COSO 2013: Getting Internal Control Under Control

Transcription

COSO 2013:Getting Internal ControlUnder ControlNovember 22, 2017

November 22, 20172COSO 2013Inter

November 22, 20173The Agenda COSO 2013 in a Nutshell How COSO 2013 Can Create Assurance,and Why This is a Good Thing How to Make Your Case that COSO 2013is Either Working in Your Organization, orThat Things Need to ChangeInter

November 22, 20174COSO 2013

November 22, 20175The Definition COSO 2013 IC definition:Internal control is a process, effected by an entity’sboard of directors, management, and otherpersonnel, designed to provide reasonableassurance regarding the achievement of objectivesrelating to operations, reporting, and compliance.

November 22, 20176The Five Components

November 22, 2017The Seventeen Principles7

November 22, 2017Present and Functioning8

November 22, 20179What is Internal Control, Really? COSO 2013 IC definition:Internal control is a process, effected by an entity’sboard of directors, management, and otherpersonnel, designed to provide reasonableassurance regarding the achievement of objectivesrelating to operations, reporting, and compliance.

November 22, 201710What is Internal Control, Really? COSO 2013 IC definition:Internal control is a process, effected by an entity’sboard of directors, management, and otherpersonnel, designed to provide reasonableassurance regarding the achievement of objectivesrelating to operations, reporting, and compliance.

November 22, 201711Assurance

November 22, 201712Is it Present?

November 22, 201713Does it Function?

November 22, 201714Making Your CaseInter

November 22, 201715Control Environment1. Demonstrate commitment to integrity andethical values2. Exercise oversight responsibility3. Establish structures, reporting lines, authoritiesand responsibilities4. Demonstrate commitment to a competentworkforce5. Hold people accountable

November 22, 201716Risk Assessment6.7.8.9.Specify appropriate objectivesIdentify and analyze risksEvaluate fraud risksIdentify and analyze changes that couldsignificantly affect internal controls

November 22, 201717Control Activities10.Select and develop control activities thatmitigate risks11.Select and develop technology controls12.Deploy control activities through policiesand procedures

November 22, 201718Information & Communication13.Use relevant, quality information tosupport the internal control function14.Communicate internal control informationinternally15.Communicate internal control informationexternally

November 22, 201719Monitoring16.Perform ongoing and/or periodicevaluations of internal controls17.Communicate internal controldeficiencies

November 22, 201720Self Evaluation Thinking about Internal Control outside ofthe IC Process Does the Report Reflect Reality?

COSO 2013 in a Nutshell How COSO 2013 Can Create Assurance, and Why This is a Good Thing How to Make Your Case that COSO 2013 is Either Working in Your Organization, or That Things Need to Change Inter. November 22, 2017 4 COSO 2013. November 22, 2017 5 The Definition