Internal Control Integrated Framework. May 2013
|
|
|
- Samantha Page
- 9 years ago
- Views:
Transcription
1 Internal Control Integrated Framework May
2 Table of Contents COSO & Project Overview Internal Control-Integrated Framework Illustrative Documents Illustrative Tools for Assessing Effectiveness of a System of Internal Control Internal Control over External Financial Reporting: A Compendium of Approaches and examples Transition & Impact Recommended Actions Questions & Comments 1
3 COSO & Project Overview 2
4 COSO Overview Internal Control Publications
5 Why update what works The Framework has become the most widely adopted control framework worldwide. Original Framework COSO s Internal Control Integrated Framework (1992 Edition) Refresh Objectives Reflect changes in business & operating environments Expand operations and reporting objectives Articulate principles to facilitate effective internal control Enhancements Updates Context Broadens Application Clarifies Requirements Updated Framework COSO s Internal Control Integrated Framework (2013 Edition) 4
6 Project timetable Assess & Survey Stakeholders Design & Build Public Exposure, Assess & Refine Finalize
7 Project participants COSO Board of Directors PwC Author & Project Leader COSO Advisory Council AICPA AAA FEI IIA IMA Public Accounting Firms Regulatory observers (SEC, GAO, FDIC, PCAOB) Others (IFAC, ISACA, others) Stakeholders Over 700 stakeholders in Framework responded to global survey during 2011 Over 200 stakeholders publically commented on proposed updates to Framework during first quarter of 2012 Over 50 stakeholders publically commented on proposed updates in last quarter of
8 Project deliverable #1 Internal Control-Integrated Framework (2013 Edition) Consists of three volumes: Executive Summary Framework and Appendices Illustrative Tools for Assessing Effectiveness of a System of Internal Control Sets out: Definition of internal control Categories of objectives Components and principles of internal control Requirements for effectiveness 7
9 Project deliverable #2 Internal Control over External Financial Reporting: A Compendium... Illustrates approaches and examples of how principles are applied in preparing financial statements Considers changes in business and operating environments during past two decades Provides examples from a variety of entities public, private, not-for-profit, and government Aligns with the updated Framework 8
10 Internal Control Integrated Framework 9
11 Update expected to increase ease of use and broaden application What is not changing... What is changing... Core definition of internal control Three categories of objectives and five components of internal control Each of the five components of internal control are required for effective internal control Important role of judgment in designing, implementing and conducting internal control, and in assessing its effectiveness Changes in business and operating environments considered Operations and reporting objectives expanded Fundamental concepts underlying five components articulated as principles Additional approaches and examples relevant to operations, compliance, and non-financial reporting objectives added 10
12 Update considers changes in business and operating environments Environments changes... have driven Framework updates Expectations for governance oversight Globalization of markets and operations Changes and greater complexity in business Demands and complexities in laws, rules, regulations, and standards Expectations for competencies and accountabilities Use of, and reliance on, evolving technologies Expectations relating to preventing and detecting fraud COSO Cube (2013 Edition) 11
13 Update articulates principles of effective internal control Control Environment Risk Assessment Control Activities Information & Communication Monitoring Activities 1. Demonstrates commitment to integrity and ethical values 2. Exercises oversight responsibility 3. Establishes structure, authority and responsibility 4. Demonstrates commitment to competence 5. Enforces accountability 6. Specifies suitable objectives 7. Identifies and analyzes risk 8. Assesses fraud risk 9. Identifies and analyzes significant change 10. Selects and develops control activities 11. Selects and develops general controls over technology 12. Deploys through policies and procedures 13. Uses relevant information 14. Communicates internally 15. Communicates externally 16. Conducts ongoing and/or separate evaluations 17. Evaluates and communicates deficiencies 12
14 Update articulates principles of effective internal control (continued) Control Environment 1. The organization demonstrates a commitment to integrity and ethical values. 2. The board of directors demonstrates independence from management and exercises oversight of the development and performance of internal control. 3. Management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities in the pursuit of objectives. 4. The organization demonstrates a commitment to attract, develop, and retain competent individuals in alignment with objectives. 5. The organization holds individuals accountable for their internal control responsibilities in the pursuit of objectives. 13
15 Update articulates principles of effective internal control (continued) Risk Assessment 6. The organization specifies objectives with sufficient clarity to enable the identification and assessment of risks relating to objectives. 7. The organization identifies risks to the achievement of its objectives across the entity and analyzes risks as a basis for determining how the risks should be managed. 8. The organization considers the potential for fraud in assessing risks to the achievement of objectives. 9. The organization identifies and assesses changes that could significantly impact the system of internal control. 14
16 Update articulates principles of effective internal control (continued) Control Activities 10. The organization selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels. 11. The organization selects and develops general control activities over technology to support the achievement of objectives. 12. The organization deploys control activities through policies that establish what is expected and procedures that put policies into place. 15
17 Update articulates principles of effective internal control (continued) Information & Communication 13. The organization obtains or generates and uses relevant, quality information to support the functioning of internal control. 14. The organization internally communicates information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control. 15. The organization communicates with external parties regarding matters affecting the functioning of internal control. 16
18 Update articulates principles of effective internal control (continued) Monitoring Activities 16. The organization selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning. 17. The organization evaluates and communicates internal control deficiencies in a timely manner to those parties responsible for taking corrective action, including senior management and the board of directors, as appropriate. 17
19 Update clarifies requirements for effective internal control Effective internal control provides reasonable assurance regarding the achievement of objectives and requires that: Each component and each relevant principle is present and functioning The five components are operating together in an integrated manner Each principle is suitable to all entities; all principles are presumed relevant except in rare situations where management determines that a principle is not relevant to a component (e.g., governance, technology) Components operate together when all components are present and functioning and internal control deficiencies aggregated across components do not result in one or more major deficiencies A major deficiency represents an internal control deficiency or combination thereof that severely reduces the likelihood that an entity can achieve its objectives 18
20 Update describes important characteristics of principles, e.g., Control Environment 1. The organization demonstrates a commitment to integrity and ethical values. Points of Focus: Sets the Tone at the Top Establishes Standards of Conduct Evaluates Adherence to Standards of Conduct Addresses Deviations in a Timely Manner Points of focus may not be suitable or relevant, and others may be identified Points of focus may facilitate designing, implementing, and conducting internal control There is no requirement to separately assess whether points of focus are in place 19
21 Update describes the role of controls to effect principles The Framework does not prescribe controls to be selected, developed, and deployed for effective internal control An organization s selection of controls to effect relevant principles and associated components is a function of management judgment based on factors unique to the entity A major deficiency in a component or principle cannot be mitigated to an acceptable level by the presence and functioning of other components and principles However, understanding and considering how controls effect multiple principles can provide persuasive evidence supporting management s assessment of whether components and relevant principles are present and functioning 20
22 Update describes how various controls effect principles, e.g., Component Control Environment Principle 1. The organization demonstrates a commitment to integrity and ethical values. Controls embedded in other components may effect this principle Human Resources review employees confirmations to assess whether standards of conduct are understood and adhered to by staff across the entity Control Environment Management obtains and reviews data and information underlying potential deviations captured in whistleblower hotline to assess quality of information Information & Communication Internal Audit separately evaluates Control Environment, considering employee behaviors and whistleblower hotline results and reports thereon Monitoring Activities 21
23 Summary of public exposure of proposed update Interest across geographic regions approximately 50% of respondents from North America and 50% from international regions Proposed updates to Framework released for public comments: December 20, 2011 to March 31, 2012 September 18, 2012 to December 4, 2012 COSO sought comments from the general public on proposed updates, including whether the: Requirements of effective internal control are clearly set forth Roles of components, principles, and points of focus are clearly set forth Framework remains sound, logical, and useful to management of entities of all types and sizes Public comment letters available at until Dec. 31,
24 Updates are responsive to public comments Principles Provide clarity regarding the role of principles in designing, implementing, and conducting internal control, and assessing its effectiveness Clarify descriptions of some principles, but no additional principles Effectiveness Recognize effective internal control can provide reasonable assurance of achieving effective and efficient operations objectives (as noted before) Clarify requirement that each of the components and relevant principles must be present and functioning and components must operating together Remove presumption that points of focus are present and functioning, and clarify that no separate assessment of points of focus is required Standardize classification of internal control deficiencies, and clarify use of only relevant criteria established in laws, rules, regulations and standards 23
25 Updates are responsive to public comments (continued) Objective Setting Retain five components of internal control Retain specification of objectives as a principle of effective internal control, but objective setting may be driven by laws, rules, regulations,or external standards that are outside a system of internal control Objectives Retain view that safeguarding of assets primarily relates to operations objectives, and recognize its consideration within reporting and compliance Acknowledge some laws rules, regulations and standards establish safeguarding of assets as a separate category of objectives Retain view that strategic objectives is not part of internal control Retain operations, reporting, and compliance objective categories, and expand descriptions 24
26 Updates are responsive to public comments (continued) Enterprise Risk Management (ERM) Retain distinction between ERM and internal control, and acknowledge these frameworks are complementary Retain view that strategy-setting, strategic objectives, and risk appetite are aspects of ERM, not Internal Control-Integrated Framework Retain discussion of risk appetite and application of risk tolerance Smaller Entities and Governments Provide additional guidance specific to smaller entities and governments (Appendix C) Technology Expand discussion in the points of focus and in several chapters Decline suggestion to address risk associated with specific technologies because of the rapid pace of change 25
27 Updates are responsive to public comments (continued) Structure and Layout Retain view that all chapters 1-10 comprise the Framework Due Process COSO believes there has been a substantive due process effort to capture views on proposed update Surveyed stakeholders to ascertain preferences concerning nature and extent of needed updates; 700 responses (December 2010 to September 2011) Conducted eleven meetings with COSO Advisory Council Provided exposure drafts of proposed updates for public comments (December 2011 to March 2012, and September to December 2012) Participated in many conferences, webinars, and seminars with membership of COSO to seek views of stakeholders (January 2011 to January 2013) 26
28 Illustrative Documents: - Illustrative Tools for Assessing Effectiveness of a System of Internal Control - Internal Control over External Financial Reporting: A Compendium of Approaches and Examples 27
29 Illustrative Tools for Assessing Effectiveness of a System of Internal Control Assist users when assessing effectiveness of internal control based on the requirements set forth in the Framework Templates illustrate a possible summary of assessment results Scenarios illustrate practical examples of how the templates can be used to support an assessment and important considerations in performing an assessment Focus on evaluating components and relevant principles, not the underlying controls that affect relevant principles Cannot satisfy criteria established through laws, rules, regulations, or external standards for evaluating the severity of internal control deficiencies Can customize level and amount of detail included in the templates as management may deem necessary 28
30 Internal Control over External Financial Reporting (ICEFR): A Compendium of Approaches and Examples Approaches and Examples illustrate how various characteristics of principles may be present and functioning within a system of internal control relating to external financial reporting Approaches are designed to give a summary-level description of activities that management may consider as they apply the Framework Examples illustrate one or more points of focus of a particular principle. They are not designed to provide a comprehensive, end-to-end example of how a principle may be fully applied in practice. Selected approaches and examples do not illustrate all aspects of components and relevant principles that would be necessary for effective internal control Stakeholders should refer to the Framework for the requirements of effective internal control Compendium supplements and can be used in concert 29
31 Summary of public exposure of the Illustrative Documents Proposed Internal Control over External Financial Reporting: Compendium of Approaches and Examples was released for public comment from September 18, 2012 to December 4, 2012 In conjunction with the public exposure of ICEFR Compendium, COSO made available revised versions of the previously exposed Framework and Appendices and Executive Summary COSO made available the proposed Illustrative Tools for Assessing Effectiveness of a System of Internal Control COSO sought comments from the general public on relevant topics Public comment letters available at until Dec. 31,
32 Illustrative documents are responsive to public comments ICEFR: A Compendium of Approaches and Examples Add or clarify specific examples, including: Establishing responsibilities for reviewing financial statements Monitoring investigation and reporting of whistleblower allegations Monitoring identification and protection of sensitive financial information Monitoring identification and analysis of risk of material misstatement due to fraud Address a risk-based approach for achieving external financial reporting objectives Specify suitable objectives for external financial reporting Risks to achieving suitable objectives Responses to risks 31
33 Transition & Impact 32
34 Transition & Impact Users are encouraged to transition applications and related documentation to the updated Framework as soon as feasible Updated Framework will supersede original Framework at the end of the transition period (i.e., December 15, 2014) During the transition period, external reporting should disclose whether the original or updated version of the Framework was used Impact of adopting the updated Framework will vary by organization Does your system of internal control need to address changes in business? Does your system of internal control need to be updated to address all principles? Does your organization apply and interpret the original framework in the same manner as COSO? Is your organization considering new opportunities to apply internal control to cover additional objectives? 33
35 Transition & Impact (continued) The principles-based approach provides flexibility in applying the Framework to multiple, overlapping objectives across the entity Easier to see what is covered and what is missing Focus on principles may reduce likelihood of considering something that s irrelevant Understanding the importance of specifying suitable objectives focuses on those risks and controls most important to achieving these objectives. Focusing on areas of risk that exceed acceptance levels or need to be managed across the entity may reduce efforts spent mitigating risks in areas of lesser significance. Coordinating efforts for identifying and assessing risks across multiple, overlapping objectives may reduce the number of discrete risks assessed and mitigated. 34
36 Transition & Impact (continued) Selecting, developing, and deploying controls to effect multiple principles may also reduce the number of discrete, layered-on controls. Applying an integrated approach to internal control - encompassing operations, reporting, and compliance may lessen complexity. In assessing severity of internal control deficiencies, use only the relevant classification criteria as set out in the Framework or by regulators, standardsetting bodies, and other relevant third parties, as appropriate. 35
37 Recommended Actions Read COSO s updated Framework and illustrative documents Educate the audit committee, C-suite, operating unit and functional management Establish a process for identifying, assessing, and implementing necessary changes in controls and related documentation Develop and implement a transition plan timely to meet key objectives e.g., apply updated Framework by December 31, 2014 for external reporting 36
38 Getting COSO s Publications The updated Framework and related Illustrative documents are available in 3 layouts 1. E-book This layout is ideally suited for those wanting access in electronic format for tablet use. An e-book reader from the AICPA is required to view this layout. Printing is restricted in this layout. Purchase through 2. Paper-bound This layout is ideally suited for those wanting a hard copy. Purchase through 3. PDF This layout is ideally suited for organizations interested in licensing multiple copies. Contact the AICPA at [email protected] 37
39 Questions & Comments 38
COSO 2013 Internal Control Integrated Framework FRED J. PETERSON, PARTNER MOSS ADAMS LLP
COSO 2013 Internal Control Integrated Framework FRED J. PETERSON, PARTNER MOSS ADAMS LLP Disclaimer The material appearing in this presentation is for informational purposes only and should not be construed
COSO Internal Control Integrated Framework (2013)
COSO Internal Control Integrated Framework (2013) The Committee of Sponsoring Organizations of the Treadway Commission (COSO) released its updated Internal Control Integrated Framework (2013 Framework)
COSO s 2013 Internal Control Framework in Depth: Implementing the Enhanced Guidance for Internal Control over External Financial Reporting
in Depth: Implementing the Enhanced Guidance for Internal Control over External Financial Reporting Table of Contents EXECUTIVE SUMMARY... 3 BACKGROUND... 3 SIGNIFICANT CHANGES AFFECTING INTERNAL CONTROL
Impact of New Internal Control Frameworks
Impact of New Internal Control Frameworks Webcast: Tuesday, February 25, 2014 CPE Credit: 1 0 With You Today Bob Jacobson Principal, Risk Advisory Services Consulting Leader West Region [email protected]
COSO Framework 2013 & SOX Compliance. Roxanne L. Halverson, CISM, CGEIT Atlanta ISACA Geek Week August 19, 2013
COSO Framework 2013 & SOX Compliance Roxanne L. Halverson, CISM, CGEIT Atlanta ISACA Geek Week August 19, 2013 What s Happened On May 14, 2013, after a little more than 20 years the Committee of Sponsoring
The Updated COSO Internal Control Framework. Frequently Asked Questions
The Updated COSO Internal Control Framework Frequently Asked Questions Introduction The Committee of Sponsoring Organizations of the Treadway Commission (COSO) an organization providing thought leadership
COSO 2013: WHAT HAS CHANGED & STEPS TO TAKE TO ENSURE COMPLIANCE
COSO 2013: WHAT HAS CHANGED & STEPS TO TAKE TO ENSURE COMPLIANCE COMMITTEE OF SPONSORING ORGANIZATIONS (COSO) 2013 The Committee of Sponsoring Organizations (COSO) Internal Controls Integrated Framework,
RISK BASED AUDITING: A VALUE ADD PROPOSITION. Participant Guide
RISK BASED AUDITING: A VALUE ADD PROPOSITION Participant Guide About This Course About This Course Adding Value for Risk-based Auditing Seminar Description In this seminar, we will focus on: The foundation
The Updated COSO Internal Control Framework
The Updated COSO Internal Control Framework Frequently Asked Questions Second Edition Introduction The Committee of Sponsoring Organizations of the Treadway Commission (COSO) an organization providing
COSO 2013 Internal Control Framework
COSO 2013 Internal Control A Guide to Implementation July 24, 2014 Justin Adamson Agenda COSO Background Changes to the Roadmap to Implementation Implementation Considerations & Lessons Learned 2 1 Who/What
The 2013 COSO Framework & SOX Compliance
The 2013 COSO Framework & SOX Compliance ONE APPROACH TO AN EFFECTIVE TRANSITION By J. Stephen McNally, CPA The 2013 COSO Framework & SOX Compliance ONE APPROACH TO AN EFFECTIVE TRANSITION By J. Stephen
Enterprise Risk Management: COSO, New COSO, ISO 31000. Review of ERM
Enterprise Risk Management: COSO, New COSO, Dr. Hugh Van Seaton, Ed. D., CSSGB, CGMA, CPA Review of ERM COSO a process, effected by an entity's board of directors, management and other personnel, applied
Internal Control over Financial Reporting Guidance for Smaller Public Companies
Internal Control over Financial Reporting Guidance for Smaller Public Companies Frequently Asked Questions Internal Control over Financial Reporting Guidance for Smaller Public Companies Frequently Asked
INTERNAL AUDITING S ROLE IN SECTIONS 302 AND 404
INTERNAL AUDITING S ROLE IN SECTIONS 302 AND 404 OF THE U.S. SARBANES-OXLEY ACT OF 2002 May 26, 2004 Copyright 2004 by, 247 Maitland Avenue, Altamonte Springs, Florida, 32701-4201, USA Internal Auditing
STAFF GUIDANCE FOR AUDITORS OF SEC-REGISTERED BROKERS AND DEALERS JUNE 26, 2014
1666 K Street, N.W. Washington, DC 20006 Telephone: (202) 207-9100 Facsimile: (202) 862-8430 www.pcaobus.org STAFF GUIDANCE FOR AUDITORS OF SEC-REGISTERED BROKERS AND DEALERS JUNE 26, 2014 This publication
A&CS Assurance Review. Accounting Policy Division Rule Making Participation in Standard Setting. Report
A&CS Assurance Review Accounting Policy Division Rule Making Participation in Standard Setting Report April 2010 Table of Contents Background... 1 Engagement Objectives, Scope and Approach... 1 Overall
SECTION B DEFINITION, PURPOSE, INDEPENDENCE AND NATURE OF WORK OF INTERNAL AUDIT
SECTION B DEFINITION, PURPOSE, INDEPENDENCE AND NATURE OF WORK OF INTERNAL AUDIT Through CGIAR Financial Guideline No 3 Auditing Guidelines Manual the CGIAR has adopted the IIA Definition of internal auditing
ENTERPRISE RISK MANAGEMENT POLICY
ENTERPRISE RISK MANAGEMENT POLICY TITLE OF POLICY POLICY OWNER POLICY CHAMPION DOCUMENT HISTORY: Policy Title Status Enterprise Risk Management Policy (current, revised, no change, redundant) Approving
ISRE 2400 (Revised), Engagements to Review Historical Financial Statements
International Auditing and Assurance Standards Board Exposure Draft January 2011 Comments requested by May 20, 2011 Proposed International Standard on Review Engagements ISRE 2400 (Revised), Engagements
Professional Development for Engagement Partners Responsible for Audits of Financial Statements (Revised)
IFAC Board Exposure Draft August 2012 Comments due: December 11, 2012 Proposed International Education Standard (IES) 8 Professional Development for Engagement Partners Responsible for Audits of Financial
Internal Audit Quality Assessment. Presented To: World Intellectual Property Organization
Internal Audit Quality Assessment Presented To: World Intellectual Property Organization April 2014 Table of Contents List of Acronyms 3 Page Executive Summary Opinion as to Conformance to the Standards,
Proposed Consequential and Conforming Amendments to Other ISAs
IFAC Board Exposure Draft November 2012 Comments due: March 14, 2013, 2013 International Standard on Auditing (ISA) 720 (Revised) The Auditor s Responsibilities Relating to Other Information in Documents
Internal Auditing Guidelines
Internal Auditing Guidelines Recommendations on Internal Auditing for Lottery Operators Issued by the WLA Security and Risk Management Committee V1.0, March 2007 The WLA Internal Auditing Guidelines may
ISSAI 1300. Planning an Audit of Financial Statements. Financial Audit Guideline
The International Standards of Supreme Audit Institutions, ISSAI, are issued by the International Organization of Supreme Audit Institutions, INTOSAI. For more information visit www.issai.org. Financial
Developing Effective Internal Controls Using the COSO Model
Developing Effective Internal Controls Using the COSO Model Office of State Controller Internal Controls in a COSO Environment Seminar Raleigh, North Carolina March 2007 Mark S. Beasley Director, ERM Initiative
ISA 200, Overall Objective of the Independent Auditor, and the Conduct of an Audit in Accordance with International Standards on Auditing
International Auditing and Assurance Standards Board Exposure Draft April 2007 Comments are requested by September 15, 2007 Proposed Revised and Redrafted International Standard on Auditing ISA 200, Overall
PRACTICE GUIDE. Formulating and Expressing Internal Audit Opinions
PRACTICE GUIDE Formulating and Expressing Internal Audit Opinions 2 of 23 Table of Contents 1. Executive Summary... 1 2. Introduction... 2 3. Planning the Expression of an Opinion... 3 3.1 Expressing an
Initial Professional Development Technical Competence (Revised)
IFAC Board Exposure Draft July 2012 Comments due: November 1, 2012 Proposed International Education Standard (IES) 2 Initial Professional Development Technical Competence (Revised) COPYRIGHT, TRADEMARK,
IT audit updates. Current hot topics and key considerations. IT risk assessment leading practices
IT audit updates Current hot topics and key considerations Contents IT risk assessment leading practices IT risks to consider in your audit plan IT SOX considerations and risks COSO 2013 and IT considerations
Guide to the Sarbanes-Oxley Act: IT Risks and Controls. Frequently Asked Questions
Guide to the Sarbanes-Oxley Act: IT Risks and Controls Frequently Asked Questions Table of Contents Page No. Introduction.......................................................................1 Overall
Exposure Draft: Improving the Structure of the Code of Ethics for Professional Accountants Phase 1
Ken Siong IESBA Technical Director IFAC 6 th Floor 529 Fifth Avenue New York 10017 USA 22 April 2016 Dear Mr Siong Exposure Draft: Improving the Structure of the Code of Ethics for Professional Accountants
Internal Audit Manual
Internal Audit Manual Version 1.0 AUDIT AND EVALUATION SECTOR AUDIT AND ASSURANCE SERVICES BRANCH INDIAN AND NORTHERN AFFAIRS CANADA April 25, 2008 #933907 Acknowledgements The Institute of Internal Auditors
LEVERAGING COSO ACROSS THE THREE LINES OF DEFENSE
Committee of Sponsoring Organizations of the Treadway Commission Governance and Internal Control LEVERAGING COSO ACROSS THE THREE LINES OF DEFENSE By The Institute of Internal Auditors Douglas J. Anderson
GAO. Government Auditing Standards. 2011 Revision. By the Comptroller General of the United States. United States Government Accountability Office
GAO United States Government Accountability Office By the Comptroller General of the United States December 2011 Government Auditing Standards 2011 Revision GAO-12-331G GAO United States Government Accountability
GET YOUR INTERNAL AUDIT RISK ASSESSMENT RIGHT THIS YEAR NOAH GOTTESMAN
GET YOUR INTERNAL AUDIT RISK ASSESSMENT RIGHT THIS YEAR NOAH GOTTESMAN ABOUT THE AUTHOR Leveraging his background in internal audit and internal controls, Noah Gottesman provides industry thought leadership
Internal Controls and Risk Management Report
42 Internal Controls and Risk Management Report Responsibility Our Board of Directors has the overall responsibility to ensure that sound and effective internal controls are maintained, while management
Board oversight of risk: Defining risk appetite in plain English
www.pwc.com/us/centerforboardgovernance Board oversight of risk: Defining risk appetite in plain English May 2014 Defining risk appetite in plain English Risk oversight continues to be top-of-mind for
Enterprise Risk Management
Cayman Islands Society of Professional Accountants Enterprise Risk Management March 19, 2015 Dr. Sandra B. Richtermeyer, CPA, CMA What is Risk Management? Risk management is a process, effected by an entity's
ISAE 3000 (Revised), Assurance Engagements Other Than Audits or Reviews of Historical Financial Information
International Auditing and Assurance Standards Board Exposure Draft April 2011 Comments requested by September 1, 2011 Proposed International Standard on Assurance Engagements (ISAE) ISAE 3000 (Revised),
) ) ) ) ) ) ) ) ) ) ) )
1666 K Street, NW Washington, D.C. 20006 Telephone: (202) 207-9100 Facsimile: (202)862-8430 PROPOSED AUDITING STANDARD RELATED TO CONFIRMATION AND RELATED AMENDMENTS TO PCAOB STANDARDS ) ) ) ) ) ) ) )
AN AUDIT OF INTERNAL CONTROL OVER FINANCIAL REPORTING THAT IS INTEGRATED WITH AN AUDIT OF FINANCIAL STATEMENTS:
1666 K Street, NW Washington, D.C. 20006 Telephone: (202) 207-9100 Facsimile: (202) 862-8430 www.pcaobus.org STAFF VIEWS AN AUDIT OF INTERNAL CONTROL OVER FINANCIAL REPORTING THAT IS INTEGRATED WITH AN
the role of the head of internal audit in public service organisations 2010
the role of the head of internal audit in public service organisations 2010 CIPFA Statement on the role of the Head of Internal Audit in public service organisations The Head of Internal Audit in a public
Addressing Disclosures in the Audit of Financial Statements
Exposure Draft May 2014 Comments due: September 11, 2014 Proposed Changes to the International Standards on Auditing (ISAs) Addressing Disclosures in the Audit of Financial Statements This Exposure Draft
Fundamental Principles of Financial Auditing
ISSAI 200 ISSAI The 200 International Fundamental Standards Principles of Supreme of Financial Audit Institutions, Auditing or ISSAIs, are issued by INTOSAI, the International Organisation of Supreme Audit
INTERNATIONAL STANDARDS FOR THE PROFESSIONAL PRACTICE OF INTERNAL AUDITING (STANDARDS)
INTERNATIONAL STANDARDS FOR THE PROFESSIONAL PRACTICE OF INTERNAL AUDITING (STANDARDS) Introduction to the International Standards Internal auditing is conducted in diverse legal and cultural environments;
Background. Audit Quality and Public Interest vs. Cost
Basis for Conclusions: ISA 600 (Revised and Redrafted), Special Considerations Audits of Group Financial Statements (Including the Work of Component Auditors) Prepared by the Staff of the International
AUDIT COMMITTEE CHARTER
AUDIT COMMITTEE CHARTER Purpose The Audit Committee ( Committee ) shall assist the Board of Directors (the Board ) in the oversight of (1) the integrity of the financial statements of the Company, (2)
International Forum of Independent Audit Regulators Report on 2014 Survey of Inspection Findings March 3, 2015
International Forum of Independent Audit Regulators Report on 2014 Survey of Inspection Findings March 3, 2015 Executive Summary In 2014, the International Forum of Independent Audit Regulators (IFIAR)
February 2015. Sample audit committee charter
February 2015 Sample audit committee charter Sample audit committee charter This sample audit committee charter is based on observations of selected companies and the requirements of the SEC, the NYSE,
Governance, Risk and Best Value Committee
Governance, Risk and Best Value Committee 2.00pm, Wednesday 23 September 2015 Internal Audit Report: Integrated Health & Social Care Item number Report number Executive/routine Wards Executive summary
INTERNATIONAL STANDARDS FOR THE PROFESSIONAL PRACTICE OF INTERNAL AUDITING (STANDARDS)
INTERNATIONAL STANDARDS FOR THE PROFESSIONAL PRACTICE OF INTERNAL AUDITING (STANDARDS) Revised: October 2012 i Table of contents Attribute Standards... 3 1000 Purpose, Authority, and Responsibility...
CFE 2. Enterprise Risk Management. Study Guide - Supplemental Background Material
P a g e 1 CFE 2 Enterprise Risk Management Study Guide - Supplemental Background Material The passing score for this test is 74% Reference Guides: Enterprise Risk Management Best Practices: From Assessment
Guide to Internal Control Over Financial Reporting
Guide to Internal Control Over Financial Reporting The Center for Audit Quality prepared this Guide to provide an overview for the general public of internal control over financial reporting ( ICFR ).
University of Edinburgh Risk Policy and Risk Appetite
University of Edinburgh Risk Policy and Risk Appetite 1. Pushing the boundaries of knowledge, innovating, and implementing strategic developments will always have risks. Effective risk management increases
University Audit and Compliance. Internal Controls Enterprise-Wide Risk Assessment
Internal Controls Enterprise-Wide Risk Assessment Balancing Risk and Controls In order to achieve goals and objectives, management needs to effectively balance risks and controls. Control procedures need
INTERNATIONAL STANDARD ON ASSURANCE ENGAGEMENTS (ISAE) 3402 ASSURANCE REPORTS ON CONTROLS AT A SERVICE ORGANIZATION
INTERNATIONAL STANDARD ON ASSURANCE ENGAGEMENTS (ISAE) 3402 ASSURANCE REPORTS ON CONTROLS AT A SERVICE ORGANIZATION (Effective for service auditors assurance reports covering periods ending on or after
Enterprise Risk Management: From Theory to Practice
INSURANCE Enterprise Risk Management: From Theory to Practice KPMG LLP Executive Summary Enterprise Risk Management (ERM) is a structured and disciplined business tool aligning strategy, processes, people,
The Compliance Universe
The Compliance Universe Principle 6.1 The board should ensure that the company complies with applicable laws and considers adherence to non-binding rules, codes and standards This practice note is intended
Reporting Service Performance Information
AASB Exposure Draft ED 270 August 2015 Reporting Service Performance Information Comments to the AASB by 12 February 2016 PLEASE NOTE THIS DATE HAS BEEN EXTENDED TO 29 APRIL 2016 How to comment on this
SARBANES-OXLEY SECTION 404: A Guide for Management by Internal Controls Practitioners
SARBANES-OXLEY SECTION 404: A Guide for Management by Internal Controls Practitioners SARBANES-OXLEY SECTION 404: A Guide for Management by Internal Controls Practitioners The Institute of Internal Auditors
STANDING ADVISORY GROUP MEETING
1666 K Street, N.W. Washington, DC 20006 Telephone: (202) 207-9100 Facsimile: (202) 862-8430 www.pcaobus.org RISK ASSESSMENT IN FINANCIAL STATEMENT AUDITS Introduction The Standing Advisory Group ("SAG")
IRM CERTIFICATE AND DIPLOMA OUTLINE SYLLABUS
IRM CERTIFICATE AND DIPLOMA OUTLINE SYLLABUS 1 Module 1: Principles of Risk and Risk Management Module aims The aim of this module is to provide an introduction to the principles and concepts of risk and
Guidance Note: Corporate Governance - Board of Directors. March 2015. Ce document est aussi disponible en français.
Guidance Note: Corporate Governance - Board of Directors March 2015 Ce document est aussi disponible en français. Applicability The Guidance Note: Corporate Governance - Board of Directors (the Guidance
Solvency II Own Risk and Solvency Assessment (ORSA)
Solvency II Own Risk and Solvency Assessment (ORSA) Guidance notes September 2011 Contents Introduction Purpose of this Document 3 Lloyd s ORSA framework 3 Guidance for Syndicate ORSAs Overview 7 December
Administrative Guidelines on the Internal Control Framework and Internal Audit Standards
Administrative Guidelines on the Internal Control Framework and Internal Audit Standards GCF/B.09/18 18 February 2015 Meeting of the Board 24 26 March 2015 Songdo, Republic of Korea Agenda item 24 Page
Initial Professional Development - Professional Values, Ethics, and Attitudes (Revised)
IFAC Board Exposure Draft July 2012 Comments due: October 11, 2012 Proposed International Education Standard (IES) 4 Initial Professional Development - Professional Values, Ethics, and Attitudes (Revised)
Sample Financial institution Risk Management Policy 2011
Sample Financial institution Risk Management Policy 2011 1 Contents Risk Management Program...2 Internal Control and Risk Management Diagram... 2 General Control Environment... 2 Specific Internal Control
4. Critical success factors/objectives of the activity/proposal/project being risk assessed
ARTC Risk Management Work Instruction 2: 1. Conduct Risk Assessment Workshop This Work Instruction provides general guidelines for conducting a generic Risk Assessment workshop. The instructions supplement
2015-16 Internal Control Questionnaire and Assessment
Bureau of Financial Monitoring and Accountability Florida Department of Economic Opportunity September 9, 2015 107 East Madison Street Caldwell Building Tallahassee, Florida 32399 www.floridajobs.org TABLE
Leveraging Effective Risk Management and Internal Control
Leveraging Effective Risk Management and Internal Control By J. Stephen McNally, CPA, and Vincent H. Tophoff, RA Effective risk management and internal control (RM/IC) is an important driver of business
FS Regulatory Brief SEC Proposes Amendments to Broker- Dealer Financial Reporting Rule
SEC Proposes Amendments to Broker- Dealer Financial Reporting Rule Amendments call for brokerdealers assertion of compliance with the Financial Responsibility Rules, new reviews by independent auditors,
The Auditor's Responsibilities Relating to Other Information
Exposure Draft April 2014 Comments due: July 18, 2014 Proposed International Standard on Auditing (ISA) 720 (Revised) The Auditor's Responsibilities Relating to Other Information Proposed Consequential
International Diploma in Risk Management Syllabus
International Diploma in Risk Management Syllabus Module 1: Principles of Risk and Risk Management The aim of this module is to provide an introduction to the principles and concepts of risk and risk management.
ENTERPRISE RISK MANAGEMENT FRAMEWORK WHAT IS ERM? JOIN. ENGAGE. LEAD.
ENTERPRISE RISK MANAGEMENT FRAMEWORK WHAT IS ERM? JOIN. ENGAGE. LEAD. Enterprise Risk Credit Risk Market Risk Operational Risk Regulatory Compliance Securities Lending INCREASED FOCUS ON ERM Although the
Internal Audit and Advisory Services DRAFT
Internal Audit and Advisory Services DRAFT PAGE(S) Message from the Internal Audit and Advisory Services...1-2 Internal Audit and Advisory Services Plan...3-5 Objectives...6-7 Risk Assessment Process...8
Understanding the Entity and Its Environment and Assessing the Risks of Material Misstatement
Understanding the Entity and Its Environment 1667 AU Section 314 Understanding the Entity and Its Environment and Assessing the Risks of Material Misstatement (Supersedes SAS No. 55.) Source: SAS No. 109.
Solvency II Data audit report guidance. March 2012
Solvency II Data audit report guidance March 2012 Contents Page Introduction Purpose of the Data Audit Report 3 Report Format and Submission 3 Ownership and Independence 4 Scope and Content Scope of the
CHAPTER 7 PLANNING THE AUDIT: IDENTIFYING AND RESPONDING TO THE RISKS OF MATERIAL MISSTATEMENT
A U D I T I N G A RISK-BASED APPROACH TO CONDUCTING A QUALITY AUDIT 9 th Edition Karla M. Johnstone Audrey A. Gramling Larry E. Rittenberg CHAPTER 7 PLANNING THE AUDIT: IDENTIFYING AND RESPONDING TO THE
The Auditor s Communication With Those Charged With Governance
The Auditor s Communication With Governance 2083 AU Section 380 The Auditor s Communication With Those Charged With Governance (Supersedes SAS No. 61.) Source: SAS No. 114. Effective for audits of financial
What Every Director. How to get the most from your internal audit. Endorsed by
What Every Director Should Know How to get the most from your internal audit Endorsed by Foreword This is the second edition of our flagship governance guide What every director should know. Since we published
ALLEGIANT TRAVEL COMPANY AUDIT COMMITTEE CHARTER
I. PURPOSE ALLEGIANT TRAVEL COMPANY AUDIT COMMITTEE CHARTER (As Revised January 28, 2013) The Audit Committee shall provide assistance to the Company's Board of Directors (the "Board") in fulfilling the
Sears Hometown and Outlet Stores, Inc. Audit Committee of the Board of Directors Charter
Sears Hometown and Outlet Stores, Inc. Audit Committee of the Board of Directors Charter Purpose The Audit Committee is appointed by the Board of Directors (the Board ) of Sears Hometown and Outlet Stores,
STANDARDS OF SOUND BUSINESS AND FINANCIAL PRACTICES. ENTERPRISE RISK MANAGEMENT Framework
STANDARDS OF SOUND BUSINESS AND FINANCIAL PRACTICES ENTERPRISE RISK MANAGEMENT Framework September 2011 Notice This document is intended as a reference tool to assist Ontario credit unions to develop an
How to achieve excellent enterprise risk management Why risk assessments fail
How to achieve excellent enterprise risk management Why risk assessments fail Overview Risk assessments are a common tool for understanding business issues and potential consequences from uncertainties.
A Risk-Based Audit Strategy November 2006 Internal Audit Department
Mental Health Mental Retardation Authority of Harris County ENTERPRISE RISK MANAGEMENT A Framework For Assessing, Evaluating And Measuring Our Agency s Risk A Risk-Based Audit Strategy November 2006 Internal
Charter of the Audit Committee of the Board of Directors of Woodward, Inc.
AUDIT COMMITTEE CHARTER Charter of the Audit Committee of the Board of Directors of Woodward, Inc. Purpose The Audit Committee (the Committee ) is appointed by the Board of Directors to oversee the accounting
Practice Guide COORDINATING RISK MANAGEMENT AND ASSURANCE
Practice Guide COORDINATING RISK MANAGEMENT AND ASSURANCE March 2012 Table of Contents Executive Summary... 1 Introduction... 1 Risk Management and Assurance (Assurance Services)... 1 Assurance Framework...
Sarbanes-Oxley Compliance Workbook. From Zero to SOX. Sarbanes-Oxley Compliance Workbook. sensiba san filippo www.ssfllp.com sox@ssfllp.
From Zero to SOX Zero to SOX An Overview The goals of a program to meet SOX 404 requirements go far beyond compliance. The process of building a sustainable, comprehensive internal control environment
INTERNATIONAL STANDARD ON AUDITING 700 FORMING AN OPINION AND REPORTING ON FINANCIAL STATEMENTS CONTENTS
INTERNATIONAL STANDARD ON 700 FORMING AN OPINION AND REPORTING ON FINANCIAL STATEMENTS (Effective for audits of financial statements for periods beginning on or after December 15, 2009) CONTENTS Paragraph
RALLY SOFTWARE DEVELOPMENT CORP.
RALLY SOFTWARE DEVELOPMENT CORP. CHARTER OF THE AUDIT COMMITTEE OF THE BOARD OF DIRECTORS Approved by the Board of Directors on March 19 2013 PURPOSE The primary purpose of the Audit Committee (the Committee
