0% found this document useful (0 votes)
9 views61 pages

Computer-Assisted Internal Control Thesis

This Master's thesis in Financial and Operational Audit examines Computer-Assisted Internal Control through a case study on the VALDYS software. It addresses the conceptual framework of internal control, its definitions, as well as the advantages and limitations of automation in this field. The objective is to analyze how this type of control can facilitate the implementation of internal processes in companies.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
9 views61 pages

Computer-Assisted Internal Control Thesis

This Master's thesis in Financial and Operational Audit examines Computer-Assisted Internal Control through a case study on the VALDYS software. It addresses the conceptual framework of internal control, its definitions, as well as the advantages and limitations of automation in this field. The objective is to analyze how this type of control can facilitate the implementation of internal processes in companies.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

ROBERT SCHUMAN UNIVERSITY

Strasbourg School of Management

Master Financial Audit

AND OPERATIONAL

2008-2009

Thesis Subject:

Computer-Assisted Internal Control


Case study: VALDYS

Mohammed EZ-ZOUAK
ROBERT SCHUMAN UNIVERSITY

Strasbourg School of Management

Master Financial Audit

OPERATIONAL

2008-2009

Subject of the Thesis:

Computer Assisted Internal Control


Case Study: VALDYS

Mohammed EZ-ZOUAK

Internship organization: Sochaux Company Mutual

Thesis Supervisor: Pr Pierre SCHEVIN

Internship Supervisor: Ms. Roselyne PATOIS (head of the mutual health insurance)

2
THANKS

This thesis for obtaining the M2 degree in Financial and Operational Audit is the result
of a considerable effort. This effort could not have succeeded without the contribution of several
people. Thus the opportunity arises to thank them: First of all,

To Pr Pierre SCHEVIN, The Director of this thesis during this internship for his availability
and his advice

To Ms. Roselyne PATOIS, Head of the 'Sochaux Company Mutual' service,


my professional supervisor for their total commitment and very constructive advice

To Ms. Nathalie De STEUR, IT manager at the MES, for her assistance and her
instructions.

Without forgetting all the staff of the Mutual without exception for their moral support and
educational during the 2 months of this internship

And finally, my parents, my family, and my brother-in-law for their moral and financial support.
during this year of studies

3
Introduction _______________________________________________________________ 6
Introduction to internal control
1 Conceptual framework of internal control _______________________________________ 9
1.1 Etymology of the word_______________________________________________________ 9
1.2 Definitions of internal control _____________________________________________ 9
1.3 The COSO model _______________________________________________________ 11
1.4 Sarbanes Oxley_________________________________________________________ 13
1.5 The Financial Security Law (LSF) _____________________________________ 14
1.6 Comparison between the Sarbanes-Oxley Act and the Financial Security Act_______ 15
2 The process of internal control__________________________________________ 16
2.1 Definition and characteristics of the internal control approach _______________ 16
2.2 Analysis of some models of the internal control approach _______________ 17
3 Classic approach adopted by internal control software publishers _______ 19
3.1 Identification of processes
3.2 Declination of the strategy into objectives _____________________________________ 20
3.3 Process analysis ___________________________________________________ 21
3.4 Risk assessment ___________________________________________________ 22
3.5 Implementation of control activities
Part (2): Computer-Assisted Internal Control____________________________ 26
1 Introduction to Computer-Assisted Internal Control ______________________ 26
1.1 The concept_____________________________________________________________ 26
1.2 The objectives of Computer-Assisted Internal Control______________________ 27
1.3 The internal control software on the market _______________________________ 29
2 Advantages and limitations of Computer-Assisted Internal Control ________________ 31
2.1 The contribution of Computer-Assisted Internal Control _________________________ 31
2.2 The limits of Computer-Assisted Internal Control _______________________ 36
2.3 The keys to success of a Computer-Assisted Internal Control project ______ 39
3 Valdys Software Case Study______________________________________________ 40
3.1 Presentation of the software __________________________________________________ 40
3.2 The architecture of Valdys_________________________________________________ 42
3.3 The Internal Control project according to Valdys__________________________________ 44
3.4 The documents generated internally by Valdys _______________________________ 48
50
Annexes__________________________________________________________________ 52
1 Annex (1): Valdys Glossary _____________________________________________ 53
2 Annex (2): the Macro-process _________________________________________ 55
3 Annex (3): Risk Tree____________________________________________ 56

4
4 Annex (4): Phase Diagram and Flowchart ___________________________ 57
5 Annex (5): Risk Family Tree ___________________________________ 58
6 Annex (6): The nomenclature model and the structure diagram model _______ 59
7 Annex (7): The role/competency tree model and risk mapping _ 60
8 Appendix (8): Html pages_____________________________________________ 61

5
Introduction

The automation of information processing dates back to the invention of the first
computer. Since then, all branches of science and industry have tried to exploit the
huge capabilities of this tool, especially those for calculating and processing data with a
unimaginable speed that surpasses the limits of the human brain. It is then that the economy and
finance was among the sectors that were able to benefit from the advantages of automated processing
some information.

The miniaturization of components and the reduction of production costs, combined with a
increasingly urgent need for processing all kinds of information (scientific,
financial, commercial, etc.) has led to a spread of computing in all
layers of the economy as well as of everyday life.1

After accounting, finance, and financial auditing, today, it's about internal control.
to integrate into the world of automated information and fully benefit from the contributions of
computer science in this field. In this perspective, the "Internal Control Assisted by
Computer » marks current events by its contribution to the internal and external auditor as a tool
of assistance and management of control missions.

Until today, no one has been able to perceive that a field as abstract and evolving as the
internal control whose reflection (risks) and development (control points) play a
a crucial role would call for the services of IT. However, the symptoms of this
The new wave of software solution providers for businesses has already been felt. These
editors of management software applications and in the face of intense competition in the
software market was able to adapt to overcome the barrier of limited knowledge in the
management areas. For them, the solution is to offer software that allows
to help and assist the auditor in carrying out their internal control mission by
maximizing its expertise and its analytical and observational abilities in a
specific domain (insurance, energy, nuclear industry,...) then cross-referencing it with the
practices recognized by auditors in the sector and the regulations in force. Indeed,
the observed difference between the existing and the conceptual is at the base of the results and the
obtained interpretations.

1
[Link] on 02/17/2009

6
2
Several audit and internal control software packages exist on the market, a set of
diversified choice of management IT solutions to manage control processes
internet and ensure compliance with regulations (Financial Security Act, law of
Sarbanes-Oxley, Basel II, Solvency II, etc.). Among these products, FrontControl is highlighted. 3,
Enablon Continuous Assessment4ISIMAN5and finally VALDYS which will be the subject of a study
of cases in this thesis. All these solutions are based on the same principle by constituting a
reference base for internal control of a given sector for the auditor and in assisting them in
his approach to establishing and monitoring the internal control process.

In this thesis, I will attempt to address and analyze the following issue:

To what extent can Computer-Assisted Internal Control contribute to


the framework and acceleration of the establishment of an internal control process
in a company?

To answer this question, my analysis will focus on the following two parts:

The first part will focus on the conceptual framework of internal control where I will present
the different definitions of internal control, the approaches and the regulations that
frame this sector and finally describe the process of establishing a system of
internal control. This section is a crucial part for better understanding the two
axes that will follow.

In the second part, I will address the crux of the issue where I will analyze the contribution.
of Computer-Assisted Control on several dimensions: the originality of the concept,
the contribution of computer-assisted internal control and lastly I will address the
limits of this concept. The second axis of this part of the thesis is a case study of
VALDYS software (French software for internal control developed to meet the needs
of insurance companies and mutuals). This case study aims to illustrate the conclusions
and the results obtained.

2
Product and software contraction
3
[Link] February 17, 2009
4
[Link] February 17, 2009
5 [Link] the
February 17, 2009

7
The objective of this thesis with its two parts is to address the problem raised in
moving from a conceptual framework to an empirical framework. The type of argumentation used is
an argumentation by illustration. This argument consists of using a concrete example
justifying a statement that we make. In other words, we will formulate the problem, then
we will present a specific and real fact or case that embodies and materializes the deductions
obtained.

For the same purpose of illustration and argumentation, several documentary sources will be
shared used among bibliographic sources, webographic sources, and documentary databases
electronics.

8
Part (1): Introduction to Internal Control

1 Conceptual framework of internal control


1.1 Etymology of the word
The word control comes from the word counter-role which means 'a record kept in duplicate.' 6. In its

In the book 'Internal Control', Frédéric Bernard distinguishes between the French word
"Control" and the Anglo-Saxon word "Control":

The term internal control is the literal translation of the Anglo-Saxon expression: Internal
Control (or Business Control for Americans) in which the verb 'to control'
means maintaining control of the situation whereas in French the word 'contrôle' is
better understood as the act of exercising surveillance over something
to evaluate it7.

Despite the etymological and phonetic resemblance of the two French and Anglo-Saxon words,
we find that the term 'internal control' reflects the upstream and preventive aspect of the process
internal control through monitoring measures and risk analysis regarding the word
Internal Control translates the downstream and corrective dimension of internal control.
identification of control elements, planning of control tasks, organization of
responsibilities, following up on recommendations, etc.). This divergence of meaning between the two
words reflect and explain the subtle difference in the way of practicing and implementing
the internal control process between French companies and Anglo-
Saxons.

1.2 Definitions of internal control


There are various definitions of internal control. This multitude and diversity of definitions of
the concept generates a confusion in understanding and communicating the roles of each
major player in internal control (internal and external auditors, Board of Directors, the
direction, the staff and the legislator). Among the adopted definitions of internal control by
the authors and the national and international institutions, we find:

1) Internal control is a set of mechanisms aimed at ensuring, on one hand, the


protection, the preservation of heritage and the quality of information, on the other hand

6
[Link] on 19/02/2009
7 Frédéric Bernard, Rémi Gayraud and Laurent Rousseau, "Internal Control", [Link], Paris, 2006, p. 303

9
to ensure the application of the instructions from Management and to promote improvement of
performances.8
Definition given by the accountants, at the congress in 1977: "internal control
is the set of securities contributing to the management of the company. Its purpose is
to ensure the protection, safeguarding of heritage and the quality of information of a
part and on the other hand, the application of the management's instructions, and to promote
the improvement of performance.

3) The definition proposed by the CNCC (National Company of Auditors)


Accounts) best reflects the modern approach to the concept: "Control procedures
internal involves: adherence to management policies, safeguarding assets,
prevention and detection of fraud, the accuracy and completeness of records
Accountants, the timely establishment of accounting and financial information
stables.9
4) The definition given by standard 400 of the IAASB (International Auditing and)
Assurance Standard Board: the internal control system is the set of
policies and procedures implemented by the management of an entity to ensure,
to the extent possible, the rigorous and efficient management of its activities. These
procedures involve compliance with management policies, the safeguarding of assets,
prevention and detection of frauds and errors, completeness of records
accountants and the timely establishment of stable financial information.
The definition given by the Coopers&Lybrand firm and translated in 'the new
"practice of internal control" by the French Institute of Auditors and Consultants
Internal: Internal control is a process implemented by the Board
of Administration, the leaders and staff of an organization, intended to provide
a reasonable assurance regarding the achievement of the following objectives:
The execution and optimization of operations;
The reliability of financial information
Compliance with applicable laws and regulations10

8
Frédéric Bernard, Rémi Gayraud, and Laurent Rousseau, "Internal Control", [Link], Paris, 2006, p 303
9
CNCC Standard 2-301, risk assessment and internal control, paragraph 08, CNCC normative framework, 2003
10
Coopers & Lybrand, 'The New Practice of Internal Control', Organization Edition, Paris, 1994, p 378

10
The study and analysis of these different definitions distinguishes between two approaches
fundamentals:
On one hand, a classic approach that emphasizes the basic principles of internal control: the
heritage preservation, information reliability, compliance with regulations
and performance improvement. These elements are faithfully reflected in the first and the
second definition without straying from the carefully outlined framework by these components.
This limitation of the scope of interpretation and reaction has made internal control a concept
equipped with a rigid structure that is difficult to adapt to different natures and situations
of companies.

On the other hand, a modern approach illustrated by the last three definitions (CNCC,
IAASB, Coopers & Lybrand). This approach includes the notion of process or procedure.
in its definition and it involves the key players in the internal control process in
this process while emphasizing the role of the staff. Furthermore, it mentions for the
first time the respect of management policy as a main factor in the system of
internal control.

1.3 The COSO Model


The COSO model is an internal control framework defined by the 'Committee Of
Sponsoring Organizations of the Treadway Commission. It is used notably in the
framework for implementing provisions under the Sarbanes-Oxley Act or LSF for the
companies subject to American or French laws. The initial reference
Called COSO 1, it has evolved since 2002 into a second body known as COSO 2.11

1.3.1 COSO 1
Internal control is made up of 5 interrelated elements that stem from the way
the activity is managed and is integrated into management processes:

Control environment: presents the "space" in which people


complete their tasks and assume their responsibilities regarding control. It
serves as a reference for other elements of internal control. It also presents the
individuals and their individual qualities, their integrity, their ethics, their competence.
In other words, the control environment exerts a deep influence on the
structuring of activities and procedures, risk assessment, activities of
control, the information system and the monitoring of recommendations.
11
[Link] the February 22, 2009

11
Risk assessment: it involves the identification and analysis of factors
susceptible to affecting the achievement of the strategic objectives of the company. It is a
continuous and repetitive process that determines how risks should
to be managed. It is up to the leaders and heads of the relevant services.
to assess and set an acceptable risk rate.

Control activities: control activities are the application of standards and


procedures intended to ensure the implementation of management directives in order to
master the real and potential risks of the organization. The categories of operations
Control related to objectives is the operational domain, the information
financial and the regulations in force.

•Information and communication: relevant information must be identified,


collected and disseminated in a form and within deadlines that allow everyone
to assume these responsibilities. The information must concern all levels of
The company. The information system will allow to define, collect, analyze and then
disseminate this data.

•Management: internal control systems must in turn be controlled in order to


to assess qualitative performances over time. In this context, it is essential
to establish a permanent management system and to carry out evaluations
periodicals. Thus, management operations can be carried out either by
current activities either through occasional assessments.

1.3.2 COSO 2
The COSO 2 model constitutes a continuation and a follow-up of COSO 1. Frédéric Bernard defines
and explain the difference between COSO 1 and COSO 2: "... It does not provide a framework for
internal control (as opposed to COSO) but a risk management model. It relies on
on COSO as a framework for Internal Control.12

12
Frédéric Bernard, Rémi Gayraud, and Laurent Rousseau, "Internal Control", [Link], Paris, 2006, p. 303

12
Among the contributions of COSO 2:

On one hand, it provides auditors and internal controllers with a reference for risk management.
of the company (Enterprise Risk Management Framework). Indeed, COSO 2 reminds us of the
elements of COSO 1 and especially complements it on the dimension of 'risk management'. It is
thus based on an approach oriented towards the mastery of business risks. On the other hand,
it presents a more limited framework for decomposing the structure of an organization then
that COSO 1 does not retain a specific decomposition structure. However, this
distribution among different levels of the organization is very useful for the approach of
control proposed by the COSO model. However, it is necessary to take into account
the organization as a whole so that COSO 2 can be successfully implemented.

Presentation of the COSO pyramid and cube13

1.4 Sarbanes Oxley


Following the financial scandals that the United States experienced in the years 2001-2002. The
American legislation has launched new legal devices known as 'Sarbanes-Oxley'.
the law was passed by Congress and was the largest reform of the American financial market
for a long time. Its core principles are the accuracy of information, responsibility
managers and the independence of audit bodies. Its goal is to address the
insufficiencies of internal control.

13
[Link] visited on 03/05/2009

13
The fundamental decisions of this law are:

Financial statements must be certified by the General Director (Chief)


Executive Officer) or the Chief Financial Officer. The purpose of this
the provision is to make leaders accountable for the existing risks in their
companies.
The obligation to appoint independent directors to the audit committee of
Board of Directors
The specific advantages of leaders are increasingly regulated.
The Sarbanes-Oxley Act requires the company to rotate external auditors.
services offered for the verification of financial statements by these external auditors
must be adapted to the company's activity (information systems).14
The tightening of penal sanctions and the amounts of fines in case of fraud
or non-compliance.
The obligation for American companies to attach a report to the annual reports
on internal control. This report established by the company's management must be validated
and certified by the external auditor.

Despite all the efforts made at the level of the 'Sarbanes-Oxley' law to limit the
financial frauds, the assurance that this law provides for the organization remains an assurance
reasonable against the risk since there are always points of failure for
circumvent internal control barriers. Michael Oxley supports this reasoning in
his interview with Liz Alderman: "I won't go so far as to say that the Sarbanes-Oxley Act us
sheltered from a scandal such as the bankruptcies of Enron and Worldcom nor that individuals do not
will not be intelligent enough to circumvent the rules. After all, murder is illegal.
in all countries and yet murders are committed every day.15

1.5 The Law on Financial Security (LSF)


Like the Sarbanes-Oxley Act, the Financial Security Act was enacted following
of numerous financial scandals to restore investors' trust in particular
in accounting practices.

14
Kamal ABOU EL JAOUAD, "The Stakes of Internal Control" Clermont University
15
[Link] visited on 03/15/2009

14
The National Assembly and the Senate have adopted LAW No. 2003-706 of 1 heAugust 2003 on the
financial security in view of decision no. 2003-479 DC of the Constitutional Council dated the 30th
July 2003.16

This law applies to all public limited companies. It includes the obligation for the
Chairman of the Board of Directors or Supervisory Board to report in a
report on the control procedures implemented by the company. It also considers that
the establishment of a report on internal control is a key factor for competitiveness and
the development of private enterprises.

1.6 Comparison between the Sarbanes-Oxley Act and the Financial Security Act
The fundamental distinction between the Financial Security Act and the Sarbanes-Oxley Act is
the degree of formality that is clearly defined in the second law. Thus, reference frames
such as COSO provide a precise framework for internal control actors. However, this
is not the case currently for the Financial Security law. The major obstacle for
this is the non-existence of a French framework that governs the work of auditors. The LSF
does not refer to any reference framework and does not even provide a definition of 'internal control'.

Also, the Financial Security Law is less demanding than the Sarbanes-Oxley Act and by
consequently, it allows to adjust the level of formality of Internal Control in relation to the
size of the company, however it complicates the work of the Auditor.

Currently, there are no new legal provisions on internal control of


French public limited companies. And the national company of statutory auditors does not
no new instructions given regarding the control by the legal auditors of the report
from the President on internal control.

The LSF engages all public limited companies. Its scope is broader than that of the law.
Sarbanes Oxley which is limited only to publicly traded companies. It directly involves the
Chairman of the Board of Directors or Board of Supervisors while the Sarbanes Act
Oxley engages the operational management. Finally, the LSF concerns all procedures of
internal control while the Sarbanes-Oxley Act only concerns information
accounting and financial. The European model defending every shareholder of companies
Anonymous opposes the American model that only cares about company shareholders.
making a public appeal for savings.

16
[Link] visited March 15, 2009

15
The approach of internal control
2.1 Definition and characteristics of the internal control approach
Internal control, unlike financial auditing, does not have a limited scope of intervention, it
concerns all types of risks that may exist in the company (Financial risks,
human risks, technical risks,…). Its main objective is to safeguard heritage.
of the company and to establish a control system.

Internal control is no longer an unpredictable process that happens day by day, nor is it a
ready-to-wear solution applicable to all companies without adaptation to contexts,
the environment and the specific structures of these.

On the contrary, the internal control approach is an organized, appropriate process, and
sustainable. Specifically, it is a process of change:

2.1.1 An organized approach


The implementation of an internal control system must be organized within a time framework.
schedule interview dates with managers and staff, set the dates for
control and monitoring, respecting periodic control dates, etc.) while ensuring compliance
the order of control operations and the scheduled duration for each step. Also, this
the setup must always be preceded by a preparation phase that includes the study of
the company's environment, the determination of the scope of the review and the arrangement
resources and means to ensure the success of the mission.

2.1.2 An appropriate approach


The extent of the control perimeter as well as the importance of human resources and
The material assets to invest in largely depend on the properties of the audited company. The size of
this one, the complexity of its organizational structure and the performance of its governance
and its management determines the characteristics of the control mission. In
As a consequence, the nature of the mission and its attributes can vary from one company to another.
However, the foundations of the approach will remain the same.

2.1.3 Sustainable Approach

The establishment of control points, preventive and corrective processes, is carried out in
a continuity perspective of the approach over time. It takes place in a perspective of

16
sustainability of the activity and the life of the company. Clearly, the internal control approach
is a medium and long-term approach.

2.1.4 The change and the break with the past


In the context of the internal control process as in any systematic approach
In business, change is a concern or at least a fundamental topic of
discussion17

The change in this context means the acceptance by the stakeholders of the company that a
unavoidable and radical change in the internal organization and functioning of
The company is likely to occur. However, any act of refusal or resistance to this
the process of change is a human and expected phenomenon.

The planned changes concern the tools and work techniques (use of
new software), management methods (transition from hierarchical management to a
participatory management) and the values of the company (transforming a culture of closure and
segmentation into a culture of openness and sharing.

The management's ability to implement this transformation in operations and


the organization of the company's staff will have a very positive effect on the process of
internal control. Thus, it will contribute to a more rational assessment of risks, a
awareness of the impacts of risks on processes and effectiveness at the level of
the application of recommendations and the establishment of control systems.

2.2 Analysis of some models of the internal control approach

2.2.1 Approach of Benoît Pigé


The internal control approach follows a universal and unique logic recognized by most.
of regulations and laws in force.

Benoît Pigé in his work "Audit and Internal Control" proposes the following approach:

The understanding of the company which includes the comprehension of


the environment (the industry and the economic situation) in which it operates
situated as well as the identification of the company's specificities (the structure
organizational, the strategic policy of the company, the competitive position of
the company and the company's shareholding

17
Frédéric Bernard, Rémi Gayraud and Laurent Rousseau, "Internal Control", [Link], Paris, 2006, p 303

17
The assessment of specific risks that may arise from a financial situation,
of a social situation or internal organizational changes
The evaluation of internal control involves describing the procedures (observation, the...
interviews with company staff and formalization) check the adequacy
procedures to achieve objectives (setting objectives and implementing the
necessary means) to carry out the application and effectiveness tests of the procedures
internal control.
•Perform product validation tests. (sampling, full validation)18

2.2.2 Internal control approach of Frédéric Bernard


Other authors like Frédéric Bernard have broken down the process of internal control into
several phases. However, they kept the same components and the same tools in
level of their approach. The approach proposed by this author is broken down into several
phases

[Link] Analysis phase of the existing and tool development


In this step, two main tools are developed:

Risk mapping19identification of major risks and then a


graphical representation of the vulnerability of the analyzed entity. The mapping
is obtained from the responses of the operators to the analysis questionnaires
risks
The general framework action plan aimed at improving vulnerability to
identified risks

[Link] Operational implementation phase of the Control system


Internal
This phase involves documenting the new tools by writing user manuals and then
to set up training sessions for the operators on the use of these
tools.

We can observe the divergence in form of the two previous methodologies, but one
convergence on the substance.

18
Benoît Pigé "Audit and Internal Control", Ed EMS, Paris, 2001, p210
19
See appendix (7)

18
3 Classic approach adopted by software publishers
of internal control
3.1 Identification of processes

3.1.1 Definition 1
Yvon MOUGIN Consultant and Trainer at Cap Entreprise defines the process as a
set of related resources and activities that transform input elements into output elements
output. In other words, it is a black box that has a purpose (the output data) and that
to achieve this purpose, use external elements (input data) and transform them
by providing added value through work and tools (activities and resources).20

3.1.2 Definition 2
A process is a succession of activities within an organization, linked together in order to
to produce a result. Collaborative work applications can define different
process according to the organization and the tools implemented.21

However, it is important to distinguish between the term process and the term procedure, which means
a specified way of carrying out an activity.

The identification of processes is the first step in the risk management approach.
It helps to understand the jobs within the company and contributes to the sustainability of the
internal control process. The objectives of this phase are to build a clear idea and
structured processes of the activity, to describe the processes and to collect the information
for the identification of risks and the controls planned.

Internal control operations are very connected to all levels of activities of


the organization. All of its activities consist of an indefinite number of
process. "Internal control is not an isolated event or a unique circumstance.
but a set of actions that spread across all the activities of the company.
These actions are perceptible at all levels and are inherent to the way the activity
is managed22

20
[Link] visited on 25/03/2009
21
The link provided seems to lead to a glossary page, but no specific text was provided for translation. visited on 25/03/2009
22 Coopers & Lybrand, "The New Practice of Internal Control", Organization Edition, Paris, 1994, p 378

19
3.1.3 Process Mapping
To implement an internal control process, it is essential first to
know and understand the activities, then define the links and dynamic flows between them
(incoming flows and outgoing flows)

The different levels of granularity in risk mapping are presented in the


following diagram:

Macroprocess
.

Major Process
.

Processus
Activité
Procédure
Pyramid of granularity levels 1

3.2 Implementation of the strategy into objectives


The objectives explain the purpose of the process. They also result from the established strategy.
and are formalized within the framework of the company's management process. Each company
through its management determines the objectives and strategies for the
achieve. They can be set for the organization as a whole or directed towards
specific activities. The overall objectives set at the company level are related to
more specific objectives at the level of 'activities'. The objectives must be clearly
are generally defined and stem from the values of the company and its overall strategy.
These objectives are classified into 3 categories:

Operational objectives: optimization of the use of economic resources


of the company
•Financial objectives: establishing reliable financial statements that present a
faithful image
•Compliance objectives: compliance with laws and regulations
vigour

20
To illustrate the notion of a goal and its characteristics, we can refer to Alain.
Gérard-Cohen, in his work "Internal Control and Public Auditing," discusses the
declination of a reflection by objectives: "...through an organized, coherent reflection,
encrypted, iterative, allowing all choices and trade-offs (including political), in a way
clear and transparent, thus ensuring a realistic optimization of resources
means and resources in response to explicit and prioritized needs.23

Also, it is necessary to determine with significant precision, the human, financial, and
techniques necessary to achieve one's goals. To measure performance results
obtained, there are a multitude of indicators that are defined according to the nature of the objectives and
other factors.

3.3 Process Analysis


The analysis of processes is a major step in the internal control approach.

On one hand, it involves setting the main objectives of the process, raising the factors
success factors of the process and key performance indicators, frame the process by
a beginning and an end.

On the other hand, the analysis of processes must answer the questions: Who does it (role)? What?
(task)? Through what information flow? (support information systems)

The analysis of processes is an operation that requires special attention from the auditor.
since it is at this level that it can foresee the existence of a potential risk or a point
fallible in the process. Thus, the degree of vigilance and precision in the design and
the analysis of these processes will increase the added value of this step in the
internal control process.

Example analysis grid for processes

Process Objectives Factors of Role Indicators Task Systems


success performance information
Level 1
Level 2
Level 3

23 Alain-Gérard Cohen, 'Internal Control and Public Audit', ed LGDJ, PARIS, 2005, p 183

21
3.4 Risk Assessment

3.4.1 Notion of risk


Danger can be measured to a certain extent, which can be more or
less forecast.24

Risk is a potential, identified, and quantifiable loss (stakes), inherent to a situation.


or an activity, associated with the probability of the occurrence of an event or a series
of events.25

Threat that an event, action or inaction affects the company's ability to


reaching one's goals and in particular affects one's performance.26

3.4.2 The identification and the different categories of risk


The risk identification process is carried out from the processes or from a
given nomenclature:

The nomenclature of a risk can be structured into five levels:

Operational risks
Information system risks
Human risks
Legal risks
External risks (exogenous)

Every potential or actual risk must be recorded and studied even if one considers that it is
minimized by an appropriate control device. The risk is divided into 3 categories:

The inherent risk: it is the risk of a significant error occurring in


the organization following a mistake (intentional or not), or a fraud
•The risk of internal control: it is the risk that the control system present in
the company cannot prevent a significant inaccuracy
•Risk of non-detection or audit risk: the risk that the audit does not allow for
detect a significant inaccuracy.27

24 Universal Encyclopedic Dictionary. Precise Edition 1998. P1383


25 [Link] visited on 04/06/2009
26 Ernst&Young. "Developing a mapping of operational risks, within the framework of the future requirements
directive Solvency II

22
3.4.3 Process and characteristics of the evaluation approach
risks
All organizations, regardless of their size, structure, or the nature of their activities and
the economic sector in which they operate, face risks and this at all
the levels. All of its identified risks must be subject to an evaluation based on
the assessment of their potential consequences and the likelihood of their occurrence.

In the same vein, Sean Cleart and Thierry Malleret consider two essential elements for
measuring risk: 'Risk is generally quantified by considering two elements: the
probability of an event occurring and its impact if applicable _usually expressed
in terms of financial impact and opportunity cost.28

The optimization of risk management assumes the existence of a reliable assessment system.
and relevant. A good assessment of a risk takes into account its different nature and
its specificities compared to other risks. Not all risks are the same, a
an effective risk management system is therefore based on understanding the extent of
each of them, the circumstances under which they can emerge and their
possible consequences.29

To develop an effective risk assessment, the company's management must


determine the following axes:

A projection of risk over the time horizon to measure the degree of exposure
The devices and available means intended to address undesirable events
which could develop
A unique risk assessment scale tailored to the specificities of the company
used to assess exposure to risk
A benchmark allowing the company to have a point of comparison and a measurement tool.
of his performance.

27 Hugues Angot, Christian Fischer, Baudouin Theunissen. "Accounting Audit, IT Audit". Edition: 3
De Boeck University, 2004. p 304
Seán Cleary, Thierry Malleret Collaborator Klaus Schwab, "Risks: Perception, Evaluation, Management".
Editions Maxima. 2006. 253 pages

29 Seán Cleary, Thierry Malleret Collaborator Klaus Schwab, "Risks: Perception, Evaluation, Management."
Editions Maxima. 2006. 253 pages

23
3.4.4 The criteria for risk assessment

[Link] The frequency


The frequency F represents the product of a probability and an exposure frequency.
probability corresponds to the forecast that the incident/accident will occur while the
exposure frequency gives an idea of the demand of the mission likely to
provoke the risk.

[Link] Detectability
Detectability D represents the organism's ability to detect and identify risks.

[Link] Gravity
The gravity (or effect) G gives an indication of the possible damage and consequences in case
of the occurrence of the accident/incident.

[Link] The criticality


The criticality (C) encompasses all the preceding criteria. It can be calculated in different ways.
methods. The most common one consists of taking the product of the probability, the frequency, of the
detectability and severity; C = F x D x G

[Link] Mastery
Mastery M represents the organization's ability to manage and control risk. This
mastery can be understood in terms of two parameters: the awareness or non-awareness of the risk thus
whether the existence or non-existence of barriers.

3.5 Implementation of control activities

3.5.1 Definition of control activities


Control activities can be presented as an application of standards and procedures.
which ensure the implementation of the guidelines coming from management. These actions enable
to ensure that the necessary measures are taken with the aim of controlling the risks
susceptible to affecting the achievement of the company's objectives. The control activities are
carried out at all hierarchical and functional levels.

Therefore, measures will be taken to limit the occurrence of these risks or in any case
to limit the adverse effects: we will therefore apply standards, procedures,

24
will approve, will authorize, will verify, will reconcile, will appreciate everything that needs to be or rather

everything that is worth it. Control activities thus represent the third level.
of the rocket.30

There are many types of control activities, whether they are control activities aimed at
prevention or towards detection, manual or computer checks or also controls
hierarchical. Among the control activities, we can highlight:

The analyses carried out by management


Management of activities or functions
Data processing
Physical controls
Performance indicators

3.5.2 Determination of control points and control actions


After the risk assessment phase by combining several elements for the calculation of the
criticality and impact, it is time to describe control points and establish
preventive actions (actions that allow to control the effects of risk before its occurrence)
and corrective actions (actions to control the risk after it has appeared).

Experiences in the field of internal control have shown that actions


Preventive measures are the most effective and they help minimize the cost of risk.
However, implementing preventive actions requires advanced knowledge of
potential risk, of its nature and extent, which is not always the case. Adding to
this, the fact that most major risks turn out to be fatal because of their non
detectability. As for corrective actions, they are more costly since they
intervene after the occurrence of the risk by trying to limit the damage caused by it.
last. The corrective checkpoint remains the most obvious to establish and implement
since it relates, unlike preventive action, to tangible elements of risk.

30 Étienne Barbier. "BETTER PILOT AND BETTER USE OF AUDIT". Maxima Editions, 1998. p 124

25
Part (2): Computer-Assisted Internal Control

1 Introduction to Computer-Assisted Internal Control


1.1 The concept
Today, the integration of computing in all areas of management and in all
the economic and financial sectors is just a matter of time. The industry, the
finance or telecommunications have already realized the need to develop their systems
of information and to place them at the center of sustainable development.

In the beginning, the role of computing was primarily to perform very calculation operations.
complex tasks that the human brain could not perform with the speed and precision of
the computer. Thus, the evolution of the computer depends primarily on the evolution of its
computational capacity. A computer is primarily an execution tool, it translates the data
inputs based on a user-programmed model in order to achieve a
precise result.

The notion of computer assistance constitutes a break with the conceived idea of the
function of this tool. From now on, the software application has a new role: to guide and
assist the user in completing a task or any activity.

To try to clarify the notion of computer-assisted internal control, it is necessary to explain


first the notion of assistance:

Assist31:

Vto assist (from Latin assistere, to stand by)

1. Provide help or assistance to someone: The town hall assists families.


destitute (to assist; to abandon, to neglect).
2. To assist someone: The apprentice helps the chef in making this cake (to aid).
To be present at; to participate in: Attend a dance show (see; miss).
2. To witness; to observe: We are witnessing a continuous decrease in unemployment.
Assist32:
[asiste]. [1] Etre présent. 2. Aider, seconder quelqu’un. Tech : équiper d’un dispositif
assistance. Help given to someone. To ask, to provide assistance to a friend.

31 [Link] visited on 15/04/2009

32 Universal Encyclopedic Dictionary. Precise Edition 1998. P1383

26
assembly, audience.
and to transmit it to a mechanism

Assisted: Tech. Equipped with an assistance device. Power steering. Assisted braking.

The set of definitions that exists for the verb 'assist' or the word assistance repeats
always keywords such as support, presence, and the assistance system. These words
generally summarize the purpose and objectives of the Internal Control concept
Computer Assisted.

The computer applications of internal audit and particularly of internal control


revolve around the following 3 objectives:

Help and guide the user in their Internal Control process.


Ensure the continuity and sustainability of the approach within the organization
Establish a baseline reference for the organization

Thus, we can build a global definition for "Internal Control Assisted by


Computer » by accumulating all the previous interpretations:

Computer-assisted Internal Control is the use of computer tools to


help, guide, and sustain the internal control process within an organization in
setting up a set of devices aimed, on one hand, at ensuring the
protection of heritage and the quality of information in the company, on the other hand,
to ensure the implementation of management instructions and to promote improvement of
performances.

1.2 The objectives of Computer-Assisted Internal Control

1.2.1 Assist and guide the user in their process of Internal Control
Internal control software has the primary objective of assisting
the internal auditor or the head of internal control of a company to carry out its mission
audit in the best possible conditions. Most of these software have as a point
the existence of a pre-established database that is well-suited to the sector
of the company's activity or the area of control. This adaptation allows the auditor to
situate each time in relation to a reference or a listing of regulatory standards.
Especially with the existence of multiple fields and areas of control application.
internal.

27
1.2.2 Ensure the sustainability of the internal control approach and
these devices over time
Assisted internal control provides the auditor with a selection of features.
which allows him to save and archive all of his work done during his
audit mission. These saved data can be used and exploited in the suite
control work and the implementation of an action plan. Moreover, they can serve for
the future inspection missions. In fact, no internal control document is damaged
You lost. Also, the auditor has the option to review the history and development of
risk and control indicators over multiple periods.

The entire system of solutions motivates internal control actors to expand and
ensure the continuity of the internal control process. This is not the case for SMEs
currently in the case of a check not using this tool. The latter do not
lacking the human and material resources to ensure the sustainability of control
intern within the organization.

1.2.3 Establish a baseline reference for the organization


Internal control software can serve as a baseline reference for control.
internal either for the management of the company. Thanks to a set of modeling tools
graphic and logic of procedures that allows staff to review methods
applied for the accomplishment of a given activity and the knowledge of the devices of
controls planned for the organization's risks. Additionally, most of this software assists
management to establish dashboards, job sheets (monitoring the profile gap
competence). Ultimately, they serve as a storage place for most documents
internal company documents (management report, financial report, articles of association, regulations of

sector, statistical documents,...) then it allows their connection with an activity or a task
data.

28
1.3 Internal control software on the market
The software Main clients Features Strengths
VALDYS Taitbout Group Documentation and formalization Strong modeling capacity
Manage and model the Mut'Est processes and risks Ease of use
control internal and The consulting firm Formalization of the reference frameworkVery fine granularity
master the risks R & B Partner control •Compliance with Solvency II and
operational AXIEM Crossing of points requirements of the ACAM
control with the processes Configuration according to the profession of
Generation of tables the company
control and documents
of audit
Traceability of internal control
Action plan and monitoring
results
Frontcontrol The post Mapping of internal control Compliance with the law
=Ensure consistency of Groupama bank Generation of forms Sarbanes Oxley and the Law of
control device Macif control Financial Security
internal and the mechanisms PSA Finance Bank Information gathering Assistance in writing the report
self-evaluation) Identification of action plans of control
and update of the mapping Evolutive
Reporting
Enablon Internal Control Auchan Evaluation of controls Compliance with the law
A management solution IONIS Testing Sarbanes Oxley and the law of the
and control piloting Reporting financial security
internal considered as Capitalization and sharing of Assessment grids
one of the solutions of analysis work customized to the profiles of
market reference. A centralized repository entities
A management and monitoring module ease of use, its
operations architecture

29
Dashboards •its decentralized management and its
Dynamic cross-analysis of multilingualism
procedures

ISIMAN French Agency of Connection control and risk Enter the results of the
=> create a repository of Development your objective offline mode checks
internal control and the AGIRC-ARRCO Definition of controls and then import them into
deploy within Management Bank level 1 and 2 a single operation in the
the company Edmond of Orchestrate the distribution of database
Rothschild Monaco control sheets over time Compliance with Basel II
(BGER) and in the organization Solvency 2 and ACAM
• Group Credit allow the controls of Ease of use and
Mutual: Federal controls compatibility with Windows and
Finance Form of the Lunix
Group Malakoff recommendations and actions
Médéric follow-up
IRP Auto
PRO BTP

30
2 Advantages and limitations of Assisted Internal Control
Computer
2.1 The Contribution of Computer-Assisted Internal Control

2.1.1 Acceleration of the implementation of the control process


internal
Among the main advantages of internal control software is the enormous time savings.
in the implementation of the audit process and the management of control missions.
Subsequently, we are witnessing a highly motivated competition among the various publishers for
to offer increasingly effective and efficient products that allow for savings
always more management work time. In truth, these publishers quickly understood that
Time for the company is a rare and costly commodity. The easier the software is...
exploitable and allows for the automation of more manual operations for the software user
is satisfied. So, how does Computer-Assisted Internal Control enable acceleration?
the process of Internal Control?

2.1.2 The existence of a reference base in the area of activity of


the company

Specifically, to understand this advantage, we need to go back to the function of assistance and
auditor's orientation. Computer-Assisted Internal Control benefits from a base of
reference in accordance with the standards and legislation in force related to a given industry
(example: nuclear industry, insurance and mutuality, distribution, etc.) and which replaces the
automatic recourse to manual documentation (books, internal documents, internet,
etc.

By resorting to this solution, a beginner or experienced auditor saves a lot of


time for research and reflection to adapt the control mission to the nature of the activity
the company. The viability of this allocation is primarily felt during the identification phase of
risks and definition of control points.

31
2.1.3 The automatic generation of control documents
The automatic generation of certain basic documents for the execution of a mission of
Internal control is a key function and a necessary condition for clients of this type.
software. This automatic generation of documents allows for selection, sorting, and a
extraction of data related to a document concerning a specific step of the process
internal audit. Immediately, the application injects this data into the document to be generated in
avoiding in this way to perform search and calculation operations manually.
Thus, the developers have made great efforts to automate the generation of a
a considerable number of audit documents, among which I highlight:

Audit sheets
Risk mapping
Dashboards
Action plans
Control tables
Internal control report
Audit tests ...

2.1.4 The crossing of data


The data cross-checking operation allows for the detection of discrepancies and anomalies in the implementation.

in operation between different levels and stages of control, thus allowing the auditor
to correct the design and estimation errors made previously (for example
crossing of control points with control tasks

This function characterizes some of the most efficient software on the market. The choice of
Putting this option in an application requires a lot of vigilance and effort.
of programming. Also, the introduction of this option requires the user to
particular precision in the choice and establishment of its internal control terminology
in order to overcome the risk of confusion and misinterpretation by the program
computer science.

2.1.5 Sharing and capitalization of internal control data


Today, thanks to computer networks, the communication of information and
Data has become a simple and routine operation for company personnel.

32
he only needs limited knowledge to share all the relevant data
in a few minutes.

In this context, Computer-Assisted Internal Control meets the needs of


listeners, to share a set of references and data between several services within
of the same structure or between a set of sites located in spaced-out places. The
existing software on the market exploit the internal computer networks of the company to
execute a set of electronic communication operations thus avoiding this way
movement, the risk of losing paper documents during their sending and the waste of
time needed for their transfer.

Among the advantages of sharing data between different cells within the same structure
or between several structures:

Instant data update for all positions linked to the source


thus preventing conflicts related to delays in information transmission
and to keep all listeners updated
Several users can work on the same mission at the same time or at different times.
delayed moments from multiple locations
Possibility for listeners (depending on the rights granted) to make changes to the
central database and to express its opinion on modifications made by
other listeners

2.1.6 The consistency of the internal control system

[Link] Consistency with respect to the reference frameworks

The complexity of the current regulations and legislation at the national, European, and
international requires auditors to adhere to strictly defined standards and at the same time
time to comply with a number of internal audit practice standards.

The entire internal control software is in compliance with one or more laws in
the field, such as:

Financial Security Act


Sarbanes-Oxley Act

33
Solvency II
COSO
Bale II
These software programs require or compel the user to comply with a specific standard or law.
limiting the user's leeway or prohibiting certain modifications that do not
are not in compliance with industry regulations.

[Link] Consistency with the internal control approach


The execution of an internal control mission is a sequence of phases (see part 1
point B: the approach of internal control) where each phase corresponds well to a panel
control operations. The scheduling of these phases follows a precise logic and in
Under no circumstances can these phases be reorganized. This instruction is followed to the letter.
because first the internal control process is carried out by the computer application
according to a well-defined plan and the steps are carried out and executed in a sequence
pre-established.

[Link] Consistency among software users


Consistency in the design of procedures, as well as in the analysis and criteria
The evaluation must be respected by all auditors. We cannot imagine two methods.
distinct evaluations for a risk of the same nature. Subsequently, two action plans
two contradictory control tasks can never be established for two risks
identical. To address this issue, Computer Assisted Internal Control allows
to put all users on the same wavelength. Thus, any conflict or contradiction is
detectable by the system and can be reported at the very moment of its occurrence.

2.1.7 Relevance of risk assessment mechanisms


Computer-Assisted Internal Control provides an adequate solution to be able to
conduct a relevant risk assessment. First of all, the system asks to determine
a reference scale on the criteria and methods for risk assessment adopted by
the management and the Board of Directors. This basis will be utilized and respected at all
long of the audit process. Each time the auditor incorporates data related to the
pricing of a risk, the computer launches a reminder message of this reference base or
blocks the entry of certain inconsistent data from this initial database. It also constrains
The user must follow the procedure designed for the evaluation even for the risks that

34
seem insignificant compared to the others. Indeed, this option allows to detect
Risks considered acceptable but which turn out to be very significant after the rating phase.

Example:

An auditor chooses the rating scale as follows:

from 1 to 5

C = D*G*C

The computer does not recognize then an evaluation of D=6, G=5, and C=3 is launched with a message
of error

The calculation of criticality is automatic only if the evaluation criteria are respected.
choose.

2.1.8 Assistance in drafting the internal control report


At the end of an internal control mission, the auditors prepare a control report.
in which they present the control work carried out at all phases of the audit, their
observations and recommendations to follow in the next steps.

Law No. 2003-706 of 1heAugust 2003 said Financial Security Law imposes on the president of
Board of Directors or Supervisory Board to report, in a report
attached to the annual management report, the conditions for the preparation and organization of the work
of the board, as well as the internal control procedures implemented by the company33.
Initially applied to all public limited companies, the obligation to establish this report has been
then limited to only public companies making a public offering.34.

The internal control report allows the company to have a real picture of the degree of
maturity of its controls and thus address the associated risks. Control software
interns provide an effective way to minimize costs and completion time of
report.

These softwares then allow to:

•Collect and sort all the necessary information for the preparation of the report by
referring to the already existing database.

33 Article 117 of the law amending articles L. 225-37 and L. 225-68 of the commercial code
Law No. 2005-842 of July 26, 2005 for confidence and modernization of the economy (Breton law)

35
Give the user the choice to include or not a number of elements in the report.
according to the importance of the latter for the regulatory bodies
Automate the calculations and formatting of the obtained results
Allow an automatic update of the report after each modification
Allows for a general idea of the progress of the work at each stage of completion.
of the report.

2.1.9 Sustaining the audit approach


The establishment of an internal control system is an operation that is not limited to the
the duration of the control mission but it continues throughout the life of the company.
In fact, the internal auditor is required to continuously update the risk assessment, to
to monitor the application and implementation of the recommendations and to develop activities of
mastery, etc. The change of the environment and the metamorphosis of risks are the
main causes of this ongoing mobilization.

In this context, the added value of Computer-Assisted Internal Control is the ability to
update the data automatically without having to redo the same work
with each new audit mission and to document the periodic changes using the
software. Furthermore, it allows for tracking and observing the evolution of risks
and real-time controls. In this way, the user can modify the characteristics
of a risk or a control point whenever the situation requires it. This option
lightens the auditor's workload as it allows the effort made throughout the year to be shared and
thus avoids a buildup of work over a particular period.

2.2 The limits of Computer-Assisted Internal Control

2.2.1 Partial rigidity


The main function of internal control software is to assist the auditor in their
The 'internal control process' leads to an imbalance between, on one hand, the will of a
excessive formalization of the procedures of the company's activities and on the other hand the use
adapted from internal audit techniques.

Indeed, the developer seeks to limit the user's leeway by the


blocking of hundreds of features and prohibiting access to others, in order to
to compel compliance with the laws and regulations in force. As a result, the

36
users tend to give up on a number of findings or observations in the
measure where they are unable to integrate them into the computer system.

Thus, users will be required to comply with the audit method proposed by the system.
and to abandon any appropriate approach to the auditor or already used by the company in
the previous missions.

2.2.2 Limited mastery of the software features


To take advantage of all the features of an internal control application, the user
must have advanced computer skills and a good understanding of
the software architecture. This quality allows it to make the most of the tools that
obtaining the software and optimizing the desired results.

This knowledge is not limited only to the application of internal control but must
also focus on other tools such as office tools, database management
and the architecture of computer networks. In fact, most internal control software
calls on other external resources to feed and perform calculation operations
Example: Word for document generation, Excel for complex calculations and the
graphics, Access or MySQL for database management, Internet Explorer for
reading HTML pages.

In order to overcome this obstacle, software publishers offer training modules.


for their software and remote assistance during the duration of the contract usage.
For the same purpose, they include in their applications tools for assistance and exercises.
practices to improve and respond to user questions.

2.2.3 The computer errors


Like other applications, internal control software has some points
of failures that can harm the user and prevent them from performing certain operations
data entry, processing or document generation. These issues are
generally due to programming or design errors. Among the errors the
more common:

Incompatibility errors with other software or operating systems


Bugs that often result from programming errors such as mistakes in
a calculation formula or incomprehensible messages.

37
Application installation errors on a computer and errors of
settings
Errors in defining access and modification rights
Non-compliance with certain network security standards
The large part of his problems is explained by the novelty of these software on the
market. Thus, developers are always on the lookout to correct these flaws
computer science through regular updates as part of software development or
following a user report. However, the older solutions on the market
always benefit from a step ahead of others thanks to experience
accumulated in this field.

2.2.4 Dependence
The use of Computer Assisted Internal Control never replaces analytical thinking.
and the listener's critique as well as their rationality in risk assessment. It calls upon
also to his creative capacity and his instinct as a listener. However, the continued use and
The permanence of this tool can stimulate a relative dependence on this tool and then lead to a
notable influence on the choices and analyses of the listener.

In addition, the existence of an initial database related to the nature of the company's activity
implies a tendency of the user to adopt ready-made solutions instead of making the effort
from a structured analysis. However, the pre-existing solutions in the database do not
do not always apply to the audited organization.

2.2.5 Irrational time management


Computer-Assisted Internal Control requires a lot of investment in terms of
time. The first months are the hardest, and the user feels that the work
advance very slowly. This is not surprising; it is entirely normal that in the early
we start very slowly since it is the period of training and discovery of
software. The user then encounters a large number of technical blockages and
of misunderstandings especially regarding the logic of graphic modeling.

In reality, it is only the first few months that take up a lot of time because
It is a period of adaptation and design. After this phase, the acceleration of
the implementation procedures are remarkable, the phases of risk analysis of
development of control activities and monitoring of action plans takes less than

38
time. The evolution of the implementation of Computer-Assisted Internal Control in the axis
time follows an exponential curve.

Progress
of putting into
CI square

Phase 3

Phase 2

Phase 1

Weather

Graph representing the evolution of the implementation of CIAO over time

2.3 The keys to success of a Computer-Assisted Internal Control project


The success of the introduction of Computer Assisted Internal Control in one
Organization begins first with a set of arrangements and prerequisites:

An organization with a clear definition of roles, equipped with resources


necessary and appropriate skills and relying on information systems
effective, on procedures or operating modes, instruments and devices
adapted.
Relevant, reliable and effective internal communication that enables everyone to exercise
his responsibilities without confusion or disorder.
The existence of a system for cataloging, evaluating, and analyzing the main
identifiable risks, to achieve the organization's objectives and to ensure the existence
procedures for controlling these risks.
The existence of control activities proportionate to the risks associated with each process,
and designed to ensure that necessary measures are taken to control the
risks that may affect the achievement of objectives.
•Continuous monitoring of the internal control system as well as a
regular review of its functioning.

39
3 Case study software Valdys
3.1 Software Presentation

3.1.1 Major Functions and Contribution of the Software

From now on, insurance companies and mutuals (company, mutual or institution of
Insurance) are subject to strict regulations that require them to have knowledge.
particular in internal control and complete mastery of operational risks including
financial risks. Indeed, the second pillar of the Solvency 2 directive requires companies
of the insurance sector to implement internal control and management actions
risks that require the use of a structured methodology and know-how
innovative in internal control.

In this context, Effisoft (publisher of management software solutions) has developed


the Valdys application: a structuring tool for managing and modeling control
internal. It provides comprehensive knowledge and total mastery of risks
operational related to the company subject to the control of the ACAM.35

Valdys allows for the implementation of the internal control framework by describing and
by formalizing the processes and risks within a structuring approach integrating the
specificities of insurance professions (property and casualty, health, provident, retirement, ...). Also, he

integrate the risk assessment function, identification of control points and their
intersections with the company's processes. It allows for the generation of control tables.
internal and audit documents (control sheets, test sheets, audit schedules,
summary tables) as well as all the deliverables required as part of the control
permanent of the ACAM.

On the other hand, it allows the dissemination of the internal control framework and its implementation.

operational control points by automatically generating them in the form of documents


electronic, paper documents or intranet web pages, processes, procedures,
the analysis of risks and the action and monitoring plans to facilitate the dissemination of
information to all concerned parties.

The features of this tool are generally the objectives concerning Assisted Control.
by Computer to know:

The reduction of the time required to implement an internal control system

[Link]

40
The backup and archiving of results obtained at a given time for the purpose
of the traceability of the approach
The automatic generation of a set of audit documents and the report of
internal control
Compliance with the constraints related to Solvency 2
The economy of material and human resources
Online assistance and technical and professional support

3.1.2 Technical characteristics


Valdys is a solution that is not very demanding on the hardware performance of computers.
or network servers. This feature enhances its contribution as a solution
economic for the company. As a result, customers are not led to have any
high-performance equipment to get it started.

Depending on the needs, Valdys can be installed as a thick or thin client. Another advantage is its
compatibility with all market databases (Access, MYSQL,…).

The required configuration is as follows:

Required disk space: 50MB


1GB
Processor: Pentium III or higher
Windows, Windows NT4 SP6, Windows 2000 SP3, Windows XP
IE 5.1 or higher

On the other hand, some failures of this software have been raised:

The installation of the software requires very advanced computer skills.


difficulties are mainly due to very strict measures against software piracy.
Significant number of errors and computer bugs
Incompatibility with the latest version of Windows (Vista) and the latest version
Office 2007, to work around this problem the publisher offers for its clients equipped with
this type of operating system, updates.
The editing of the internal control report still requires considerable efforts.
the user to adapt it to the requirements of the ACAM.

41
3.2 The architecture of Valdys

3.2.1 Presentation of the Valdys tree structure

Overall, the software is designed in the form of a tree structure consisting of several
levels. Each level presents a particular viewpoint on the internal control system
configurable according to the control phase to be carried out. The information generated during
The use of Valdys is recorded in a modeling database represented by a or
several files.

CI database

Projet 1 Point of view 1 Modèle 1

Projet 2 Point of view 2 Modèle 2

Projet 3 Point of view 3 Modèle 3


Modèle 4
Projet 4 Point of view 4

Schema of the overall architecture of the database

3.2.2 The project, the point of view and the model

[Link] The project

The first level of structuring the modeling base is the Project. It is possible to
model different projects within the same database. A project is a homogeneous set.
of viewpoints and aims to achieve the defined objectives of internal control. It is the level
the highest level of the design of an internal control system. It consists of a or

42
several viewpoints deemed relevant for structuring the control framework
internet36It is possible to model different projects within the same database.

Project example: "Creation of an internal control system for a mutual."

[Link] The Point of View


Set of identical or different models included in a project and describing a
specific focus on the object of modeling. Examples: management processes,
core business processes, etc.37

The Points of View allow for the expression of different complementary dimensions:

Complementarity over time (a current perspective, a target perspective)


Complementarity in the organization (an internal perspective, a perspective
external)
Complementarity in space (a central point of view, a local point of view)

A Point of View is expressed through one or more Models.

[Link] The Model

Set of frameworks, construction rules, and editing tools providing a representation


structured38Each model belongs to a type of model that specifies the manipulable concepts.
in this one. For example, a Mission Tree type model allows for manipulating the
mission concept and the links allow structuring a decomposition of missions into
sub-missions, sub-sub-mission, etc.

In general, a Model is a graph made up of nodes and links, which


represent manipulable concepts. These nodes and links manipulated by the different
template editors are therefore the graphical representatives of the concepts that are stored in
the Dictionary of elements. The latter is specific to a Project and is shared by all
Viewpoints and Models of a Single Project.

36 Appendix 1 "Valdys Glossary"


37 Appendix 1 'Valdys Glossary'
38 Appendix 1 'Valdys Glossary'

43
3.3 The Internal Control project according to Valdys

3.3.1 Identification/Formalization of processes

The first step in implementing the internal control project is to


decline the missions and objectives of the organization in order to identify the key processes of
this one as well as the means implemented to ensure their proper functioning. There is
three levels of process design in the organization.

[Link] The Macro-process39

It is the overall vision of the company's profession with a homogeneous breakdown and
coherent according to these different missions. The breakdown of the company's activity
proposed by Valdys concerns 3 major categories (Pilotage mission, Core mission
profession and mission Support, according to ISO 9000 standards

•The management or steering processes: they outline the way in which the
The company's management practices its steering and governance policy.
Business realization processes or business processes: these processes deal with the
functioning of producing a product or service by breaking down
the sequence of operational activities in several phases.
Support processes: they allow representing the resources needed for implementation.
business process work.

[Link] The Phase Diagram40

It is the graphical representation of a set of activities within the same mission.


of control. The phase symbolizes a period during which a set takes place.
activities through a temporal breakdown. The connections between the different diagrams
The phases are in the form of input connectors or output connectors.

39
See annex (2)
40
See appendix (4)

44
[Link] The Flowchart41

The third level of vision of the procedures is the Flowchart "Diagram representing a
process implemented to ensure a mission42».

At this stage, an auditor can have a synthetic representation of an activity by modeling


tasks and links with horizontal or vertical flows. With this diagram, the response
to the question 'who does what?' is complete. The Flowchart describes from a point of view
operational an activity through the practices of the company's trades (a procedure for
(ISO 9000 sense). The description of flowcharts thus allows for the formalization of practices.
existing operations and possibly allows for the optimization of the information system and /
the production system of the company within a given scope.

Diagram representing a process implemented to ensure a mission43

Macroprocess

Phase diagram

Flowchart

3.3.2 Risk identification and assessment

[Link] Categories of risks

After the definition and modeling of procedures, the auditor begins the phase
of identification and risk assessment. First, it is necessary to share the risks into risks
exogenous and endogenous risks:

41
See annex (4)
42 See appendix (1)
43
See appendix (1)

45
Exogenous risks are risks originating from outside the company (for example: the
natural disasters, power outages, etc.)
Endogenous risks are the risks related to factors triggered within
the company (internal fraud, data entry error, misinterpretation of a law text by
the staff, etc.).

The first category of risk is modeled with 'Risk Family Trees'44


while the second category is modeled in the form of a 'Risk Tree'. The
The graphical representation of these trees highlights the relationship between the missions and the
objectives as well as the risks associated with each objective (adverse event or class
of undesirable events).

The establishment and analysis of procedures is a preparatory step for identification and
the assessment of risks. Valdys's logic allows us to deduce risks by analyzing the
goals to achieve and the regulatory constraints to respect. These risks generally are
produced within the framework of carrying out the company's activities. Thus, the modeling
the risks under the term 'risk tree' are as follows:

Objective Event Checkpoint


undesirable
Mission (Risque) or
class Corrective action
events
Constraint undesirable Preventive action

[Link] Risk Assessment

Risk assessment is a critical phase in the internal control process. Everything


efforts made by an auditor are based on a reliable and rational analysis of risks.
the opposite case, the entire audit mission and its related objectives may be doomed to failure.

44
See appendix (5)

46
Aware of the strategic importance of this phase, Valdys allocates a lot of resources and
resources for risk assessment. First, to assess the criticality of a risk
Valdys integrates 3 factors into the calculation function:

Frequency F (from 1 to 5)
Detectability D (from 1 to 5)
Severity G (from 1 to 5)

The calculation formula for criticality is: Criticality = Frequency * Detectability * Severity

Criticality is thus understood to be between 1 and 100.

In some cases, the auditor is led to take into account the significant weight of one of the
previous factors. To do this, Valdys allows changing the calculation formula to another one.
for example (C=F*G², F*G, G^4*F²*D).

Then, Valdys also allows for detailing the assessment of Severity by breaking it down into
several impacts of different natures (financial impact, customer impact, image impact, impact
supplier, ...)

Finally, the software allows the generation of risk maps. Once the risks have been rated, it
It is possible to generate a risk map graphically representing the risks and
45
their importance. For this, all the risks of the Risk Tree do not need to be
necessarily slanted. It is possible to generate a risk mapping for a single tree of
risks for both or for all the trees present in the "Risk Tree" model or
for all the risk trees of a project

3.3.3 Identification of control elements and cross-referencing with the


control tasks or activities

For each major or minor risk, Valdys allows for the identification of one or more elements of
mastery

Corrective action
Preventive action

45
Annex (3)

47
Checkpoint

Each element of mastery must correspond to a control task present at the level of
Logigrams. This operation of linking between points and control tasks is called
risk crossing process. A subsequent generation of control tables
will allow us to detect failures in the internal control system within the company
the risks for which there is no corresponding control task.

3.3.4 Monitoring and Improvement

Valdys allows for the planning and implementation of action and control plans, to carry out
control evaluations and follow-up on recommendations. In this context, it has
several tools and means:

The control sheet: it describes how risks are taken into account.
level of processes (operating mode, responsible person, frequency of control, etc.) in
the aim of mastering the risks of the profession.

The Control Panel: it allows to synthesize the reconciliation between the risks,
the control points and processes; and this, in order to identify the gaps.

•The Dashboard: it summarizes the progress of audits and results.


obtained; and this, by period, type of risk, date, etc.

The Action Plan: it allows visualizing corrective and preventive actions.


then organize their follow-up.

The evaluation schedule: it indicates, for a given period, the list of audits to be conducted.
bring and the corresponding workload in order to plan effectively the
evaluations.

3.4 The documents generated internally by Valdys

3.4.1 The internal control report

The internal control report summarizes all the information integrated into Valdys.
by organizing them in a coherent and homogeneous manner. The internal control report is
specifically intended for supervisory authorities such as the ACAM - Control Authority of
Insurance and Mutuals.

48
In this context, Valdys allows for the generation of an internal control report in the form of a
file in Word format. The script uses the entire available database and the
information recorded by the auditor to generate an internal control report. The
The final structure of the internal control report is modifiable according to the user's needs.
Thus, the auditor decides whether or not to include a certain number of pieces of information in the

control report according to their degree of importance and usefulness.

Nevertheless, the software's performance in generating the report remains limited.


Indeed, the user must personally input a number of pieces of information that will feed the
Valdys database (for example: information on the organization of the Board of Directors) and
make final modifications to bring the report into compliance with the requirements of
the ACAM. The user is then faced with restrictive measures established by the publisher of the
software in the context of overseeing the audit mission. This creates a lot of difficulties
to change or modify elements of the report such as the content of the tables or the
graphs. Another drawback is that the software only offers one option regarding the
report structure; consequently, the user cannot modify the architecture of the
report. In this case, he is invited to make a considerable effort to change the structure of
default report. In addition, we note the absence of automatic generation of a note of
synthesis on the state and outcome of the audit control work done by the auditor.

3.4.2 The generation of HTML pages46

The generation of a website is a very useful feature for dissemination and sharing.
Information sharing among staff. All the work done on modeling procedures
until the report generation is fully accessible. This generated website can be
consulted and integrated into the company's intranet or into an extranet network. The users
having administrator rights have the option to prohibit and secure access to elements
confidential.

46
See annex (8)

49
Conclusion

Computer-Assisted Internal Control is an option that brings great added value


for companies and auditing firms to assist and accelerate the implementation process
in the implementation of the internal control process.

The three axes of this thesis demonstrate the important role of Assisted Internal Control
Computer for organizational management and risk control processes. Acceleration
of processes, cost efficiency related to control operations, consistency of approach
Among auditors, indeed the added value of this tool is becoming increasingly remarkable.

However, we must not ignore the importance of the failures observed and deduced during
our analysis of the concept and particularly in our case study especially concerning the dimensions
techniques and mastery of software tools. Moreover, it is still too early to bring a
negative judgment due to the aforementioned drawbacks. Particularly because our analysis
focused on a single software (Valdys) and also referring to other resources
documentaries. To generalize our study, it is necessary to involve other software in the analysis
and other users. This analysis must be subject to practical and technical tests carried out
by the actors and experts of internal control and the publishers and designers of these solutions
of management. A combined effort among all these parties can contribute to development
and to the improvement of Computer-Assisted Internal Control.

Ultimately, we can say that like all the IT solutions offered to


companies, Computer-Assisted Internal Control is experiencing rapid development and
supported by the number of these clients thanks to a better cost/effectiveness ratio and thus becomes
a formidable competitor for audit firms.

50
Bibliography:
Frédéric Bernard, Rémi Gayraud and Laurent Rousseau, "Internal Control", [Link],
Paris, 2006, p 303
•CNCC Standard 2-301, risk assessment and internal control", paragraph 08, Framework
normative CNCC, 2003
• Coopers & Lybrand, "The new practice of internal control", Organization Edition,
Paris, 1994, p 378
Kamal ABOU EL JAOUAD, "The stakes of internal control" University of Clermont
Benoît Pigé "Audit and Internal Control", Ed EMS, Paris, 2001, p210
Alain-Gérard Cohen, "Internal Control and Public Audit"
Universal Encyclopedic Dictionary. Precise Edition 1998. P1383
Ernst&Young. "Developing a mapping of operational risks, within the framework of
requirements of the future Solvency II directive
Hugues Angot, Christian Fischer, Baudouin Theunissen. "Accounting Audit, Audit
computer science. Edition: 3 De Boeck Université, 2004. p 304
Seán Cleary, Thierry Malleret Collaborator Klaus Schwab, "Risks: Perception,
Evaluation, Management
Étienne Barbier. "BETTER PILOTING AND BETTER UTILIZATION OF AUDIT". Maxima Editions,
1998. p 124
•Universal encyclopedic dictionary. Exact edition 1998. P1383

Webography:

• [Link]
• [Link]
• [Link]
uuQQ
• control
• Invalid input, no translatable text provided.
The provided text is a URL and does not contain translatable content.
• Unable to access or translate content from external links.
• Unable to access the content of the provided link.
• Unable to access external links.
• Invalid input. Please provide text for translation.
• to attend
• The provided text is a URL and does not require translation.

51
Annexes

52
1 Appendix (1): Valdys Glossary

53
54
Annex (2): the Macro-process

55
3 Annex (3): Risk Tree

56
Annex (4): Phase Diagram and Flowchart

57
Annex (5): Risk Family Tree

58
6 Appendix (6): The nomenclature model and the model
structure diagram

59
7 Annex (7): The tree model of roles/skills and
the mapping of risks

60
8 Appendix (8): The Html pages

61

You might also like