1 COMMITTEE OF SPONSORING ORGANIZATIONS OF THE TREADWAY COMMISSION Internal Control Integrated Framework Guidance on Monitoring Internal Control Systems Introduction
2 Committee of Sponsoring Organizations of the Treadway Commission Board Members Larry E. Rittenberg COSO Chair Charles E. Landes American Institute of Certified Public Accountants Mark S. Beasley American Accounting Association David A. Richards The Institute of Internal Auditors Michael P. Cangemi Financial Executives International Jeffrey Thomson Institute of Management Accountants Grant Thornton LLP Author Principal Contributors R. Trent Gazzaway (Project Leader) Managing of Corporate Governance Grant Thornton LLP Charlotte James P. Burton Grant Thornton LLP Denver J. Russell Gates President Dupage Consulting LLC Chicago Keith O. Newton Grant Thornton LLP Chicago Sridhar Ramamoorti Grant Thornton LLP Chicago Richard L. Wood Grant Thornton LLP Toronto R. Jay Brietz Senior Manager Grant Thornton LLP Charlotte Review Team Andrew D. Bailey Jr. Senior Policy Advisor Grant Thornton LLP Phoenix Dorsey L. Baskin Jr. Regional of Professional Standards Grant Thornton LLP Dallas Craig A. Emrick VP Senior Accounting Analyst Moody s Investors Service Philip B. Livingston Vice Chairman, Approva Corporation Former President and CEO, Financial Executives International COSO Task Force Abraham D. Akresh Senior Level Expert for Auditing Standards U.S. Government Accountability Office Douglas J. Anderson Corporate Auditor Dow Chemical Company Robert J. Benoit President and Director of SOX Research Lord & Benoit, LLC Richard D. Brounstein Chief Financial Officer, NewCardio, Inc. Director, The CFO Network Jennifer M. Burns Deloitte & Touche LLP Paul Caban Assistant Director U.S. Government Accountability Office James W. DeLoach Managing Director Protiviti Miles E. Everson PricewaterhouseCoopers LLP Audrey A. Gramling Associate Professor Kennesaw State University Scott L. Mitchell Chairman and CEO Open Compliance & Ethics Group James E. Newton KPMG LLP Edith G. Orenstein Director, Technical Policy Analysis Financial Executives International John H. Rife Ernst & Young LLP Michael P. Rose Grant Thornton LLP Former CEO and Senior GR Consulting LLP Robert S. Roussey Professor of Accounting University of Southern California Andre Van Hoek Vice President, Corporate Controller Celgene Corporation Observer Securities and Exchange Commission Josh K. Jones SEC Observer Professional Accounting Fellow
3 Guidance on Monitoring Internal Control Systems Introduction January 2009
4 LCN All Rights Reserved. No part of this publication may be reproduced, redistributed, transmitted or displayed in any form or by any means without written permission. For information regarding licensing and reprint permissions please contact the American Institute of Certified Public Accountants, licensing and permissions agent for COSO copyrighted materials. Direct all inquiries to or to AICPA, Attn: Manager, Rights and Permissions, 220 Leigh Farm Rd., Durham, NC Telephone inquiries may be directed to Additional copies of this work may be obtained by visiting
5 1 Monitoring: An Integral Component of Internal Control Over the past decade, organizations have invested heavily in improving the quality of their internal control systems. They have made the investment for a number of reasons, notably: (1) good internal control is good business it helps organizations ensure that operating, financial and compliance objectives are met, and (2) many organizations are required to report on the quality of internal control over financial reporting, compelling them to develop specific support for their certifications and assertions. Internal control is designed to assist organizations in achieving their objectives. The five components of COSO s Internal Control Integrated Framework (the COSO Framework) work in tandem to mitigate the risks of an organization s failure to achieve those objectives. The COSO Board recognizes that management s assessment of internal control often has been a time-consuming task that involves a significant amount of annual management and/or internal audit testing. Effective monitoring can help streamline the assessment process, but many organizations do not fully understand this important component of internal control. As a result, they underutilize it in supporting their assessments of internal control. Figure 1 depicts the comprehensive nature of monitoring and illustrates how effective monitoring considers the collective effectiveness of all five components of internal control. Monitoring Applied to the Internal Control Process Figure 1 COSO s 2008 Guidance on Monitoring Internal Control Systems (COSO s Monitoring Guidance) was developed to clarify the monitoring component of internal control. It does not replace the guidance first issued in the COSO Framework or in COSO s 2006 Internal Control over Financial Reporting Guidance for Smaller Public Companies (COSO s 2006 Guidance). Rather, it
6 2 expounds on the basic principles contained in both documents, guiding organizations in implementing effective and efficient monitoring. How Does Monitoring Benefit the Governance Process? Unmonitored controls tend to deteriorate over time. Monitoring, as defined in the COSO Framework, is implemented to help ensure that internal control continues to operate effectively. 1 When monitoring is designed and implemented appropriately, organizations benefit because they are more likely to: Identify and correct internal control problems on a timely basis, Produce more accurate and reliable information for use in decision-making, Prepare accurate and timely financial statements, and Be in a position to provide periodic certifications or assertions on the effectiveness of internal control. Over time effective monitoring can lead to organizational efficiencies and reduced costs associated with public reporting on internal control because problems are identified and addressed in a proactive, rather than reactive, manner. Fundamentals of Effective Monitoring COSO s Monitoring Guidance builds on two fundamental principles originally established in COSO s 2006 Guidance: 2 Ongoing and/or separate evaluations enable management to determine whether the other components of internal control continue to function over time, and Internal control deficiencies are identified and communicated in a timely manner to those parties responsible for taking corrective action and to management and the board as appropriate. The monitoring guidance further suggests that these principles are best achieved through monitoring that is based on three broad elements: Establishing a foundation for monitoring, including (a) a proper tone at the top; (b) an effective organizational structure that assigns monitoring roles to people with appropriate capabilities, objectivity and authority; and (c) a starting point or baseline of known effective internal control from which ongoing monitoring and separate evaluations can be implemented; 1 COSO Framework, p See principles #19 and #20 in COSO s Internal Control over Financial Reporting Guidance for Smaller Public Companies issued in 2006 (COSO s 2006 Guidance).
7 3 Designing and executing monitoring procedures focused on persuasive information about the operation of key controls that address meaningful risks to organizational objectives; and Assessing and reporting results, which includes evaluating the severity of any identified deficiencies and reporting the monitoring results to the appropriate personnel and the board for timely action and follow-up if needed. Breadth of Monitoring Processes Organizations may select from a wide variety of monitoring procedures, including but not limited to: Periodic evaluation and testing of controls by internal audit, Continuous monitoring programs built into information systems, Analysis of, and appropriate follow-up on, operating reports or metrics that might identify anomalies indicative of a control failure, Supervisory reviews of controls, such as reconciliation reviews as a normal part of processing, Self-assessments by boards and management regarding the tone they set in the organization and the effectiveness of their oversight functions, Audit committee inquiries of internal and external auditors, and Quality assurance reviews of the internal audit department. Continued advancements in technology and management techniques ensure that internal control and related monitoring processes will change over time. However, the fundamental concepts of monitoring, as outlined in COSO s Monitoring Guidance, are designed to stand the test of time. Using the Guidance to Move Monitoring Forward Management can begin the monitoring process by encouraging the people with control system responsibility to read COSO s Monitoring Guidance and consider how best to implement it or whether it has already been incorporated into certain areas. Further, personnel with appropriate skills, authority and resources should be charged by management with addressing these four fundamental questions: 1. Have we identified the meaningful risks to our objectives, for example, the risks related to producing accurate, timely and complete financial statements? 2. Which controls are key controls that will best support a conclusion regarding the effectiveness of internal control in those risk areas? 3. What information will be persuasive in telling us whether the controls are continuing to operate effectively?
8 4 4. Are we presently performing effective monitoring that is not well utilized in the evaluation of internal control, resulting in unnecessary and costly further testing? Management and the board of directors should understand the concepts of effective monitoring and how it serves their respective interests. As the board learns more about monitoring, it will develop the knowledge necessary to ask management in relation to any area of meaningful risk, How do you know the internal control system is working? COSO s Monitoring Guidance is designed to help organizations answer these and other questions within the context of their own unique circumstances circumstances that will change over time. As they progress in achieving effectiveness in monitoring, organizations likely will have the opportunity to further improve the process through the use of such tools as continuous monitoring software and exception reports tailored to their processes. The guidance also covers other concepts that are important to effective and efficient monitoring, including: The characteristics associated with the objectivity of the evaluator; The period of time and the circumstances by which an organization can rely on adequately designed indirect information when used in combination with ongoing or periodic persuasive direct information to conclude that internal control remains effective; Determining the sufficiency and suitability of information used in monitoring to ensure that the results can adequately support conclusions about internal control; and Ways in which the organization can make monitoring more efficient without reducing its effectiveness. COSO s Monitoring Guidance encompasses three volumes. Volume I presents the fundamental principles of effective monitoring and develops the linkage to the COSO Framework. Volume II conveys in greater detail the principles outlined in Volume I and provides guidance to those responsible for implementing effective monitoring. Volume III contains examples of effective monitoring. Many organizations, through applying the concepts set forth in the guidance, should improve the effectiveness and efficiency of their internal control systems. To that end, COSO s Monitoring Guidance is designed to help organizations (1) identify effective monitoring where it already exists and use it to the maximum benefit, and (2) identify less effective or efficient monitoring, leading to improvements. In both instances, the internal control system may be improved, increasing the likelihood that organizational objectives will be achieved.
10 Committee of Sponsoring Organizations of the Treadway Commission COSO is a voluntary private sector organization dedicated to improving the quality of financial reporting through business ethics, effective internal controls, and corporate governance.
Internal Control over Financial Reporting Guidance for Smaller Public Companies Volume I : Executive Summary Committee of Sponsoring Organizations of the Treadway Commission Board Members Larry E. Rittenberg
Committee of Sponsoring Organizations of the Treadway Commission Governance and Internal Control LEVERAGING COSO ACROSS THE THREE LINES OF DEFENSE By The Institute of Internal Auditors Douglas J. Anderson
Enterprise Risk Management Integrated Framework Executive Summary September 2004 Copyright 2004 by the Committee of Sponsoring Organizations of the Treadway Commission. All rights reserved. You are hereby
C o m m i t t e e o f S p o n s o r i n g O r g a n i z a t i o n s o f t h e T r e a d w a y C o m m i s s i o n G o v e r n a n c e a n d O p e r a t i o n a l P e r f o r m a n c e I m p r o v i n g
C o m m i t t e e o f S p o n s o r i n g O r g a n i z a t i o n s o f t h e T r e a d w a y C o m m i s s i o n G o v e r n a n c e a n d I n t e r n a l C o n t r o l C O S O I N T H E C Y B E R A G
Examination of an Entity s Internal Control 1403 AT Section 501 An Examination of an Entity s Internal Control Over Financial Reporting That Is Integrated With an Audit of Its Financial Statements Source:
Sarbanes-Oxley Section 404 Work Looking at the Benefits by Larry E. Rittenberg, Ph.D., CIA, CPA Ernst & Young Professor of Accounting University of Wisconsin and Patricia K. Miller, CIA, CPA, CISA Partner,
Internal Control - Integrated Framework Executive Summary Senior executives have long sought ways to better control the enterprises they run. Internal controls are put in place to keep the company on course
Practice Guide Reliance by Internal Audit on Other Assurance Providers DECEMBER 2011 Table of Contents Executive Summary... 1 Introduction... 1 Principles for Relying on the Work of Internal or External
Standards for Internal Control in New York State Government October 2007 Thomas P. DiNapoli State Comptroller A MESSAGE FROM STATE COMPTROLLER THOMAS P. DINAPOLI My Fellow Public Servants: For over twenty
What Every Director Should Know How to get the most from your internal audit Endorsed by Foreword This is the second edition of our flagship governance guide What every director should know. Since we published
Corporate Governance Toolkit for small and medium enterprises: 2 nd Edition April 2005 CORPORATE GOVERNANCE TOOLKIT Forward This series of information sheets is part of the CPA Australia program to advance
Training Material on Internal Auditing 1 Session 1 External Audit...5 1.1 Definition and Objective...5 1.2 Responsibilities of External Audit...5 1.3 Scope of the Audit...6 1.4 Auditor s Report Basic Elements...6
IIA Position Paper: THE THREE LINES OF DEFENSE IN EFFECTIVE RISK MANAGEMENT AND CONTROL JANUARY 2013 TABLE OF CONTENTS Introduction... 1 Before the Three Lines: Risk Management Oversight and Strategy-Setting...
1 Copyright 2015 by American Institute of Certified Public Accountants, Inc. New York, NY 10036-8775 All rights reserved. For information about the procedure for requesting permission to make copies of
2 SECOND EDITION IT governance is the term used to describe how those persons entrusted with governance of an entity will consider IT in their supervision, monitoring, control and direction of the entity.
The Guide to Not-For-Profit Governance 2014 Title Not-For-Profit Governance and Best Practices 1 New Governance Rules for New York Not-For-Profit Corporations It s Time to Prepare 2 Duties and Liabilities
The Auditor s Communication With Governance 2083 AU Section 380 The Auditor s Communication With Those Charged With Governance (Supersedes SAS No. 61.) Source: SAS No. 114. Effective for audits of financial
CORPORATE RESPONSIBILITY AND CORPORATE COMPLIANCE: A Resource for Health Care Boards of Directors THE OFFICE OF INSPECTOR GENERAL OF THE U.S. DEPARTMENT OF HEALTH AND HUMAN SERVICES AND THE AMERICAN HEALTH
GAO United States General Accounting Office Executive Guide March 2004 Version 1.1 INFORMATION TECHNOLOGY INVESTMENT MANAGEMENT A Framework for Assessing and Improving Process Maturity a GAO-04-394G March
M-IC Comptroller of the Currency Administrator of National Banks January 2001 M Management Table of Contents OVERVIEW... 1 BACKGROUND... 1 Objectives... 2 Regulatory Requirements... 3 Components... 5 OCC
INTUITIVE SURGICAL, INC. CORPORATE GOVERNANCE GUIDELINES The Board of Directors (the Board ) of Intuitive Surgical, Inc., a Delaware corporation (the Company ), has adopted the following Corporate Governance
Internal Audit's Value Addition Approach - A Study in the Dallas-Fort Worth Area The Research Committee of the Dallas Chapter of the IIA 2011 Internal Audit s Value Addition Approach- a Study in the Dallas-Fort
20 Questions Directors Should Ask about Internal Audit Second Edition John Fraser, CA, CIA, CISA Hugh Lindsay, FCA, CIP How to use this publication Each 20 Questions briefing is designed to be a concise,
United States Government Accountability Office Report to Congressional Committees March 2015 DEFENSE SCIENCE AND TECHNOLOGY Further DOD and DOE Actions Needed to Provide Timely Conference Decisions and
Fraud Control in Australian Government Entities Better Practice Guide March 2011 This Better Practice Guide was prepared by the Australian National Audit Office and KPMG. ISBN No. 0 642 81180 6 Commonwealth
Business Ethics Infrastructure 6 This chapter examines an essential element of a business ethics program: business ethics infrastructure the structures and systems that help enterprise owners and managers
INTEGRATED SILICON SOLUTION, INC. CORPORATE GOVERNANCE PRINCIPLES Effective January 9, 2015 These principles have been adopted by the Board of Directors (the "Board") of Integrated Silicon Solution, Inc.