IC Training Material_第1页
IC Training Material_第2页
IC Training Material_第3页
IC Training Material_第4页
IC Training Material_第5页
已阅读5页,还剩49页未读, 继续免费阅读

下载本文档

版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领

文档简介

1、1A General Understanding of Internal ControlJanuary 19, 20092Session Agenda Introduction and Documentation Requirement Flowchart Risk and Control Matrix Internal Controls Concepts The COSO Internal Control Integrated Framework Q&A3Introduction and documentation requirement4SAMVO is required to f

2、ile an internal control report with the relevant gaming licensing boards and authorities. Managements responsibilities to establish and maintain adequate internal controls and procedures for financial reporting Managements conclusion on the effectiveness of these internal controls at year end (Decem

3、ber 31) The COSO (Committee of Sponsoring Organizations of Treadway Commission) framework used by management as criteria for evaluation control effectiveness The companys public accountant (Ernst & Young) has attested to and reported on managements evaluationIntroduction5 What should be document

4、ed?Key component of the processes and transaction flows are documented so that the project team can understand how transactions are initiated, authorized, recorded, processed and reportedEnable the project team to source the risk of errors and omissions and access the controls that mitigate these ri

5、sksDocument processes relevant to financial reportingSignificant errors, omissions or fraud that might occur within the processesUnderstanding of the flow provides the foundation for an evaluation of internal control over financial reportingOverviewWhat should be documented?6Process Maps (Flowcharts

6、)7Flowchart DefinitionA flowchart is a format which visually presents the flow of an operation/process using symbols (e.g. forms, information and process), in order to recognize how important transactions are initiated, recorded, authorized, processed and reported. 8Flowchart ExplainednShapes are th

7、e basic building blocks of a flowchartnIt is important to understand that the shapes have meaningnA shape includes the symbol and the text inside the symbolnLines and arrows indicate the direction of the action9Flowchart Key SymbolsExample Symbols to use during your process mapping SystemPage connec

8、torManual operationStart/End ProcessDocumentDataDecision pointProcess/Action10Flowchart Symbols - DescriptionsActivity / Process Description: Indicates that an activity or task is being performed. Write the specific activity, such as “Check for Errors” or “Prepare Form” inside the symbol.Decision Bo

9、x: When this symbol appears, the task sequence flows to the right if the decision is “no” or down if the decision is “yes”. As with other symbols, write a brief description inside the symbol, keeping it as simple as possible. Often a simple “Approved?” or “OK?” is sufficient.Hardcopy Document: Repre

10、sents the generation of a physical document. Write the specific document name inside the symbol.11Flowchart Symbols - DescriptionsDirection of Flow: Flow arrows show the order in which activities are completed. The arrows depict the process flow.Page Connector: Shows the continuation of the flow fro

11、m page to page of a Process Map. When you reach the bottom of a page, draw a flowchart connector symbol and connect it to the last item on the chart. Label the inside of the symbol with a letter beginning with “A” and the page number on which the process continues. The label A/2 for example, instruc

12、ts the reader to look for Point A on page 2.12Identify Risk Points in FlowchartSources of risk to identify:lAs information enters the processfrom external entitiesfrom other processeslAs information moves from person to personlAs information moves between departmentslAs information moves between com

13、puter systemslManual/ System interfaces13Identify Controls in FlowchartExample questions to ask: lWhat can go wrong & how is it prevented? lDoes the control technique work?lDoes it efficiently achieve the objective?lShould part of the control be automated e.g. through system check & exceptio

14、n reporting?lInformation Technology Controls!14Benefits of using Flowchart as Documentation1) Provide a common language lEasy-to-follow supporting documentationlSupply the project team with a frame of reference for discussing control strengthens and weaknesses2) Reduce Project Risk lFlowchart reduce

15、 the risk that the project team misses key risks and controls during the evaluation process3) Facilitates analysis lProcess maps bring risks and controls related to timing and sequence of events to the surface15Benefits of using Flowchart as Documentation (Cont)4) Document evidence lFlowcharts give

16、the process owners a visual tool to use in asserting that their process continues to work correctly5) Support auditors walkthroughlFlowcharts facilitate the walk through process by providing a visual depiction of all important aspects of each critical process6) Enable focus of changelFlowcharts prov

17、ide a way to identify process changes during subsequent reviews7) Provide operating benefitlProvides a framework for tying together the activities of people who work on a process so team members understand the other roles and responsibilities within the process16Flowcharts - Types1) Illustrative (To

18、p-down Flowcharts) Level 12) Transactional (Process Flowcharts) Level 23) Process Inter-functional Flowcharts Level 317Flowcharts Types (Cont)1) Illustrative (Top-down Flowcharts) Level 1Capture entire process in several stepsGood method to create condensed overview of processNot sufficient to sourc

19、e risks and control points18Flowcharts Types (Cont)2) Transactional (Process Flowcharts) Level 2second level of detailsseries of activities and decisionsinputs, activities, interfaces, and outputs19Flowcharts Types (Cont)3) Process Inter-functional Flowcharts Level 3represents processes that occur b

20、etween various functions, information flow between functions, and how each function receives or provides information to anotherhelp identify redundant process steps20Process MappingControlReferenceExample: Process Inter-functional Flowcharts Level 321Flowchart Mapping Key ThoughtsKeep in mind as you

21、 map your process:1.Focus on Controls not just the transaction flow2.Focus on evidence e.g., signoff, etc3.Use Titles (not names)4.Enough Detail for an auditor to “walkthrough”5.Use standard symbol and template6.Utilize Notes to provide detail explanations for transaction flows22Key Areas to include

22、 Are the following sections included in your documentation?1.Process Description (scope)2.Key Personnel Involved3.Key Systems4.Key Data Forms / Reports5.Controls (tied to the RCM)23Risk and Control Matrix (RCM)24Control Evaluation How evaluated for SOX 404 For financial accounts to be accurate, spec

23、ific financial reporting assertions must be achieved For the assertions to be achieved, the associated risks must be mitigated For risks to be mitigated, controls need to be both designed and operating effectively25Risk and Control Matrix DefinitionA Risk and Control Matrix depicts a companys object

24、ives, the risks to achieving those objectives, and the controls in place to mitigate those risksA Risk and Control Matrix pull together salient points and effectively link the controls underlying a process to the assertion risks they mitigateLinkage of risk and control is important:1. Enable effecti

25、ve assessment of controls design effectiveness2. Enable “filtering” population of controls down to the few vital that matters26Elements of Risk and Control MatrixnRisksnDescription of control activitynRelated sub-process or transaction typenReference to documentation (link to flowchart)nFrequencynPr

26、eventive or detective controlnAutomated or manual controlnRelated COSO elementnDesign effective or notnControl Owner (Who performs)nPrimary or Secondary27Control description in RCM Points for attentionControl Description (6Ws)What is the risk being controlled?What is the control activity?Why is the

27、activity performed?Who (or what system) performs the control activity?When (how often) is the activity performed?What kind of reports are generated?Avoid writing several controls as 1 controlsDistort testing statisticsDivert control evaluation focusAvoid too much description on process activities ra

28、ther than controls28A control is a policy, a procedure, a system to mitigate risk!Execution of ControlConsidering how control is executed, you can classify as: Control by human effort (Manual Control) Control by (computer) system-base (System Control)The relationship of Control Strength can be gener

29、ally described as below.ButIn general, it is expensive to establish strong control.You should establish control necessary for your companys situation, considering cost-benefit effect and effect when risk would occur. What is control?SystemDetectiveControlSystemPreventiveControlManualPreventiveContro

30、lManualDetectiveControlDesirabilityReliabilitySystemDetectiveControlSystemPreventiveControlManualPreventiveControlManualDetectiveControlDesirabilityReliability29 Control Classification 1 Control TypeControl TypeNature of ControlSummary of ControlReliabilityManualControls executed dependently by one

31、or more individuals.SystemControls executed dependently by programmed applications or IT systems. DesirabilityPreventiveControls designed to prevent errors or omissions from occurring. Generally positioned at the source of risk within the process. DetectiveControls which are designed to detect and c

32、orrect an error, fraud, or an omission within a timely manner prior to completion of a stated objective.KeyControlPrimaryControls that are especially critical to the mitigation of risk and to the ultimate achievement of one or more financial reporting assertions SecondarySecondary controls are impor

33、tant to the mitigation of risk and compensating other controls. Detective controls to detect and correct errors which was not covered by preventive and primary controls, or controls which verify that primary controls are functioning, are often designed to be secondary controls. FrequenciesMultiple d

34、aily (By transaction) Daily Weekly Monthly Quarterly biannually AnnuallyMultiple daily is the case when control is operated a few times a day. If control is operated as needed but once a month, it is identified as “monthly.” Identify based on frequency.30Control Classification 2 linkage to COSO Comp

35、onentsCOSO ComponentsSummaryControl Activity Policies and procedures that help ensure management directives are carried out.Concrete activities to mitigate risks throughout entire organization and all functions Control activity is mainly used at process level control.Monitoring The processes that as

36、sess the quality of internal control performance over timeRoutine monitoring activities, independent evaluation (e.g. internal audit)System to report to management and correct deficiency in internal control Control EnvironmentPolicies and procedures that help ensure management directives are carried

37、out.Concrete activities to mitigate risks throughout entire organization and all functions Risk AssessmentIdentification and analysis of relevant risks to the achievement of its objectives, forming a basis for determining how the risks should be managed.Structure to respond to change of environment,

38、 new risks Information and CommunicationIdentification, capture and exchange of external and internal information in a form and time frame that enable people to carry out their responsibilitiesEffective communication up, down and across the organization.Maintenance of information system For evaluati

39、on and documentation of internal control, the COSO Internal Control Integrated Framework of U.S is one of the widely used standard. In order to carry out documentation in accordance with internal control framework, it is necessary to identify which COSO internal control component is related to each

40、recognized control. 31Pertain to the maintenance of records in reasonable detail that fairly and accurately reflect the transactions and dispositions of the assets of the company;Provide reasonable assurance that transactions are recorded as necessary to permit preparation of financial statements in

41、 accordance with generally accepted accounting principles, and transactions are being made only in accordance with authorizations of management and director(s) of the company; and,Provide reasonable assurance regarding prevention or timely detection of unauthorized acquisition, usage or disposition

42、of assets that could have a material effect on the financial statements.What are the Financial Reporting Assertions?“Presentation and Disclosure”“Proper Classification”“Substantiation of Balances”“Authorization”“Completeness and Accuracy”“Evaluation of Balances”“Access to Assets” “Rights and Obligat

43、ions” Internal Control over Financial Reporting is a process effected by the management and other personnel of the company, to provides reasonable assurance regarding the reliability of financial reporting and preparation of financial statements for external purpose in accordance with generally acce

44、pted accounting principles. It includes the policies and procedures that:32In critical financial reporting elements:“Completeness and Accuracy” Risk Risk of some transactions during a specific period is not recorded or reported or not processed accurately in a timely basis in accordance with managem

45、ents policy. “Rights and Obligations” Risk Risk that the assets and liabilities reported on the balance sheet does not truly reflect the rights and obligations of the organization as of the balance sheet date.“Authorization” Risk Risk of recognizing unauthorized economic events and executing unautho

46、rized transactions.“Access to Assets” Risk Risk of lack of safeguard for assets or risk of access to assets without management authorization.“Substantiation of Balances” Risk Risk of being unable to verify or prove that reported information is reconciled with reality.“Evaluation of Balances” RiskRis

47、k that assets, liabilities, revenues and expenses are not recorded at an appropriate amount in accordance with generally accepted accounting principles.“Proper Classification” RiskRisk that in the Financial Statement accounts and disclosures, the assets, liabilities, revenues and expenses are not pr

48、operly classified in conformity with generally accepted accounting principles.“Presentation and Disclosure” RiskRisk that accounts, disclosures and other items in the financial statements are not properly described and classified. As well as not properly presented in conformity with generally accept

49、ed accounting principles. What risks exist in Financial Reporting?33Antifraud controls Fraudulent financial reportingInappropriate earnings management or “cooking the books” e.g. improper revenue recognition, intentional overstatement of assets, understatement of liabilities, etc.Misappropriation of

50、 assetsEmbezzlement and theft that could materially affect the financial statementsExpenditures and liabilities incurred for improper or illegal purposesBribery and influence payments that can result in reputation lossFraudulently obtained revenue and assets/ or avoidance of costs and expensesScams

51、and tax fraud that can result in reputation lossAntifraud control are those controls related to the prevention, deterrence and detection of fraud. They are the controls that are intended to mitigate the risk of fraudulent actions that could have an impact on financial reporting. Examples included:34

52、予防的予防的発見的発見的Example of Control( (Manual Control) )Example of manual ControlPrepare Code or Manual, Communicate about it to employees and Train them Trace the result of entry to evidenced documents after every data entry Keep evidence of completion (e.g. seal of completion) every time after completio

53、n of work. Segregate clearly uncompleted work and completed work.Put serial number on each transaction to check the missing numbered transaction and verify the transactions.Authorize transaction by proper authorized personnel before execution of contract or transaction.Keep issued or obtained docume

54、nts properly at the execution of contract or transaction. Trace to related information including documents, vouchersProper administrator or third party regularly conducts field audit or traces administrative documentsSeparately from regular operations, send documents to dealers to verify consistency

55、 in data.(Inquiry, operations for substantiation of balance)Appropriate supervisor reviews and approves the content of job done by person in charge.Experienced employees review the content of jobs( (e.g. analysis of data change)Risk evaluation and development of action plan is conducted regularly or

56、 as needed.Segregation of duties for related operations. Rotate employees periodicallyPreventiveDetective35予防的予防的発見的発見的Example of control (System Control)DetectivePreventiveExample of System ControlTrace transaction data to preset master file dataTrace data to other transaction dataTrace itemized da

57、ta to aggregated data( (sum check) )Check items for abnormal data or missing information at the time of input ( (Check of data entry) )Add to issued documents information for preservation and control (addressee, confidentiality, storage duration)Output of forms which can check accuracy of data (e.g.

58、 checklist of input data)Send alarm before transactions or operations lose its timelinessOutput of slips about information which processes exception or deviations from expectation is abnormal( (alarm for abnormal data) )Only authorized person can access to information stored in system ( (Access Cont

59、rol) )Maintain history of processed information in the system ( (backup) )Maintenance of information system (hard and soft) or its review is conducted regularly or timely. Only the personnel with approval authority can perform pre-approved registration of transaction information and operations canno

60、t proceed to next step without its approval ( (electronic approval) )Process operations such as calculation, aggregation or classification, automatically by information system, not through manual operation. PreventiveDetective36Evaluation of Internal Control Design EffectivenessIs control designed to be operated b

温馨提示

  • 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
  • 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
  • 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
  • 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
  • 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
  • 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
  • 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。

评论

0/150

提交评论