0% found this document useful (0 votes)
6 views9 pages

Internal Control Processes Overview

Chapter 6 discusses the importance of internal control processes in business, emphasizing their role in safeguarding assets, ensuring accurate financial reporting, and compliance with laws. It outlines various frameworks like COSO, Turnbull, and CoCo, each providing different perspectives on internal control components and effectiveness. Key issues for assessing internal control effectiveness are also identified, including management responsibility, audit committee oversight, and the need for regular reviews of control processes.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
6 views9 pages

Internal Control Processes Overview

Chapter 6 discusses the importance of internal control processes in business, emphasizing their role in safeguarding assets, ensuring accurate financial reporting, and compliance with laws. It outlines various frameworks like COSO, Turnbull, and CoCo, each providing different perspectives on internal control components and effectiveness. Key issues for assessing internal control effectiveness are also identified, including management responsibility, audit committee oversight, and the need for regular reviews of control processes.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Chapter 6 – Internal Control Processes

Business processes need to be well controlled. “Internal control” is the control exercised within
the business by management and overseen by the board. It also includes the control of activities that
have been outsourced.
Internal control comprises the plan of organization and the coordinate methods and measures
adopted within a business to safeguard its assets, check the accuracy and reliability of its accounting
data, promote operational efficiency, and encourage adherence to prescribed managerial policies.
Internal control is broadly defined as a process, effected by the entity’s board of directors,
management and other personnel, designed to provide reasonable assurance regarding the
achievement of objectives in the following categories:
• Effectiveness and efficiency of operations.
• Reliability of financial reporting.
• Compliance with applicable laws and regulations.

PARADIGM 1: COSO ON INTERNAL CONTROL


COSO (Committee of Sponsoring Organizations) stated that Control depends on each of the
other functions of management. There is no control without:
• Planning—for instance, design of the right procedures (which is part of planning) is essential
for effective control. There has to be a plan against which to exercise control. Without a plan there can
be no control.
• Organizing—for instance, structuring the business into subdivisions and determining reporting
arrangements. To illustrate the proximity between organizing and controlling it is illuminating to
remember that Fayol used the label “span of control” to describe the issue of how many subordinates
one boss might supervise—yet this is clearly a matter of organization as well as of control.
• Directing and leading—few would question that the quality of leadership impacts upon
control.
• Staffing—too few or too many staff can lead to things getting out of control—as can
incompetent, disloyal, dishonest or lazy staff.
• Coordinating—is the art of ensuring that happenings occur in harmony with each other—
without which things will be out of control.

Internal control is regarded by COSO as a process, not a state of affairs; and note that the definition
acknowledges that effective internal control requires a conscious process of design (and redesign) as it
cannot be expected to happen by chance. According to the COSO internal control framework, internal
control is achieved by means of five essential components of internal control that must be in place and
must be functioning well.
1. Control environment
2. Risk assessment
3. Control activities
4. Information and communication
5. Monitoring

PARADIGM 2: TURNBULL ON INTERNAL CONTROL


The UK’s Turnbull guidance is closely similar to the COSO internal control framework, though
developed in much less detail. The UK Corporate Governance Code has this to say about internal
control:
C.2 Internal Control - The board should maintain a sound system of internal control to safeguard
shareholders’ investment and the company’s assets.
C.2.1 The board should, at least annually, conduct a review of the effectiveness of the group’s
system of internal controls and should report to shareholders that they have done so. The review should
cover all material controls, including financial, operational and compliance controls and risk
management systems. Turnbull defines internal control as: An internal control system encompasses the
policies, processes, tasks, behaviors and other aspects of a company.
Turnbull guidance repeats the COSO essential components of internal control, except that it
confusingly combines “control environment and control activities”.

PARADIGM 3: COCO ON INTERNAL CONTROL


The internal control framework of the Canadian Institute of Chartered Accountants’ Criteria of
Control Board (“CoCo”) is less “mechanical” and more “behavioral” than the COSO internal control
framework and, arguably, has advantages in application within organizations that are more
participative and less hierarchical, as well as being a valuable control framework to use in control self
assessment situations.
CoCo also defines internal control broadly, as does COSO, to cover everything that management
does other than the setting of objectives. CoCo defines internal control as follows: Control comprises
those elements of an organization (including its resources, systems, processes, culture, structure and
tasks) that, taken together, support people in the achievement of the organization’s objectives.

CoCo explains: A person performs a task, guided by an understanding of its purpose (the
objectives to be achieved) and supported by capability (information, resources, supplies and skills).
The person will need a sense of commitment to perform the task well over time. The person will
monitor his or her performance and the external environment to learn about how to do the task
better and about changes to be made. The same is true of any team or work group. In any
organization of people, the essence of control is purpose, commitment, capability, and monitoring
and learning.

PARADIGM 4: A SYSTEMS/CYBERNETICS MODEL OF INTERNAL CONTROL


Conceptually this paradigm views the organizational process as analogous to, for instance, an
air conditioning system. The plan is the room temperature setting of the thermostat. Actual
performance is monitored and compared to the plan. If a significant variance between “plan” and
“actual” occurs, then the control system makes a decision to switch the fan on or off in order that, and
until, room temperature is within an acceptable tolerance of the planned temperature. So the control
system is continuously interpreting information available to it. In this system the monitoring and
decision taking is automated or programmed into the programmer or controller.

A system is a set of related elements with a purpose. A system has three main elements The
“process” changes the “input” into “output”. The parts of the elements which may change are termed
“variables”. A system conceptually has a “boundary” within which the functioning of the system [Input >
Process > Output] takes place. A subsystem is a smaller system within a larger system. The term
“internal” is used to refer to what happens within a system, and “external” if the variable enters from
outside the system boundary, or exits to beyond the system boundary. The environment of a system is
what takes place beyond its boundary. A turbulent environment often requires a system to be more
“open” to the environment in order to cope with rapid change. Particularly with open systems we use
our discretion to draw the boundaries depending upon the focus of our interest. We can invariably “peel
off the skin” and see other, smaller systems within an outer boundary.
With reference to Figure 6.6, the “control object” is the variable of the system’s behavior which
is to be monitored and controlled. The “detector” is the part of the system which measures (or
monitors) the control object. The “reference point” is the standard against which the actual
performance of the control object is compared.
PARADIGM 5: CONTROL BY DIVISION WITH SUPERVISION
This model of internal control is based on the premise that effective control may be achieved
by means of an appropriate combination of various opportunities to “divide” (“separate off” or
“segregate”), together with supervision. Designing our control processes to take advantage of sensible
opportunities to divide may be a costless way of achieving effective internal control as it may be just a
matter of allocating work in ways that reduce the likelihood that errors and losses, deliberate or
accidental, will occur.

Division of Duties
Ensure that two or more people work together on tasks where there is a risk of a lack of
control, so that they act as a cross-check on each other. This also has the advantage of avoiding
excessive dependence upon one member of staff. Examples might include issuing passwords, granting
and adjusting credit limits, the database administrator role, requiring two staff to open a vault, and so
on.

Division of Fundamentally Incompatible Responsibilities


Control will be strengthened if authorization is required from someone who does not execute
the task, and if both the authorization and the execution are separated from the accounting for this
activity. This can often be applied to custodial activities such as the cashier function or the warehousing
function. The cashier should not be the person who authorizes the release of cash or the replenishment
of the cash float; neither the cashier nor the authorizing person should maintain the control account for
cash. Another, noncustodial example would be that the purchasing manager places orders against
someone else’s authorization and neither have a hand in accounting for purchases.

Division of Operations
Some activities conflict with each other if undertaken by the same person or group. For
example, selling should be divided from making decisions about levels of credit extended to customers;
if this is not done, then the control weakness needs to be compensated for by supervision—perhaps by
review of sales staff’s credit limit adjustment decision by a credit control committee.

Division of Staff
Be aware of the control weaknesses that may arise when the effect of other divisions is negated
because of personal relationships. For instance when two members of staff undertaking segregated
tasks share the same office and informally substitute for each other, or when they strike up a personal
relationship outside work.

Division of Data
Modern IT databases mean that data is held once only on IT databases, to be accessible to all
users from different parts of the organization who need to access that data. Artificial walls need to be
built into IT systems. At the design stage, for each category of data it should be determined who has the
authority to add, change, delete and merely to look at that category of data. Controls should then be
built into the software to limit activity in that desired way—e.g. by means of password control. Internal
auditors should have unrestricted authority to look at data but no opportunity to add, change or delete
any data.

Division of Data Entry and Accounts Postings


Consider whether control may be improved if certain “bookkeeping” activities are divided. For
instance the posting of debits from the post of credits to personal accounts; the posting of adjusting
entries from the posting of original entries; the submission of corrections to rejected input data from
the original submission of the input errors, etc.

Division of Authority
There are different ways in which authority to commit the organization can be allocated with
varying degrees of control effectiveness. It could be allocated to one person; or to one person with
review by another; or by two people jointly, or to a committee, or to nobody. Who these individuals are,
and their degree of independence from each other, also impacts upon the effectiveness of the
authorization control.

Division of Time
Often “time is of the essence” in modern businesses. To complete a transaction promptly tends
to speed up business cycle times and increase the volume of business while lowering costs. But
sometimes it can be sensible to build deliberate time delays into transactions and to make other uses of
time in order to improve control. Examples include delaying shipment until the payment has cleared,
time locks on vaults, “log off after time out”, etc. Control may be improved if the system provides after
the event evidence of control sensitive activity, and also if after the event authorization is required
before a change can be implemented. For example if a customer’s credit limit is changed, the system
may be programmed to require after the event authorization by a supervisor before the changed credit
limit can be used.

PARADIGM 6: CONTROL BY CATEGORY


A particular type of control may be appropriate in a certain circumstance, and indeed more than
one type of control may be needed to bear down effectively on a particular risk. Some categories of
control are as shown in the table. As with most categorizations, there is overlap between some of them.
DETERMINING WHETHER INTERNAL CONTROL IS EFFECTIVE
The CoCo program of the Canadian Institute of Chartered Accountants has stated that control is
effective to the extent that it provides reasonable assurance that an organization will achieve its
objectives reliably; or, control is effective to the extent that the remaining (uncontrolled) risks of the
organization failing to meet its objectives are acceptable. Authoritative guidance, for instance the
Turnbull Report or the SEC rule on implementing s. 404 of the Sarbanes-Oxley Act, make it clear that two
questions must be answered before a conclusion can be made about the effectiveness of internal
control.
1. Have any outcomes occurred which indicate that internal control has been ineffective?
2. Is the internal control process robust enough to give reasonable assurance of the
achievement of management’s objectives?
ISSUES FOR INTERNAL CONTROL PROCESSES
Objectives of Internal Control Processes
To provide reasonable assurance of:
(a) The reliability and integrity of financial and operational information.
(b) The effectiveness and efficiency of operations.
(c) The safeguarding of assets.
(d) Compliance with laws, regulations, policies and contracts.

1 Key Issues
1.1 Is a control framework applied to the design and assessment of internal control within the
organization?
1.2 Have there been significant errors and/or losses due to control weaknesses that have not
been corrected?
1.3 Over time, are all significant business processes reviewed for their control effectiveness?
1.4 Does management understand that they are responsible for the effectiveness of internal
control?
1.5 Does the audit committee of the board report to the board the committee’s overall opinion
of the effectiveness of internal control?
1.6 Is the chief audit executive required to report to the audit committee, or to the board,
internal audit’s overall opinion of the effectiveness of internal control?
1.7 Are key processes documented, highlighting their key controls; and is the design adequacy of
these key controls evaluated?
1.8 Is there a satisfactory program for testing the operation of key controls, executed by
management and by internal audit?
1.9 What is the level of risk that management may override controls, and if this were to occur
would it be reported to an independent level?
2 Detailed Issues
2.1 Does the control framework used measure up to COSO, CoCo or Turnbull?
2.2 When necessary, is the internal control of outsourced processes within the scope of the
organization’s design and assessment of internal control
2.3 Are management and staff trained to understand the meaning of internal control and how it
is achieved?
2.4 Is there evidence that controls are dysfunctional in that they are hampering the
achievement of objectives?
2.5 Is internal control achieved in a cost-effective way?
2.6 Is there over-control through unnecessarily costly control processes, or through duplicate
controls?
2.7 Is line management required to regularly assess, and certify to, the control effectiveness of
their areas of responsibility?
2.8 When the chief audit executive believes that senior management has accepted a level of
residual risk that may be unacceptable to the organization, and has not resolved the matter
through discussion, does the chief audit executive report the matter to the board, or to the
audit committee, for resolution?
2.9 Does a lack of effective internal control create a moral hazard for management, staff,
contractors, customers, suppliers or other parties?
2.10 Would errors, fraud or other avoidable losses be detected?
2.11 Is responsibility for the prevention, detection and investigation of fraud clearly assigned
within the job descriptions of appropriate staff?

You might also like