0% found this document useful (0 votes)
35 views123 pages

COSO Internal Control Framework Checklist

This document presents a guide for evaluating internal control based on the components of the COSO Integrated Framework for Internal Control. The guide includes instructions for evaluating each of the five components of internal control (control environment, risk assessment, control activities, information and communication, and monitoring) at the company and process level. Additionally, it provides summary tables of the evaluation results and a general conclusion about the adequacy of the organization's internal control.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
35 views123 pages

COSO Internal Control Framework Checklist

This document presents a guide for evaluating internal control based on the components of the COSO Integrated Framework for Internal Control. The guide includes instructions for evaluating each of the five components of internal control (control environment, risk assessment, control activities, information and communication, and monitoring) at the company and process level. Additionally, it provides summary tables of the evaluation results and a general conclusion about the adequacy of the organization's internal control.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

SUMMARY GUIDE CHECKLIST OF

INTRODUCTION

COSO publishes the update of the Integrated Internal Control Framework whose objectives are: to clarify the requirements
de la aplicación del control interno a muchos cambios en las empresas y ambientes operatvos, y ampliar su
issuing reports. This new Integrated Framework allows for greater coverage of the risks to which one is

OBJECTIVE

Evaluate and document the internal control of the organization, from the financial perspective, to identify r
of auditing.

INSTRUCTIONS FOR USE

1. Enter each of the tabs displayed at the bottom

2. Complete each of the criteria in the table

3. At the bottom you will find a table that summarizes each component and each assigned response.
Additionally, a data consolidation table is presented to conclude.
4. According to the previous criteria, you will find a diagnosis of the evaluated component.

RESUMEN DE LOS RESULTADOS OBTENIDOS - Nivel Empr

Component % Ref.
Control environment 1% BC-01
Risk assessment 3% BC-02
Control activities 2% BC-03
Information and communication 2% BC-04
Follow-up and monitoring 6% BC-05

COMPANY LEVEL

6%

5%

4%

3%

2%

1%

0%
Environment of con- Evaluation of the Activities of Information and Follow-up and
troll risk control communication monitoring

SUMMARY OF THE RESULTS OBTAINED - Process Level

Component % Ref.
Control environment 1% BC-01
Risk assessment 5% BC-02
Control activities 5% BC-03
Information and communication 4% BC-04
Follow-up and monitoring 11% BC-05

LEVEL PROCESS

6%

5%

4%

3%

2%
1%

0%
Environment of with- Evaluationof Activities of Information and Follow-up and
risk control control communication monitoring

CONCLUSION

The components of the company's internal control are appropriate: YES

According to the procedures and evidence obtained, it was determined that the control components
preliminary strategy to assess the trust of the controls, identify the activities that mitigate the risks
design of control, implementation and operational effectiveness to obtain it
AND THIS

internal control deficiencies, update the context


an application when expanding the operational and objectives
currently facing organizations.

important risks during the development of the assignment

about design effectiveness and operational effectiveness,

journey
that
the internal ones are appropriate and a must be established a
risks of material error, it should also assess the
security of this.
CONTROL ENVIRONMENT PRINCIPLES (COSO)

Entity: Reference of P/T:

Period Ended: BC-01

OBJECTIVE

Evaluate and document the internal control of the organization from the financial perspective to identify significant risks during the development of the audit engagement.

SCOPE

The stated activities do not intend to cover all situations. It is necessary to conduct an analysis and determine the developed activity according to the nature of the business and the requirements of COSO.

Principle 1: The organization demonstrates commitment to integrity and ethical values.

Summary of controls
Effectiveness of the design, Operational effectiveness
No. Requirement (total compliance, partial, no) Summary of evidence (total compliance, partial, none
Company level Process level of control
fulfilled) fulfilled)

Does top management reflect their commitment through their example?


1.1. in compliance with the standards of conduct YES YES
established?

Has the senior management defined and disclosed the standards?


1.2 expected behavior for the organization, for which YES
Have you defined a communication strategy?

Do the standards of conduct include expectations?


1.3 legal and ethical issues associated with the Financial Report and
business?

Have the conduct standards been included in the


1.4
Code of Ethics of the organization?

The conduct standards allow for the


collaborators can identify behaviors and
1.5 actions that go against them, and therefore
they may have criteria to question its application and/or
report anomalous situations.

Defined levels responsible for attending


1.6 the collaborators' questions regarding the application
of the standards.
Does the communication strategy ensure that everyone
levels of the organization know the consequences
1.7
what can bring the deviation and/or non-compliance of
the established standards of conduct?

Is there an induction and training plan available?


continue, both for new collaborators and
1.8
ancient about the expected standards of conduct and
the Code of Ethics?

Does the organization develop performance evaluations?


1.9 that allow for tracking behavior
of the collaborators in achieving the objectives?

There is an incentive plan that promotes


both good behavior and the report of
1.10
actions that go against the expected behavior,
in front of achieving the objectives.

Do the controls designed in the organization contribute


1.11 in compliance with the standards of conduct
expected?

Top management timely executes the


relevant investigations regarding any alleged
1.12
inconsistency with the standards of conduct of the
entdad.

Any deviation from the standards of conduct


1.13 confirmed generates an immediate corrective action?

Suppliers are evaluated before their affiliation.


1.14 validating your good name and ethical behavior in
the market.

In the evaluation of suppliers, the following are considered


deviations of performance indicators and
internal analytical reviews of the information
1.15
operational and financial, which can be an indicator
potential for fraudulent financial reporting or bad
behaviors.

Are the results of the evaluations considered?


continuous and independent of internal control, for
1.16
evaluate both collaborators, suppliers, and
partners?
The organization considers and analyzes the facts,
1.17 trends in reporting lines and aids that may
indicate frauds or unethical aspects.

The organization requests feedback from the


meetings held with the suppliers of
1.18 external services and partners when obtained
information that affects internal control over the
financial report of the entity.

The investigations carried out regarding behaviors


1.19 questions are carried out by independent personnel
to the area and/or to the organization, as required.

The investigations carried out regarding the deviations,


1.20
are prioritized.

In the face of deviations from conduct standards


presented, the organization considers carrying out:

Investigation of the facts of possible violations


to ensure an understanding of the events and the
circumstances.

When appropriate, assess the impact of the


financial statements and determine internal controls
about the external financial report that they could have
failed in the detection and prevention of the events.

• Develop the documentation and reports for the


appropriate support for fraudulent, illegal acts, or
no issues that could be presented

Identification and communication with all those who are


under investigation and monitoring of any action
Corrective action taken to remedy the consistent facts.
and promptly in accordance with the guidelines
company prescriptions.
1.21

• Restricted access to information regarding


to the allegation of the authorized persons to handle
the investigation.

Inform the board of the deviations in the application


of the standards and any exemption that could
have been granted or is being considered.
Determine how and when the violation will occur.
communicated and whether it will be made public.

Communicate to all company personnel


that an investigation and appropriate corrective actions
have been carried out.

Depending on the nature and influence of


the deviation that has occurred, establish actions
necessary corrections to make corrections
retrospectives and future improvements.

Is there a code of code in which it is determined


aspects of acceptable business practices, the
1.22
conflicts of interest and standards of behavior
etco?

Collaborators are informed about the existence of


1.23 a code or ethical behavior standards
moment of your hiring

Principle 2: The board of directors demonstrates independence from management and oversees the performance of the internal control system.

Summary of controls
Effectiveness of the design, Operational effectiveness
Evidence summary
No. Requirement (total compliance, partial, none) (total compliance, partial, none
Company level Process level fulfilled) of control fulfilled)

Is the effectiveness of the control supervision carried out?


internal of the external financial report, including the
2.1
risk assessment, significant deficiencies and the
material weaknesses, if any?

Is the administration evaluation carried out?


any significant fact, considering the impact
2.2
potential in the financial report and the need for
corrective actions?

The establishment of formal communication with the


2.3 management of the internal audit function is
effective in facilitating the discussion of any situation.

The quality of the financial report and disclosures is


2.4
adequate.
The hiring and payment of external auditors is carried out
2.5
effectively.

2.6 The board of directors and the audit committee oversee the
performance of internal control administration?

The board reviews and approves policies and practices


that support the performance of internal control through
2.7
of the business in regular meetings between the
administration and the board.

The audit committee complies with:

Appropriate forums that enable the board of directors to


ask investigative questions about administration.

A calendar that establishes the times and the


frequency of meetings with the administration.

Expected practices to maintain the board of directors


updated on the emerging standards that are
adopted, and their impact on the financial statements of the
entdad.

2.8 Procedures for reviewing the development of the


management and performance of internal control over
the external financial report.

Authority to engage the necessary experts


and the supervision to ensure that the administration
appropriately resolve the facts presented by the
board of directors.

Criteria and procedures for calling


special or urgent meetings/encounters whenever necessary
necessary.

Assignment of the tempo in the board meetings


Direct for discussions with external advisors,
internal and external auditors and legal advisors, without the
presence of the administration.
The board periodically evaluates and confirms its
2.9 collective ability to provide supervision
effective?

Through independent reviews and


self-assessments, does the board determine what is appropriate of
2.10
its composition has enough members
independent and with the appropriate experience?

To meet the financial reporting objectives


external to the entity, the board of directors identifies
2.11 independent candidates from the administration and the
Entity, and has experience in financial reporting
necessary.

The procedures that ensure the potential of the


the members of the board are:

Key risk assessment faced by the


organization and appropriate definition of the profile of the
members of the board of directors.

Develop history reviews and obtain


independent references.

•Review current affiliations and advisors for


ensuring independence with the administration and the
enough.

Consideration of experience and skills, which go


from the financial necessary knowledge to the
regulations and other technical knowledge for
understand the situations that may affect the report
external financing of the entity.

2.12
Validation of credentials and certifications
presented demonstrating the level of competence
achieved.

• Review of financial information and others


relations with the company, its external auditors or
administration.

Use an independent nominating committee or


a search firm to oversee the
due diligence procedures.
Periodic evaluation of due diligence procedures
due diligence used for the identification of possible
directors, including the review of all the
certificates, determining if they are complete,
updated, and comply with the guidelines of the
entity and the rules of independence.

The Board of Directors demonstrates an adequate level of


skepticism of the judgments and statements of the
2.13
administration, that may affect the report
financial, through test questions?

The audit committee is particularly requesting clarifications.


justifications of the company's processes through
de:

Selection and implementation of accounting policies.

Determination of critical accounting estimates.


2.14

• Make key assumptions used in the


application of technical, accounting, and reporting matters.

Assessment of other risks faced by the


organization with a potential impact on the report
financial.

The audit committee meets regularly with


internal and external auditors, and reviewers
independents to review and discuss topics such as:

Key risks faced by the organization.


Scope of the audit and test plans.
Bases to define materiality.
Changes in accounting policies.
2.15
Assumptions in models and calculations.
Resources and staff.
Organization and culture.
Assessment of Internal Control Management
about the External Financial Report.
Significant audit results.
• Quality and reliability of the financial report and
revelations.
The audit committee considers the information
obtained from the company's complaints and programs
antifraud, to monitor the risks of errors in the
2.16
financial report, and includes within the risks acts
inappropriate actions of the staff and the administration in the
omission of controls.

The audit committee reviews any complaint and


evaluate the management's analysis on any
2.17
fact, its possible impact on the financial report and the
corrective actions to take.

Financial objectives are established by


2.18 management with realistic and coherent expectations for the
operational personnel

Principle 3: Management establishes, with the supervision of the board, the appropriate structures, reporting lines, and levels of authority and responsibility for the achievement of objectives.

Summary of controls
Effectiveness of the design, Operational effectiveness
No. Requirement (total compliance, partial, no Summary evidence total compliance, partial, no
Company level Process level of control
fulfilled) fulfilled)

Top Management defines the organizational charts for


document, communicate and enforce with the
3.1
responsibility oriented towards the objectives of
financial report of the entity.

The established organizational chart in the organization has


as an objective:

Present the duties of authority and responsibility.


Ensure that the responsibilities are
adequately segregated.
3.2 • Establish reporting lines and channels of
communication.
Define the different reporting dimensions
important for the organization.
• Identify the dependencies for the roles and
responsibilities included in the financial report as such
as the ones responsible for the third parties.

The Board of Directors asserts its supervisory authority


3.3 for the financial report on Senior Management to
through its regulations.
The administration considers the impact on the environment
of control and the importance of effectiveness of the
3.4
segregation of duties, when they are established
authorities and responsibilities.

The established policies define the levels in cascade.


3.5 of authority, reviews, and checks to authorize
accounting transactions, as well as the report of the
financial results.

The assigned responsibility and authority is limited for


3.6 balance the need for compliance with the
objectives and the risks that may lead to actions and
inappropriate behaviors.

According to the delegated levels of authority, the


administration maintains the job descriptions
3.7
to outline the responsibilities of the report
financial, and update them when necessary.

The administration provides sufficient guidance and


direction to ensure that employees understand and
recognize your responsibility for internal control and
3.8
the importance of properly applying due diligence and
business trial when they carry out their
responsibilities and functions.

The Board of Directors reviews the descriptions made.


by the administration, related to the positions
3.9 financial report key and consider how these
they can strengthen internal control over reporting
external financial?

For external service providers, there


they establish their responsibilities through agreements
3.10 such as time specifications and quality of reports
generated financials.

The Board of Directors delegates to the Audit Committee its


role of the supervisor in front of the Audit Function
3.11 Internal, ensuring that the internal audit plan
provides adequate security in suitability
of the coverage of key risk areas.

Principle 4: The organization demonstrates commitment to attracting, developing, and retaining competent professionals, in alignment with the organization's objectives.

Summary of controls
Efectvidad del diseño, Efectvidad operatva
Effectiveness of the design, Operational effectiveness
Summary evidence
No. Requirement (total compliance, partial, none) (total compliance, partial, none)
Company level Process level fulfilled) of control fulfilled

The audit committee reviews and approves the


competency requirements for all people
that play a key role in financial reporting
4.1 and of internal audit. The requirements are from
in accordance with the relevant laws and regulations and the
necessary experience to apply the policies and
practices of the entity related to the report
external finance.

Does the description of the positions contain all the


expectations regarding knowledge, skills,
4.2 experience, necessary titles to carry out
effectively the responsibilities in each position of
work?

The human resources department periodically updates


the company's policies and procedures for
4.3
attract, train, evaluate, and retain personnel
suitable?

The policies and practices that represent the standards


of the entity's competence for the positions in the
financial reports are used as a basis for the
human resources activities and compliance of
the employees, taking into account:

Selection and interviews of candidates.


Review of references and experience.
4.4
Hiring, retention, promotion, and termination of
contracts.
Development of training and education plans.
Establish expectations in certification.
Conducting final interviews to reveal
any important matter related to control
internal on the external financial report of the
entdad.

The identification and implementation of training


related to financial reports, are designed to
4.5 acuerdo a los parámetros de regulación, estándares
emerging from accounting and reporting, and within the
company in areas that require improvement.

Trainings are prioritized as needed.


4.6 in response to both internal and
externals of the organization.
Does the administration identify the skills and
necessary experience to support the objectives of
4.7 external financial report of the entity, for which
evaluate personal site with experience and
capabilities or hire third parties?

The hiring of third parties is determined by


4.8 share your experience and skills, as well as the
policies and standards of the organization?

Contracts entered into with third parties include all the


requirements related to experience, skills and
4.9 knowledge, as well as establishes the foundations for evaluation
periodically the commitment and competence of its
services.

For the standards of competence and behavior


expected, the administration communicates the expectations
through policies and practices, and evaluates adherence
from the employees to these through:

• Development of incentives and compensations that


they consider the multiple dimensions of behavior and
performance.

Reinforcement of the expectations of the continuous


demonstration and strengthening of levels of
expected competencies.

• Ensure that individual and team goals are set.


defined in support of achieving the objectives of
the entity uses observable metrics, and they are
communicated to each employee.

Development of an evaluation process


performance that confirms the employee's knowledge
of their progress in relation to the goals,
4.10 and its status within the organization.

Conducting regular performance reviews and


employee evaluations in relation to their roles
assigned to confirm that the skills of the
employees are suitable for the responsibilities
current position in the organization.
Appropriate decision-making regarding promotions
the termination of contracts based on the results
of employee performance evaluations.

Change in performance evaluation processes,


as necessary, based on the lessons
learned or changes in the strategy and objectives
operatives of the organization.

• Continuously support and promote the


behavior consistent with the standards of
competition and discourage behaviors
inappropriate.

Does the board of directors use the competency standards?


and expected behavior, to evaluate the
individual competencies of the relevant positions
4.11 in the financial report as the chief executive officer,
financial director and
the executive director of auditing?

Does the senior management evaluate the capability of the staff that
registers and reports the information, designs and develops the
4.12
financial reporting systems that include technologies
of information?

Identification and development of alternative candidates


for key financial reporting positions, for which
4.13 The administration defines succession plans to facilitate
any future transaction and risk mitigation of
non-compliance with financial reporting objectives.

The board of directors supervises the succession plan, to


ensure that the administration has evaluated and
4.14
properly managed the risks associated with it
plan?

Principle 5: The organization defines the responsibilities of individuals at the internal control level for the achievement of objectives.

Summary of controls
Effectiveness of the design, Operational effectiveness
No. Requirement (total compliance, partial, no Summary of evidence (total fulfillment, partial, no)
Company level Process level of control
fulfilled) fulfilled)

The administration develops the descriptions of several


job positions to reinforce their responsibility for
5.1
carry out internal control over the report
external finance.
The board of directors and senior management maintain a
5.2 philosopher and a working style that demonstrates a great
commitment to ethics, integrity, and competence.

Periodically, the executive director and the director


financial, they are responsible for internal control, for
5.3
which they request from the staff within the entity
confirmation of the responsibility for your actions.

Top management defines performance measures,


incentives and compensations, which must be:

Aligned with the ethical values of the entity.

Developed at all levels of the entity, that the


administration is necessary to support and
5.4 ensure responsibility towards the achievement of the
short-term and long-term objectives of the entity.
• Balanced to induce financial and non-financial measures
financial.

Incorporated into the hiring structures,


evaluation and promotion of the entity.

The board of directors and the management evaluate


periodically the appropriateness of the measures of
performance used to determine sitenen a
expected influence on how the staff responds to the
pressure, incentives, and compensations. This evaluation
can include:

Reevaluation of the relevance of the measures


performance considering industry trends,
regulatory changes, or changes in the objectives of the
entdad.

Consideration of past financial errors,


ethical violations, and instances of non-compliance, and if
the established measures could have caused
5.5 excessive pressures to overcome the controls.

Commit the external parties to carry out


market comparisons and interviewing employees.
Monitor the changing sources of threats that
they exert pressure to avoid the established controls or
take shortcuts.

Consider whether the selection of accounting policies has


sido exageradamente influenciadas por las medidas de
established performance.

Use of assessments to make changes to the


performance measures and associated structures of
hiring, evaluation and promotion.

The board of directors supervises the periodic evaluations


to ensure that they have been completed and are aligned
5.6 to the objects of the entity and in this way to approve them
compensation plans?

5.7 The administration designs evaluation systems and


compensation for employees who
5.7
they provide compensations periodically to
personal or disciplinary actions, as the case may be.

Effectiveness of the component design Efectvidad operatva del componente de


Summary of control environment control activities control activities

In summary, are the established processes sufficient to meet the


five principles of the control environment identified and to facilitate achievement
of the organization's objectives related to information
financial?

Summarize the arguments that support this conclusion, along with the actions.
that the company will undertake to improve the quality of internal control
about financial information.

Results Consolidation - Control Environment Company Level Process Level Design Effectiveness Operational Effectiveness

Commitment to Integrity and Ethical Values 3% 6% Partial Compliance #REF!

2. Independence of direction and supervision of


0% 0% Partial Compliance #REF!
performance

3. Achievement of the objectives 0% 0% Partial Compliance #REF!


4. Commitment to develop Professionals 0% 0% Partial Compliance #REF!
competent

5. Definition of responsibilities 0% 0% Partial Compliance #REF!

Average 1% 1%

DIAGNOSIS

According to the evaluation of the Control Environment Checklist, the company has deficiencies in the implementation of internal control regarding these principles, which is why it is recommended to address the risk matrix and
include the risks and the appropriate measures to try to mitigate them

Prepared by:

Final Comments and Observations:

Company REVIEWED by:

Company SUPERVISED by:

Approved by:
PRINCIPLES OF

Entity:

Period Ended:

Evaluar y documentar el control interno de la organización, desde la perspectva financiera, para iden

The stated activities do not aim to cover all situations. It is necessary for a

Principle 6: The organization defines the objectives with surface

Summary of
No. Requirement
Company level

Does the management determine the related objectives?


to the preparation of the financial statements, including
6.1 revelations, and identify the relevant figures of the YES
financial statements based on commission risk
material and false statements?

Is a periodic review carried out on the plans?


6.2 strategic of the company and these are updated,
Reviewed and approved by the board of directors?

The administration identifies for each account


and revelation, relevant statements, transactions and
6.3
underlying events, and processes that support these
financial statement accounts?

Does the administration specify reporting objectives?


6.4 high-level financial that establish
the basis for all sub-objectives?

The administration documents that the objectives are


specific, measurable, attainable, relevant and timely
6.5 band (smart), as well as it should evaluate if the objectives are
accordance with the principles of accounting according to the
circumstances of the entity.
Does the administration evaluate the materiality of
the relevant accounts, considering factors
qualitative and quantitative?, for which the
administration considers factors such as:

• Who uses financial statements (creditors,


shareholders, suppliers, employees, clients
regulators).
6.6
Size of the elements of the financial statements.

Exclusivity of transactions.

Difficulty in valuing the balance or for


specify the transactions.

Trends.

The administration reviews publications from bodies


professionals, to update themselves on the
6.7
relevant accounting pronouncements for the
business.

Periodically, does the administration present to the committee?


of audit an analysis of the published changes or
6.8
emerging facts that may impact
significantly the financial report?

The administration, with the supervision of the committee of


audit, does it consider the range of activities of the
6.9 entity to evaluate whether all the material activities
they are properly registered in the states
financial?

Is the budget update carried out or


6.10 projections to determine aspects that may
Has it changed over the course of the year?

Principle 7: The organization identifies the risks to achieving its objectives

Summary of
No. Requirement
Company level
Does management include an identification process?
of risks that identify the risk
of material omission and error, and the probability of
7.1
the occurrence of risks in relevant assertions
from the financial statements for each account and disclosure
important?

The administration considers the processes and units of


businesses that support the accounts and revelations of the
financial statements, which include discussions and
meetings with the leaders of each process and unit of
7.2
business, as well as considering the identification of
the information technology systems that support
business processes that are relevant for
the objectives of external financial reporting.

Management identifies the risks for the


compliance with the financial reporting objectives,
7.3 through the consideration of the factors related to
each relevant account of the financial statements and
associated statements.

The process of risk identification and analysis


consider both quantitative factors
as qualitative?, taking into account:

Impact on the accounts of the financial statements:


each account is evaluated in relation to its category and the
management evaluates both qualitative and
quantities to categorize each account as high,
medium or low. According to the impact on the states
financial.

Account characteristics: the administration


consider internal factors such as volume of
transactions, required trial and complexity of the
principles of accounting.

• Characteristics of business processes: the


administration identifies the business processes that
7.4 they generate transactions in each of the accounts of the
financial statements, considering factors such as,
complexity of the processes, centralization and
decentralization, technology systems of the
information, changes in processes, and interactions
with external parts.

Fraud risk: management assesses the risk of


error due to fraud for susceptible accounts.
The administration considers general factors
internal activities of the company,
employee access to assets, quantity and quality
of personnel, provided levels of training,
changes in information systems, and changes
organizational. All these factors are considered
in relation to its effect on the characteristics of the
account, business processes and risk of fraud.

The finance staff meets regularly with:

Information technology personnel for


monitor the changes in technologies that may
affect the risks related to financial reporting.

• Human resources personnel to identify and


7.5 evaluate how the changes in personnel and positions
Work can affect the necessary competencies.
for internal control over the external financial report.

Legal advisors to stay updated with changes


regulatory and legal.

Other members of the entity belonging to areas


relevant according to the administration's criteria.

The administration analyzes the importance of risks


identified based on the probability of the
occurrence of risk and the inherent risk of a
7.6
material omission and error for reporting purposes
external financial of the entity, determining the
risk management at a tolerable level.

The management considers external factors that


can impact the ability to meet the
objectives of financial reporting, such as:

Economic changes.
7.7
Human or natural catastrophes.
New standards.
Changes to laws and regulations.
Changes in customer demands.
Technological developments.
The management considers internal factors that
can impact the ability to comply with
the objectives of financial reporting, such as:

Use of capital source determinations.

Changes in responsibilities of the


7.8 administration.

Considerations for hiring and training


of personal.

Employee access to goods.

Internal changes in information technologies.

The administration considers several responses to the


7.9 risks (rejection, acceptance, reduction, sharing)
when assessing if the risks are reduced to a level
acceptable.

Principle 8: The organization considers the probability

Summary of
No. Requirement
Company level

Does the administration conduct a comprehensive evaluation of


fraud risk to identify the different ways
in which fraud and misconduct can occur?
In this process it is considered:

The degree of estimates and judgments in the report


external financial.

Methodology for the registration and calculation of certain


accounts.

Fraud schemes and scenarios that are common


for the sectors of industry and markets in the
What is the operating entity?
8.1

Geographical regions where the entity develops its


business

Incentives that could motivate behavior


fraudulent.
Nature of automation.
Unusual or complex transactions subject to
influence of relevant management.
Last minute transactions.

Vulnerability of the administration to exceed


controls and possible schemes to ignore the
existing control activities.

Does the management consider how the staff could


overcome the controls aimed at preventing or
detect the fraud?
Considering that the staff of the entity could
intentionally exceed controls of different
ways, such as:

Register fictitious events and transactions.


8.2
Changes in transaction times and dates
legitimate.
Establish or reverse reservations for manipulation
results.

Alteration of records and related terms to


relevant or unusual transactions.

Does the executive director of auditing include the


results of the fraud risk assessment in the
8.3 internal audit plan? Does the director review and confirm
that the internal audit plan is directed towards the
relevant risks?

The board of directors and management review the


compensation programs and evaluation processes
of performance to identify possible incentives and
pressures for the
8.4 employees that motivate them to commit fraud? Is this
review considers how the meetings or
no, the financial report, possible impacts, a
individual evaluation, compensation and continuous employment
among other aspects?

Principle 9: The organization identifies and evaluates the ca

Summary of
No. Requirement
Company level

The administration develops approaches to observe


changes in the external market and evaluate the possible
impact on the entity's operations and report
financial. This process includes the review of:

Websites and social media.


9.1
Website tracking tools.
Newspaper clipping services.
Search engines.
Commercial publications and fairs.
Conferences.
Professional organizations.

In the face of the decision of a new strategy,


the administration conducts a detailed evaluation
9.2 of risks, to consider how changes could
impact the achievement of all objectives to
through the entity.

For the succession process, the administration reviews the


planned changes in management positions
and leadership, the attitudes and values represented by the
9.3 titles to these positions,
through interviews with the staff within
the entity.

The audit committee interrogates candidates for


to know your vision on the importance of control
internal and how the need for a
effective internal control and other pressures for the
performance and cost considerations. Likewise,
9.4
consider attitudes toward risk, tolerance to
risk, internal controls, the history of the candidates
in the maintenance of control and management
effect of pressure for development, within the
profile to identify the ideal candidate.

The company and its integral evaluation is assessed


9.5 environment, considering the possibilities that in a
initially were not considered
Risk assessment summary

In short, are the processes presented sufficient to meet the three


principles of evaluation of identified risks and to facilitate the achievement of the
Company objectives related to financial information?

Summarize the arguments that support this conclusion, along with the actions.
that the company will undertake to improve the quality of internal control over
financial information.

Consolidation of results - Evaluation of Company Level


Risk

6. Define the objectives with sufficient clarity 10%

7. The organization identifies the risks for the


achievement of their objectives 0%

The organization considers the likelihood of fraud. 0%

9. Identify and evaluate the changes 0%

Average 3%

According to the assessment of the Risk Assessment Checklist, the company has deficiencies in the i
and include the risks and the appropriate measures to try to mitigate them

Final Comments and Observations:


AND THE RISK ASSESSMENT (COSO)

P/T reference:

BC-02

PURPOSE

Identify important risks during the development of the audit engagement.

SCOPE

an analysis is conducted and the activity developed is determined according to the nature of the business and continues

my clarity to allow the identification and evaluation of related risks.

and controls
Effectiveness of the design,
Summary of evidence
(total compliance, partial, none
Process level fulfilled) of control

YES

YES
at all levels of the entity and analyzes them as a basis on which to determine how

and controls
Effectiveness of the design,
Summary evidence
(total compliance, partial, none of control
Process level fulfilled
fraudability when assessing the risks for achieving the objectives.

and controls
Effectiveness of the design,
(total compliance, partial, none Evidence Summary
Process level of control
fulfilled)
Changes that could significantly affect the internal control system.

and controls
Efectvidad del diseño,
Effectiveness of the design,
Summary evidence
(total compliance, partial, none
Process level fulfilled) of control
Effectiveness of the evaluation component design Operational effectiveness of the field
of risk

Total compliance Total compliance

Partial compliance Partial compliance

Not fulfilled Not fulfilled

Process Level Design Effectiveness Operational Effectiveness

20% Partial Compliance Partial Compliance

0% Partial Compliance Partial Compliance

0% Partial Compliance Partial Compliance

0% Partial Compliance Partial Compliance

5%

DIAGNOSIS

implementation of Internal control concerning these principles, Therefore, it is recommended

Prepared by:

Company REVIEWED by:


Company SUPERVISED by:

Company APPROVED by:


meets the requirements of COSO.

Operational effectiveness
(total compliance, partial, none
fulfilled)
how they should be managed.

Operational effectiveness
(total compliance, partial, none)
fulfilled
Operative effectiveness
(total compliance, partial, none
fulfilled)
Efectvidad operatva
Operative effectiveness
total compliance, partial, no
fulfilled)
risk assessment component

not to address the risk matrix


PRINCIPLES OF

Entity:

Period Ended:

Evaluate and document the internal control of the organization, from the financial perspective, to identify

The stated activities do not aim to cover all situations. It is necessary to carry out a

Principle 10: The organization defines and develops control activities that co

Summary of
No. Requirement
Business level

Once the risks have been identified and


structured for the relevant assertions of the
financial statements, does management determine the
10.1 YES
relevant business processes and select and
develop control activities to direct each
risk?

Does management involve stakeholders?


to identify the appropriate control activities, it
that includes the personnel responsible for risks in their
10.2 areas, financial personnel responsible for the report
financial, and other control experts such as auditors
interns and others who have the knowledge
specialized?

A centralized group responsible for reporting


financial or control activities, periodically
10.3 review the risk control matrices to help
ensure that the risks to financial reporting of the
entities are being properly directed.
The selection and development of control activities is
is carried out through various methods, which can
include:

Use of matrices to outline the risks


identified for control activities.
10.4
Implementation of working groups to identify
the appropriate control activities for each risk
identified.

Use of activity control inventory,


adapting them as appropriate

The administration considers the segregation of


responsibilities and a mix of activities of
control for transactions and reviews of the
10.5
business processes, and in the same way considers
the use of automated controls as long as the
systems allow it.

Are the controls complemented by activities of


10.6 manual control when automated controls do not
Are they available?

The administration is responsible for designing,


implement and carry out a control system
10.7 effective and efficient internal when hiring third parties
parts for the development of some of its operations.

The management gains a clear understanding of the


activities of the organization that are carried out by
third parties, and if these can affect or have an impact
in the classes of transactions, accounts, or disclosures
in the company's reporting processes, for which
se consideran los siguientes factores:

The importance of transactions or information that


proceed for the third party for the financial statements of
the entity.

The risk of material omission and error associated with the


statements affected by third-party processes,
taking into account whether the activities involve assets
10.8 that are susceptible to loss or misappropriation.
•La naturaleza y complejidad de los servicios
provided by the third party and if these are highly
standardized and used extensively by many
organizations, or they are unique and used only by a few
organizations.

The degree to which the processes of the entity and


control activities interact with those of the third party.
The control activities of the entity that are
applied to the transactions affected by the
third activities.

The terms of the contract between the entity and the third party,
as well as the degree of authority delegated to the third party.

When the organization determines that the processes of


third are relevant for internal control over the
external financial report, management must:

10.9 Identify specific control activities


carried out by the third party that are relevant to
the assertions of the financial statements.
Select and develop control activities
internally about the activities carried out by
the service organization.

Does management determine business processes?


relevant and select and develop activities of
10.10
control to direct each
risk?

The administration considers a combination of


transaction control activities and reviews of
business performance, and in this process the
administration considers the probability that a
control failure and did not operate effectively. In the evaluation
of the risk of failure, the management evaluates factors,
such as:
Type of control and the frequency at which it operates.

Control complexity.
The risk that the administration will exceed the
10.11 controls.
The degree of professional judgment to carry out the
control.
• Competence of the personnel developing the
controls.
Changes in personnel.
Nature and materiality of the statements
erroneous ones that the control must prevent or detect.
The degree to which control depends on effectiveness
from other controls.
Evidence of the operation of control in years
previous.
Does the administration identify incompatibilities in the
10.12 functions that require segregation of
appropriate responsibilities?

Are the policies regularly updated to


10.13
reflect the changes in responsibilities and activities?

Are incompatible functions considered in the


10.14 development or review of policies to grant access
active and systems?

Principle 11: The organization defines and develops activities of c

Summary of
No. Requirement
Company level

Does the administration document the technology that supports


the control activities in risks and matrices of
control, organizational charts or descriptions?
11.1
With the use of this information, the administration can
document the link between control activities and
the technology.

Does the administration know which aspects of the


Technology is important for an operation
11.2 appropriate and continuous use of technology and any
associated automated control?

The administration develops an understanding of how


11.3 various applications
and technology are interconnected with each other.

The management assesses the risk of statements


11.4 erroneous, or errors in the results of the
end user applications.
Based on the risk levels, the management
select and develop general control activities
sobre la tecnología cubriendo los procesos relevantes
about:

11.5 Technological infrastructure.


Management of security.
• End user of computing. Development and
maintenance.
The complete and accurate controls between the system
end-user computing and other systems.

The administration contracts certain aspects of its


IT infrastructure to a service provider
externals, which may or may not have a report on the
service organization controls, following a
appropriate local or international standard. If the report
it is available, the administration uses it to
determine which relevant financial IT processes
they are covered, as well as valid if the controls
appropriate are established in the provider of
11.6 service, and what controls are required in its own
organization to mitigate the risks to the report
external financing at an acceptable level.

In the absence of an appropriate report, the


management uses internal resources to review the
supplier controls, verifying that the
combination of the company's controls and those of
Mitigating financial reporting risks
external to an acceptable level.

Applications, databases, operating systems and


networks that financially support the processes
significants are configured to support access
restricted to financial applications and data
consistent with the policies
11.7
and procedures of the organization. The configuration
includes a means to authenticate users or systems and
support restricted access, as well as key parameters,
such as minimum length passwords and their age
of the passwords.
The management selects and develops the activities
for control so that the transaction processes are
11.8 complete, accurate and valid in real time, just as it
They review manually and through alerts.
automated when they encounter problems.

Financial management establishes policies that


define appropriate access rights to be
11.9 consistent with the job functions, including the
segregation of responsibilities for applications
and relevant financial processes.

The new access requirements or changes


11.10 accesses are reviewed in relation to the policies by
functional monitoring of IT resources.
The owner of the IT resources recertifies
November 11periodically access to ensure that it is of
agreement with the policies.

The issues in the reports are reviewed.


11.12 regularly and corrective actions are taken
when problems are identified.

The administration considers several factors


when selecting new software packages,
11.13 including functionality, application controls,
security features, and requirements of
data conversion.

The administration uses competent internal resources.


or carries out the hiring of suppliers for
11.14 implement the software according to the requirements
of the organization.

Management in the process of change of controls


defined to implement a system of
updates or corrections, includes the evaluation of
the nature of the update or correction and whether this is
appropriate for implementation. If it is deemed appropriate
11.15 It is evaluated at the system and user level in an environment
of tests, in such a way that the stakeholders
determine the change before its implementation. It
maintain documentation to provide the
evidence that the changes have been made.

The administration develops a process for the


systems (SDLC) that covers problem solving to
greater implementation.

The life cycle covers a number of processes and


control activities, which include:
Initiation, authorization, monitoring and analysis: the
changes are captured in change controls or
development of specifications. The progress of the
changes are tracked and the authorization to proceed is
carried out by the appropriate parties. The possible impact on
the internal controls over financial reporting is
evaluated, and the changes are approved by the parties
relevant financials.

• Design and construction: during the design phase, it


they follow programming standards and are established
procedures to provide version control.

11.16
• Quality assurance: tests are
developed before publishing it to check if the
change meets the specification and has not caused
unforeseen changes in the existing software. The
The quantity and type of tests vary according to the
nature of the change and includes unit tests,
system, integration, and user acceptance, as applicable
appropriate.

Data conversion: as applicable, the data is


conversion complete, exact and valid from the
previous technology.

Implementation of programs and authorization


commissioning: the change is approved by
the relevant parts before entering into
functioning, and only the approved version of the software
is implemented.

• Documentation and training: the end user, the


IT support documentation and training are
created and updated as necessary.

Principle 12: The organization deploys control activities through policies

Summary of
No. Requirement
Company level

The Administration develops and documents policies and


procedures for all control activities
12.1
related to the
External Financial Report?
The procedures are documented using various
formats such as narratives, flowcharts, and matrices
of control. The administration develops a format
standardized for policies and procedures, the
which includes:

Reasons for the policy and the procedure,


including the associated risks.

• Location, units, and processes to which it applies


the policies and procedures.
Roles and responsibilities to own, create,
12.2 implement, the execution and maintenance of the
policy and procedure.
Facts covered by the policies and procedures,
including corrective actions to be taken as part
of the development of the control activity.
Classification procedures for exceptions
of the policies.
Cross-references between the policies and
associated procedures.
Required competence of the staff that develops the
procedures.
Review of the data.
The business units or functional leaders
they implement control activities in their areas of
12.3 responsibility through the construction of policies and
procedures among the daily activities of the
organization.

The policies and procedures are communicated through


in different ways, including programs of
12.4 training, meetings, and distribution of documents
formal and informal.

The owners of the control activities, together


with experts in financial reporting
and control, they review the documentation of the activities
12.5 to control to verify its relevance
and significant changes. The changes are made when
redundant control activities are found,
obsolete or ineffective.

Summary of control activities


In summary, have sufficient control procedures been established over
the main cycles of transactions, accounting estimates, and process of
closures that allow achieving the company's objectives regarding the
financial information? Write brief conclusions regarding this, with
reference to each of the processes identified above.

In summary, have sufficient control procedures been established over


the main cycles of transactions, accounting estimates and process of
closures that allow achieving the company's objectives regarding the
financial information?

Consolidation of results - Activities of


Control Company Level

10. The organization defines and develops activities of


7%
controls that contribute to the mitigation of risks

11. The organization defines and develops activities of


0%
control at the entity level over technology

12. The organization deploys control activities.


0%
through policies

Average 2%

According to the evaluation of the Risk Assessment Checklist, the company has deficiencies in the i.
and include the risks and appropriate measures to try to mitigate them.
Final Comments and Observations:
AND CONTROL ACTIVITIES (COSO)

Reference of P/T:

BC-03

PURPOSE

Identify important risks during the development of the audit assignment.

SCOPE

In the analysis, determine the activity developed according to the nature of the business and follow up.

contribute to the mitigation of risks to acceptable levels for achieving

and controls
Effectiveness of the design,
(total compliance, partial, no Summary of control evidence)
Process level fulfilled

YES

YES
control at the entity level over technology to support the achievement of objectives

and controls
Effectiveness of the design,
total compliance, partial, no Summary evidence of control
Process level fulfilled)
It sets out the general guidelines for internal control and procedures to carry out.

and controls
Effectiveness of the design,
(total compliance, partial, no control evidence summary)
Process level cumplido)
Effectiveness of the activity component design Operational effectiveness of the field
of control
Total compliance We did it

Partial compliance We fulfill

Not fulfilled No cum

Process Level Design Effectiveness Operational Effectiveness

14% Partial Compliance Partial Compliance

0% Partial Compliance Partial Compliance

0% Partial Compliance Partial Compliance

5%

DIAGNOSIS

implementation of internal control concerning these principles, Therefore, it is recommended

Company PREPARED by:


Company REVIEWED by:

Company SUPERVISED by:

Approved by:
meet the requirements of COSO.

of the objectives.

Operational effectiveness
(total compliance, partial, none
fulfilled)
os.

Operational effectiveness
(total compliance, partial, none)
fulfilled)
to said policies.

Operational effectiveness
(total compliance, partial, none
fulfilled)
control activities component
total number

partial delivery

fulfilled

You must address the risk matrix.


PRINCIPLES OF INF

Entity:

Period Ended:

Evaluate and document the internal control of the organization, from the financial perspective, to identify

The activities listed do not intend to cover all situations. It is necessary to carry out a

Principle 13: The organization obtains, generates, and uses information

Summary of
No. Requirement
Company level

The Administration defines common categories and types of


information that is aligned with the objectives of
external financial report and related risks. A
13.1 among these categories, Financial Management YES
identify relevant information from both sources
internal as well as external, that adapt to the
needs of the Administration.

The Administration creates an inventory of the information and


sketch each item for one or more members of the
13.2 Administration that has a position in the Report
External Finance, assigning responsibilities to
staff to collect the required information.

The data and information sources vary according to


with the specific roles and responsibilities of each
individual.

The sources of information may include:

Industry publication subscriptions


and regulatory updates.

Participation in conferences, exhibitions


13.3 commercials, and other industry events.
• Verbal and electronic communications with the
suppliers, clients, or service providers
externals.
Membership and participation in organizations
relevant.
Subscription to third parties and social media of the
industry and the company.
Industry research reports.
Industry calls and financial records.

The financial personnel evaluates external information.


collected and the incorporation of events, trends and
changes in the daily financial report or in the
related internal control responsibilities.
13.4 In addition, the financial staff ensures that any
pronouncement regarding the changes to update
the accounting standards and requirements
regulations, should be summarized, reviewed, and disseminated to
others within the financial reporting organization.

The staff of senior management in accounting and finance is


meet at least monthly with the
Administration and staff from other areas of the business.
During these meetings, the information about the
business events and trends are obtained in a way
verbal and written. The aspects to review may include:

• New or significant losses of customers,


suppliers and other stakeholders.

Estimate the impact of employee turnover.


13.5
Unexpected trends.

Indications of unethical or improper behavior.

Budget in relation to actual expectations and


forecasted.

Contractual, compliance, or regulatory facts.

Customer or supplier complaints.

Results of internal audit reports.


All this information is organized and summarized for
to be presented to senior management for evaluation
impact on the financial statements, in the effectiveness of
the internal controls, or in the necessary changes in
the policies and procedures.

Does the High Administration establish a policy for


manage the information that is collected, produced and
shared through the company? Is the policy
13.6
designed to facilitate efficient capture, use, and
reuse of the relevant information provided
to the management and the staff in the company?

The management and employees in reporting roles


external financial procedures are followed for the
identification and categorization of information. These
procedures require that the attributes of each
pieces of information are registered before the
information is accepted in the warehouse.

13.7 The attributes may include:


Owner of the information,
• Expected users,
Sources,
Criticality
Frequency,
Supported process,
Retention period.

All this information is organized and summarized for


to be presented to upper management for evaluation the
impact on the financial statements, on the effectiveness of
the internal controls, or in the necessary changes in
the policies and procedures.

The administration designs its computing applications


to capture data from internal and external sources,
13.8 transform the data into information, and maintain the
quality of data and information through the
processing and reporting.

Are the activities related to capture and


the processing of data regarding transactions
13.9 financial matters are documented in the policies and
company procedures?
Does the application design include controls for
13.10 automated applications like reviews of
entries for existence and validity, and the reviews of
outputs for completeness and accuracy?

The Senior Management establishes a government program of


data to support the company's objectives
November 13ensuring the reliability of the information used in
the support of internal controls and Financial Reporting
External.

The data governance program includes


procedures and policies for:

13.12 Assignment of roles and responsibilities within the group


Central data administrator, business functions and
TI.

Validation of information sources.

The Senior Management formalizes policies, procedures and


responsibilities for the
data and information of the Administration, considering
13.13
the volume, complexity and
demand for quick captures and dissemination
from multiple sources.

The IT Senior Management establishes policies to define


data categories and assign requirements for the
security and data retention. These policies
13.14 they support the responsibilities of the Administration and the
employees of information protection
unauthorized access or changes, and to comply with
the requirements for data retention and destruction.

The Senior Data Administrator develops processes for


13.15
llevar a cabo la polítca de clasificación de datos.

The data classification requirements are


communications to the responsible staff of the
13.16 transaction processing through
periodic notifications regarding responsibilities
important internal control.

Principle 14: The organization communicates information internally, including the ob

Summary of
No. Requirement
Company level
The procedures are documented using various
formats such as narratives, flowcharts, and matrices
of control. The administration develops a format
standardized for policies and procedures, the
which includes:

Reasons for the policy and the procedure,


including the associated risks.

• Location, units, and processes to which it applies


the policies and procedures.
Roles and responsibilities to own, create,
12.2 implement, the execution and maintenance of the
policy and procedure.
Facts covered by the policies and procedures,
including corrective actions to be taken as part
of the development of the control activity.
Classification procedures for exceptions
of the policies.
Cross-references between the policies and
associated procedures.
Required competence of the staff that develops the
procedures.
Review of the data.
The business units or functional leaders
they implement control activities in their areas of
12.3 responsibility through the construction of policies and
procedures among the daily activities of the
organization.

The policies and procedures are communicated through


in different ways, including programs of
12.4 training, meetings, and distribution of documents
formal and informal.

The owners of the control activities, together


with experts in financial reporting
and control, they review the documentation of the activities
12.5 to control to verify its relevance
and significant changes. The changes are made when
redundant control activities are found,
obsolete or ineffective.

Summary of control activities


Frequency and number of Board meetings
14.5 Directly, including the committees,

Objectives of each meeting and committee,

Nature and extent of the information to be


shared in each meeting,

Responsibility to prepare and approve the minutes of


the meetings and the committees.

The Chief Financial Officer and the support staff present


financial information in meetings and committees of
the Board of Directors, providing an analysis of the
14.6 results compared with the expectations, including
updates on forecasts and major changes
in the original budgets, and communicates other facts
relevant to the financial report.

The Executive Director, the Chief Financial Officer and the


The Executive Director of Audit presents the draft of
the external financial statements, material events,
14.7 significant changes in the estimates or
statements, and new revelations? The external auditor
he/she also attends the meeting to present his/her point of view
view on the financial statements.

Every quarter, the Financial Director and the Director


Audit executives present a summary of the
14.8 important changes in internal control, results of
the evaluations, and the actions in response to any
identified deviation?

The Audit Committee meets with Management


and the external auditors to share the information
14.9 sensible, and to present questions to facilitate the
responsibilities of each party in relation
with the internal control?
The Administration and the Board of Directors establish a
anonymous reporting program for employees
have a direct line to communicate facts,
instances or matters related to misconduct
with the external financial report.

To raise awareness of the reporting program to the


14.10
employees, different forms are used.
communication, such as bulletin board postings,
notifications, among others.

The program allows employees to submit their


anonymous reports, ensuring a
confidential communication.

The issues reported in the complaints program


they are evaluated by an objective part and communicated to
14.11 the Board of Directors or an appropriate person, according to
be the case, to take the necessary actions.

The Administration provides an alternative for the


report to a line Director. This alternative includes:
14.12
Mentoring programs that provide support to the
employees.

Meetings where employees can present


your concerns,

• Staff in different departments and levels that are


meet to discuss the matters, and present them
comments and observations to the Administration.

The Administration develops communication processes


and multifunctional and departmental forums that
14.13
allow the staff to communicate control matters
internal through the entity.

Representatives from each department have defined


roles and responsibilities for communication of
internal control matters through these processes and
forums. The team meets periodically to discuss
14.14
issues, trends, and future events that may
impact internal controls.
The Administration and the relevant personnel evaluate and
they respond to the impact of these issues and facts.

Principle 15: The organization communicates with interest groups


Summary of
No. Requirement
Company level

The Administration considers all external parts.


relevant parties requesting information on internal control
about the Company's External Financial Report. The
15.1 The company's disclosure committee has established
a process to evaluate events, policies, and
company activities that impact the parties
externals that are important for the objectives of the
entdad.

The Disclosure Committee determines the information that


can be shared with external parties, which
you can include:

• Internal controls over transactions and balances that


represent accounts payable, accounts receivable or
commitments with external parties.
15.2
Results of supervision procedure
compliance with contractual commitments,

Policies for the protection of received information


from external parts,

Client responsibilities.

The administration surveys customers and sellers.


regarding your perception of integrity and ethical values
of the company staff. These surveys
they provide a communication channel for the
clients of the company,
important information about commitments
with the clients.

15.3
These surveys can be conducted in different ways.
shapes:

Periodic surveys sent to clients.

Feedback mechanisms.

Meetings with third parties.


The Administration provides a reporting hotline.
anonymous to customers, suppliers, and companies
hired and other external parties, to facilitate the
15.4 report and feedback on relevant issues.
The line is communicated through different means.
like the company's website or
direct communications with external parties.

According to the reviews of the external auditor of the


financial information and evaluations of the
effectiveness of internal control, the Administration receives
a report on the significant issues identified. The
15.5 The Board of Directors meets with the Administration and
External Audit to discuss these matters, where
External Audit presents them and the Management
propose the possible actions to take.

Summary of information and communication

In summary, are the established processes sufficient to comply


with the four identified principles of information and communication,
and allow achieving the company's objectives regarding information
financial?

Summarize the arguments that support this conclusion, along with the actions.
that the company will undertake to improve the quality of internal control of the
financial information.

Consolidation of results-Information and


Communication Company Level

13. Generation and use of relevant information 6%

14. Internal Communication 0%

15. External Communication 0%

Average 2%
According to the evaluation of the Information and Communication Principles Checklist, the company
the risk matrix and include the risks and the appropriate measures to try to mitigate them.

Final Comments and Observations:


TRAINING AND COMMUNICATION (COSO)

Reference of P/T:

BC-04

OBJECTIVE

Identify important risks during the development of the audit assignment.

SCOPE

in analysis and determine the activity developed according to the nature of the business and follow

Relevant and quality information to support the functioning of internal control.

and controls
Effectiveness of the design,
Summary evidence
(total compliance, partial, none
Process level fulfilled) of control

YES

YES
jobs and responsibilities that are necessary to support the functioning of the system

and controls
Effectiveness of the design,
Summary of evidence
(total compliance, partial, no) of control
Process level fulfilled)
There are external factors regarding the key aspects that affect the functioning of internal control.
and controls
Effectiveness of the design,
Summary of evidence
(total compliance, partial compliance, none
of control
Process level fulfilled)
Effectiveness of component design Operational effectiveness of the field
information and communication information and communication.

Total compliance Total compliance

Partial compliance Partial compliance

Not fulfilled Not fulfilled

Process Level Effectiveness of Design Operational Effectiveness

13% Partial Compliance Partial Compliance

0% Partial Compliance Partial Compliance

0% Partial Compliance Partial Compliance

4%
DIAGNOSIS

ne deficiencias en la implementación del control Interno en lo concerniente a estos principios, Po

Company PREPARED by:

Firm REVIEWED by:

Firm SUPERVISED by:

Approved by:
the requirements of COSO.

Operational effectiveness
(total compliance, partial, none
fulfilled
internal control email.

Operational effectiveness
(total compliance, partial, no
cumplido)
no.
Operational effectiveness
(total compliance, partial, none)
fulfilled)
onente of
or what is recommended to address to
PRINCIP

Entity:

Period Ended:

Evaluate and document the internal control of the organization, from the financial perspective, to identify

The stated activities do not intend to cover all situations. It is necessary to carry out a

Principle 16: The organization selects, develops, and conducts evaluations with
before

Summary of
No. Requirement
Company level

The senior management meets periodically to review


the assignments of efforts among the evaluations
continuous and independent used to carry out
monitoring activities.
The combination of monitoring activities on the
internal control and the External Financial Report depends
from the evaluations of the administration of:
16.1 YES
Regulatory requirements of the entity and objectives
of financial report,
Changes in the industry,
Results of the evaluations of the effectiveness of the
controls,
Changes presented that have impacted some
component of the Internal Control System.

Top Management develops a benchmark for


el entendimiento del diseño y estado actual del Sistema
16.2 of Internal Control of the entity, through:

The determination of a starting point of the system.


The review of whether the controls are operating as
is scheduled for the fulfillment of the objectives.

The Administration uses this benchmark to


establish which continuous evaluations and
independents are more appropriate.

The Administration identifies the metrics that


they correlate the completeness and accuracy of the
financial transactions to provide the
16.3 continuous evaluations of control activities
established. In this way, the Administration
consider the processes that must be monitored and
develop the appropriate measures and frequency for the
evaluation.

The Administration develops and implements frameworks of


I ask for the reviewers to use them in their
actvidades diarias.

These paintings may include:

Detailed performance information of the


controls.

• Information and metrics for evaluations and


16.4 investigations

Visual representations of the state of operation of


the controls,

Frequency of evaluations,

Identified deficiencies and solutions to them,

• Personnel and contacts responsible for the processes.

The Administration uses technology to support the


monitoring of the internal control system in the course
16.5
ordinary of the business, through applications of
automated monitoring.

The Administration conducts evaluations


independent of internal control over the Report
External Financial Taking into account:

Conducting visits and reviews of the


Administration.

Conducting reviews across the units


operational.
16.6
Comparison of the components of the System
Internal Control with other companies in the sector,

Development of self-assessments,

Hiring of external parties for development


of specific evaluations.

Does the Administration have appropriate personnel and


qualified for internal audit functions, and
16.7 to provide an objective perspective of the
elements of internal control over the Report
External Financing?

Are the internal audit reports delivered to the


16.8 Upper Management, the Board of Directors, and the other parties
pertinent?

The Administration obtains and reviews periodically the


information from external service providers
16.9 to identify any changes in the activities that
they may affect the internal control over the Report
External Financial of the entity.

Principle 17: The organization evaluates and communicates internal control deficiencies.
and the

Summary of
No. Requirement
Company level

The Administration develops policies and practices to


17.1 periodically evaluate and communicate the results of
las actvidades de monitoreo de la entdad?

The Administration has established that all


Deficiencies must be reported to the staff.
17.2 responsible for taking the correct actions. The
deficiencies must be classified to provide
a timely response to each one.

The Administration establishes practices to review the


status of the corrective actions taken for
17.3
verify that the deficiencies have been remedied
timely.

The Board of Directors has expectations with the management.


Address on the lost positions of deficiencies in the controls
17.4 that have been reported to the Board. The Board analyzes each
deficiency and supervises the actions developed by the
Administration to remedy these deficiencies.
Follow-up summary

In summary, are the established processes sufficient to comply with the


two identified principles of monitoring, and allow achieving the objectives of
the company regarding financial information?

Summarize the arguments that support this conclusion, along with the actions.
that the company will undertake to improve the quality of internal control
about financial information.

Consolidation of results-Supervision Company Level

16. Conduct ongoing assessments and/or 11%


independent

17. Evaluate and communicate deficiencies 0%

Average 6%

According to the evaluation of the Monitoring Principles Checklist, the company has deficiencies and
risks and include the risks and appropriate measures to try to mitigate them.

Final Comments and Observations:


FOLLOW-UP PIOS (COSO)

P/T Reference:

BC-05

OBJECTIVE

Identify important risks during the development of the audit assignment.

SCOPE

an analysis is carried out and the activity developed is determined according to the nature of the business and subsequent

ntnuas and/or independent to determine if the components of the control system


present and in operation.

and controls
Effectiveness of the design,
(total compliance, partial, none Summary of evidence
Process level of control
fulfilled

YES
YES
or in a timely manner to the parties responsible for applying corrective measures, including
the advice, as appropriate.

and controls
Effectiveness of the design,
Summary evidence
(total compliance, partial, none)
Process level fulfilled of control
Effectiveness of the tracking component design Operational effect of the co

Total compliance We comply

Partial compliance We fulfill

Not fulfilled No cum

Process Level Design Effectiveness Operational Effectiveness

22% Partial Compliance Partial Compliance

0% Partial Compliance Partial Compliance

11%

DIAGNOSIS

in the implementation of Internal control regarding these principles, Therefore, it is reco

Prepared by:

Company REVIEWED by:

Company SUPERVISED by:


Company APPROVED by:
meet the requirements of COSO.

inside they are

Operational effectiveness
(total compliance, partial, no)
fulfilled
I give the senior management

Operational effectiveness
(total compliance, partial, none
fulfilled
tracking component

total number

partial invoice

fulfilled

please address to the matrix of

You might also like