0% found this document useful (0 votes)
16 views7 pages

Internal Control and COSO Framework Overview

accountability and control ch11

Uploaded by

ahmad arabi
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
16 views7 pages

Internal Control and COSO Framework Overview

accountability and control ch11

Uploaded by

ahmad arabi
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Internal Control and COSO Framework

Internal Control Objectives


 A system of internal control consists of policies and procedures designed to provide management with
reasonable assurance that the company achieves its objectives and goals. These policies and procedures are
often called controls, and collectively, they make up the entity’s internal control.
1- Reliability of financial reporting: (Auditors Focus on)
This objective relates to internal and external financial reporting as well as nonfinancial reporting
management is responsible for preparing financial statements for investors, creditors, and other users.
Management has both a legal and professional responsibility to be sure that the information is fairly
presented.

2- Efficiency and effectiveness of operations:


Controls within a company encourage efficient and effective use of its resources to optimize the
company’s goals.

3- Compliance with laws and regulations: (Auditors Focus on)


Section 404 requires management of all public companies to issue a report about the operating
effectiveness of internal control over financial reporting. organizations are required to follow many laws
and regulations.

Management and Auditor Responsibilities for Internal Control

 Auditors: responsibilities include understanding and testing internal control over financial reporting. Auditors
of larger public companies are required by the SEC to annually issue an audit report on the operating
effectiveness of those controls.

 Management: is responsible for establishing and maintaining the entity’s internal controls. Management is
also required by Section 404 to publicly report on the operating effectiveness of those controls. Also is
responsible for the preparation of financial statements in accordance with applicable accounting frameworks.

 Two key concepts underlie management’s design and implementation of internal control:
1- Reasonable Assurance
A company should develop internal controls that provide reasonable, but not absolute, assurance that
the financial statements are fairly stated. Internal controls are developed by management after
considering both the costs and benefits of the controls.

2- Inherent Limitations
Internal controls can never be completely effective, regardless of the care followed in their design and
implementation. Even if management can design an ideal system, its effectiveness depends on the
competency and dependability of the people using it. Also, collusion is still possible.

 An act of two or more employees who conspire to steal assets or misstate records is called collusion.

Management’s Section 404 Reporting Responsibilities


 Requires management of all public companies to issue an internal control report that includes the following:
1- A statement that management is responsible for establishing and maintaining an adequate internal control
structure and procedures for financial reporting.
2- An assessment of the effectiveness of the internal control structure and procedures for financial reporting
as of the end of the company’s fiscal year
 Management must also identify the framework used to evaluate the effectiveness of internal control. The
internal control framework used by most U.S. companies is the Committee of Sponsoring Organizations of the
Treadway Commission (COSO)
 Management’s assessment of internal control over financial reporting consists of two key aspects.
1- Design of Internal Control
Management must evaluate whether the controls are designed and put in place to prevent or detect
material misstatements in the financial statements.
2- Operating Effectiveness of Controls
The objective is to determine whether the controls are operating as designed and whether the person
performing the control possesses the necessary authority and qualifications to perform the control
effectively.

Auditor Responsibilities for Understanding Internal Control


 Auditing standards require the auditor to obtain an understanding of internal control relevant to the audit on
every audit engagement. Auditors are primarily concerned about controls over:
1- Controls Over the Reliability of Financial Reporting
Auditors focus primarily on controls related to the first of management’s internal control concerns:
reliability of financial reporting. Also, should not ignore budgets and internal performance reports.
2- Controls Over Classes of Transactions
Auditors emphasize internal control over classes of transactions rather than account balances because the
accuracy of accounting system outputs (account balances) depends heavily on the accuracy of inputs and
processing (transactions).
The auditor must also gain an understanding of controls over ending account balance and presentation and
disclosure objectives.
 Section 404(b) of Sarbanes-Oxley requires that the auditor report on the effectiveness of internal control over
financial reporting.

COSO Components of Internal Control


 The COSO Framework describes five components of internal control that
management designs and implements to provide reasonable assurance that
its control objectives will be met.
1- Control Environment 4- Information and Communication
2- Risk Assessment 5- Monitoring
3- Control Activities
 The updated COSO framework includes a total of 17 broad principles that provide guidance to support all
three internal control objectives:

1- Reporting 3- Compliance
2- Operations

1- The control environment


o The control environment consists of the
actions, policies, and procedures that reflect
the overall attitudes of top management,
directors, and owners of an entity about
internal control and its importance to the
entity.
o There is five principles related to the
control environment include:
1) Integrity and Ethical Values:
 Integrity and ethical values are the product of the entity’s ethical and behavioral standards, as
well as how they are communicated and reinforced in practice.
 It includes management’s actions to remove or reduce incentives, also include the
communication of entity values and behavioral standards to personnel through policy statements,
codes of conduct, and by example.
 For example, does management take significant risks or is it risk averse? Are sales and earnings
targets unrealistic, and are employees encouraged to take aggressive actions to meet those
targets? Can management be described as “fat and bureaucratic”; “lean and mean”?

2) Board of Director or Audit Committee Participation:


 BOD has ultimate responsibility to make sure management implements proper internal control
and financial reporting processes.
 An effective board of directors is independent of management.
 The board creates an audit committee independent of management that is charged with oversight
responsibility for financial reporting.

3) Organizational Structure:
 The entity’s organizational structure defines the existing lines of responsibility and authority.
 By understanding the client’s organizational structure, the auditor can learn the management and
functional elements of the business and perceive how controls are implemented.

4) Commitment to Competence
 Competence is the knowledge and skills necessary to accomplish tasks that define an individual’s
job.
 If employees are competent and trustworthy, other controls can be absent, and reliable financial
statements will still result.
 Because of the importance of competent, trustworthy personnel in providing effective control,
the methods by which persons are hired, evaluated, trained, promoted, and compensated are an
important part of internal control.

5) Accountability
 Management and the board of directors are responsible for communicating expectations and
holding individuals accountable for internal control duties.
 Incentives should be provided for employees to fulfill their internal control duties.

2- Risk Assessment
o A process for identifying and analyzing risks that may prevent the organization from achieving its
objectives.
o Involves management’s identification and analysis of risks relevant to the preparation of financial
statements in conformity with appropriate accounting standards.
o There are four underlying principles related to risk assessment:
1) Have clear objectives.
2) Determine how risks should be managed.
3) Consider potential for fraud.
4) Monitor changes.

3- Control Activities
o The policies and procedures that help ensure that necessary actions are taken to address the risks to the
achievement of the entity’s objectives.
o There are three underlying principles related to control activities:
1) Develop control activities that mitigate risks to an acceptable level.
2) Develop general controls over technology.
3) Establish appropriate policies, procedures, and expectations.
o Control activities generally fall into the following five types:
1) Adequate separation of duties
Four general guidelines for adequate separation of duties:
a. Separation of the Custody of Assets from Accounting
A person who has temporary or permanent custody of an asset should not account for that
asset.

b. Separation of the Authorization of Transactions from the Custody of Related Assets


It is desirable to prevent persons who authorize transactions from having control over the
related asset

c. Separation of Operational Responsibility from Record-Keeping Responsibility


For example, if a department or division oversees the creation of its own records and
reports, it might change the results to improve its reported performance.

d. Separation of IT Duties from User Departments

2) Proper authorization of transactions and activities


This is composed of both general authorization that management establishes through policies and
procedures and specific authorization that applies to individual transactions.

3) Adequate documents and records


Documents and records are the records upon which transactions are entered and summarized. They
include such diverse items as sales invoices, purchase orders, subsidiary records, sales journals,
and employee time reports.
Certain principles dictate the proper design and use of documents and records:
 Prenumbered consecutively
 Prepared at the time a transaction takes place.
 Designed for multiple use.
 Constructed to encourage correct preparation.

4) Physical control over assets and records


To maintain internal control, assets and records must be protected.
An example is the use of storerooms for inventory to guard against theft.
5) Independent checks on performance
Careful and continuous review of the first four control activities. This is often called independent
checks or internal verification. Personnel responsible for verification must be independent of those
originally responsible for preparing the data.

4- Information and Communication:


o The entity’s information and communication system’s purpose is to initiate, record, process, and report the
entity’s transactions and maintain accountability for related assets.
o There are three underlying principles related to Information and Communication:
1) Use relevant, quality information to support the functioning of internal controls.
2) Communicate information internally, including objectives and responsibilities for internal control.
3) Communicate with external parties relevant information related to internal controls.

5- Monitoring
o Involves ongoing or periodic assessment of the quality of internal control by management. In larger
companies, the internal audit department is essential for this function.
o There are three underlying principles related to Monitoring:
1) Perform periodic evaluations.
2) Communicate identified deficiencies to those who can remediate.

Internal Controls Specific to Information Technology


Auditing standards describe two categories of controls for IT systems: general controls and application controls:

1. General controls
Controls that apply to all aspects of the IT function, including IT administration; separation of IT duties;
systems development; physical and online security over access to hardware, software, and related data;
backup and contingency planning in the event of unexpected emergencies; and hardware controls.

2. Application controls
Typically operate at the business process level and apply to processing transactions, such as controls over the
processing of sales or cash receipts.

Systems Development includes:


o Purchasing or developing software that meets the organization’s needs
o Testing all new software to ensure that it is compatible with existing software, which may be done as:
a. Pilot testing:
A new system is implemented in one part of the organization while other locations continue to rely
on the old system.
b. Parallel testing:
The old and new systems operate simultaneously in all locations.

Input controls:
o are designed to ensure that the information entered into the computer is authorized, accurate, and complete.
o Typical controls developed for manual systems are still important in IT systems, such as:
a. Management’s authorization of transactions.
b. Adequate preparation of input source documents.
c. Competent personnel.
o Controls specific to IT include:
a. Adequately designed input screens with preformatted prompts for transaction information
b. Pull-down menu lists of available software options.
c. Computer-performed validation tests of input accuracy, such as the validation of customer numbers
against customer master files.
d. Online-based input controls for e-commerce applications where external parties, such as customers
and suppliers, perform the initial part of the transaction inputting.
e. Immediate error correction procedures, to provide for early detection and correction of input errors.
f. Accumulation of errors in an error file for subsequent follow-up by data input personnel.

You might also like