COSO System & Internal Control in Auditing
COSO System & Internal Control in Auditing
FACULTY OF ADMINISTRATION
SUBJECT
AUDIT III
TEACHER
THEME:
MEMBERS:
CYCLE B
Guayaquil - Ecuador
2021
For Albert Salvador Lafuente, economist and internal auditor. Specialist in Internal Fraud.
The COSO Report is a document that contains the main directives for implementation.
management and control of a control system. Due to the great acceptance it has enjoyed,
since its publication in 1992, the COSO Report has become the standard of
reference.
There are currently 2 versions of the COSO Report. The 1992 version and the version of
2004, which incorporates the requirements of the Sarbanes-Oxley Act into its model.
It is designed to identify events that may potentially affect the entity and to
manage risks, provide reasonable security for management and for the board
organizational directive oriented towards achieving business objectives.
The history of the COSO model is framed by two fundamental aspects: Context in which
it originates and the working group that made the proposal. As a way to address diversity
of concepts, definitions, and existing interpretations surrounding internal control, is published
in 1992, the COSO model in the United States (General Internal Control Standards, 2007).
Likewise, Melini (2005) states that the COSO model was born as a response to concern.
generalized regarding the reasoning cases jurisprudential that evidence situations
limits, where bankruptcies are caused by failures of the managers regarding management
of the companies' assets.
The COSO report is a methodology for the implementation and management of a system of
internal control. Based on COSO, entities can design their own systems of
internal control, through the identification of the risks that affect compliance with the
objectives of internal control, the implementation of measures to address those risks and the
assessment of compliance with those measures.
The evaluation of internal control allows the auditor to determine whether they are being carried out.
correctly and using the methods, policies, and procedures established by management
of the company.
Understanding and evaluating the entity's internal control process is the auditor's responsibility.
design tests that allow for the identification of controls, risks, and to test the established processes in
the company. An evaluation of internal control involves an examination of the effectiveness of the system
of the internal controls of an organization. By participating in this evaluation, our auditor
it can determine the scope of other tests that need to be conducted to reach an opinion
about the equity of the entity's financial statements. A robust system of controls
internals reduce the risk of fraudulent activity, which moderates the need for
additional audit procedures. The examination focuses on issues such as:
Record protection
The Audit Procedures Committee of the IMCP, when studying the audit standards
concludes that the Public Accountant must carry out an appropriate study and evaluation of the control
internal existing in the company that examines, with the basic aim of determining trust that
you can assign to each phase and activity of the business, to specify the nature, scope and
opportunity that will be given for their audit tests.
The study of internal control evaluation has as its primary objective the formulation of
an audit program that, when executed, allows the Public Accountant to issue an opinion
about the financial statements. The end of the review of the accounting procedures and of
internal control is to investigate what procedures are used and the efficiency of the system
of the existing internal control, as a basis for determining the scope of the examination. The review does not
it does not end with the investigations conducted at the beginning of the audit, but rather continues in the
the course of her.
Another objective is to take note of any modifications that may be recommended for
reinforce, improve or simplify the existing system. These aspects should be communicated by
means of suggestion memorandums, containing the identified deficiencies in the
business organization.
According to Bulletin 3050 issued by the Commission on Standards and Audit Procedures,
within its generalities explains to us that the study and evaluation of internal control is
It is carried out with the aim of fulfilling the work execution standard which requires that 'The control
the internal includes the organization plan and all the methods and procedures that in form
coordinated measures are adopted in an entity to safeguard its assets, verify the reasonableness and
reliability of its financial information and complementary administrative and operational information,
promote efficiency in operation and encourage adherence to the policies prescribed by the
administration.
The different types of COSO systems that have existed over time, including the
structure of each of them
COSO I
In 1992, the commission published the first report 'Internal Control - Integrated Framework'
called COSO I with the aim of helping entities to evaluate and improve their systems of
internal control, facilitating a model based on which they could evaluate their control systems
internal and generating a common definition of "internal control".
According to COSO, Internal Control is a process carried out by management and the rest of the
personnel of an entity, designed with the aim of providing a degree of security
reasonable in terms of achieving objectives within the following categories:
1. Control Environment
2. Risk Assessment
3. Control Activities
4. Information and Communication
5. Supervision.
COSO II
In 2004, the standard "Enterprise Risk Management - Integrated Framework" (COSO) was published.
II) Integrated Risk Management Framework that expands the concept of internal control to the
risk management necessarily involving all staff, including directors and
administrators.
1. Control environment: it is the values and philosophy of the organization, it influences the
workers' view on risks and control activities of the
same.
2. Establishment of objectives: strategic, operational, informational, and
compliances.
3. Identification of events that may impact compliance.
objectives.
4. Risk Assessment: identification and analysis of relevant risks for the
achievement of the objectives.
5. Response to the risks: determination of actions in the face of the risks.
6. Control activities: Policies and procedures that ensure they are carried out.
I take actions against risks.
7. Information and communication: effective in content and timing, to allow for the
workers fulfill their responsibilities.
8. Supervision: to monitor the activities.
COSO III
In May 2013, the third version COSO III was published. The new features it will introduce
this Integrated Risk Management Framework is:
Concepts and elements that are part of each of the elements of the Coso.
COMPONENTS
Internal Control consists of five interrelated components, which derive from the form
how the administration manages the entity, and they are integrated into administrative processes, the
which are classified as:
Control environment
Risk assessment
Control activities
Information and communication
Monitoring
1. CONTROL ENVIRONMENT:
Define parameters to manage the internal control of the company that relates to the
organizational structure, administrative policies, institutional ethics, and relationships
hierarchy, authority and responsibility; as well as integrity, the company’s values and the
administrative philosophy. The control environment is the foundation upon which the rest is positioned.
elements and fundamentally influences the objectives and strategy of the company.
The elements of a control environment are prioritized as follows:
Organizational Structure
Administrative policies
Institutional ethics
Company Values
Administrative Philosophy
2. RISK ASSESSMENT
During the assessment, risks are identified and [Link] to the probability of
impact and frequency, to understand their possible consequences in case they occur. In
in this process, each risk is analyzed and classified as high (it is very likely to occur),
medium (feasible) or low (very little feasible).
It is analyzed whether each impact can be internal or external and whether it is high, medium, or low for
prioritize them in that order. This evaluation serves to start working on the most
urgent and propose strategies to mitigate or avoid them.
To assess the risks,it is recommended to create a heat map, where it is classified the
impact and probability. Each is identified by a different color: High Risk (Red) -
Riesgo Medio - Alto (Naranja) - Riesgo Medio (Amarillo) - Riesgo Bajo (Verde).
The principles that should be followed in risk assessment are as follows:
The organization specifies objectives to enable the identification and assessment of the
risks.
The organization identifies and analyzes the risks.
The organization assesses the risk of fraud by analyzing the risks.
The organization identifies and assesses changes in the internal control system.
3. CONTROL ACTIVITIES
It refers to the policies and procedures that outline the appropriate actions to manage the
risks, making decisions that favor the operation and the achievement of objectives. All the
Areas of the company, without exception, are responsible for executing control activities,
that lead to a correct decision-making and fulfillment of objectives.
These control activities, according to COSO, can be preventive or detective and can
cover a wide range of manual and automated activities. These activities must
minimize the risks that hinder the achievement of the organization's objectives.
Companies must manage information from all their areas and unify it to have
convergence and speaking the same language. Information is one of the most important assets.
from the organization, which must be protected and must be available to all areas of the
company, this way errors are reduced whenidentify, classify, evaluate and manage the
risks.
Therefore, the leaders of each area must ensure to gather information that allows for analysis of the
risks and exchange it to have a general view of the company. As long as we
This will be fulfilled, there will be better internal control, and obstacles that threaten the...
achievement of objectives.
In this sense, the information is not only used for financial statements but also in
decision making. For this reason, leaders must be rigorous when it comes to gathering the
information, verify them and confirm them to be true and accurate. Meanwhile, the
communication is the process of providing, sharing, and obtaining the necessary information,
relevant and of quality.
The principles related to this component are as follows:
The organization obtains and generates relevant information for its functioning.
internal control.
The organization communicates internally information for its operation.
internal control.
The organization communicates externally with third parties regarding situations that
they affect the functioning of internal control.
[Link]
Continuous monitoring of risk managementfrom the organization helps the strategies
to mitigate them effectively and reduce errors that may affect goals. Additionally,
It serves to verify the effectiveness of internal control. Adequate risk management is
achieve with supervision and continuous monitoring, as well as with frequent evaluations.
With the software ofPirani Riskment Suite you will be able to register the controls you consider
necessary to prevent, detect or correct risks to which your company is exposed,
you will be able to assess them through design, execution, and solidity, and finally, you will be able to associate risks
and responsible for supervising these controls.
The principles of this component are as follows:
The organization conducts ongoing evaluations to check whether the components of
The internal control system is functioning adequately.
The organization communicates the deficiencies of internal control.
A perhaps simpler way to obtain information about how the system operates.
internal control in an entity will be the inquiry, observation, and review of the manuals of
organization and functions, accounting and internal audit manuals, internal regulations of
work, the procedures and internal instructions and other provisions adopted by the
administration or management; as well as conversations or interviews with executives about the
constitution, organization, social capital of the company, judicial processes, amount of
workers, etc. However, the most commonly used means or methods to document
adequately the evaluation of the internal control system in the company and that to the same
The times that can serve to record having carried out the evaluation are the following
métodos: descriptivo, cuestionario, gráficos o flujogramas.
Descriptive method:
It consists, as its name indicates, of describing or narrating the different activities of the
departments, officials and employees, and the records involved in the system. Without
embargo, one should not make the mistake of describing the activities of the departments or of
employees in an isolated or objective manner. The description should be made following the course of
the operations through its management in the mentioned departments.
Questionnaire method:
The objective of the internal control questionnaire is to gather information to uncover facts,
evidence, opinions, in order to gather data or quantitative information. The information
the obtained data must be tabulated, refined, and serve together with other agents as support for the report
The questionnaires address issues that participants will need to consider, focusing on their
reflection on the internal and external factors that have given rise to, or could give rise to, events
negatives.
Questions can be open or closed, depending on the objective of the survey. They can
address an individual or several, or can also be used in connection with a survey of
broader base, whether within an Organization or aimed at clients, suppliers or
third parties.
a. The questionnaire must be drafted according to the education level of the people to whom it is addressed.
direct.
b. The questions must be written clearly and allow some freedom for the respondent
Do not feel inclined to give a specific answer or to respond with yes or no.
c. Subjective terms should be avoided and if possible, questions should be concise and
necessary in order to achieve greater concentration and avoid fatigue for the interviewee.
It consists of being presented through charts or graphs. If the auditor designs a flowchart
of internal control, it will be necessary for you to visualize the flow of information and the documents that are
they process. The flowchart must be created using standard symbols so that those who
they understand the symbols can extract useful information related to the system. If the auditor uses a
flowchart prepared by the entity, must be able to read it, interpret its symbols and draw conclusions
useful conclusions regarding the system represented by the flowchart. In some cases perhaps
the graphing method has been applied, in others it may be convenient to use the method of
questionnaires, and in others it may be easier or the method may be better interpreted
narrative descriptive.
This method simplifies the task of describing procedures and techniques through the use of
of transaction movement graphs, also called flow diagrams or flow charts.
This diagram provides the reader with a clear image of the system, showing the nature and
sequence of procedures, division of responsibilities, sources, distribution of
documents and status of the accounting records.
Typesetting Techniques:
Flowcharts of processes:
The process flow analysis is the schematic representation of a process, with the aim
to understand the interrelations between inputs, tasks, outputs, and responsibilities of their
components.
Events can be identified and considered against the objectives of the process.
They are known as Ishikawa diagrams or fishbone diagrams, and they are useful for identifying the
causes of the risks.
After conducting the evaluation of the internal control system in an organization, one
perform the tabulation and analysis of the obtained information, subsequently a letter is issued
internal control attaching the observations and recommendations in order for the senior management
management or administration shall take the appropriate and timely corrective measures to safeguard interests.
business
Bibliographies
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
s_de_c_i_3e_cap16.pdf