0% found this document useful (0 votes)
13 views19 pages

Internal Control Overview and Framework

Uploaded by

Nấm
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
13 views19 pages

Internal Control Overview and Framework

Uploaded by

Nấm
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

LOGO

INTERNAL CONTROL

PhD. Ta Thu Trang

LOGO
Internal Control
 Chapter 1: Overview of Internal Control
 Chapter 2: Components of Internal Control
 Chapter 3: Internal Control over Purchasing and
Payment Cycle
 Chapter 4: Internal control over sale and collection
cycle
 Chapter 5: Internal control over personel & payroll
cycle
 Chapter 6: Internal control over tangible fixed
assets
 Chapter 7: Internal control over the cash
2

LOGO
Chapter 1
Overview of Internal Control
1.1 Definition of Internal Control

1.2 Evolution of Internal Control

1.3 Limitation of Internal Control

1.4 Content of COSO Framework

1.5 Role of interested parites for internal control

[Link] Phan Thanh Hải 1


LOGO

1.1. Definition of Internal Control

“Internal Control is the system designed, implemented


and maintained by those charged with governance,
management and other personnel, to provide reasonable
assurance about the achievement of an entity’s objectives
with regard to reliability of financial reporting, effectiveness
and efficiency of operations, and compliance with

applicable laws and regulations”


(ISA 315)
4

LOGO
1.1. Definition of Internal Control

“A system of internal control consists of policies and


procedures designed to provide management with
reasonable assurance that the company achieves its
objectives and goals”.
(Alvin et al., 2020)

LOGO

1.1. Definition of Internal Control


Internal control means establishment and implementation
of internal mechanism, policies, procedures, and
regulations conformable with law meant to prevent,
discover, and deal with the risks and meet the set
requirements.
(Accounting Law No. 88/2015/QH13/ Article 39)
Each accounting unit must establish an internal control
system to meet the following requirements:
a) Its assets are protected from improper and inefficient
use;
b) The transactions are approved intra vires and fully
recorded as the basis for making and presenting truthful
and reasonable financial statements.
6

[Link] Phan Thanh Hải 2


LOGO
1.1. Definition of Internal Control

 Internal control is defined as follows:

Internal control is a process, effected by an entity’s


board of directors, management, and other personnel,
designed to provide reasonable assurance regarding the
achievement of objectives relating to operations, reporting,
efficiency reliability
and compliance.
& effectiveness
with regulations (COSO 2013 - Framework)

LOGO

1.1. Definition of Internal Control


This definition reflects certain fundamental concepts.
Internal control is:
 Geared to the achievement of objectives in one or more
categories—operations, reporting, and compliance
 A process consisting of ongoing tasks and activities—a means to an
end, not an end in itself
 Effected by people—not merely about policy and procedure
manuals, systems, and forms, but about people and the actions
they take at every level of an organization to affect internal control
 Able to provide reasonable assurance—but not absolute assurance,
to an entity’s senior management and board of directors
 Adaptable to the entity structure—flexible in application for the
entire entity or for a particular subsidiary, division, operating unit, or
business process
8

LOGO

1.1. Definition of Internal Control


Objectives of Internal Control:
 Operations Objectives—These pertain to effectiveness and
efficiency of the entity’s operations, including operational and
financial performance goals, and safeguarding assets against loss.

 Reporting Objectives—These pertain to internal and external


financial and non-financial reporting and may encompass reliability,
timeliness, transparency, or other terms as set forth by regulators,
recognized standard setters, or the entity’s policies.

 Compliance Objectives—These pertain to adherence to laws and


regulations to which the entity is subject.
9

[Link] Phan Thanh Hải 3


LOGO
* Limitation of Internal Control
 Costs should not exceed benefit.

 Breakdowns that can occur because of human failures such as


simple errors

 Ability of management to override internal control

 Ability of management, other personnel, and/or third parties to


circumvent controls through collusion

 External events beyond the organization’s control

 Design to deal with what normally or routinely happens in a


business

10

LOGO

1.2. Evolution of Internal Control

The theoretical foundation for internal control


can mainly be found in the financial statement
audit, in the 1940s a first attempt at formalizing
an internal control concept was made in the US,
where from the beginning this concept focused
on getting organizations under control.

LOGO
1.2. Evolution of Internal Control

 One of the first published definitions of internal control can be


found in the 1949 research report of the Committee on Auditing
Procedure of the American Institute of Certified Public
Accountants (AICPA), followed by many adjustments and
refinements.
 Management's role in internal control was explicitly discussed for
the first in the Statement on Auditing Standards No. 1, issued by
the AICPA in 1972
 In 1983, the Institute of Internal Auditors published a very broad
definition of internal control
 In 1985, the Treadway Commission was established to examine
the causes of fraudulent financial reporting by leading
organizations of which some went bankrupt entirely unexpectedly
and auditors had apparently not been able to discover this in time

[Link] Phan Thanh Hải 4


LOGO

1.2. Evolution of Internal Control


 In 1992 the cooperation of five US regulatory institutes (AICPA, AAA,
FEI, IMA, IIA) resulted in the report of the Committee of Sponsoring
Organizations of the Treadway Commission (COSO report).

 This report was prepared based on recommendations of the Treadway


Commission to have management report on the effectiveness of its
internal controls, to create greater management awareness that the
control environment, the audit committee, codes of conduct and the
internal audit are important elements in an internal control system, and
to arrive at a consensus as to the various internal control concepts and
definitions that were in use until that time. The COSO report provided a
broad definition of internal control that is currently still authoritative.

LOGO
1.2. Evolution of Internal Control
Over time and internationally the definition of internal control as
provided in the COSO report has gained wide support. This support
has only increased with the recent enactment of the Sarbanes-Oxley
Act since this Act primarily adopts the COSO definition of internal
control.

In 2004, It extensively discusses risk management. Informally this


report is known as the COSO II report, but we will refer to this report
as the ERM COSO report to indicate that it does not deal with just
internal control, but with Enterprise Risk Management (ERM), of
which internal control is a part.

LOGO
ERM - COSO

[Link] Phan Thanh Hải 5


LOGO
1.2. Evolution of Internal Control
- Reasons for a new COSO framework (2013)
 Address significant changes to the business
environment and associated risks => updated and
enhanced and clarified Framework
 Codify criteria to use development and assessment
of systems of internal control => added principles
and points of focus.
 Increase focus on operations, compliance and non-
financial reporting objectives => Expanded internal
and non-financial reporting guidance.
=> COSO updated Internal Control—Integrated
Framework (Framework) in 2013

LOGO
1.2. Evolution of Internal Control
Internal Control in Information Technology Enterprises
 Originally published in 1996, COBIT helped financial auditors better
navigate their IT environment growth.
 ISACA released a more comprehensive version in 1998. It enveloped
areas beyond audit controls. The third and fourth versions, released in
the 2000s, added further management guidelines around cyber security.
 The fifth COBIT version came in 2013 and brought along tools,
objectives, and best practices universally applicable to all IT operations
in enterprises.
 ISACA then updated COBIT 5 to COBIT 2019. It is the latest version.
This COBIT version is more comprehensive, flexible, and suitable for all
enterprises, irrespective of their immediate goals or size.
 COBIT® 2019 Framework: Introduction and Methodology (the “Work”)
primarily as an educational resource for enterprise governance of
information and technology (EGIT), assurance, risk and security
professionals.

LOGO
1.2. Evolution of Internal Control
- Internal Control related to Independent Audit

• International standard on auditing 315 (ISA 315) “Identifying and


assessing the risks of material misstatement through understanding the
entity and its environment”– refers to definition of Internal Control and
relationship with performing audit engagement.

• International standard on auditing 265 (ISA 265) “Communicating


deficiencies in internal control to those charged with governance and
management” refers to determination of whether deficiencies in Internal
control have been identified, significant deficiencies in internal control,
communication of deficiencies in internal control.

[Link] Phan Thanh Hải 6


LOGO
1.2. Evolution of Internal Control

- Internal Control in Bank Organizations

Basel Committe on Banking Supervision (BCBS) published


Framework for Internal Control System in Banking
Organisations. These report included Basel I (1998), Basel II
(2004) and Basel III (2012) which are a set of international
banking regulations developed by the Bank for International
Settlements in order to promote stability in the international
financial system.

LOGO

1.3. Content of COSO framework (2013)

1 Executive summary

2 COSO framework và Implementation Guide

3 Effectiveness of Internal Control

4 Internal Control over financial reporting for


external stakeholders

20

LOGO

1.3.1. Executive Summary


Internal control helps entities achieve important
objectives and sustain and improve performance.
COSO’s Internal Control—Integrated Framework
enables organizations to effectively and efficiently develop
systems of internal control that adapt to changing
business and operating environments, mitigate risks to
acceptable levels, and support sound decision making and
governance of the organization.
The Framework assists management, boards of
directors, external stakeholders, and others interacting
with the entity in their respective duties regarding internal
control without being overly prescriptive.

21

[Link] Phan Thanh Hải 7


LOGO
1.3.2. COSO Framework and
Implementation Guide
- COSO Framework:
+ Definition of Internal Control
+ Effectiveness of Internal Control
+ Components of Internal Control
+ Principles of Internal Control
 Instruct management and boards of directors at all levels of the
organization to: design, implement and evaluate the effectiveness of
internal control.

- Implementation Guide:
Glossary
Note for small businesses
Summary of changes of the COSO 2013 Report compared to the
COSO 1992

22

LOGO

1.3.3. Effective Internal Control


The Framework sets forth the requirements for an effective system of internal
control.
 Each of the five components and relevant principles is present and
functioning. “Present” refers to the determination that the components
and relevant principles exist in the design and implementation of the
system of internal control to achieve specified objectives. “Functioning”
refers to the determination that the components and relevant principles
continue to exist in the operations and conduct of the system of internal
control to achieve specified objectives.
 The five components operate together in an integrated manner.
“Operating together” refers to the determination that all five components
collectively reduce, to an acceptable level, the risk of not achieving an
objective. Components should not be considered discretely; instead,
they operate together as an integrated system. Components are
interdependent with a multitude of interrelationships and linkages among
them, particularly the manner in which principles interact within and
across components.
23

LOGO

1.3.4. Internal control over over


External Financial Reporting
For external stakeholders of an entity and others that interact with the
entity, application of this Framework provides:
 Greater confidence in the board of directors’ oversight of internal
control systems
 Greater confidence regarding the achievement of entity objectives
 Greater confidence in the organization’s ability to identify, analyze,
and respond to risk and changes in the business and operating
environments
 Greater understanding of the requirement of an effective system of
internal control
 Greater understanding that through the use of judgment,
management may be able to eliminate ineffective, redundant, or
inefficient controls
24

[Link] Phan Thanh Hải 8


LOGO

1.3.5. Important changes in the COSO 2013


report compared to the 1992 COSO report
 A principles-based approach that provides flexibility and allows for
judgment in designing, implementing, and conducting internal control—
principles that can be applied at the entity, operating, and functional levels
 Requirements for an effective system of internal control by considering
how components and principles are present and functioning and how
components operate together
 An opportunity to expand the application of internal control beyond
financial reporting to other forms of reporting, operations, and compliance
objectives
 An effective system of internal control demands more than rigorous
adherence to policies and procedures: it requires the use of judgment.
Management and boards of directors use judgment to determine how
much control is enough. Management and other personnel use judgment
every day to select, develop, and deploy controls across the entity.
25

LOGO

1.3.6. Components and Principles


Control environment:
Principle 1: The organization2 demonstrates a commitment to integrity
and ethical values.
Principle 2: The board of directors demonstrates independence from
management and exercises oversight of the development and
performance of internal control.
Principle 3: Management establishes, with board oversight, structures,
reporting lines, and appropriate authorities and responsibilities in the
pursuit of objectives.
Principle 4: The organization demonstrates a commitment to attract,
develop, and retain competent individuals in alignment with objectives.
Principle 5: The organization holds individuals accountable for their
internal control responsibilities in the pursuit of objectives.

26

LOGO
1.3.6. Components and Principle
Risk assessment
Principle 6: The organization specifies objectives with sufficient
clarity to enable the identification and assessment of risks relating
to objectives. identify objectives
Principle 7: The organization identifies risks to the achievement of
its objectives across the entity and analyzes risks as a basis for
determining how the risks should be managed. identify risk, analyse risk
Principle 8: The organization considers the potential for fraud in
assessing risks to the achievement of objectives.
Principle 9: The organization identifies and assesses changes that
could significantly impact the system of internal control.

27

[Link] Phan Thanh Hải 9


LOGO
1.3.6. Components and Principle
Control Activities
Principle 10: The organization selects and develops control
design
activities that contribute to the mitigation of risks to the huong dan thuc hien, thuc hanh
achievement of objectives to acceptable levels.
IT general control
Principle 11: The organization selects and develops general
control activities over technology to support the achievement
of objectives.

Principle 12: The organization deploys control activities operation


through policies that establish what is expected and
lm tnao de dua vao thuc hien hd nhu ki vong cua cta
procedures that put policies into [Link] to put this control in practice,
how to control other effectiveness
28

A1
LOGO
1.3.6. Components and Principle
Information and Communication
Principle 13: The organization obtains or generates and uses
relevant, quality information to support the functioning of internal
control.

Principle 14: The organization internally communicates


information, including objectives and responsibilities for internal
control, necessary to support the functioning of internal control.

Principle 15: The organization communicates with external parties


regarding matters affecting the functioning of internal control.

29

LOGO

1.3.6. Components and Principle


Monitoring Activities
Principle 16: The organization selects, develops, and performs ongoing
and/or separate evaluations to ascertain whether the components of
internal control are present and functioning. the way u perform on ongoing and separate evaluations

Principle 17: The organization evaluates and communicates internal


control deficiencies in a timely manner to those parties responsible for
taking corrective action, including senior management and the board of
directors, as appropriate. the way u report the result of effectiveness
of IC to those charge

30

[Link] Phan Thanh Hải 10


Slide 29

A1 Admin, 7/29/2023
LOGO
1.5. Roles of the interested parties for
Internal Control
 The Board of Directors
 Audit Committee
 Control Board
 Internal Auditor
 Senior Management
 Other Management and Personnel
 Independent Auditor

31

LOGO
1.5. Roles of the interested parties
for Internal Control

32

LOGO
1.5. Roles of the interested parties
for Internal Control

33

[Link] Phan Thanh Hải 11


LOGO
1.5. Roles of the interested parties for
Internal Control (Vinamilk)

34

LOGO
1.5. Roles of the interested parties for
Internal Control

35

LOGO
The Board of Directors

 The board should discuss with senior management the state of the
entity’s system of internal control and provide oversight as needed.
 The board needs to establish its policies and expectations of how
members should provide oversight of the entity’s internal control.
 The board should be apprised of the risks to the achievement of the
entity’s objectives, the assessments of internal control deficiencies,
the management actions deployed to mitigate such risks and
deficiencies, and how management assesses the effectiveness of
the entity’s system of internal control.
 The board should challenge management and ask the tough
questions, as necessary, and seek input and support from internal
auditors, external auditors, and others.
 Subcommittees of the board often can assist the board by
addressing some of these oversight activities.

36

[Link] Phan Thanh Hải 12


LOGO

Audit Committee
An audit committee undertaking good practice will provide benefits to
the board and the entity by:
 strengthening the internal control structure and helping to ensure
the maintenance of appropriate accounting records
 facilitating appropriate communication channels between
management, the board, external auditors and internal auditors
 improving the quality of financial disclosures and the effectiveness
of the audit function by providing an independent review of these
functions
 keeping the board fully informed about relevant accounting and
auditing issues
 highlighting relevant important matters that require the board’s
attention
 ensuring that an effective whistleblower system is in place within the
corporation. 37

LOGO
Control Board
 Support the Board of Directors in periodically evaluating internal control
activities
 Identify and appropriately handle the risks of the enterprise
 Evaluate operation plan prepared by the Internal Controller and receive
reports from the members of Control Board
 Recommend to the Board of Directors or the General Meeting of
Shareholders measures to amend and improve the organizational
structure of management and business activities of the enterprise.

38

LOGO
Internal Auditors

 Internal auditors should review their


internal audit plans.
 Internal auditors perform on-going and
periodic assessment about the design
and operation of Internal Control and any
report on the entity’s system of internal
control to Audit Committee.

39

[Link] Phan Thanh Hải 13


LOGO
Senior Management

 Senior management is responsible for designing and


operating the entity's internal controls
 Senior management should assess the entity’s system of
internal control in relation to the Framework, focusing on how
the organization applies the seventeen principles in support
of the components of internal control
 Management performs an ongoing evaluation of the overall
effectiveness of the entity’s system of internal control

40

LOGO
Other Management and Personnel

 consider how they are conducting their


responsibilities for performing internal control
and discuss with more senior personnel ideas
for strengthening internal control.
 consider how existing controls affect the
effectiveness of internal control

41

LOGO
Independent Auditors

 Independent auditor is engaged to audit or


examine the effectiveness of the client’s internal
control over financial reporting in addition to
auditing the entity’s financial statements.
 Auditors can assess the entity’s system of internal
control in relation to the Framework, focusing on
how the organization has selected, developed,
and deployed controls that affect the principles
within the components of internal control.

42

[Link] Phan Thanh Hải 14


LOGO
Exercise 1

Complete the definition taking the words


following: Attitudes, importance, control,
environment awareness, governance, actions,
control
The …………. …………………. includes the
governance and management functions and
the…………….., ………………… and …………. of
those charged with …………… and management
concerning the entity's internal ……… and its
………………. in the entity.

43

LOGO
Exercise 2

Following are descriptions of internal controls:


1. Senior management obtains data about external events that might
affect the entity and evaluates the impact of that information on its
existing accounting processes.
2. Each quarter, department managers are required to perform a self-
assessment of the department’s compliance with company policies.
Reports summarizing the results are to be submitted to the senior
executive overseeing that department.
3. Before a cash disbursement can be processed, all payee information
must be verified by matching the payee to the company’s approved
vendor listing.
4. The system automatically reconciles the detailed accounts
receivable subsidiary ledger to the accounts receivable general ledger
account on a daily basis.

44

LOGO

5. The company has developed a detailed series of


accounting policy and procedures manuals to help provide
detailed instructions to employees about how controls are
to be performed.
6. The company has an organizational chart that
establishes the formal lines of reporting and authorization
protocols.
7. The compensation committee reviews compensation
plans for senior executives to determine if those plans
create unintended pressures that might lead to distorted
financial statements.
Required: Indicate which principles of the five COSO
internal control components is best represented by each
internal control. 45

[Link] Phan Thanh Hải 15


LOGO
Questions:

a. Which of the following would not be considered an


inherent limitation of the potential effectiveness of an
entity’s internal control structure?
(1) Incompatible duties
(2) Management override
(3) Mistakes in judgment
(4) Collusion among employees

46

LOGO
Questions:

b. Actions, policies, and procedures that reflect the


overall attitude of management, directors, and owners
of the entity about internal control relate to which of
the following internal control components?
(1) Control environment
(2) Information and communication
(3) Risk assessment
(4) Monitoring

47

LOGO
Questions:

c. Vendor account reconciliations are performed by three


clerks in the accounts payable department on Friday of
each week. The accounts payable supervisor reviews the
completed reconciliations the following Monday to ensure
they have been completed. The work performed by the
supervisor is an example of which COSO component?
(1) Control activities
(2) Information and communication
(3) Risk assessment
(4) Monitoring

48

[Link] Phan Thanh Hải 16


LOGO
Questions

e. An organization’s directors, management, and internal


auditors all have important roles in creating a proper
control environment. Senior management is primarily
responsible for
a. Establishing a proper ethical culture BOD
b. Designing and operating a control system that provides
reasonable assurance that establish objectives and
goals will be achieved BOM = senior management
c. Ensure that external and internal auditors adequately
monitor the control environment internal auditors
d. Implementing and monitoring controls designed by the
board of directors. risk owners = department head or leader
= Chiu tnhiem lap KH ung pho risk thich hop va bcao tien do qly rui ro
49

LOGO
Questions
f. Each of the following is a method to evaluate
internal control based on COSO framework,
except:
1. Distinguish economy risk from industry risk and
enterprise risk internal control focus on business risk
bcs economy risk too general
2. Evaluating internal control that focus on risk
identification of specific losses
3. Identifying mitigating control to prevent losses
4. Testing to determine whether the controls are
operating effectively and have prevented
losses in the past
50

LOGO
3 limitations (human element, collusion. unusual transaction)
Questions
g. Which of the following situations is not an example of an
inherent limitation of internal control?
(1) A programming error in the design of an automated
control allows an employee to give himself an unauthorized
pay increase. automated --> co system error la bthg
(2) Management’s failure to enforce control policies
surrounding access to inventory allows employees to steal
assets. human element
(3) A lack of physical controls over the safeguarding of
assets allows an employee to steal company assets.
(4) A fraud scheme whereby an employee orders personal
goods and his supervisor, who is in on the scheme, signs
the checks to pay for those goods. collusion
51

[Link] Phan Thanh Hải 17


LOGO

d. According to COSO, which of the following is a compliance objective. lm tnao de quan ly nhan su lm sao
a, To maintain the adequate staffing to keep overtime expense within [Link] chi phi hd trong ngan sach
--> operations obj
b. To maintain a safe level of carbon dioxide mission during production --> KEY
c. To maintain material price variances within published guidelines --> operations obj
d. To maintain accounting principles that conform to GAAP --> reporting reliably obj

h. Inherent limitation in internal control must be considered in evaluating its effectiveness in preventing or detecting
errors and fraud. Inherent limitations or the effects of them do not include:
a. The inability to provide more than reasonable assurance
b. Incompatible functions performed by the same person --> KEY
c. Faulty human judgment in decision making
d. Simple error

Explain: Internal control has inherent limitations. The performance of incompatible duties, however,
is a failure to assign different people the functions of authorization, recording, and asset custody, not
an inevitable limitation of internal control. Segregation of duties is a category of control activities.

[Link] Phan Thanh Hải 18

You might also like