Internal Control & Review

32
1 Management control systems in corporate governance 4

description

Internal audit

Transcript of Internal Control & Review

Page 1: Internal Control & Review

1

Management control systems in corporate governance

4

Page 2: Internal Control & Review

2

Objectives/learning outcomes

Define and explain internal management control [2] Explain and explore the importance of internal

control and risk management in CG [3] Describe objectives of ICS [2] Identify, explain and evaluate the CG and executive

management roles in risk management [3] Identify and assess the importance of the

components of ICS Explore and evaluate the effectiveness of ICS [3] Describe and assess the need to report on ICS to

shareholders [3]

Page 3: Internal Control & Review

3

Internal management control

Control means: Ensuring what the organisation intends to

happen happens Happens in the way it's supposed to happen Happens when it's supposed to happen.

Internal control – magt action to manage risks & ensure objectives are met

Page 4: Internal Control & Review

4

Internal control system - definition

Comprises

Control Environmen

t

Control Procedures

Magt style, attitudes to ICs

Necessary for ICs

Policies & procedures to achieve objectives

Corporate culture and values of employees

Page 5: Internal Control & Review

5

Objectives of internal control systems

Objectives

Achievement of objectives

Safeguard assets

Compliance with laws & regulations

Reliable financial & magt reports

Risk management

Page 6: Internal Control & Review

6

ICS and risk management ICS should be designed to counter the risks Factors to consider in setting up an ICS:

The nature and extent of risks facing the company Acceptable and unacceptable risks The likelihood of the risks concerned materialising Company’s ability to reduce the incidence and

impact on the business of risks that do materialise The costs and benefits of operating particular

controls

Page 7: Internal Control & Review

7

Key features of a ‘sound’ system of internal controls - Turnbull

Characteristics

Quick response to environmental change

Immediate reporting of weaknesses

Embedded in operations & systems

Page 8: Internal Control & Review

8

Components of an internal control system – COSO model

Elements

Information & communication e.g. of risks, weaknesses

Control policies & procedures – specific actions (ACCAMAPS)

Control environment

Risk assessment – controllable & uncontrollable risks

Monitoring of controls – e.g. by internal audit

Page 9: Internal Control & Review

9

Control procedures (ACCAMAPS)

Authorisation (e.g. of purchases and stock issues) Computer controls (e.g. passwords, range checks) Comparison controls (e.g. stock records with actual

stocks) Accounting recons (e.g. bank & supplier recon) Maintain TB and control accounts (e.g. debtors’

control) Accuracy or arithmetic controls (e.g. re-

computation) Physical controls (e.g. limiting access to computers) Segregation of duties (between ordering, custody of

stock and authorising payments)

Page 10: Internal Control & Review

10

Executive magt role in ICS

Responsibility

Board

Snr executive magt

Business unit heads

Employees

Role

Ensure adequacy & effectiveness of ICS

Set IC policy; monitor ICS

Establish specific IC policies & procedures

Operate & adhere to ICs

ICS are everyone’s business

Page 11: Internal Control & Review

11

Limitations/weaknesses of internal control systems

Human error Magt overriding controls Collusion to circumvent controls Failure to deal with new & un-usual

situations Internal control systems can only

provide reasonable (not absolute) assurance

Page 12: Internal Control & Review

12

Reporting on internal controls to shareholders

Board should review effectiveness of internal controls & report to shareholders

Benefits of reporting: Increased shareholder satisfaction Audit committee forced to consider their

work seriously Company open to additional scrutiny Fulfills CG requirements

Page 13: Internal Control & Review

13

Conclusion – ICS

Main points Importance of control environment to

ICS effectiveness ICS should be ‘sound’ Effective ICS reduces risk, improves

CG ICS is not ‘fool proof’, has weaknesses ICS are everyone’s business

Page 14: Internal Control & Review

14

Internal audit (IA) in corporate governance

5

Page 15: Internal Control & Review

15

Objectives/learning outcomes

Describe the function and importance of internal audit [1] Explain, and discuss the importance of, auditor

independence in all client audit situations (including internal audit) [3]

Explain, and assess the nature and sources of risks, to auditor independence [3].

Explain and evaluate the importance of compliance and the role of the internal audit committee in internal control [3]

Explain and explore the importance and characteristics of, the audit committee’s relationship with external auditors [2]

Describe and analyse the work of the internal audit committee in overseeing the internal audit function [2]

Page 16: Internal Control & Review

16

Internal audit - definition

Independent appraisal activity within an entity as a service to it

Control over other controls Improves CG by strengthening

internal control

Page 17: Internal Control & Review

17

Types of audits

Transaction audits – audit of individual transactions

Systems audits – audit of internal controls within a system e.g.: Design of internal controls Operation of internal controls

Risk-based audits – concentrates audit effort (staff & time) on risky areas of business

Page 18: Internal Control & Review

18

• Audit of accounting systems

• Operational audits – adequacy & effectiveness

• Value for money audits – on 3 Es

• Management audits – on magt and org structure

• Social & environmental audits

Internal auditing – a range of areas

Page 19: Internal Control & Review

19

Organisational structure of internal audit

Separate dept in large entities

Responsibility of specific individuals in smaller entities

May be outsourced to accounting firms

Head IA

Manager IT auditsManager Financial

auditsManager Forensic

audits

Page 20: Internal Control & Review

20

Need for IA function Contingent factors that determine the

need for an internal audit function include: Complexity of operations Size of organisation Internal control systems problems Cost-benefit issues Unexplained or unacceptable events Changes in structures, processes, and

systems

Page 21: Internal Control & Review

21

Functions/roles of IA

Reviewing accounting & internal control systems

Risk identification Carry out value for money audits (VFM) Reviewing compliance with laws Carry out special investigations e.g. into

suspected frauds Examine financial & operating

information

Page 22: Internal Control & Review

22

Intimidation

Advocacy Self review

Familiarity

Threats

Self interest

Threats to independence of IA

Page 23: Internal Control & Review

23

Sources of threats to independence of IA Conflicts of interest resulting in lack of

impartiality and bias (self interest) Reporting to executive management

(intimidation) Interference in determining the scope of

their work, performing the audit, and communicating results (intimidation, familiarity)

Assessing specific operations for which they may have responsibility (self review/interest)

Page 24: Internal Control & Review

24

• Professional proficiency

• Scope of work

• Performance of work (planning, supervision, review)

• Independence

• Authority

• Effective Management of dept

Factors to consider in measuring or improving effectiveness of IA Dept

Page 25: Internal Control & Review

25

INTERNAL EXTERNAL

Appointed by & reports to

Appointed by directors

Shareholders, via AGM

Responsible for

Internal controls mainly

Both internal and external factors

Required by Companies articles

Statute

Scope of work

Limited to Directors/ magtment instruction

Unlimited, determined by auditor

Internal v External Audit

Page 26: Internal Control & Review

26

Internal audit reporting IA report has no prescribed

format Contents may include:

Objectives of audit work Summary of process undertaken Audit opinion Recommendations (should be

practical, cost-effective & reduce risk to tolerable level)

Page 27: Internal Control & Review

27

Internal Audit Committee

• Sub-committee of board of directors

• To comprise at least 3 NEDs, one with financial knowledge

• Must have written terms of reference

• Must be provided with sufficient resources

Page 28: Internal Control & Review

28

The Role of Audit Committee

Review financial & management reports & systems

Liaise with external auditors Review of internal audit Review of internal control Review of risk management Review results of one-off

investigations

Page 29: Internal Control & Review

29

Audit committee & internal audit

Ensure recommendations are actioned

Monitor & assess effectiveness

Appoint/dismiss IA head

Check efficiency of IA e.g. plan Vs actual costs

Role in overseeing IA function

Review annual work plan

Help preserve independence

Ensure accountable to audit committee

Page 30: Internal Control & Review

30

Audit committee & external auditors

Assess possible other services

Review scope of audit work

Carry out post completion review (errors, adjustments)

Role in overseeing external auditors

Recommend appointment

Help preserve independence

Agree contract terms & perks

Page 31: Internal Control & Review

31

Audit committee & internal control

Review auditors reports on ICs Review

statement on ICs

Review magt reports on ICs

Role in IC delegated by board

Review internal financial controls

Review risk magt systems

Page 32: Internal Control & Review

32

Conclusion – internal audit Main points

Role of internal audit Enhancing effectiveness of IA Importance of auditor independence Threats to auditor independence Role of audit committee in IA Role of audit committee in ICS Role of audit committee in external

audit