Internal Control Concepts and Frameworks
Internal Control Concepts and Frameworks
5.1 Introduction
According to the definition of internal auditing, one of the main areas that internal auditors
should focus their efforts on is internal control. Before internal control and what it entails
within an organisation can be discussed, it is important to understand that control is part
of everyday life. When a person buys something, pays cash for it and
receives change, the checking of whether it is the correct amount is referred to as control.
When a house has burglar bars and a security system, the protection of assets is referred
to as control. When a refrigerator has a thermostat, the regulation of the temperature is
referred to as control.
Control within an organisation has a similar function and objectives as the controls that
are part of everyday life. In this chapter, the principles of internal control, the parties
responsible for the implementation and monitoring thereof, the advantages and
limitations, as well as internal control in an information technology (IT) environment are
introduced. Specifically, the role and responsibility of internal auditing with regard to
internal control will be explained.
Monitoring
Control activities
Risk assessment
Control environment
Management can execute the above principles by using different approaches, referring
to the philosophy it supports and the style in which it operates. Management’s philosophy
and operating style is covered in more detail chapter 2 that deals specifically with
management and leadership.
Grouping of activities
Perhaps the most important decision that must be made in developing organisational
arrangements is the way in which, and to what extent, the activities should be grouped.
The major approaches normally used in practice are a division into functional, product or
geographical segments. In the functional approach (the most commonly used), the
organisation is structured along the lines of the major functions such as production,
marketing, personnel, and finance. The benefits exist in the specialised concentration of
authority that flows down through the various organisational levels. The disadvantages
are that key decisions must be co-ordinated and made at the top, restricting the possibility
of more urgently needed response at field levels.
The internal auditor should evaluate the organisational structure in order to ensure that
the necessary information does, in fact, reach the personnel concerned, as this
information flow will directly affect the decision-making process.
l Personnel scheduling
Regular scheduling of personnel in respect of tasks should take place. In the same way,
the assignment of personnel’s tasks and duties should take the annual leave of personnel
into consideration.
Corrective controls
These controls take over when improper outcomes occur and are detected. All the
detective controls are worthless if the identified deficiency remains uncorrected or is
permitted to recur. Management must develop structures that keep the spotlight on an
undesirable condition until it is corrected and, where appropriate, must set up procedures
to prevent recurrence. Documentation and reporting structures keep problems under
management surveillance until they have been solved or the defect corrected. Corrective
controls thus close the loop that starts with prevention and passes through detection to
correction.
Deterrent controls
These controls aim to deter people from doing wrong. It could be a warning that a person
found shoplifting or trespassing will be prosecuted, CCTV cameras that monitor
movement and actions or a security guard that check a till slip to purchases when a
customer leaves the store. These controls tend to be easy and cost effective and plays
an important role in protecting information assets.
Segregation of duties
The principal purpose of segregation of duties is to reduce the opportunities for an
individual to make and then conceal errors or irregularities while performing a task. To
achieve this, no individual should be responsible for more than one of the following:
• authorising the transactions;
• recording the transaction; and
• executing the transaction or having custody of assets.
In an IT environment, there are other major functions that need to be segregated, but this
is dealt with in more detail later.
When duties are properly segregated, at least two personnel members would have to
work together to avoid complying with an established control. This is termed “collusion”.
An individual is less likely to attempt to commit an irregularity if he or she must first obtain
another personnel member’s consent. This is also why a good control environment is
important.
Personnel responsible for recording transactions should not also have the responsibility
for authorising the transactions. The organisation wants to ensure that only valid
authorised transactions take place. If the personnel member responsible for recording
may authorise a transaction, he or she could create and authorise fake transactions, in
order to balance the accounts.
Personnel who have access to or control physical assets should not be able to authorise
transactions. The same person should not be able to authorise a payment to a supplier
and sign the cheque, as the money in the bank is a form of asset.
Segregation of custody of assets from the recording function is needed to prevent the
personnel member from disposing of the asset for personal gain and then adjusting the
records to cover the fraudulent action. For example, if the cashier receives cash and is
responsible for recording the receipt and sales into the cash receipt journal, it becomes
possible for the cashier to take the cash received, adjust the debtors account by recording
some fictitious credit for discount or write-off, pocket the money, and neither the debtor
nor organisation will be any the wiser.
Separation of the execution of the transaction, or of the operational responsibility, from
the record-keeping responsibility, is important to safeguard physical assets. If the
warehouse personnel are also responsible for recording the transaction, there would not
be independent reconciliation between the physical assets and the recorded assets, as
records could be adjusted. If each department was responsible for preparing its own
records and reports, there could be a tendency to bias the results to improve reported
performance. To ensure unbiased information, record-keeping is typically a separate
function.
Reconciliations
This control activity involves the comparison of information from different sources to
establish that the information in both sources are the same. The activity is primarily
aimed at achieving completeness and accuracy. Examples are a reconciliation between
the sub-ledger and the general ledger or between a bank statement and the general
ledger.
Supervision
The act of watching a person or activity and making sure that things are done correctly
and according to rules.
Application controls
Application control activities, which consist of both manual and ICT control activities, are
those control activities that specifically relate to an application or transaction cycle.
Application controls are covered in detail in section 5.5.2.
Control activities are covered further in section 5.5.2 on application controls in this
chapter and in chapters 15 to 19 of the textbook.
5.2.5 Monitoring
The last component, that is, monitoring, addresses the fact that most organisations
function in a changing environment. Internal control structures need to be monitored; a
process that assesses the quality of the structure’s performance over time to make sure
that current risks are identified, and the necessary controls are in place to address them.
Organisational objectives
Risk(s) threatening
achievement of objectives
Control weakness
(Lack of control
activities)
Yes No
Management must ensure that control activities are adequate. Adequacy entails that
management has planned and designed controls in such a manner that reasonable
assurance is provided that risks are managed effectively, and organisational objectives
will be achieved.
It should also be noted that, according to the IIA Standards, if management does not
implement adequate controls, the likelihood of a risk occurring and/or the impact of the
loss resulting from the risk will increase, and management must accept this residual risk
(the risk that still remains after management has implemented internal control activities).
If the chief audit executive believes that senior management has accepted a level of
residual risk that is unacceptable to the organisation, he or she should discuss the matter
with senior management. If the issue is not resolved, the matter should be reported to
the governing body for resolution.
Ensure the reliability of financial reporting and compliance with legislation and
regulations
A system of internal control, no matter how well it has been designed, can only give
reasonable, but not absolute, assurance concerning the attainment of goals.
Certain limitations are inherent to all structures of internal control, such as:
• faulty judgement being applied in the decision-making process;
• ordinary errors being made;
• collusion between two or more persons invalidating the structure of internal control;
• management having the ability to override the structure; and
• the design of a system of internal control being limited by available resources, so
that the advantages arising from the control have to be compared to the cost.
The internal auditor should also consider the possibility of over-controlling. In some in-
stances, the controls recommended are too voluminous, too complex, too generalised,
stereotyped and misleading.
OR Output
Processing
Online data
input
Data
capture
5.5.2.1Data capturing
[Link].1 Definition
Data capturing normally entails a manual action (exceptions do however exist), which
includes the initiation, recommendation, authorisation, review and preparation of
documentation which constitutes the transaction. Data capturing is mainly of importance
in batch systems to ensure reliability and accuracy of data prior to the data being entered
into the computer system. Examples include customers completing an application form,
for example, when opening a new bank account. Normally this is done by completing a
document in pen (filling in the fields on the form for date of birth, identity number,
addresses). All the application forms will have to be entered into a system and converted
into electronic format at a later stage.
However, as mentioned, data capturing does not always have to be the manual
completion of a document. Consider the numerous examples where application forms
can be completed electronically, on-line. Even though there is no paper document, this
still represents data capturing, as the data is captured for the first time and constitutes
the
beginning of a process or transaction where data will make its way through the ICT
system.
[Link].2 Risks
Risks present during data capturing include:
l Omission of valid transactions – A document is not completed and entered at all
or is not fully completed.
l Inaccurate source data – The document, whether manual or electronic is
completed but the date on the document is incorrect, for example, a person enters
his or her date of birth as 07/08/82 where the actual date is 8 July 1982. If no control
is present, the wrong date will end up on the database of the organisation.
l Transaction captured in the wrong accounting period – Because there is a time
delay between capturing data, especially where manual forms are used, and the
subsequent entry and processing of the data on the document by the system,
transactions might be processed and posted in the wrong accounting period,
even though they occurred in an earlier period.
l Incorrect valuation and/or classification – When data is captured for the first
time, the risk of incorrectly valuating or classifying a transaction is very high. Think
of an example where a retailer writes out a manual invoice to a customer and
calculates the total and tax by himself. In addition, the retailer should take into
account discounts (whether bulk or cash) and indicate those on the written invoice.
Any error in calculations or wrong classification of the discount will end up on the
system when the manual invoices are entered and electronically processed at a
later stage.
l Invalid transactions captured – Source documents that should not be used for
capturing information are completed, or customers complete the wrong forms on-
line and submit them.
l Valid transactions are captured twice – This is a high risk where physical source
documents are used. Sometimes a person will complete a form, make a mistake
and start completing a new form, the risk here is that both forms, essentially relating
to a single transaction, are allowed to flow through the process.
l Valid transactions may get lost – A completed manual form may not end up in the
right place or be included in the right batch to follow its intended process. In today’s
on-line environment, ICT often happens that customers complete forms or
documents on-line and press the submit button but breaks in the connection or other
interferences cause the transaction to be lost and never reach its destination where
ICT would have been the source for the next step in the process.
[Link] Risks
l Source data may be incorrect – Incorrect data was not prevented, detected or
corrected during the capturing stage and reached this stage. Unless it is identified
here, it will be submitted for processing.
l Transaction may be omitted during data preparation – As documents are
batched and prepared to be sent to the next stage, some transactions and
documents might be excluded either intentionally or unintentionally.
l Incorrect valuation and/or classification of data may take place during
conversion and coding – The source data is correct but during entry, the wrong
data is keyed in, either intentionally or unintentionally.
l Transactions are converted more than once – This is a common risk both for
manual documents and where the source data was initially captured electronically.
Examples include the same application form at the bank being entered twice or a
form completed by a person on-line being submitted twice.
l Unauthorised transactions are added – A document or transaction that was not
created in the data capturing stage is either entered into the batch for capturing (a
fake document) or a transaction is entered into the system (data entry) that does
not exist in the source data.
• Financial total (or other comprehendible total): Rand value of all the
transactions in the batch (or total hours worked on all clock cards).
• Hash total: The total of the fields that would not normally be added. This
total usually ensures the correct allocation of transactions.
• Sign test – Certain fields can only contain either a positive or a negative value,
for example, quantity received can only be positive.
• Value test – Certain fields always have the same value, for example, cash
discount will always be R0 in a credit sale.
• Alpha test – Certain fields only consist of alphabetical letters, for example,
client name.
• Numeric test – Certain fields always consist of numeric characters, for ex-
ample, quantity, hours worked, identity number.
• Alphanumeric test – Field should consist of both numbers and letters, for
example, address.
• Field size test – A field may only consist of a fixed number of characters, for
example, a field for an identity number will only allow 13 characters to be
entered.
• Limit test – The value of a field may not exceed a predetermined value, for
example, a field for normal hours worked in a payroll system is limited to 40.
• Invalid data combination test – With reference to other fields, the validity of
data is tested, for example, no data could be entered in the overtime field of
a payroll programme unless the normal hours worked field is 40. This test is
also widely used in credit sales programmes to compare the value of a sale to
the field “credit available”.
• Control or check digit – Last digit of a code that verifies the correctness of the
preceding digits. This test is widely used for credit card numbers, account
numbers and identity numbers. Various methods for calculating check digits
exist. An example of one such method follows on the next page.
• Key verification – Duplicate input of data and the comparison of the two sets
of data.
• The computer will recalculate control totals for the batch, based on the
documents entered. This total is compared to the manual total reviewed (or
entered) prior to the start of capturing to ensure the accuracy of data
entered.
Test
Account number entered as 253658 (transposition of the 6 and 3):
2 5 3 6 5 8
× 6 5 4 3 2 1
12 + 25 + 12 + 18 + 10 + 8 = 85
85/11 = 7 (ignore anything after the decimal) and the remainder is 8 (7 × 11 = 77 and the
difference between 77 and 85 is 8 (this should be zero and indicates an invalid account
number).
Entered correctly as 256358:
2 5 6 3 5 8
× 6 5 4 3 2 1
12 + 25 + 24 + 9 + 10 + 8 = 88
88/11 = 8 and the remainder is 0 (8 × 11 = 88 and 88 – 88 = 0).
If the remainder is 0 ICT indicates a valid account number.
5.5.4 Processing
[Link] Definition
Processing is the internal computer function where calculations are effected on data in
accordance with the instructions of the program.
[Link] Risks
l Errors occur as a result of incorrect calculations – As a result of incorrect
processing and reference tables in a computer program, mathematically processing
transactions using this incorrect logic may lead to mistakes. An example will be
where the payroll is processed and the system applies the incorrect tax rate for the
tax deduction or adds certain deductions from the gross amount instead of
subtracting them. There will be a consistency in the error, as computer systems will
apply this programming error to all the payroll transactions processed.
l Errors may result from incorrect processing logic – The flow of processing
might be incorrect. For example, in a payroll system the system is programmed to
first calculate tax and then all other deductions. This will lead to the incorrect tax
amount being deducted, as we first need to process the tax deductible items such
as retirement contributions and medical aid before the tax rate is applied.
l The wrong file may be used in processing – The master file with new unit prices
must be used from 1 January, but the previous file is still used and all sales
transaction are processed at the incorrect price.
l The wrong record may be updated – Debtor number 73211 is used instead of
debtor 732111 and the transaction is incorrectly posted.
l Incorrect table values or factors may be used – Previous year’s tax tables
applied to a payroll program.
l Wrong default values may be used – Interest calculated on all outstanding
accounts, instead of accounts in arrears for more than one month only.
l Wrong version of a program may be used – An updated program with new
functionalities to meet changing business demands is not used when it should have
been implemented and used.
l A transaction may be automatically generated that does not conform to
normal policies – This is generally applicable to enterprise resource planning
(ERP) systems, these will be discussed later in this chapter. The program may
automatically generate orders for certain products, even though inventory is not at
re-order level.
• Dual field input: Data is entered in two separate but related fields (inventory
sold is credited on the sales account and the stock records are adjusted
accordingly – at the end of the day the two accounts are compared).
• Data limit test: Results must be equal or less than a certain value.
5.5.5 Output
[Link] Definition
Output refers to the storing of data after processing took place on one or more storage
media, such as a database, computer readable format (disks), printouts or microfilm.
Nature of Internal Audit Work 5
[Link] Risks
l Output received by users may be inaccurate or incomplete – Although
everything might have been correct to this point, a user might ask for a printout of
certain information that is now on the data files and this printout might be incomplete,
or might be of a previous version of the file.
l Output may be distributed or displayed to unauthorised individuals – The
results of processing may end up in the wrong hands, for example, an unauthorised
person received a printed copy of the final payroll processed for this month and sees
the earning of all the employees in the organisation. In the case of electronic access,
an unauthorised person obtains access to the classified pricing information in the
supplier file on the database.
• Transmittal sheets (attached to each printout to identify the report and its
destination).
• Report release forms (user must sign the report release form in
acknowledgement of receipt).
l Workstation display control activities – General control activities regarding
workstation security must ensure only authorised access is granted.
28
Nature of Internal Audit Work 5
• Review the distribution checklist for the timely receipt of printouts and/or
electronic files.
29
Nature of Internal Audit Work 5
new address should appear. The auditor can print out the data to see if ICT reflects
the new address, or choose to access the debtors master file (only if the internal
auditor has such access rights) and verify the change without printing out the file.
l File balances – These can be reviewed for proof of the correct processing of
transactions related to transactions files.
l Accounting reports – These are summaries of accounting transactions that were
processed and posted on the system for a specified period, or for specific types of
accounting transactions, depending on the engagement objective.
l Management reports and reference reports – These are reports that provide
summarised information on events and transactions for certain periods. Examples
might include the quantity of a specific product sold in the last month, the revenue
from those sales, and a breakdown of the locations where the sales occurred.l
Error reports – These are reports of definite errors, in other words, transactions
that were not processed. A payroll transaction that was presented for processing,
but no such employee was found on the employee master file, would end up on the
error report as unprocessed, with a code for the reason why the system rejected the
transaction.
l Exception reports – These are reports on abnormal or unexpected results after
processing. The internal auditor should review the exception report as this is usually
a very convenient summary of high risk transactions. Exception and error reports
were discussed earlier in this chapter.
[Link] Risks
To explain the risk in on-line entry, let us use the example of a customer placing an order
telephonically with a call centre agent, who enters and submits the order details
immediately for processing:
l Transactions are not entered – The detail of the order transaction is not entered
into the system as the order is placed.
l Data entered into the workstation is inaccurate – The customer provides his or
her account number to the agent, but the agent enters the account number
incorrectly by transposing two numbers in the account or enters the quantity of the
order as 03 when ICT should be 30.
30
Nature of Internal Audit Work 5
l Transaction entered in the wrong accounting period – The customer would like
to place an order for delivery next month, but the agent processes the transaction
immediately.
l Data entered at a workstation may be incorrectly valued or classified – The
wrong inventory codes are entered for products ordered or the wrong price is
entered.
l Invalid transactions are entered – The customer never places the order, but the
agent enters an order to meet sales targets for the month.
l Transactions are entered twice – After the data provided by the customer is
entered, the sales agent unintentionally hits the submit button twice and the order
is immediately processed twice by the system.
l Data entered at a workstation may be changed or lost during transfer – The
order never reaches the processing stage as a result of a disruption in the transfer
process, or the data is intercepted and changed – this risk is especially high in
today’s Internet environment.
• Computer dialogue, where the system asks you to confirm, and gives
messages as to what is expected of you.
31
Nature of Internal Audit Work 5
l Verifying data – Match data entered with existing data on file (inventory code
entered is compared to inventory codes on the inventory master file and the quantity
on hand is checked).
l Data approval test – Programmed approval by the system of a credit sales
transaction after comparing the value of the transaction to the available credit
balance.
32
Nature of Internal Audit Work 5
l Except for changes in balances that occur automatically through changes in the
transaction files, all other information should be subjected to the completion of a
request document for changes. This is sometimes referred to as master file
amendment form. Thus all changes should be recorded on a document first.
l Amendment forms should be authorised and signed before changes are affected to
the master file.
l Once these changes have been made to the master file, and independent person
should compare the document with the new information on the master file to ensure
the changes was made correctly.
l Logs of changes to master file information should frequently be reviewed to ensure
only valid changes were made to the master file.
Revisiting our bank account example, think of the process that needs to be followed to
change your address with the bank. As this is a master file change you will not be able
to change your address at an ATM or via Internet banking (which is used for trans-
actional purposes and only affect transaction files). You will have to physically visit a
branch, provide proof of identity and proof of the new address in document format, you
will also be requested to complete a form and duly sign the form. The form will also be
signed and stamped by a bank employee before being submitted to an authorised
person who will make the change on your master file. All these documents will also be
kept on file by the bank as evidence of the validity of the change made.
5.7 Reporting
The internal audit activity performs assurance reviews on the governance, risk
management and control processes within the organisation and issues a report of the
result of its assurance reviews. The Chief Audit Executive is responsible for issuing the
report to the stakeholders. Stakeholders that have an interest in the internal audit report
are:
33
Nature of Internal Audit Work 5
governing body to provide oversight as needed to direct management in addressing
areas of concern and ensure continuous improvement.
Senior management
The recommendations made by internal audit assists senior management in
improving the control environment within the organisation to meet the objectives
related to governance, risk management and control.
Operational management
The recommendations made by internal audit assists operational management in
improving effectiveness and efficiency of operational processes and systems
(including control activities) within the organisation.
External audit
Results of internal audit reports assist external audit with their risk assessment and
planning of the financial audit. To ensure proper audit coverage and to minimise a
duplication of efforts, external audit is encouraged to consider the work of internal
audit.
5.8 Summary
It is management’s responsibility to design and implement an appropriate internal control
structure by using an internal control framework, such as COSO, to provide reasonable
assurance that the organisation’s risks are mitigated, and objectives are met. Control
weaknesses and/or non-adherence to current internal controls must be brought to
management’s attention and internal auditors should make appropriate recom-
mendations for improvement.
34
Nature of Internal Audit Work 5
Annexure 1 – The ABC of controls
Type Description Example
a F Accounting Integrity and accuracy of the accounting Bank reconciliation
system and all financial reports being
generated.
b F Administrative Operations without any direct link to Review of production
accounting controls. report
c F Operational Dictate the manner in which various Organisational chart
activities are performed and affairs are
conducted.
d F Compliance Ensuring that policies, procedures, laws, Segregation of duties
rules and regulations are followed.
e F Legal Ensuring the organisation is operating Document disciplinary
within the boundaries of legislation and action
other government regulations.
f T Input Provide reasonable assurance that data Print out of access
received by the computer has been denied
authorised, etc.
g T Process Provide reasonable assurance that data File labels
processed by the computer has been
classified correctly.
h T Output Final check on accuracy of results of Reconciliation of input
computer process. and output
i O Directive Designed to produce positive results. Training of personnel
j O Preventive Prevent errors from occurring. Fire drill
k O Detective Detect errors after occurring. Fire alarm
l O Adaptive Can be adapted to various situations. Thermostat
m O Corrective Corrects problems identified by detective Fire extinguisher
controls.
n C Documentary Recording in writing the various activities Procedure manual
of the organisation.
o C Physical Things that can be seen and touched to Fence
prevent unfavourable activities from
occurring.
p C Manual Performed by people. Count of inventory
q C IT Security of data through a computer Encryption of message
system.
continued
35
Nature of Internal Audit Work 5
Type Description Example
r OT Dysfunctional Control working properly as planned, but does Sensitive data in safe with
not accomplish what it was designed to key on desk
accomplish.
s OT Redundant Two or more controls accomplishing the same Show ID and use password
objective.
t OT Non-functional Control not operating properly. Door with broken lock
u OT Post-activity Eliminating the deviation in future cycles of the Quality check
process.
v OT Pre-activity Preventing the deviation in the cycle of the Using seat belt
process.
w OT Absent Lack of control in an area where One person performs all
error/irregularity could be prevented, corrected accounting functions
or detected.
x OT Safety Promoting safety of individuals and property. First-aid kit
y OT Environment Promoting the preservation of the environment Disposal of waste
in which the organisation operates.
z OT Limit Prohibits a significant deviation from occurring in Number of people allowed
a process or system. in elevator limited to 12
F = Functional, T = Time-frame, O = Objective, C = Classification and OT = Other
36
Preventative control activities enhance accuracy and reliability by establishing guidelines and checks that prevent errors during data entry. For example, batch control activities calculate totals and document counts to ensure all transactions are accounted for. Input validation tests check for data accuracy as it is entered, while user procedure manuals ensure consistent data capturing processes. Features like drop-down menus limit options to prevent entry errors, and review of input data ensures completeness before processing .
Risks associated with data capturing include omission of valid transactions, inaccurate source data, transactions captured in the wrong period, incorrect valuation or classification, capturing invalid transactions, and duplicate entries . Control activities to mitigate these risks include the implementation of user procedure manuals to ensure consistent capturing, batch control activities to verify document counts and totals, transmission documents to maintain accountability, and input validation tests to ensure accuracy and completeness of data entered into the system .
Management is responsible for designing the internal control structure and implementing internal control activities to achieve its objectives and meet organisational goals . The external auditor evaluates and tests accounting structures, related internal control structures, and financial control activities to achieve audit-related objectives and express an opinion on financial statements . The internal auditor assesses the adequacy and effectiveness of internal control activities to achieve engagement objectives and ensure controls are mitigating risks effectively. The internal audit activity should assist management in maintaining effective controls by evaluating their efficiency and promoting continuous improvement .
Internal auditing identifies control weaknesses by evaluating the effectiveness and efficiency of existing controls through risk assessments and adequacy evaluations. Upon identifying weaknesses, the internal auditor provides findings and recommendations that are both effective and efficient for addressing the problems. These findings are reported to senior management and the governing body, influencing governance by promoting control improvements and policy changes . Internal auditors should also be continuously attentive and provide recommendations to enhance the internal control structure .
Continuous monitoring is essential because organisations operate in dynamic environments that constantly change, presenting new risks and challenges. Monitoring ensures that internal control systems remain effective over time by assessing the quality of current controls and adjusting them to address emerging risks . It should be implemented through regular evaluations of the internal control structures to provide reasonable assurance of their effectiveness and efficiency. Additionally, it involves reviewing controls across various programs or operations to align them with the organisation's goals and objectives and adapting to changes as necessary .
An internal control system helps an organisation achieve profitability and operational goals, prevents resource losses, ensures reliable financial reporting, and supports compliance with laws and regulations. It also protects the organisation's reputation by preventing surprises and threats that could lead to adverse outcomes .
Effective communication ensures that all personnel understand their roles in the internal control structure and how their activities relate to others. This includes a clear message from senior management about the importance of control responsibilities, which fosters a unified approach to risk management . Consequently, communication serves as a catalyst for enabling individuals to fulfill their responsibilities effectively, thereby enhancing the overall effectiveness of internal controls.
Internal controls cannot ensure an organisation's success or the absolute reliability of financial reporting. While they can assist in achieving profitability goals and preventing losses, external factors such as government policy and economic conditions are beyond their control. Internal controls can identify weaknesses, but cannot force a change in management's behavior. Additionally, inherent limitations like human error and management override can affect the reliability of financial reporting .
Internal auditors effectively communicate findings by preparing detailed reports on control weaknesses, including analyses of the impact and risk of such weaknesses. They provide actionable recommendations for improvement, prioritizing the most critical issues. Communication with senior management and the governing body is key, ensuring that issues are understood and incorporated into strategies for improvement. Continuous dialogue helps resolve issues proactively and bolsters confidence in the organisation's governance systems .
The internal auditor plays a crucial role in supporting the Chief Audit Executive and the audit committee by providing assessments on the adequacy and effectiveness of internal controls. They ensure a reasonable evaluation of the control environment based on their findings, which informs governance decisions. The Chief Audit Executive is expected to deliver an annual report on the state of internal controls, using insights from internal audits as a foundation for analysis and recommendations concerning governance issues .