ORGANIZATIONAL INTEGRITY & AUDIT SERVICES ANNUAL WORK PLAN DEVELOPMENT RISK ASSESSMENT FACTORS

Size: px
Start display at page:

Download "ORGANIZATIONAL INTEGRITY & AUDIT SERVICES ANNUAL WORK PLAN DEVELOPMENT RISK ASSESSMENT FACTORS"

Transcription

1 RISK RATINGS The overall assessment of risk should be made in consideration of both the Impact of the area to Trinity Health and the Likelihood of a significant risk issues occurring in the area being assessed. IMPACT The purpose of assessing the impact is to answer the question How significant are the potential consequences of the risk? It is helpful to focus on a realistic worst-case scenario when assessing the impact or significance of a risk area. Consider the impact or significance of an area in terms of the organization s ability to achieve it s Strategic Goals Operational Goals Financial Goals Impact on Strategic Goals Consider the impact of a significant risk event occurring in the identified area on the achievement of Trinity Health and/or Ministry Organization strategic goals by asking questions such as: Is this risk area a key objective in the Trinity Health and/or Organization s Strategic Plan? Would the occurrence of a significant risk event in this area have a material impact on the organization s ability to achieve its desired strategic goals and objectives? Would the occurrence of a significant risk event in this area have a material impact on Trinity Health and/or the Ministry Organization s reputation? Impact on Operations Consider the impact of a significant risk event occurring in the identified area on Trinity Health and/or the Ministry Organization s operations by asking questions such as: How significant is the identified risk area to Trinity Health and/or the Ministry Organization s total operations? Would the occurrence of a significant risk event have a material impact on the organization s operations? Impact on Financial Goals Consider the impact of a significant risk event occurring in the identified area on the achievement of Trinity Health and/or Ministry Organization financial goals by asking questions such as How significant is the risk area in terms of measures such as operating revenue, operating expenses, total assets, net income or loss to Trinity Health and/or the Ministry Organizations total operations? Would the occurrence of a significant risk event in this area have a material impact on the organization s ability to achieve its desired financial goals and objectives? 1

2 The measure of materiality most meaningful to the area should be used in evaluating financial impact. In certain cases, a combination of different criteria may be used. Evaluations will be necessarily judgmental and will likely involve discussions with your Manager or Director. However, the basis for the evaluation should be reasonable and supportable based on objective criteria. Examples of Potential Financial Impact Measures: Materials Management Inventory Payroll Pharmacy Home Health subsidiary - annual purchases - balance sheet amounts - annual payroll expense - department operating revenue or expenses - total assets, revenues or expenses, net income/loss Impact Risk Rating After giving consideration to the impact or significance of the identified risk area based on the above criteria, assign an impact risk rating to the area based on its significance to Trinity Health and/or the Ministry Organization s strategic, operational and/or financial goals: Scale 1 Not Significant Description 3 Minor Significance 5 Moderate Significance 7 High Significance 9 Extremely High Significance LIKELIHOOD The purpose of assessing the likelihood is to answer the question How likely is it that a potential significant risk event will occur in this risk area? In assessing the likelihood of a significant risk event occurring, you should give consideration to the following risk factors when making your evaluation: Control and Operating Environment Internal and External Factors Regulatory and Compliance Factors Control and Operating Environment The control and operating environment reflects the overall attitude, awareness, and actions of management and associates concerning the importance of controls and the emphasis placed on control in the organization s policies, procedures, methods and organizational structure. The 2

3 overall assessment of the control and operating environment ultimately comes down to three questions: Has management installed the necessary risk management/control mechanisms to monitor risks? Are the risk management/control mechanisms established functioning effectively? Consider the overall control and operating environment of the risk area giving consideration to the following: Probability that a material risk event could occur and not be detected by management in the course of daily operations; Effectiveness of accounting and reporting system in providing management with sufficient, accurate, and timely information; Area requiring significant estimation or judgment by management and/or analyses performed on only a non-routine basis; The extent of self-monitoring mechanisms established to monitor risks in the normal performance of operations (quality control standards and reporting, periodic sample audits, system controls or edits, etc.) Existence of documented and communicated policies and procedures; Physical controls; Segregation of duties; Key management review (monitoring of actual vs. budgeted performance, comparisons to industry benchmarks, etc.); Appropriateness of organizational structure. In general, entities, departments, business units which are not integrated with other local operations (e.g. financial and information systems, policies, procedures are separate and independent) generally present higher risks than those fully integrated within local operations. Management s historical philosophy and operating style concerning internal controls and risk avoidance; Nature of findings or conditions noted in prior audits or external audit management letters. Management s input is critical in evaluating the control environment and should be obtained through inquiry and discussion. As a general rule of thumb, an audit area should be evaluated as "Moderate" risk in the absence of any specific knowledge of the effectiveness of the control environment. Internal and External Factors Factors outside the control of the organization/department and management may also have an impact on area. These factors can directly affect management s attitude toward the conduct and reporting of operations and the importance of the control environment. Consider the risk area in consideration of the following internal and external factors: Economic conditions - pressure to improve overall operating performance or to meet established budget targets; Influence of joint venture owner or business partner on activities of the area; Competition and strategic position in the marketplace; Complexity of the area; Recent changes in key personnel or organizational structure; Recent acquisition of a previously non-affiliated entity; Concerns of management, board of trustees or its committees concerning the area. 3

4 Regulatory and Compliance Factors Consider the extent to which the area under consideration is impacted by requirements of federal or state laws and regulations or subject to standards of accrediting organizations such as JCAHO, NCQA, etc. Consider the following: Extent of current regulatory review of identified area by federal or state agencies such as the Office of Inspector General, Department of Justice, etc; Extent and results of previous reviews of the identified area performed by OIAS personnel, external consultants or the organization; The existence or lack of systems, procedures and policies addressing the identified risk area as well as the effectiveness of current monitoring procedures as obtained through prior reviews or management inquiries; The results of reviews of the identified area performed by OIAS personnel for other Ministry Organizations; Likelihood Risk Rating After giving consideration to likelihood of a significant risk event occurring in the identified risk area based on the above criteria, assign an impact risk rating to the area based on the following: Scale 1 Very Low Description 3 Low 5 Moderate 7 High 9 Very High 4

5 Based on the risk ratings assigned to impact and likelihood, a weighted risk rating is determined. For purposes of weighting, the impact risk factor is multiplied by.6, while the likelihood risk factor is weighted.4. The end result is that additional emphasis will be placed on those areas considered to have the most significant impact to Trinity Health and/or the Ministry Organization s strategic, operational and financial goals. The combined weighted average risk can be presented on a matrix as follows: Impact Likelihood WORK PLAN DEVELOPMENT Those risk areas with the highest combined risk rating as identified in the risk assessment process should be prioritized in developing the annual OIAS Work Plan based on timing, availability of resources, etc. 5

RELEVANT TO ACCA QUALIFICATION PAPERS F8 (INT), P7 (INT) AND FOUNDATION LEVEL PAPER FAU (INT)

RELEVANT TO ACCA QUALIFICATION PAPERS F8 (INT), P7 (INT) AND FOUNDATION LEVEL PAPER FAU (INT) RELEVANT TO ACCA QUALIFICATION PAPERS F8 (INT), P7 (INT) AND FOUNDATION LEVEL PAPER FAU (INT) ISA 315 (Revised), Identifying and Assessing the Risks of Material Misstatement through Understanding the Entity

More information

Institute of Internal Auditors. Dallas Chapter August 6, 2009

Institute of Internal Auditors. Dallas Chapter August 6, 2009 Institute of Internal Auditors Dallas Chapter August 6, 2009 Outline Why perform a Risk Assessment Risk Assessment Approaches What is Risk? Audit Universe Risk Model Risk Factors and Weighting Risk Scoring

More information

Internal Control Systems

Internal Control Systems Internal Control Systems What are Internal Controls? Internal Controls are a set of rules, policies, and procedures a municipality can implement to provide reasonable assurances that: its financial reports

More information

Internal Audit Department Update. December 7, 2016 Cassaundra Rouse

Internal Audit Department Update. December 7, 2016 Cassaundra Rouse Internal Audit Department Update December 7, 2016 Cassaundra Rouse Agenda Audit Committee schedule Internal Audit charter Internal Audit resources Risk assessment Internal Audit Plan 2017 and 2018 Next

More information

Internal Control at OSU COSO & Enterprise Risk Management. Oregon State University Board of Trustees Executive & Audit Committee Educational Session

Internal Control at OSU COSO & Enterprise Risk Management. Oregon State University Board of Trustees Executive & Audit Committee Educational Session Internal Control at OSU COSO & Enterprise Risk Management Oregon State University Board of Trustees Executive & Audit Committee Educational Session OSU Internal Control Model - COSO The COSO framework

More information

The most commonly applied model for designing and auditing internal

The most commonly applied model for designing and auditing internal Fair Value Accounting Fraud: New Global Risks and Detection Techniques By Gerard M. Zack Copyright 2009 by Gerard M. Zack Appendix C Internal Controls over Fair Value Accounting Applications The most commonly

More information

Implementation Tool for Auditors

Implementation Tool for Auditors Implementation Tool for Auditors CANADIAN AUDITING STANDARDS (CAS) DECEMBER 2017 STANDARD DISCUSSED CAS 315, Identifying and Assessing the Risks of Material Misstatement through Understanding the Entity

More information

Internal controls over Financial Reporting Key concepts. Presentation by Jayesh Gandhi at WIRC

Internal controls over Financial Reporting Key concepts. Presentation by Jayesh Gandhi at WIRC Internal controls over Financial Reporting Key concepts Presentation by Jayesh Gandhi at WIRC Page 1 ICFR Key Concepts WIRC 28 May 2016 Agenda Scope and requirements Overview of internal controls as per

More information

Gleim CIA Review Updates to Part Edition, 1st Printing June 2018

Gleim CIA Review Updates to Part Edition, 1st Printing June 2018 Page 1 of 15 Gleim CIA Review Updates to Part 1 2018 Edition, 1st Printing June 2018 Study Unit 3 Control Frameworks and Fraud Pages 66 through 69 and 76 through 77, Subunit 3.2: In accordance with the

More information

The Role of the Chief Risk Office and the Board s Role in Risk Oversight

The Role of the Chief Risk Office and the Board s Role in Risk Oversight The Canadian Society of Corporate Secretaries 16th Annual Corporate Governance Conference Banff Springs Hotel Banff, AB August 24 27, 2014 The Role of the Chief Risk Office and the Board s Role in Risk

More information

COSO Updates and Expectations. IIA San Diego Chapter January 8, 2014

COSO Updates and Expectations. IIA San Diego Chapter January 8, 2014 COSO Updates and Expectations IIA San Diego Chapter January 8, 2014 Agenda Overview of 2013 Internal Control-Integrated Framework and Companion Guidance 2013 Framework General Enhancements by Component

More information

VIRGINIA STATE UNIVERSITY RISK ANALYSIS SURVEY OPERATIONAL. 1. Operating Concerns of the Assessable Unit and/or Business Process

VIRGINIA STATE UNIVERSITY RISK ANALYSIS SURVEY OPERATIONAL. 1. Operating Concerns of the Assessable Unit and/or Business Process ASSESSABLE UNIT: Enter name of the Assessable Unit here BUSINESS PROCESS: Enter the Business Process here BANNER INDEX CODE: Enter Banner Index Code here 1. Operating Concerns of the Assessable Unit and/or

More information

RISK BASED AUDIT WORK GROUP GUIDELINES FOR ANNUAL AUDIT PLANNING AND RESOURCE ALLOCATION FISCAL YEAR 2001

RISK BASED AUDIT WORK GROUP GUIDELINES FOR ANNUAL AUDIT PLANNING AND RESOURCE ALLOCATION FISCAL YEAR 2001 The following risk model is for use in all University audit environments (campuses, laboratories, and medical centers.) Each predictive factor is assigned a score of one (lowest risk) to five (highest

More information

On the Revision of the Standards and Practice Standards for. Management Assessment and Audit concerning Internal Control

On the Revision of the Standards and Practice Standards for. Management Assessment and Audit concerning Internal Control (Provisional translation) On the Revision of the Standards and Practice Standards for Management Assessment and Audit concerning Internal Control Over Financial Reporting (Council Opinions) Released on

More information

Understanding the Entity and Its Environment and Assessing the Risks of Material Misstatement

Understanding the Entity and Its Environment and Assessing the Risks of Material Misstatement Issued December 2007 International Standard on Auditing Understanding the Entity and Its Environment and Assessing the Risks of Material Misstatement The Malaysian Institute of Certified Public Accountants

More information

Anti-Fraud Programs and Control Policy

Anti-Fraud Programs and Control Policy Anti-Fraud Programs and Control Policy OVERVIEW This document provides an overview of the programs and controls Tahoe Resources Inc. ( Tahoe ) follows in order to evaluate fraud risk as it pertains to

More information

Chapter 06. Audit Planning, Understanding the Client, Assessing Risks, and Responding. McGraw-Hill/Irwin

Chapter 06. Audit Planning, Understanding the Client, Assessing Risks, and Responding. McGraw-Hill/Irwin Chapter 06 Audit Planning, Understanding the Client, Assessing Risks, and Responding McGraw-Hill/Irwin Copyright 2012 by The McGraw-Hill Companies, Inc. All rights reserved. Obtaining Clients Submit a

More information

Institute of Chartered Accountants of India. Standards on Auditing

Institute of Chartered Accountants of India. Standards on Auditing Institute of Chartered Accountants of India Standards on Auditing Presented by: CA Sunil Nagrani February 16, 2013 Contents SA 315 - Identifying and Assessing the Risk of Material Misstatement Through

More information

Modern Auditing: Assurance Services and the Integrity of Financial Reporting, 8 th Edition

Modern Auditing: Assurance Services and the Integrity of Financial Reporting, 8 th Edition Modern Auditing: Assurance Services and the Integrity of Financial Reporting, 8 th Edition William C. Boynton California Polytechnic State University at San Luis Obispo Raymond N. Johnson Portland State

More information

This charter defines the purpose, authority and responsibility of News Corporation s (the Company ) Corporate Audit Department.

This charter defines the purpose, authority and responsibility of News Corporation s (the Company ) Corporate Audit Department. CORPORATE AUDIT DEPARTMENT CHARTER PURPOSE This charter defines the purpose, authority and responsibility of News Corporation s (the Company ) Corporate Audit Department. The Institute of Internal Auditors

More information

Mapping of Original ISA 315 to New ISA 315 s Standards and Application Material (AM) Agenda Item 2-C

Mapping of Original ISA 315 to New ISA 315 s Standards and Application Material (AM) Agenda Item 2-C Mapping of to 315 s and Application Material (AM) Agenda Item 2-C AM 1. The purpose of this International Standard on Auditing (ISA) is to establish standards and to provide guidance on obtaining an understanding

More information

Audit Training-of-Trainers Workshop, November 2014, Vienna Components of internal control within organization

Audit Training-of-Trainers Workshop, November 2014, Vienna Components of internal control within organization Audit Training-of-Trainers Workshop, 18-19 November 2014, Vienna Components of internal control within organization Andrei Busuioc, Senior Financial Management Specialist, CFRR Session objectives The session

More information

Auditing Standards and Practices Council

Auditing Standards and Practices Council Auditing Standards and Practices Council PHILIPPINE STANDARD ON AUDITING 315 UNDERSTANDING THE ENTITY AND ITS ENVIRONMENT AND ASSESSING THE RISKS OF MATERIAL MISSTATEMENT PHILIPPINE STANDARD ON AUDITING

More information

INTERNATIONAL STANDARD ON AUDITING 315 UNDERSTANDING THE ENTITY AND ITS ENVIRONMENT AND ASSESSING THE RISKS OF MATERIAL MISSTATEMENT CONTENTS

INTERNATIONAL STANDARD ON AUDITING 315 UNDERSTANDING THE ENTITY AND ITS ENVIRONMENT AND ASSESSING THE RISKS OF MATERIAL MISSTATEMENT CONTENTS INTERNATIONAL STANDARD ON AUDITING 315 UNDERSTANDING THE ENTITY AND ITS ENVIRONMENT AND ASSESSING THE RISKS OF MATERIAL MISSTATEMENT (Effective for audits of financial statements for periods beginning

More information

Gleim CPA Review Updates to Business Environment and Concepts 2018 Edition, 1st Printing March 2018

Gleim CPA Review Updates to Business Environment and Concepts 2018 Edition, 1st Printing March 2018 Page 1 of 16 Gleim CPA Review Updates to Business Environment and Concepts 2018 Edition, 1st Printing March 2018 The content of BEC Study Unit 2, Subunit 2, has undergone extensive edits due to the 2017

More information

Chapter 7 Internal Controls

Chapter 7 Internal Controls Chapter 7 Internal Controls Establishment of and adherence to internal controls is a major part of managing an organization. Internal controls serve as the first line of defense in safeguarding assets

More information

Community Bankers Conference

Community Bankers Conference 3rd Annual Regional and Community Bankers Conference The Federal Reserve Bank of Boston Disclaimer NEVER WRONG DON T COMPLETELY RELY UPON Recent Developments in Audit Practice SOX, FDICIA 112, Other Robert

More information

Internal Controls: Need Them, Have Them, Love Them

Internal Controls: Need Them, Have Them, Love Them Internal Controls: Need Them, Have Them, Love Them Tiffany R. Winters, Esquire twinters@bruman.com Brustein & Manasevit Fall Forum 2010 Why Do We Have Internal Controls? The Federal Managers Financial

More information

The Basics of Internal Controls & Segregation of Duties

The Basics of Internal Controls & Segregation of Duties The Basics of Internal Controls & Segregation of Duties Presented by: Kevin L. Pegish, CPA Senior Audit Manager Northwest Region klpegish@ohioauditor.gov Internal Controls, we will discuss the following:

More information

IAASB Main Agenda (December 2004) Page Agenda Item

IAASB Main Agenda (December 2004) Page Agenda Item IAASB Main Agenda (December 2004) Page 2004 2159 Agenda Item 7-B PROPOSED INTERNATIONAL STANDARD ON AUDITING XXX THE AUDIT OF GROUP FINANCIAL STATEMENTS CONTENTS Paragraph Introduction... 1-3 Definitions...

More information

INTERNAL CONTROL: COMPLIANCE, OPERATIONAL AND FINANCIAL

INTERNAL CONTROL: COMPLIANCE, OPERATIONAL AND FINANCIAL INTERNAL CONTROL: COMPLIANCE, OPERATIONAL AND FINANCIAL SECTOR / INTERNAL AUDIT NON-TECHNICAL & CERTIFIED TRAINING COURSE The course then tackles controls at board and senior management level and into

More information

Support Services Review Template

Support Services Review Template Update Year: 2012 Unit Name: Office of Internal Audit Today s Date: June 28, 2012 Unit Review Leader: Imad Mouchayleh Five Fundamental Questions 1. What are the primary services or outcomes provided by

More information

What is Enterprise Risk Management (ERM)? What the Heck is ERM? Is There an 8 th Element of a Good Compliance Program?

What is Enterprise Risk Management (ERM)? What the Heck is ERM? Is There an 8 th Element of a Good Compliance Program? What the Heck is ERM? Is There an 8 th Element of a Good Compliance Program? Kim Otte, Chief Compliance Officer Chris Davies, Regional Compliance Officer, NW Wisconsin Brenda Mickow, Revenue Compliance

More information

S r. M a n a g e r R i s k A d v i s o r y. D a n S m i t h. D e c e m b e r S e r v i c e s. Operational Auditing & Operations Management

S r. M a n a g e r R i s k A d v i s o r y. D a n S m i t h. D e c e m b e r S e r v i c e s. Operational Auditing & Operations Management Operational Auditing & Operations Management Operational Auditing & Operations Management D a n S m i t h S r. M a n a g e r R i s k A d v i s o r y S e r v i c e s D e c e m b e r 2 0 1 4 Experis December

More information

PART 6 - INTERNAL CONTROL

PART 6 - INTERNAL CONTROL PART 6 - INTERNAL CONTROL INTRODUCTION The A-102 Common Rule and OMB Circular A-110 (2 CFR part 215) require that non-federal entities receiving Federal awards (i.e., auditee management) establish and

More information

IAASB Main Agenda (March 2005) Page Agenda Item 12-C

IAASB Main Agenda (March 2005) Page Agenda Item 12-C IAASB Main Agenda (March 2005) Page 2005 429 Agenda Item 12-C [ISA AND IAPS SPLIT] PROPOSED INTERNATIONAL AUDITING PRACTICE STATEMENT XXX THE APPLICATION OF INTERNATIONAL STANDARDS ON AUDITING IN AN AUDIT

More information

Presented by Ed Williamson and Erica Bailey

Presented by Ed Williamson and Erica Bailey Presented by Ed Williamson and Erica Bailey Internal Controls & Fraud Detection Objectives Background on internal controls Review of organizational and functional level controls Fraud prevention and risk

More information

ISO 14001:2015 and Life Cycle Perspective

ISO 14001:2015 and Life Cycle Perspective ISO 14001:2015 and Life Cycle Perspective 14th Annual Gatekeeper Regulatory Roundup March 23 rd, 2018 Disha Gadre Trinity Consultants Agenda Intro to Environmental Management Systems Overview of changes

More information

EXECUTIVE SUMMARY INTERNAL AUDIT REPORT. IOM Berlin DE NOVEMBER 2017

EXECUTIVE SUMMARY INTERNAL AUDIT REPORT. IOM Berlin DE NOVEMBER 2017 EXECUTIVE SUMMARY INTERNAL AUDIT REPORT IOM Berlin DE201701 15-23 NOVEMBER 2017 Issued by the Office of the Inspector General Page 1 of 8 Report on the Audit of IOM Berlin Executive Summary Audit File

More information

CHAPTER II THEORETICAL FOUNDATION. ensure the effectiveness and efficiency of a company s operation. Operational audit is

CHAPTER II THEORETICAL FOUNDATION. ensure the effectiveness and efficiency of a company s operation. Operational audit is CHAPTER II THEORETICAL FOUNDATION 2.1 Definition of Operational Audit Operational audit is an audit which is commonly performed in a company in order to ensure the effectiveness and efficiency of a company

More information

G11: Convergence of Security and Compliance - An Integrated Approach to Information Risk Management Larry A. Jewik and Ramy Houssaini, Kaiser

G11: Convergence of Security and Compliance - An Integrated Approach to Information Risk Management Larry A. Jewik and Ramy Houssaini, Kaiser G11: Convergence of Security and Compliance - An Integrated Approach to Information Risk Management Larry A. Jewik and Ramy Houssaini, Kaiser Permanente The Convergence of Security and Compliance -- An

More information

Risk-Focused Examination Process an Overview. Federal Reserve System

Risk-Focused Examination Process an Overview. Federal Reserve System Risk-Focused Examination Process an Overview Federal Reserve System Traditional Process Point-in-time Surprise entry Revalidation of the balance sheet and income statement Compliance with laws and regulations

More information

Report on Inspection of KPMG AG Wirtschaftspruefungsgesellschaft (Headquartered in Berlin, Federal Republic of Germany)

Report on Inspection of KPMG AG Wirtschaftspruefungsgesellschaft (Headquartered in Berlin, Federal Republic of Germany) 1666 K Street, N.W. Washington, DC 20006 Telephone: (202) 207-9100 Facsimile: (202) 862-8433 www.pcaobus.org Report on 2016 (Headquartered in Berlin, Federal Republic of Germany) Issued by the Public Company

More information

CHAPTER 2 THEORETICAL FOUNDATIONS. organization which responsible to record and employs physical resources and other

CHAPTER 2 THEORETICAL FOUNDATIONS. organization which responsible to record and employs physical resources and other CHAPTER 2 THEORETICAL FOUNDATIONS 2.1 Accounting Information System (AIS) Accounting information system can be defined as an integrated system within an organization which responsible to record and employs

More information

Strengthening Control and integrity: A Checklist for government Managers

Strengthening Control and integrity: A Checklist for government Managers Forum: Analytics and Risk Management Tools for Making Better Decisions Strengthening Control and integrity: A Checklist for government Managers By James A. Bailey The next contribution is based on a Center

More information

B U S I N E S S O F F I C E R Schematic Code ( )

B U S I N E S S O F F I C E R Schematic Code ( ) I. DESCRIPTION OF WORK B U S I N E S S O F F I C E R Schematic Code 10900 (31000040) Positions in this banded class administer and manage the business and financial affairs of a department, unit, or organization.

More information

Managing Risk In Higher Education. Jeff Mueller, CPA / Ron Bocciardi April 25, 2012

Managing Risk In Higher Education. Jeff Mueller, CPA / Ron Bocciardi April 25, 2012 Managing Risk In Higher Education Jeff Mueller, CPA / Ron Bocciardi April 25, 2012 Agenda What is risk management? Integrating risk management concepts into higher education What do you get? Questions

More information

INTERNAL CONTROLS AUDITOR JOHN BYRD, SENIOR AUDITOR TONYA CARRIGAN, SENIOR AUDITOR

INTERNAL CONTROLS AUDITOR JOHN BYRD, SENIOR AUDITOR TONYA CARRIGAN, SENIOR AUDITOR 1 INTERNAL CONTROLS FOR THE BEGINNING AUDITOR JOHN BYRD, SENIOR AUDITOR TONYA CARRIGAN, SENIOR AUDITOR UF HEALTH SHANDS HOSPITAL AHIA 32 nd Annual Conference August 25-28, 2013 Chicago, Illinois www.ahia.org

More information

A Discussion About Internal Controls February 2016

A Discussion About Internal Controls February 2016 A Discussion About Internal Controls February 2016 What we will cover today 001 Introductions 002 Defining Internal Controls 003 COSO Internal Controls Integrated Framework 004 Approach to Designing Internal

More information

(Effective for audits of financial statements for periods ending on or after December 15, 2013) CONTENTS

(Effective for audits of financial statements for periods ending on or after December 15, 2013) CONTENTS INTERNATIONAL STANDARD ON AUDITING 315 (REVISED) IDENTIFYING AND ASSESSING THE RISKS OF MATERIAL MISSTATEMENT THROUGH UNDERSTANDING THE ENTITY AND ITS ENVIRONMENT Introduction (Effective for audits of

More information

INTERNAL CONTROLS FOR NONPROFITS

INTERNAL CONTROLS FOR NONPROFITS INTERNAL S FOR NONPROFITS Best Practice Principles, Policies, and Procedures INTRO 1 INTERNAL S FOR NONPROFITS GUIDE BACK NEXT PAGE INTERNAL S FOR NONPROFITS: Best Practice Principles, Policies, and Procedures

More information

Environmental Scanning and Risk Assessment

Environmental Scanning and Risk Assessment Margaret Hambleton CHC-F, CHRC Vice President and Corporate Compliance Officer Dignity Health Environmental Scanning and Risk Assessment Health Care Compliance Association Orange County, CA Regional Conference

More information

716 West Ave Austin, TX USA

716 West Ave Austin, TX USA FRAUD-RELATED INTERNAL CONTROLS GLOBAL Headquarters the gregor building 716 West Ave Austin, TX 78701-2727 USA Figure 2.1 COSO defines an internal control as a process, effected by an entity s board of

More information

Internal Controls and the Internal Auditor. Presented By: Richard Kudlik, CPA

Internal Controls and the Internal Auditor. Presented By: Richard Kudlik, CPA Internal Controls and the Internal Auditor Presented By: Richard Kudlik, CPA Interrelated Components Control Environment Risk Assessment Control Activities Information and Communication Monitoring What

More information

INTERNAL CONTROLS FOR NONPROFITS

INTERNAL CONTROLS FOR NONPROFITS INTERNAL S FOR NONPROFITS Best Practice Principles, Policies, and Procedures 1 INTERNAL S FOR NONPROFITS GUIDE BACK NEXT PAGE S WITH INTERNAL S FOR NONPROFITS: Best Practice Principles, Policies, and Procedures

More information

SRI LANKA AUDITING STANDARD 315 (REVISED)

SRI LANKA AUDITING STANDARD 315 (REVISED) SRI LANKA AUDITING STANDARD 315 (REVISED) IDENTIFYING AND ASSESSING THE RISKS OF MATERIAL MISSTATEMENT THROUGH UNDERSTANDING THE ENTITY AND ITS ENVIRONMENT (Effective for audits of financial statements

More information

Certified Internal Auditor - Part 1, The Internal Audit Activity's Role in Governance, Risk, and Control

Certified Internal Auditor - Part 1, The Internal Audit Activity's Role in Governance, Risk, and Control IIA IIA-CIA-Part1 Certified Internal Auditor - Part 1, The Internal Audit Activity's Role in Governance, Risk, and Control https://killexams.com/pass4sure/exam-detail/iia-cia-part1 Question: 555 During

More information

PREPARING A RISK BASED AUDIT WORK PROGRAM

PREPARING A RISK BASED AUDIT WORK PROGRAM 1 PREPARING A RISK BASED AUDIT WORK PROGRAM BAILEY JORDAN PARTNER, GRC PRACTICE LEADER GRANT THORNTON, LLP DAVID TYLER PRINCIPAL, HEALTH CARE ADVISORY GRANT THORNTON, LLP AHIA 32 nd Annual Conference August

More information

1. Definition & Mission

1. Definition & Mission 1. Definition & Mission 1.1 Internal Auditing is an independent, objective assurance and consulting activity that is guided by a philosophy of adding value to improve the operations of. 1.2 Group Internal

More information

Identifying and Assessing the Risks of Material Misstatement through Understanding the Entity and Its Environment

Identifying and Assessing the Risks of Material Misstatement through Understanding the Entity and Its Environment ISA 315 (Revised) Issued September 2012; updated February 2018 International Standard on Auditing Identifying and Assessing the Risks of Material Misstatement through Understanding the Entity and Its Environment

More information

OUR PEOPLE MAKE THE DIFFERENCE Our professional management team is committed to making you and your property a success.

OUR PEOPLE MAKE THE DIFFERENCE Our professional management team is committed to making you and your property a success. OUR PEOPLE MAKE THE DIFFERENCE Our professional management team is committed to making you and your property a success. www.greenstpm.com An Attitude of Ownership Green Street Management has many years

More information

City of West Richland Job Description

City of West Richland Job Description City of West Richland Job Description Job Title: Accounting Technician Department: Finance Reports To: Finance Director FLSA Status: Non-Exempt Prepared By: Jessica Platt, Finance Director Approved By:

More information

Chapter 18. Integrated Audits of Public Companies. McGraw-Hill/Irwin. Copyright 2012 by The McGraw-Hill Companies, Inc. All rights reserved.

Chapter 18. Integrated Audits of Public Companies. McGraw-Hill/Irwin. Copyright 2012 by The McGraw-Hill Companies, Inc. All rights reserved. Chapter 18 Integrated Audits of Public Companies McGraw-Hill/Irwin Copyright 2012 by The McGraw-Hill Companies, Inc. All rights reserved. Nature of an Integrated Audit Auditors of public companies should

More information

AUDITING. Auditing PAGE 1

AUDITING. Auditing PAGE 1 AUDITING Auditing 1. Professionalism The International Professional Practices Framework (IPPF) is the conceptual framework that organizes authoritative guidance promulgated by The Institute of Internal

More information

International Standard on Auditing (Ireland) 315

International Standard on Auditing (Ireland) 315 International Standard on Auditing (Ireland) 315 Identifying and Assessing the Risks of Material Misstatement Through Understanding the Entity and its Environment MISSION To contribute to Ireland having

More information

International Standards for the Professional Practice of Internal Auditing (Standards)

International Standards for the Professional Practice of Internal Auditing (Standards) Attribute Standards 1000 Purpose, Authority, and Responsibility The purpose, authority, and responsibility of the internal audit activity must be formally defined in an internal audit charter, consistent

More information

FY17-FY18 Audit Plan. Office of Internal Auditing

FY17-FY18 Audit Plan. Office of Internal Auditing FY17-FY18 Audit Plan Office of Internal Auditing -Page Intentionally Blank- TABLE OF CONTENTS Executive Summary... 4 Audit Plan Details... 6 Budgeted Hours... 7 Risk Assessment... 8 Allocation of Resources...

More information

International Standard on Auditing (UK) 315 (Revised June 2016)

International Standard on Auditing (UK) 315 (Revised June 2016) Standard Audit and Assurance Financial Reporting Council June 2016 International Standard on Auditing (UK) 315 (Revised June 2016) Identifying and Assessing the Risks of Material Misstatement Through Understanding

More information

INTERNAL CONTROLS FOR NONPROFITS

INTERNAL CONTROLS FOR NONPROFITS INTERNAL S FOR NONPROFITS Best Practice Principles, Policies, and Procedures 1 INTERNAL S FOR NONPROFITS GUIDE BACK NEXT PAGE S WITH INTERNAL S FOR NONPROFITS: Best Practice Principles, Policies, and Procedures

More information

STUDY UNIT TEN INTERNAL AUDIT RESPONSIBILITIES FOR FRAUD

STUDY UNIT TEN INTERNAL AUDIT RESPONSIBILITIES FOR FRAUD STUDY UNIT TEN INTERNAL AUDIT RESPONSIBILITIES FOR FRAUD 1 10.1 Fraud -- Nature, Prevention, and Detection..................................... 1 10.2 Fraud -- Indicators........................................................

More information

I N V E S T M E N T AN AL Y S T Schematic Code ( )

I N V E S T M E N T AN AL Y S T Schematic Code ( ) I. DESCRIPTION OF WORK I N V E S T M E N T AN AL Y S T Schematic Code 10735 (31000046) Positions in this banded class analyze financial or credit information to forecast business industry and economic

More information

Conducting a Fraud Risk Assessment

Conducting a Fraud Risk Assessment Conducting a Fraud Risk Assessment Approach, Pitfalls and Recommendations IAAIA Istanbul October 10-13, 2010 Jean Pierre Garitte, CIA, CCSA, CISA, CFE, RFA May 2010 Introduction and Overview Why Conduct

More information

What s New in Government Internal Control Standards? Going Green

What s New in Government Internal Control Standards? Going Green What s New in Government Internal Control Standards? Going Green Page 1 Session Objective To discuss GAO s revision to the Standards for Internal Control in the Federal Government (Green Book) Page 2 What

More information

Diving into the 2013 COSO Framework. Presented by: Ronald A. Conrad

Diving into the 2013 COSO Framework. Presented by: Ronald A. Conrad Diving into the 2013 COSO Framework Presented by: Ronald A. Conrad 2 Objectives Obtain an understanding of why the COSO Framework has been updated Understand how the framework has changed Identify the

More information

AUDIT RISK ASSESSMENT AND RESPONSES TO ASSESSED RISK BY Geoffrey Byamugisha Partner, Ernst & Young. Lessons on Audit Risk. Responding to fraud risk

AUDIT RISK ASSESSMENT AND RESPONSES TO ASSESSED RISK BY Geoffrey Byamugisha Partner, Ernst & Young. Lessons on Audit Risk. Responding to fraud risk AUDIT RISK ASSESSMENT AND RESPONSES TO ASSESSED RISK BY Geoffrey Byamugisha Partner, Ernst & Young ICPAU Page 1 COURSE CONTENT Lessons on Audit Risk Identification of audit risk and audit risk assessment

More information

Sarbanes-Oxley: Company Case Study - Viacom Inc. IT General Controls - Sustaining Compliance Efforts. Anthony Noble VP, IT Internal Audit

Sarbanes-Oxley: Company Case Study - Viacom Inc. IT General Controls - Sustaining Compliance Efforts. Anthony Noble VP, IT Internal Audit Sarbanes-Oxley: A Focus on IT Controls Company Case Study - Viacom Inc. IT General Controls - Sustaining Compliance Efforts Anthony Noble VP, IT Internal Audit Today s Agenda Introduction Viacom Methodology

More information

UNF Finance and Audit Committee January 15, 2013

UNF Finance and Audit Committee January 15, 2013 Item 7 UNF Finance and Audit Committee January 15, 2013 Issue Office of Internal Auditing Audit Planning Methodology Proposed Action Report Background Information The purpose of this item is to present

More information

VERSION #1 WRITE ON YOUR SCANTRON!!!

VERSION #1 WRITE ON YOUR SCANTRON!!! ECON 132A WINTER 2009 MIDTERM #2 Name: Date: ANSWER ALL MULTIPLE CHOICE QUESTIONS ON GREEN SCANTRON ANSWER QUESTIONS 29 & 30 IN THE SPACE PROVIDED ANSWER THE SIMULATION ASSIGNMENT IN YOUR BLUE-BOOK, PUT

More information

SUGGESTED SOLUTIONS. KC4 Corporate Governance, Assurance & Ethics. December All Rights Reserved. KC4 - Suggested Solutions.

SUGGESTED SOLUTIONS. KC4 Corporate Governance, Assurance & Ethics. December All Rights Reserved. KC4 - Suggested Solutions. SUGGESTED SOLUTIONS KC4 Corporate Governance, Assurance & Ethics Page 1 of 16 All Rights Reserved Answer 1 Relevant Learning Outcomes/s; 3.1/3.4/ 4.1 / 4.2 (a) Suggested Detailed Answer: (1) Audit Strategy

More information

Risk Management. Body of Knowledge Review Based on the 2014 ACMPE Exam Blueprint

Risk Management. Body of Knowledge Review Based on the 2014 ACMPE Exam Blueprint Body of Knowledge Review Based on the 2014 ACMPE Exam Blueprint Risk Management Under HIPAA regulations, what is the definition of a healthcare provider? 1 Risk Management A person or organization that

More information

covered member immediate family impaired not a covered member close relative not impaired

covered member immediate family impaired not a covered member close relative not impaired BUS 425 Auditing Tad Miller May 22, 2017 Audit Planning, Analytical Procedures, Materiality & Risk, Internal Control Evaluation and Audit Plan 1. INDEPENDENCE All independence problems refer to a client

More information

2016 NOT-FOR-PROFIT ENTITIES OVERVIEW FOR KNOWLEDGE COACH USERS

2016 NOT-FOR-PROFIT ENTITIES OVERVIEW FOR KNOWLEDGE COACH USERS 2016 OT-FOR-PROFIT ETITIES OVERVIEW FOR KOWLEDGE COACH USERS PURPOSE This document is published for the purpose of communicating, to users of the toolset, updates and enhancements included in the current

More information

Transparency in the Workforce System Establishing Firewalls & Internal Controls

Transparency in the Workforce System Establishing Firewalls & Internal Controls Transparency in the Workforce System Establishing Firewalls & Internal Controls Presented by the Today s Objectives Define internal controls Identify components of an internal control structure Discuss

More information

Glasgow Caledonian University Internal Audit Annual Report for the year ended 31 July 2008

Glasgow Caledonian University Internal Audit Annual Report for the year ended 31 July 2008 Government and Public Sector Internal Audit Services October 2008 Internal Audit Annual Report for the year ended 31 July 2008 Contents Section Page 1. Background and Scope...1 2. Our Annual Opinion...3

More information

International Standards for the Professional Practice of Internal Auditing (Standards)

International Standards for the Professional Practice of Internal Auditing (Standards) INTERNATIONAL STANDARDS FOR THE PROFESSIONAL PRACTICE OF INTERNAL AUDITING (STANDARDS) Attribute Standards 1000 Purpose, Authority, and Responsibility The purpose, authority, and responsibility of the

More information

Data Standards in Oil & Gas

Data Standards in Oil & Gas Data Standards in Oil & Gas September, 2014 Business challenges currently impacting data standards in the E&P Marketplace Mergers and acquisitions have caused data challenges in identifying common field

More information

Project Risk Management

Project Risk Management Hujambo (Swahili) Project Management Process Groups Initiating Planning Executing Monitoring & Controlling Closing Project 4. Integration Management 5. Scope Knowledge Areas 6. Time 7. Cost 8. Quality

More information

Internal Audit and SOX Best Practices

Internal Audit and SOX Best Practices Internal Audit and SOX Best Practices ERIC LISTER RISK ADVISORY SERVICES Agenda Internal Audit Procedures and Examples SOX 404 Procedures and Examples Questions and Discussion Overview of IA Best Practices

More information

Guide to Internal Controls

Guide to Internal Controls Guide to Internal Controls Table of Contents Introduction to Internal Controls...3 Roles...4 Components....5 Control Environment...5 Risk assessment...6 Control Activities...7 Information & Communication...9

More information

ACFE FRAUD PREVENTION CHECK-UP ASSOCIATION OF CERTIFIED FRAUD EXAMINERS

ACFE FRAUD PREVENTION CHECK-UP ASSOCIATION OF CERTIFIED FRAUD EXAMINERS ACFE FRAUD PREVENTION ASSOCIATION OF CERTIFIED FRAUD EXAMINERS ACFE FRAUD PREVENTION One of the ACFE s most valuable fraud prevention resources, the ACFE Fraud Prevention Check-Up is a simple yet powerful

More information

Standards for Internal Control in New York State Government 2016 Update

Standards for Internal Control in New York State Government 2016 Update Standards for Internal Control in New York State Government 2016 Update Presented to the New York State Internal Control Association John F. Buyce Audit Director April 28, 2016 1 Last Revised in 2007 A

More information

Maryland School for the Deaf

Maryland School for the Deaf Audit Report Maryland School for the Deaf December 2015 OFFICE OF LEGISLATIVE AUDITS DEPARTMENT OF LEGISLATIVE SERVICES MARYLAND GENERAL ASSEMBLY For further information concerning this report contact:

More information

An Overview of the 2013 COSO Framework. August 2013

An Overview of the 2013 COSO Framework. August 2013 An Overview of the 2013 COSO Framework August 2013 Introduction Dean Geesler, KPMG Senior Manager Course Objectives Summarize the key changes from the 1992 Framework to the 2013 Framework including the

More information

Identifying and Assessing the Risks of Material Misstatement through Understanding the Entity and Its Environment

Identifying and Assessing the Risks of Material Misstatement through Understanding the Entity and Its Environment ISA 315 February 2008 International Standard on Auditing Identifying and Assessing the Risks of Material Misstatement through Understanding the Entity and Its Environment INTERNATIONAL STANDARD ON AUDITING

More information

To the members of the International Ethics Standards Board for Accountants:

To the members of the International Ethics Standards Board for Accountants: Ken Siong IESBA Technical Director International Ethics Standards Board for Accountants 545 Fifth Avenue, 14th Floor New York, NY 10017 August 18, 2014 Audit Tax Advisory Kim Gibson Global head - Independence

More information

AN AUDIT OF INTERNAL CONTROL THAT IS INTEGRATED WITH AN AUDIT OF FINANCIAL STATEMENTS: GUIDANCE FOR AUDITORS OF SMALLER PUBLIC COMPANIES

AN AUDIT OF INTERNAL CONTROL THAT IS INTEGRATED WITH AN AUDIT OF FINANCIAL STATEMENTS: GUIDANCE FOR AUDITORS OF SMALLER PUBLIC COMPANIES 1666 K Street, NW Washington, D.C. 20006 Telephone: (202) 207-9100 Facsimile: (202) 862-8430 www.pcaobus.org PRELIMINARY STAFF VIEWS AN AUDIT OF INTERNAL CONTROL THAT IS INTEGRATED WITH AN AUDIT OF FINANCIAL

More information

Chapter 2 (new version)

Chapter 2 (new version) Chapter 2 (new version) MULTIPLE CHOICE 1. An agreement between two entities to exchange goods or services or any other event that can be measured in economic terms by an organization is a) give-get exchange

More information

and Assessing the Risks of Material Misstatement through Understanding the Entity and Its Environment

and Assessing the Risks of Material Misstatement through Understanding the Entity and Its Environment IFACIAAS Board IAASB Main Agenda (April 2013) Agenda Iten 5-D Final Pronouncement March 2012 International Standard on Auditing ISA 315 (Revised), Identifying and Assessing the Risks of Material Misstatement

More information

LINK Darla Hill. Office of University Audits. Director, CPA, CIA, CFE https://www.audits.uillinois.edu/

LINK Darla Hill. Office of University Audits. Director, CPA, CIA, CFE https://www.audits.uillinois.edu/ LINK 2017 Office of University Audits Darla Hill Director, CPA, CIA, CFE https://www.audits.uillinois.edu/ Agenda Internal Control Concepts Fraud Scenarios and Internal Control Impacts Internal Audits

More information