0% found this document useful (0 votes)
12 views14 pages

COSO System & Internal Control in Auditing

The document discusses the COSO system and its significance in internal control assessment methods in auditing, detailing its evolution from the original 1992 version to the 2004 and 2013 updates. It emphasizes the importance of internal control in achieving organizational objectives, managing risks, and ensuring the reliability of financial information. The document also outlines the components of internal control and various evaluation methods used to assess its effectiveness within organizations.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
12 views14 pages

COSO System & Internal Control in Auditing

The document discusses the COSO system and its significance in internal control assessment methods in auditing, detailing its evolution from the original 1992 version to the 2004 and 2013 updates. It emphasizes the importance of internal control in achieving organizational objectives, managing risks, and ensuring the reliability of financial information. The document also outlines the components of internal control and various evaluation methods used to assess its effectiveness within organizations.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

LAICA UNIVERSITY VICENTE ROCAFUERTE OF GUAYAQUIL

FACULTY OF ADMINISTRATION

Degree in Accounting and Auditing

SUBJECT

AUDIT III

TEACHER

MBA. PAZMIÑO ENRIQUEZ JOSE ERNESTO

THEME:

The COSO System and Internal Control Assessment Methods in Auditing

MEMBERS:

Allan Jesus Barros Zavala


Carrera Ramos Sebastian Alejandro
Choez Choez Jorge Ulises
Galarza Martínez Jocelyn Valentina
Guaman Paucar Jennifer Maribel
Square Loor Dayanna Marisol
Lopez Arevalo Evelyn Domenica
Olmedo Vera Oscar Daniel
Suarez Villacis David Andres
Vera Borell Adrian Edmundo

CYCLE B

SIXTH SEMESTER - NIGHT

Guayaquil - Ecuador

2021
For Albert Salvador Lafuente, economist and internal auditor. Specialist in Internal Fraud.

The COSO Report is a document that contains the main directives for implementation.
management and control of a control system. Due to the great acceptance it has enjoyed,
since its publication in 1992, the COSO Report has become the standard of
reference.

There are currently 2 versions of the COSO Report. The 1992 version and the version of
2004, which incorporates the requirements of the Sarbanes-Oxley Act into its model.

It is designed to identify events that may potentially affect the entity and to
manage risks, provide reasonable security for management and for the board
organizational directive oriented towards achieving business objectives.

The history of the COSO model is framed by two fundamental aspects: Context in which
it originates and the working group that made the proposal. As a way to address diversity
of concepts, definitions, and existing interpretations surrounding internal control, is published
in 1992, the COSO model in the United States (General Internal Control Standards, 2007).

Likewise, Melini (2005) states that the COSO model was born as a response to concern.
generalized regarding the reasoning cases jurisprudential that evidence situations
limits, where bankruptcies are caused by failures of the managers regarding management
of the companies' assets.

The COSO report is a methodology for the implementation and management of a system of
internal control. Based on COSO, entities can design their own systems of
internal control, through the identification of the risks that affect compliance with the
objectives of internal control, the implementation of measures to address those risks and the
assessment of compliance with those measures.

Methods of Internal Control Evaluation in Auditing

The evaluation of internal control allows the auditor to determine whether they are being carried out.

correctly and using the methods, policies, and procedures established by management
of the company.

Understanding and evaluating the entity's internal control process is the auditor's responsibility.
design tests that allow for the identification of controls, risks, and to test the established processes in
the company. An evaluation of internal control involves an examination of the effectiveness of the system
of the internal controls of an organization. By participating in this evaluation, our auditor
it can determine the scope of other tests that need to be conducted to reach an opinion
about the equity of the entity's financial statements. A robust system of controls
internals reduce the risk of fraudulent activity, which moderates the need for
additional audit procedures. The examination focuses on issues such as:

The separation of duties

Checks and balances

Record protection

The level of training and competence of the employees.

The effectiveness of the entity's internal audit function.

The Internal Control in the Audit of Financial Statements.

The Audit Procedures Committee of the IMCP, when studying the audit standards
concludes that the Public Accountant must carry out an appropriate study and evaluation of the control
internal existing in the company that examines, with the basic aim of determining trust that
you can assign to each phase and activity of the business, to specify the nature, scope and
opportunity that will be given for their audit tests.

The study of internal control evaluation has as its primary objective the formulation of
an audit program that, when executed, allows the Public Accountant to issue an opinion
about the financial statements. The end of the review of the accounting procedures and of
internal control is to investigate what procedures are used and the efficiency of the system
of the existing internal control, as a basis for determining the scope of the examination. The review does not

it does not end with the investigations conducted at the beginning of the audit, but rather continues in the
the course of her.

Another objective is to take note of any modifications that may be recommended for
reinforce, improve or simplify the existing system. These aspects should be communicated by
means of suggestion memorandums, containing the identified deficiencies in the
business organization.

According to Bulletin 3050 issued by the Commission on Standards and Audit Procedures,
within its generalities explains to us that the study and evaluation of internal control is
It is carried out with the aim of fulfilling the work execution standard which requires that 'The control
the internal includes the organization plan and all the methods and procedures that in form
coordinated measures are adopted in an entity to safeguard its assets, verify the reasonableness and
reliability of its financial information and complementary administrative and operational information,
promote efficiency in operation and encourage adherence to the policies prescribed by the
administration.

The different types of COSO systems that have existed over time, including the
structure of each of them

COSO I
In 1992, the commission published the first report 'Internal Control - Integrated Framework'
called COSO I with the aim of helping entities to evaluate and improve their systems of
internal control, facilitating a model based on which they could evaluate their control systems
internal and generating a common definition of "internal control".

According to COSO, Internal Control is a process carried out by management and the rest of the
personnel of an entity, designed with the aim of providing a degree of security
reasonable in terms of achieving objectives within the following categories:

Effectiveness and efficiency of operations


Reliability of financial information
Compliance with applicable laws, regulations, and standards

The structure of the standard was divided into five components:

1. Control Environment
2. Risk Assessment
3. Control Activities
4. Information and Communication
5. Supervision.

COSO II
In 2004, the standard "Enterprise Risk Management - Integrated Framework" (COSO) was published.
II) Integrated Risk Management Framework that expands the concept of internal control to the
risk management necessarily involving all staff, including directors and
administrators.

COSO II (ERM) expands the COSO I framework to eight components:

1. Control environment: it is the values and philosophy of the organization, it influences the
workers' view on risks and control activities of the
same.
2. Establishment of objectives: strategic, operational, informational, and
compliances.
3. Identification of events that may impact compliance.
objectives.
4. Risk Assessment: identification and analysis of relevant risks for the
achievement of the objectives.
5. Response to the risks: determination of actions in the face of the risks.
6. Control activities: Policies and procedures that ensure they are carried out.
I take actions against risks.
7. Information and communication: effective in content and timing, to allow for the
workers fulfill their responsibilities.
8. Supervision: to monitor the activities.

COSO III
In May 2013, the third version COSO III was published. The new features it will introduce
this Integrated Risk Management Framework is:

Improvement of the agility of risk management systems to adapt to


environments
Greater confidence in risk elimination and achieving objectives
Greater clarity regarding information and communication.

Concepts and elements that are part of each of the elements of the Coso.

COMPONENTS

Internal Control consists of five interrelated components, which derive from the form
how the administration manages the entity, and they are integrated into administrative processes, the
which are classified as:

Control environment
Risk assessment
Control activities
Information and communication
Monitoring

1. CONTROL ENVIRONMENT:
Define parameters to manage the internal control of the company that relates to the
organizational structure, administrative policies, institutional ethics, and relationships
hierarchy, authority and responsibility; as well as integrity, the company’s values and the
administrative philosophy. The control environment is the foundation upon which the rest is positioned.
elements and fundamentally influences the objectives and strategy of the company.
The elements of a control environment are prioritized as follows:

Organizational Structure
Administrative policies
Institutional ethics
Company Values
Administrative Philosophy

2. RISK ASSESSMENT
During the assessment, risks are identified and [Link] to the probability of
impact and frequency, to understand their possible consequences in case they occur. In
in this process, each risk is analyzed and classified as high (it is very likely to occur),
medium (feasible) or low (very little feasible).
It is analyzed whether each impact can be internal or external and whether it is high, medium, or low for
prioritize them in that order. This evaluation serves to start working on the most
urgent and propose strategies to mitigate or avoid them.
To assess the risks,it is recommended to create a heat map, where it is classified the
impact and probability. Each is identified by a different color: High Risk (Red) -
Riesgo Medio - Alto (Naranja) - Riesgo Medio (Amarillo) - Riesgo Bajo (Verde).
The principles that should be followed in risk assessment are as follows:
The organization specifies objectives to enable the identification and assessment of the
risks.
The organization identifies and analyzes the risks.
The organization assesses the risk of fraud by analyzing the risks.
The organization identifies and assesses changes in the internal control system.

3. CONTROL ACTIVITIES
It refers to the policies and procedures that outline the appropriate actions to manage the
risks, making decisions that favor the operation and the achievement of objectives. All the
Areas of the company, without exception, are responsible for executing control activities,
that lead to a correct decision-making and fulfillment of objectives.

These control activities, according to COSO, can be preventive or detective and can
cover a wide range of manual and automated activities. These activities must
minimize the risks that hinder the achievement of the organization's objectives.

The principles of this component are as follows:


The organization designs and implements control activities to mitigate risks.
The organization designs and implements controls over its information systems.
(technology).
The organization implements policies and procedures for its control activities.

4. INFORMATION AND COMMUNICATION

Companies must manage information from all their areas and unify it to have
convergence and speaking the same language. Information is one of the most important assets.
from the organization, which must be protected and must be available to all areas of the
company, this way errors are reduced whenidentify, classify, evaluate and manage the
risks.
Therefore, the leaders of each area must ensure to gather information that allows for analysis of the
risks and exchange it to have a general view of the company. As long as we
This will be fulfilled, there will be better internal control, and obstacles that threaten the...
achievement of objectives.
In this sense, the information is not only used for financial statements but also in
decision making. For this reason, leaders must be rigorous when it comes to gathering the
information, verify them and confirm them to be true and accurate. Meanwhile, the
communication is the process of providing, sharing, and obtaining the necessary information,
relevant and of quality.
The principles related to this component are as follows:

The organization obtains and generates relevant information for its functioning.
internal control.
The organization communicates internally information for its operation.
internal control.
The organization communicates externally with third parties regarding situations that
they affect the functioning of internal control.

[Link]
Continuous monitoring of risk managementfrom the organization helps the strategies
to mitigate them effectively and reduce errors that may affect goals. Additionally,
It serves to verify the effectiveness of internal control. Adequate risk management is
achieve with supervision and continuous monitoring, as well as with frequent evaluations.

Monitoring is: 'Concurrent or separate evaluations, or a combination of both. It is


used to determine whether each of the components of Internal Control, including the
controls to implement the principles within each component are present and
functioning. The findings are evaluated and the deficiencies are communicated in a timely manner,
the significant ones are communicated to senior management and the board of directors.

With the software ofPirani Riskment Suite you will be able to register the controls you consider
necessary to prevent, detect or correct risks to which your company is exposed,
you will be able to assess them through design, execution, and solidity, and finally, you will be able to associate risks
and responsible for supervising these controls.
The principles of this component are as follows:
The organization conducts ongoing evaluations to check whether the components of
The internal control system is functioning adequately.
The organization communicates the deficiencies of internal control.

Themes that address the COSO system


Definition of "CI"
It is a process carried out by the board of directors, management, and the rest of the staff.
an entity, designed to provide a reasonable level of security regarding
to the achievement of goals within the following categories:
Effectiveness and efficiency of operations.
Reliability of financial information.
Compliance with applicable laws and regulations.
It does not constitute an isolated event or task.
It is a set of coordinated actions to achieve an end (it is not an end in itself).
This series of actions extends across all levels and activities of an organization.
CI is part of the basic processes of planning, execution, and supervision.
It is not an added element to the activities of the entity as some authors think. It should not be
see it not as an imposed and inevitable burden, but as a process intertwined with the rest of the
activities of the entity.
CIs are more effective when integrated into the infrastructure of an entity:
CIs must be incorporated, not added.
The incorporation of controls directly influences the ability to achieve objectives.
What the entity pursues, besides supporting quality initiatives.
The controls allow companies to be more agile and competitive: they impact on the
cost containment and response times.

It is carried out by people


The implementation and monitoring of the CI is carried out by the Council of
Administration, the Management, and other members of the entity.

It is not enough to have policy and manual guidelines.


The responsibility for carrying it out lies at all levels of the organization. People are
who establishes the objectives of the organization and implements the control mechanisms.
At the same time, IQ affects people's performance.
Not all members of an entity have the same objectives or functions or perform their
committed in a uniform manner.
The CI seeks a close link between the functions of each individual, the way of execution.
and the objectives of the entity.

Seek reasonable security


The CI, no matter how well designed and implemented it is, can only contribute
a reasonable degree of security to the management and the board of directors regarding the
achievement of the entity's objectives. There are inherent limitations in all systems
of CI.
Problems in the system's operation as a consequence of failures
humans.
Controls can be bypassed if two or more people set their minds to it.
Management may find it appropriate to circumvent the CI system.

The opinions on which decisions regarding CI are based


may be incorrect.
The employees in charge of the implementation of the CI need to analyze the
cost/benefit ratio.
To achieve the objectives
Every organization has a mission and vision, these determine the objectives and the
necessary strategies to achieve them. Objectives can be set for the overall
organization or for specific activities within it.
The objectives in this report can be classified into 3 categories:
Operational: effective and efficient use of the entity's resources. For example:
performance, profitability, asset safeguarding, etc.
Financial Information: preparation and publication of reliable financial statements.

The Different Methods of Evaluating Internal Control

A perhaps simpler way to obtain information about how the system operates.
internal control in an entity will be the inquiry, observation, and review of the manuals of
organization and functions, accounting and internal audit manuals, internal regulations of
work, the procedures and internal instructions and other provisions adopted by the
administration or management; as well as conversations or interviews with executives about the
constitution, organization, social capital of the company, judicial processes, amount of
workers, etc. However, the most commonly used means or methods to document
adequately the evaluation of the internal control system in the company and that to the same
The times that can serve to record having carried out the evaluation are the following
métodos: descriptivo, cuestionario, gráficos o flujogramas.

Classification of Evaluation Methods for the Internal Control System

Descriptive method:

It consists, as its name indicates, of describing or narrating the different activities of the
departments, officials and employees, and the records involved in the system. Without
embargo, one should not make the mistake of describing the activities of the departments or of
employees in an isolated or objective manner. The description should be made following the course of
the operations through its management in the mentioned departments.

Typically, it describes procedures, records, forms, files, departments that


they intervene in the control system. This method presents the drawback that many
people lack the ability to express their ideas in writing clearly, precisely and
synthetic, which results in some control weakness not being expressed
in the description.

Questionnaire method:

It involves using pre-formulated questionnaires as an instrument for research.


which include questions about how transactions or operations are handled
the people involved in its management, the way operations flow through
the positions or places where control procedures are defined or determined for the
conducting operations.

The questionnaire method is extensively used by independent auditors as the


internal auditors, consists of a systematic survey presented in the form of questions
referred to basic aspects of the system, and in the face of a negative, it reveals an absence of control.
The questionnaires can be organized by classifying the questions according to the objectives.
of control and each question refers to the presence of control measures to achieve the
the objective of the matter.

The objective of the internal control questionnaire is to gather information to uncover facts,
evidence, opinions, in order to gather data or quantitative information. The information
the obtained data must be tabulated, refined, and serve together with other agents as support for the report

of audit based on working papers.

The questionnaires address issues that participants will need to consider, focusing on their
reflection on the internal and external factors that have given rise to, or could give rise to, events

negatives.

Questions can be open or closed, depending on the objective of the survey. They can
address an individual or several, or can also be used in connection with a survey of
broader base, whether within an Organization or aimed at clients, suppliers or
third parties.

Characteristics of questionnaire writing:

In the preparation or development of a questionnaire, the auditor must keep in mind


certain fundamental characteristics, such as:

a. The questionnaire must be drafted according to the education level of the people to whom it is addressed.
direct.

b. The questions must be written clearly and allow some freedom for the respondent
Do not feel inclined to give a specific answer or to respond with yes or no.

c. Subjective terms should be avoided and if possible, questions should be concise and
necessary in order to achieve greater concentration and avoid fatigue for the interviewee.

The questions must be directed to meet the goal of the evaluation.


of internal control and should not eliminate the interview but rather complement it.

Example of Internal Control Questionnaires:


Flowchart Method (Flow Diagram):

It consists of being presented through charts or graphs. If the auditor designs a flowchart
of internal control, it will be necessary for you to visualize the flow of information and the documents that are

they process. The flowchart must be created using standard symbols so that those who
they understand the symbols can extract useful information related to the system. If the auditor uses a
flowchart prepared by the entity, must be able to read it, interpret its symbols and draw conclusions
useful conclusions regarding the system represented by the flowchart. In some cases perhaps
the graphing method has been applied, in others it may be convenient to use the method of
questionnaires, and in others it may be easier or the method may be better interpreted
narrative descriptive.

This method simplifies the task of describing procedures and techniques through the use of
of transaction movement graphs, also called flow diagrams or flow charts.
This diagram provides the reader with a clear image of the system, showing the nature and
sequence of procedures, division of responsibilities, sources, distribution of
documents and status of the accounting records.

Typesetting Techniques:

Flowcharts of processes:

The process flow analysis is the schematic representation of a process, with the aim
to understand the interrelations between inputs, tasks, outputs, and responsibilities of their
components.

Events can be identified and considered against the objectives of the process.

It can be used in a global view of the organization or at a detailed level.

Cause and effect diagrams:

They are known as Ishikawa diagrams or fishbone diagrams, and they are useful for identifying the
causes of the risks.

Sales Cycle Diagram:

After conducting the evaluation of the internal control system in an organization, one
perform the tabulation and analysis of the obtained information, subsequently a letter is issued
internal control attaching the observations and recommendations in order for the senior management
management or administration shall take the appropriate and timely corrective measures to safeguard interests.

business

Bibliographies
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
s_de_c_i_3e_cap16.pdf

You might also like