance$$all five components must be present and
functioning effectively to conclude that internal control over operations is effective.
The internal control definition$$with its underlying fundamental concepts of a process, effected by
people, providing reasonable assurance$$together with the categorization of ob&ectives and the
components and criteria for effectiveness, and the associated discussions, constitute this internal
control framework.
What Internal Control Can !o
Internal control can help an entity achieve its performance and profitability targets, and prevent loss of
resources. It can help ensure reliable financial reporting. (nd it can help ensure that the enterprise
complies with laws and regulations, avoiding damage to its reputation and other conse+uences. In
sum, it can help an entity get to where it wants to go, and avoid pitfalls and surprises along the way.
What Internal Control Cannot !o
.nfortunately, some people have greater, and unrealistic, expectations. They look for absolutes,
believing that"
Internal control can ensure an entity%s success$$that is, it will ensure achievement of basic
business ob&ectives or will, at the least, ensure survival.
#ven effective internal control can only help an entity achieve these ob&ectives. It can provide
management information about the entity%s progress, or lack of it, toward their achievement. But
internal control cannot change an inherently poor manager into a good one. (nd, shifts in government
policy or programs, competitors% actions or economic conditions can be beyond management%s control.
Internal control cannot ensure success, or even survival.
Internal control can ensure the reliability of financial reporting and compliance with laws and
regulations.
This belief is also unwarranted. (n internal control system, no matter how well conceived and
operated, can provide only reasonable$$not absolute$$assurance to management and the board
regarding achievement of an entity%s ob&ectives. The likelihood of achievement is affected by
limitations inherent in all internal control systems. These include the realities that &udgments in
decision$making can be faulty, and that breakdowns can occur because of simple error or mistake.
(dditionally, controls can be circumvented by the collusion of two or more people, and management
has the ability to override the system. (nother limiting factor is that the design of an internal control
system must reflect the fact that there are resource constraints, and the benefits of controls must be
considered relative to their costs.
Thus, while internal control can help an entity achieve its ob&ectives, it is not a panacea.
Roles and Res"onsi#ilities
#veryone in an organization has responsibility for internal control.
anagement
$$The chief executive officer is ultimately responsible and should assume -ownership- of the system.
/ore than any other individual, the chief executive sets the -tone at the top- that affects integrity and
ethics and other factors of a positive control environment. In a large company, the chief executive
fulfills this duty by providing leadership and direction to senior managers and reviewing the way they%re
controlling the business. Senior managers, in turn, assign responsibility for establishment of more
specific internal control policies and procedures to personnel responsible for the unit%s functions. In a
smaller entity, the influence of the chief executive, often an owner$manager, is usually more direct. In
any event, in a cascading responsibility, a manager is effectively a chief executive of his or her sphere
of responsibility. ,f particular significance are financial officers and their staffs, whose control activities
cut across, as well as up and down, the operating and other units of an enterprise.
$oard of !irectors
$$/anagement is accountable to the board of directors, which provides governance, guidance and
oversight. #ffective board members are ob&ective, capable and in+uisitive. They also have a
knowledge of the entity%s activities and environment, and commit the time necessary to fulfill their
board responsibilities. /anagement may be in a position to override controls and ignore or stifle
communications from subordinates, enabling a dishonest management which intentionally
misrepresents results to cover its tracks. ( strong, active board, particularly when coupled with
effective upward communications channels and capable financial, legal and internal audit functions, is
often best able to identify and correct such a problem.
Internal Auditors
$$Internal auditors play an important role in evaluating the effectiveness of control systems, and
contribute to ongoing effectiveness. Because of organizational position and authority in an entity, an
internal audit function often plays a significant monitoring role.
%ther &ersonnel
$$Internal control is, to some degree, the responsibility of everyone in an organization and therefore
should be an explicit or implicit part of everyone%s &ob description. 0irtually all employees produce
information used in the internal control system or take other actions needed to effect control. (lso, all
personnel should be responsible for communicating upward problems in operations, noncompliance
with the code of conduct, or other policy violations or illegal actions.
( number of external parties often contribute to achievement of an entity%s ob&ectives. #xternal
auditors, bringing an independent and ob&ective view, contribute directly through the financial
statement audit and indirectly by providing information useful to management and the board in
carrying out their responsibilities. ,thers providing information to the entity useful in effecting internal
control are legislators and regulators, customers and others transacting business with the enterprise,
financial analysts, bond raters and the news media. #xternal parties, however, are not responsible for,
nor are they a part of, the entity%s internal control system.
%rgani'ation of this Re"ort
This report is in four volumes. The first is this #xecutive Summary, a high$level overview of the internal
control framework directed to the chief executive and other senior executives, board members,
legislators and regulators.
The second volume, the 1ramework, defines internal control, describes its components and provides
criteria against which managements, boards or others can assess their control systems. The
#xecutive Summary is included.
The third volume, eporting to #xternal !arties, is a supplemental document providing guidance to
those entities that report publicly on internal control over preparation of their published financial
statements, or are contemplating doing so.
The fourth volume, #valuation Tools, provides materials that may be useful in conducting an
evaluation of an internal control system.
What to !o
(ctions that might be taken as a result of this report depend on the position and role of the parties
involved"
Senior anagement
$$/ost senior executives who contributed to this study believe they are basically -in control- of their
organizations. /any said, however, that there are areas of their company$$a division, a department or
a control component that cuts across activities$$where controls are in early stages of development or
otherwise need to be strengthened. They do not like surprises. This study suggests that the chief
executive initiate a self$assessment of the control system. .sing this framework, a '#,, together with
key operating and financial executives, can focus attention where needed. .nder one approach, the
chief executive could proceed by bringing together business unit heads and key functional staff to
discuss an initial assessment of control. 2irectives would be provided for those individuals to discuss
this report%s concepts with their lead personnel, provide oversight of the initial assessment process in
their areas of responsibility and report back findings. (nother approach might involve an initial review
of corporate and business unit policies and internal audit programs. )hatever its form, an initial self$
assessment should determine whether there is a need for, and how to proceed with, a broader, more
in$depth evaluation. It should also ensure that ongoing monitoring processes are in place. Time spent
in evaluating internal control represents an investment, but one with a high return.
$oard em#ers
$$/embers of the board of directors should discuss with senior management the state of the entity%s
internal control system and provide oversight as needed. They should seek input from the internal and
external auditors.
%ther &ersonnel
$$/anagers and other personnel should consider how their control responsibilities are being conducted
in light of this framework, and discuss with more senior personnel ideas for strengthening control.
Internal auditors should consider the breadth of their focus on the internal control system, and may
wish to compare their evaluation materials to the evaluation tools.
(egislators and Regulators
$$3overnment officials who write or enforce laws recognize that there can be misconceptions and
different expectations about virtually any issue. #xpectations for internal control vary widely in two
respects. 1irst, they differ regarding what control systems can accomplish. (s noted, some observers
believe internal control systems will, or should, prevent economic loss, or at least prevent companies
from going out of business. Second, even when there is agreement about what internal control
systems can and can%t do, and about the validity of the -reasonable assurance- concept, there can be
disparate views of what that concept means and how it will be applied. 'orporate executives have
expressed concern regarding how regulators might construe public reports asserting -reasonable
assurance- in hindsight after an alleged control failure has occurred. Before legislation or regulation
dealing with management reporting on internal control is acted upon, there should be agreement on a
common internal control framework, including limitations of internal control. This framework should be
helpful in reaching such agreement.
&rofessional %rgani'ations
$$ule$making and other professional organizations providing guidance on financial management,
auditing and related topics should consider their standards and guidance in light of this framework. To
the extent diversity in concept and terminology is eliminated, all parties will benefit.
Educators
$$This framework should be the sub&ect of academic research and analysis, to see where future
enhancements can be made. )ith the presumption that this report becomes accepted as a common
ground for understanding, its concepts and terms should find their way into university curricula.
)e believe this report offers a number of benefits. )ith this foundation for mutual understanding, all
parties will be able to speak a common language and communicate more effectively. Business
executives will be positioned to assess control systems against a standard, and strengthen the
systems and move their enterprises toward established goals. 1uture research can be leveraged off
an established base. 4egislators and regulators will be able to gain an increased understanding of
internal control, its benefits and limitations. )ith all parties utilizing a common internal control
framework, these benefits will be realized.
&urchasing Information
',S, publications are available through the (merican Institute of 'ertified !ublic (ccountants
[Link].org6. 1or further information about ',S, products or to order, contact (I'!( at 777$888$
8988 or visit the '!(:BI; )eb site.
Internal Control - Integrated Framework, : 0ols. 'lick to purchase
Internal Control Issues in Derivatives Usage-An Information Tool, !roduct number <<99=9

Common questions

Powered by AI

Management's philosophy and operating style significantly impact the control environment by influencing the organization's culture and ethical values, which form the foundation of an effective internal control system . The tone set by management affects employee behavior and attitudes towards control practices and adherence to policies . A management team characterized by transparency, integrity, and consistency fosters a positive control environment where employees understand the importance of controls and are committed to upholding them . Conversely, if management exhibits a high tolerance for risk, lack of ethics, or inconsistent policies, it may weaken the control environment, leading to potential control failures . Therefore, management's approach shapes the overall effectiveness of the internal control system and the organization's ability to achieve its objectives .

An effective 'tone at the top' can mitigate control deficiencies by setting a high standard of integrity, ethical behavior, and commitment to control principles that permeates throughout the organization . When senior management and the board emphasize the importance of controls, it creates a culture where employees understand and value compliance and accountability . This top-down approach influences the control environment positively, leading to conscientious and diligent adherence to procedures . Furthermore, an appropriate tone at the top encourages open communication, where employees feel empowered to report deficiencies without fear of retribution, allowing for timely corrective actions . The 'tone at the top' serves as a deterrent to unethical behavior, reduces the risk of management override, and fosters resilience against errors or fraud, thus reinforcing the overall internal control system .

The five interrelated components of internal control—Control Environment, Risk Assessment, Control Activities, Information and Communication, and Monitoring—integrate with the management process by providing a structured framework that influences the control consciousness of an organization’s personnel. The Control Environment sets the foundation for all other components as it establishes the tone and culture, including integrity, ethical values, and competence . Risk Assessment involves identifying and analyzing risks that could hinder objective achievement, thus forming a basis for managing these risks . Control Activities are the policies and procedures that ensure management directives are executed and objectives are achieved . Information and Communication allow pertinent information to be captured and communicated effectively for informed decision-making . Monitoring involves assessing the performance of the control system over time through ongoing activities and evaluations . Together, these components ensure that internal controls are woven into the fabric of the organizational processes, enabling responsiveness to changing conditions .

Internal control assists in achieving an entity's objectives by providing a structured process that enhances performance and profitability, helps ensure reliable financial reporting, and ensures compliance with laws and regulations, thereby preventing resource loss and reputational damage . However, internal control faces limitations, as it can only provide reasonable—not absolute—assurance of achieving objectives due to inherent limitations such as human error, faulty judgment, management override, collusion, and resource constraints . Internal control cannot guarantee the entity's success or survival, nor can it ensure reliability in all circumstances . These limitations suggest that while internal control is vital in guiding towards objectives, it is not foolproof and must be continuously assessed for effectiveness and adaptation to changing conditions .

Monitoring is essential for assessing the performance quality of the internal control system over time. It involves ongoing monitoring activities embedded in operations, regular management and supervisory activities, and separate evaluations based on risk assessments. Effective monitoring enables the identification and correction of control deficiencies, ensuring the system remains responsive to changing conditions. It helps provide assurance that the controls continue to do what they are designed to do, maintaining alignment with organizational objectives .

Control activities help mitigate risks by implementing policies and procedures that ensure management's directives are executed with the aim of achieving the organization’s objectives . These activities occur throughout the organization and encompass a range of functions including approvals, authorizations, verifications, reconciliations, performance reviews, asset security, and duty segregation . By embedding these controls across all levels and functions, organizations can address risks more comprehensively, ensuring that the necessary actions are taken to mitigate identified risks and adapt to changing conditions . This holistic approach ensures that control activities are effective in mitigating risks, supporting the enterprise’s overall internal control system .

Effective information and communication are critical to the internal control process as they ensure that pertinent information is identified, captured, and communicated in a timely manner across the organization, thus enabling individuals to carry out their responsibilities effectively . Information systems produce reports containing operational, financial, and compliance-related information crucial for running and controlling the business . Moreover, communication must flow down, across, and up the organization, delivering a clear message from top management about the seriousness of control responsibilities . Such communication not only facilitates informed decision-making but also enhances transparency and accountability, supporting overall governance through feedback loops . External communication with customers, suppliers, regulators, and shareholders is equally important, supporting compliance and strategic objectives .

Management can override the internal control system by ignoring or stifling communications from subordinates, enabling potentially dishonest reporting. A robust, active board, particularly with effective upward communication channels and capable financial, legal, and internal audit functions, plays a crucial role in recognizing and addressing potential management overrides. The board's governance, guidance, and oversight capacities are essential in ensuring the integrity and effectiveness of the internal control system .

The integration of internal controls into an entity's operations ensures that controls are not isolated activities but are intimately involved with operating processes and decisions. This integration helps align controls with business objectives, supporting quality and empowerment initiatives, minimizing unnecessary costs, and enabling a quick response to changes. It ensures that controls are part of the organization's essence, effectively functioning as part of its infrastructure, which enhances the overall effectiveness of the internal control system .

Misconceptions about internal control systems include the belief that they guarantee success, survival, and absolute reliability in financial reporting and compliance. These beliefs are unfounded as internal controls can only provide reasonable assurance due to inherent limitations. Addressing these misconceptions involves clarifying that while internal controls can guide organizations towards their objectives, they cannot alter external factors or managerial competence. Promoting a common understanding of their role, limitations, and reasonable expectations can help set realistic views .

You might also like