3 3 Start If gift is stock If gift is credit card If gift is cash/check Mail opened, checks stamped FDO Community Foundation, totals logged & verified 1 Administrative Assistant & mail verifier Cash Receipts Internal Controls Cash/checks recorded individually by check # on electronic cash receipts log with notation of donation purpose & locked in secure location Executive Assistant Bank deposits prepared & delivered to bank as necessary 3 Deposits verified & approved prior to delivery to bank Written log & electronic log compared & verified; gifts other than cash & check added to bottom of log for total receipts 4 Cash log reviewed at weekly staff meeting Cash receipts entered in FIMS & compared to log 5 Cash log, gift edit, journal entries reviewed & approved before posting Gifts & journal entries posted in FIMS Gift acknowledgments prepared & printed Administrative Assistant Gift acknowledgments verified 8 9 Gift acknowledgments approved & signed Gift acknowledgments mailed to donors & filed electronically Administrative Assistant 1. Two people independent of accounting staff open mail (verifier rotates) & log receipts in total daily. C,R. Cash receipts logged in detail by position independent of accounting staff & mail openers & locked in secure location. C,R 3. Deposit slips verified & approved by associate director prior to delivery to bank. C,V,A 4. Logs compared & verified by position independent of mail openers. C,A,R 5. Cash receipts entered into FIMS verified against cash receipts log. C,A,V,R. Cash receipts verified & approved by associate director before posting. C,A,V,R. Access to post gifts to system restricted to finance assistant and associate director. S 8. Gift acknowledgements verified to cash receipt log by position independent of letter processing. A 9. Gift acknowledgements approved & signed by executive director. V 1
PO generated & approved 1 Operating invoices stamped for approval, coded for general ledger account & matched to PO PRC approved grant & scholarship distribution forms forwarded to finance assistant weekly Payment request form prepared for the weekly check run Payment request form & payment documentation approved ( way match) Cash Disbursement Internal Controls See Approval Authority See grant & scholarship disbursement controls Operating invoices entered into FIMS Grants, scholarships & operating invoices are posted 3 5 8 4 Pre-numbered checks cut & posted to system based on approved payment request form Bank transfers approved Checks countersigned & Checks verified for signatures Executive Assistant Departments mail checks & file distribution forms See EFT Payments Each check compared to the check register & documented on check register 1. Purchase orders required for all purchases over $100. A,V,R. Payment request form and payment documentation approved. C,A,V,R 3. Access to post disbursements restricted to finance assistant & associate director. S. Board of directors annually authorizes check signers. Authorized signers are board president, board treasurer, executive director & associate director. All checks must be dual signed. Payments are reviewed for fictitious vendors & verified against check register. A,V,R Check register is uploaded to bank for positive pay Check register is approved for positive pay 4. Access to generate checks limited to finance assistant & associate director. Check stock has security measures embedded. S 5. Bank transfers approved by associate director. C,A,V,R. Check register is uploaded to bank s positive pay by finance assistant with approval by associate director or executive director. C,A,V,R 8. Checks are verified for appropriate number of signatures & that signatures are from appropriate personnel on checks & corresponding payment authorization documents. V
Payroll Internal Controls Timecards signed & submitted by employees Hourly staff timecards approved & submitted to finance Payroll worksheet prepared (includes hours, paid time off & any adjustments necessary) Payroll worksheet approved & timecards reviewed Payroll submitted via internet to TPV ALL Supervisors 4 5 Payroll reviewed upon delivery Payroll approval form prepared Payroll entered in FIMS Payroll reviewed & approved & Payroll posted in FIMS Direct deposit receipts disbursed to staff mailboxes All employees are encouraged to participate in payroll direct deposit 1. Hourly time cards approved by supervisors. C,A,R,V. Payroll submittal worksheet & time cards reviewed by associate director. C,A,V,R For employees that participate in the CF IRA plan, it is suggested that telephone redemptions be removed from their plan to limit access 3. Access to payroll system limited to finance assistant & associate director. S 4. Payroll reviewed by finance assistant. C,A,R 5. Payroll reviewed & approved by associate director & executive director. C,A,R 3
1 Semi-annual Performance Assessment Management Team Payroll Internal Controls Annual salary adjustment process Compensation matrix is reviewed annually Personnel Committee 1. Performance Assessment process takes place for ratings & is applied to compensation matrix. C,A,V 3 recommend salary increase pool for annual budget. Compensation matrix is reviewed annually by Personnel committee. C,A,V Governance Committee 3. Governance committee reviews & approves pool for annual merit increases & bonus pool. V Staff salary adjustment approved based on performance assessment ratings in matrix 4 4. Board president approves salary adjustments. C,A,V Board President 5. Payroll adjustments package forwarded to finance assistant. Signed off by executive director and board president. C,A,V,R. Salaries on payroll register verified each pay period by associate director. C,A,V,R Increases submitted to finance assistant for payroll adjustments 5 New salary entered into payroll system Review of salary amounts on payroll register 4
1 Cash reconciled monthly in FIMS Cash reconciliations reviewed before posting in FIMS Financial Close Internal Controls Cash logs compared to bank statements Cleared checks on check register are compared for amount & check number sequence; voided checks are investigated Transfers between accounts verified 3 4 5 Trial balance & financial statement reviewed monthly Cash reconciliation, trial balance & financial statement reviewed monthly Financial statements reviewed quarterly Audit Committee & Board of Directors 1. Accounts reconciled monthly. Access to reconcile accounts & posting restricted to finance assistant and associate director. C,A,V,R,S. Cash reconciliations reviewed prior to posting. C,A,R 3. Trial balance & financial statements reviewed monthly by associate director. C,A,V,R 4. Cash reconciliation, trial balance & financial statements reviewed monthly by executive director. C,A,V,R 5. Financial statements reviewed quarterly by audit committee & board of directors to assess: areas of risk, significant changes in numbers, & any new areas requiring monitoring. C,A,V,R. Statements distributed quarterly to donor, if discrepancy donor will communicate to Community Foundation. A,R. Annual audit reviewed by audit committee & board of directors. C,A,V,R Fund statements distributed to donors quarterly Annual audit performed Independent Auditor Annual audit reviewed Audit Committee & Board of Directors 5
1 Building Security IT Security/ Backup/Recovery Internal Controls Server located in locked room 3 Server locked 1. Building security: Alarm system, property management company is first response to alarm calls. All staff of CF & cleaning crew have key fob access with individual, unique security codes to enter building. Physical Security. Server located in locked mechanical room. Physical Security 3. Server screen is set to lock. Administrative password is only known by IT support & limited staff. S 4. Server is protected by battery backup to allow for shut down without data loss. Server protected by Cisco Firewall, Trend Micro virus protector & Mailprotector. S 5. A backup schedule is maintained in Storage Craft for M-F full & incremental backups. Daily backup reports are sent to 3 staff & IT support. Tapes drives are rotated off site daily & one offsite monthly to bank lock box. Tape drives are tested quarterly for recovery when maintenance is performed by IT support. S. Items checked with the quarterly maintenance: *Memory & Utilization Statistics *Exchange 003 *Antivirus Software *Tape Backup Software includes test restore *Battery Backup Test *Firewall logs checked for attack *Errors in Event Viewer * Random Verification of software update process on PCs S Server Protection Backup schedule DWD Qtrly Maintenance 4 5
IT User Access Internal Controls Exiting employee checklist 1 3 New employee checklist Computer security 4 5 1. Exiting employee checklist includes removing user from system by authorized IT staff. S. New employee checklist includes adding user with appropriate access by authorized IT staff. User access must be approved by supervisor. S Security levels for all applications Applications Remote users Annual review of all access tables 3 Computer security: Each employee is assigned an individual user ID & password. Mandatory network password changes are system forced every 180 days. S 4. Security levels for all applications: Network, Network accounting drive, FIMS, Payroll, banking, & etc. S 5. Remote access my be set up as determined by organizational needs with supervisor approval. S. Executive director reviews all rights. V
Applications IT User Access Internal Controls: Applications FIMS database Profile module 8 9 Grant/Scholarship module Gift/Pledges module 10 11 1 Funds module Accounts Payable, General Ledger, and FACTS modules Change management. Limited staff allowed to create and make changes. S 8. Program staff create & finance post. S 9. Finance create & post. S 10. Finance create & changes. S 11. Finance create & post. S 1. User access & upgrades initiated by associate director & reviewed by executive director. S 8
IT User Access Internal Controls: Applications cont d Applications cont d 1 14 1 1 18 Credit Card donations Network Online Banking access restricted to read only Payroll Copier Academic Works 19 Wells Fargo Merchant Account Authorize.net gateway Trustwave PCI compliance System Administrator Access, Executive Assistant & Director of Programs 13 Online Banking transfers restricted to corporate accounts & 15 System Administrator Access Scholarship Manager, Director of Programs & Committee members 1. Credit card portal has secured access for finance assistant & associate director. PCI compliance is maintained thru Authorize. net. No credit card information (card numbers, etc.) are obtained or stored by Community Foundation. 13. Network system administrator access limited to associate director, executive assistant, & director of programs. S 14. Access limited to read only for finance assistant. S 15. Access to online banking execution of transactions limited to associate director & executive director. Access to transfers limited to corporate accounts. S 1. Access to payroll system limited to finance assistant & associate director. S 1. Copier vendor gives hard drive out of copier for us to destroy. Confidential Shredding Services is the vendor used for shredding. S 18. Academic Works security controls are operated by Amazon Web Services (AWS). S 19. Access to system limited to Scholarship Manager( Administrator) & Committee members. Exiting committee members are made inactive in the system by administrator. S 9
VISIO Shape Legend Process Document Connector Start Annotation Off page Reference Tree Connector Colors represent segregation of duties 10
Control Objectives Legend C Completeness: no unrecorded assets, liabilities, transactions, or events or undisclosed items A Accuracy: recorded transactions are input and processed correctly in appropriate period V Validity: transactions and updates are authorized by appropriate personnel and supported by valid source documents R Real: asset or liability exists at a given date, or an event actually took place during the period S Access Restricted: ability to record or modify information is restricted to appropriate personnel