Roles and Responsibilities Corporate Compliance and Internal Audit
|
|
|
- Mitchell Gordon
- 10 years ago
- Views:
Transcription
1 Roles and Responsibilities and By Mark P. Ruppert, CPA, CIA, CISA, CHFP The focus group of Health Care Compliance Association (HCCA) and Association of Healthcare ors (AHIA) members continues to explore opportunities to better define and explain auditing and monitoring, clarify the roles of compliance and internal audit functions as they address issues within their healthcare organizations, and develop guidance and reference materials on key aspects of health care auditing and monitoring processes. The Seven Component Framework developed by the AHIA/HCCA focus group for compliance auditing and monitoring is comprised of the following activities: Perform a risk assessment and determine the level of risk Understand laws and regulations Obtain and/or establish policies for specific issues and areas Educate on the policies and procedures and communicate awareness Monitor compliance with laws, regulations, and policies Audit the highest risk areas Re-educate staff on regulations and issues identified in the audit This article provides the focus group s view regarding the roles and responsibilities of the corporate compliance and internal audit functions. There is no attempt to address the merits of having separate or combined corporate compliance and internal audit functions. Whether the functions are separate or combined, the roles and responsibilities remain essentially the same for each function, though each approach provides reciprocal advantages and disadvantages to an organization, which can best be summarized as follows: With separate compliance and internal audit functions, collaboration is more challenging but functional independence is assured. In combined compliance and internal audit shops, collaboration is assured but functional independence is more challenging. The Focus Group categorized the different roles and responsibilities for comparative purposes. This categorization and comparison is summarized in a matrix as Exhibit A to this article. Twenty-two comparative categories were identified: requirement, purpose, reporting, internal authority, span of responsibility, professional standards, high level focus, primary focus from a risk standpoint, activity focus, relationship to management, training responsibility, auditing, monitoring, expertise, impact on internal audit plan, impact on compliance plan, risk assessment, follow-up, investigation, hotline, information systems, and internal controls. This of course highlights the complexity of attempting to discern the roles and responsibilities, though once addressed it s actually quite easier than it seems. When looking at the first several categories of roles and responsibilities, especially related to formal standards, the Focus Group identified that internal audit has more history as a profession and its work is governed by formal standards for the conduct of its work. Thus, internal audit has been accepted and understood by industry boards and executives before corporate compliance programs were conceived. While corporate compliance and internal audit certifications and codes of ethics exist, corporate compliance activities are not yet governed by widely acknowledged standards. From this context then the roles can best be identified, understood and applied by looking first at similarities and then at uniqueness. AM-AuditCompliance-RolesResp(FINAL-Article ) (2).doc 1/5
2 Roles and Responsibilities and By Mark P. Ruppert, CPA, CIA, CISA, CHFP Similar Roles and Responsibilities Corporate compliance and internal audit functions are best served by being independent of the operations they assess. To achieve independence, proper governance, lines of reporting and authority, organizational placement and organizational access are key to the success of both functions. Since both compliance and audit are focused on helping the organization achieve responsible and effective corporate governance and ethics, best practice corporate compliance and internal audit functions should: Report functionally to the organization s board, typically through an audit or compliance committee. This reporting relationship provides each function with the necessary authority to effectively address their responsibilities. Function relative to a board-approved program or charter. A board-approved charter documents the established authority. Report administratively to the organization s CEO. This reporting relationship ensures that functional administration and resource allocation is not inappropriately influenced by operational areas subject to corporate compliance and internal audit activities. Have access to the entire organization per board direction, typically identified in the boardapproved program or charter. Compliance and internal audit professionals must have open access to the records and personnel of the organization to ensure unbiased results. Recognize and communicate that management is responsible for compliance, corporate compliance is not. Management is responsible for ensuring its activities comply with applicable laws, rules and regulations. This fact should be identified in the board-approved program or charter. Recognize and communicate that management is responsible for internal controls, internal audit is not. Management is responsible for ensuring that appropriate internal controls are implemented to meet organizational mission and strategic objectives. This fact should be identified in the board-approved program or charter. Have the authority to conduct investigations. In many cases, compliance and audit collaborate to conduct investigations. Depending upon the nature of the investigation, either function may work on their own or in collaboration with other functions like human resources, information technology, legal and security. Both functions are also cost centers of an organization, that is, functions that are not designed to contribute directly to the financial bottom line. While both functions often identify cost-saving or revenue-enhancing opportunities, neither should carry that as their primary role. Since they are cost centers, functional resources are limited. Both functions best serve their organizations with these limited resources by fulfilling their responsibilities through focus on the priority or highest risk areas. Risk assessment is a key component of both functions. Risk assessment involves the application of a methodical process for identifying key risks that face the organization. Both corporate compliance and internal audit address corporate level risk, governance and control. As defined by the Committee of Sponsoring Organizations (COSO) of the Treadway Commission, internal control is broadly defined as a process, effected by an entity's board of directors, management and other personnel, designed to provide reasonable assurance regarding the achievement of objectives in the following categories: Effectiveness and efficiency of operations. Reliability of financial reporting. Compliance with applicable laws and regulations. AM-AuditCompliance-RolesResp(FINAL-Article ) (2).doc 2/5
3 Roles and Responsibilities and By Mark P. Ruppert, CPA, CIA, CISA, CHFP Each function addresses corporate level risk, governance and control and a risk assessment helps each function prioritize resources to effectively address the most important matters. However, the compliance risk assessment is focused on regulatory and other compliance related matters and the internal audit risk assessment is focused on internal control related matters, including controls that affect compliance. Because there is some overlap, coordination of planning efforts typically improves the risk assessment results thereby benefiting both functions as well the organization The Focus Group issued a previous article that specifically addressed the completion of a compliance risk assessment. You may reference that article for additional details. Unique Roles and Responsibilities Exhibit A identifies in detail by category the uniqueness of each function. The following discussion summarizes the unique roles of each function deemed most notable by the Focus Group. Operations While both functions should be independent of operations Corporate compliance functions own the compliance program operations, and supporting policies and processes. Auditing and Monitoring Internal audit must be independent of all areas subject to audit to ensure objectivity. Professional standards prohibit internal audit responsibility for operations. Understanding the unique roles of corporate compliance and internal audit requires an appreciation for the definitions of auditing and monitoring. The last article published by the Focus Group addressed these definitions as follows: Auditing is a formal, systematic and disciplined approach designed to evaluate and improve the effectiveness of processes and related controls. Auditing is governed by professional standards, completed by individuals independent of the process being audited, and normally performed by individuals with one of several acknowledged certifications. Objectivity in governance reporting is the benefit of independence. Monitoring is an on-going process usually directed by management to ensure processes are working as intended. Monitoring is an effective detective control within a process. Compliance ensures that auditing and monitoring for key compliance risk areas occurs. If properly governed and conducted according to professional audit standards, compliance may conduct or engage outside services for the conduct of compliance audits. Follow-up is responsible for all internal audit activity within an organization. Given the application of formal audit methodology and reporting requirements, does not complete monitoring activities though its work can sometimes identify the need for and provide the basis for monitoring mechanisms being established. Follow-up relates to ensuring that improvement opportunities and problems identified through auditing and monitoring efforts have been addressed by the organization, typically through the efforts directed by management. Follow-up is an effective mechanism to establish management accountability for compliance and internal control. While compliance and internal audit are responsible for following up to ensure remedial actions have been taken AM-AuditCompliance-RolesResp(FINAL-Article ) (2).doc 3/5
4 Roles and Responsibilities and By Mark P. Ruppert, CPA, CIA, CISA, CHFP Corporate compliance documents follow-up regarding resolution of hotline calls and reported compliance issues. Follow-up reporting to the board is not specifically mandated and is therefore at the compliance officer s discretion. Compliance Program Internal audit is required to ensure follow-up of recommendations made in internal audit reports to determine if management has responded accordingly. Formal tracking and reporting to the board is also required. A formal documented compliance program is recommended by the Office of the Inspector General. Some organizations are also required to have such programs by corporate integrity agreements reached with the government due to prior significant compliance failures. Compliance and internal audit work in tandem to ensure the compliance programs are functioning and effective. Corporate compliance creates and executes the organization s corporate compliance program relative to its role. Management and all members of the organization are responsible for ensuring that compliance with laws, rules and regulations occurs. Internal audit provides advice and consultation relative to the compliance program. Internal Audit is responsible for auditing compliance program implementation and evaluating program effectiveness. Compliance Risks Compliance risk is the driving need for a corporate compliance program: organizations must ensure that they are taking reasonable measures to comply with applicable laws, rules and regulations, as well as their own policies. Corporate compliance and internal audit have comparable roles relative to addressing compliance risk. However Corporate compliance creates and executes an annual or periodic compliance work plan that ensures compliance risks are being addressed through the use of compliance personnel and management led monitoring activities. Information Technology Internal audit addresses compliance risk as part of risk-based audits or in conjunction with corporate compliance coordination and the compliance work plan. Information technology presents significant compliance and internal control risks. In many cases such risks are one in the same. Internal auditors/information systems auditors have been addressing information systems risk for many years and much of the current HIPAA guidance is parallel to such recommendations. Corporate compliance provides input on necessary compliance controls relative to new systems implementation and existing systems controls. The function also coordinates with or oversees the privacy officer (and in some cases security officer) to ensure proper HIPAA privacy and security controls are in place. Internal audit completes audits of new systems implementation and existing systems controls to ensure mitigation of business, compliance and other risks, including HIPAA. AM-AuditCompliance-RolesResp(FINAL-Article ) (2).doc 4/5
5 Roles and Responsibilities and By Mark P. Ruppert, CPA, CIA, CISA, CHFP Conclusion Corporate compliance and internal audit share similar roles and responsibilities, while also maintaining specific, unique roles and responsibilities. These roles and responsibilities are not structured the same in all organizations and, in some cases, are combined. Regardless of how your organization structures these important governance functions, corporate compliance and internal audit are most effective when they work in a collaborative manner, one that includes joint planning and coordination of risk assessment efforts to review for overlapping areas, coordinated reporting to management and the board on significant issues, and shared involvement in key compliance related committees, task forces and other working groups. Understanding the similarities and differences as summarized in this article should help to ensure such collaboration is deliberate and effective. About the AHIA/HCCA Focus Group The AHIA/HCCA focus group will continue to address compliance auditing and monitoring directives through white papers, articles and educational initiatives. The Focus Group welcomes your feedback and requests to address particular matters related to auditing and monitoring. Please submit your request directly to any member of the focus group. Members of the focus group are: Mark P. Ruppert, Cedars-Sinai Health System Debi Weatherford, CHAN Healthcare Auditors Randall Brown, Baylor Health Care System Kathy Thomas, Duke University Health System Debra Muscio, Central Connecticut Health Alliance Jan Coughlin, Scripps Health AM-AuditCompliance-RolesResp(FINAL-Article ) (2).doc 5/5
6 AHIA HCCA Auditing & Monitoring Focus Group Defining the Key Roles and Responsibilities and Discussion Points Requirement: May be required if the organization must comply with Sarbanes-Oxley. Otherwise, is implemented as an organizational governance/business decision and best practice. Purpose: Provide independent appraisals of governance, risk and control. Review the reliability and integrity of financial and operation information. Ensure the safeguarding of assets. Review operations for consistency with operational goals and objectives. Recommend operating improvements. Audit annually the compliance program. Federal Sentencing Guidelines May be required if the organization is under a corporate integrity agreement (CIA). Otherwise, OIG guidance is advisory. May be required if the organization must comply with Sarbanes-Oxley. Prevent Fraud and Abuse: Encourage the use of internal controls to efficiently monitor adherence to applicable statutes and regulations. Effect change as necessary in the organization to achieve regulatory compliance. Ensure that compliance policy and procedure exist. Provide compliance training. Implement a hotline. Reporting: Independent Reporting to the Board or a Committee of the Board. Protect and Secure PHI: Implement HIPAA Privacy Standards. Implement HIPAA Security Standards. Independent Reporting to the Board or a Committee of the Board. Internal Authority: Board Approved Charter. Board Approved Compliance Program. May also have a Board Approved Compliance Committee Charter. Span of Responsibility: Access to entire organization. Access to entire organization. Audit_vs_Compliance-Responsibilities(FINAL )-1.doc 1
7 AHIA HCCA Auditing & Monitoring Focus Group Defining the Key Roles and Responsibilities and Discussion Points Professional Standards: High Level Focus: Primary focus from a risk standpoint: Activity Focus Professional Standards: Institute of ors Standards for the Professional Practice of Internal Auditing (SPPIA) AICPA Generally Accepted Auditing Standards (GAAS) ISACA Standards IIA Code of Ethics Certified or (CIA) Certified Information Systems Auditor (CISA) Internal auditing is an independent, objective assurance and consulting activity designed to add value and improve an organization's operations. It helps an organization accomplish its objectives by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of risk management, control, and governance processes. Driven by audit planning, which is based upon an organization-wide risk assessment. Audit/project based, periodic assurance based on concurrent or retrospective reviews. Primarily evident in the Federal Sentencing Guidelines and the OIG Compliance Program Guidance. Additionally, guidance is evident relative to: HIPAA Stark Others like JCAHO, state, etc HCCA Code of Ethics HCCA Compliance Certification Program Health Ethics Trust and related certification Corporate Governance, Ethics and Risk from a Regulatory Compliance Perspective. Preserving corporate integrity and adherence to a code of organization ethics. Driven by federal and state fraud and abuse investigative agendas, to include Stark, AKS, Intermediate Sanctions, and HIPAA Investigations. Also, by the law, ethics and other regulatory requirements, with consideration of the OIG work plan. On-going monitoring and evaluation of the ethical culture and compliance with laws, regulations, policies and procedures. Also, ongoing training related to the above. Audit_vs_Compliance-Responsibilities(FINAL )-1.doc 2
8 AHIA HCCA Auditing & Monitoring Focus Group Defining the Key Roles and Responsibilities and Discussion Points Relationship to Management: Training Responsibility: Auditing: Independent with no operational responsibilities. Does not own policies. Consults on policy and other matters related to governance risk and control. Management is responsible for implementing internal controls. Not responsible for corporate training. May provide training in certain areas i.e. training on the audit process; training to expand knowledge on issues identified as part of an audit. Auditing is a primary internal audit function. projects are completed in accordance with professional standards. Independent but with operational responsibility for administering the corporate compliance program. (i.e., owns the compliance program). Individual with operational responsibilities may also be assigned responsibility for corporate compliance; if possible, best practice is for a compliance function to be independent of operational responsibilities. May own policies (hotline, etc.). Consults on policy and other regulatory compliance matters. Management is responsible for ensuring compliance with laws, rules and regulations. Responsible for ensuring that new employees/management are oriented on the compliance program, that continuing employees/management undergo annual training on selected topics, and that employees in high risk areas receive appropriate specialized training. Also updates management and the Board on new laws, regulations and government activities. Compliance can complete audits of operations for which it does not have operational responsibility. However, Compliance audits are not governed by formal audit standards. Typically, compliance officers are responsible for ensuring that management appropriately monitors their staff. Audit_vs_Compliance-Responsibilities(FINAL )-1.doc 3
9 AHIA HCCA Auditing & Monitoring Focus Group Defining the Key Roles and Responsibilities and Discussion Points Monitoring: Not typically an role. Typical component of compliance program though often completed by departmental management and reported to Compliance. Compliance officer is responsible for ensuring that such management appropriately monitors their staff. Expertise: Primarily with internal controls. Primarily in regulatory matters. Impact on plan: Impact on Compliance Plan: Risk Assessment: Follow-up: Investigation: Creates and executes. Provides advice and consultation. Audits compliance program implementation and evaluates effectiveness. Assesses risk in developing its annual audit plan and in planning individual audit projects. Evaluates the risk management processes in the organization. Formal follow-up of recommendations made in reports to determine if management has responded accordingly. Typically responsible for investigating fraud, irregularities and other accounting related improprieties. Coordinates activities with Compliance, Legal, Security, IT, HR and other areas as deemed necessary to effectively conduct the investigation. May complete investigations on its own accord, at the request of the Board or Management. Typically supports the Compliance Officer in investigating non-hr related hotline complaints. Provides advice and consultation. Provides input on the types of compliance risk that should be considered in audits. Creates and executes. Assesses compliance risk in developing its annual work plan. Documented follow-up regarding resolution of hotline calls and reported compliance issues. Typically responsible for ensuring that all hotline calls and other complaints/inquiries made to the Compliance officer are addressed and resolved in an appropriate manner. May coordinate with or obtain direct assistance from, Legal, Security, IT, HR and other areas as deemed necessary to effectively conduct the investigation. May complete investigations on its own accord, at the request of the Board or Management. Audit_vs_Compliance-Responsibilities(FINAL )-1.doc 4
10 AHIA HCCA Auditing & Monitoring Focus Group Defining the Key Roles and Responsibilities and Discussion Points Hotline: Best Practice Component of the OIG Model Compliance Program. Information Systems: Audits new systems implementation and existing systems controls. Provides input on necessary compliance controls relative to new systems implementation and existing systems controls. Coordinates with Privacy Officer to ensure proper HIPAA privacy and security controls are in place. Internal Controls Evaluate the effectiveness of internal controls. Understand and encourage the use of internal controls. Audit_vs_Compliance-Responsibilities(FINAL )-1.doc 5
AHIA HCCA Auditing & Monitoring Focus Group Defining the Key Roles and Responsibilities Corporate Compliance and Internal Audit.
and Requirement: May be required if the organization must comply with Sarbanes-Oxley. Otherwise, is implemented as an organizational governance/business decision and best practice. Purpose: Provide independent
Compliance Education/Awareness Tools and Techniques. Author: Kathy Thomas, Associate Compliance Officer, Duke University Health System
Compliance Education/Awareness Tools and Techniques Author: Kathy Thomas, Associate Compliance Officer, Duke University Health System Introduction A focus group of Health Care Compliance Association (HCCA)
Emphasizing a Documented Comprehensive Approach to Compliance Auditing
Emphasizing a Documented Comprehensive Approach to Compliance Auditing Author: Debi Weatherford, Vice President Compliance & Audit Services, Revenue Cycle Solutions, Marietta, GA Introduction A focus group
Performing a Compliance Risk Assessment for Compliance Auditing & Monitoring in Healthcare Organizations
Performing a Compliance Risk Assessment for Compliance Auditing & Monitoring in Healthcare Organizations Author: Glen C. Mueller, Chief Audit & Compliance Officer, Scripps Health, San Diego, CA Introduction
HCCA COMPLIANCE INSTITUTE. HCCA - AHIA Auditing & Monitoring Focus Group Progress Report
HCCA COMPLIANCE INSTITUTE New Orleans, LA Tuesday, April 19, 2005 Workshop from 3:00pm 4:00pm HCCA - AHIA Auditing & Monitoring Focus Group Progress Report Randall Brown, CIA Baylor Healthcare System Corporate
Agenda Item: 7.6 Prepared by: Mark Majek, Kathy Thomas, Deborah Bell, Tamara Cowen and Jaye Stepp Meeting Date: October 2014
Agenda Item: 7.6 Prepared by: Mark Majek, Kathy Thomas, Deborah Bell, Tamara Cowen and Jaye Stepp Meeting Date: October 2014 Summary of Request: The purpose, authority, and responsibility of the internal
Internal Auditing Guidelines
Internal Auditing Guidelines Recommendations on Internal Auditing for Lottery Operators Issued by the WLA Security and Risk Management Committee V1.0, March 2007 The WLA Internal Auditing Guidelines may
Standards for the Professional Practice of Internal Auditing
Standards for the Professional Practice of Internal Auditing THE INSTITUTE OF INTERNAL AUDITORS 247 Maitland Avenue Altamonte Springs, Florida 32701-4201 Copyright c 2001 by The Institute of Internal Auditors,
INTERNATIONAL STANDARDS FOR THE PROFESSIONAL PRACTICE OF INTERNAL AUDITING (STANDARDS)
INTERNATIONAL STANDARDS FOR THE PROFESSIONAL PRACTICE OF INTERNAL AUDITING (STANDARDS) Revised: October 2012 i Table of contents Attribute Standards... 3 1000 Purpose, Authority, and Responsibility...
BOARD OF EDUCATION OF BALTIMORE COUNTY OFFICE OF INTERNAL AUDIT - OPERATIONS MANUAL INTERNAL AUDIT OPERATIONS MANUAL
BOARD OF EDUCATION OF BALTIMORE COUNTY INTERNAL AUDIT OPERATIONS MANUAL BACKGROUND The Office of Internal Audit Operations Manual was developed to be used as a guide and resource for the Office of Internal
Seven Component Framework For Compliance Auditing & Monitoring Physician Contracting In Healthcare Organizations
Seven Component Framework For Compliance Auditing & Monitoring Physician Contracting In Healthcare Organizations Author: Debi J. Weatherford, Vice President, Compliance and Audit Services, Revenue Cycle
AHIA Auditing and Monitoring Framework Seven Key Components
AHIA Auditing and Monitoring Framework Seven Key Components Author: Debi J. Weatherford Director, Internal Audit & Corporate Compliance at Children s Healthcare of Atlanta Introduction This publication
INTERNATIONAL STANDARDS FOR THE PROFESSIONAL PRACTICE OF INTERNAL AUDITING (STANDARDS)
INTERNATIONAL STANDARDS FOR THE PROFESSIONAL PRACTICE OF INTERNAL AUDITING (STANDARDS) Introduction to the International Standards Internal auditing is conducted in diverse legal and cultural environments;
TITLE: Scripps Compliance Program
PAGE 1 of 7 TITLE: Scripps Compliance Program IDENTIFIER: S-FW-LD-1003 APPROVED: Executive Cabinet 08/14/12 ORIGINAL FORMULATION: 11/00 REVISED: 02/06, 11/06, 10/09, 08/12 REVIEWED: EFFECTIVE: Acute Care:
INDIANA UNIVERSITY SCHOOL OF OPTOMETRY HIPAA COMPLIANCE PLAN TABLE OF CONTENTS. I. Introduction 2. II. Definitions 3
INDIANA UNIVERSITY SCHOOL OF OPTOMETRY HIPAA COMPLIANCE PLAN TABLE OF CONTENTS I. Introduction 2 II. Definitions 3 III. Program Oversight and Responsibilities 4 A. Structure B. Compliance Committee C.
Broker-Dealer and Investment Adviser Compliance Programs
Lori A. Richards Principal, PricewaterhouseCoopers Financial Services Regulatory Practice Broker-Dealer and Investment Adviser Compliance Programs Regulatory Requirements, Common Minimum Elements, Other
INTERNAL AUDIT CHARTER AND TERMS OF REFERENCE
INTERNAL AUDIT CHARTER AND TERMS OF REFERENCE CHARTERED INSTITUTE OF INTERNAL AUDIT DEFINITION OF INTERNAL AUDIT Internal auditing is an independent, objective assurance and consulting activity designed
Health Sciences Compliance Plan
INDIANA UNIVERSITY Health Sciences Compliance Plan 12.18.2014 approved by University Clinical Affairs Council Table of Contents Health Sciences Compliance Plan I. INTRODUCTION... 2 II. SCOPE... 2 III.
Administrative Guidelines on the Internal Control Framework and Internal Audit Standards
Administrative Guidelines on the Internal Control Framework and Internal Audit Standards GCF/B.09/18 18 February 2015 Meeting of the Board 24 26 March 2015 Songdo, Republic of Korea Agenda item 24 Page
Larry Laine, Deputy Land Commissioner and Chief Clerk. Annual Report on the Internal Audit Quality Assurance and Improvement Program
DATE: TO: FROM: SUBJECT: Larry Laine, Deputy Land Commissioner and Chief Clerk Tracey Hall, Deputy Commissioner of Internal Audit Annual Report on the Internal Audit The following report is presented in
BAPTIST HEALTH CORPORATE COMPLIANCE PLAN
BAPTIST HEALTH CORPORATE COMPLIANCE PLAN BAPTIST HEALTH and its subsidiaries have a long-standing reputation for conducting both business and patient care activities with the highest level of ethical behavior
INTERNAL AUDITING S ROLE IN SECTIONS 302 AND 404
INTERNAL AUDITING S ROLE IN SECTIONS 302 AND 404 OF THE U.S. SARBANES-OXLEY ACT OF 2002 May 26, 2004 Copyright 2004 by, 247 Maitland Avenue, Altamonte Springs, Florida, 32701-4201, USA Internal Auditing
LEVERAGING COSO ACROSS THE THREE LINES OF DEFENSE
Committee of Sponsoring Organizations of the Treadway Commission Governance and Internal Control LEVERAGING COSO ACROSS THE THREE LINES OF DEFENSE By The Institute of Internal Auditors Douglas J. Anderson
B o a r d of Governors of the Federal Reserve System. Supplemental Policy Statement on the. Internal Audit Function and Its Outsourcing
B o a r d of Governors of the Federal Reserve System Supplemental Policy Statement on the Internal Audit Function and Its Outsourcing January 23, 2013 P U R P O S E This policy statement is being issued
How To Be A Successful University
TUSDM Patient Billing and HIPAA Privacy Compliance Program Adopted: 12/14/12 TABLE OF CONTENTS Section 1. Definitions 2. Objectives Page 1 1 3. Oversight Responsibility 2 4. Compliance Procedures for Submitting
Internal Audit Standards
Internal Audit Standards Department of Public Expenditure & Reform November 2012 Copyright in material supplied by third parties remains with the authors. This includes: - the Definition of Internal Auditing
Internal Audit Manual
Internal Audit Manual Version 1.0 AUDIT AND EVALUATION SECTOR AUDIT AND ASSURANCE SERVICES BRANCH INDIAN AND NORTHERN AFFAIRS CANADA April 25, 2008 #933907 Acknowledgements The Institute of Internal Auditors
GAO. Government Auditing Standards. 2011 Revision. By the Comptroller General of the United States. United States Government Accountability Office
GAO United States Government Accountability Office By the Comptroller General of the United States December 2011 Government Auditing Standards 2011 Revision GAO-12-331G GAO United States Government Accountability
COMPLIANCE WITH LAWS AND REGULATIONS (CLR)
Principle: Ensuring compliance with applicable laws, regulations and professional standards of practice implementing systems and processes that prevent fraud and abuse. 91 Compliance with Laws and Regulations
Mental Health Resources, Inc. Mental Health Resources, Inc. Corporate Compliance Plan Corporate Compliance Plan
Mental Health Resources, Inc. Mental Health Resources, Inc. Corporate Compliance Plan Corporate Compliance Plan Adopted: January 2, 2007 Revised by Board of Directors on September 4, 2007 Revised and Amended
Five-Year Strategic Plan
U.S. Department of Education Office of Inspector General Five-Year Strategic Plan Fiscal Years 2014 2018 Promoting the efficiency, effectiveness, and integrity of the Department s programs and operations
Action Plan to Enhance Institutional Compliance. THE UNIVERSITY OF TEXAS SYSTEM Updated 2003
Action Plan to Enhance Institutional Compliance THE UNIVERSITY OF TEXAS SYSTEM Updated 2003 Audit Office System-wide Compliance Program June 2003 I N T R O D U C T I O N This 2003 Action Plan to Enhance
UMDNJ COMPLIANCE PLAN
UMDNJ COMPLIANCE PLAN INTRODUCTION...2 COMPLIANCE OVERSIGHT 3 COMPLIANCE COMMITTEE STRUCTURE...4 CHIEF COMPLIANCE OFFICER S RESPONSIBILITIES...5 RESEARCH COMPLIANCE.5 UNIT IMPLEMENTATION.6 COMPLIANCE POLICIES
Puerto Rican Family Institute, Inc.
Puerto Rican Family Institute, Inc. Stronghold for Families, a Pathfinder for Children Corporate Compliance Program Plan - 2014 Updated by: Approved by: Yolanda Alicea Winn, LCSWR Vice President/Corporate
Internal Audit and Advisory Services DRAFT
Internal Audit and Advisory Services DRAFT PAGE(S) Message from the Internal Audit and Advisory Services...1-2 Internal Audit and Advisory Services Plan...3-5 Objectives...6-7 Risk Assessment Process...8
November 2009 Report No. 10-014. An Audit Report on The Department of Aging and Disability Services Home and Community-based Services Program
John Keel, CPA State Auditor An Audit Report on The Department of Aging and Disability Services Home and Community-based Services Program Report No. 10-014 An Audit Report on The Department of Aging and
This article will provide background on the Sarbanes-Oxley Act of 2002, prior to discussing the implications for business continuity practitioners.
Auditing the Business Continuity Process Dr. Eric Schmidt, Principal, Transitional Data Services, Inc. Business continuity audits are rapidly becoming one of the most urgent issues throughout the international
Comptroller of Public Accounts Effectiveness of Internal Engagement May 1997
Table of Contents Comptroller of Public Accounts Effectiveness of Internal Engagement May 1997 Overall Conclusion...1 The Internal Audit Department Is Currently Effective in All Eight Criteria, But Could
Using Computer Assisted Audit Techniques For More Effective Compliance Auditing and Monitoring In Healthcare Organizations
Using Computer Assisted Audit Techniques For More Effective Compliance Auditing and Monitoring In Healthcare Organizations Author: Glen C. Mueller, Chief Audit & Compliance Officer, Scripps Health, San
M-Aud. Comptroller of the Currency Administrator of National Banks. Internal and External Audits. Comptroller s Handbook. April 2003.
M-Aud Comptroller of the Currency Administrator of National Banks Internal and External Audits Comptroller s Handbook April 2003 M Management Internal and External Audits Table of Contents Introduction...1
Internal Audit Manual
COMPTROLLER OF ACCOUNTS Ministry of Finance Government of the Republic of Trinidad Tobago Internal Audit Manual Prepared by the Financial Management Branch, Treasury Division, Ministry of Finance TABLE
POLICY SUBJECT: EFFECTIVE DATE: 5/31/2013. To be reviewed at least annually by the Ethics & Compliance Committee COMPLIANCE PLAN OVERVIEW
Compliance Policy Number 1 POLICY SUBJECT: EFFECTIVE DATE: 5/31/2013 Compliance Plan To be reviewed at least annually by the Ethics & Compliance Committee COMPLIANCE PLAN OVERVIEW Sound Inpatient Physicians,
Compliance Requirements for Healthcare Carriers
INFORMATION DRIVES SOUND ANALYSIS, INSIGHT REGULATORY COMPLIANCE ADVISORY Compliance Requirements for Healthcare Carriers Introduction With the introduction of the new healthcare exchanges in January 2014
INTERNAL AUDIT MANUAL
དང ལ ར ས ལ ན ཁག Internal Audit Manual INTERNAL AUDIT MANUAL Royal Government of Bhutan 2014 i i ii ii Internal Audit Manual དང ལ ར ས ལ ན ཁག ROYAL GOVERNMNET OF BHUTAN MINISTRY OF FINANCE TASHICHHO DZONG
GAO DEFENSE CONTRACT AUDITS. Actions Needed to Improve DCAA's Access to and Use of Defense Company Internal Audit Reports
GAO United States Government Accountability Office Report to the Committee on Armed Services, U.S. Senate December 2011 DEFENSE CONTRACT AUDITS Actions Needed to Improve DCAA's Access to and Use of Defense
PRACTICE ADVISORIES FOR INTERNAL AUDIT
Société Française de Réalisation, d'etudes et de Conseil Economics and Public Management Department PRACTICE ADVISORIES FOR INTERNAL AUDIT Tehnical Assistance to the Ministry of Finance for Development
Risk committee performance evaluation
Risk committee performance evaluation While there is currently not a legal or regulatory requirement for board risk committees to complete a performance evaluation, King III recommends regular performance
Montgomery County, Unique Aspects of the Medicaid Control System
MONTGOMERY COUNTY POLICY AND PROCEDURE Date Drafted: 12/07/09 Date Approved: 12/15/09 Date(s) Revised: I. POLICY: It is the policy of Montgomery County to promote compliance with all federal, state, and
1. This bulletin, which contains the Charter of the Office of Internal Oversight Services (IOS) of
UNIDO/DGB/(M).92/Rev.3 28 January 2015 Distribution: All staff members at headquarters, established offices and permanent missions 1. This bulletin, which contains the Charter of the Office of Internal
Effective Internal Audit in the Financial Services Sector
Effective Internal Audit in the Financial Services Sector Recommendations from the Committee on Internal Audit Guidance for Financial Services: How They Relate to the Global Institute of Internal Auditors
Internal Auditing: Assurance, Insight, and Objectivity
Internal Auditing: Assurance, Insight, and Objectivity WHAT IS INTERNAL AUDITING? INTERNAL AUDITING business people all around the world are familiar with the term. But do they understand the value it
Application of King III Corporate Governance Principles
Application of Corporate Governance Principles Application of Corporate Governance Principles This table is a useful reference to each of the principles and how, in broad terms, they have been applied
Approved by the Audit and Compliance Committee of the Providence Health & Services Board of Directors
Integrity and Compliance Description Approved by the Audit Committee of the Providence Health & Services Board of Directors December 7, 2009 Contents: Introduction Page 1 Purpose Page 2 Compliance Administration
How quality assurance reviews can strengthen the strategic value of internal auditing*
How quality assurance reviews can strengthen the strategic value of internal auditing* PwC Advisory Internal Audit Table of Contents Situation Pg. 02 In response to an increased focus on effective governance,
IFAD Policy on Enterprise Risk Management
Document: EB 2008/94/R.4 Agenda: 5 Date: 6 August 2008 Distribution: Public Original: English E IFAD Policy on Enterprise Risk Management Executive Board Ninety-fourth Session Rome, 10-11 September 2008
The University of Texas Health Science Center at Houston Institutional Healthcare Billing Compliance Plan JANUARY 14, 2013
JANUARY 14, 2013 I. Preamble The University of Texas Health Science Center at Houston (UTHealth) is committed to ensuring that its affairs are conducted in accordance with applicable laws and regulations.
Accountable Care Organization. Medicare Shared Savings Program. Compliance Plan
Accountable Care Organization Participating In The Medicare Shared Savings Program Compliance Plan 2014 Corporate Location: 3190 Fairview Park Drive Falls Church, VA 22042 ARTICLE I INTRODUCTION This Compliance
Performance Measures for Internal Auditing
Performance Measures for Internal Auditing A simple question someone may ask is Why measure performance? An even simpler response would be that what gets measured gets done. McMaster University s discussion
Guidance Note: Corporate Governance - Board of Directors. March 2015. Ce document est aussi disponible en français.
Guidance Note: Corporate Governance - Board of Directors March 2015 Ce document est aussi disponible en français. Applicability The Guidance Note: Corporate Governance - Board of Directors (the Guidance
HIPAA Privacy Rule Policies
DRAFT - Policies and Procedures PRIVACY OFFICE ASSIGNMENT AND RESPONSIBILITIES APPROVED BY: SUPERCEDES POLICY: Policy #1 ADOPTED: REVISED: REVIEWED: Purpose This policy is designed to assure the establishment
ACCA P1 Internal Control. incorporated into Combined code, it was last revised in 2005 and still present as a standalone document.
Internal Control ACCA P1 Internal Control Turnbull Report 1999 provided guidance for creating strong internal control system and later incorporated into Combined code, it was last revised in 2005 and still
NORFOLK STATE UNIVERSITY INTERNAL AUDIT CHARTER
INTRODUCTION Internal Auditing as defined by the Institute of Internal Auditors, is an independent objective assurance and consulting activity designed to add value and improve an organization s operations.
2012-2013 MEDICARE COMPLIANCE TRAINING EMPLOYEES & FDR S. 2012 Revised
2012-2013 MEDICARE COMPLIANCE TRAINING EMPLOYEES & FDR S 2012 Revised 1 Introduction CMS Requirements As of January 1, 2011, Federal Regulations require that Medicare Advantage Organizations (MAOs) and
Practice Guide COORDINATING RISK MANAGEMENT AND ASSURANCE
Practice Guide COORDINATING RISK MANAGEMENT AND ASSURANCE March 2012 Table of Contents Executive Summary... 1 Introduction... 1 Risk Management and Assurance (Assurance Services)... 1 Assurance Framework...
MSO/IPA Compliance Program
MSO/IPA Compliance Program PROSPECT MEDICAL HOLDINGS, INC. MSO/IPA COMPLIANCE PROGRAM Coverage The terms of the Compliance Program set forth herein shall apply to, and govern, the medical group business
Internal Audit Charters
Internal Audit Charters Part of a series of notes to help Centers review their own internal management processes from the point of view of managing risks and promoting good governance and value for money,
February 2015. Audit committee performance evaluation
February 2015 Audit committee performance evaluation Audit committee performance evaluation The following questionnaire is based on emerging and leading practices to assist in the self-assessment of an
Application for CISA Certification
Application for CISA Certification 4/2015 Requirements to Become a Certified Information Systems Auditor become a Certified Information Systems Auditor (CISA), an applicant must: 1. Score a passing grade
THE FCA INSPECTOR GENERAL: A COMMITMENT TO PUBLIC SERVICE
THE FCA INSPECTOR GENERAL: A COMMITMENT TO PUBLIC SERVICE FORWARD I am pleased to introduce the mission and authorities of the Office of Inspector General for the Farm Credit Administration. I hope this
Common Internal Audit Findings and How to Avoid Them
Common Internal Audit Findings and How to Avoid Them May 2, 2011 Boyd Kumher University Compliance Officer Tina Griffiths Senior Manager, Deloitte Brian Bartos Senior Consultant, Deloitte Today s Agenda
AppleCare. 2013 General Compliance Training
AppleCare 2013 General Compliance Training Goals After completing this course, you will understand: The Principles of Ethics and Integrity and the Compliance Plan How to report a suspected or detected
INTERNAL AUDIT FRAMEWORK
INTERNAL AUDIT FRAMEWORK April 2007 Contents 1. Introduction... 3 2. Internal Audit Definition... 4 3. Structure... 5 3.1. Roles, Responsibilities and Accountabilities... 5 3.2. Authority... 11 3.3. Composition...
Impact of New Internal Control Frameworks
Impact of New Internal Control Frameworks Webcast: Tuesday, February 25, 2014 CPE Credit: 1 0 With You Today Bob Jacobson Principal, Risk Advisory Services Consulting Leader West Region [email protected]
Application of King III Corporate Governance Principles
APPLICATION of KING III CORPORATE GOVERNANCE PRINCIPLES 2013 Application of Corporate Governance Principles This table is a useful reference to each of the principles and how, in broad terms, they have
COHERENT, INC. Board of Directors. Governance Guidelines
COHERENT, INC. Board of Directors Governance Guidelines Effective: December 12, 2013 1. Mission of the Board The Board of Directors (the Board ) has the ultimate responsibility for the well being of the
Practice guide. quality assurance and IMProVeMeNt PrograM
Practice guide quality assurance and IMProVeMeNt PrograM MarCh 2012 Table of Contents Executive Summary... 1 Introduction... 2 What is Quality?... 2 Quality in Internal Audit... 2 Conformance or Compliance?...
Board Charter. May 2014
May 2014 Document History and Version Control Document History Document Title: Board Charter Document Type: Charter Owner: Board [Company Secretary] Description of content: Corporate Governance practices
Introduction Auditing Internal Controls in an IT Environment SOx and the COSO Internal Controls Framework Roles and Responsibilities of IT Auditors
Introduction Auditing Internal Controls in an IT Environment SOx and the COSO Internal Controls Framework Roles and Responsibilities of IT Auditors Importance of Effective Internal Controls and COSO COSO
How To Comply With The Law Of The Firm
A Firm s System of Quality Control 2523 QC Section 10 A Firm s System of Quality Control (Supersedes SQCS No. 7.) Source: SQCS No. 8. Effective date: Applicable to a CPA firm s system of quality control
ADMINISTRATIVE POLICY # 32 8 2 (2014) Information Security Roles and Responsibilities
Policy Title: Information Security Roles Policy Type: Administrative Policy Number: ADMINISTRATIVE POLICY # 32 8 2 (2014) Information Security Roles Approval Date: 05/28/2014 Revised Responsible Office:
MANUAL OF UNIVERSITY POLICIES PROCEDURES AND GUIDELINES. Applies to: faculty staff students student employees visitors contractors
Page 1 of 5 Applies to: faculty staff students student employees visitors contractors Effective Date of This Revision: October 19, 2006 Contact for More Information: Chief Privacy Officer 1303 A West Campus
CORPORATE COMPLIANCE PROGRAM
CORPORATE COMPLIANCE PROGRAM BACKGROUND AND POLICY: The Oakwood Accountable Care Organization, LLC. ( ACO ) corporate policy relating to compliance with applicable laws and regulations is embodied in this
Mapping COBIT 5 with IT Governance, Risk and Compliance at Ecopetrol S.A. By Alberto León Lozano, CISA, CGEIT, CIA, CRMA
Volume 3, July 2014 Come join the discussion! Alberto León Lozano will respond to questions in the discussion area of the COBIT 5 Use It Effectively topic beginning 21 July 2014. Mapping COBIT 5 with IT
Professional Certification Programs
Professional Certification Programs Certified Internal Control Specialists - CICS Certified Internal Control Professional - CICP Copyright 2009 by Internal Control Institute Introduction The Certified
RISK ADVISORY SERVICES. HYDRO UTILITIES Overview of Internal Audit & Control Services: 2014 Credentials
RISK ADVISORY SERVICES HYDRO UTILITIES Overview of Internal Audit & Control Services: 2014 Credentials THE INCREASED IMPORTANCE OF INTERNAL CONTROLS FOR HYDRO UTILITIES TO MEET THE OBJECTIVES OF FINANCIAL
