COSO Framework 2013 & SOX Compliance. Roxanne L. Halverson, CISM, CGEIT Atlanta ISACA Geek Week August 19, 2013

Size: px
Start display at page:

Download "COSO Framework 2013 & SOX Compliance. Roxanne L. Halverson, CISM, CGEIT Atlanta ISACA Geek Week August 19, 2013"

Transcription

1 COSO Framework 2013 & SOX Compliance Roxanne L. Halverson, CISM, CGEIT Atlanta ISACA Geek Week August 19, 2013

2 What s Happened On May 14, 2013, after a little more than 20 years the Committee of Sponsoring Organizations of the Treadway Commission (a/k/a as COSO) has revised its widely used 1992 framework to update it for the modern realities of how business is carried out two decades later, especially with respect to how technology is used in business. COSO specifically set its transition date and determined it will no longer make its earlier version available after December 15, 2014 to facilitate a transition. 2

3 Call to Action Each publicly traded company subject to SOX Section 404 compliance must gain senior management s alignment & support, assess the impact of the Framework on existing SOX compliance activities and then complete a timely transition to the updated Framework no later than December 15,

4 Background Authored by PwC under the direction of COSO Widely adopted by organizations around the world COSO developed the related illustrative documents to provide tools to assist companies in implementing or evaluating their system of internal control & offer specific approaches & examples as to how the Framework applies to external financial reporting. 4

5 Drivers Behind COSO s Refresh Project Result of a significant multi-year project 2 rounds of public exposure Lessons Learned from applying the original framework Included lengthy discussions of internal control concepts that are not institutional knowledge Concepts of internal control principles may have been embedded in the original Framework, the principles themselves were hidden within the details Practitioners have used the Framework primarily for internal control over financial reporting yet the Framework encompasses 3 major categories of objectives, including operations, overall reporting, and compliance objectives Objective was to keep COSO relevant & streamline the original Framework Clarify the requirement of effective internal control Update the context for applying internal control to many changes in business an operating environments Broaden its application by expanding the operations and reporting objectives Enhancing usability 5

6 Newly Release COSO Documents Internal Control-Integrated Framework Executive Summary Provides a high-level overview of the 2013 Framework & is intended for the CEO & other senior management, BODs and regulators Internal Control-Integrated Framework & Appendices 175 pages that defines the Framework in detail Defines internal control, underlying principles & direction for all levels of mgt. Internal Control-Integrated Framework Illustrated Tools for Assessing Effectiveness of a System of Internal Control Provides templates and scenarios to support mgt. in applying the Framework, specifically in terms of assessing effectiveness. Internal Control over External Financial Reporting: A Compendium of Approaches & Examples Provides practical approaches & examples illustrating how the components & principles in the Framework can be applied in preparing external financial statements. Intended to be used as a resource to research on specific principles vs. being read cover to cover 6

7 Case for Transition COSO Board emphasized that the key concepts and principles defined in the original Framework remain fundamentally sound for designing, implementing, & maintaining systems of internal controls & assessing effectiveness Next slides review Fundamentals Retained 7

8 Fundamentals Retained Report s general organization structure & component chapter structure Formal definition of internal control COSO Cube 5 components that work together in an integrated manner Control environment Risk Assessment Control Activities Information & communication Monitoring Activities 8

9 Fundamental remaining page 2 Emphasis that internal control is a process effected by people that can only provide reasonable vs. absolute assurance and has inherent limitations Internal control is geared toward achieving specified objectives Internal control can be applied at the entity level or any of an entity s units Concepts relating to cost-benefit analysis Mgt needs to use judgment but cost alone is not an acceptable reason to avoid implementing internal controls Discussion of appropriate documentation Relationship between the management process & internal control Importance of management s judgment in designing, implementing, and conducting internal control, and assessing its effectiveness 9

10 One Transition Approach Step 1: Develop Awareness, Expertise & Alignment Step 2: Conduct Preliminary Impact Assessment Step 3: Facilitate Broad Awareness, Training, and Comprehensive Assessment Step 4: Develop and Execute COSO Transition Plan for SOX Compliance Step 5: Drive Continuous Improvement 10

11 Step 1- Develop Awareness, Expertise & Alignment Provide awareness to senior management so gain their support Initial audience COSO/SOX subject matter experts in your company Obtain & review newly released publications (listed on prior slide) In addition to those go to COSO website ( which includes press releases and Frequently Asked Questions document 11

12 Webinars Step 1 Other resources Articles External auditor Networking & building connections with peers at similar companies can benefit you & your teams. 12

13 COSO Timeless Concepts Internal Controls is a process effected by an entity s board of directors, management, and other personnel, designed to provide reasonable assurance regarding the achievement of objectives relating to operations, reporting, and compliance Still provides for 3 categories of objectives: Operations Reporting Compliance Still provides 5 integrated components Control Environment Risk Assessment Control Activities Information & Communication Monitoring Activities Continues to allow a company to consider internal controls from an entity, division, operating unit or function like a shared service center/center of excellence Updated COSO Cube 13

14 Expanded Reporting Category Under objective categories, the reporting category was expanded to include not only external reporting but internal reporting and nonfinancial reporting objectives Explicitly permits use in these other reporting situations even though they aren t directly relevant from a SOX perspective 14

15 The most significant enhancement is the formulation of 17 Principles of internal control which serve as the criteria for determining whether an entity s internal control is effective 1992 Framework conceptually introduced 17 relevant principles associated with the 5 components of internal control They are essential in assessing that the 5 components are present & functioning These concepts are now explicitly articulated in the 17 principles COSO Board believes each principle adds value & is suitable to all entities presumed relevant Document the rationalization if a principle isn t relevant CONTROL ENVIRONMENT 1. Demonstrates commitment to integrity & ethical values 2. Exercises oversight responsibility 3. Establishes structure, authority & responsibility 4. Demonstrates commitment to competence 5. Enforces accountability RISK ASSESSMENT 6. Specifies suitable objectives 7. Identifies and analyzes risk 8 Assess fraud risk 9. Identifies and analyzes significant change CONTROL ACTIVITIES 10. Selects & develops control activities 11. Selects & develops general controls over technology 12. Deploys through policies & procedure INFORMATION & COMMUNICATIONS 13. Uses relevant information 14. Communicates internally 15, Communicates externally MONITORING 16. Conducts ongoing and/or separate evaluations 17. Evaluates & communicates deficiencies 15

16 Requirements of Effective Internal Control For management to conclude that its system of internal control is effective, all 5 components of internal control and all relevant principles must be present & functioning Being present implies a given component or principle exists within the design & implementation of an entity s system of internal control Functioning implies the component or principle continues to exist in the operation & conduct of the internal control system Effective internal control also requires that all 5 components operate together in an integrated manner. Management can conclude they do if each component is present and functioning and the aggregation of internal control deficiencies across the components doesn t result in one or more major deficiences 16

17 Internal Control Deficiencies A major deficiency exists if an internal control deficiency or combination thereof severely reduces the likelihood of an entity achieving it s objectives If mgt. used it s professional judgment to determine that a control objective isn t being met because a relevant principle or associated component isn t present & functioning or the 5 components aren t operating together, the entity has a major deficiency While the 2013 Framework defines the terms deficiency & major deficiency mgt should use relevant criteria as established by standards-setting bodies, regulators and other relevant third parties for defining the severity of evaluating and reporting deficiencies 17

18 Points of Focus provided by 2013 Framework Describes to assist management in the design, implementation, and maintaining internal control & assessing whether the 17 principles are present & functioning Represent important characteristics of the respective principles defined in Framework or uniquely identified by management Enablers not required in order to have an effective system of internal control 18

19 Step 2: Conduct Preliminary Impact Assessment Once 2013 Framework is understood you need to assess how transitioning to it will impact your company s current SOX program The most significant factor may be how well management implemented the original one Map your existing system of internal control against the update Framework This will help you determine the degree of work required to complete the transition Instead of mapping directly to the 5 components of internal control, first map to the 17 principles that underlie each of the 5 components Develop a list of gaps to remediate 19

20 Step 3: Facilitate Broad Awareness, Training, and Comprehensive Assessment Step 1 & 2 targeted the company s SOX compliance subject matter experts or core SOX compliance team Step 3 engaging the broader organization to build awareness & to build awareness and to pressure-test the preliminary impact assessment conducted in Step 2 Depending on the nature & complexity of your organization, SOX compliance efforts may occur centrally, or there may be multiple layers of assessment Example each Business Unit or location may prepare it s own local assessment 20

21 Step 3 continued Either way, you should facilitate broad awareness of COSO s updated Framework & the potential impact on your SOX compliance program Discuss the impact of COSO s 2013 Framework on your SOX efforts with your company s external auditors. Provide stakeholders a brief update, via or in person, will be sufficient. In other cases, in-depth training & work sessions may be needed 21

22 Step 3 continued Leverage key stakeholders, such as process/controls owner or business unit SOX leads, to pressure-test you preliminary impact assessment, especially in a more decentralized or highly complex environment Have those who are directly responsible for implementing your company s SOX controls critique the preliminary mapping from Step 2 to ensure analysis is complete & accurate 22

23 Step 4 Develop & Execute COSO Transition Plan for SOX Compliance Planning Phase finalize your company s updated SOX compliance: Methodology & approach Define project governance & decision rights Develop a detailed project plan with key milestones Identify and assign resources, and complete other necessary planning activities Set realistic plans & expectations Regardless of current SOX compliance programs some effort in transition is required 23

24 Step 4 Phase 1 Documentation & Evaluation You may need to update the format and or flow of your underlying documentation aligning it to the new mapping created during Step 2. All 5 components of internal control and all relevant principles must be present and functioning Underlying documentation must support management in making such a conclusion Phase entails evaluating the design of the underlying controls & enhancing the design as needed 24

25 Step 4 Phase 2: Validation Testing & Gap Remediation Once you re satisfied that your company s controls around external financial reporting and disclosure are effective in their design, you need to perform SOX validation testing to ensure these controls have been implemented and are operating as expected. Remediate any action items or gaps if deficiencies are identifed 25

26 Step 4: Phase 3 External Review & Testing Prepare for the external auditor needing/wanting to assess & gain comfort with the updated SOX compliance program and supporting documentation. 26

27 Step 5: Drive Continuous Improvement Adequate vs. best-in-class system of internal controls Stronger corporate governance should translate into stronger business results & increased shareholder value 27

28 Step 5 continued Once 2013 Framework transition is complete, challenge yourself to drive continuous improvement with these practices: Ensure there is appropriate tone at the top Embed internal control responsibility into the fabric of your company s culture, business processes & procedures Improve control reporting & communication Enhance your enterprise risk management capability Tooling & Automation 28

29 Call to Action Last reminder Key Takeaway Those who currently use COSO s 1992 Framework should complete their transition to the 2013 version no later than December 15, 2014 as the former version will be superseded While most companies expect few changes & a relatively smooth transition you still need to work through it The onus is on us / those working in publicly traded companies subject to SOX Section 404 compliance to build awareness, assess the impact, complete timely transition The 5-step process is one approach that could support you and your team s success 29

30 COSO COBIT Mapping 30

31 Questions? Contact Information: Roxanne Halverson

32 The Committee of Sponsoring Organizations of the Treadway Commission (COSO) PIP Kathleen Hoffeilder, CFO. Com, May 21, 2013, New Guidelines Could Help Deter Fraud J. Stephen McNally, CPA, The 2013 COSO Framework & SOX Compliance, Strategic Finance, June 2013 PwC Dataline, A Look At Current Financial Reporting Issues, No , dated May 14, Richard M. Steinberg, Compliance Week, July, 3013, Insights Into COSO s Internal Control Framework, pages Tammy Whitehouse, icompli, So Far, SEC Hold Silent on New COSO Framework, May 22,

The 2013 COSO Framework & SOX Compliance

The 2013 COSO Framework & SOX Compliance The 2013 COSO Framework & SOX Compliance ONE APPROACH TO AN EFFECTIVE TRANSITION By J. Stephen McNally, CPA The 2013 COSO Framework & SOX Compliance ONE APPROACH TO AN EFFECTIVE TRANSITION By J. Stephen

More information

COSO 2013: WHAT HAS CHANGED & STEPS TO TAKE TO ENSURE COMPLIANCE

COSO 2013: WHAT HAS CHANGED & STEPS TO TAKE TO ENSURE COMPLIANCE COSO 2013: WHAT HAS CHANGED & STEPS TO TAKE TO ENSURE COMPLIANCE COMMITTEE OF SPONSORING ORGANIZATIONS (COSO) 2013 The Committee of Sponsoring Organizations (COSO) Internal Controls Integrated Framework,

More information

COSO 2013 Internal Control Integrated Framework FRED J. PETERSON, PARTNER MOSS ADAMS LLP

COSO 2013 Internal Control Integrated Framework FRED J. PETERSON, PARTNER MOSS ADAMS LLP COSO 2013 Internal Control Integrated Framework FRED J. PETERSON, PARTNER MOSS ADAMS LLP Disclaimer The material appearing in this presentation is for informational purposes only and should not be construed

More information

Internal Control Integrated Framework. May 2013

Internal Control Integrated Framework. May 2013 Internal Control Integrated Framework May 2013 0 Table of Contents COSO & Project Overview Internal Control-Integrated Framework Illustrative Documents Illustrative Tools for Assessing Effectiveness of

More information

Impact of New Internal Control Frameworks

Impact of New Internal Control Frameworks Impact of New Internal Control Frameworks Webcast: Tuesday, February 25, 2014 CPE Credit: 1 0 With You Today Bob Jacobson Principal, Risk Advisory Services Consulting Leader West Region Bob.Jacobson@mcgladrey.com

More information

COSO Internal Control Integrated Framework (2013)

COSO Internal Control Integrated Framework (2013) COSO Internal Control Integrated Framework (2013) The Committee of Sponsoring Organizations of the Treadway Commission (COSO) released its updated Internal Control Integrated Framework (2013 Framework)

More information

COSO s 2013 Internal Control Framework in Depth: Implementing the Enhanced Guidance for Internal Control over External Financial Reporting

COSO s 2013 Internal Control Framework in Depth: Implementing the Enhanced Guidance for Internal Control over External Financial Reporting in Depth: Implementing the Enhanced Guidance for Internal Control over External Financial Reporting Table of Contents EXECUTIVE SUMMARY... 3 BACKGROUND... 3 SIGNIFICANT CHANGES AFFECTING INTERNAL CONTROL

More information

RISK BASED AUDITING: A VALUE ADD PROPOSITION. Participant Guide

RISK BASED AUDITING: A VALUE ADD PROPOSITION. Participant Guide RISK BASED AUDITING: A VALUE ADD PROPOSITION Participant Guide About This Course About This Course Adding Value for Risk-based Auditing Seminar Description In this seminar, we will focus on: The foundation

More information

International Institute of Management

International Institute of Management Executive Education Executive Action Learning Seminars Executive Seminars Executive Courses International Institute of Management Executive Education Courses CIO & Sarbanes Oxley Compliance SOX Implementation

More information

COSO 2013 Internal Control Framework

COSO 2013 Internal Control Framework COSO 2013 Internal Control A Guide to Implementation July 24, 2014 Justin Adamson Agenda COSO Background Changes to the Roadmap to Implementation Implementation Considerations & Lessons Learned 2 1 Who/What

More information

Mapping COBIT 5 with IT Governance, Risk and Compliance at Ecopetrol S.A. By Alberto León Lozano, CISA, CGEIT, CIA, CRMA

Mapping COBIT 5 with IT Governance, Risk and Compliance at Ecopetrol S.A. By Alberto León Lozano, CISA, CGEIT, CIA, CRMA Volume 3, July 2014 Come join the discussion! Alberto León Lozano will respond to questions in the discussion area of the COBIT 5 Use It Effectively topic beginning 21 July 2014. Mapping COBIT 5 with IT

More information

Internal Controls over Financial Reporting. Integrating in Business Processes & Key Lessons learned

Internal Controls over Financial Reporting. Integrating in Business Processes & Key Lessons learned Internal Controls over Financial Reporting Integrating in Business Processes & Key Lessons learned Introduction Stephen McIntyre, CA, CPA (Illinois) Senior Manager at Ernst & Young in the Risk Advisory

More information

Leveraging Effective Risk Management and Internal Control

Leveraging Effective Risk Management and Internal Control Leveraging Effective Risk Management and Internal Control By J. Stephen McNally, CPA, and Vincent H. Tophoff, RA Effective risk management and internal control (RM/IC) is an important driver of business

More information

The Updated COSO Internal Control Framework. Frequently Asked Questions

The Updated COSO Internal Control Framework. Frequently Asked Questions The Updated COSO Internal Control Framework Frequently Asked Questions Introduction The Committee of Sponsoring Organizations of the Treadway Commission (COSO) an organization providing thought leadership

More information

Internal Control over Financial Reporting Guidance for Smaller Public Companies

Internal Control over Financial Reporting Guidance for Smaller Public Companies Internal Control over Financial Reporting Guidance for Smaller Public Companies Frequently Asked Questions Internal Control over Financial Reporting Guidance for Smaller Public Companies Frequently Asked

More information

Enterprise Risk Management

Enterprise Risk Management Cayman Islands Society of Professional Accountants Enterprise Risk Management March 19, 2015 Dr. Sandra B. Richtermeyer, CPA, CMA What is Risk Management? Risk management is a process, effected by an entity's

More information

Internal Financial Controls

Internal Financial Controls Internal Financial Controls Who All Are Responsible? 3 What is Internal Financial Control (IFC)? 5 What is Internal financial controls over financial reporting (ICFR)? Internal Controls Global Perspective

More information

Enterprise Risk Management: COSO, New COSO, ISO 31000. Review of ERM

Enterprise Risk Management: COSO, New COSO, ISO 31000. Review of ERM Enterprise Risk Management: COSO, New COSO, Dr. Hugh Van Seaton, Ed. D., CSSGB, CGMA, CPA Review of ERM COSO a process, effected by an entity's board of directors, management and other personnel, applied

More information

Developing Effective Internal Controls Using the COSO Model

Developing Effective Internal Controls Using the COSO Model Developing Effective Internal Controls Using the COSO Model Office of State Controller Internal Controls in a COSO Environment Seminar Raleigh, North Carolina March 2007 Mark S. Beasley Director, ERM Initiative

More information

Strategic Risk Assessment. A first step for improving risk management and governance. COVER STORY. By Mark L. Frigo and Richard J.

Strategic Risk Assessment. A first step for improving risk management and governance. COVER STORY. By Mark L. Frigo and Richard J. Strategic Risk Assessment ILLUSTRATION: TIM LEE/WWW.LEEILLO.COM A first step for improving risk management and governance. By Mark L. Frigo and Richard J. Anderson December 2009 I STRATEGIC FINANCE 25

More information

Change Management. Tools and Techniques for Change Management Success

Change Management. Tools and Techniques for Change Management Success Change Management Tools and Techniques for Change Management Success Insert Title Here INTRODUCTION ScottMadden has long recognized the managerial challenges caused by change. Our clients consider our

More information

How quality assurance reviews can strengthen the strategic value of internal auditing*

How quality assurance reviews can strengthen the strategic value of internal auditing* How quality assurance reviews can strengthen the strategic value of internal auditing* PwC Advisory Internal Audit Table of Contents Situation Pg. 02 In response to an increased focus on effective governance,

More information

SARBANES-OXLEY SECTION 404: A Guide for Management by Internal Controls Practitioners

SARBANES-OXLEY SECTION 404: A Guide for Management by Internal Controls Practitioners SARBANES-OXLEY SECTION 404: A Guide for Management by Internal Controls Practitioners SARBANES-OXLEY SECTION 404: A Guide for Management by Internal Controls Practitioners The Institute of Internal Auditors

More information

A&CS Assurance Review. Accounting Policy Division Rule Making Participation in Standard Setting. Report

A&CS Assurance Review. Accounting Policy Division Rule Making Participation in Standard Setting. Report A&CS Assurance Review Accounting Policy Division Rule Making Participation in Standard Setting Report April 2010 Table of Contents Background... 1 Engagement Objectives, Scope and Approach... 1 Overall

More information

How to achieve excellent enterprise risk management Why risk assessments fail

How to achieve excellent enterprise risk management Why risk assessments fail How to achieve excellent enterprise risk management Why risk assessments fail Overview Risk assessments are a common tool for understanding business issues and potential consequences from uncertainties.

More information

Sarbanes-Oxley Section 404 Implementation Practices of Leading Companies

Sarbanes-Oxley Section 404 Implementation Practices of Leading Companies Sarbanes-Oxley Section 404 Implementation Practices of Leading Companies Sarbanes-Oxley Section 404 Implementation Practices of Leading Companies Dr. Robert A. Howell Distinguished Visiting Professor of

More information

IT audit updates. Current hot topics and key considerations. IT risk assessment leading practices

IT audit updates. Current hot topics and key considerations. IT risk assessment leading practices IT audit updates Current hot topics and key considerations Contents IT risk assessment leading practices IT risks to consider in your audit plan IT SOX considerations and risks COSO 2013 and IT considerations

More information

Auditor Attestation of Internal Control Over Financial Reporting: What You Can Expect. A Smaller Public Company Perspective

Auditor Attestation of Internal Control Over Financial Reporting: What You Can Expect. A Smaller Public Company Perspective Auditor Attestation of Internal Control Over Financial Reporting: What You Can Expect A Smaller Public Company Perspective Smaller public companies were required to comply with the management assertion

More information

Sarbanes-Oxley Compliance Workbook. From Zero to SOX. Sarbanes-Oxley Compliance Workbook. sensiba san filippo www.ssfllp.com sox@ssfllp.

Sarbanes-Oxley Compliance Workbook. From Zero to SOX. Sarbanes-Oxley Compliance Workbook. sensiba san filippo www.ssfllp.com sox@ssfllp. From Zero to SOX Zero to SOX An Overview The goals of a program to meet SOX 404 requirements go far beyond compliance. The process of building a sustainable, comprehensive internal control environment

More information

Internal Controls and Risk Management Report

Internal Controls and Risk Management Report 42 Internal Controls and Risk Management Report Responsibility Our Board of Directors has the overall responsibility to ensure that sound and effective internal controls are maintained, while management

More information

ACCA P1 Internal Control. incorporated into Combined code, it was last revised in 2005 and still present as a standalone document.

ACCA P1 Internal Control. incorporated into Combined code, it was last revised in 2005 and still present as a standalone document. Internal Control ACCA P1 Internal Control Turnbull Report 1999 provided guidance for creating strong internal control system and later incorporated into Combined code, it was last revised in 2005 and still

More information

Internal Auditing Guidelines

Internal Auditing Guidelines Internal Auditing Guidelines Recommendations on Internal Auditing for Lottery Operators Issued by the WLA Security and Risk Management Committee V1.0, March 2007 The WLA Internal Auditing Guidelines may

More information

February 2015. Sample audit committee charter

February 2015. Sample audit committee charter February 2015 Sample audit committee charter Sample audit committee charter This sample audit committee charter is based on observations of selected companies and the requirements of the SEC, the NYSE,

More information

How To Write An Impactful Audit Report

How To Write An Impactful Audit Report IIA Chicago Chapter 53 rd Annual Seminar April 15, 2013, Donald E. Stephens Convention Center @IIAChicago #IIACHI How To Write An Impactful Audit Report The role of Audit adds increasingly more value Susan

More information

University Audit and Compliance. Internal Controls Enterprise-Wide Risk Assessment

University Audit and Compliance. Internal Controls Enterprise-Wide Risk Assessment Internal Controls Enterprise-Wide Risk Assessment Balancing Risk and Controls In order to achieve goals and objectives, management needs to effectively balance risks and controls. Control procedures need

More information

The Updated COSO Internal Control Framework

The Updated COSO Internal Control Framework The Updated COSO Internal Control Framework Frequently Asked Questions Second Edition Introduction The Committee of Sponsoring Organizations of the Treadway Commission (COSO) an organization providing

More information

2015-16 Internal Control Questionnaire and Assessment

2015-16 Internal Control Questionnaire and Assessment Bureau of Financial Monitoring and Accountability Florida Department of Economic Opportunity September 9, 2015 107 East Madison Street Caldwell Building Tallahassee, Florida 32399 www.floridajobs.org TABLE

More information

7/22/2014. From Treadway To the Cube (1987 2014) So, Who is COSO? What Does COSO Do?

7/22/2014. From Treadway To the Cube (1987 2014) So, Who is COSO? What Does COSO Do? From Treadway To the Cube (1987 2014) National Society of Accountants for Cooperatives (NSAC) CLAconnect.com Instructor: Ron Durkin, CPA/CFF, CFE, CIRA National Principal in Charge Fraud & Misconduct Investigations

More information

Response e-mailed to comments@pcaobus.org

Response e-mailed to comments@pcaobus.org Richard F. Chambers Certified Internal Auditor Certified Government Auditing Professional Certification in Control Self-Assessment President and Chief Executive Officer DATE Office of the Secretary PCAOB

More information

1. FPO. Guide to the Sarbanes-Oxley Act: IT Risks and Controls. Second Edition

1. FPO. Guide to the Sarbanes-Oxley Act: IT Risks and Controls. Second Edition 1. FPO Guide to the Sarbanes-Oxley Act: IT Risks and Controls Second Edition Table of Contents Introduction... 1 Overall IT Risk and Control Approach and Considerations When Complying with Sarbanes-Oxley...

More information

Sarbanes-Oxley Control Transformation Through Automation

Sarbanes-Oxley Control Transformation Through Automation Sarbanes-Oxley Control Transformation Through Automation An Executive White Paper By BLUE LANCE, Inc. Where have we been? Where are we going? BLUE LANCE INC. www.bluelance.com 713.255.4800 info@bluelance.com

More information

Guide to the Sarbanes-Oxley Act: IT Risks and Controls. Frequently Asked Questions

Guide to the Sarbanes-Oxley Act: IT Risks and Controls. Frequently Asked Questions Guide to the Sarbanes-Oxley Act: IT Risks and Controls Frequently Asked Questions Table of Contents Page No. Introduction.......................................................................1 Overall

More information

Director Notes. Strategic Risk Management: A Primer for Directors

Director Notes. Strategic Risk Management: A Primer for Directors Director Notes Strategic Risk Management: A Primer for Directors by Mark L. Frigo and Richard J. Anderson Recent significant risk events, including catastrophic weather events, cybercrime, macroeconomic

More information

ENTERPRISE RISK MANAGEMENT POLICY

ENTERPRISE RISK MANAGEMENT POLICY ENTERPRISE RISK MANAGEMENT POLICY TITLE OF POLICY POLICY OWNER POLICY CHAMPION DOCUMENT HISTORY: Policy Title Status Enterprise Risk Management Policy (current, revised, no change, redundant) Approving

More information

Assessing & Managing IT Risk

Assessing & Managing IT Risk Assessing & Managing IT Risk ISACA Pittsburgh Chapter Meeting October 18, 2010 Agenda Introductions IT Risk Assessment An Approach That Makes Sense to IT Measuring Risk Determining Results Audit Planning

More information

A LAYPERSON S GUIDE INTERNAL CONTROL OVER FINANCIAL REPORTING (ICFR)

A LAYPERSON S GUIDE INTERNAL CONTROL OVER FINANCIAL REPORTING (ICFR) A LAYPERSON S GUIDE TO INTERNAL CONTROL OVER FINANCIAL REPORTING (ICFR) Prepared by Kayla J. Gillan, Member of the Public Company Accounting Oversight Board For The Council of Institutional Investors Annual

More information

RISK MANAGEMENT POLICY (Revised October 2015)

RISK MANAGEMENT POLICY (Revised October 2015) UNIVERSITY OF LEICESTER RISK MANAGEMENT POLICY (Revised October 2015) 1. This risk management policy ( the policy ) forms part of the University s internal control and corporate governance arrangements.

More information

Josephine Mathias. Kenneth J. Horowitz Phone: 609-586-4800 Ext. 3468 e-mail: horowitk@mccc.edu

Josephine Mathias. Kenneth J. Horowitz Phone: 609-586-4800 Ext. 3468 e-mail: horowitk@mccc.edu ACC204 Auditing Administrative Outline Course Information Organization Mercer County Community College Course Number ACC204 Credits 3 Lecture/Lab 3/1 Catalog Description Investigation into and application

More information

STANDARD. Risk Assessment. Supply Chain Risk Management: A Compilation of Best Practices

STANDARD. Risk Assessment. Supply Chain Risk Management: A Compilation of Best Practices A S I S I N T E R N A T I O N A L Supply Chain Risk Management: Risk Assessment A Compilation of Best Practices ANSI/ASIS/RIMS SCRM.1-2014 RA.1-2015 STANDARD The worldwide leader in security standards

More information

How To Understand The Role Of An Internal Audit

How To Understand The Role Of An Internal Audit Top Ten Issues facing Internal Auditing in the Future The IIA Dallas Chapter April 6, 2006 Presented by: David A. Richards, CIA, CPA President The Institute of Internal Auditors drichards@theiia.org 1

More information

Conducting a System Implementation Risk Review at Higher Education Institutions

Conducting a System Implementation Risk Review at Higher Education Institutions Conducting a System Implementation Risk Review at Higher Education Institutions October 23, 2013 1 Webinar moderator Justin T. Noble ACUA Distance Learning Chairman 2 Your presenters Mike Cullen, Senior

More information

Does Your Business Strategy Prioritize Talent Management?

Does Your Business Strategy Prioritize Talent Management? ISSUE ANALYSIS Does Your Business Strategy Prioritize Talent Management? Successful talent management strategy starts with leadership By: Lynn Roger, Chief Talent Officer, BMO Financial Group Executive

More information

Results & Key Findings

Results & Key Findings Results & Key Findings Sample Executive Assessment Overview 310.652.5678 fax 310.652.5677 www.profitablesolutions.com TABLE OF CONTENTS OVERVIEW..... ii METHODOLOGY iii EXECUTIVE SUMMARY Assessment Highlights....

More information

Dataline A look at current financial reporting issue

Dataline A look at current financial reporting issue Dataline A look at current financial reporting issue No. 2013-24 November 25, 2013 What s inside: Overview... 1 At a glance... 1 The main details... 1 Contents of the Guide... 2 Concepts and application

More information

C o m m i t t e e o f S p o n s o r i n g O r g a n i z a t i o n s o f t h e T r e a d w a y C o m m i s s i o n

C o m m i t t e e o f S p o n s o r i n g O r g a n i z a t i o n s o f t h e T r e a d w a y C o m m i s s i o n C o m m i t t e e o f S p o n s o r i n g O r g a n i z a t i o n s o f t h e T r e a d w a y C o m m i s s i o n T h o u g h t L e a d e r s h i p i n E R M E m b r a c i n g E n t e r p r i s e R i s

More information

PwC. Bill 198 Overview September 2004

PwC. Bill 198 Overview September 2004 PwC Bill 198 Overview September 2004 Agenda Welcome and overview Regulatory environment and background Three rules: 52-109 Strategies for implementing the CEO/CFO certification process 52-110 Requirements

More information

www.pwc.com Third Party Risk Management 12 April 2012

www.pwc.com Third Party Risk Management 12 April 2012 www.pwc.com Third Party Risk Management 12 April 2012 Agenda 1. Introductions 2. Drivers of Increased Focus on Third Parties 3. Governance 4. Third Party Risks and Scope 5. Third Party Risk Profiling 6.

More information

Implementation of Solvency II: The dos and the don ts

Implementation of Solvency II: The dos and the don ts KEYNOTE SPEECH Gabriel Bernardino Chairman of EIOPA Implementation of Solvency II: The dos and the don ts International conference Solvency II: What Can Go Wrong? Ljubljana, 2 September 2015 Page 2 of

More information

COBIT 5 for Risk. CS 3-7: Monday, July 6 4:00-5:00. Presented by: Nelson Gibbs CIA, CRMA, CISA, CISM, CGEIT, CRISC, CISSP ngibbs@pacbell.

COBIT 5 for Risk. CS 3-7: Monday, July 6 4:00-5:00. Presented by: Nelson Gibbs CIA, CRMA, CISA, CISM, CGEIT, CRISC, CISSP ngibbs@pacbell. COBIT 5 for Risk CS 3-7: Monday, July 6 4:00-5:00 Presented by: Nelson Gibbs CIA, CRMA, CISA, CISM, CGEIT, CRISC, CISSP ngibbs@pacbell.net Disclaimer of Use and Association Note: It is understood that

More information

SHARED SERVICES OR OUTSOURCING?

SHARED SERVICES OR OUTSOURCING? SHARED SERVICES OR OUTSOURCING? Assessing Scope, Process Maturity and Organizational Design Kevin Lewis, ISG Director; CPA, CGMA www.isg-one.com INTRODUCTION As organizations grow in size and complexity,

More information

INTERNATIONAL FRAMEWORK FOR ASSURANCE ENGAGEMENTS CONTENTS

INTERNATIONAL FRAMEWORK FOR ASSURANCE ENGAGEMENTS CONTENTS INTERNATIONAL FOR ASSURANCE ENGAGEMENTS (Effective for assurance reports issued on or after January 1, 2005) CONTENTS Paragraph Introduction... 1 6 Definition and Objective of an Assurance Engagement...

More information

Improving Corporate Governance with the Balanced Scorecard

Improving Corporate Governance with the Balanced Scorecard #04-044 Improving Corporate Governance with the Balanced Scorecard Robert S. Kaplan Michael E. Nagel Copyright 2004 Robert S. Kaplan and Michael E. Nagel Working papers are in draft form. This working

More information

Enterprise Risk Management: From Theory to Practice

Enterprise Risk Management: From Theory to Practice INSURANCE Enterprise Risk Management: From Theory to Practice KPMG LLP Executive Summary Enterprise Risk Management (ERM) is a structured and disciplined business tool aligning strategy, processes, people,

More information

The Advanced Certificate in Performance Audit for International and Public Affairs Management. Workshop Overview

The Advanced Certificate in Performance Audit for International and Public Affairs Management. Workshop Overview The Advanced Certificate in Performance Audit for International and Public Affairs Management Workshop Overview Performance Audit What is it? We will discuss the principles of performance audit. The session

More information

WHITE PAPER INTERNAL CONTROL WITH ADRA

WHITE PAPER INTERNAL CONTROL WITH ADRA WHITE PAPER INTERNAL CONTROL WITH ADRA About this document The purpose of this document is to discuss Internal Control and how Adra products supports ERM (Enterprise Risk Management), Internal Control

More information

Hand IN Hand: Balanced Scorecards

Hand IN Hand: Balanced Scorecards ANNUAL CONFERENCE T O P I C Risk Management WORKING Hand IN Hand: Balanced Scorecards AND Enterprise Risk Management B Y M ARK B EASLEY, CPA; A L C HEN; K AREN N UNEZ, CMA; AND L ORRAINE W RIGHT Recent

More information

THE GOVERNANCE OF RISK MANAGEMENT. Session 5

THE GOVERNANCE OF RISK MANAGEMENT. Session 5 THE GOVERNANCE OF RISK MANAGEMENT Session 5 Polling Question: Who is primarily responsible for risk governance in any organization? 0% A. The board or board risk committee (if applicable) B. The CRO 0%

More information

SOX FDICIA COSO 2013 Best Practices Presented by: Raji Sathappan MBA, CRCM, CAMS, CISA

SOX FDICIA COSO 2013 Best Practices Presented by: Raji Sathappan MBA, CRCM, CAMS, CISA SOX FDICIA COSO 2013 Best Practices Presented by: Raji Sathappan MBA, CRCM, CAMS, CISA Certified Public Accountants Consultants Wealth Management Technology Restatements - Mistakes that Dog Financial Reporting

More information

THE BOARD S ROLE AND RESPONSIBILITIES OVER THE CONTROL ENVIRONMENT. Session 4

THE BOARD S ROLE AND RESPONSIBILITIES OVER THE CONTROL ENVIRONMENT. Session 4 THE BOARD S ROLE AND RESPONSIBILITIES OVER THE CONTROL ENVIRONMENT Session 4 Road Map of Presentation Review of the key responsibilities of the Board - the direct links to the IC System & IA function Analyze

More information

Enterprise Risk Management Integrated Framework. Executive Summary

Enterprise Risk Management Integrated Framework. Executive Summary Enterprise Risk Management Integrated Framework Executive Summary September 2004 Copyright 2004 by the Committee of Sponsoring Organizations of the Treadway Commission. All rights reserved. You are hereby

More information

THE SOUTH AFRICAN HERITAGE RESOURCES AGENCY ENTERPRISE RISK MANAGEMENT FRAMEWORK

THE SOUTH AFRICAN HERITAGE RESOURCES AGENCY ENTERPRISE RISK MANAGEMENT FRAMEWORK THE SOUTH AFRICAN HERITAGE RESOURCES AGENCY ENTERPRISE RISK MANAGEMENT FRAMEWORK ACCOUNTABLE SIGNATURE AUTHORISED for implementation SIGNATURE On behalf of Chief Executive Officer SAHRA Council Date Date

More information

LEVERAGING COSO ACROSS THE THREE LINES OF DEFENSE

LEVERAGING COSO ACROSS THE THREE LINES OF DEFENSE Committee of Sponsoring Organizations of the Treadway Commission Governance and Internal Control LEVERAGING COSO ACROSS THE THREE LINES OF DEFENSE By The Institute of Internal Auditors Douglas J. Anderson

More information

Fraud Prevention and Deterrence

Fraud Prevention and Deterrence Fraud Prevention and Deterrence Fraud Risk Assessment 2016 Association of Certified Fraud Examiners, Inc. What Is Fraud Risk? The vulnerability that an organization faces from individuals capable of combining

More information

AUDIT OF READINESS FOR THE IMPLEMENTATION OF THE POLICY ON INTERNAL CONTROL

AUDIT OF READINESS FOR THE IMPLEMENTATION OF THE POLICY ON INTERNAL CONTROL AUDIT OF READINESS FOR THE IMPLEMENTATION OF THE POLICY ON INTERNAL CONTROL AUDIT REPORT JUNE 2010 TABLE OF CONTENTS EXCUTIVE SUMMARY... 3 1 INTRODUCTION... 5 1.1 AUDIT OBJECTIVE. 5 1.2 SCOPE...5 1.3 SUMMARY

More information

Domain 5 Information Security Governance and Risk Management

Domain 5 Information Security Governance and Risk Management Domain 5 Information Security Governance and Risk Management Security Frameworks CobiT (Control Objectives for Information and related Technology), developed by Information Systems Audit and Control Association

More information

COMPANY LEVEL CONTROLS A PRACTICAL FRAMEWORK

COMPANY LEVEL CONTROLS A PRACTICAL FRAMEWORK COMPANY LEVEL CONTROLS A PRACTICAL FRAMEWORK During the past two years a group of internal control specialists of large Dutch companies listed in the USA have held regular meetings to share experiences

More information

GAO. Government Auditing Standards. 2003 Revision. By the Comptroller General of the United States. United States General Accounting Office.

GAO. Government Auditing Standards. 2003 Revision. By the Comptroller General of the United States. United States General Accounting Office. GAO United States General Accounting Office By the Comptroller General of the United States June 2003 Government Auditing Standards 2003 Revision GAO-03-673G GAO United States General Accounting Office

More information

Enterprise Risk Management

Enterprise Risk Management Enterprise Risk Management Topic Gateway Series No. 49 1 Prepared by Jasmin Harvey and Technical Information Service July 2008 About Topic Gateways Topic Gateways are intended as a refresher or introduction

More information

Auditing Standard 5- Effective and Efficient SOX Compliance

Auditing Standard 5- Effective and Efficient SOX Compliance Auditing Standard 5- Effective and Efficient SOX Compliance September 6, 2007 Presented to: The Dallas Chapter of the Institute of Internal Auditors These slides are incomplete without the benefit of the

More information

Audit of the Policy on Internal Control Implementation

Audit of the Policy on Internal Control Implementation Audit of the Policy on Internal Control Implementation Natural Sciences and Engineering Research Council of Canada Social Sciences and Humanities Research Council of Canada February 18, 2013 1 TABLE OF

More information

The audit committee and risk management

The audit committee and risk management Audit Committee Institute Sponsored by KPMG The audit committee and risk management Is the board of directors adequately overseeing management's process for identifying and monitoring key business risks?

More information

The Role of the Board in Enterprise Risk Management

The Role of the Board in Enterprise Risk Management Enterprise Risk The Role of the Board in Enterprise Risk Management The board of directors plays an essential role in ensuring that an effective ERM program is in place. Governance, policy, and assurance

More information

A CFO s Guide to Corporate Governance

A CFO s Guide to Corporate Governance A CFO s Guide to Corporate Governance By Linda D. Henman, Ph.D. Few people can define governance in concrete terms, yet it remains one of those allencompassing words that people use frequently. The dictionary

More information

The Role of Internal Audit In Business Continuity Planning

The Role of Internal Audit In Business Continuity Planning The Role of Internal Audit In Business Continuity Planning Dan Bailey, MBCP Page 0 Introduction Dan Bailey, MBCP Senior Manager Protiviti Inc. dan.bailey@protiviti.com Actively involved in the Information

More information

U.S. CFO Program The Four Faces of the CFO. 2010 Deloitte Touche Tohmatsu

U.S. CFO Program The Four Faces of the CFO. 2010 Deloitte Touche Tohmatsu U.S. CFO Program The Four Faces of the CFO 2010 Deloitte Touche Tohmatsu CFOs Play Four Critical Roles in Companies Catalyze behaviors across the organization to execute strategic and financial objectives

More information

Enterprise risk management: A pragmatic, four-phase implementation plan

Enterprise risk management: A pragmatic, four-phase implementation plan Enterprise risk management: A pragmatic, four-phase implementation plan Prepared by: John Brackett, Managing Director, Risk Advisory Services, RSM McGladrey, Inc. 704.442.3820, john.brackett@mcgladrey.com

More information

RE: PCAOB Rulemaking Docket Matter No. 041: Concept Release on Audit Quality Indicators

RE: PCAOB Rulemaking Docket Matter No. 041: Concept Release on Audit Quality Indicators Office of the Secretary Public Company Accounting Oversight Board 1666 K Street, N.W. Washington, DC 20006-2803 September 29, 2015 RE: PCAOB Rulemaking Docket Matter No. 041: Concept Release on Audit Quality

More information

The Committee of Sponsoring Organizations of the Treadway Commission

The Committee of Sponsoring Organizations of the Treadway Commission The Committee of Sponsoring Organizations of the Treadway Commission Request for Proposal to Develop Additional Application Guidance on Monitoring, Including Tools and Techniques October 17, 2006 The Committee

More information

Phase II of Compliance to the Policy on Internal Control: Audit of Entity-Level Controls

Phase II of Compliance to the Policy on Internal Control: Audit of Entity-Level Controls Phase II of Compliance to the Policy on Internal Control: Audit of Entity-Level Controls Office of the Chief Audit and Evaluation Executive Audit and Assurance Services Directorate November 2013 Cette

More information

Internal Controls: Documentation and Testing What the Auditor Is Looking For

Internal Controls: Documentation and Testing What the Auditor Is Looking For What the Auditor Is Looking For Presented by: Dennis F. Dycus, CPA, CFE, CGFM, Director Office of the Comptroller of the Treasury Division of Municipal Audit TAUD Administrative Professional s Conference

More information

November 21, 2013. Public Company Accounting Oversight Board 1666 K Street Washington, DC 20006

November 21, 2013. Public Company Accounting Oversight Board 1666 K Street Washington, DC 20006 November 21, 2013 Public Company Accounting Oversight Board 1666 K Street Washington, DC 20006 International Auditing and Assurance Standards Board 529 Fifth Avenue, 6 th Floor New York, NY 10017 Via upload

More information

On the Setting of the Standards and Practice Standards for. Management Assessment and Audit concerning Internal

On the Setting of the Standards and Practice Standards for. Management Assessment and Audit concerning Internal (Provisional translation) On the Setting of the Standards and Practice Standards for Management Assessment and Audit concerning Internal Control Over Financial Reporting (Council Opinions) Released on

More information

Guideline. Operational Risk Management. Category: Sound Business and Financial Practices. No: E-21 Date: June 2016

Guideline. Operational Risk Management. Category: Sound Business and Financial Practices. No: E-21 Date: June 2016 Guideline Subject: Category: Sound Business and Financial Practices No: E-21 Date: June 2016 1. Purpose and Scope of the Guideline This Guideline sets out OSFI s expectations for the management of operational

More information

Summary of Internal Control-Integrated Framework by COSO:

Summary of Internal Control-Integrated Framework by COSO: Summary of Internal Control-Integrated Framework by COSO: COSO stands for Commission of Sponsoring Organizations a private commission chartered to research and report on improving quality of financial

More information

Practice guide. quality assurance and IMProVeMeNt PrograM

Practice guide. quality assurance and IMProVeMeNt PrograM Practice guide quality assurance and IMProVeMeNt PrograM MarCh 2012 Table of Contents Executive Summary... 1 Introduction... 2 What is Quality?... 2 Quality in Internal Audit... 2 Conformance or Compliance?...

More information

The Role of Internal Audit in Risk Governance

The Role of Internal Audit in Risk Governance The Role of Internal Audit in Risk Governance How Organizations Are Positioning the Internal Audit Function to Support Their Approach to Risk Management Executive summary Risk is inherent in running any

More information

Risk Assessment & Enterprise Risk Management

Risk Assessment & Enterprise Risk Management Risk Assessment & Enterprise Risk 1 Healthcare Corporate Governance Today s environment requires building a culture of risk awareness and management of risk across the organization, while formulating less

More information

Service Organization Control (SOC) Reports Focus on SOC 2 Reporting Standard

Service Organization Control (SOC) Reports Focus on SOC 2 Reporting Standard Information Systems Audit and Controls Association Service Organization Control (SOC) Reports Focus on SOC 2 Reporting Standard February 4, 2014 Tom Haberman, Principal, Deloitte & Touche LLP Reema Singh,

More information

Sharing of Experience Section 404 Sarbanes-Oxley Act

Sharing of Experience Section 404 Sarbanes-Oxley Act Sharing of Experience Section 404 Sarbanes-Oxley Act 13th September 2005 Peter Koo Partner Deloitte Touche Tohmatsu CPA(HK), CA, AICPA, CISA, CISM, CIA,CFE, CRP Tel (HK): +852-2852-6507 Tel (China) : +86

More information

How To Get A Tech Startup To Comply With Regulations

How To Get A Tech Startup To Comply With Regulations Agile Technology Controls for Startups a Contradiction in Terms or a Real Opportunity? Implementing Dynamic, Flexible and Continuously Optimized IT General Controls POWERFUL INSIGHTS Issue It s not a secret

More information