utsouthwestern风险与内部控制_第1页
utsouthwestern风险与内部控制_第2页
utsouthwestern风险与内部控制_第3页
utsouthwestern风险与内部控制_第4页
utsouthwestern风险与内部控制_第5页
已阅读5页,还剩55页未读 继续免费阅读

下载本文档

版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领

文档简介

P,he,raining,ost,An Educational Computer Based Training Program,T,T,CBT,Effectively Controlling Risk,UT SouthwesternGeneral Compliance Training,Effectively Controlling Risk,In order to achieve the goals of providing the highest levels of medical education, biomedical research and patient care, UT Southwestern must have effective internal controls. There needs to be an appropriate balance between controls and risks is necessary to provide reasonable assurance that the medical centers operations will be effective,efficient and in compliance with laws and regulations.,Effectively Controlling Risk,What is the purpose of this training?Why is it necessary?What is internal control?What are the components of internal control?Where can I learn more?,Effectively Controlling RiskWhat is the purpose of this training?,Provide employees with the training and tools to evaluate internal control at the activity, process and department levels. Two tools available to achieve this goal are the:Risk and Control Self-Assessment GuidelineRisk Assessment and Control Activities Worksheet,Effectively Controlling RiskWhy is it necessary?,Highly publicized frauds at other public institutions have caused concerns among UT System and component administrators.What was determined to bethe problem? WEAK INTERNAL CONTROLS,Effectively Controlling Risk What is internal control?,:,Internal control is a process, effected by UT Southwesterns governing board, administration, faculty, and staff, designed to provide reasonable assurance regarding the achievement of objectives in the following categories:Effectiveness and efficiency of operations,Reliability of financial reporting, andCompliance with applicable laws and regulations.,Effectively Controlling RiskInternal Control Process,5 ComponentsEstablish Control EnvironmentPerform Risk AssessmentImplement Control ActivitiesCommunicate InformationMonitor Performance,Internal Control ProcessEstablish Control Environment,The control environment is the control consciousness of an organization.The control environment includes the integrity and ethical values of its people, their competence, and the way they do business.,Internal Control ProcessElements of the Control Environment,Standards of Conduct Guide Regents Rules, Business Procedures Memorandums, etc.Department standards of conductHuman resources policies and proceduresDepartment policies and proceduresConflicts of interest-disclosure formsEthics GuideHonestyZero tolerance,Internal Control Process Perform Risk Assessment,Risk assessment is the identification and analysis of risks associated with achieving your objectives.Risk assessment helps to form a basis for determining how to manage identified risks.,Internal Control Process What is our risk?,With internal controls, RISK is . . .The possibility that the organization will NOT:Achieve its goalsOperate effectively and efficientlyProtect itself from lossProvide reliable financial data (reports)Comply with applicable laws, regulations, policies, and procedures,RISK,Internal Control ProcessPerform Risk Assessment,Components and Departments must define their goals and objectives in relation to their:Mission,Operations,Financial reporting,Compliance, andSignificant activities or processes.,Then, they must identify and analyze potential risks by asking certain questions:What could go wrong?What must go right?What is the significance of our risks?What is the likelihood of occurrence?,Internal Control ProcessPerform Risk Assessment,Questions employees should consider:What business are you in?Who are your customers?What do they need and want?What does that say about what you are trying to accomplish?How will you know you have been successful?,Internal Control ProcessPerform Risk Assessment,A risk is ANYTHING that could jeopardize the achievement of a goal or objective.For each goal or objective, identify your risks.Be comprehensive, by considering external and internal factors.,Internal Control ProcessPerform Risk Assessment,For each identified risk, estimate the potential significance (cost, safety, institutional image) and likelihood of occurrence.Focus on the major risks, and determine how those risks should be managed and minimized to acceptable levels.,Internal Control ProcessImplement Control Activities,Control activities are the policies and procedures that help ensure that actions identified as necessary to manage risks are carried out properly and in a timely manner.Control activities should be proactive, value-added, and cost effective.,Internal Control ProcessImplement Control Activities,Properly balancing risks and controls makes good business sense!,Internal Control ProcessImplement Control Activities,Examples of Control Activities at UT Southwestern:Approvals, authorizations, and verificationsHaving written policies and procedures and limits to authorityReconciliationsExplanations of the difference between two sets of data AND taking corrective action,Internal Control ProcessImplement Control Activities,Examples of Control Activities at UT Southwestern, continued. . . Reviews of performance For components, departments, and individual employees Security of AssetsLimiting access, keeping records, and making periodic counts to compare to our records,Internal Control ProcessImplement Control Activities,Examples of Control Activities at UT Southwestern, continued . . .Segregation of DutiesMake sure no one person can initiate, approve, record and reconcile transactionsControls over Information SystemsGeneral controls over access and development, as well as specific controls within applications,Internal Control ProcessCommunicate Information,Reliable and relevant information, from both internal and external sources, must be identified and communicated to employees.Information should be processed and communicated in a timely manner and in a form that is usable.,Internal Control ProcessCommunicate Information,What information is relevant and reliable?Job responsibilitiesGoals and objectivesInformation to assess risksPolicies and proceduresLaws and regulationsPerformance indicatorsCustomer feedbackPerformance evaluations,Internal Control ProcessCommunicate Information,How should we communicate?Methods include one-on-one, staff meetings, telephone calls, e-mail, memos, and reportsONLY communicate information to those who need itCommunicate up, down, and across the organization,Internal Control ProcessMonitor Performance,Monitoring involves evaluating internal control performance over time to determine whether controls are:adequately designed,properly executed, andeffective.How do we know?,Internal Control ProcessMonitor Performance,Internal controls are adequately designed and properly executed if all five internal control components are present and functioning as designed: Control environment Risk assessment Control activities Information and communication Monitoring,Internal Control ProcessMonitor Performance,Internal controls are effective if administrators believe:They understand the extent to which the objectives of their operations are being achieved,Financial statements are reliable, andLaws and regulations are complied with.,Internal Control ProcessMonitor Performance,Monitoring Activities Include:Managerial and supervisory monitoringSelf-assessmentsInternal audits,Effectively Controlling RiskSelf-Assessment,What is a self-assessment?A self-assessment is a “self-audit” of a departments internal control components performed on a periodic basis.,Effectively Controlling RiskPerforming a Self-Assessment,Steps in performing a self-assessment include:Evaluating your strengths and deficienciesTesting the strengthsDocumenting testsDisclosing weaknessesDeveloping an action plan to correct problemsSummarizing and documenting results,Effectively Controlling RiskPerforming a Self-Assessment,What is a weakness?A material weakness is an internal control shortcoming which increases the risk ofirregularities, illegal acts, errors, waste, ineffectiveness, or conflicts of interestabove a REASONABLE level.,Effectively Controlling RiskSummary,What does all this have to do with me?Internal control effectiveness is primarily determined by the knowledge and commitment of ALL UT Southwestern employees.By knowing the internal control policies and procedures and complying with all laws and regulations, YOU can help the medical center achieve its goals.This training is an internal control activity!,Effectively Controlling RiskWhere can I learn more?,UT Southwestern Internal Audit Department.Ask your supervisor or a UT Southwestern Institutional Compliance Committee member.,Test Your Knowledge,Following are several questions to test your knowledge of the information presented. Answer all questions correctly to receive credit for the training.,Question #1,The major problem which caused recent frauds at other Texas institutions was weak internal controls?,TRUE,FALSE,Sorry, the correct answer is .,Highly publicized frauds at other public institutions have caused concerns among UT System and component administrators.What was determined to bethe problem? WEAK INTERNAL CONTROLS,Question #1,The major problem which caused recent frauds at other Texas institutions was weak internal controls?,TRUE,FALSE,Question #2,Which of the following are components of the internal control process?,ESTABLISHING A CONTROLENVIRONMENT,PERFORMING A RISKASSESSMENT,BOTH OF THE ABOVE,Sorry, the correct answer is .,5 ComponentsEstablish Control EnvironmentPerform Risk AssessmentImplement Control ActivitiesCommunicate InformationMonitor Performance,Question #2,Which of the following are components of the internal control process?,ESTABLISHING A CONTROLENVIRONMENT,PERFORMING A RISKASSESSMENT,BOTH OF THE ABOVE,Question #3,With internal controls, RISK includes the possibility that our organization will NOT achieve its goals and protect itself from loss?,TRUE,FALSE,Sorry, the correct answer is .,With internal controls, RISK is . . .The possibility that the organization will NOT:Achieve its goalsOperate effectively and efficientlyProtect itself from lossProvide reliable financial data (reports)Comply with applicable laws, regulations, policies, and procedures,RISK,Question #3,With internal controls, RISK includes the possibility that our organization will NOT achieve its goals and protect itself from loss?,TRUE,FALSE,Question #4,Control Activities should be . . .,RESTRICTIONS ON ANEMPLOYEES AUTHORITY,PROACTIVE, VALUE-ADDED,AND COST-EFFECTIVE,BOTH OF THE ABOVE,Control activities are the policies and procedures that help ensure that actions identified as necessary to manage risks are carried out properly and in a timely manner.Control activities should be proactive, value-added, and cost effective.,Sorry, the correct answer is ,Question #4,Control Activities should be . . .,RESTRICTIONS ON ANEMPLOYEES AUTHORITY,PROACTIVE, VALUE-ADDED,AND COST-EFFECTIVE,BOTH OF THE ABOVE,Question #5,Some examples of control activities at UT Southwestern include reconciliations and having written policies and procedures?,TRUE,FALSE,The correct answer is .,Examples of Control Activities at UT Southwestern:Approvals, authorizations, and verificationsHaving written policies and procedures and limits to authorityReconciliationsExplanations of the difference between two sets of data AND taking corrective action,Question #5,Some examples of control activities at UT Southwestern include reconciliations and having written policies and procedures?,TRUE,FALSE,Question #6,Which of the following is relevant information for UT Southwestern employees?,JOB RESPONSIBILITIES,POLICIES AND PROCEDURES,CUSTOMER FEEDBACK,ALL OF THE ABOVE,Sorry, the correct answer is .,What information is relevant and reliable?Job responsibilitiesGoals and objectivesInformation to assess risksPolicies and proceduresLaws and regulationsPerformance indicatorsCustomer fe

温馨提示

  • 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
  • 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
  • 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
  • 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
  • 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
  • 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
  • 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。

评论

0/150

提交评论