Moving Internal Audit Back into Balance

Size: px
Start display at page:

Download "Moving Internal Audit Back into Balance"

Transcription

1 Moving Internal Audit Back into Balance A Post-Sarbanes-Oxley Survey Fourth Edition

2 Table of Contents Introduction... 1 Executive Summary... 2 Overview of Rebalancing Initiatives... 4 Current Status of Sarbanes-Oxley Compliance... 4 State of Rebalancing... 5 Making Progress... 6 Primary Benefits... 7 Key Activities by Organizations Seeking to Rebalance... 8 Addressing IT Audits... 9 Sarbanes-Oxley Compliance Strategies as Part of Rebalancing Efforts Addressing IT Audits Primary Ownership Impact of SEC S Interpretive Guidance and PCAOB AS Rebalancing Efforts Changes in Efforts/Hours Quantity and Scope of Processes and Controls Impact of Rebalancing Initiatives Internal Audit Responsibilities in Sarbanes-Oxley Compliance Allocating Internal Audit Efforts for COSO Internal Control Objectives Rebalancing the Skills Gap Internal Audit Staffing, Hours and Budget Allocations Impact of SEC s and PCAOB s Guidance Outsourcing Sarbanes-Oxley Compliance Activities External Quality Assessments Changing Landscape Demands Ongoing Rebalancing Methodology survey Demographics About Protiviti INC... 34

3 Introduction Unless commitment is made, there are only promises and hopes... but no plans. Peter Drucker Without question, much has changed in the seven years since the U.S. Sarbanes-Oxley Act became law. We conducted our first Internal Audit Rebalancing study in 2005 to assess how organizations were relying on their internal audit departments for Sarbanes-Oxley compliance-related activities while seeking to rebalance these functions to also address more traditional internal auditing responsibilities. (For the purposes of this survey, rebalancing is defined as the process of moving activities away from Sarbanes-Oxley compliance to a broader coverage of business objectives as defined by the COSO framework.) In subsequent years of the study, we noted how the landscape continued to change, with organizations becoming more familiar with the Sarbanes-Oxley compliance process and thus streamlining their efforts. Perhaps most notably, in 2007, a potential paradigm shift was introduced with the U.S. Securities and Exchange Commission s (SEC) interpretive guidance to management on implementing Section 404 of Sarbanes-Oxley, along with a new standard, Auditing Standard No. 5 (AS5), from the Public Company Accounting Oversight Board (PCAOB). Both of these were intended, in part, to alleviate some of the time and cost burdens associated with the compliance process. The results of our 2008 Rebalancing survey suggested that both the SEC s interpretive guidance and PCAOB AS5 were having their intended effect. In our 2009 Rebalancing survey, one of the more interesting trends emerging from our analysis of the data is an apparent drop among organizations in activities and perceived benefits relating to these regulatory pronouncements. Both were designed to ease compliance burdens among companies and facilitate a more efficient and streamlined attestation by external auditors of internal control over financial reporting. There could be several reasons behind this trend. Certainly there is a heightened regulatory environment in the wake of the many well-publicized bank and corporate failures worldwide. There also could be a general aura of compliance conservatism because of the global financial crisis that is impacting virtually every organization around the world. It also could be that the rate of changes being implemented by companies has slowed since it has now been two years since the SEC s and PCAOB s announcements. We explore these and other themes further throughout this report. This year s survey, which was modified slightly from previous years, consisted of questions grouped into two divisions: Rebalancing Strategy and Internal Audit Organization and Focus. More than 600 respondents a majority of whom are chief audit executives, audit directors and audit managers took part by completing the survey in person or online. We would like to extend our appreciation to all of the chief audit executives and internal audit professionals who participated in our 2009 Rebalancing survey. We also want to recognize The Institute of Internal Auditors for its continued leadership and guidance for the profession. We are very appreciative of the continued positive feedback on this study that we receive from chief executive officers, chief financial officers, board members and other executives, as well as internal audit leaders. We are certain our 2009 report will again be of interest to any organization assessing how to balance ongoing Sarbanes-Oxley compliance with traditional internal auditing responsibilities. Protiviti June 2009 Moving Internal Audit Back into Balance 1

4 Executive Summary Impact of the SEC s Interpretive Guidance and PCAOB Auditing Standard No. 5 While approximately half of survey participants reported the SEC s guidance and PCAOB AS5 are enabling them to increase rebalancing efforts significantly or moderately, the response was down from Hours for external audit, internal company and other external resources have decreased, but not as much as reported last year. A majority of respondents reported decreases in the number of key controls and total controls documented and tested. One of the more notable trends in this year s results is an apparent lessening in the positive effects of the SEC s interpretive guidance and PCAOB AS5, with a general across-the-board decrease in their respective impact. This could be a result of many factors, including the global economic crisis, heightened regulatory environment, continued significant reliance on manual processes and controls, growing conservatism among companies in order to maintain the status quo, or a belief among organizations that they already have implemented changes in response to these regulatory rulings and are not planning further adjustments. Primary Benefits of Rebalancing Internal audit being able to perform more traditional audits and more appropriate coverage of risk rank as the top benefits. Reduced Section 404 and 302 compliance costs is the third-highest ranked benefit, yet the response was down 7 percent from After 2005 (the first year of the survey), there is a clear trend showing more traditional audits to be a top benefit of rebalancing, which is understandable given the interest in shifting internal audit away from a Sarbanes-Oxley-only emphasis. Such a shift enables organizations to achieve more appropriate coverage of their risks. Sarbanes-Oxley Compliance: Current Status Most respondents are in or beyond their fourth year of Sarbanes-Oxley compliance, generally mirroring the compliance timeline since the act went into effect for large accelerated filers. These results are similar to those from the 2008 Rebalancing study. Of note, there was a year-over-year increase in the number of organizations identifying themselves as in either the first year or pre-first year of compliance. This is the result of the pending deadline for smaller companies to comply with the auditor attestation requirement of Section 404 (beginning for fiscal years ending on or after December 15, 2009). Rebalancing Status: One Year Ago Versus Today Nearly three out of four organizations have achieved or moved beyond rebalancing, or have rebalancing underway or in the planning stages. This is very consistent with results from the 2008 and 2007 Rebalancing surveys. These results clearly show that even with the ongoing requirements for Sarbanes-Oxley compliance, most companies view rebalancing the internal audit department as a key priority to ensure the long-term effectiveness of the internal audit function in helping management and the board identify, manage, mitigate and monitor key risks. 2 Moving Internal Audit Back into Balance

5 Strategies: Current Versus Planned As in 2008, reducing the number of key controls and using a risk-based testing approach were the top two strategies, but percentages for both were down year-over-year. Reduction in number of key controls leads the strategies that organizations are currently employing, followed by use of a risk-based testing approach, greater reliance on internal auditors by external auditors and reduction in total population of controls. However, when comparing this year s results to those from 2008, there was a consistent decrease in the percentage of responses for each category. This may be a signal that some companies believe they have completed making adjustments in response to the SEC s and PCAOB s pronouncements, or be further indication of an apparent hesitancy among organizations to fully implement practices based on the SEC s interpretive guidance and PCAOB AS5. It also could mean that some organizations believe they have applied a top-down, risk-based approach, consistent with the SEC s guidance. Based on our experience, we believe many organizations with this point of view continue to rely heavily on manual financial reporting processes and controls. Activities as Part of Rebalancing Risk-based testing and rescoping workloads are the top rebalancing activities. Implement risk-based testing, added to the Rebalancing survey this year, ranked as the top activity, with two out of three organizations including this as part of their rebalancing efforts. Rescope workloads has ranked first or second in the past three studies. Also of note, just one in five respondents cited add additional resources this year, continuing a downward trend from 2005 (62 percent). Moving Internal Audit Back into Balance 3

6 Overview of Rebalancing Initiatives Current Status of Sarbanes-Oxley Compliance: Most in their Fourth Year or Beyond A majority of respondents are in or beyond their fourth year of Sarbanes-Oxley compliance, generally mirroring the compliance timeline since the act went into effect for large accelerated filers. Similar to the results from the 2008 Rebalancing study, among all respondents, a majority are at least in their fourth year of Sarbanes-Oxley compliance, and 40 percent are beyond the fourth year. Of note, there was a yearover-year increase in the number of organizations identifying themselves as in either the first year or pre-first year of compliance (22 percent this year versus 16 percent in 2008). This could be the result of the pending deadline that smaller companies or nonaccelerated filers, as defined by the SEC must comply with the auditor attestation requirement of Section 404 beginning in fiscal years ending on or after December 15, This group of companies includes those that underwent initial public offerings in Year of Sarbanes-Oxley Compliance 4 Beyond 4th year of compliance 2 4th year of compliance 16% Pre-1st year of compliance 11% 3rd year of compliance 6% 1st year of compliance 7% 2nd year of compliance 4 Moving Internal Audit Back into Balance

7 State of Rebalancing Most organizations recognize the importance of rebalancing their internal audit departments to focus more on traditional responsibilities. Respondents were asked the following two questions: One year ago, how would you have described your organization s efforts to rebalance internal audit priorities away from Sarbanes-Oxley compliance projects? Today, how would you describe your organization s efforts to rebalance internal audit priorities away from Sarbanes-Oxley compliance projects? Nearly three out of four organizations today 73 percent have achieved or moved beyond rebalancing, or have rebalancing underway or in the planning stages. This is very consistent with results from the 2008 and 2007 Rebalancing surveys. These results clearly show that even with the ongoing requirements for Sarbanes-Oxley compliance, most companies view rebalancing the internal audit department as a key priority to ensure the long-term effectiveness of the internal audit function in helping management and the board identify, manage, mitigate and monitor key risks. State of Rebalancing 4 One year ago Today 3 32% 27% 2 21% 1 12% 15% 15% 13% 17% 13% 6% 8% 7% 7% 7% Beyond rebalancing Rebalancing achieved Rebalancing underway Rebalancing planned Haven t started planning, but intend to rebalance Doesn t apply not yet under first year of S-O Act compliance Not intending to rebalance Moving Internal Audit Back into Balance 5

8 Overview of Rebalancing Initiatives (cont.) Making Progress Most organizations consistently report moderate progress in their rebalancing efforts. Over the past three years of the Rebalancing study, results on the progress of rebalancing efforts have been very consistent, with 71 percent to 73 percent of respondents reporting their rebalancing projects are making significant or moderate progress. Results related to expectations also have been consistent, with a growing number of respondents noting progress has met or exceeded them. These trends show that once an organization initiates rebalancing efforts, it is likely to achieve significant or moderate progress toward its goals in other words, there is a strong chance of success. Rebalancing Progress Made So Far: Three-Year Comparison (Base: Rebalancing Underway) % 56% 53% % 17% 18% 27% 26% 26% Significant Moderate Minimal 1% 3% None Expectations of Rebalancing Progress to Date: Three-Year Comparison (Base: Rebalancing Underway) % 54% % % 36% 2 24% 1 11% 11% 1 5% 5% 5% Much less than expected Somewhat less than expected About the same as expected Somewhat more than expected 1% 1% 1% Much more than expected 6 Moving Internal Audit Back into Balance

9 Primary Benefits Consistent with previous years results, the top two benefits of rebalancing are having internal audit perform more traditional audits and achieving more appropriate coverage of risk. The top responses for 2009 internal audit being able to perform more traditional audits and more appropriate coverage of risk have been relatively consistent over the four years of the Rebalancing study. However, one notable change this year was a drop in the benefit of having reduced Section 404 and 302 compliance costs. While this may be unexpected to some given that the SEC s interpretive guidance and PCAOB AS5 were intended to facilitate a reduction in efforts and costs for reporting companies, some organizations were of the view that they were already applying a top-down, risk-based approach when the 2007 guidance was issued, while other companies may have the view that they have completed their implementation of the new guidance and standard. Again, significant reliance on manual financial reporting processes and controls can limit the potential benefits from implementing the SEC interpretive guidance and PCAOB AS5. Primary Benefit of Rebalancing: Four-Year Comparison (Base: All respondents except those not engaged in or planning rebalancing) Internal audit able to perform more traditional (operational and nonfinancial reporting-related) audits 18% 36% 35% 47% More appropriate coverage of risk 15% 25% 25% 29% Reduced Section 404 and 302 compliance costs 12% 15% 19% 18% 2005 Increased reliance by external auditors on work of internal audit (PCAOB AS5) Increased effectiveness and efficiency of operations Increased objectivity of the internal audit department Other No benefit 1% 3% 3% 5% 2% 1% 3% 3% 3% 2% 9% 7% 8% 8% 4% 7% 12% 13% 12% 5% 1 15% 2 25% 3 35% 4 45% 5 Moving Internal Audit Back into Balance 7

10 Overview of Rebalancing Initiatives (cont.) Key Activities by Organizations Seeking to Rebalance Risk-based testing and rescoping workloads stand out as the top rebalancing activities. Implement risk-based testing was added to the Rebalancing survey this year and ranked as the top activity, with two out of three organizations including it as part of their rebalancing efforts. Rescope workloads has ranked first or second in the past three studies. Both application of (PCAOB) AS5 by the company s external auditors and increase testing and reliance on monitoring controls were cited by half of respondents. Of note, the latter activity coincides with the recent release of the new COSO Monitoring Guidance, which further indicates the higher priority being placed on the monitoring of controls. Notable four-year trends in the findings for this category include the following: Nearly two out of three respondents 62 percent cited add additional resources in 2005, but just 22 percent did so in 2009, continuing a four-year decline for this rebalancing activity. Reallocate existing resources received approximately half of the response in 2005 and 2007, but just 32 percent in Rescope workload has increased over the past four years as a rebalancing activity, from 41 percent in 2005 to 65 percent this year. Key Rebalancing Activities (Base: All respondents except those not engaged in or planning rebalancing) Implement risk-based testing*** 66% Rescope workload 65% Increase testing and reliance on monitoring controls*** Application of AS5 (vs. AS2) by the company s external auditors* 5 49% Conduct an enterprisewide risk assessment Automating more controls (moving more controls from manual to automated)*** Increased ownership by process owners** 39% 41% 45% Utilize more self-assessment and self-audits by process owners and executives Reallocate existing resources 34% 32% Company s effort in applying the SEC s interpretive guidance* Add additional resources Use third parties to complete certain work to assist in the rebalancing effort Create a separate risk and controls function to focus primarily on Section % 22% 21% 18% * Not applicable in 2005 and 2007 surveys ** Not included in 2005 survey *** Not included in previous surveys Other 2% Moving Internal Audit Back into Balance

11 Addressing IT Audits Respondents specifically were asked how IT audits not related to Sarbanes-Oxley compliance were being addressed as part of their rebalancing efforts. Consistent with last year, the most common response was no change. However, collectively over half of all respondents reported they are increasing IT audits when it comes to rebalancing efforts. This year s results show that technology remains an important part of the rebalancing process. Now that organizations have more experience with Sarbanes-Oxley, IT audit efforts might be shifting toward maintaining compliance efforts while also working to lower compliance costs and improve the balance of audit coverage for other areas of risk. Protiviti s 2009 Internal Audit Capabilities and Needs Survey supports the continued importance of technology as a critical enabler of virtually all business processes and helping organizations achieve objectives and address risks. 1 In this study, technology skills hold a prominent place in the need to improve category of general technical knowledge. The recent changes to The IIA Standards also corroborate the importance of technology audits. For example, IIA Standard 2110.A2 now includes the word must when providing guidance to internal audit in its role related to assessing IT governance. As organizations adopt the new and revised Standards as of January 1, 2009, we will monitor whether IT audits continue to hold an important role in rebalancing efforts, and it is quite possible the survey results for this category will change next year. IT (IT audits not related to Sarbanes-Oxley) Assessed as Part of Rebalancing: Four-Year Comparison (Base: All respondents except those not engaged in or planning rebalancing) % 41% 37% 31% % 25% 26% 26% % 12% 13% 15% 15% Increase(d) It audits >25% Increase(d) It audits 10-25% Increase(d) It audits <1 no change 4% 5% 4% decrease(d) It audits 3% 1 For more information, read Protiviti s 2009 Internal Audit Capabilities and Needs Survey, available at Moving Internal Audit Back into Balance 9

12 Overview of Rebalancing Initiatives (cont.) Sarbanes-Oxley Compliance Strategies as Part of Rebalancing Efforts As in 2008, reducing the number of key controls and using a risk-based testing approach were the top two strategies, but percentages for both were down year-over-year. Similar to last year, reduction in number of key controls leads the strategies organizations are currently employing, followed by use of a risk-based testing approach, greater reliance on internal auditors by external auditors and reduction in total population of controls. For each of these strategies, there also was a significant increase compared to the percentage of respondents who reported in 2008 that they were planning to employ it in the coming year. This shows that, in one sense, the SEC s interpretive guidance and PCAOB AS5 are having their intended effect. However, when comparing the current results with the prior year, there was a consistent decrease in the percentage of responses for each category in In last year s survey, for example, 47 percent of respondents reported they were currently reducing the number of key controls, versus 33 percent this year. For use of a risk-based testing approach, the 2008 currently response was 45 percent versus 30 percent this year, and for reduction in total population of controls the numbers were 43 percent versus 26 percent. These findings could be a further indication that some organizations have already taken steps to reduce their control populations, and thus no longer see a need to incorporate these specific strategies as part of their rebalancing efforts. However, it is also possible that some organizations have an apparent hesitancy in 2009 to implement practices based on the SEC s interpretive guidance as well as PCAOB AS5. This could be attributed to a more conservative approach in order to preserve the status quo. Also of note, increase in number of automated controls leads the strategies organizations are planning to employ in 2009, followed by use of data mining and analytics to better understand process performance, reduction in manual controls, increase in number of monitoring controls and consolidation of redundant IT platforms and systems. These strategies are key because, for many organizations, they represent the last frontier for improving the cost-effectiveness of financial reporting controls, reducing financial reporting risks and streamlining Sarbanes-Oxley compliance. The notable increase in focus on these strategies indicates that some organizations understand their importance in this regard. 10 Moving Internal Audit Back into Balance

13 Strategies: Current vs. Planned reduction in number of key controls use of a risk-based testing approach* greater reliance on internal auditing by external auditors reduction in total population of controls tightening of overall scope centralization of common processes and functions Increase in testing within key risk areas reduction in number of in-scope locations** consolidation of redundant It platforms and systems Increase in number of monitoring controls accelerate timing of selected control tests** Increase in number of automated controls reduction in manual controls use of self-assessment techniques Improvement in quality and compression of time in business processes affecting financial reporting reduction of independent tests of controls use of data mining and analytics to increase understanding of process performance other** no specific strategies considered or employed** * Not included in 2007 survey ** Not included in 2007 and 2008 surveys don't know** 2% 2% 4% 4% 9% 1 11% 13% 14% 14% 12% 14% 14% 21% 18% 12% 16% 18% 11% 13% 18% 9% 11% 1 9% 15% 13% 15% 14% 14% 14% 13% 12% 14% 12% 18% 18% 14% 16% 16% 13% 13% 18% 19% 21% 2 23% 26% 25% 27% 3 33% currently Employing 2009 Planning to Employ 2009 Planning to Employ % 27% 29% 5% 1 15% 2 25% 3 35% Moving Internal Audit Back into Balance 11

14 Overview of Rebalancing Initiatives (cont.) Addressing IT Audits When asked what percentage of IT audits were related to Sarbanes-Oxley for each year of compliance, respondents reported that most IT auditing activity occurs in Years Two and Four. Organizations continue to express that these audits do not have a prominent role in the first year of Sarbanes-Oxley compliance, even though their importance increases significantly in Year One when compared to the precompliance period. As organizations become more experienced with Sarbanes-Oxley, they come to realize the important role IT plays in managing related risks and processes. More than 60 percent of respondents whose organizations are beyond Year Four reported that they spend at least 20 percent of their time on IT audits. This is consistent with the 2008 study. Over the years, organizations have acknowledged the benefits of automating internal controls: increased reliability, lower error rates, and less time and effort required to test compared to manual controls. The bottom line is that technology, when used appropriately, improves risk coverage and test results, leading to an improved internal control environment and effective compliance strategy. This is in line with the intention of the SEC s interpretive guidance and PCAOB AS5. As noted earlier (see page 9), changes this year to IIA Standard 2110.A2, which states that internal audit functions must assess IT governance, reinforce the importance of technology audits. In next year s Rebalancing survey, there may be notable changes in the results for this category. Percentage of IT Audits Related to Sarbanes-Oxley Compliance Beyond 4 th year of compliance 4 th year of compliance 3 rd year of compliance 2 nd year of compliance 1 st year of compliance Pre-1 st year of compliance 3% 4% 5% 4% 6% 5% 5% 4% 9% 9% 9% 9% 9% 9% 11% 1 13% 13% 12% 13% 13% 13% 17% 13% 17% 13% 13% 16% 23% 18% 21% 18% 18% 23% 26% 25% 29% % 35% Don t know None < % 20-49% 50-75% >75% 52% 12 Moving Internal Audit Back into Balance

15 Primary Ownership Internal audit owns the rebalancing process in most organizations. A review of Rebalancing survey results over the past three years shows that internal audit departments consistently have primary ownership of rebalancing activities in their organizations. This year, in fact, there was an even larger gap between internal audit and other business owners in the organization. Respondents also were asked to indicate, in terms of rebalancing efforts, the level of involvement of different groups and individuals in the organization. More than half reported that executive management, the audit committee, management and/or process owners, and the external auditor are involved to a significant or moderate extent. Primary Ownership for Rebalancing: Three-Year Comparison (Base: Beyond Rebalancing, Rebalancing Achieved, Underway, Planned and Intended) % 69% % Internal audit staff 7% 1 1 7% 5% Executive management 14% Management 6% 3% 9% 6% 8% Audit committee Other 12% 4% 5% 3% 3% 3% No one primary owner Don t know Moving Internal Audit Back into Balance 13

16 Impact of SEC s Interpretive Guidance and PCAOB AS5 Similar to results from the 2008 Rebalancing study, this year s response shows a continued positive impact as a result of PCAOB AS5 and the SEC s interpretive guidance for Section 404. However, across all sections in this category of the study, there is a noticeable decrease in the positive impact responses compared to These findings are interesting given that guidance from both organizations was intended to increase the emphasis on applying a top-down, risk-based approach and enable organizations to reduce the time and costs required for compliance. It also would be expected that rebalancing efforts would be sustained. Rebalancing Efforts Efforts have decreased, but less so than in While nearly 40 percent of respondents reported that the impact of the SEC s interpretive guidance is enabling them to increase rebalancing efforts significantly or moderately, the cumulative increase figures dropped from 60 percent in Similarly, while 56 percent of respondents last year said that, as a result of PCAOB AS5, they were increasing rebalancing activities significantly or moderately, the response dropped to 44 percent this year. Impact of SEC s Interpretive Guidance on Rebalancing: Two-Year Comparison % % 3 32% 37% 2 1 6% 14% Significantly increased rebalancing efforts Moderately increased rebalancing efforts No change 1% 3% Moderately decreased rebalancing efforts Impact of PCAOB AS5 (vs. AS2) on Rebalancing: Two-Year Comparison % 52% 42% % 14% Significantly increased rebalancing efforts Moderately increased rebalancing efforts No change 4% 4% Moderately decreased rebalancing efforts 14 Moving Internal Audit Back into Balance

17 Changes in Efforts/Hours Organizations are being more conservative in reducing hours and activities. A large percentage of respondents reported that as a result of the SEC s interpretive guidance and PCAOB AS5, external audit hours have decreased, as have the hours required of other external and internal resources. However, these charts do illustrate slight drops in the percentages of decrease in all three categories. For example, this year a combined 40 percent of respondents reported a decrease in external audit hours as a result of the SEC s guidance, whereas 50 percent reported such a decrease in Similar changes are evident in the other two categories. We will continue to monitor these trends and determine why these changes might be occurring. Changes in Efforts/Hours SEC s Interpretive Guidance SEC s Interpretive Guidance Change in External Audit Efforts (Hours) Between the Year in Effect and the Prior Year: Two-Year Comparison 6 55% 5 49% % % 18% 2 4% 6% Decreased >25% Decreased 10-25% Decreased <1 No change 5% 1% Increased Moving Internal Audit Back into Balance 15

18 Impact of SEC s Interpretive Guidance and PCAOB AS5 (cont.) SEC s Interpretive Guidance Change in Internal Company Efforts (Hours) Between the Year in Effect and the Prior Year: Two-Year Comparison 5 49% 4 44% % % 17% 17% 14% 11% 5% Decreased >25% Decreased 10-25% Decreased <1 No change Increased SEC s Interpretive Guidance Change in Use of External Resources (Hours) Between the Year in Effect and the Prior Year: Two-Year Comparison % 12% 8% 14% 1 1 Decreased >25% Decreased 10-25% Decreased <1 No change 4% 4% Increased 16 Moving Internal Audit Back into Balance

19 Are Companies Failing to Take Full Advantage of Revised Regulations? This year s findings that suggest a diminished positive impact of PCAOB AS5 and the SEC s interpretive guidance on Section 404 are worth further commentary. Both of these standards relaxed previously stringent guidelines for companies and external auditors with regard to establishing and attesting to internal control over financial reporting, as mandated by Section 404. Among the new guidance from each of these regulatory bodies were opportunities to rely more heavily on the work of others, such as the internal audit function. For example, as detailed in Protiviti s Guide to Internal Audit: Frequently Asked Questions About Developing an Effective Internal Audit Function: The PCAOB encourages greater use of the work of others in AS5 by requiring auditors to (1) understand the relevant activities of others and determine how the results of that work may affect his or her audit, and (2) evaluate whether and how to use their work to reduce audit testing. There is no reason why the external auditor should not do this, particularly if an effectively functioning internal audit function is in place. AS5 emphasizes the importance of assessing the competency and objectivity of the persons who the (external) auditor plans to use to determine the extent to which the (external) auditor may use their work. The higher degree of competence and objectivity, the greater use the (external) auditor may make of the work. The guidance included in AS5 applies the principles in AU 322 to focus the auditor s use of the work of others more specifically on altering the nature, timing and extent of the external auditor s work than otherwise would have been performed to test the operating effectiveness of controls as part of an integrated audit of the financial statements and internal control over financial reporting (ICFR). The basic premise of AS5 is that the external auditor may use work performed by, or receive assistance from, internal auditors, other company personnel (in addition to internal auditors) and third parties working under the direction of management or the audit committee that provides evidence about ICFR effectiveness. In assessing the results from this year s Rebalancing study, it is possible that some companies are being too conservative. There could be a variety of reasons at play to explain why, among them: If it isn t broken, don t fix it Without question, achieving Sarbanes-Oxley compliance was an engrossing and time-consuming process for most reporting companies. Many failed to plan properly or begin their compliance efforts early enough, resulting in organizational fire drills. It is possible that as a result of these trials and tribulations, some companies may have little appetite to rescope workloads or otherwise change processes that currently have them in compliance. This, of course, defeats the purpose of the SEC s guidance and AS5. We have also seen circumstances where managers responsible for Sarbanes-Oxley compliance are rewarded for compliance and not for cost-effectiveness; therefore, there is little incentive for them to alter the status quo. Law of diminishing returns We see many companies continuing to rely heavily on manual processes and controls. The SEC interpretive guidance and PCAOB AS5 can only take a company and its auditors so far until the process reaches the point where there is a declining impact from applying the SEC guidance and the PCAOB standard. There is a strong linkage between (a) improving process quality, time and cost performance, and (b) strengthening the effectiveness of ICFR. A simple, more streamlined and automated process is easier to control than a complex, cumbersome and manual one. Many companies continue to have opportunities to improve their process performance by building in (versus inspecting in) quality, reducing costs and compressing time within their processes and all of this while simultaneously reducing financial reporting risks and the costs of Sarbanes-Oxley compliance. Still figuring it out The difference between this year s results and last year s could be a reflection of companies still determining exactly where and how to achieve time and cost savings by rescoping workloads, reducing controls (key and total number) and increasing their rebalancing efforts. If this year s results indicate a swing back as companies, through trial and error, continue to define how to accomplish these objectives, we might expect higher positive impact responses in the 2010 Rebalancing survey. Moving Internal Audit Back into Balance 17

20 Impact of SEC s Interpretive Guidance and PCAOB AS5 (cont.) Changes in Efforts/Hours (cont.) Changes in Efforts/Hours PCAOB AS5 PCAOB AS5 Change in External Audit Efforts (Hours) Between the Year in Effect and the Prior Year: Two-Year Comparison 5 48% % 35% % 23% 25% 1 5% 8% Decreased >25% Decreased 10-25% Decreased <1 No change 3% 2% Increased Are Companies Failing to Take Full Advantage of Revised Regulations? (cont.) More small companies beginning the compliance process Beginning for fiscal years ending on or after December 15, 2009, nonaccelerated filers must comply with the auditor attestation requirement of Section 404. It is possible that this year s results reflect the fact that 7 percent of respondents are in the smaller public company category and would not be initiating rebalancing or other cost- and time-saving activities as of yet. Lack of knowledge Despite the SEC s and PCAOB s well-publicized announcements of their respective actions in 2007, it could be that many companies are not fully aware of these new guidelines and the potential opportunities to reduce time and costs involved with compliance. It could be expected in most cases that the external auditor would provide such knowledge; however, there could be some hesitancy among the auditors to leverage the revised guidelines, which could be attributable to custom and habit, the perceived reporting risks, or lack of support for certain AS5 principles such as the use of the work of others to ascertain the effectiveness of an organization s ICFR. Regardless of the reasons, the bottom line is that it behooves any company to acquire a full understanding of the SEC s interpretive guidance and PCAOB AS5, and to talk to its external auditor about activities internal audit and other departments can perform to assist in the ICFR attestation process. 18 Moving Internal Audit Back into Balance

21 PCAOB AS5 Change in Internal Company Efforts (Hours) Between the Year in Effect and the Prior Year: Two-Year Comparison % % 17% 17% 17% 19% 15% 15% 5% Decreased >25% Decreased 10-25% Decreased <1 No change Increased PCAOB AS5 Change in Use of External Resources (Hours) Between the Year in Effect and the Prior Year: Two-Year Comparison 7 67% 6 59% % 11% 1 14% 1 12% Decreased >25% Decreased 10-25% Decreased <1 No change 4% 4% Increased Moving Internal Audit Back into Balance 19

22 Impact of SEC s Interpretive Guidance and PCAOB AS5 (cont.) Quantity and Scope of Processes and Controls Decreases were reported, but not as much as in Respondents were asked about the impact of the SEC s guidance on numerous compliance-related processes and controls in the organization. They also were asked about the impact of the application of PCAOB AS5 by their external auditors on these same processes and controls. Similar to 2008, there are several positive trends, including a majority of respondents reporting decreases in key controls and total controls documented and tested. However, in most compliance-related process and control categories, the percentage of decreased responses dropped compared to 2008, while the increased response percentages rose year-over-year. Impact of SEC s Interpretive Guidance: Two-Year Comparison 2009 Decreased No Change Increased 2008 Decreased No Change Increased 2009 Number of key controls documented and tested 2008 Number of key controls documented and tested 6 35% 5% 75% 23% 2% 2009 Number of total controls documented and tested 2008 Number of total controls documented and tested 56% 39% 5% 68% 3 2% 2009 Number of key in-scope processes 2008 Number of key in-scope processes 45% 5 5% 58% 4 2% 2009 Number of total risks identified 2008 Number of total risks identified 44% 5 6% 58% 38% 4% 2009 Number of in-scope locations 2008 Number of in-scope locations 24% 7 6% 36% 61% 3% 2009 Use of a risk-based testing approach 2008 Use of a risk-based testing approach 15% 5 35% 18% 41% 41% 2009 Increased reliance on monitoring and/or entity-level controls 2008 Increased reliance on monitoring and/or entity-level controls 15% 56% 29% 17% 41% 42% 2009 Reliance on the work of others by the external auditor 2008 Reliance on the work of others by the external auditor 15% 47% 38% 14% 4 46% *2009 Increased reliance on self-assessment techniques 9% 75% 16% * Not included in 2008 survey Moving Internal Audit Back into Balance

23 The Importance of Understanding Risk The real key in Year Four and beyond of Sarbanes-Oxley compliance is how to keep things fresh and keep people vigilant. The recent financial collapse of so many companies shows that Sarbanes-Oxley was not the be all and end all to prevent loss of shareholder wealth. While companies were spending significant time and money ensuring things were recorded properly, they lost sight of the business risks that could bring down a company or an industry, wiping out billions of dollars in shareholder wealth in the process. The real key for investors (and employees) is around understanding risk: What are the risks? Are they independent or dependent? If they are dependent, what are they dependent on? How can they impact the company? What is the magnitude and likelihood? Are they being monitored properly? This is where internal audit can best assist the audit committee and management, and where we must strengthen our skill set as a profession hence the importance to rebalance resources. Without understanding risk, we can be auditing the wrong areas at the wrong time. The bottom line is that businesses face far greater risks today than Sarbanes-Oxley, and internal audit must not only rebalance but also retool to meet the current requirements. There is going to be a sea change in internal audit, and each of us has a choice be ready, willing and able, or become obsolete. Larry Harrington, Vice President, Internal Audit, Raytheon Company Impact of PCAOB AS5: Two-Year Comparison 2009 Decreased No Change Increased 2008 Decreased No Change Increased 2009 Number of key controls documented and tested 2008 Number of key controls documented and tested 55% 4 5% 64% 34% 2% 2009 Number of total controls documented and tested 2008 Number of total controls documented and tested 51% 44% 5% 6 39% 1% 2009 Number of total risks identified 2008 Number of total risks identified 39% 57% 4% 53% 46% 1% 2009 Number of key in-scope processes 2008 Number of key in-scope processes 42% 54% 4% 51% 48% 1% 2009 Number of in-scope locations 2008 Number of in-scope locations 24% 72% 4% 36% 62% 2% 2009 Use of a risk-based testing approach 2008 Use of a risk-based testing approach 12% 53% 35% 17% 44% 39% 2009 Increased reliance on monitoring and/or entity-level controls 2008 Increased reliance on monitoring and/or entity-level controls 12% 56% 32% 16% 45% 39% 2009 Reliance on the work of others by the external auditor 2008 Reliance on the work of others by the external auditor 1 48% 42% 15% 38% 47% *2009 Increased reliance on self-assessment techniques 7% 16% 77% * Not included in 2008 survey Moving Internal Audit Back into Balance 21

24 Impact of Rebalancing Initiatives Internal Audit Responsibilities in Sarbanes-Oxley Compliance Lead responsibility remains the most common role for internal audit. Findings regarding internal audit s role in Sarbanes-Oxley compliance have been consistent over the course of the Rebalancing studies. Of note, control design evaluation and testing of operational effectiveness decreases with each year of compliance, as do serving as members of compliance teams and steering committees, and developer of documentation. This could indicate that process owners are taking more direct ownership and responsibility for their processes and controls, as permitted under PCAOB AS5. (Please note that in the interest of simplicity, the chart below illustrates internal audit s primary roles in the first year of Sarbanes-Oxley compliance and beyond the fourth year of compliance. Percentages of responses for Years Two to Four consistently fall in the gap between these two trend lines.) Internal Audit Primary Roles 35% 3 25% 1st year of compliance Beyond 4th year of compliance 2 15% 1 5% Control design evaluation and testing of operational effectiveness Lead responsibility Member of compliance team/steering committee Developer of documentation Advisor to compliance team/steering committee Limited to testing of operational effectiveness Limited to control design evaluation None Don t know Other 22 Moving Internal Audit Back into Balance

25 Allocating Internal Audit Efforts for COSO Internal Control Objectives Consistent with the past three surveys, reliability of financial reporting remains the top COSO objective of focus for internal audit activities. The continued concentration on reliability of financial reporting is an interesting trend given that one in three respondents reported that they had achieved rebalancing or were beyond rebalancing. Remember, the purpose of rebalancing is to move internal audit activities away from Sarbanes-Oxley compliance toward broader coverage of the COSO framework. We would expect these rebalanced, or soon to be rebalanced, internal audit organizations to have established a better balance among all aspects of the COSO model by now. Organizations also should be aware that the internal audit landscape is changing. According to The IIA, financial reporting is only part of the internal control picture. As of January 1, 2009, the internal audit activity must evaluate and contribute to the improvement of governance, risk management and control processes using a systematic and disciplined approach (Standard 2100). Another Standard (2120.A1) notes that internal audit must evaluate risk exposures regarding reliability and integrity of financial and operational information; effectiveness and efficiency of operations; safeguarding of assets; and compliance with laws, regulations and contracts. Internal Audit Efforts Allocated Against COSO Objectives of Internal Control st year of compliance 2nd year of compliance 3rd year of compliance 4th year of compliance Beyond 4th year of compliance Effectiveness and efficiency of operations Reliability of financial reporting (including Sarbanes-Oxley compliance) Compliance with applicable laws and regulations Safeguarding of assets Note: Chart does not include Other and Don t know responses. Moving Internal Audit Back into Balance 23

26 Impact of Rebalancing Initiatives (cont.) Rebalancing the Skills Gap While down slightly from the 2008 results, a substantial percentage of this year s respondents perceive a significant or moderate skills gap among Sarbanes-Oxley-experienced auditors for other internal audit projects. Survey participants were asked to what extent there is a skills gap in their organizations among Sarbanes-Oxleyexperienced auditors for other internal audit projects, such as operational and nonfinancial reporting audits. Four out of 10 respondents perceive either a significant or moderate gap. This is consistent with Protiviti s Internal Audit Capabilities and Needs Survey. 2 Over the past three years, this study has identified traditional internal audit skills such as enterprise risk management and fraud risk management as competencies most in need of improvement. One troubling finding in this category is the 17 percent Don t know response. The revised IIA Standards (which became effective in January 2009) require the CAE to report any resource constraints to management and the board of directors. More definitive results in this category of the survey would be expected in light of this Standard, as there should not be a lack of knowledge about skills within the internal audit function. Also of note, 43 percent of respondents reported there is no skills gap in their departments with regard to Sarbanes-Oxley auditors performing other types of internal audit activities. Perceived or Real Skills Gap Sarbanes-Oxley-Experienced Auditors for Other Internal Audit Projects: Two-Year Comparison No skills gap 43% 49% Moderate skills gap 31% 36% Significant skills gap 9% 8% 2009 Don t know 7% 17% % 1 15% 2 25% 3 35% 4 45% 5 2 For more information, read Protiviti s 2009 Internal Audit Capabilities and Needs Survey, available at 24 Moving Internal Audit Back into Balance

27 Changes to The IIA Standards On January 1, 2009, The IIA formally released its revised International Professional Practices Framework, which includes revisions to the organization s International Standards for the Professional Practice of Internal Auditing. Key changes to the Standards include the following: Six new Standards have been added. In virtually all of the Standards, The IIA has revised its wording, replacing should with must. Additional requirements have been added to existing Standards. Interpretations have been added, incorporating components that previously were part of The IIA s practice advisories. With the change from should to must in most of the Standards and the addition of six new Standards, internal audit functions must take action to achieve or remain in compliance. For some, only minimal adjustments may be necessary. For others, however, there may be a need for substantial changes to their internal audit plans and structures. Without question, the internal audit rebalancing activities of organizations could be among the many areas affected by the new and revised Standards. Of particular note, IT governance and fraud risk management are key areas The IIA addresses in all-new Standards. We plan to monitor and report on key trends related to the Standards in next year s Rebalancing survey report. Internal Audit Staffing, Hours and Budget Allocations During Year One of Sarbanes-Oxley, most internal audit departments spend a majority of their time on compliancerelated activities. This year s results are consistent with previous Rebalancing surveys. After Year Two, there is a relative level of consistency in internal audit hours dedicated to Sarbanes-Oxley compliance, indicating that internal audit departments are planning or implementing rebalancing efforts to address more traditional responsibilities. Internal Audit Hours Dedicated to Each Year of Sarbanes-Oxley Compliance st year of compliance 2nd year of compliance 3rd year of compliance 4th year of compliance Beyond 4th year of compliance 2 1 > 75% 50-75% 20-49% 10-19% < 1 None Don t know Moving Internal Audit Back into Balance 25

28 Impact of Rebalancing Initiatives (cont.) Impact of SEC s and PCAOB s Guidance These regulations continue to have a positive impact on internal audit hours dedicated to Sarbanes-Oxley compliance. However, as indicated in many of the findings from this year s Rebalancing survey, respondents noted less of a decrease compared to what was reported in Internal Audit Hours, SEC s Interpretive Guidance: Two-Year Comparison % 42% 37% 42% % 3% 8% 3% Significantly increased Moderately increased No change Moderately decreased 11% 1 Significantly decreased Internal Audit Hours, PCAOB AS5: Two-Year Comparison % 38% 43% % 2 1 2% 1% 11% 11% Significantly increased Moderately increased No change Moderately decreased 1 7% Significantly decreased 26 Moving Internal Audit Back into Balance

About the Pulse of Internal Audit

About the Pulse of Internal Audit About the Pulse of Internal Audit Number of Responses The IIA s Audit Executive Center (AEC ) has gathered insight from leaders in the CAEs 460 profession through the annual Pulse of Internal Audit survey

More information

Review of Duke Energy Florida, LLC Internal Audit Function

Review of Duke Energy Florida, LLC Internal Audit Function Review of Duke Energy Florida, LLC Internal Audit Function MAY 2017 B Y A U T H O R I T Y O F The Florida Public Service Commission Office of Auditing and Performance Analysis Review of Duke Energy Florida,

More information

Sarbanes-Oxley Act of 2002 Can private businesses benefit from it?

Sarbanes-Oxley Act of 2002 Can private businesses benefit from it? Sarbanes-Oxley Act of 2002 Can private businesses benefit from it? As used in this document, Deloitte means Deloitte Tax LLP, which provides tax services; Deloitte & Touche LLP, which provides assurance

More information

FREQUENTLY ASKED QUESTIONS ABOUT INTERNAL CONTROL OVER FINANCIAL REPORTING

FREQUENTLY ASKED QUESTIONS ABOUT INTERNAL CONTROL OVER FINANCIAL REPORTING FREQUENTLY ASKED QUESTIONS ABOUT INTERNAL CONTROL OVER FINANCIAL REPORTING Nature and Timing of the Reporting Requirement When must registrants begin to report on internal control over financial reporting?

More information

Evaluating Internal Controls

Evaluating Internal Controls A SSURANCE AND A DVISORY BUSINESS S ERVICES Fourth in the Series!@# Evaluating Internal Controls Evaluating Overall Effectiveness, Identifying Matters for Improvement, and Ongoing Assessment of Controls

More information

The New 404 Balancing Act

The New 404 Balancing Act The New 404 Balancing Act Assessing Choices and Making the Right Decisions E Q S e c t i o n 1 Highlights of SEC Management Guidance On May 23, 2007, the Securities and Exchange Commission (SEC) unanimously

More information

STANDING ADVISORY GROUP MEETING

STANDING ADVISORY GROUP MEETING 1666 K Street, NW Washington, D.C. 20006 Telephone: (202) 207-9100 Facsimile: (202) 862-8430 www.pcaobus.org STANDING ADVISORY GROUP MEETING PRESENTATION AUDITING IMPLICATIONS OF COSO PROJECT TO UPDATE

More information

Increasing External Auditor Reliance

Increasing External Auditor Reliance Increasing External Auditor Reliance Guiding Internal Auditors to realize the benefits of raising the bar on External Auditor Reliance. SOX Software Made Simple Table of Contents 1 Introduction 3 Factors

More information

For the first time in the history of corporate financial reporting and. Management Reporting on Internal Control. Use of COSO 1992 in.

For the first time in the history of corporate financial reporting and. Management Reporting on Internal Control. Use of COSO 1992 in. Cover Story Use of COSO 1992 in Management Reporting on Internal Control THE COSO FRAMEWORK provides an integrated framework that identifies components and objectives of internal control. But does it set

More information

AUDITING. Auditing PAGE 1

AUDITING. Auditing PAGE 1 AUDITING Auditing 1. Professionalism The International Professional Practices Framework (IPPF) is the conceptual framework that organizes authoritative guidance promulgated by The Institute of Internal

More information

Advisory Services Governance, Risk & Compliance

Advisory Services Governance, Risk & Compliance Advisory Services Governance, Risk & Compliance Caribbean Association of Audit Committee Members Inc. 2010 Conference Caretakers of Integrity and Accountability: The Role of Internal Audit in Corporate

More information

Speech by SEC Staff: Remarks before the 2007 AICPA National Conference on Current SEC and PCAOB Developments

Speech by SEC Staff: Remarks before the 2007 AICPA National Conference on Current SEC and PCAOB Developments Home Previous Page Speech by SEC Staff: Remarks before the 2007 AICPA National Conference on Current SEC and PCAOB Developments by Josh Jones Professional Accounting Fellow, Office of the Chief Accountant

More information

COSO Updates and Expectations. IIA San Diego Chapter January 8, 2014

COSO Updates and Expectations. IIA San Diego Chapter January 8, 2014 COSO Updates and Expectations IIA San Diego Chapter January 8, 2014 Agenda Overview of 2013 Internal Control-Integrated Framework and Companion Guidance 2013 Framework General Enhancements by Component

More information

SARBANES-OXLEY COMPLIANCE MANAGING CHANGING EXPECTATIONS January 20, 2017

SARBANES-OXLEY COMPLIANCE MANAGING CHANGING EXPECTATIONS January 20, 2017 SARBANES-OXLEY COMPLIANCE MANAGING CHANGING EXPECTATIONS January 20, 2017 Pat Mitchell Managing Director Internal Audit, Risk, Business & Technology Consulting CHANGES IN THE COST AND SCOPE OF SOX COMPLIANCE

More information

Practice Guide. Developing the Internal Audit Strategic Plan

Practice Guide. Developing the Internal Audit Strategic Plan Practice Guide Developing the Internal Audit Strategic Plan JUly 2012 Table of Contents Executive Summary... 1 Introduction... 2 Strategic Plan Definition and Development... 2 Review of Strategic Plan...

More information

Beyond Compliance. Leveraging Internal Control to Build a Better Business: A Response to Sarbanes-Oxley Sections 302 and 404

Beyond Compliance. Leveraging Internal Control to Build a Better Business: A Response to Sarbanes-Oxley Sections 302 and 404 Beyond Compliance Leveraging Internal Control to Build a Better Business: A Response to Sarbanes-Oxley Sections 302 and 404 Note to Readers Regarding This First Edition April 2003: This document was published

More information

[RELEASE NOS ; ; FR-77; File No. S ]

[RELEASE NOS ; ; FR-77; File No. S ] SECURITIES AND EXCHANGE COMMISSION 17 CFR PART 241 [RELEASE NOS. 33-8810; 34-55929; FR-77; File No. S7-24-06] Commission Guidance Regarding Management s Report on Internal Control Over Financial Reporting

More information

In Control: Getting Familiar with the New COSO Guidelines. CSMFO Monterey, California February 18, 2015

In Control: Getting Familiar with the New COSO Guidelines. CSMFO Monterey, California February 18, 2015 In Control: Getting Familiar with the New COSO Guidelines CSMFO Monterey, California February 18, 2015 1 Background on COSO Part 1 2 Development of a comprehensive framework of internal control Internal

More information

FINANCIAL INSTITUTIONS AUDIT COMMITTEE GUIDE FOR FINANCIAL INSTITUTIONS

FINANCIAL INSTITUTIONS AUDIT COMMITTEE GUIDE FOR FINANCIAL INSTITUTIONS FINANCIAL INSTITUTIONS AUDIT COMMITTEE GUIDE FOR FINANCIAL INSTITUTIONS Dear clients and friends of the firm, Corporate governance is a significant area of focus for stakeholders of financial institutions.

More information

Catching Fraud During a Recession Through Superior Internal Controls. FICPA s 25 th Annual Accounting Show. J. Stephen Nouss September 29, 2010

Catching Fraud During a Recession Through Superior Internal Controls. FICPA s 25 th Annual Accounting Show. J. Stephen Nouss September 29, 2010 Catching Fraud During a Recession Through Superior Internal Controls FICPA s 25 th Annual Accounting Show J. Stephen Nouss September 29, 2010 1 Session Objectives Fraud Facts (2008 Association of Certified

More information

The Future of Internal Auditing:

The Future of Internal Auditing: Internal Audit The Future of Internal Auditing: Changing Internal Audit s Value Proposition October 12, 2010 Istanbul, Turkey Presented by: Naman Parekh Partner, Agenda Background of the 2012 Study Key

More information

REVISED CORPORATE GOVERNANCE PRINCIPLES FOR BANKS (CONSULTATION PAPER) ISSUED BY THE BASEL COMMITTEE ON BANKING SUPERVISION

REVISED CORPORATE GOVERNANCE PRINCIPLES FOR BANKS (CONSULTATION PAPER) ISSUED BY THE BASEL COMMITTEE ON BANKING SUPERVISION January 9, 2015 Secretariat of the Basel Committee on Banking Supervision Bank for International Settlements CH-4002 Basel, Switzerland Submitted via http://www.bis.org/bcbs/commentupload.htm REVISED CORPORATE

More information

See your auditor clearly. Transparency report: How we perform quality audit engagements

See your auditor clearly. Transparency report: How we perform quality audit engagements See your auditor clearly. Transparency report: How we perform quality audit engagements February 2014 Table of contents 1) A message from the CEO and Managing Partner Assurance 2 2) Quality control policies

More information

The Impact of the Sarbanes- Oxley Act and Similar Legislation: Lessons Learned and Considerations for the Future

The Impact of the Sarbanes- Oxley Act and Similar Legislation: Lessons Learned and Considerations for the Future The Impact of the Sarbanes- Oxley Act and Similar Legislation: Lessons Learned and Considerations for the Future Protiviti, together with the input of the Singapore Accountancy Commission, has developed

More information

Enterprise Risk Management: Developing a Model for Organizational Success. White Paper

Enterprise Risk Management: Developing a Model for Organizational Success. White Paper Enterprise Risk Management: Developing a Model for Organizational Success White Paper January 2009 Overview Less than a decade ago, Enterprise Risk Management (ERM) was an unfamiliar concept. Today, the

More information

Risk Based Internal Audit Plan

Risk Based Internal Audit Plan Risk Based Internal Audit Plan (Developing a Risk based IA Plan and updating the Audit Universe) C.A. Milan Mody WIRC of ICAI Presentation on 18th August 2018 1 2 Table of Contents Backdrop What is Risk?

More information

Re: PCAOB Rulemaking Docket Matter No. 37

Re: PCAOB Rulemaking Docket Matter No. 37 SanDisk Corporation 601 McCarthy Boulevard Milpitas, CA 95035-7932 Phone: 408-801-1000 Fax: 408-801-8657 December 9, 2011 Office of the Secretary PCAOB 1666 K Street, N.W. Washington, D.C. 20006-2803 Re:

More information

BUSINESS CPA EXAM REVIEW V 3.0. For Exams Scheduled After March 31, 2017

BUSINESS CPA EXAM REVIEW V 3.0. For Exams Scheduled After March 31, 2017 For Exams Scheduled After March 31, 2017 CPA EXAM REVIEW BUSINESS UPDATES AND ACADEMIC HELP Click on Community and Support at www.becker.com/cpa CUSTOMER SERVICE AND TECHNICAL SUPPORT Call 1-877-CPA-EXAM

More information

Internal Audit Best Practices for Community Banks. A CSH White Paper

Internal Audit Best Practices for Community Banks. A CSH White Paper Internal Audit Best Practices for Community Banks A CSH White Paper Internal audit is not an option; examiners expect your bank to have an effective internal audit program in place. However, in today s

More information

J. Gordon Seymour, Secretary Martin F. Baumann, Chief Auditor and Director of Professional Standards

J. Gordon Seymour, Secretary Martin F. Baumann, Chief Auditor and Director of Professional Standards Eaton Corporation 1111 Superior Avenue Cleveland, OH 44114-2584 tel: 216-523-4336 fax: 216-479-7336 Richard H. Fearon Vice Chairman and Chief Financial and Planning Officer December 13, 2011 Office of

More information

IPO Readiness. Sarbanes-Oxley Compliance & Other Considerations. Presented by:

IPO Readiness. Sarbanes-Oxley Compliance & Other Considerations. Presented by: IPO Readiness Sarbanes-Oxley Compliance & Other Considerations Presented by: IPO Readiness Enhanced Financial / Legal compliance SEC / Stock Exchange Compliance Entity Structure / Registration Filing Requirements

More information

Best Practices for Establishing a Cost-Effective Internal Audit Function. Article by Heidi Wier June 2016

Best Practices for Establishing a Cost-Effective Internal Audit Function. Article by Heidi Wier June 2016 Best Practices for Establishing a Cost-Effective Internal Audit Function Article by Heidi Wier June 2016 Best Practices for Establishing a COST-EFFECTIVE INTERNAL AUDIT FUNCTION BY HEIDI WIER The heightened

More information

Internal controls over financial reporting

Internal controls over financial reporting Internal controls over financial reporting Outlining a program that meets stakeholder expectations kpmg.com After showing why a company s internal controls over financial reporting (ICOFR) program may

More information

Guide to the Sarbanes-Oxley Act: Internal Control Reporting Requirements

Guide to the Sarbanes-Oxley Act: Internal Control Reporting Requirements Guide to the Sarbanes-Oxley Act: Internal Control Reporting Requirements Frequently Asked Questions Regarding Section 404 Updated to reflect the SEC's final rules Table of Contents Page No. Introduction

More information

Audit Committee Resource Guide

Audit Committee Resource Guide Audit Committee Resource Guide As used in this document, Deloitte means Deloitte LLP and its subsidiaries. Please see www.deloitte.com/us/about for a detailed description of the legal structure of Deloitte

More information

Should boards and CEOs care about COSO ERM 2017? By Tim J. Leech

Should boards and CEOs care about COSO ERM 2017? By Tim J. Leech Should boards and CEOs care about COSO ERM 2017? By Tim J. Leech Source: Conference Board December 2017 https://www.conferenceboard.org/blog/postdetail.cfm?post=6631 As globalization accelerates and the

More information

2013 COSO Internal Control Framework Update. September 5, 2013

2013 COSO Internal Control Framework Update. September 5, 2013 2013 COSO Internal Control Framework Update September 5, 2013 Agenda 2013 COSO IC Framework Topic Minutes The update process 5 What is not changing / What is changing 5 The 17 principles and changes to

More information

February 23, Office of the Secretary Public Company Accounting Oversight Board 1666 K Street, N.W. Washington, D.C.

February 23, Office of the Secretary Public Company Accounting Oversight Board 1666 K Street, N.W. Washington, D.C. McGladrey & Pullen LLP Third Floor 3600 American Blvd West Bloomington, MN 55431 O 952.835.9930 February 23, 2007 Office of the Secretary Public Company Accounting Oversight Board 1666 K Street, N.W. Washington,

More information

COSO Internal Control Integrated Framework Proposed Update

COSO Internal Control Integrated Framework Proposed Update COSO Internal Control Integrated Framework Proposed Update Presented by: Dustin Birashk September 20, 2012 1 DISCLOSURE STATEMENT The material appearing in this presentation is for informational purposes

More information

Viewpoint Transition to the cloud

Viewpoint Transition to the cloud Transition to the cloud Get answers to common public sector questions Table of contents What are the 2 considerations that preserve the benefits of moving to a cloud platform? How do cloud 2 services affect

More information

ABA Section of Business Law. Internal Control Reporting Under Section 404: An Update and Current Assessment. November 19, 2004

ABA Section of Business Law. Internal Control Reporting Under Section 404: An Update and Current Assessment. November 19, 2004 ABA Section of Business Law Internal Control Reporting Under Section 404: An Update and Current Assessment November 19, 2004 Thomas L. Riesenberg and Linda L. Griggs, Cochairs Table of Contents 2.1 Auditing

More information

The Value Proposition

The Value Proposition The Value Proposition Home Online Publications Journal of Accountancy Online Issues September 2005 The Value Proposition Page 1 of 7 SARBANES-OXLEY There s more to Sarbanes-Oxley compliance than meets

More information

Quality Management System Guidance. ISO 9001:2015 Clause-by-clause Interpretation

Quality Management System Guidance. ISO 9001:2015 Clause-by-clause Interpretation Quality Management System Guidance ISO 9001:2015 Clause-by-clause Interpretation Table of Contents 1 INTRODUCTION... 4 1.1 IMPLEMENTATION & DEVELOPMENT... 5 1.2 MANAGING THE CHANGE... 5 1.3 TOP MANAGEMENT

More information

i am pleased to transmit to you a summary of the Public Company Accounting

i am pleased to transmit to you a summary of the Public Company Accounting PCAOB Public Company Accounting Oversight Board May 27, 2005 1666 K Street, N.W. Washington, DC 20006 Telephone: (202) 207-9100 Facsimile: (202) 862-8430 ww.pcaobus.org By Hand Deliverv The Honorable Wiliam

More information

This charter defines the purpose, authority and responsibility of News Corporation s (the Company ) Corporate Audit Department.

This charter defines the purpose, authority and responsibility of News Corporation s (the Company ) Corporate Audit Department. CORPORATE AUDIT DEPARTMENT CHARTER PURPOSE This charter defines the purpose, authority and responsibility of News Corporation s (the Company ) Corporate Audit Department. The Institute of Internal Auditors

More information

Auditor General s Office REVIEW OF THE CITY SAP COMPETENCY CENTRE APPENDIX 1. June 1, 2010

Auditor General s Office REVIEW OF THE CITY SAP COMPETENCY CENTRE APPENDIX 1. June 1, 2010 APPENDIX 1 REVIEW OF THE CITY SAP COMPETENCY CENTRE June 1, 2010 Auditor General s Office Jeffrey Griffiths, C.A., C.F.E. Auditor General City of Toronto TABLE OF CONTENTS EXECUTIVE SUMMARY...1 BACKGROUND...2

More information

Agenda. Enterprise Risk Management Defined. The Intersection of Enterprise-wide Risk Management (ERM) and Business Continuity Management (BCM)

Agenda. Enterprise Risk Management Defined. The Intersection of Enterprise-wide Risk Management (ERM) and Business Continuity Management (BCM) The Intersection of Enterprise-wide Risk (ERM) and Business Continuity (BCM) Marc Dominus 2005 Protiviti Inc. EOE Agenda Terminology and Process Introductions ERM Process Overview BCM Process Overview

More information

The Social Marketer vs. the Social Enterprise Social media in financial institutions is in transition.

The Social Marketer vs. the Social Enterprise Social media in financial institutions is in transition. DECEMBER 2014 THE STATE OF Social Media in Financial Services The Social Marketer vs. the Social Enterprise Social media in financial institutions is in transition. Although social media is largely perceived

More information

) ) ) ) ) ) ) ) ) ) ) )

) ) ) ) ) ) ) ) ) ) ) ) 1666 K Street, N.W. Washington, DC 20006 Telephone: (202) 207-9100 Facsimile: (202) 862-8430 www.pcaobus.org PROPOSED AUDITING STANDARD RELATED TO COMMUNICATIONS WITH AUDIT COMMITTEES AND RELATED AMENDMENTS

More information

Response ed to

Response  ed to February 29, 2012 Office of the Secretary PCAOB 1666 K Street, N.W. Washington, D.C. 20006-2803 Response e-mailed to comments@pcaobus.org RE: PCAOB Rulemaking Docket Matter No. 030 Proposed Auditing Standard

More information

Audit of Entity Level Controls

Audit of Entity Level Controls Unclassified Internal Audit Services Branch Audit of Entity Level Controls February 2014 SP-606-03-14E You can download this publication by going online: http://www12.hrsdc.gc.ca This document is available

More information

CORPORATE GOVERNANCE THEORY, SCOPE AND IMPORTANCE

CORPORATE GOVERNANCE THEORY, SCOPE AND IMPORTANCE CORPORATE GOVERNANCE THEORY, SCOPE AND IMPORTANCE What is on the agenda Corporate Governance: In Theory Brief history The concept Principles Corporate Governance: In Practice Corporate governance elements

More information

B S R & Co. LLP. Reporting on Internal. Reporting An Overview. Sarbanes Oxley Act (SOX) 28 December 2013

B S R & Co. LLP. Reporting on Internal. Reporting An Overview. Sarbanes Oxley Act (SOX) 28 December 2013 B S R & Co. LLP Reporting on Internal Controls over Financial Reporting An Overview Sarbanes Oxley Act (SOX) 28 December 2013 Agenda Sarbanes Oxley Key Sections COSO Framework Management Approach to ICOFR

More information

Auditing Standard 16

Auditing Standard 16 Certified Sarbanes-Oxley Expert Official Prep Course Part K Sarbanes Oxley Compliance Professionals Association (SOXCPA) The largest association of Sarbanes Oxley Professionals in the world Auditing Standard

More information

State of Sustainable Business Survey October 2013

State of Sustainable Business Survey October 2013 State of Sustainable Business Survey 2013 October 2013 About BSR BSR works with its global network of more than 250 member companies to build a just and sustainable world. From its offices in Asia, Europe,

More information

SAS Teleconference

SAS Teleconference SAS 104-111 Teleconference Jan. 15, 2009 Craig Funkhouser, Crowe Horwath LLP craig.funkhouser@crowehorwath.com Ken Goldmann, J.H. Cohn kgoldmann@jhcohn.com 1 Today s Program Historical Background, Review

More information

) ) ) ) ) ) ) ) ) ) ) ) PCAOB Release No June 9, 2004

) ) ) ) ) ) ) ) ) ) ) ) PCAOB Release No June 9, 2004 1666 K Street, N.W. Washington, DC 20006 Telephone: (202 207-9100 Facsimile: (202 862-8430 www.pcaobus.org RULE REGARDING CERTAIN TERMS USED IN AUDITING AND RELATED PROFESSIONAL PRACTICE STANDARDS PCAOB

More information

The ADT Corporation. Board Governance Principles. December 2013

The ADT Corporation. Board Governance Principles. December 2013 The ADT Corporation Board Governance Principles December 2013 TABLE OF CONTENTS ADT VISION AND VALUES... 3 ADT Vision: Why We Exist and the Essence of Our Business... 3 ADT Values: What Matters Most at

More information

SOLUTION BRIEF RSA ARCHER AUDIT MANAGEMENT

SOLUTION BRIEF RSA ARCHER AUDIT MANAGEMENT RSA ARCHER AUDIT MANAGEMENT INTRODUCTION Internal audit departments are struggling to deliver strategic leadership, coordinated assurance and other services their stakeholders need, but this task isn t

More information

Enterprise Risk Management Handbook. June, 2010

Enterprise Risk Management Handbook. June, 2010 Enterprise Risk Management Handbook June, 2010 Table of Contents Overview... 4 What is Enterprise Risk Management?... 5 Why Undertake Enterprise Risk Management?... 6 Draft UW System ERM Vision, Mission,

More information

Assessment of the Design Effectiveness of Entity Level Controls. Office of the Chief Audit Executive

Assessment of the Design Effectiveness of Entity Level Controls. Office of the Chief Audit Executive Assessment of the Design Effectiveness of Entity Level Controls Office of the Chief Audit Executive February 2017 Cette publication est également disponible en français. This publication is available in

More information

1. Definition & Mission

1. Definition & Mission 1. Definition & Mission 1.1 Internal Auditing is an independent, objective assurance and consulting activity that is guided by a philosophy of adding value to improve the operations of. 1.2 Group Internal

More information

REPORT 2016/033 INTERNAL AUDIT DIVISION

REPORT 2016/033 INTERNAL AUDIT DIVISION INTERNAL AUDIT DIVISION REPORT 2016/033 Advisory engagement on the Statement on Internal Control project at the United Nations Joint Staff Pension Fund 25 April 2016 Assignment No. VS2015/800/01 CONTENTS

More information

Final Report Evaluation of Translation Bureau Programs Volume 2: Translation and Other Linguistic Services Program

Final Report Evaluation of Translation Bureau Programs Volume 2: Translation and Other Linguistic Services Program 2012-603 Evaluation of Translation Bureau Programs Office of Audit and Evaluation January 21, 2014 Table of Contents MAIN POINTS... i INTRODUCTION... 1 PROFILE... 1 Background... 1 Authority... 2 Roles

More information

CHARTER INTERNAL OVERSIGHT OFFICE (IOO)

CHARTER INTERNAL OVERSIGHT OFFICE (IOO) CHARTER INTERNAL OVERSIGHT OFFICE (IOO) VISION The vision of IOO is - To be a high-performing internal oversight activity that meets the expectations of WMO stakeholders and adheres to the professional

More information

CREATING A FRAUD RISK ASSESSMENT AND IMPLEMENTING A CONTINUOUS MONITORING PROGRAM

CREATING A FRAUD RISK ASSESSMENT AND IMPLEMENTING A CONTINUOUS MONITORING PROGRAM CREATING A FRAUD RISK ASSESSMENT AND IMPLEMENTING A CONTINUOUS MONITORING PROGRAM Compliance professionals around the world are struggling with how to do more with less. In order to provide effective assurance

More information

Implementation Guides

Implementation Guides Implementation Guides Implementation Guides assist internal auditors in applying the Definition of Internal Auditing, the Code of Ethics, and the Standards and promoting good practices. Implementation

More information

Report. Quality Assessment of Internal Audit at <Organisation> Draft Report / Final Report

Report. Quality Assessment of Internal Audit at <Organisation> Draft Report / Final Report Report Quality Assessment of Internal Audit at Draft Report / Final Report Quality Self-Assessment by Independent Validation by Table of Contents 1.

More information

Performance Management, Balanced Scorecards and Business Intelligence: Alignment for Business Results

Performance Management, Balanced Scorecards and Business Intelligence: Alignment for Business Results Performance Management, Balanced Scorecards and Business Intelligence: Alignment for Business Results Introduction The concept of performance management 1 is not a new one, though modern management constructs

More information

Present and functioning: Fine-tuning your ICFR using the COSO update

Present and functioning: Fine-tuning your ICFR using the COSO update Present and functioning: Fine-tuning your ICFR using the COSO update November 2014 With the COSO s 1992 Control Framework being superseded by the 2013 updated edition on December 15, 2014, now is the time

More information

AN ASSESSMENT OF THE COSTS AND BENEFITS ASSOCIATED WITH THE IMPLEMENTATION OF SARBANES OXLEY SECTION 404 IN A SOUTH AFRICAN CONTEXT

AN ASSESSMENT OF THE COSTS AND BENEFITS ASSOCIATED WITH THE IMPLEMENTATION OF SARBANES OXLEY SECTION 404 IN A SOUTH AFRICAN CONTEXT AN ASSESSMENT OF THE COSTS AND BENEFITS ASSOCIATED WITH THE IMPLEMENTATION OF SARBANES OXLEY SECTION 404 IN A SOUTH AFRICAN CONTEXT by ANDRE HORN A research report submitted in partial fulfilment of the

More information

Strengthening Your Enterprise Risk Management Process

Strengthening Your Enterprise Risk Management Process Strengthening Your Enterprise Risk Management Process Belinda Mumma, Senior Consultant, Enterprise Risk Management Services bmumma@sollievo.com (866) 605-5664 x3400 Discussion Topics Definition of Enterprise

More information

GoldSRD Audit 101 Table of Contents & Resource Listing

GoldSRD Audit 101 Table of Contents & Resource Listing Au GoldSRD Audit 101 Table of Contents & Resource Listing I. IIA Standards II. GTAG I (Example Copy of the Contents of the GTAG Series) III. Example Audit Workprogram IV. Audit Test Workpaper Example V.

More information

Continuous Auditing - A Delicate Chemistry

Continuous Auditing - A Delicate Chemistry Continuous Auditing - A Delicate Chemistry Continuous Auditing - A Delicate Chemistry - WeiserMazars LLP s Governance, Risk and Compliance (GRC) Group WeiserMazars LLP is an independent member firm of

More information

PHASE TWO FOLLOW-UP REPORT ON THE AUDIT OF CONTRACTS (2008)

PHASE TWO FOLLOW-UP REPORT ON THE AUDIT OF CONTRACTS (2008) PHASE TWO FOLLOW-UP REPORT ON THE AUDIT OF CONTRACTS (2008) PREPARED BY: Government Audit Services Branch Government of Yukon APPROVED BY: Audit Committee Table of Contents Page PREFACE 3 EXECUTIVE SUMMARY

More information

Implementation Tips for Revenue Recognition Standards. June 20, 2017

Implementation Tips for Revenue Recognition Standards. June 20, 2017 Implementation Tips for Revenue Recognition Standards June 20, 2017 Agenda Overview Journey to implement the new standard The challenge ahead Page 1 Overview Where are we now? Since the new standard was

More information

Response ed to Re: PCAOB Rulemaking Docket Matter No. 028

Response  ed to Re: PCAOB Rulemaking Docket Matter No. 028 September 7, 2010 Office of the Secretary, PCAOB 1666 K Street, N.W. Washington, D.C. 20006-2803 Response e-mailed to comments@pcaobus.org Re: PCAOB Rulemaking Docket Matter No. 028 Dear PCAOB Board: The

More information

LEVERAGING COSO ACROSS THE THREE LINES OF DEFENSE

LEVERAGING COSO ACROSS THE THREE LINES OF DEFENSE Committee of Sponsoring Organizations of the Treadway Commission Governance and Internal Control LEVERAGING COSO ACROSS THE THREE LINES OF DEFENSE By The Institute of Internal Auditors Douglas J. Anderson

More information

International Finance Corporation

International Finance Corporation International Finance Corporation Corporate Governance and Internal Audit Overview Bob Lamm Independent Senior Advisor Center for Corporate Governance Deloitte LLP Neil White Global IA Analytics Leader

More information

COSO 2013: Updated internal control framework

COSO 2013: Updated internal control framework COSO 2013: Updated internal control framework Athens, 10 October 2013 Background COSO's structure and mission COSO 1 is a joint initiative of five sponsoring organizations - American Accounting Association

More information

Build a Recession-proof Practice. 5 key ways to help you strengthen your practice now for greater efficiency and profitability. seic.

Build a Recession-proof Practice. 5 key ways to help you strengthen your practice now for greater efficiency and profitability. seic. Build a Recession-proof Practice 5 key ways to help you strengthen your practice now for greater efficiency and profitability seic.com/advisors There s no doubt about it. Since the financial crisis of

More information

Report on Inspection of Deloitte LLP (Headquartered in Toronto, Canada) Public Company Accounting Oversight Board

Report on Inspection of Deloitte LLP (Headquartered in Toronto, Canada) Public Company Accounting Oversight Board 1666 K Street, N.W. Washington, DC 20006 Telephone: (202) 207-9100 Facsimile: (202) 862-8433 www.pcaobus.org Report on 2014 (Headquartered in Toronto, Canada) Issued by the Public Company Accounting Oversight

More information

June 2016 Issue 05/2016

June 2016 Issue 05/2016 CBOK 2015: THE TOP 7 SKILLS CAEs WANT Building the right mix of talent for your organisation This report is part of the 2015 Global Internal Audit Common Body of Knowledge (CBOK) Practitioner Study series.

More information

Channel Incentive Study B2B Technology Industry

Channel Incentive Study B2B Technology Industry Channel Incentive Study B2B Technology Industry A CCI Report CCI conducted a study in Q4 of 2010 to assess the utilization of various incentive program types and their relative importance and/or effectiveness

More information

Internal Audit of ICT Governance in WFP. Office of the Inspector General Internal Audit Report AR/15/11

Internal Audit of ICT Governance in WFP. Office of the Inspector General Internal Audit Report AR/15/11 Fighting Hunger Worldwide Internal Audit of ICT Governance in WFP Office of the Inspector General Internal Audit Report AR/15/11 Contents Page I. Executive summary 3 II. Context and scope 5 III. Results

More information

Conseil scolaire Viamonde (Conseil scolaire de district du Centre Sud-Ouest)

Conseil scolaire Viamonde (Conseil scolaire de district du Centre Sud-Ouest) Ministry of Education (Conseil scolaire de district du Centre Sud-Ouest) Follow-up Report to the Operational Review October 2011 TABLE OF CONTENTS 1. INTRODUCTION... 1 2. STATUS AND IMPLEMENTATION UPDATE...

More information

Heads Up. Control Integrated Framework. COSO Enhances Its Internal. In This Issue: Enhancements in the 2013 Framework

Heads Up. Control Integrated Framework. COSO Enhances Its Internal. In This Issue: Enhancements in the 2013 Framework June 10, 2013 Volume 20, Issue 17 Heads Up In This Issue: Enhancements in the 2013 Framework Effective Systems of Internal Control COSO Transition Guidance and Impact on Other COSO Documents Internal Control

More information

Comments On The AICPA s Omnibus Proposal From The Professional Ethics Executive Committee (Released June 29, 2012)

Comments On The AICPA s Omnibus Proposal From The Professional Ethics Executive Committee (Released June 29, 2012) Deloitte LLP 30 Rockefeller Plaza New York, NY 10112-0015 USA Tel: 212-492-2000 Fax: 212-653-0000 www.deloitte.com November 30, 2012 VIA EMAIL Lisa A. Snyder Director Professional Ethics Division, AICPA

More information

Quality assurance at nuclear power plants: Basing programmes on performance

Quality assurance at nuclear power plants: Basing programmes on performance Quality assurance at nuclear power plants: Basing programmes on performance A look at how QA programmes are being improved quality assurance programme is often incorrectly interpreted as only a regulatory

More information

Guidance for Smaller Public Companies Reporting on Internal Control Over Financial Reporting Exposure Draft

Guidance for Smaller Public Companies Reporting on Internal Control Over Financial Reporting Exposure Draft 3701 Algonquin Road, Suite 1010 Telephone: 847.253.1545 Rolling Meadows, Illinois 60008, USA Facsimile: 847.253.1443 Web Sites: www.isaca.org and www.itgi.org 13 January 2006 COSO Board In care of Dr.

More information

Emerging Technology and Security Update

Emerging Technology and Security Update Emerging Technology and Security Update February 13, 2015 Jordan Reed Managing Director Agenda 2015 Internal Audit Capabilities and Needs Survey 2014 IT Priorities Survey Results 2014 IT Security and Privacy

More information

Session 7: Corporate Governance

Session 7: Corporate Governance Session 7: Corporate Governance New York Bankers Association-Community Bank Auditors Group 2016 Internal Audit Training-June 6-8, 2016 MEMBER OF ALLINIAL GLOBAL, AN ASSOCIATION OF LEGALLY INDEPENDENT FIRMS

More information

Simple Strategies, Big Results: Driving Internal Audit Value. October 28 th, 2016

Simple Strategies, Big Results: Driving Internal Audit Value. October 28 th, 2016 Simple Strategies, Big Results: Driving Internal Audit Value October 28 th, 2016 Agenda Introduction Demonstrate Alignment with Organization s Strategy Playing a Key Role in Company Initiatives Goal-Based

More information

Fraud Risk Management

Fraud Risk Management Fraud Risk Management Fraud Risk Management Overview 2017 Association of Certified Fraud Examiners, Inc. Discussion Questions 1. Does your organization follow a specific risk management model? If so, which

More information

IT and Enterprise Governance By Michael J. A. Parkinson, CISA, CIA, and Nicholas J. Baker, CPA

IT and Enterprise Governance By Michael J. A. Parkinson, CISA, CIA, and Nicholas J. Baker, CPA Copyright 2005 Information Systems Audit and Control Association. All rights reserved. www.isaca.org. IT and Enterprise Governance By Michael J. A. Parkinson, CISA, CIA, and Nicholas J. Baker, CPA Enterprise

More information

Understanding and Mitigating IT Project Risks BY MIKE BAILEY AND MIKE RIFFEL

Understanding and Mitigating IT Project Risks BY MIKE BAILEY AND MIKE RIFFEL Understanding and Mitigating IT Project Risks BY MIKE BAILEY AND MIKE RIFFEL Technology projects can present organizational challenges, and the associated risk is one of the finance officer s primary concerns

More information

Caribbean Association of Audit Committee Members Inc. Independent Quality Assurance Assessment of the Internal Audit function

Caribbean Association of Audit Committee Members Inc. Independent Quality Assurance Assessment of the Internal Audit function www.pwc.com/bb Caribbean Association of Audit Committee Members Inc. Independent Quality Assurance Assessment of the Internal Audit function Strengthening the Performance and Influence of the Audit Committee

More information

METROPOLITAN TRANSPORTATION AUTHORITY

METROPOLITAN TRANSPORTATION AUTHORITY ENTERPRISE RISK MANAGEMENT AND INTERNAL CONTROL GUIDELINES Pursuant to Public Authorities Law Section 2931 Adopted by the Board on November 16, 2016 These guidelines apply to the Metropolitan Transportation

More information

UNIVERSITY OF ILLINOIS AT URBANA-CHAMPAIGN

UNIVERSITY OF ILLINOIS AT URBANA-CHAMPAIGN UNIVERSITY OF ILLINOIS AT URBANA-CHAMPAIGN Department of Accountancy College of Business 360 Wohlers Hall 1206 S. Sixth Street Champaign, IL 61820 Office of the Secretary PCAOB 1666 K Street Washington,

More information