Computer-Assisted Internal Control Thesis
Computer-Assisted Internal Control Thesis
AND OPERATIONAL
2008-2009
Thesis Subject:
Mohammed EZ-ZOUAK
ROBERT SCHUMAN UNIVERSITY
OPERATIONAL
2008-2009
Mohammed EZ-ZOUAK
Internship Supervisor: Ms. Roselyne PATOIS (head of the mutual health insurance)
2
THANKS
This thesis for obtaining the M2 degree in Financial and Operational Audit is the result
of a considerable effort. This effort could not have succeeded without the contribution of several
people. Thus the opportunity arises to thank them: First of all,
To Pr Pierre SCHEVIN, The Director of this thesis during this internship for his availability
and his advice
To Ms. Nathalie De STEUR, IT manager at the MES, for her assistance and her
instructions.
Without forgetting all the staff of the Mutual without exception for their moral support and
educational during the 2 months of this internship
And finally, my parents, my family, and my brother-in-law for their moral and financial support.
during this year of studies
3
Introduction _______________________________________________________________ 6
Introduction to internal control
1 Conceptual framework of internal control _______________________________________ 9
1.1 Etymology of the word_______________________________________________________ 9
1.2 Definitions of internal control _____________________________________________ 9
1.3 The COSO model _______________________________________________________ 11
1.4 Sarbanes Oxley_________________________________________________________ 13
1.5 The Financial Security Law (LSF) _____________________________________ 14
1.6 Comparison between the Sarbanes-Oxley Act and the Financial Security Act_______ 15
2 The process of internal control__________________________________________ 16
2.1 Definition and characteristics of the internal control approach _______________ 16
2.2 Analysis of some models of the internal control approach _______________ 17
3 Classic approach adopted by internal control software publishers _______ 19
3.1 Identification of processes
3.2 Declination of the strategy into objectives _____________________________________ 20
3.3 Process analysis ___________________________________________________ 21
3.4 Risk assessment ___________________________________________________ 22
3.5 Implementation of control activities
Part (2): Computer-Assisted Internal Control____________________________ 26
1 Introduction to Computer-Assisted Internal Control ______________________ 26
1.1 The concept_____________________________________________________________ 26
1.2 The objectives of Computer-Assisted Internal Control______________________ 27
1.3 The internal control software on the market _______________________________ 29
2 Advantages and limitations of Computer-Assisted Internal Control ________________ 31
2.1 The contribution of Computer-Assisted Internal Control _________________________ 31
2.2 The limits of Computer-Assisted Internal Control _______________________ 36
2.3 The keys to success of a Computer-Assisted Internal Control project ______ 39
3 Valdys Software Case Study______________________________________________ 40
3.1 Presentation of the software __________________________________________________ 40
3.2 The architecture of Valdys_________________________________________________ 42
3.3 The Internal Control project according to Valdys__________________________________ 44
3.4 The documents generated internally by Valdys _______________________________ 48
50
Annexes__________________________________________________________________ 52
1 Annex (1): Valdys Glossary _____________________________________________ 53
2 Annex (2): the Macro-process _________________________________________ 55
3 Annex (3): Risk Tree____________________________________________ 56
4
4 Annex (4): Phase Diagram and Flowchart ___________________________ 57
5 Annex (5): Risk Family Tree ___________________________________ 58
6 Annex (6): The nomenclature model and the structure diagram model _______ 59
7 Annex (7): The role/competency tree model and risk mapping _ 60
8 Appendix (8): Html pages_____________________________________________ 61
5
Introduction
The automation of information processing dates back to the invention of the first
computer. Since then, all branches of science and industry have tried to exploit the
huge capabilities of this tool, especially those for calculating and processing data with a
unimaginable speed that surpasses the limits of the human brain. It is then that the economy and
finance was among the sectors that were able to benefit from the advantages of automated processing
some information.
The miniaturization of components and the reduction of production costs, combined with a
increasingly urgent need for processing all kinds of information (scientific,
financial, commercial, etc.) has led to a spread of computing in all
layers of the economy as well as of everyday life.1
After accounting, finance, and financial auditing, today, it's about internal control.
to integrate into the world of automated information and fully benefit from the contributions of
computer science in this field. In this perspective, the "Internal Control Assisted by
Computer » marks current events by its contribution to the internal and external auditor as a tool
of assistance and management of control missions.
Until today, no one has been able to perceive that a field as abstract and evolving as the
internal control whose reflection (risks) and development (control points) play a
a crucial role would call for the services of IT. However, the symptoms of this
The new wave of software solution providers for businesses has already been felt. These
editors of management software applications and in the face of intense competition in the
software market was able to adapt to overcome the barrier of limited knowledge in the
management areas. For them, the solution is to offer software that allows
to help and assist the auditor in carrying out their internal control mission by
maximizing its expertise and its analytical and observational abilities in a
specific domain (insurance, energy, nuclear industry,...) then cross-referencing it with the
practices recognized by auditors in the sector and the regulations in force. Indeed,
the observed difference between the existing and the conceptual is at the base of the results and the
obtained interpretations.
1
[Link] on 02/17/2009
6
2
Several audit and internal control software packages exist on the market, a set of
diversified choice of management IT solutions to manage control processes
internet and ensure compliance with regulations (Financial Security Act, law of
Sarbanes-Oxley, Basel II, Solvency II, etc.). Among these products, FrontControl is highlighted. 3,
Enablon Continuous Assessment4ISIMAN5and finally VALDYS which will be the subject of a study
of cases in this thesis. All these solutions are based on the same principle by constituting a
reference base for internal control of a given sector for the auditor and in assisting them in
his approach to establishing and monitoring the internal control process.
In this thesis, I will attempt to address and analyze the following issue:
To answer this question, my analysis will focus on the following two parts:
The first part will focus on the conceptual framework of internal control where I will present
the different definitions of internal control, the approaches and the regulations that
frame this sector and finally describe the process of establishing a system of
internal control. This section is a crucial part for better understanding the two
axes that will follow.
In the second part, I will address the crux of the issue where I will analyze the contribution.
of Computer-Assisted Control on several dimensions: the originality of the concept,
the contribution of computer-assisted internal control and lastly I will address the
limits of this concept. The second axis of this part of the thesis is a case study of
VALDYS software (French software for internal control developed to meet the needs
of insurance companies and mutuals). This case study aims to illustrate the conclusions
and the results obtained.
2
Product and software contraction
3
[Link] February 17, 2009
4
[Link] February 17, 2009
5 [Link] the
February 17, 2009
7
The objective of this thesis with its two parts is to address the problem raised in
moving from a conceptual framework to an empirical framework. The type of argumentation used is
an argumentation by illustration. This argument consists of using a concrete example
justifying a statement that we make. In other words, we will formulate the problem, then
we will present a specific and real fact or case that embodies and materializes the deductions
obtained.
For the same purpose of illustration and argumentation, several documentary sources will be
shared used among bibliographic sources, webographic sources, and documentary databases
electronics.
8
Part (1): Introduction to Internal Control
In the book 'Internal Control', Frédéric Bernard distinguishes between the French word
"Control" and the Anglo-Saxon word "Control":
The term internal control is the literal translation of the Anglo-Saxon expression: Internal
Control (or Business Control for Americans) in which the verb 'to control'
means maintaining control of the situation whereas in French the word 'contrôle' is
better understood as the act of exercising surveillance over something
to evaluate it7.
Despite the etymological and phonetic resemblance of the two French and Anglo-Saxon words,
we find that the term 'internal control' reflects the upstream and preventive aspect of the process
internal control through monitoring measures and risk analysis regarding the word
Internal Control translates the downstream and corrective dimension of internal control.
identification of control elements, planning of control tasks, organization of
responsibilities, following up on recommendations, etc.). This divergence of meaning between the two
words reflect and explain the subtle difference in the way of practicing and implementing
the internal control process between French companies and Anglo-
Saxons.
6
[Link] on 19/02/2009
7 Frédéric Bernard, Rémi Gayraud and Laurent Rousseau, "Internal Control", [Link], Paris, 2006, p. 303
9
to ensure the application of the instructions from Management and to promote improvement of
performances.8
Definition given by the accountants, at the congress in 1977: "internal control
is the set of securities contributing to the management of the company. Its purpose is
to ensure the protection, safeguarding of heritage and the quality of information of a
part and on the other hand, the application of the management's instructions, and to promote
the improvement of performance.
8
Frédéric Bernard, Rémi Gayraud, and Laurent Rousseau, "Internal Control", [Link], Paris, 2006, p 303
9
CNCC Standard 2-301, risk assessment and internal control, paragraph 08, CNCC normative framework, 2003
10
Coopers & Lybrand, 'The New Practice of Internal Control', Organization Edition, Paris, 1994, p 378
10
The study and analysis of these different definitions distinguishes between two approaches
fundamentals:
On one hand, a classic approach that emphasizes the basic principles of internal control: the
heritage preservation, information reliability, compliance with regulations
and performance improvement. These elements are faithfully reflected in the first and the
second definition without straying from the carefully outlined framework by these components.
This limitation of the scope of interpretation and reaction has made internal control a concept
equipped with a rigid structure that is difficult to adapt to different natures and situations
of companies.
On the other hand, a modern approach illustrated by the last three definitions (CNCC,
IAASB, Coopers & Lybrand). This approach includes the notion of process or procedure.
in its definition and it involves the key players in the internal control process in
this process while emphasizing the role of the staff. Furthermore, it mentions for the
first time the respect of management policy as a main factor in the system of
internal control.
1.3.1 COSO 1
Internal control is made up of 5 interrelated elements that stem from the way
the activity is managed and is integrated into management processes:
11
Risk assessment: it involves the identification and analysis of factors
susceptible to affecting the achievement of the strategic objectives of the company. It is a
continuous and repetitive process that determines how risks should
to be managed. It is up to the leaders and heads of the relevant services.
to assess and set an acceptable risk rate.
1.3.2 COSO 2
The COSO 2 model constitutes a continuation and a follow-up of COSO 1. Frédéric Bernard defines
and explain the difference between COSO 1 and COSO 2: "... It does not provide a framework for
internal control (as opposed to COSO) but a risk management model. It relies on
on COSO as a framework for Internal Control.12
12
Frédéric Bernard, Rémi Gayraud, and Laurent Rousseau, "Internal Control", [Link], Paris, 2006, p. 303
12
Among the contributions of COSO 2:
On one hand, it provides auditors and internal controllers with a reference for risk management.
of the company (Enterprise Risk Management Framework). Indeed, COSO 2 reminds us of the
elements of COSO 1 and especially complements it on the dimension of 'risk management'. It is
thus based on an approach oriented towards the mastery of business risks. On the other hand,
it presents a more limited framework for decomposing the structure of an organization then
that COSO 1 does not retain a specific decomposition structure. However, this
distribution among different levels of the organization is very useful for the approach of
control proposed by the COSO model. However, it is necessary to take into account
the organization as a whole so that COSO 2 can be successfully implemented.
13
[Link] visited on 03/05/2009
13
The fundamental decisions of this law are:
Despite all the efforts made at the level of the 'Sarbanes-Oxley' law to limit the
financial frauds, the assurance that this law provides for the organization remains an assurance
reasonable against the risk since there are always points of failure for
circumvent internal control barriers. Michael Oxley supports this reasoning in
his interview with Liz Alderman: "I won't go so far as to say that the Sarbanes-Oxley Act us
sheltered from a scandal such as the bankruptcies of Enron and Worldcom nor that individuals do not
will not be intelligent enough to circumvent the rules. After all, murder is illegal.
in all countries and yet murders are committed every day.15
14
Kamal ABOU EL JAOUAD, "The Stakes of Internal Control" Clermont University
15
[Link] visited on 03/15/2009
14
The National Assembly and the Senate have adopted LAW No. 2003-706 of 1 heAugust 2003 on the
financial security in view of decision no. 2003-479 DC of the Constitutional Council dated the 30th
July 2003.16
This law applies to all public limited companies. It includes the obligation for the
Chairman of the Board of Directors or Supervisory Board to report in a
report on the control procedures implemented by the company. It also considers that
the establishment of a report on internal control is a key factor for competitiveness and
the development of private enterprises.
1.6 Comparison between the Sarbanes-Oxley Act and the Financial Security Act
The fundamental distinction between the Financial Security Act and the Sarbanes-Oxley Act is
the degree of formality that is clearly defined in the second law. Thus, reference frames
such as COSO provide a precise framework for internal control actors. However, this
is not the case currently for the Financial Security law. The major obstacle for
this is the non-existence of a French framework that governs the work of auditors. The LSF
does not refer to any reference framework and does not even provide a definition of 'internal control'.
Also, the Financial Security Law is less demanding than the Sarbanes-Oxley Act and by
consequently, it allows to adjust the level of formality of Internal Control in relation to the
size of the company, however it complicates the work of the Auditor.
The LSF engages all public limited companies. Its scope is broader than that of the law.
Sarbanes Oxley which is limited only to publicly traded companies. It directly involves the
Chairman of the Board of Directors or Board of Supervisors while the Sarbanes Act
Oxley engages the operational management. Finally, the LSF concerns all procedures of
internal control while the Sarbanes-Oxley Act only concerns information
accounting and financial. The European model defending every shareholder of companies
Anonymous opposes the American model that only cares about company shareholders.
making a public appeal for savings.
16
[Link] visited March 15, 2009
15
The approach of internal control
2.1 Definition and characteristics of the internal control approach
Internal control, unlike financial auditing, does not have a limited scope of intervention, it
concerns all types of risks that may exist in the company (Financial risks,
human risks, technical risks,…). Its main objective is to safeguard heritage.
of the company and to establish a control system.
Internal control is no longer an unpredictable process that happens day by day, nor is it a
ready-to-wear solution applicable to all companies without adaptation to contexts,
the environment and the specific structures of these.
On the contrary, the internal control approach is an organized, appropriate process, and
sustainable. Specifically, it is a process of change:
The establishment of control points, preventive and corrective processes, is carried out in
a continuity perspective of the approach over time. It takes place in a perspective of
16
sustainability of the activity and the life of the company. Clearly, the internal control approach
is a medium and long-term approach.
The change in this context means the acceptance by the stakeholders of the company that a
unavoidable and radical change in the internal organization and functioning of
The company is likely to occur. However, any act of refusal or resistance to this
the process of change is a human and expected phenomenon.
The planned changes concern the tools and work techniques (use of
new software), management methods (transition from hierarchical management to a
participatory management) and the values of the company (transforming a culture of closure and
segmentation into a culture of openness and sharing.
Benoît Pigé in his work "Audit and Internal Control" proposes the following approach:
17
Frédéric Bernard, Rémi Gayraud and Laurent Rousseau, "Internal Control", [Link], Paris, 2006, p 303
17
The assessment of specific risks that may arise from a financial situation,
of a social situation or internal organizational changes
The evaluation of internal control involves describing the procedures (observation, the...
interviews with company staff and formalization) check the adequacy
procedures to achieve objectives (setting objectives and implementing the
necessary means) to carry out the application and effectiveness tests of the procedures
internal control.
•Perform product validation tests. (sampling, full validation)18
We can observe the divergence in form of the two previous methodologies, but one
convergence on the substance.
18
Benoît Pigé "Audit and Internal Control", Ed EMS, Paris, 2001, p210
19
See appendix (7)
18
3 Classic approach adopted by software publishers
of internal control
3.1 Identification of processes
3.1.1 Definition 1
Yvon MOUGIN Consultant and Trainer at Cap Entreprise defines the process as a
set of related resources and activities that transform input elements into output elements
output. In other words, it is a black box that has a purpose (the output data) and that
to achieve this purpose, use external elements (input data) and transform them
by providing added value through work and tools (activities and resources).20
3.1.2 Definition 2
A process is a succession of activities within an organization, linked together in order to
to produce a result. Collaborative work applications can define different
process according to the organization and the tools implemented.21
However, it is important to distinguish between the term process and the term procedure, which means
a specified way of carrying out an activity.
The identification of processes is the first step in the risk management approach.
It helps to understand the jobs within the company and contributes to the sustainability of the
internal control process. The objectives of this phase are to build a clear idea and
structured processes of the activity, to describe the processes and to collect the information
for the identification of risks and the controls planned.
20
[Link] visited on 25/03/2009
21
The link provided seems to lead to a glossary page, but no specific text was provided for translation. visited on 25/03/2009
22 Coopers & Lybrand, "The New Practice of Internal Control", Organization Edition, Paris, 1994, p 378
19
3.1.3 Process Mapping
To implement an internal control process, it is essential first to
know and understand the activities, then define the links and dynamic flows between them
(incoming flows and outgoing flows)
Macroprocess
.
Major Process
.
Processus
Activité
Procédure
Pyramid of granularity levels 1
20
To illustrate the notion of a goal and its characteristics, we can refer to Alain.
Gérard-Cohen, in his work "Internal Control and Public Auditing," discusses the
declination of a reflection by objectives: "...through an organized, coherent reflection,
encrypted, iterative, allowing all choices and trade-offs (including political), in a way
clear and transparent, thus ensuring a realistic optimization of resources
means and resources in response to explicit and prioritized needs.23
Also, it is necessary to determine with significant precision, the human, financial, and
techniques necessary to achieve one's goals. To measure performance results
obtained, there are a multitude of indicators that are defined according to the nature of the objectives and
other factors.
On one hand, it involves setting the main objectives of the process, raising the factors
success factors of the process and key performance indicators, frame the process by
a beginning and an end.
On the other hand, the analysis of processes must answer the questions: Who does it (role)? What?
(task)? Through what information flow? (support information systems)
The analysis of processes is an operation that requires special attention from the auditor.
since it is at this level that it can foresee the existence of a potential risk or a point
fallible in the process. Thus, the degree of vigilance and precision in the design and
the analysis of these processes will increase the added value of this step in the
internal control process.
23 Alain-Gérard Cohen, 'Internal Control and Public Audit', ed LGDJ, PARIS, 2005, p 183
21
3.4 Risk Assessment
Operational risks
Information system risks
Human risks
Legal risks
External risks (exogenous)
Every potential or actual risk must be recorded and studied even if one considers that it is
minimized by an appropriate control device. The risk is divided into 3 categories:
22
3.4.3 Process and characteristics of the evaluation approach
risks
All organizations, regardless of their size, structure, or the nature of their activities and
the economic sector in which they operate, face risks and this at all
the levels. All of its identified risks must be subject to an evaluation based on
the assessment of their potential consequences and the likelihood of their occurrence.
In the same vein, Sean Cleart and Thierry Malleret consider two essential elements for
measuring risk: 'Risk is generally quantified by considering two elements: the
probability of an event occurring and its impact if applicable _usually expressed
in terms of financial impact and opportunity cost.28
The optimization of risk management assumes the existence of a reliable assessment system.
and relevant. A good assessment of a risk takes into account its different nature and
its specificities compared to other risks. Not all risks are the same, a
an effective risk management system is therefore based on understanding the extent of
each of them, the circumstances under which they can emerge and their
possible consequences.29
A projection of risk over the time horizon to measure the degree of exposure
The devices and available means intended to address undesirable events
which could develop
A unique risk assessment scale tailored to the specificities of the company
used to assess exposure to risk
A benchmark allowing the company to have a point of comparison and a measurement tool.
of his performance.
27 Hugues Angot, Christian Fischer, Baudouin Theunissen. "Accounting Audit, IT Audit". Edition: 3
De Boeck University, 2004. p 304
Seán Cleary, Thierry Malleret Collaborator Klaus Schwab, "Risks: Perception, Evaluation, Management".
Editions Maxima. 2006. 253 pages
29 Seán Cleary, Thierry Malleret Collaborator Klaus Schwab, "Risks: Perception, Evaluation, Management."
Editions Maxima. 2006. 253 pages
23
3.4.4 The criteria for risk assessment
[Link] Detectability
Detectability D represents the organism's ability to detect and identify risks.
[Link] Gravity
The gravity (or effect) G gives an indication of the possible damage and consequences in case
of the occurrence of the accident/incident.
[Link] Mastery
Mastery M represents the organization's ability to manage and control risk. This
mastery can be understood in terms of two parameters: the awareness or non-awareness of the risk thus
whether the existence or non-existence of barriers.
Therefore, measures will be taken to limit the occurrence of these risks or in any case
to limit the adverse effects: we will therefore apply standards, procedures,
24
will approve, will authorize, will verify, will reconcile, will appreciate everything that needs to be or rather
everything that is worth it. Control activities thus represent the third level.
of the rocket.30
There are many types of control activities, whether they are control activities aimed at
prevention or towards detection, manual or computer checks or also controls
hierarchical. Among the control activities, we can highlight:
30 Étienne Barbier. "BETTER PILOT AND BETTER USE OF AUDIT". Maxima Editions, 1998. p 124
25
Part (2): Computer-Assisted Internal Control
In the beginning, the role of computing was primarily to perform very calculation operations.
complex tasks that the human brain could not perform with the speed and precision of
the computer. Thus, the evolution of the computer depends primarily on the evolution of its
computational capacity. A computer is primarily an execution tool, it translates the data
inputs based on a user-programmed model in order to achieve a
precise result.
The notion of computer assistance constitutes a break with the conceived idea of the
function of this tool. From now on, the software application has a new role: to guide and
assist the user in completing a task or any activity.
Assist31:
26
assembly, audience.
and to transmit it to a mechanism
Assisted: Tech. Equipped with an assistance device. Power steering. Assisted braking.
The set of definitions that exists for the verb 'assist' or the word assistance repeats
always keywords such as support, presence, and the assistance system. These words
generally summarize the purpose and objectives of the Internal Control concept
Computer Assisted.
1.2.1 Assist and guide the user in their process of Internal Control
Internal control software has the primary objective of assisting
the internal auditor or the head of internal control of a company to carry out its mission
audit in the best possible conditions. Most of these software have as a point
the existence of a pre-established database that is well-suited to the sector
of the company's activity or the area of control. This adaptation allows the auditor to
situate each time in relation to a reference or a listing of regulatory standards.
Especially with the existence of multiple fields and areas of control application.
internal.
27
1.2.2 Ensure the sustainability of the internal control approach and
these devices over time
Assisted internal control provides the auditor with a selection of features.
which allows him to save and archive all of his work done during his
audit mission. These saved data can be used and exploited in the suite
control work and the implementation of an action plan. Moreover, they can serve for
the future inspection missions. In fact, no internal control document is damaged
You lost. Also, the auditor has the option to review the history and development of
risk and control indicators over multiple periods.
The entire system of solutions motivates internal control actors to expand and
ensure the continuity of the internal control process. This is not the case for SMEs
currently in the case of a check not using this tool. The latter do not
lacking the human and material resources to ensure the sustainability of control
intern within the organization.
sector, statistical documents,...) then it allows their connection with an activity or a task
data.
28
1.3 Internal control software on the market
The software Main clients Features Strengths
VALDYS Taitbout Group Documentation and formalization Strong modeling capacity
Manage and model the Mut'Est processes and risks Ease of use
control internal and The consulting firm Formalization of the reference frameworkVery fine granularity
master the risks R & B Partner control •Compliance with Solvency II and
operational AXIEM Crossing of points requirements of the ACAM
control with the processes Configuration according to the profession of
Generation of tables the company
control and documents
of audit
Traceability of internal control
Action plan and monitoring
results
Frontcontrol The post Mapping of internal control Compliance with the law
=Ensure consistency of Groupama bank Generation of forms Sarbanes Oxley and the Law of
control device Macif control Financial Security
internal and the mechanisms PSA Finance Bank Information gathering Assistance in writing the report
self-evaluation) Identification of action plans of control
and update of the mapping Evolutive
Reporting
Enablon Internal Control Auchan Evaluation of controls Compliance with the law
A management solution IONIS Testing Sarbanes Oxley and the law of the
and control piloting Reporting financial security
internal considered as Capitalization and sharing of Assessment grids
one of the solutions of analysis work customized to the profiles of
market reference. A centralized repository entities
A management and monitoring module ease of use, its
operations architecture
29
Dashboards •its decentralized management and its
Dynamic cross-analysis of multilingualism
procedures
ISIMAN French Agency of Connection control and risk Enter the results of the
=> create a repository of Development your objective offline mode checks
internal control and the AGIRC-ARRCO Definition of controls and then import them into
deploy within Management Bank level 1 and 2 a single operation in the
the company Edmond of Orchestrate the distribution of database
Rothschild Monaco control sheets over time Compliance with Basel II
(BGER) and in the organization Solvency 2 and ACAM
• Group Credit allow the controls of Ease of use and
Mutual: Federal controls compatibility with Windows and
Finance Form of the Lunix
Group Malakoff recommendations and actions
Médéric follow-up
IRP Auto
PRO BTP
30
2 Advantages and limitations of Assisted Internal Control
Computer
2.1 The Contribution of Computer-Assisted Internal Control
Specifically, to understand this advantage, we need to go back to the function of assistance and
auditor's orientation. Computer-Assisted Internal Control benefits from a base of
reference in accordance with the standards and legislation in force related to a given industry
(example: nuclear industry, insurance and mutuality, distribution, etc.) and which replaces the
automatic recourse to manual documentation (books, internal documents, internet,
etc.
31
2.1.3 The automatic generation of control documents
The automatic generation of certain basic documents for the execution of a mission of
Internal control is a key function and a necessary condition for clients of this type.
software. This automatic generation of documents allows for selection, sorting, and a
extraction of data related to a document concerning a specific step of the process
internal audit. Immediately, the application injects this data into the document to be generated in
avoiding in this way to perform search and calculation operations manually.
Thus, the developers have made great efforts to automate the generation of a
a considerable number of audit documents, among which I highlight:
Audit sheets
Risk mapping
Dashboards
Action plans
Control tables
Internal control report
Audit tests ...
in operation between different levels and stages of control, thus allowing the auditor
to correct the design and estimation errors made previously (for example
crossing of control points with control tasks
This function characterizes some of the most efficient software on the market. The choice of
Putting this option in an application requires a lot of vigilance and effort.
of programming. Also, the introduction of this option requires the user to
particular precision in the choice and establishment of its internal control terminology
in order to overcome the risk of confusion and misinterpretation by the program
computer science.
32
he only needs limited knowledge to share all the relevant data
in a few minutes.
Among the advantages of sharing data between different cells within the same structure
or between several structures:
The complexity of the current regulations and legislation at the national, European, and
international requires auditors to adhere to strictly defined standards and at the same time
time to comply with a number of internal audit practice standards.
The entire internal control software is in compliance with one or more laws in
the field, such as:
33
Solvency II
COSO
Bale II
These software programs require or compel the user to comply with a specific standard or law.
limiting the user's leeway or prohibiting certain modifications that do not
are not in compliance with industry regulations.
34
seem insignificant compared to the others. Indeed, this option allows to detect
Risks considered acceptable but which turn out to be very significant after the rating phase.
Example:
from 1 to 5
C = D*G*C
The computer does not recognize then an evaluation of D=6, G=5, and C=3 is launched with a message
of error
The calculation of criticality is automatic only if the evaluation criteria are respected.
choose.
Law No. 2003-706 of 1heAugust 2003 said Financial Security Law imposes on the president of
Board of Directors or Supervisory Board to report, in a report
attached to the annual management report, the conditions for the preparation and organization of the work
of the board, as well as the internal control procedures implemented by the company33.
Initially applied to all public limited companies, the obligation to establish this report has been
then limited to only public companies making a public offering.34.
The internal control report allows the company to have a real picture of the degree of
maturity of its controls and thus address the associated risks. Control software
interns provide an effective way to minimize costs and completion time of
report.
•Collect and sort all the necessary information for the preparation of the report by
referring to the already existing database.
33 Article 117 of the law amending articles L. 225-37 and L. 225-68 of the commercial code
Law No. 2005-842 of July 26, 2005 for confidence and modernization of the economy (Breton law)
35
Give the user the choice to include or not a number of elements in the report.
according to the importance of the latter for the regulatory bodies
Automate the calculations and formatting of the obtained results
Allow an automatic update of the report after each modification
Allows for a general idea of the progress of the work at each stage of completion.
of the report.
In this context, the added value of Computer-Assisted Internal Control is the ability to
update the data automatically without having to redo the same work
with each new audit mission and to document the periodic changes using the
software. Furthermore, it allows for tracking and observing the evolution of risks
and real-time controls. In this way, the user can modify the characteristics
of a risk or a control point whenever the situation requires it. This option
lightens the auditor's workload as it allows the effort made throughout the year to be shared and
thus avoids a buildup of work over a particular period.
36
users tend to give up on a number of findings or observations in the
measure where they are unable to integrate them into the computer system.
Thus, users will be required to comply with the audit method proposed by the system.
and to abandon any appropriate approach to the auditor or already used by the company in
the previous missions.
This knowledge is not limited only to the application of internal control but must
also focus on other tools such as office tools, database management
and the architecture of computer networks. In fact, most internal control software
calls on other external resources to feed and perform calculation operations
Example: Word for document generation, Excel for complex calculations and the
graphics, Access or MySQL for database management, Internet Explorer for
reading HTML pages.
37
Application installation errors on a computer and errors of
settings
Errors in defining access and modification rights
Non-compliance with certain network security standards
The large part of his problems is explained by the novelty of these software on the
market. Thus, developers are always on the lookout to correct these flaws
computer science through regular updates as part of software development or
following a user report. However, the older solutions on the market
always benefit from a step ahead of others thanks to experience
accumulated in this field.
2.2.4 Dependence
The use of Computer Assisted Internal Control never replaces analytical thinking.
and the listener's critique as well as their rationality in risk assessment. It calls upon
also to his creative capacity and his instinct as a listener. However, the continued use and
The permanence of this tool can stimulate a relative dependence on this tool and then lead to a
notable influence on the choices and analyses of the listener.
In addition, the existence of an initial database related to the nature of the company's activity
implies a tendency of the user to adopt ready-made solutions instead of making the effort
from a structured analysis. However, the pre-existing solutions in the database do not
do not always apply to the audited organization.
In reality, it is only the first few months that take up a lot of time because
It is a period of adaptation and design. After this phase, the acceleration of
the implementation procedures are remarkable, the phases of risk analysis of
development of control activities and monitoring of action plans takes less than
38
time. The evolution of the implementation of Computer-Assisted Internal Control in the axis
time follows an exponential curve.
Progress
of putting into
CI square
Phase 3
Phase 2
Phase 1
Weather
39
3 Case study software Valdys
3.1 Software Presentation
From now on, insurance companies and mutuals (company, mutual or institution of
Insurance) are subject to strict regulations that require them to have knowledge.
particular in internal control and complete mastery of operational risks including
financial risks. Indeed, the second pillar of the Solvency 2 directive requires companies
of the insurance sector to implement internal control and management actions
risks that require the use of a structured methodology and know-how
innovative in internal control.
Valdys allows for the implementation of the internal control framework by describing and
by formalizing the processes and risks within a structuring approach integrating the
specificities of insurance professions (property and casualty, health, provident, retirement, ...). Also, he
integrate the risk assessment function, identification of control points and their
intersections with the company's processes. It allows for the generation of control tables.
internal and audit documents (control sheets, test sheets, audit schedules,
summary tables) as well as all the deliverables required as part of the control
permanent of the ACAM.
On the other hand, it allows the dissemination of the internal control framework and its implementation.
The features of this tool are generally the objectives concerning Assisted Control.
by Computer to know:
[Link]
40
The backup and archiving of results obtained at a given time for the purpose
of the traceability of the approach
The automatic generation of a set of audit documents and the report of
internal control
Compliance with the constraints related to Solvency 2
The economy of material and human resources
Online assistance and technical and professional support
Depending on the needs, Valdys can be installed as a thick or thin client. Another advantage is its
compatibility with all market databases (Access, MYSQL,…).
On the other hand, some failures of this software have been raised:
41
3.2 The architecture of Valdys
Overall, the software is designed in the form of a tree structure consisting of several
levels. Each level presents a particular viewpoint on the internal control system
configurable according to the control phase to be carried out. The information generated during
The use of Valdys is recorded in a modeling database represented by a or
several files.
CI database
The first level of structuring the modeling base is the Project. It is possible to
model different projects within the same database. A project is a homogeneous set.
of viewpoints and aims to achieve the defined objectives of internal control. It is the level
the highest level of the design of an internal control system. It consists of a or
42
several viewpoints deemed relevant for structuring the control framework
internet36It is possible to model different projects within the same database.
The Points of View allow for the expression of different complementary dimensions:
43
3.3 The Internal Control project according to Valdys
It is the overall vision of the company's profession with a homogeneous breakdown and
coherent according to these different missions. The breakdown of the company's activity
proposed by Valdys concerns 3 major categories (Pilotage mission, Core mission
profession and mission Support, according to ISO 9000 standards
•The management or steering processes: they outline the way in which the
The company's management practices its steering and governance policy.
Business realization processes or business processes: these processes deal with the
functioning of producing a product or service by breaking down
the sequence of operational activities in several phases.
Support processes: they allow representing the resources needed for implementation.
business process work.
39
See annex (2)
40
See appendix (4)
44
[Link] The Flowchart41
The third level of vision of the procedures is the Flowchart "Diagram representing a
process implemented to ensure a mission42».
Macroprocess
Phase diagram
Flowchart
After the definition and modeling of procedures, the auditor begins the phase
of identification and risk assessment. First, it is necessary to share the risks into risks
exogenous and endogenous risks:
41
See annex (4)
42 See appendix (1)
43
See appendix (1)
45
Exogenous risks are risks originating from outside the company (for example: the
natural disasters, power outages, etc.)
Endogenous risks are the risks related to factors triggered within
the company (internal fraud, data entry error, misinterpretation of a law text by
the staff, etc.).
The establishment and analysis of procedures is a preparatory step for identification and
the assessment of risks. Valdys's logic allows us to deduce risks by analyzing the
goals to achieve and the regulatory constraints to respect. These risks generally are
produced within the framework of carrying out the company's activities. Thus, the modeling
the risks under the term 'risk tree' are as follows:
44
See appendix (5)
46
Aware of the strategic importance of this phase, Valdys allocates a lot of resources and
resources for risk assessment. First, to assess the criticality of a risk
Valdys integrates 3 factors into the calculation function:
Frequency F (from 1 to 5)
Detectability D (from 1 to 5)
Severity G (from 1 to 5)
The calculation formula for criticality is: Criticality = Frequency * Detectability * Severity
In some cases, the auditor is led to take into account the significant weight of one of the
previous factors. To do this, Valdys allows changing the calculation formula to another one.
for example (C=F*G², F*G, G^4*F²*D).
Then, Valdys also allows for detailing the assessment of Severity by breaking it down into
several impacts of different natures (financial impact, customer impact, image impact, impact
supplier, ...)
Finally, the software allows the generation of risk maps. Once the risks have been rated, it
It is possible to generate a risk map graphically representing the risks and
45
their importance. For this, all the risks of the Risk Tree do not need to be
necessarily slanted. It is possible to generate a risk mapping for a single tree of
risks for both or for all the trees present in the "Risk Tree" model or
for all the risk trees of a project
For each major or minor risk, Valdys allows for the identification of one or more elements of
mastery
Corrective action
Preventive action
45
Annex (3)
47
Checkpoint
Each element of mastery must correspond to a control task present at the level of
Logigrams. This operation of linking between points and control tasks is called
risk crossing process. A subsequent generation of control tables
will allow us to detect failures in the internal control system within the company
the risks for which there is no corresponding control task.
Valdys allows for the planning and implementation of action and control plans, to carry out
control evaluations and follow-up on recommendations. In this context, it has
several tools and means:
The control sheet: it describes how risks are taken into account.
level of processes (operating mode, responsible person, frequency of control, etc.) in
the aim of mastering the risks of the profession.
The Control Panel: it allows to synthesize the reconciliation between the risks,
the control points and processes; and this, in order to identify the gaps.
The evaluation schedule: it indicates, for a given period, the list of audits to be conducted.
bring and the corresponding workload in order to plan effectively the
evaluations.
The internal control report summarizes all the information integrated into Valdys.
by organizing them in a coherent and homogeneous manner. The internal control report is
specifically intended for supervisory authorities such as the ACAM - Control Authority of
Insurance and Mutuals.
48
In this context, Valdys allows for the generation of an internal control report in the form of a
file in Word format. The script uses the entire available database and the
information recorded by the auditor to generate an internal control report. The
The final structure of the internal control report is modifiable according to the user's needs.
Thus, the auditor decides whether or not to include a certain number of pieces of information in the
The generation of a website is a very useful feature for dissemination and sharing.
Information sharing among staff. All the work done on modeling procedures
until the report generation is fully accessible. This generated website can be
consulted and integrated into the company's intranet or into an extranet network. The users
having administrator rights have the option to prohibit and secure access to elements
confidential.
46
See annex (8)
49
Conclusion
The three axes of this thesis demonstrate the important role of Assisted Internal Control
Computer for organizational management and risk control processes. Acceleration
of processes, cost efficiency related to control operations, consistency of approach
Among auditors, indeed the added value of this tool is becoming increasingly remarkable.
However, we must not ignore the importance of the failures observed and deduced during
our analysis of the concept and particularly in our case study especially concerning the dimensions
techniques and mastery of software tools. Moreover, it is still too early to bring a
negative judgment due to the aforementioned drawbacks. Particularly because our analysis
focused on a single software (Valdys) and also referring to other resources
documentaries. To generalize our study, it is necessary to involve other software in the analysis
and other users. This analysis must be subject to practical and technical tests carried out
by the actors and experts of internal control and the publishers and designers of these solutions
of management. A combined effort among all these parties can contribute to development
and to the improvement of Computer-Assisted Internal Control.
50
Bibliography:
Frédéric Bernard, Rémi Gayraud and Laurent Rousseau, "Internal Control", [Link],
Paris, 2006, p 303
•CNCC Standard 2-301, risk assessment and internal control", paragraph 08, Framework
normative CNCC, 2003
• Coopers & Lybrand, "The new practice of internal control", Organization Edition,
Paris, 1994, p 378
Kamal ABOU EL JAOUAD, "The stakes of internal control" University of Clermont
Benoît Pigé "Audit and Internal Control", Ed EMS, Paris, 2001, p210
Alain-Gérard Cohen, "Internal Control and Public Audit"
Universal Encyclopedic Dictionary. Precise Edition 1998. P1383
Ernst&Young. "Developing a mapping of operational risks, within the framework of
requirements of the future Solvency II directive
Hugues Angot, Christian Fischer, Baudouin Theunissen. "Accounting Audit, Audit
computer science. Edition: 3 De Boeck Université, 2004. p 304
Seán Cleary, Thierry Malleret Collaborator Klaus Schwab, "Risks: Perception,
Evaluation, Management
Étienne Barbier. "BETTER PILOTING AND BETTER UTILIZATION OF AUDIT". Maxima Editions,
1998. p 124
•Universal encyclopedic dictionary. Exact edition 1998. P1383
Webography:
• [Link]
• [Link]
• [Link]
uuQQ
• control
• Invalid input, no translatable text provided.
The provided text is a URL and does not contain translatable content.
• Unable to access or translate content from external links.
• Unable to access the content of the provided link.
• Unable to access external links.
• Invalid input. Please provide text for translation.
• to attend
• The provided text is a URL and does not require translation.
51
Annexes
52
1 Appendix (1): Valdys Glossary
53
54
Annex (2): the Macro-process
55
3 Annex (3): Risk Tree
56
Annex (4): Phase Diagram and Flowchart
57
Annex (5): Risk Family Tree
58
6 Appendix (6): The nomenclature model and the model
structure diagram
59
7 Annex (7): The tree model of roles/skills and
the mapping of risks
60
8 Appendix (8): The Html pages
61