LOGO
INTERNAL CONTROL
PhD. Ta Thu Trang
LOGO
Internal Control
Chapter 1: Overview of Internal Control
Chapter 2: Components of Internal Control
Chapter 3: Internal Control over Purchasing and
Payment Cycle
Chapter 4: Internal control over sale and collection
cycle
Chapter 5: Internal control over personel & payroll
cycle
Chapter 6: Internal control over tangible fixed
assets
Chapter 7: Internal control over the cash
2
LOGO
Chapter 1
Overview of Internal Control
1.1 Definition of Internal Control
1.2 Evolution of Internal Control
1.3 Limitation of Internal Control
1.4 Content of COSO Framework
1.5 Role of interested parites for internal control
[Link] Phan Thanh Hải 1
LOGO
1.1. Definition of Internal Control
“Internal Control is the system designed, implemented
and maintained by those charged with governance,
management and other personnel, to provide reasonable
assurance about the achievement of an entity’s objectives
with regard to reliability of financial reporting, effectiveness
and efficiency of operations, and compliance with
applicable laws and regulations”
(ISA 315)
4
LOGO
1.1. Definition of Internal Control
“A system of internal control consists of policies and
procedures designed to provide management with
reasonable assurance that the company achieves its
objectives and goals”.
(Alvin et al., 2020)
LOGO
1.1. Definition of Internal Control
Internal control means establishment and implementation
of internal mechanism, policies, procedures, and
regulations conformable with law meant to prevent,
discover, and deal with the risks and meet the set
requirements.
(Accounting Law No. 88/2015/QH13/ Article 39)
Each accounting unit must establish an internal control
system to meet the following requirements:
a) Its assets are protected from improper and inefficient
use;
b) The transactions are approved intra vires and fully
recorded as the basis for making and presenting truthful
and reasonable financial statements.
6
[Link] Phan Thanh Hải 2
LOGO
1.1. Definition of Internal Control
Internal control is defined as follows:
Internal control is a process, effected by an entity’s
board of directors, management, and other personnel,
designed to provide reasonable assurance regarding the
achievement of objectives relating to operations, reporting,
efficiency reliability
and compliance.
& effectiveness
with regulations (COSO 2013 - Framework)
LOGO
1.1. Definition of Internal Control
This definition reflects certain fundamental concepts.
Internal control is:
Geared to the achievement of objectives in one or more
categories—operations, reporting, and compliance
A process consisting of ongoing tasks and activities—a means to an
end, not an end in itself
Effected by people—not merely about policy and procedure
manuals, systems, and forms, but about people and the actions
they take at every level of an organization to affect internal control
Able to provide reasonable assurance—but not absolute assurance,
to an entity’s senior management and board of directors
Adaptable to the entity structure—flexible in application for the
entire entity or for a particular subsidiary, division, operating unit, or
business process
8
LOGO
1.1. Definition of Internal Control
Objectives of Internal Control:
Operations Objectives—These pertain to effectiveness and
efficiency of the entity’s operations, including operational and
financial performance goals, and safeguarding assets against loss.
Reporting Objectives—These pertain to internal and external
financial and non-financial reporting and may encompass reliability,
timeliness, transparency, or other terms as set forth by regulators,
recognized standard setters, or the entity’s policies.
Compliance Objectives—These pertain to adherence to laws and
regulations to which the entity is subject.
9
[Link] Phan Thanh Hải 3
LOGO
* Limitation of Internal Control
Costs should not exceed benefit.
Breakdowns that can occur because of human failures such as
simple errors
Ability of management to override internal control
Ability of management, other personnel, and/or third parties to
circumvent controls through collusion
External events beyond the organization’s control
Design to deal with what normally or routinely happens in a
business
10
LOGO
1.2. Evolution of Internal Control
The theoretical foundation for internal control
can mainly be found in the financial statement
audit, in the 1940s a first attempt at formalizing
an internal control concept was made in the US,
where from the beginning this concept focused
on getting organizations under control.
LOGO
1.2. Evolution of Internal Control
One of the first published definitions of internal control can be
found in the 1949 research report of the Committee on Auditing
Procedure of the American Institute of Certified Public
Accountants (AICPA), followed by many adjustments and
refinements.
Management's role in internal control was explicitly discussed for
the first in the Statement on Auditing Standards No. 1, issued by
the AICPA in 1972
In 1983, the Institute of Internal Auditors published a very broad
definition of internal control
In 1985, the Treadway Commission was established to examine
the causes of fraudulent financial reporting by leading
organizations of which some went bankrupt entirely unexpectedly
and auditors had apparently not been able to discover this in time
[Link] Phan Thanh Hải 4
LOGO
1.2. Evolution of Internal Control
In 1992 the cooperation of five US regulatory institutes (AICPA, AAA,
FEI, IMA, IIA) resulted in the report of the Committee of Sponsoring
Organizations of the Treadway Commission (COSO report).
This report was prepared based on recommendations of the Treadway
Commission to have management report on the effectiveness of its
internal controls, to create greater management awareness that the
control environment, the audit committee, codes of conduct and the
internal audit are important elements in an internal control system, and
to arrive at a consensus as to the various internal control concepts and
definitions that were in use until that time. The COSO report provided a
broad definition of internal control that is currently still authoritative.
LOGO
1.2. Evolution of Internal Control
Over time and internationally the definition of internal control as
provided in the COSO report has gained wide support. This support
has only increased with the recent enactment of the Sarbanes-Oxley
Act since this Act primarily adopts the COSO definition of internal
control.
In 2004, It extensively discusses risk management. Informally this
report is known as the COSO II report, but we will refer to this report
as the ERM COSO report to indicate that it does not deal with just
internal control, but with Enterprise Risk Management (ERM), of
which internal control is a part.
LOGO
ERM - COSO
[Link] Phan Thanh Hải 5
LOGO
1.2. Evolution of Internal Control
- Reasons for a new COSO framework (2013)
Address significant changes to the business
environment and associated risks => updated and
enhanced and clarified Framework
Codify criteria to use development and assessment
of systems of internal control => added principles
and points of focus.
Increase focus on operations, compliance and non-
financial reporting objectives => Expanded internal
and non-financial reporting guidance.
=> COSO updated Internal Control—Integrated
Framework (Framework) in 2013
LOGO
1.2. Evolution of Internal Control
Internal Control in Information Technology Enterprises
Originally published in 1996, COBIT helped financial auditors better
navigate their IT environment growth.
ISACA released a more comprehensive version in 1998. It enveloped
areas beyond audit controls. The third and fourth versions, released in
the 2000s, added further management guidelines around cyber security.
The fifth COBIT version came in 2013 and brought along tools,
objectives, and best practices universally applicable to all IT operations
in enterprises.
ISACA then updated COBIT 5 to COBIT 2019. It is the latest version.
This COBIT version is more comprehensive, flexible, and suitable for all
enterprises, irrespective of their immediate goals or size.
COBIT® 2019 Framework: Introduction and Methodology (the “Work”)
primarily as an educational resource for enterprise governance of
information and technology (EGIT), assurance, risk and security
professionals.
LOGO
1.2. Evolution of Internal Control
- Internal Control related to Independent Audit
• International standard on auditing 315 (ISA 315) “Identifying and
assessing the risks of material misstatement through understanding the
entity and its environment”– refers to definition of Internal Control and
relationship with performing audit engagement.
• International standard on auditing 265 (ISA 265) “Communicating
deficiencies in internal control to those charged with governance and
management” refers to determination of whether deficiencies in Internal
control have been identified, significant deficiencies in internal control,
communication of deficiencies in internal control.
[Link] Phan Thanh Hải 6
LOGO
1.2. Evolution of Internal Control
- Internal Control in Bank Organizations
Basel Committe on Banking Supervision (BCBS) published
Framework for Internal Control System in Banking
Organisations. These report included Basel I (1998), Basel II
(2004) and Basel III (2012) which are a set of international
banking regulations developed by the Bank for International
Settlements in order to promote stability in the international
financial system.
LOGO
1.3. Content of COSO framework (2013)
1 Executive summary
2 COSO framework và Implementation Guide
3 Effectiveness of Internal Control
4 Internal Control over financial reporting for
external stakeholders
20
LOGO
1.3.1. Executive Summary
Internal control helps entities achieve important
objectives and sustain and improve performance.
COSO’s Internal Control—Integrated Framework
enables organizations to effectively and efficiently develop
systems of internal control that adapt to changing
business and operating environments, mitigate risks to
acceptable levels, and support sound decision making and
governance of the organization.
The Framework assists management, boards of
directors, external stakeholders, and others interacting
with the entity in their respective duties regarding internal
control without being overly prescriptive.
21
[Link] Phan Thanh Hải 7
LOGO
1.3.2. COSO Framework and
Implementation Guide
- COSO Framework:
+ Definition of Internal Control
+ Effectiveness of Internal Control
+ Components of Internal Control
+ Principles of Internal Control
Instruct management and boards of directors at all levels of the
organization to: design, implement and evaluate the effectiveness of
internal control.
- Implementation Guide:
Glossary
Note for small businesses
Summary of changes of the COSO 2013 Report compared to the
COSO 1992
22
LOGO
1.3.3. Effective Internal Control
The Framework sets forth the requirements for an effective system of internal
control.
Each of the five components and relevant principles is present and
functioning. “Present” refers to the determination that the components
and relevant principles exist in the design and implementation of the
system of internal control to achieve specified objectives. “Functioning”
refers to the determination that the components and relevant principles
continue to exist in the operations and conduct of the system of internal
control to achieve specified objectives.
The five components operate together in an integrated manner.
“Operating together” refers to the determination that all five components
collectively reduce, to an acceptable level, the risk of not achieving an
objective. Components should not be considered discretely; instead,
they operate together as an integrated system. Components are
interdependent with a multitude of interrelationships and linkages among
them, particularly the manner in which principles interact within and
across components.
23
LOGO
1.3.4. Internal control over over
External Financial Reporting
For external stakeholders of an entity and others that interact with the
entity, application of this Framework provides:
Greater confidence in the board of directors’ oversight of internal
control systems
Greater confidence regarding the achievement of entity objectives
Greater confidence in the organization’s ability to identify, analyze,
and respond to risk and changes in the business and operating
environments
Greater understanding of the requirement of an effective system of
internal control
Greater understanding that through the use of judgment,
management may be able to eliminate ineffective, redundant, or
inefficient controls
24
[Link] Phan Thanh Hải 8
LOGO
1.3.5. Important changes in the COSO 2013
report compared to the 1992 COSO report
A principles-based approach that provides flexibility and allows for
judgment in designing, implementing, and conducting internal control—
principles that can be applied at the entity, operating, and functional levels
Requirements for an effective system of internal control by considering
how components and principles are present and functioning and how
components operate together
An opportunity to expand the application of internal control beyond
financial reporting to other forms of reporting, operations, and compliance
objectives
An effective system of internal control demands more than rigorous
adherence to policies and procedures: it requires the use of judgment.
Management and boards of directors use judgment to determine how
much control is enough. Management and other personnel use judgment
every day to select, develop, and deploy controls across the entity.
25
LOGO
1.3.6. Components and Principles
Control environment:
Principle 1: The organization2 demonstrates a commitment to integrity
and ethical values.
Principle 2: The board of directors demonstrates independence from
management and exercises oversight of the development and
performance of internal control.
Principle 3: Management establishes, with board oversight, structures,
reporting lines, and appropriate authorities and responsibilities in the
pursuit of objectives.
Principle 4: The organization demonstrates a commitment to attract,
develop, and retain competent individuals in alignment with objectives.
Principle 5: The organization holds individuals accountable for their
internal control responsibilities in the pursuit of objectives.
26
LOGO
1.3.6. Components and Principle
Risk assessment
Principle 6: The organization specifies objectives with sufficient
clarity to enable the identification and assessment of risks relating
to objectives. identify objectives
Principle 7: The organization identifies risks to the achievement of
its objectives across the entity and analyzes risks as a basis for
determining how the risks should be managed. identify risk, analyse risk
Principle 8: The organization considers the potential for fraud in
assessing risks to the achievement of objectives.
Principle 9: The organization identifies and assesses changes that
could significantly impact the system of internal control.
27
[Link] Phan Thanh Hải 9
LOGO
1.3.6. Components and Principle
Control Activities
Principle 10: The organization selects and develops control
design
activities that contribute to the mitigation of risks to the huong dan thuc hien, thuc hanh
achievement of objectives to acceptable levels.
IT general control
Principle 11: The organization selects and develops general
control activities over technology to support the achievement
of objectives.
Principle 12: The organization deploys control activities operation
through policies that establish what is expected and
lm tnao de dua vao thuc hien hd nhu ki vong cua cta
procedures that put policies into [Link] to put this control in practice,
how to control other effectiveness
28
A1
LOGO
1.3.6. Components and Principle
Information and Communication
Principle 13: The organization obtains or generates and uses
relevant, quality information to support the functioning of internal
control.
Principle 14: The organization internally communicates
information, including objectives and responsibilities for internal
control, necessary to support the functioning of internal control.
Principle 15: The organization communicates with external parties
regarding matters affecting the functioning of internal control.
29
LOGO
1.3.6. Components and Principle
Monitoring Activities
Principle 16: The organization selects, develops, and performs ongoing
and/or separate evaluations to ascertain whether the components of
internal control are present and functioning. the way u perform on ongoing and separate evaluations
Principle 17: The organization evaluates and communicates internal
control deficiencies in a timely manner to those parties responsible for
taking corrective action, including senior management and the board of
directors, as appropriate. the way u report the result of effectiveness
of IC to those charge
30
[Link] Phan Thanh Hải 10
Slide 29
A1 Admin, 7/29/2023
LOGO
1.5. Roles of the interested parties for
Internal Control
The Board of Directors
Audit Committee
Control Board
Internal Auditor
Senior Management
Other Management and Personnel
Independent Auditor
31
LOGO
1.5. Roles of the interested parties
for Internal Control
32
LOGO
1.5. Roles of the interested parties
for Internal Control
33
[Link] Phan Thanh Hải 11
LOGO
1.5. Roles of the interested parties for
Internal Control (Vinamilk)
34
LOGO
1.5. Roles of the interested parties for
Internal Control
35
LOGO
The Board of Directors
The board should discuss with senior management the state of the
entity’s system of internal control and provide oversight as needed.
The board needs to establish its policies and expectations of how
members should provide oversight of the entity’s internal control.
The board should be apprised of the risks to the achievement of the
entity’s objectives, the assessments of internal control deficiencies,
the management actions deployed to mitigate such risks and
deficiencies, and how management assesses the effectiveness of
the entity’s system of internal control.
The board should challenge management and ask the tough
questions, as necessary, and seek input and support from internal
auditors, external auditors, and others.
Subcommittees of the board often can assist the board by
addressing some of these oversight activities.
36
[Link] Phan Thanh Hải 12
LOGO
Audit Committee
An audit committee undertaking good practice will provide benefits to
the board and the entity by:
strengthening the internal control structure and helping to ensure
the maintenance of appropriate accounting records
facilitating appropriate communication channels between
management, the board, external auditors and internal auditors
improving the quality of financial disclosures and the effectiveness
of the audit function by providing an independent review of these
functions
keeping the board fully informed about relevant accounting and
auditing issues
highlighting relevant important matters that require the board’s
attention
ensuring that an effective whistleblower system is in place within the
corporation. 37
LOGO
Control Board
Support the Board of Directors in periodically evaluating internal control
activities
Identify and appropriately handle the risks of the enterprise
Evaluate operation plan prepared by the Internal Controller and receive
reports from the members of Control Board
Recommend to the Board of Directors or the General Meeting of
Shareholders measures to amend and improve the organizational
structure of management and business activities of the enterprise.
38
LOGO
Internal Auditors
Internal auditors should review their
internal audit plans.
Internal auditors perform on-going and
periodic assessment about the design
and operation of Internal Control and any
report on the entity’s system of internal
control to Audit Committee.
39
[Link] Phan Thanh Hải 13
LOGO
Senior Management
Senior management is responsible for designing and
operating the entity's internal controls
Senior management should assess the entity’s system of
internal control in relation to the Framework, focusing on how
the organization applies the seventeen principles in support
of the components of internal control
Management performs an ongoing evaluation of the overall
effectiveness of the entity’s system of internal control
40
LOGO
Other Management and Personnel
consider how they are conducting their
responsibilities for performing internal control
and discuss with more senior personnel ideas
for strengthening internal control.
consider how existing controls affect the
effectiveness of internal control
41
LOGO
Independent Auditors
Independent auditor is engaged to audit or
examine the effectiveness of the client’s internal
control over financial reporting in addition to
auditing the entity’s financial statements.
Auditors can assess the entity’s system of internal
control in relation to the Framework, focusing on
how the organization has selected, developed,
and deployed controls that affect the principles
within the components of internal control.
42
[Link] Phan Thanh Hải 14
LOGO
Exercise 1
Complete the definition taking the words
following: Attitudes, importance, control,
environment awareness, governance, actions,
control
The …………. …………………. includes the
governance and management functions and
the…………….., ………………… and …………. of
those charged with …………… and management
concerning the entity's internal ……… and its
………………. in the entity.
43
LOGO
Exercise 2
Following are descriptions of internal controls:
1. Senior management obtains data about external events that might
affect the entity and evaluates the impact of that information on its
existing accounting processes.
2. Each quarter, department managers are required to perform a self-
assessment of the department’s compliance with company policies.
Reports summarizing the results are to be submitted to the senior
executive overseeing that department.
3. Before a cash disbursement can be processed, all payee information
must be verified by matching the payee to the company’s approved
vendor listing.
4. The system automatically reconciles the detailed accounts
receivable subsidiary ledger to the accounts receivable general ledger
account on a daily basis.
44
LOGO
5. The company has developed a detailed series of
accounting policy and procedures manuals to help provide
detailed instructions to employees about how controls are
to be performed.
6. The company has an organizational chart that
establishes the formal lines of reporting and authorization
protocols.
7. The compensation committee reviews compensation
plans for senior executives to determine if those plans
create unintended pressures that might lead to distorted
financial statements.
Required: Indicate which principles of the five COSO
internal control components is best represented by each
internal control. 45
[Link] Phan Thanh Hải 15
LOGO
Questions:
a. Which of the following would not be considered an
inherent limitation of the potential effectiveness of an
entity’s internal control structure?
(1) Incompatible duties
(2) Management override
(3) Mistakes in judgment
(4) Collusion among employees
46
LOGO
Questions:
b. Actions, policies, and procedures that reflect the
overall attitude of management, directors, and owners
of the entity about internal control relate to which of
the following internal control components?
(1) Control environment
(2) Information and communication
(3) Risk assessment
(4) Monitoring
47
LOGO
Questions:
c. Vendor account reconciliations are performed by three
clerks in the accounts payable department on Friday of
each week. The accounts payable supervisor reviews the
completed reconciliations the following Monday to ensure
they have been completed. The work performed by the
supervisor is an example of which COSO component?
(1) Control activities
(2) Information and communication
(3) Risk assessment
(4) Monitoring
48
[Link] Phan Thanh Hải 16
LOGO
Questions
e. An organization’s directors, management, and internal
auditors all have important roles in creating a proper
control environment. Senior management is primarily
responsible for
a. Establishing a proper ethical culture BOD
b. Designing and operating a control system that provides
reasonable assurance that establish objectives and
goals will be achieved BOM = senior management
c. Ensure that external and internal auditors adequately
monitor the control environment internal auditors
d. Implementing and monitoring controls designed by the
board of directors. risk owners = department head or leader
= Chiu tnhiem lap KH ung pho risk thich hop va bcao tien do qly rui ro
49
LOGO
Questions
f. Each of the following is a method to evaluate
internal control based on COSO framework,
except:
1. Distinguish economy risk from industry risk and
enterprise risk internal control focus on business risk
bcs economy risk too general
2. Evaluating internal control that focus on risk
identification of specific losses
3. Identifying mitigating control to prevent losses
4. Testing to determine whether the controls are
operating effectively and have prevented
losses in the past
50
LOGO
3 limitations (human element, collusion. unusual transaction)
Questions
g. Which of the following situations is not an example of an
inherent limitation of internal control?
(1) A programming error in the design of an automated
control allows an employee to give himself an unauthorized
pay increase. automated --> co system error la bthg
(2) Management’s failure to enforce control policies
surrounding access to inventory allows employees to steal
assets. human element
(3) A lack of physical controls over the safeguarding of
assets allows an employee to steal company assets.
(4) A fraud scheme whereby an employee orders personal
goods and his supervisor, who is in on the scheme, signs
the checks to pay for those goods. collusion
51
[Link] Phan Thanh Hải 17
LOGO
d. According to COSO, which of the following is a compliance objective. lm tnao de quan ly nhan su lm sao
a, To maintain the adequate staffing to keep overtime expense within [Link] chi phi hd trong ngan sach
--> operations obj
b. To maintain a safe level of carbon dioxide mission during production --> KEY
c. To maintain material price variances within published guidelines --> operations obj
d. To maintain accounting principles that conform to GAAP --> reporting reliably obj
h. Inherent limitation in internal control must be considered in evaluating its effectiveness in preventing or detecting
errors and fraud. Inherent limitations or the effects of them do not include:
a. The inability to provide more than reasonable assurance
b. Incompatible functions performed by the same person --> KEY
c. Faulty human judgment in decision making
d. Simple error
Explain: Internal control has inherent limitations. The performance of incompatible duties, however,
is a failure to assign different people the functions of authorization, recording, and asset custody, not
an inevitable limitation of internal control. Segregation of duties is a category of control activities.
[Link] Phan Thanh Hải 18