Internal Control Systems – Evaluation tool
Overview
Internal Control and Risk
Risk Assessment
Responsibility and Accountability
Overview of Internal Controls
TOOL #1: Control Conscious Environment
TOOL #2: Separation of Duties
TOOL #3: Authorization
TOOL #4: Control over Assets / Records
TOOL #5: Monitoring
Change Management
The “RED FLAGS” of fraud
2
What is Internal Control
• Internal Control (IC) – is a process carried out to achieve:
• Effectiveness and efficiency of operations,
• Reliability of financial reporting, and
• Compliance with applicable laws and regulations.
• Fundamentals –
• IC is the responsibility of everyone
• IC is a built-in part of the management process - applies to all
areas.
• IC provides only reasonable assurance – not absolute assurance in
achieving SASCO Group’s objectives.
3
What is Risk?
• Risk – The possibility of an event occurring that will have a negative
impact on the achievement of objectives.
• Opportunity – The opposite of risk. The possibility of an event
occurring that will have a positive impact on the achievement of
objectives.
4
Risk Assessment – taking risk, not avoidance
• Taking risks is a normal unavoidable everyday necessity
• Taking controlled, informed risks is a sensible and everyday
essential part of life
• Taking uninformed, uncontrolled risks is patently dumb
• We take risks not to avoid harm, but to achieve benefits and gains
• Risk taking is positive, not implicitly negative
5
Managing Risk
• We all manage risk consciously or unconsciously – but rarely
systematically
• Managing risk = forward thinking
• Managing risk = responsible thinking
• Managing risk = balanced thinking
• Risk management provides a framework to facilitate more effective
decision making
• Risk management is all about maximizing opportunity by managing risk
6
Risk Management Defined
Stated simply, Risk management is
about establishing the oversight,
control and discipline to drive
continuous improvement of an
entity’s risk management capabilities
in a changing operating environment
7
Benefits of Risk Management
Sustain • Incorporate operational risk management best practices
Competitive • Better identification, assessment and management of emerging external risks
Advantage
• Proactive evaluation and management of risks associated with strategic business
decisions (product/service offerings, expansion to new markets, etc.)
Optimize Costs • Standardize business process and collaborate efforts to integrate
• More efficiently allocate capital
• Preventive vs. reactive approach to risk management
• Manage KPI shortfalls and tightened margins
Improve • Better understand risks and improve risk management capabilities across
Business business functions
Performance • Improve strategic management and business planning processes – more
systematic decision-making process
8
Risk Management
C
O ESTABLISH THE CONTEXT
M
M
M
U O
N N
I I
C IDENTIFY RISKS T
A O
T R
E
ANALYZE RISKS
& &
ASSESS RISKS
C R
O EVALUATE RISKS E
N V
S I
U
E
L
T TREAT RISKS W
9
Establish the Context
ESTABLISH THE CONTEXT
Strategic Context
Organizational Context
C
Risk Management Context
O
Develop Criteria
M M
M Decide the Structure
O
U
N N
I I
IDENTIFY RISKS
C T
A O
T R
E ANALYZE RISKS
ASSESS RISKS &
&
C EVALUATE RISKS R
O E
N V
S I
U E
L
TREAT RISKS
W
T
10
Identify Risks
C
O ESTABLISH THE CONTEXT
M
M
M
O
U IDENTIFY RISKS
N N
I What can happen? I
C How can it happen? T
A O
T R
E
ANALYZE RISKS
& &
ASSESS RISKS
C R
O EVALUATE RISKS E
N V
S I
U
E
L
T TREAT RISKS W
11
Analyze Risks
C
O ESTABLISH THE CONTEXT
M
M
M
U IDENTIFY RISKS O
N N
I I
C ANALYZE RISKS T
A O
T Determine existing controls
R
E Determine Determine
Likelihood Consequences
& &
Estimate Level of Risk
C R
O E
N V
S EVALUATE RISKS I
U
E
L
T W
TREAT RISKS
12
Evaluate Risks
C
O ESTABLISH THE CONTEXT
M
M
M
U IDENTIFY RISKS O
N N
I I
C T
A ANALYZE RISKS O
T R
E
EVALUATE RISKS &
&
Rank risks R
C
O Compare against criteria E
N Set risk priorities V
S I
U
E
L
T W
TREAT RISKS
13
Treat Risks
C
O ESTABLISH THE CONTEXT
M
M
M
O
U IDENTIFY RISKS
N N
I I
C T
A ANALYZE RISKS O
T R
E ASSESS RISKS
&
& EVALUATE RISKS
C R
O E
N TREAT RISKS V
S Identify treatment options I
U Evaluate treatment options E
L Select treatment options
T W
Prepare treatment plans
Implement plan
14
Monitor & Communicate
C
O ESTABLISH THE CONTEXT
M
M
M
U O
N N
I I
C IDENTIFY RISKS T
A O
T R
E
ANALYZE RISKS
& &
ASSESS RISKS
C R
O EVALUATE RISKS E
N V
S I
U
E
L
T TREAT RISKS W
15
What is Responsibility
• The activities, goals, functions, actions, etc., that a person has to
account for or answer to.
• To provide reasonable assurance that organizational goals will be
accomplished.
What is Accountability
• A person responsible for action is also accountable.
• Responsibility and accountability are linked.
• Management can delegate some of the duties they are responsible
for, but cannot delegate responsibility or accountability
16
Overview of Internal Control Tools
• Identify the appropriate controls to manage the risks.
• Managers and employees need to focus on high risk, high priority
areas
Importance of Internal Controls
• IC is like a map that helps us to get to our destination.
• IC helps to increase reliability of information, promote efficiency and
effectiveness, safeguard assets and comply with rules and
regulations.
17
Who is Responsible for Internal Controls?
• The chairman, managing director and directors are primarily
responsible for identifying the internal controls for their operations.
• Individual employees have responsibility for evaluating, establishing
and/or improving, and monitoring internal controls for their areas of
responsibility and accountability.
The issue of trust
• Trusting employees is not a replacement for a manager’s internal
control system.
• Any override of controls provides an “opportunity” for someone to
take advantage of the system.
18
Key Control Tools
• Creation of a Control-Conscious Environment
• Separation of duties
• Authorization / Approval
• Control over physical and intellectual Assets
• Monitoring
Preventive and Detective Controls
• Preventive controls attempt to deter or prevent undesirable acts
from occurring.
• Detective controls attempt to detect undesirable acts.
• They provide evidence that a loss has occurred but do not prevent
a loss from occurring.
19
Tool #1: Control Conscious Environment
• It’s an environment that supports ethical values and business
practices – is a preventive control
• Management is responsible in setting up a control environment that
encourages:
• highest level of integrity, personal and professional standards
• a leadership philosophy and operating style throughout the
organization
• assignment of authority and responsibility to ensure highest
level of accountability
20
Tool #2: Separation of Duties
• Functions are divided so that no one person has control over all
parts of a transaction
• Activities to separate:
• Initiating / Authorizing / Recording / Reconciling
• Physical controlling
• If same person authorizes and reconciles, additional monitoring is
necessary.
21
Tool #3: Authorization
• Transactions are executed and access to assets is permitted only in
accordance with management’s directives.
• Managers should question what they sign, at least on a sample
basis.
• Questioning various transactions and requesting additional
information enhances a control conscious environment.
• Written procedures outlining the delegation guidelines should be
developed.
• Access to, and use of, computing resources is restricted to
appropriately authorized users.
22
Tool #4: Control Conscious Assets / records
• Establishing control procedures to prevent loss of physical and
intellectual assets / records and assuring that they are physically
secured.
• Managers are personally responsible for the assets in their division.
• Equipment moved between sites / divisions needs to be monitored.
• Separation of duties should be maintained between person who
has custody of assets / records and person who takes physical
inventory.
23
Tool #5: Monitoring
• Monitoring ensures that the internal control system is operating as
expected.
• The internal controls should be functioning and effective.
• Managers / employees should perform ongoing monitoring activities
to determine whether the control system can be relied on to provide
reasonable assurance that financial and compliance goals can be
accomplished and to address new risks.
• Monitoring aids in identifying losses, errors or irregularities.
24
Tool #5: Monitoring
• Management’s role in the internal control system is critical to its
effectiveness, to determine that controls are functioning in high-risk
areas.
• Financial reports are a key monitoring tool. Managers should
obtain the following reports to exercise controls:
• Comparison of actual to budget
• Comparison of the current month to the previous month
• Comparison of the current month to the previous year’s month
• Special account analysis for high risk accounts
• Reconciliation of division’s balances on a monthly basis
• Variances should be reported and summarized
25
Monitoring Activities
• Review and evaluate financial reports for propriety and trends
• Verify the propriety of supporting documentation
• Review reconciliations, ensuring that reconciling items are
investigated
• Have Internal Audit review high risk areas
• Have periodic asset counts performed
• Make surprise cash counts
• Follow-up on complaints, rumors, allegations
• Send out periodic confirmation of accounts receivable
26
Change Management
• We all are operating in a constantly changing environment
that requires continuous review and monitoring
• As external and internal events occur, an organization’s risks may
significantly change.
• All employees must re-evaluate risks and internal controls when
circumstances change
• We should review risk factors on a periodic basis. It should be part
of our on-going monitoring process.
27
The “Red flags” of fraud
Some of the factors that can result in the occurrence of fraud:
MOTIVE JUSTIFICATION OPPORTUNITY
• Greed • “It was so easy.” • Poor or weak
• Financial crisis • “They don’t pay internal control
• Gambling/drinking/ me enough.” system
• “My child is sick.” • Lack of monitoring
drugs
• True crisis, divorce, etc. the controls
• Living beyond means • High management
• Affairs • “My boss
turnover
circumvents the
• Mid-life crisis
rules.”
• Revenge
• “I’ll pay it back.”
• Unappreciated
• Workaholic
• Family Problems
28
The “RED FLAGS” of fraud
Below are some indications that fraud might be or is actual occurring:
Employee won’t take a vacation.
Unexplained variances.
No reconciliation to SASCO Group accounting records.
Missing reports/documents.
Failure to investigate reconciling items.
One employee “does it all”.
Duplicate payments or documentation is not original.
Using “exemptions” to use particular vendor over and over.
29
Any Questions?
Contact:
Govinda Raju K, ACA, CWA
Internal Auditor – SASCO Group
raj@[Link]
30