0% found this document useful (0 votes)
119 views3 pages

Internal Control Review Process Overview

Internal control review is an assessment of an organization's internal control system to ensure it is functioning as intended and provides reasonable assurance in achieving objectives related to operations, financial reporting, and compliance. It involves continuously evaluating controls across all functions to monitor and identify any deficiencies. The assessment facilitates corrective actions to improve the internal control system.

Uploaded by

Patrick Kariuki
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
119 views3 pages

Internal Control Review Process Overview

Internal control review is an assessment of an organization's internal control system to ensure it is functioning as intended and provides reasonable assurance in achieving objectives related to operations, financial reporting, and compliance. It involves continuously evaluating controls across all functions to monitor and identify any deficiencies. The assessment facilitates corrective actions to improve the internal control system.

Uploaded by

Patrick Kariuki
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
  • Introduction and FAQs
  • Components of the Internal Control System
  • Importance of Internal Control Review
  • Mandatory Submission of ICR Reports

Internal Control Review

Internal control review assumes greater importance in the light of current economic
downturn. Monitoring and assessment of internal controls across various functions is
performed through continuous evaluations to ensure whether the implemented internal
control system is effective as intended by the Board of Directors. The assessment
facilitates identification of internal control deficiencies for further corrective actions.

Frequently Asked Questions

1. What is Internal Control Review – ICR and how different it is to Internal Audit?

ICR is an overall assessment of the internal control system and its adequacy of each
business area in an organization to address the relevant risks. Through control review,
an organization's resources are directed, monitored, and measured in an effective
manner. It plays an important role in protecting the organization's tangible and intangible
resources.

Whereas, Internal audit as defined by the Institute of Internal Auditors is "an activity that
provides independent, objective assurance and consulting activity designed to add
value and improve an organization’s operations. It helps an organization accomplish its
objectives by bringing a systematic, disciplined approach to evaluate and improve the
effectiveness of risk management, control, and governance processes".

2. What is an internal control?

The framework of the Committee of Sponsoring Organizations of the Treadway


Commission (COSO) defines internal control as "a process effected by an entity's Board
of Directors, management and other personnel, designed to provide reasonable
assurance regarding the achievement of objectives in the following categories":

 Effectiveness and efficiency of operations;


 Reliability of financial reporting;
 Compliance with applicable laws and regulations.

3. How can an effective internal control system established?

To create an effective internal control system, an organization should establish the


following:

 Policies and procedures including, among others, organizational structure, job


descriptions, authorization matrix;
 Segregation of duties and responsibilities;
 Authorization and approval process;
 Performance monitoring and control procedures;
 Safeguarding assets, completeness and accuracy;
 Manpower management;
 Independent internal audit function;
 Regulatory compliance and risk management.

4. Then, what are the components of the internal control system?

As per the COSO model, the components of the internal control system are:

 Control Environment: This sets the tone for the organization, influencing the
control consciousness of its people. It is the foundation for all other components
of internal control.
 Risk Assessment: The identification and analysis of relevant risks to the
achievement of objectives, forming a basis for how the risks should be managed.
 Control Activities: The policies and procedures that help ensure management
directives are carried out.
 Information & Communication: Systems or processes that support the
identification, capture, and exchange of information in a form and time frame that
enables people to carry out their responsibilities.
 Reporting & Monitoring: Processes used to identify, monitor and report the
quality of internal control performance or deficiencies to appropriate levels.

5. Are the controls in your organization appropriate?

Controls over the business activities in an organization is said to be appropriate by


establishing the following:

 Adequacy & compliance of policy and procedures;


 Proper governance structure;
 Monitoring the manpower management;
 Proper periodical review of business activities;

6. What are the benefits of Internal Control Review?

 Encourage adherence to prescribed policies and procedures;


 Effectiveness and efficiency of operations;
 Reliability of financial reporting;
 Compliance with applicable laws and regulations;
 Detection and prevention errors and irregularities in a timely manner;

7. Is Internal Control Review mandatory?

As per the various circulars issued by Central Bank of Kuwait (CBK) from time to time,
banking and investment companies are mandated to comply with ICR regulations. The
ICR auditors are to provide their opinions and remarks on whether the regulations and
internal control systems are sufficient enough in quality and quantity to manage the
risks that the company faces in its day-to-day business.
As has been the practice, all banks have to submit ICR reports by June 30 every year to
CBK. However, this is notified year on year.

Common questions

Powered by AI

An effective internal control system contributes to organizational success and compliance by ensuring the effectiveness and efficiency of operations, the reliability of financial reporting, and adherence to applicable laws and regulations . It also facilitates the detection and timely prevention of errors and irregularities, thereby safeguarding the organization's assets and maintaining order within the operational framework . Internal controls motivate adherence to established policies, leading to improved governance and risk management .

Internal Control Review (ICR) is an overall assessment of the internal control system's adequacy to address relevant risks and involves directing, monitoring, and measuring resources effectively to protect an organization's assets . It primarily focuses on the assessment of control mechanisms and compliance with policies and procedures . Internal Audit, on the other hand, is defined as an independent and objective assurance activity aimed at adding value and enhancing operations by evaluating the effectiveness of risk management, control, and governance processes . While ICR ensures the system's adequacy, internal audit provides a systematic, disciplined approach to assess and improve processes .

The COSO framework defines internal control as a process effected by an entity's Board, management, and personnel, designed to provide reasonable assurance about achieving objectives in operations, reporting, and compliance . Its key components are the Control Environment, Risk Assessment, Control Activities, Information & Communication, and Monitoring . These components collectively help in managing risks, ensuring information flow, and maintaining control consistency across the organization .

Continuous evaluations of internal control systems are crucial for organizations as they help in assessing the effectiveness of controls in mitigating risks over time . These evaluations assist in identifying deficiencies that require corrective actions, thus enabling organizations to promptly address potential vulnerabilities . By continuously monitoring and assessing controls, organizations can maintain the reliability of risk management practices, adjust to changing conditions, and ensure compliance with evolving standards and regulations . This dynamic approach allows organizations to proactively manage risks before they escalate into significant issues .

Discovering internal control deficiencies during a review process indicates that existing controls may not be adequately mitigating relevant risks, potentially exposing the organization to operational inefficiencies or compliance violations . Corrective actions could include revising policies and procedures, enhancing training programs, reinforcing segregation of duties, or implementing additional monitoring controls to address identified gaps . Such steps ensure that controls remain effective in safeguarding assets and aligning operations with organizational objectives .

The Central Bank of Kuwait (CBK) mandates that banking and investment companies perform Internal Control Reviews (ICRs) to ensure regulatory compliance . The CBK requires banks to submit ICR reports annually, offering opinions on the sufficiency and quality of their internal control systems in managing business risks . This regulatory oversight ensures that institutions maintain robust control frameworks aligned with the CBK's directives, fostering stability and trust in the financial system . Non-compliance may lead to regulatory action, affecting the institutions' operational legitimacy and credibility within the market .

Adherence to prescribed policies and procedures is a significant benefit of conducting an Internal Control Review (ICR) because it ensures organizational consistency, accountability, and compliance with regulatory standards . ICR helps identify areas where controls may be bypassed or inadequately followed, allowing for corrective measures to be implemented, which maintains the integrity of operations and enables the organization to meet its strategic goals efficiently .

Segregation of duties enhances internal controls by dividing responsibilities among different individuals to reduce the risk of errors or fraud . This separation ensures that no single person has control over all aspects of any critical process, thus enabling checks and balances within operational procedures . If not properly managed, lack of segregation could lead to unauthorized transactions, misappropriations, and undetected errors, ultimately compromising the integrity and reliability of financial reports and operational workflows .

To establish a robust internal control environment, essential policies and procedures include defining organizational structure, clear job descriptions, and an authorization matrix . This involves setting up processes for segregation of duties, establishing authorization and approval mechanisms, and implementing performance monitoring and asset safeguarding strategies . Additionally, maintaining an independent internal audit function and ensuring compliance with regulations are crucial in supporting a resilient control environment .

The reporting and monitoring component of the COSO framework enhances governance quality by establishing processes to identify, monitor, and report the performance and deficiencies of internal controls to appropriate levels . This ensures that management and governance bodies are informed about the control environment's status, facilitating timely decision-making and corrective actions . Effective reporting and monitoring mechanisms reinforce accountability, transparency, and trust in the organization's governance processes .

Internal Control Review
Internal control review assumes greater importance in the light of current economic 
downturn. Monito

Manpower management;

Independent internal audit function;

Regulatory compliance and risk management.
4. Then, what are
As has been the practice, all banks have to submit ICR reports by June 30 every year to
CBK. However, this is notified year o

You might also like