0% found this document useful (0 votes)
131 views9 pages

Internal Auditing Standards Overview

The document outlines the International Standards for the Professional Practice of Internal Auditing, focusing on ethics, principles, and performance evaluation. It emphasizes the importance of a Code of Ethics to guide the conduct of internal auditors and details the roles of assurance and consulting services. Additionally, it discusses the evolution of internal auditing in Malaysia and the significance of strategic planning and quality assurance in enhancing the effectiveness of internal audit functions.

Uploaded by

hnsatrh26
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
131 views9 pages

Internal Auditing Standards Overview

The document outlines the International Standards for the Professional Practice of Internal Auditing, focusing on ethics, principles, and performance evaluation. It emphasizes the importance of a Code of Ethics to guide the conduct of internal auditors and details the roles of assurance and consulting services. Additionally, it discusses the evolution of internal auditing in Malaysia and the significance of strategic planning and quality assurance in enhancing the effectiveness of internal audit functions.

Uploaded by

hnsatrh26
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

INTERNATIONAL STANDARDS FOR THE PROFESSIONAL PRACTICE OF INTERNAL AUDITING CHP 2 - ETHICS:

The purpose of the Standards is to:


1. Delineate basic principles that represent the practice of internal auditing.
The Standards are principle-focused and provide a framework for performing and promoting internal auditing.
The Standards are mandatory requirements consisting of:
INTERNATIONAL
2. Provide a framework for performing and promoting a broad range of value- • Statements of basic requirements for the professional practice of internal auditing and for evaluating the PROFESSIONAL
added internal auditing. effectiveness of its performance. The requirements are internationally applicable at organizational and individual
3. Establish the basis for the evaluation of internal audit performance. levels. PRACTICES
FRAMEWORK (IPPF)
4. Foster improved organizational processes and operations. • Interpretations, which clarify terms or concepts within the statements.

• Attribute Standards address the attributes of organizations and individuals performing internal auditing.
• The Performance Standards describe the nature of internal auditing and provide quality criteria against which the performance of these services can be measured.
• Implementation Standards are also provided to expand upon the Attribute and Performance standards, by providing the requirements applicable to assurance or consulting activities
© NIRMALA (UITM SEGAMAT)
Assurance services involve the internal auditor's objective assessment of evidence to provide an Consulting services are advisory in nature, and are generally performed at ETHICS
independent opinion or conclusions regarding an entity, operation, function, process, system or the specific request of an engagement client. The nature and scope of the consulting engagement
other subject matter. There are generally three parties involved in assurance services: are subject to agreement with the engagement client. Ethics in general:
[Link] person or group directly involved with the entity, operation, function, process, system, or other Consulting • Set of moral principles, values or acceptable behaviour
subject matter-the process owner services generally involve two parties • Science of morals, study of principles of human duty,
[Link] person or group making the assessment-the internal auditor [Link] person or group offering the advice-the internal auditor rules of conduct
[Link] person or group using the assessment-the user. [Link] person or group seeking and receiving the advice the engagement client. • Provide standard of conduct in daily life

Definition of ethics:
CODE OF ETHICS • A set of moral principles that distinguish between what
The purpose of The Institute's Code of Ethics is to promote an ethical culture in the profession of internal auditing. is right and what is wrong
A code of ethics is necessary and appropriate for the profession of internal auditing, founded as it is on the trust placed in its objective assurance about governance, risk management, and control. • It is a set of values that guide the conduct and the
behavior of the individuals, enabling them to
The Institute's Code of Ethics extends beyond the Definition of Internal Auditing to include two essential components: differentiate between rights and wrong, good and bad
1. Principles that are relevant to the profession and practice of internal auditing. and what should and should not be done
2. Rules of Conduct that describe behavior norms expected of internal auditors. • “Ethical behavior is not an act BUT a HABIT…”
These rules are an aid to interpreting the principles into practical applications and are intended to guide the ethical conduct of internal auditors.
EVOLUTION OF INTERNAL AUDIT IN
PRINCIPLE RULES OF CONDUCT MALAYSIA
[Link] - How internal auditors perform their [Link] Internal auditors: • In 1970, Ministry of Defence set up its internal audit unit.
work with honesty and professional courage • Shall perform their work with honesty, diligence, and responsibility. • In 1979, the Federal Government issued a circular
[Link] - An unbiased mental attitude that • Shall observe the law and make disclosures expected by the law and the profession. expanding the establishment of IA to other ministries
allows internal auditors to make professional • Shall not knowingly be a party to any illegal activity, or engage in acts that are discreditable to the profession of internal auditing or to the with a broader role which include operational audit.
judgements. organization. • In 1993, the Ministry of Finance requested all
[Link] – Internal auditors must be • Shall respect and contribute to the legitimate and ethical objectives of the organization. government-owned organizations to set up an audit
aware of and comply with any policies and [Link] Internal auditors: committee:
procedures while handling the secrecy of the • Shall not participate in any activity or relationship that may impair or be presumed to impair their unbiased assessment. This participation • To protect the government interest as a shareholder
information includes those activities or relationships that may be in conflict with the interests of the organization. • To oversee the internal audit function in these
[Link] - Internal auditors apply the • Shall not accept anything that may impair or be presumed to impair their professional judgment. organizations.
knowledge, skills, and experience needed in • Shall disclose all material facts known to them that, if not disclosed, may distort the reporting of activities under review. • Internal auditing in private sector
the performance of internal audit services. [Link] Internal auditors: • Mainly focus on evaluating the efficiency and
[Link] Due To Professional Care - The • Shall be prudent in the use and protection of information acquired in the course of their duties. effectiveness of internal control systems and
internal auditors must plan and perform the • Shall not use information for any personal gain or in any manner that would be contrary to the law or detrimental to the legitimate and ethical compliance
details of the internal auditors’ work. objectives of the organization. • Since 1993, it was mandatory for all public listed
Assessing the audit engagement following [Link] Internal auditors: organizations to establish audit committee to monitor
relevant regulations and internal audit • Shall engage only in those services for which they have the necessary knowledge, skills, and experience. accountability, governance, independence and
standards and communicating with the related • Shall perform internal audit services in accordance with the International Standards for the Professional Practice of Internal Auditing (Standards). objectivity of the internal audit department.
parties. • Shall continually improve their proficiency and the effectiveness and quality of their services • Bursa Malaysia Listing Requirements, amended in
[Link] 2008, mandated public listed organizations to set up
internal audit function.
CHP 5 - MANAGING THE INTERNAL AUDIT FUNCTION OUTSOURCING

• a great impact to the business world Reasons for outsourcing:


© NIRMALA (UITM SEGAMAT) • involves independent parties to perform functions within an
organization
• scarcity or unavailability of internal audit resources
• to acquire timely and professional internal audit services
• opted because no large capital investment required • cost advantage
INTERNAL AUDIT CHARTER (STAFFING) • ready-made staff with the necessary skills and competencies

Staffing requirement Elements affecting staffing requirements IIA COMMON BODY OF KNOWLEDGE (CBOK) OUTSOURCING ARRANGEMENTS
• competent and skilled • staffing strategies, • Internal auditors should focus on risk areas that pose the greatest threat to the organisation.
• adequate number • understanding customer needs, • Maintain good relationship with governance parties, especially the audit committee and executive management 1. FULL OUTSOURCING 3. CO-SOURCING
• adding value, • Evaluate the internal audit processes and to continuously improve the performance. • Execution of a full-scope and risk-focused internal audit plan • Execution of an internal audit plan is shared between an
• addressing risks and use of audit tools contracted to an external provider, usually from professional accounting firm and the organization. In most cases, the
accounting firms. The oversight and responsibility for the internal audit outsource d party handles specialized areas (Reporting
activity cannot be outsourced. should be made to the management and the board.
BODY OF KNOWLEDGE AND CHARACTER
• Should require the approval of the audit committee and reporting to 4. SUB-CONTRACTING
the board or other governing body. • Involves the engagement of an external party for a limited
The knowledge and skills that internal auditors should possess include: 2. PARTIAL OUTSOURCING period to undertake a specific engagement or a portion of
• Proficiency in applying internal auditing standards, procedures and techniques to perform effective and efficient internal audits. • Execution of the internal audit plan is partly done by an internal some engagement'
• Adequate knowledge on accounting principles and techniques, management principles as well as, fundamentals of law, economics, taxation, finance and other related subject matters provider on an ongoing basis. • In-house internal audit department will normally provide the
• External provider will report to the head of the internal audit management and oversight functions.
TRAINING AND PROMOTION SELECTING STAFF ATTRIBUTES OF AN EFFECTIVE INTERNAL AUDIT FUNCTION department.

BENEFIT LIMITATION
• For continuous improvements of internal audit An appropriate process for hiring to ensure that only candidates • Objective and free from undue influence
performance with the appropriate qualification and experience are selected • Aligns with strategies, objectives and risk of organisations
• Focus on core competencies • Allegiance of in-house vs external provider
• The purpose of the training is to enhance and upgrade Process can include: • Demonstrate quality and continuous improvements.
• Costs minimisation • Organisation culture hindering external provider’s performance
knowledge, skill and competencies of internal auditors • written test – for their IQ testing • Communicates effectively
• Business efficiency • Statutory requirement – Sarbanes-Oxley Act 2002
• use of key performance indicators (KPIs) for evaluation • presentation – communication skill • Provide risk-based assurance
• Enhancement of external audit • Increasing costs in the long term
procedures, • Interview – face-to-face • Insightful, proactive and future-focused
• Increase business geographical locations • External provider lack of knowledge
• orientation - adaptability • Promotes organizational improvements
coverage • Succession plan affected
• Future expectations for in-house auditor • Lack long-range development
QUALITY ASSURANCE IMPROVEMENT PROGRAMME • Increase credibility

IMPORTANCE OF QAIP PURPOSE AND BENEFIT


RISK-BASED INTERNAL AUDIT PLAN RESOURCE MANAGEMENT
• To enable an evaluation of IA activities which include operation, processes • To ensure scope of IA activity includes all activities in the standards and in the IIA definition of IA
and methods in conformance with Definition, Standards and Code of Ethics • To provide reasonable assurance to the various stakeholders of IA activity
• Can assess efficiency and effectiveness of IA activity and identify • According to PA 1310-1: Conflict can arise between: Consequences: Conflicts within the internal audit department normally exist when:
opportunities for improvement • Conformance to definition, Code of Ethics and ISPPIA • internal and external • adverse effect on • Lack of understanding due to ambiguity and uncertainty.
• Adding value to IA activity and improve organisation’s operation • Adequacy of IA activity’s charter, goals, objectives., policies and procedures auditors and reputation • Failure to think strategically and systematically.
• Implementation of new internal audit policy • Contribution to organisation’s governance, risk management and control processes • internal auditors and other • efficacy of work • Lack of understanding on the importance of and challenges facing the
• Updates system for evaluation of audit risk, internal audit staff training • Compliance with applicable laws, regulations and government or industry standards employees profession
• Improvement in administrative and monitoring systems for IA functions • Effectiveness of continuous improvement activities and adoption of best practices
• Whether auditing activity add values and improve organisation’s operations
TYPES OF CONFLICT
QUALITY ASSURANCE METHODOLOGY
Inherent conflicts Avoidable conflicts
INTERNAL ASSESSMENT EXTERNAL ASSESSMENT • caused by lack of communication in the organization • Conflicts within the internal audit department and process examples
• misconceptions of audit function • can be avoided with proper audit guidance
Types of Internal Assessments External Assessments Types of External Assessments Steps For External • lack of cooperation from auditees
1. Ongoing monitoring of the performance of the IA activity: • Must be conducted at least 1. Full external assessment: Quality Assurance
1. Conducted routinely throughout the process of audit once every 5 years by 1. Involves an outside team under the leadership of an experienced 1. Annoucement
2. Can be an integral part of the day-today supervision, qualified, independent professional project manager Letter To CAE Recommended practices for avoidable conflicts
review and measurement of IA activity assessor or assessment 2. The team members should be competent professionals who are 2. Preliminary Survey • Internal auditors need to develop trust. This can be done by showing a genuine intention in assisting to improve the organization, thus
3. Can be incorporated into routine policies and practices team from outside of the wellversed in the best IA practices 3. Fieldwork: Interview ensuring co-operation.
used organization 2. Self-assessment with independent validation: And Substantive • Internal auditors have to be salespersons. Internal auditors should be able to explain the problems or issues to auditees, instead of
2. Periodic self assessments: • CAE must discuss with the 1. Conducted by a competent independent evaluator who is Testing identifying problems and telling the auditees how to fix them.
1. Not a routine but performed through self-assessments or board: wellversed in quality assessment methodology to validate the 4. Reporting • Help the auditees understand the audit objectives. When the auditees know the objectives and the information needed, conflict can be
by other persons within an organisation with sufficient • Form and frequency of selfassessment of IA activity avoided.
knowledge in IA practices external assessments; 2. The validator substantiates work done by self-assessment team, • Internal auditors should be objective and factual about their findings. Different words or phrases can affect the auditees' value judgment.
2. Can be conducted by special-purpose reviews and will • Qualifications and makes an on site visit and interviews senior management
usually involve compliance testing independence of external 3. Co-signs CAE’s report or issues separate report How to deal with conflicts
assessor/assessment • Consider the positive aspects of the conflict because some of these conflicts may help an organization move towards its objectives.
team • Compromise in situations where the auditees are more responsive to important findings rather than to less important findings. Internal
auditors should be firm, but at the same time fair, in taking a stance over their findings.
Common issue Best approach • Internal auditors should try to appreciate and anticipate all potential sources of conflict and consider all possible solutions to the conflicts
• Inappropriate chief audit executive — reporting relationships • Need greater commitment from management prior to any negotiation with auditees.
• Out-of-date charters • All activities performed must be consistent with IIA’s standards of quality and Code of Ethics • Seek support from high level management, especially the audit committee. Internal auditors should be able to segregate personal
• Lack of board approved policy on internal control responsibility • An organisation should develop a set of policies, procedures and controls for its QAIP differences in opinion from critical control issues or ethical questions.
• Client perception of inadequate audit staff knowledge • Both methods of assessments should be implemented • Internal auditors should not feel guilty or be made responsible for situations having negative consequences as a result of the audit findings.
• An organisation must implement all corrective actions recommended
IMPORTANCE OF STRATEGIC 2. ENGAGEMENT PLAN
PLANNING CHP 6 - INTERNAL
• To ensure that the governance, risk and control AUDIT PROCESS – The IIA in its IPPF Standard 2200 stipulated that;
“Internal auditors must develop and document a plan for each engagement, including the engagement’s objectives, scope, timing, and resource allocations.”
PLANNING AND
issues are properly addressed during the
implementation of the audit itself
There are four aspects that need to be considered when preparing a plan for the engagement:
• Ensure effective conduct and audit
• Incorporation of IA strategies
FIELDWORK • The objectives of the activity being reviewed and the means by which the activity controls its performance
• The significant risks to the activity, its objectives, resources, and operations and the means by which the potential impact of risk is kept to an acceptable level

Step In Developing Strategic Plan:


© NIRMALA (UITM • The adequacy and effectiveness of the activity's governance, risk management and control processes compared to a relevant framework or model
• The opportunities for making significant improvements to the activity governance, risk management and control processes.
1. Understand the Relevant Industry and the
Organization’s Objectives
SEGAMAT)
• For the internal audit activity to deliver any SETTING UP OBJECTIVE RISK CONTROL ASSESSMENT
value, it should contribute to the
achievement of the organization's strategic 1. RISK BASED PLANNING AND • Understanding of the auditee to ensure that the engagement objectives can capture meaningful area that can add value 1. Likelihood Assessment Of
and operational reporting as well as to the AUDITING to the auditee's operation. Risk
compliance objectives while providing • Preliminary assessment of the risks relevant to the activity under review. The assessment should be aligned to the 2. Consequences Assessment
assurance that the organization maintains The Performance Standard 2010 – Planning engagement objectives. 3. Risk Scoring
an ethical environment and a culture of • The chief audit executive must establish a • Probability of significant errors, fraud, non-compliance and other exposures when developing the engagement
accountability. risk-based plan to determine the priorities objectives.
2. Consider the International Professional of the internal audit activity, consistent • Criteria that can adequately evaluate governance, risk management and controls. It is to determine whether objectives
Practices Framework (IPPF) with the organization’s goal and goals have been accomplished.
• The CAE should be well versed in the IPPF The process
and consider its requirement and guidance CREATE TEST PLAN DEVELOP WORK PROGRAM
1. Form a risk assessment to determine the
when developing the internal audit strategic priorities for assurance
plan. • Creating a test plan involves determining the Practice Advisory 2240-1, “internal auditors must develop and document work programs that achieve
2. Form organizational plans to consider the nature, timing & extent of the procedures needed to the engagement objectives. The work program includes methodologies to be used, such as
3. Understand Stakeholder Expectations timing for each assurance activity
• It is important to include key internal and gather required evidence. technology-based audit and sampling techniques.”
3. Form consultation to determine activity of • Test plans include tests of control activities, direct • Extremely pertinent planning device.
external stakeholders like engaging with other assurance Providers
senior management such as the chief tests of performance gauges. • Specifically outlines audit procedure required to accomplish engagement objectives
4. Identify un-addressed assurance priorities • A plan for testing control activities already placed in • over the course of engagement, IAs sign off on the procedure to indicate work has been ompleted
executive to understand their expectation 5. Determine the degree of reliance to be
4. Update the internal Audit Vision and Mission operation should be designed to gathered sufficient • In turn, enables engagement team supervisors to review work done and monitor the work that
given to other providers competent evidence – determine whether control remains to be done
• The CAE should develop and update the 6. Build an internal audit plan to address
vision and mission statements based on activities auditee has already determined are • At then end, completed program serves as a record of the work completed and document who
residual priorities adequately designed are also operating effectively. completed the work and when it is completed.
stakeholders' expectations and IIA
guidance.
5. Define the Critical Success Factors ALLOCATE RESOURCES TO ENGAGEMENT DOCUMENTATION AND COMMUNICATION
• These factors provide the IAF with the
essential elements that all major initiatives Standard 2230 – Engagement Resource The engagement plan needs to be clearly documented and approved at the appropriate levels. Documentation
be vetted against to ensure that resources Allocation states that “Internal auditors is in fact required throughout the overall audit process. The well documented plan should be made available to
are directed to the most important must determine appropriate and sufficient the staff involved in the engagement to ensure that everyone understands the objectives, scope, test plan,
activities. Three questions that may be resources to achieve engagement objectives resource allocation and the expected output.
helpful in identifying the CSFs are: . based on an evaluation of the nature and It includes key elements such as the following:
Positioning, Processes, People. complexity of each engagement, time • Planned engagement objectives and scope of work.
6. Perform on SWOT Analysis constraints, and available resources.” • Preliminary assessment of risks and controls.
• The aim of any SWOT analysis is to identify This involves determining : • The timing of the engagement work.
the key internal and external factors that are • audit expertise needed, • Internal auditors assigned to the engagement.
important in achieving the strategy. • estimating the time taken to complete • The process of communicating throughout the engagement, including the methods, time frames and the
7. Identify Key Initiatives engagement, person in charge.
• For each initiative, it is valuable to identify a • assigning appropriate IAs to engagement • Business conditions and operations of the activity being reviewed, including recent changes in management
timeline for implementation, the desired • scheduling the work so that it is or major system.
objectives, the performance measurements completed on time. • Concerns or any request by audit committee/management.
(qualitative and quantitative) and the • Audit strategy and test plan.
associated SWOT elements.
4. EVALUATION AND CONCLUSION
3. PERFORMING THE ENGAGEMENT

• IPPF 2300 – Performing the Engagement. Internal auditors must identify, analyze, evaluate, and
document sufficient information to achieve the engagement’s objectives.
Standard 232 -Analysis and Evaluation states that internal
auditors must base conclusions and engagement results on CHP 6 - INTERNAL
appropriate analyses and evaluation.
• IPPF 2310 – Identifying Information Internal auditors must identify sufficient, reliable, relevant, and
useful information to achieve the engagement’s objectives. The process: AUDIT PROCESS –
PLANNING AND
• Sufficient information is factual, adequate, and convincing so that a prudent, informed person would • Review and evaluate audit evidence
reach the same conclusions as the auditor. Reliable information is the best attainable information • Formulating audit opinion
through the use of appropriate engagement techniques. Relevant information supports engagement • Formulating recommendation
observations and recommendations and is consistent with the objectives for the engagement. Useful
information helps the organization meet its goals. Opinions and Recommendations are based on the following
attributes:
FIELDWORK
AUDIT FIELDWORK – DATA COLLECTION/AUDIT EVIDENCE ANALYSING AND • Criteria: The standards, measures or expectations used in
(to determine the risks and the location to perform audit. ) EVALUATING making an evaluation and/or verification (the correct state).
• Condition: The factual evidence that the internal auditor finds in
© NIRMALA (UITM SEGAMAT)
Steps are divided into as follows: Audit Evidence [Link] the course of the examination (the current state).
i. understanding the business process flow requirement: [Link] • Cause: The reason for the difference between expected and
ii. identifying the prescribed internal controls i. Types of [Link] actual conditions.
iii. assessing the controls evidence • Effect: The risk or exposure the organization and/or others
iv. developing the audit procedures ii. Availability encounter because the condition is not consistent with the 5. COMMUNICATION RESULT
v. audit testing iii. Selection criteria (the impact of the difference). In determining the degree
vi. audit report iv. Nature of risk or exposure, internal auditors must consider the effect on
vii. engagement supervision their engagement IPPF 2400 Internal auditors must communicate the Criteria of Quality
results of engagements. Communication
DOCUMENTATION When arriving at the conclusion, auditors should consider the The Process: Quality
following: 1. Preparation of the initial draft of the report. • Accurate
Practice Advisory 2330-1: Recording Information (Working papers that document the engagement should • whether the conclusion encompasses the entire scope of an 2. Review and edit by members of the audit team. • Objective
be prepared by the internal auditor and reviewed by management of the internal audit activity.) engagement or specific aspects 3. Preparation of the revised audit report. • Clear
Purpose: • program objectives and goals 4. Review and edit by the manager of audit assignment • Concise
1. Tools for efficient Conduct And supervision • to review alignment to organization goals; whether the 5. Preparation of the second revision of the report. • Constructive
2. Support audit Conclusion And report organization's objectives and goals are being met 6. Review and edit by the head of internal audit • Complete
3. Review and Quality Control • whether the activity under review is functioning as intended department • Timely
4. Form of evidence • an overall assessment ofcontrols or area under review 7. Preparation of the third revision of the report.
• whether the scope is limited to specific controls or aspects of 8. Combined review and edit by the audit team leader,
the engagement manager, and director.
ACTIVITIES DETAIL EXAMPLES
9. Preparation of the “discussion draft” of the report for
Interviewing or conducting inquiry Discuss with payroll manager on payroll calculation. The following are factors to be considered when developing
review by auditee management.
recommendations:
Verifying or vouching Review the payroll payment instruction letter sent to the bank. 10. Review by management and response provided on
• Be specific to the problem and offer some alternatives or advice
audit findings.
Observation Observe employee clock in attendance. to solve the problem
11. Preparation of the final draft of the audit report for
• Avoid dictatorial connotations by using should, ought or must
Re-performance/Recalculation Recalculate amount of tax deduction. distribution.
• Findings must be taken seriously by the management/auditee
Questionnaires Issue survey on employee satisfaction. but not always obligated to accept the audit recommendations
• Suited to the auditee's needs and considerations
Analytical procedures Calculate ratio on total monthly tax deduction for 12 months.
Computer assisted audit tools and Using audit software to reconcile payroll file and employee master
6. FOLLOW-UP ACTIVITES
techniques (CAATTs) file.
Physical inspection Test drive the company car used by the chief executive officer to Performance Standard 2500 states that the Factors to consider in determining the nature, timing and extend of the follow up procedures:
ensure that it is in good condition CAE should establish a follow-up process to • The significance of the reported observation or recommendation.
Review of published reports or Review minutes of meeting to identify decision on bonuses for the monitor and ensure that management actions • The degree of effort and cost needed to correct the reported condition.
minutes year. have been effectively implemented or that • The impact that may result should the corrective action fail.
Confirmation Send letters to employees who took company car loan to confirm senior management has accepted the risk of • The complexity of the corrective action.
the loan balance due. not raking action. • The time period involved
REPORT DESIGN • An internal audit report is fundamentally the final product from an audit engagement that can be considered important to management.
• The reporting is compulsory based on the Performance Standard 2400
COMPONENT CONTENT
Purposes of Internal Audit Report
CHP 7 - INTERNAL
• Criteria: A report is based on the standards, measures or expectations
used in making and evaluation and/or verification.
• The purpose statement - The
purpose of engagement should be
• Developing recommendation
• Present management with control and risk issues
AUDIT PROCESS -
• Condition: Factual evidence internal auditors found during the audit
engagement.
conducted in observing identified risk
area and the expected outcome from
• Promote problems to management
• To documented the results REPORTING AND
MONITORING
• Cause: Reasons for the difference between expected (based on the the engagement. • Developing action plan
criteria and requirement) and actual conditions. Here, it is proven that • The scope statement - This part 1. The report should disclose the current internal control situation highlighting the problems discovered during the engagement. The role of an audit report is aimed
there is system deficiency whenever actual conditions do not meet the identifies the audit process and how to change or to improved internal controls.
2. The internal audit report should highlight the importance of control and risks occurred with the business objectives. Management need to determine high priority
standards, measures or expectations.
• Effect: The risk or exposure the organization and/or others encounter
because the condition is not consistent with the criteria. In determining
the work is to be performed, including
the relevant methods in audit
process pertaining to observation.
control, adequate solution and improvement tools in order to focus on their future achievement.
3. The action plan is a one step ahead of the recommendation where management will make some required changes.
© NIRMALA (UITM
4. The highlighting and promoting problem to management will make management more concerned on risk area problem and they able to plan for any action plans.
the degree of risk or exposure, internal auditors must consider the
effect their engagement observations and recommendations may have
on the organization’s operations and financial statements.
• Opinion - The opinion will be the
overall assessment on controls from
the overall audit process.
5. The internal audit report will act as a formal tool to convey audit findings to management in order to highlight the risk areas and provide opinions and
recommendations.
SEGAMAT)
• Recommendations: This will include action plans that need to be • The main body - The main body will 6. The internal audit report will assured and confirmed that problems happened in organization may have no major errors that affect the effectiveness of operation.
employed for future prevention and current correction. Correction include the background of the audit
plans need to correct past errors, and prevention plans need to be process, observations, Process of Report Writing LEGAL AND PROFFESIONAL CONSIDERATION
thoroughly looked into. recommendations and action plans. 1. Field Audit Exit Meeting - The purpose of an exit meeting is to enable auditors to discuss matters on the weaknesses of the system and the risk area discovered
during the audit. • Internal auditors should be cautious when include results
2. Draft Audit Report - The draft audit will include audit observations, audit recommendations and an audit plan. and opinions regarding law and regulatory violations and
QUALITY OF REPORT WRITING GUIDELINES ON INTERNAL AUDIT REPORT BEST PRACTICE 3. Responses from Department - The auditee itself must take into consideration for each recommendation provide by internal auditors for the purpose of improving other legal issues in the report
the business operation and to ensure the effectiveness of the system. • Internal auditor should work closely with legal counsel and
Sawyer (2012) - has suggested a report 1. The main point must be stated immediately because clients, 4. Final Audit Report- The final report will include the significant issues, action plan, recommendations, department’s responses and auditors’ conclusion. compliance officer on the sensitivity of information from
quality checklist which can be considered senior executives and audit committee members want a 5. Post Audit Survey- The purpose is to evaluate the effectiveness of the audit process, audit planning, audit performance, professionalism and knowledge of the legal consideration
the most productive. This checklist will be succinct description of the issue, its level of risk, and audit team. • Internal audit department should have policies and
one of the rule of thumb and requirement in recommended mitigation or corrective actions. 6. Follow-up Audit- Internal auditors will request for follow up information to review and report on corrective actions taken in addressing all previous significant procedures in handling matters that relate to legal and
reporting in order to ensure every information 2. Auditors need to communicate the severity of risks and explain issues. professional considerations
taken from observation will be written the risk in meaningful ways in order for management to focus
completely in internal audit report. more on recommendations.
• Factors of good quality report writing 3. The report should be written to communicate the necessary REPORT MONITORING AND FOLLOW-UP
A good quality report will enhance the ideas that focus on audit findings in order to inform the readers.
understandability by the senior 4. Auditors need to avoid using technical terms because not every MONITORING FOLLOW-UP
management. readers would understand and be familiar with accounting and
1. Readability - Message placement, auditing terminologies. The CAE should establish procedures according to Practice • The final part is the follow-up process, where internal auditors need to look through whether management has take action for each recommendation.
coherence, conciseness and the use of 5. In preparing an internal audit report, auditors need to use the Advisory 2500-1' The procedures are as follows: • A follow-up is a process by which internal auditors evaluate the adequacy, effectiveness and timeliness of actions taken by management on reported observations
graphics can help enhance the readability correct words and acceptable practice for business 1. A timeframe within which management's response to and recommendations, including those made by external auditors and others.
of a report documents. engagement observations and recommendations is
2. Clarity - Definitions are crucial in 6. Auditors need to construct sentences which consist of a noun required Types of Follow-Up
understanding concepts for each that readers can easily understand and visualize. 2. Evaluation of management's response. • Follow-Up Documentation - Referring to Performance Standard 2330, internal auditors must document relevant information to support their conclusions and
observation and audit process. 7. Each sentence must generally be short and contain no more 3. Verification of the response. engagement results as well as document follow-up procedures and results.
3. Objective Wording and Tone - The report than 24 words to ensure readability. 4. Performance for each risk area of a follow-up • Follow-Up Reporting Results - CAE should also report the results of these procedures to upper management and the board. The report preparation depends on the
must be prepared objectively when 8. Ideas in an internal audit report can be improved by simplifying engagement. organization's culture. In a formal culture, the auditor might conclude the engagement by sending written reports to upper management and the board on any open
describing the engagement, where the ideas into lists. This list will help readers to digest and process 5. A communication process that escalates unsatisfactory issues.
wording used must be fair, impartial and information in a short time. responses/actions, including the assumption of risk, to • Follow-Up Frequency - Follow-up procedures need to be conducted and performed in order to provide confidence and assurance to the CAE, upper management and
unbiased. The tone of writing has to reflect 9. The report should emphasize the possibility of failure; thus, the appropriate levels of senior management or the the board. According to Flpn (2010), the rule of thumb for follow-up performance is that it should be conducted at least twice a year.
the level of severity for each observation. auditors should point out potential improvement for each of the board.
4. Language - The level of understanding of control.
the report is dependent on good grammar, 10. Auditors must avoid using negative words because such words
punctuation and mechanics. have a high tendency to provoke rather than convince clients DISTRIBUTION OF REPORT

QUALITY OF GOOD REPORTING • The purpose of the report distribution is to assist clients / auditees to achieve the desired action.
• The control of distribution for the final engagement report is done by the Chief Audit Executive (CAE). The CAE determines who receives the report in accordance
• Accurate – Free from errorrs and distortions and is faithful to the underlying facts Key steps to effective
• Objective – Fair, impartial and unbiased and is the result of a fair-minded and communication INTERNAL COMMUNICATION COMMUNICATE WITH OUTSIDE READER DISSEMINATING INFORMATION TO OUTSIDE READER
balanced assessment of all relevant facts and circumstances. • Must make advance
• Clear – easily understand and logical, avoiding unnecessary technical language preparation when • CAE may adopt policies or The CAE may facilitate the adoption of appropriate policies if there are no preexisting In disseminating information to outside readers, there are matters to be considered:
and providing all significant and relevant information communicating bad news guidelines in communicating guidelines, which may include: • Usefulness of written agreement with intended recipients concerning information to be
• Concise – communication is to the point and avoid unnecessary elaboration, • Must focus on the setting sensitive information within and • Authorization to seek approval in reporting information outside the organization. reported and internal auditor’s responsibilities.
superfluous details, redundancy and wordiness. for the meeting outside the group of internal • Process for seeking approval to report information outside the organization. • Identification of information providers, sources, report signers, recipients and related persons
• Constructive – helpful to the engagement client and organization and leads to • Must be straightforward auditors and/or chain of command. • Guidelines for permissible and nonpermissible information to be reported. to receive report or information.
improvements where needed. and honest in their delivery • Most information communicated • Outside persons authorized to receive information and types of information they may • Identification of objectives, scope and procedures to be performed in generating applicable
• Complete – lacks nothing that is essential to the target audience and include all • Must anticipate the may exposure threats, receive. information.
significant and relevant information and observation to support responses or feedbacks uncertainties, fraud, waste and • Related privacy regulation, regulatory requirements, and legal considerations for • Nature of report or other communication including opinions, inclusions or exclusion of
recommendations and conclusion from clients mismanagement, illegal activities, reporting information outside the organization. recommendations, disclaimers, limitations and types of assurance or assertions to be
• Timely – opportune and expedient, depending on the significance of the issue, • Determining the corrective abuse of power, misconduct that • Nature of assurances, advice, recommendations, opinions, guidance and other provided.
allowing management to take appropriate corrective action actions endangers, public health or safety information that may be included in communicating information outside the • Copyright issues, intended use of information and limitations on further distribution or sharing
or other wrongdoings. organization. of information.
TECHNOLOGY
CHP 8 - IMPACT OF TECHNOLOGY TECHNOLOGY CHALLENGES TO IA IA FUNCTION IN AN IT BUSINESS IT RELATED RISK

IMPLICATIONS OF ENVIRONMENT

INFORMATION
• Business becomes more and • Issues surrounding modification of system • IA – knowledgeable about computers, IT-related risks
more dependent on IT • Poor IS management comfortable and confident with 1. System Application Error
• Set of skills required by • Unstable system and confidence erosion technology • The risk of system error might increase since the system requires to be upgraded
TECHNOLOGY ON business– technical skill &
business process knowledge


Extra cost and time to correct system
Business loses credibility
• IA must be able to visualise impact of
technology on business – good and bad
from time to time due to the expansion of business operations. Too many changes
and flaws in the system program procedures will lead to the issue of reliability of the

INTERNAL AUDITING • But, with IT – more risks faced by


the business, and at the same


Authority intervention
Compromised control that could result in fraud
• Impact of technology on business
going concern
software.
2. Hardware Failure
time greater earning capacity • Poor database management, data integrity • Specialised field – IS auditors • Computer hardware such as central processing unit (CPU), monitor and servers can
© NIRMALA (UITM • Entity dependent on IT must b
evaluated from going concern


Threat to asset security
Systems and process confusion – result in fraud
• Standards issued by IIA– Guide to
Assessment of IT General Controls
easily malfunction if not properly maintained and protected.
3. Computer Crime
aspect using IT perspective Scope Based on Risk (GAIT) • Business transactions conducted via the Internet can expose the organization's
SEGAMAT) electronic data to attacks from hackers, competitors, terrorist groups, previous
employees or industrial spies.

IT AUDIT
EVALUATION OF GENERAL & APPLICATION CONTROLS
IT audit focuses on the evaluation of an organization's TYPES OF IT AUDIT INFORMATION SYSTEM AUDIT
computer systems and network to ensure: GENERAL CONTROL – Applicable to all aspects of IT functions, for
• the effectiveness of control procedures in minimizing • Operational computer system audits Purpose – to provide assurance that an appropriate level of control over the confidentiality, example the administration of IT function, hardware or software
related technology risks • IT application audits integrity and availability of information within system acquisition and maintenance and physical and security control over
• the compliance with international or Malaysia’s • Developing system audit (SDLC) • System operation is opened to threat (e.g. virus attack), vulnerability of system (e.g. product hardware
standard operating practice, policies, procedures and • IT management audit flaw) and associated risk
related law or regulations of the regulatory body. • IT process audit • Business need to have information security policy Scope Of Audit Objectives of Audit
• Information security and control audit • Network environment – e-commerce websites reside
• Disaster contingency or disaster recovery audit • Sources of threats to network environment: network segment, application software, system Logical Access To ensure a proper control in place for
• IT strategy audit software, process integrity and physical security Controls infrastructure, applications and data.

ELEMENT OF IT AUDIT GUIDE TO CONDUCT IT AUDIT Physical Access To ensure proper control in place for physical
Controls access within IT department and its critical
1. Physical and Environmental Review – Reviews physical facilities and conditions of IT environment such as physical access, power supply, 1. The GAIT Methodology B-head areas.
air conditioning and humidity control • a guideline to assess the scope of IT general controls using a top-down and
2. System Administration Review –It includes review of security control procedures of existing operating systems and database management risk based approach. Administration of IT To ensure proper administration of people and
systems. • helps the management to identify any deficiencies in key IT general controls Function resources of the department.
3. Application Software Review – Reviews all business application software, for example, software to record accounting and finance that may result in material errors in financial statements.
transactions used by the finance department, software to process salary used by the payroll department and web-based customer order • It include four principles that form the basis for this guideline Backup and To ensure that a proper backup and
system used by the sales department. 2. GAIT for IT General Control Deficiency Assessment Contingency Plan contingency plan is in place for unexpected
4. Network Security Review – Reviews IT network's infrastructure, which includes internal and external connections to the system, perimeter • a guideline to evaluate any IT general controls deficiencies identified during emergencies such as fire, virus attack, power
security, firewall review, router access control lists' port scanning and intrusion detection assessment failure or natural disaster.
5. Business Continuity Review – Reviews control procedures in ensuring the systems and information are available when needed. 3. GAIT for Business and IT Risk
6. Data Integrity Review – Rieviews control security measures around IT operating systems and application software to ensure output • a guideline to help identify the IT controls that are critical to achieve APPLICATION CONTROL – Include control of usage of individual
produced is accurate, complete, timely and valid. business goals and objectives. transactions specific to certain software application. For example,
controls over the processing of sales
STEPS TO PERFORM IT AUDIT ISSUE IN IT AUDIT
Scope Of Objectives of Audit
1. Establish the Terms of Engagement – The CAE will determine the scope and objectives of the audit of IT functions. • Security – To ensure access to the system and its data is restricted to Audit
2. Preliminary Review – This is the process where the auditor needs to gather information on the IT department as a basis for preparing an authorized personnel only
audit plan. • Confidentiality – To ensure that sensitive information of an organization is Input Control To check the integrity of data entered into an
3. Establish Materiality and Assess Risk – The auditor needs to establish judgement on the materiality of the IT function as well as perform protected from unauthorized access or disclosure. organization application.
assessment on the auditee's business risk in order to set the scope for the audit. • Privacy – To ensure personal information of any third party such as
Processing To ensure proper control for data processing so that
4. Plan the Audit – Normally, a proper audit plan includes engagement's objectives, scope, timing and resource allocation. customers' addresses and contact numbers are treated in accordance with
Control the process is complete, accurate and authorized.
5. Consider Internal Control – The auditor has to consider the internal control of the auditee in order to begin the audit process. The the organization's business policy and protected from unauthorized access
information on internal controls could come from a variety of sources such as studies of existing internal controls, previous audit reports, or disclosure.
Output Control To ensure output results similar with input data. To
reports by regulators such as Bank Negara Malaysia, Bursa Malaysia or feedback from operating personnel. • Processing Integrity – To ensure business data are processed accurately
ensure computer output is not interrupted by or
6. Perform Audit Procedures – The auditor will perform the audit process based on the scope stated in the audit plan. The auditor will use a and completely in a timely manner with proper authorization.
shown to unauthorized users.
substantive test approach to audit IT business functions. • Availability – To ensure the operating system and its data are available at
7. Issue the Audit Report – The auditor will issue an audit report once all audit procedures have been completed and evaluated. all times to meet the needs of business operations.
AUDITING OF SYSTEM DEVELOPMENT LIFE CYCLE (SDLC) COMPUTER-ASSISTED AUDIT TOOLS (CAATs)
CHP 8 -
IMPLICATIONS OF
System Development Life Cycle (SDLC) is a series of steps used to identify the phases of an information
system development project an approach of auditing using computers. It offers FUNCTION

INFORMATION
• Process centric approach to develop and implement system - set of defined goals and timelines that sets various tools or utilities, which help the auditor to
out the completion date and associated deliverables within each phases of the life cycle select, gather, analyze and report audit findings. • Information

TECHNOLOGY ON
• Each phase (plan, analyse, design, implement) sequentially executed – allow proper evaluation and Tools/utilities to help auditor to select, gather, analyse retrieval and
resolution of problems within each phase and report audit findings. analysis

INTERNAL AUDITING
CAATs can be classified: • Fraud detection
Phase 1: Systems planning • Electronic working papers tool
During this phase, management will plan a system to meet the organization's mission and objectives. The • Information retrieval and analysis • Audit reporting
plan will include general guidelines for system development, time frame and budget.
Phase 2: Systems Analysis
© NIRMALA (UITM • Fraud detection
• Network security
function
During the second phase, a system analyst will gather the necessary information such as facts and samples • Electronic commerce and internet security
to be used in the project from the end users.
Phase 3: Conceptual Design
SEGAMAT) • Continuous monitoring
• Audit reporting
During this phase, a conceptual design is developed to include views from all respective persons involved
with the development project. AUDITING E-COMMERCE ADVANTAGES
Phase 4: Systems Selection
A system selection phase involves a process where the management together with the system analyst will Issues in E-commerce Environment • CAATs are suitable to audit large volume of transactions. It is valuable to
evaluate alternative system requirements to select the best system to meet the requirements stipulated by • Business continuity organisations with complex processes, distributed operations and high
the users as well as to fulfil the organization's objectives. • Information security and privacy transaction volumes.
Phase 5: Detail Design • The use of CAATs is important for auditors to gain access into audited data in a
• The lack of audit trails
At this level, the system analyst will develop a system based on the DFD created in phase 3, taking into much effecient way. A direct access to an organisation’s data will eventually
• Record retention reduce the time and effort spent in performing audit procedures with assured
consideration the analysis made during the selection process.
Phase 6: Programming and Testing Systems • Segregation of duties accuracy.
It will determine whether the outcome of the project is able to meet the predetermined objectives. • Legal liability • Using CAATs in performing substative testing will provide total assurance to the
Phase 7: Systems Implementation area being audited. It allows auditors to point out errors or fraud easily in order to
Management has to sign-off the user acceptance agreement before the system is made live. However, the provide effective recommendations.
process of the SDLC does not end at this stage. Management is required to perform post-implementation E-commerce Environment • CAATs provides a standard uniform practice and user-friendly interface for
evaluation on the project. • Electronic commerce (e-commerce) is the process by auditors. It allows auditors to perform various tasks, irrespective of data format or
which organisations conduct their business over the underlying operating system of an organisation.
IA Involvement in SDLC Risk Factors in SDLC electronic systems such as the Internet and other • Data could be examined faster and more accurate
• Proactive auditor’s involvement • New system does not meet business computer networks with their customers, suppliers • Practical to scrutiny large volume data
• On-the-spot advice for all phases – not wait till the requirements • Improve effectiveness and efficiency of audit
and other external business partners.
end • Failure to develop adequate/complete user • Continuous in usage once the software is available
• Threats to e-commerce environments include virus • Flexible as the parameters can be varies
• Advisory role to the project team requirements, poor understanding about the
• Independently monitor progress of project and project, lack of user involvement, infections, hacking, cybercrime and failure of the
make recommendations requirements and specifications keep system and infrastructure. DISADVANTAGES
• Independent postimplementation review changing
• Gaining better understanding about the system • Poor project management/SDLC methodology Reason for Audit e-Commerce • Audit software incompatible with other softwares
• Better position to understand the system if involved • Planned financial resources exceeded, late • To assess the effectiveness of the infrastructure and • May require considerable computer resources/capacity
in the development process completion of individual task, missed security measures of an e-commerce. • Give rise to question cost vs. benefits
• Would assist in subsequent IT audit; or in using IT deadlines, pressure to agree to impossible • To evaluate compliance of ecommerce business • Modifications to systems may render vendor’s warranty void
for audit (e.g CAAT) schedules operations with an organisation’s IT security policies • Security and validity of the system can be compromised – especially in using
• Independence of internal auditors • Inadequate change management control dummy data
as well as with the industry good practices.
• Professional relationship from consultant • Lack of systems and process to manage • Compitability issues with the existing software applications used by a company.
• To evaluate the readiness of IT functions in the event • Installation process require various computer resources or facility, for examples
perspective – advisory capacity only change
of a major failure in e-commerce business the type of processor, size of memory and storage required.
• Better risk management • Who has made the changes, what changes
• Provider of assurance and advisory services only are made, when they are made transactions. • Sensitive business data such as customers’ detail, business plan and strategy
• Better identification of risk from independent • To identify other security issues that may affect the could be compromised by irresponsible persons, if not handled properly.
perspective current infrastructure of an e-commerce model. • Too many software available – may need software specialist to support the
system
CHP 9 - INTERNAL AUDIT PROCESS – INVESTIGATION OF FRAUD © NIRMALA (UITM SEGAMAT)
FRAUD

Fraud encompasses a wide range of irregularities and illegal acts characterized by intentional deception or misrepresentation. In TYPES OF FRAUD
general, fraud is defined as an act or course of deception, an intentional concealment, omission or perversion of truth, to:
• gain unlawful or unfair advantage 1. Asset Misappropriation
• induce another to part with some valuable item or surrender a legal right • Involves stealing of cash or assets (supplies, inventories, equipment and information) from the organisation. In many cases, the perpetrator tries to conceal the theft, usually by adjusting the records.
• inflict injury in some manner. 2. Financial Statement Fraud
• Wilful fraud is a criminal offense which calls for severe penalties, and its prosecution and punishment (like that of a murder) is not • Involves misrepresenting financial statements, often by overstating assets or revenue or understating liabilities and expenses. Financial statement fraud is typically perpetrated by managers who seek to enhance
bound by the statute of limitations. the economic appearance of the organisation. Members of the organisation may benefit directly from the fraud by selling stock, receiving performance bonuses, or using the false report to conceal another fraud.
Other definition of fraud 3. Corruption
1. as an advantage gained by unfair or wrongful means, an infraction of the rules of fair trade; a false representation of fact made • Misused of entrusted power for private gain. Corruption includes bribery and other improper uses of power. Corruption is off–book fraud meaning that there is little financial evidence available to prove that the
knowingly, without belief in its truth, recklessly, not caring whether it is true or false crime occurred. Corrupt employees do not have to fraudulently change financial statements to cover up their crimes. They simply received cash payments under the table. In most cases, these crimes are
2. as a deception deliberately practiced in order to secure unfair or unlawful gain uncovered through tips or complaints from third parties. Corruption often involves the purchasing processes.
3. Intentional misinterpretations of financial information by one or more individuals among management, employees or third parties. 4. Bribery
• Is offering, giving, receiving or soliciting of anything of value to influence an outcome. Bribes may be offered to key employees or managers who are purchasing agents and who have the ability to award businesses
to vendors.
FRAUD TRIANGLE 5. Falsification of Expense Claims
• An old favourite with both senior and junior staff. Common ‘ruses’ include inflating mileage claims, entertaining friends and relatives at the company’s expense and claiming for expenses that were never incurred.
1. PRESSURE 6. Stealing Money from the Company Bank Account
• Pressure is what causes a person to commit fraud. Pressure can include almost anything including medical bills, expensive tastes, • The perpetrator having gotten away with stealing once will keep on doing it again.
addiction problems, etc. Most of the time, pressure comes from a significant financial need/problem. Often this need/ problem is 7. Manipulating Sales Figures to Reach Target and Achieve Bonuses
non-sharable in the eyes of the fraudster. That is, the person believes, for whatever reason, that their problem must be solved in • A simple version of this involves booking sales in one month then crediting them back the next, unless the perpetrator keeps this up, the overstatement in one month will naturally show as a shortfall in the next.
secret. However, some frauds are committed simply out of greed alone. 8. Falsifying Supplier Invoices
2. OPPORTUNITY • A senior manager who had renovation work carried out on his house and then arranged for the invoices to be sent to the company, booked as costs for work carried out on the company’s premises.
• Opportunity is the ability to commit fraud. Because fraudsters don't wish to be caught, they must also believe that their activities 9. Stock Theft
will not be detected. Opportunity is created by weak internal controls, poor management oversight, and/or through use of one's • A time-honoured way to make a ‘fast buck’. The perpetrator will over a period of time abscond with a number of items from the warehouse and resell them. So long as the stock losses are within tolerance, then it is
position and authority. Failure to establish adequate procedures to detect fraudulent activity also increases the opportunities possible for this to remain undetected for a significant period of time.
fraud for to occur, Of the three elements, opportunity is the leg that organizations have the most control over. It is essential that 10. Transactions That Are Not ‘Arms Length’
organizations build processes, procedures and controls that don't needlessly put employees in a position to commit fraud and that • When a company asks for tenders for a contract, they usually obtain at least three quotes from third parties. The best value quote should then be selected. When the system does not run effectively, there is an
effectively detect fraudulent activity if it occurs. opportunity for friends and relatives of the purchasing department to send in quotes that are accepted, bypassing the quotes from reputable suppliers.
3. RATIONALIZATION 11. Tax Evasion
• Rationalization is a crucial component in most frauds. Rationalization, involves a person reconciling his/her behavior (stealing) • Fraud at corporate level. Excessively complex organisational structures are created and designed to obfuscate the revenue streams to hide the reality from tax authorities.
with the commonly accepted notions of decency and trust. Some common rationalizations for committing fraud are: 12. Fictitious Invoicing
o The person believes committing fraud is justified to save a family member or loved one • Where there are poor accounting controls, fraudsters can arrange for fake invoices from connected parties to be passed for payment.
o The person believes they will lose everything-family, home, car, etc. if they don't take the money 13. Acquisition of Company Property at Less Than Market Value
o The person believes that no help is available from outside • This requires the collusion of at least two people (usually quite senior in position). Company property is ‘sold’ to one of the individuals at a bargain price approved by the other. The property is then resold at market
o The person labels the theft as "borrowing", and fully intends to pay the stolen money back at some point value and the profit is split between the two individuals.
o The person, because of job dissatisfaction (salaries, job environment, treatment by managers, etc.), believes that something is 14. Theft of Raw Materials
owed to him/her • Manufacturers should measure the quantities and costs of the raw materials used in the manufacturing process. Some processes use expensive materials such as gold. When the measurement system is
o The person is unable to understand or does not care about the consequence of their actions or of accepted notions of decency compromised or management does not investigate adverse yield variances, fraudsters have the opportunity to steal the raw material.
and trust.

FRAUD INDICATOR (RED FLAG)

1. COMMON PERSONALITY TRAITS OF 2. COMMON SOURCES OF PRESSURE 3. CHANGES IN BEHAVIOUR


FRAUDSTERS

• Wheeler and dealer • Medical problems — especially for a loved one • Suddenly appears to be buying more material items Brags about new
• Domineering/controlling • Unreasonable performance goals purchases
• Do not like people reviewing their work • Spouse loses a job • Starts to carry unusual amounts of cash
• Strong desire for personal gain • Divorce • Creditors/bill collectors show up at work or call frequently
• Have a ‘Beat the System Attitude’ • Starting a new business or current business is struggling • Borrows money from co-workers
• Live beyond their means • Criminal conviction • Becomes more irritable or moody
• Close relationship with customers or • Civil lawsuit • Becomes unreasonably upset when questioned
vendors • Purchase of a new home, a second home, or a home renovation • Becomes territorial over their area of responsibility
• Unable to relax • Need to maintain a certain lifestyle (‘champagne tastes’ or • Would not take vacation or sick time or only takes it in small increments
• Often have a ‘too good to be true’ work ‘keep up with the Jones’) —person (or spouse) either likes • Works unnecessary overtime
performance expensive things or feels pressure to ‘keep up with’ or out-do • Turns down promotions
• Do not take vacation or sick time or only others in regards to material possessions • Starts coming in early or staying late
take leave in small amounts • Excessive gambling • Redoes or rewrites work to ‘make it neat’
• Often work excessive overtime • Drug or alcohol addiction • May start or mentions family or financial problems
• Outwardly appear to be very trustworthy • Exhibits signs of drug or gambling addiction
• Often display some sort of drastic change • Exhibits signs of dissatisfaction
in personality or behaviour
RESPONSIBILITIES OF FRAUD PREVENTION & DETECTION

CHP 9 - INTERNAL AUDIT ROLE OF BOARD OF


DIRECTOR
• To oversee and monitor
ROLE OF AUDIT COMMITTEE
• To evaluate management’s identification of fraud risks.
• To implement anti-fraud measures.
ROLE OF MANAGEMENT
• Responsible for overseeing the activities of employees and typically does so by implementing
and monitoring processes and internal controls.

PROCESS – INVESTIGATION OF management’s actions to


manage fraud.
• To evaluates
• To provide the tone at the top that fraud will not be accepted in any form.
• To hire external auditors to report on the financial statements of the organisation.
• To provides recommendations on internal control.
• Assess the vulnerability of the entity to any fraudulent activities.
• Responsible for establishing and maintaining an effective internal control system at a
reasonable cost.

FRAUD management’s
identification of fraud risks.
• To implement anti-fraud
• To be responsible for overseeing management’s compliance with appropriate
financial reporting.
• To be responsible for preventing senior management from overriding the controls or
• Maintain discussions with investigators and legal counsel to develop controls over the
investigation process, including developing policies and procedures for effective fraud
investigations and for handling the results of investigations, reporting and communications.
measures. other inappropriate influence over the reporting process.

© NIRMALA (UITM SEGAMAT) • To set the tone at the top.

ROLE OF INTERNAL AUDITOR ROLE OF EXTERNAL AUDITOR ROLE OF FRAUD INVESTIGATOR ROLE OF OTHER EMPLOYEE
• To launch initial or full investigation of suspected fraud, to perform • External auditors have the • Fraud investigators are usually responsible • Employees are the eyes and ears of an
root cause analysis and control improvement recommendations, to responsibility to comply with for the detection and investigation of fraud organisation, and they should be empowered to
monitor a reporting/whistle-blowing hotline and provide ethics professional standards and to plan as well as the recovery of assets. They also maintain a workplace of integrity.
FORENSIC AUDIT training and perform audit for an have a role in fraud prevention. • Employees can report their suspicion of fraud to
• To obtain sufficient skills and competencies including knowledge of organisation’s financial statements • Senior management and the audit the employee hotline, the internal audit
• Forensic audit is defined as the application of accounting methods to the tracking and collection of forensic evidence. fraud schemes, investigation techniques and laws to obtain reasonable assurance committee need to support investigators department or a member of management.
• Financial auditing may be defined as a concentrated audit of all the transaction of the entity to find the correctness of such • To conduct proactive auditing to search for misappropriation of whether these statements are free and to let all stakeholders know that the • To deter and detect fraud and abuse, many
transactions and to report whether or not any financial benefits has been attained by way of presenting unreal picture. assets and information misrepresentation using CAAT techniques from material misstatements and if business entity is ready to respond quickly experts believe an employee hotline that is
• Forensic audit involves examination of legalities by blending the techniques of propriety (VFM audit), regularity, investigative and data mining misstatements were found, whether and appropriately to fraud risks. appropriately monitored is the single most cost-
and financial audits. The objective is to find out whether or not true business value has been reflected in financial • To employ analytical and other procedures of high-risk accounts they were caused by error or fraud. effective fraud detection and deterrence
statements and in the course of examination to ascertain if any fraud has taken place and transactions to identify potential fraud mechanism.

SKILLS FOR FORENSIC AUDITOR APPLICATION EXAMINATION METHOD


• Knowledge of entity’s business • Forensic Accounting and Audit • Tests of reasonableness –
FRAUD RISK ASSESSMENT
and legal environment. may be applied in the following includes check weaknesses of
• Awareness of computer assisted areas besides fraud detection: internal control, identify • A fraud risk assessment is a tool that assists management and WAY TO COLLECT THE INFORMATION ON FRAUD
audit procedures. • Conducting due-diligence questionable transactions and internal auditors to systematically identify where and how fraud
• Innovative approach and sceptics (especially for segment wise review questionable transaction may occur and who may be in the position to commit fraud. A fraud 1. Code of conduct confirmation
of routine audit practices. profitability analysis) documents. risk assessment concentrates on fraud schemes and scenarios and • When employees sign an annual code of conduct outlining their responsibilities in the prevention and detection of fraud, they can be asked
• Business valuation • Historical Comparisons – wheher or not the controls can be circumvented. to report any known violations.
• Management auditing includes develop profile, identify • A fraud risk assessment generally includes FIVE KEY STEPS: 2. Whistle-blower hotline
• Assessing loss before settling questionable accounts and 1. Identify Relevant Fraud Risk Factors • This can take the form of a telephone call or a web-based reporting system where the whistle blower can remain anonymous.
insurance claims. gather and preserve evidenc 2. Identify Potential Fraud Schemes and Prioritize Them Based on 3. Exit interviews
Risk • Conduct exit interviews for terminated employees or those who have resigned can help identify fraudulent schemes. These interviews may
FRAUD INVESTIGATION 3. Map Existing Controls to Potential Fraud Schemes and Identify also determine whether there are issues regarding management’s integrity, and may provide information regarding conditions conducive to
Gaps fraud.
A fraud investigation consists of gathering sufficient information about specific details and performing those procedures 4. Test Operating Effectiveness of Fraud Prevention and Detection 4. Proactive employee survey
necessary to determine whether fraud has occured, the loss or exposure associated with the fraud, who was involved and how it Controls • Routine employee surveys can be conducted to solicit employees’ knowledge of fraud and unethical behaviour within the organisation. A
happened 5. Document and Report of the Fraud Risk Assessment proactive survey could elicit anonymous information from employees, which would aid the organisation in catching fraud sooner than
waiting for employees to volunteer the information.
1. INVESTIGATION PROCESS 2. INTERNAL AUDITING'S ROLE
Management is responsible for the investigation • Help management identify critical indicators of fraud schemes.
process, which includes: • Evaluate gaps in internal controls during the progression of fraud FRAUD PREVENTION FRAUD DETERRENCE
• developing policies and procedures reviews/ investigations. Conducting of ad hoc forensic accounting
• preserving evidence investigations. 1. Control environment • Training is usually a key factor in deterring fraud. Training can cover the
• handling the results of investigations • Support the chief audit executive to ensure appropriate • Elements of a strong control environment to help prevent fraud include the following: organisation’s expectations of its employees’ conduct, the procedures and
• reporting communication on fraud issues is addressed by IA to the board, the o A code of conduct, ethics policy or fraud policy to set the appropriate tone at the top. standards necessary to implement internal controls and employee roles and
• communication audit committee and others. o Ethics and whistle-blower programmes to report fraud. responsibilities to report misconducts.
o Hiring and promotion guidelines and practices. • Deterrence measures:
o Oversight by the audit committee, board or other oversight body. o Fraud policies
3. CONDUCTING THE 4. REPORTING 5. COMMUNICATION OF FRAUD INCIDENT 2. Risk assessment o Analytical review
INVESTIGATION Reporting fraud There are two types of communication • Establishing a fraud risk assessment process that considers fraud risk factors and fraud schemes by involving appropriate o Employee education
The common investigation procedures investigations • Internal communication – Strategic tools used by personnel in the process. Also, fraud risk assessments should be conducted on a regular basis o Surprise audit
include: consists of oral, the management to reinforce its position regarding 3. Control activities
• Obtaining evidence – collecting written, interim or integrity, action taken on fraudster when there is a • Are policies and procedures for business processes, including appropriate authority limits and segregation of duties.
and preparing the evidence is a final communication violation of policy and demonstrating the 4. Information and communication FRAUD DETECTION
critical stage in proving the fraud to senior importance of internal control. Such • Promoting the importance of the fraud risk management programme and the organisation’s position on fraud risk both
• Interviewing – Investigators need management and/or communications may take the form of newsletter, internally and externally through corporate communications programs by:
Fraud detection methods need to be flexible, adaptable and continuously changing
to be knowledgeable. They have the board regarding memo or fraud training program. o Designing and delivering fraud awareness training.
to meet the changes in the risk environment. While preventive measures are
responsibility to ensure that the the status and results • External communication - Management will o Ascertaining affirmation or creating a certification process to ensure that employees have read and understood
apparent and readily identifiable, detective controls may not be as apparent.
investigation process is handled of fraud determine whether to inform public or not after corporate policies and that the employees are in compliance with the policies.
in a consistent and prudent investigations. consulting with legal counsel, human resource 5. Monitoring
manner personnel and the CAE. Notification to the • Providing periodic evaluation of antifraud controls by:
enforcement is also needed. o Using independent evaluators for the fraud risk management programme by internal auditors or other groups.
o Using technology to aid in continuous monitoring and detection activities.

You might also like