INTERNAL CONTROLS AUDITOR JOHN BYRD, SENIOR AUDITOR TONYA CARRIGAN, SENIOR AUDITOR

Size: px
Start display at page:

Download "INTERNAL CONTROLS AUDITOR JOHN BYRD, SENIOR AUDITOR TONYA CARRIGAN, SENIOR AUDITOR"

Transcription

1 1 INTERNAL CONTROLS FOR THE BEGINNING AUDITOR JOHN BYRD, SENIOR AUDITOR TONYA CARRIGAN, SENIOR AUDITOR UF HEALTH SHANDS HOSPITAL AHIA 32 nd Annual Conference August 25-28, 2013 Chicago, Illinois

2 Two Academic Medical Centers with Level 1 Trauma Centers UF Health Shands Hospital UF Health Jacksonville Hospitals UF Health Shands Cancer Hospital UF Health Shands Children s Hospital UF Health Rehab Hospital UF Health Shands Psychiatric Hospital UF faculty physicians provide outpatient care in more than 80 UF Clinics

3 3 Audit Services Provides Audit Services to all Shands Hospitals Provide approximately 2,200 Hours Annually to the External Audit Department 1 Director IT Audit Manager 6 Senior Auditors 1 Staff Auditor

4 4 Better Known for:

5 5 Presentation ti Objectives: Explain the relationship between risk and control Provide an understanding di of internal controls Explain the importance of implementing an internal control framework Learn to identify internal controls within processes Examine and understand d common controls

6 Adding Value 6 Internal Auditors Can Add Value by: Reviewing Critical Control Environments and Risk Management Providing Advice on Control System Improvement and Design Implementing Risk-Based Audit Approach Directing Audit Resources to Most Important Areas of the Organization

7 7 Objectives and Risk Objective: All businesses have an objective In healthcare it is usually to Deliver Quality Patient Care Risks: Enterprise Risk Management ERM Framework for management to identify risk

8 8 Internal Controls to the Rescue

9 9 Internal Controls COSO Definition It Internal control is broadly defined d as a process, effected by an entity's board of directors, management and other personnel, designed to provide reasonable assurance regarding the achievement of objectives in the following categories: 1. Effectiveness and efficiency of operations. 2. Reliability of financial reporting. 3. Compliance with applicable laws and regulations.

10 10 Internal controls include: Definition Continued Promoting efficient and effective operations Safeguarding organizational resources Increasing reliability of information Rd Reducing surprises and unexpected outcomes Assuring compliance with policies, procedures and applicable laws and regulations

11 11 Control Framework Established process for the application and testing of an organization s control environment

12 12 COSO and COBIT COSO Committee of Sponsoring Organizations of the Treadway Commission Jointly Sponsored by: Five Organizations Including the IIA The Institute t of Internal Auditors COBIT COBIT 5 is the latest edition of ISACAs ISACA s globally accepted framework Provides framework for IT Control Testing

13 COSO Framework 13 New Frame work introduced in 2013 Control Environment Risk Assessment Control Activities Information and Communication The COSO Cube Monitoring Activities COSO Executive Summary

14 Control Environment 14 Sets the Tone for an organization Provides Structure Management s philosophy, assigned responsibilities COSO Executive Summary

15 15 Control Environment Examples Examples: Tone at the Top Internal Control Policy Compliance Program Code of Conduct

16 16 Risk Assessment Established objectives linked at different levels Identification of relevant risk to the achievement of the objectives Special risk are those specific to an industry COSO Executive Summary

17 17 Risk Assessment Mechanism to Identify Risk Control Self Assessments Meetings with Management Risk Matrix ERM Enterprise Risk Management COSO Executive Summary

18 18 Control Activities Policies and Procedures that help mitigate risk and assist management in meeting their hi objectives Heart and Soul of control testing

19 19 Control Activities Examples Examples: Approvals/Authorizations Reconciliations Segregations of Duties Verifications Security of Assets

20 Information and 20 Communication Necessary for the entity to carry out internal control responsibilities to support the achievement of its objectives Communication is the continual process of providing, sharing, and obtaining necessary information COSO Executive Summary

21 21 Examples: Information and Communication Present properly the transactions and related disclosures in the financial statements Provide and communicate relevant and accurate information to enable decision making

22 COBIT 22 Based on 5 Principles Principle 1: Meeting Stakeholder Needs Principle 2: Covering the Enterprise End-to-End Principle 3: Applying a Single, Integrated Framework Principle 4: Enabling a Holistic Approach Principle 5: Separating Governance From Management ISACA.org

23 TYPES of CONTROLS 23 Preventative Designed to prevent errors or irregularities Approvals Segregation of Duties (SOD) Detective Designed to detect errors or irregularities Reconciliations Cash Counts

24 TYPES of CONTROLS 24 Corrective Designed to correct errors or irregularities Insurance Policy Compensating For inadequate control environment Management Review

25 25 Limitations of Controls Existence of the inherent limitations it ti No Absolute Assurance Cost/Benefit Human element Collusion Judgment Management M t Override Breakdowns

26 26 Identifying i Controls and Controls by Area

27 27 Key and Non-Key Key Controls Significant controls within the business process, which if operating correctly will both ensure and give assurance that the organization is achieving its key business objectives [1] Provide reasonable assurance over the reliability of financial i reporting and the preparation of the financial i statements (ICFR) Non-Key Still Important Key Controls, The Solution for Sarbanes-Oxley Internal Control Compliance by James Brady Vorhies, CIA,CISA,CPA Institute of Internal Auditors Research Foundation

28 28 Considerations When Identifying Controls Where are the points in the flow of transactions where errors can occur? Who performs the control? Does the control depend on IT? What could go wrong?

29 29 Tools Risk Assessments Narratives Walk-Throughs Flow Charts

30 30 Risk Assessments Internal Control Self Assessments Meetings with Management Risk Identified from Other Audits Known Rik Risk within ihi the Id Industry

31 31 Narratives Narratives Describes a Process From Beginning to End Details Significant ifi Steps within the Process Identifies Key and Non-Key Controls Helps to Identify Gaps Ongoing and Updated on an Annual Basis

32 32 Walk-Throughs Walk-Throughs Begins at Initiation of Major Class of Transactions Walk-Through One Transaction Question Personnel on Important Processing Controls Identify Exceptions to the Identified Process

33 33 Flow Charts Flow Charts Use Basic Type of Flow Chart Functional Atiiti Activities It Interactt Process Sequence and Relationships Keep it Simple Map the Important Processes Identify Key Controls Use Software for Assistance eg: Visio

34 34 Significant Areas ITGC General IT Controls Revenue Ancillary Pharmacy Operating Rooms Labs

35 35 Expenditures Payroll Accounts Payable Fixed Assets Inventory T reasury Financial Reporting Quality and Governance Significant Areas

36 36 ITGC General IT Controls ITGC General IT Controls Segregation of Duties Application Controls Access Controls Privileged Accounts Disaster Recovery Management

37 37 Patient Revenue Patient Revenue A/R Reconciliations Valuation of Bad Debt/Contractuals Medical Records/Coding di Billing Charge Capture

38 38 Expenditures Expenditures Accounts payable Purchasing Purchasing cards

39 HR and Payroll 39 HR and Payroll Hiring Payroll Processing Training i Pension Other

40 40 Fixed Assets Fixed Assets Acquisition Depreciation Fixed Asset Reconciliation Monthly reconciliation to detail Other

41 41 Inventory Acquisition Consignment Perpetual Records Other Inventory

42 Financial Reporting 42 Financial Reporting Balance Sheet Account Reconciliations New G/L Accounts and Cost Centers Monthly Financial Statement Review Journal Entries

43 43 Treasury Treasury Wire Transfers Investments Cash collections Other

44 Pharmacy 44 Pharmacy Policies and procedures SOD Monitoring of Controlled Substances ADC Inventory Formulary

45 45 OR/Surgery OR/Surgery Policies and procedure over: Start and Stop Times Vendor Access Room Scheduling Preference Cards Patient Identification and Safety Completion of the Charge List

46 46 Other Ancillary Labs/Radiology/Cardiology Charge Capture Reconciliation Policies and procedures PFS/Admissions Plii Policies and Procedures Proper Financial Class Assignment on Admission Pre-Certs and Authorizations Billing Edits Denial Tracking

47 47 Quality and Governance Policies and Procedures SOD Quality and Governance Prevention of Readmissions Incident Reporting Disaster Drills Regulation Compliance

48 52 TIPS Beware of Reliance on System Controls Always Maintain Healthy Skepticism Trust but Verify Know Your Business Balance Your Control Count Think Critically Remember the IIA Code of Ethics

49 53 Thank You UF Health Shands Hospital John Byrd, Senior Auditor Tonya Carrigan, Senior Auditor

50 Save the Date September 21-24, rd Annual Conference Austin, Texas 54

Internal Financial Control (IFC)& Internal Financial Controls over Financial Reporting (IFCoFR)

Internal Financial Control (IFC)& Internal Financial Controls over Financial Reporting (IFCoFR) Internal Financial Control (IFC)& Internal Financial Controls over Financial Reporting (IFCoFR) Origin of IFC The first significant focus on internal control certification related to financial reporting

More information

GAIT FOR BUSINESS AND IT RISK

GAIT FOR BUSINESS AND IT RISK GAIT FOR BUSINESS AND IT RISK (GAIT-R) The Institute of Internal Auditors March 2008 Table of Contents 1. Introduction...1 2. Executive Summary...2 3. Why GAIT-R?...4 4. The GAIT-R Principles...6 5. GAIT-R

More information

The most commonly applied model for designing and auditing internal

The most commonly applied model for designing and auditing internal Fair Value Accounting Fraud: New Global Risks and Detection Techniques By Gerard M. Zack Copyright 2009 by Gerard M. Zack Appendix C Internal Controls over Fair Value Accounting Applications The most commonly

More information

38 Years of Excellent Client Service New COSO Model and How Internal Controls Help to Reduce Opportunity for Fraud

38 Years of Excellent Client Service New COSO Model and How Internal Controls Help to Reduce Opportunity for Fraud 38 Years of Excellent Client Service New COSO Model and How Internal Controls Help to Reduce Opportunity for Fraud Presented By William Blend, CPA, CFE Session Overview Review the new COSO model on internal

More information

PREPARING A RISK BASED AUDIT WORK PROGRAM

PREPARING A RISK BASED AUDIT WORK PROGRAM 1 PREPARING A RISK BASED AUDIT WORK PROGRAM BAILEY JORDAN PARTNER, GRC PRACTICE LEADER GRANT THORNTON, LLP DAVID TYLER PRINCIPAL, HEALTH CARE ADVISORY GRANT THORNTON, LLP AHIA 32 nd Annual Conference August

More information

FRAUD SCHEMES. South Carolina HFMA Finance & Reimbursement Forum. November 13, 2012 WITH RELATED INTERNAL CONTROLS

FRAUD SCHEMES. South Carolina HFMA Finance & Reimbursement Forum. November 13, 2012 WITH RELATED INTERNAL CONTROLS FRAUD SCHEMES WITH RELATED INTERNAL CONTROLS South Carolina HFMA Finance & Reimbursement Forum November 13, 2012 2 Fraud Facts: Estimated loss of 5% of annual revenues to occupational fraud Financial statement

More information

PART 6 - INTERNAL CONTROL

PART 6 - INTERNAL CONTROL PART 6 - INTERNAL CONTROL INTRODUCTION The A-102 Common Rule and OMB Circular A-110 (2 CFR part 215) require that non-federal entities receiving Federal awards (i.e., auditee management) establish and

More information

Evaluenz Special Edition on Internal Controls Over Financial Reporting (ICFR) 2016

Evaluenz Special Edition on Internal Controls Over Financial Reporting (ICFR) 2016 Greetings from Evaluenz!! We are pleased to present you Evaluenz Connect Special Edition on Internal Controls Over Financial Reporting (ICFR), a publication, sharing knowledge and insight with respect

More information

9. Internal control Internal control, as defined in accounting and auditing, is a process for assuring achievement of an organization's objectives in

9. Internal control Internal control, as defined in accounting and auditing, is a process for assuring achievement of an organization's objectives in 9. Internal control Internal control, as defined in accounting and auditing, is a process for assuring achievement of an organization's objectives in operational effectiveness and efficiency, reliable

More information

Internal Controls. June-20-17

Internal Controls. June-20-17 Internal Controls June-20-17 Background The Audit Committee is responsible for ensuring the adequacy and effectiveness of HRM s systems of internal control in relation to financial controls and risk management

More information

COSO What s New, What s Changed, Why Does it Matter and Other Frequently Asked Questions

COSO What s New, What s Changed, Why Does it Matter and Other Frequently Asked Questions COSO 2013 What s New, What s Changed, Why Does it Matter and Other Frequently Asked Questions Today s Presenter Jonathan Reiss is a Director in Protiviti s New York office in the Internal Audit Practice.

More information

Private Company Services. Private companies: are your internal controls supporting your business strategy?*

Private Company Services. Private companies: are your internal controls supporting your business strategy?* Private Company Services Private companies: are your internal controls supporting your business strategy?* private companies and internal controls Benefits for private companies // 3 Internal controls

More information

Internal Controls: Need Them, Have Them, Love Them

Internal Controls: Need Them, Have Them, Love Them Internal Controls: Need Them, Have Them, Love Them Tiffany R. Winters, Esquire twinters@bruman.com Brustein & Manasevit Fall Forum 2010 Why Do We Have Internal Controls? The Federal Managers Financial

More information

Diving into the 2013 COSO Framework. Presented by: Ronald A. Conrad

Diving into the 2013 COSO Framework. Presented by: Ronald A. Conrad Diving into the 2013 COSO Framework Presented by: Ronald A. Conrad 2 Objectives Obtain an understanding of why the COSO Framework has been updated Understand how the framework has changed Identify the

More information

Implementation Tool for Auditors

Implementation Tool for Auditors Implementation Tool for Auditors CANADIAN AUDITING STANDARDS (CAS) DECEMBER 2017 STANDARD DISCUSSED CAS 315, Identifying and Assessing the Risks of Material Misstatement through Understanding the Entity

More information

Internal Control Questionnaire and Assessment

Internal Control Questionnaire and Assessment Bureau of Financial Monitoring and Accountability Florida Department of Economic Opportunity September 30, 2017 107 East Madison Street Caldwell Building Tallahassee, Florida 32399 www.floridajobs.org

More information

Internal Control Questionnaire and Assessment

Internal Control Questionnaire and Assessment Bureau of Financial Monitoring and Accountability Florida Department of Economic Opportunity September 15, 2016 107 East Madison Street Caldwell Building Tallahassee, Florida 32399 www.floridajobs.org

More information

SOX perspective of internal control & COSO, COBIT Control frameworks.

SOX perspective of internal control & COSO, COBIT Control frameworks. SOX perspective of internal control & COSO, COBIT Control frameworks. Applies to: Business Experts. Summary An effective internal control is foundation of safe and sound organizational financial policy

More information

Internal Controls: Providing an Effective Control Environment. Why This Session Is Needed. Lesson Overview & Module Objectives

Internal Controls: Providing an Effective Control Environment. Why This Session Is Needed. Lesson Overview & Module Objectives Internal Controls: Providing an Effective Control Environment Internal Controls 1 Why This Session Is Needed Uniform Guidance has expanded the requirements and increased the focus on internal controls

More information

Committee for Senior Business Administrators. Segregation of Duties

Committee for Senior Business Administrators. Segregation of Duties Committee for Senior Business Administrators Segregation of Duties Presented by: Tammy R. Hoskens and Margaret (Peggy) B. Zapalac University Risk and Compliance May 21, 2009 Segregation of Duties Segregation

More information

9/17/2017. An Overview of COSO s New Framework and Implementation Guidance SPEAKER. Laura Harden, CPA History

9/17/2017. An Overview of COSO s New Framework and Implementation Guidance SPEAKER. Laura Harden, CPA History An Overview of COSO s New Framework and Implementation Guidance SPEAKER Laura Harden, CPA lharden@cbh.com History 2 1 About COSO Committee of Sponsoring Organizations Formed in 1985 to sponsor the National

More information

Internal Controls Integrating COSO

Internal Controls Integrating COSO Community Action Partnership 2016 Annual Convention August 30 September 2, 2016 Austin, TX J.W. Marriott Austin Internal Controls Integrating COSO Thursday, September 1, 2016 9:15 am 10:45 am Presented

More information

Internal Controls and the Internal Auditor. Presented By: Richard Kudlik, CPA

Internal Controls and the Internal Auditor. Presented By: Richard Kudlik, CPA Internal Controls and the Internal Auditor Presented By: Richard Kudlik, CPA Interrelated Components Control Environment Risk Assessment Control Activities Information and Communication Monitoring What

More information

Using the COSO Map. Unpublished Article By Larry Hubbard

Using the COSO Map. Unpublished Article By Larry Hubbard Unpublished Article By Larry Hubbard Internal Control Integrated Framework published by the Committee of Sponsoring Organizations (COSO) of the Treadway Commission How many times have we read articles

More information

Audit Training-of-Trainers Workshop, November 2014, Vienna Components of internal control within organization

Audit Training-of-Trainers Workshop, November 2014, Vienna Components of internal control within organization Audit Training-of-Trainers Workshop, 18-19 November 2014, Vienna Components of internal control within organization Andrei Busuioc, Senior Financial Management Specialist, CFRR Session objectives The session

More information

The Basics of Internal Controls & Segregation of Duties

The Basics of Internal Controls & Segregation of Duties The Basics of Internal Controls & Segregation of Duties Presented by: Kevin L. Pegish, CPA Senior Audit Manager Northwest Region klpegish@ohioauditor.gov Internal Controls, we will discuss the following:

More information

Community Bankers Conference

Community Bankers Conference 3rd Annual Regional and Community Bankers Conference The Federal Reserve Bank of Boston Disclaimer NEVER WRONG DON T COMPLETELY RELY UPON Recent Developments in Audit Practice SOX, FDICIA 112, Other Robert

More information

Seminar Internal Control Identification and Filtering

Seminar Internal Control Identification and Filtering Seminar Internal Control Identification and Filtering 4 March 2011 by Stephen Ho Definition The process designed, implemented and maintained by those charged with governance, management and other personnel

More information

BUSINESS CPA EXAM REVIEW V 3.0. For Exams Scheduled After March 31, 2017

BUSINESS CPA EXAM REVIEW V 3.0. For Exams Scheduled After March 31, 2017 For Exams Scheduled After March 31, 2017 CPA EXAM REVIEW BUSINESS UPDATES AND ACADEMIC HELP Click on Community and Support at www.becker.com/cpa CUSTOMER SERVICE AND TECHNICAL SUPPORT Call 1-877-CPA-EXAM

More information

29 th Regional Conference of WIRC

29 th Regional Conference of WIRC 29 th Regional Conference of WIRC Internal Financial Control - Auditors responsibility The Lalit International, Mumbai 6 December 2014 Contents 1 Provisions of Companies Act, 2013 2 Auditors responsibility

More information

Internal Control Systems

Internal Control Systems Internal Control Systems What are Internal Controls? Internal Controls are a set of rules, policies, and procedures a municipality can implement to provide reasonable assurances that: its financial reports

More information

2/27/2017. Segregation of Duties/ Internal Controls. Objectives. Agenda

2/27/2017. Segregation of Duties/ Internal Controls. Objectives. Agenda Segregation of Duties/ Internal Controls 2017 WASBO Accounting Conference David Maccoux, Shareholder Objectives Discuss failures of internal controls to detect or prevent fraud and learn how to implement

More information

IPO Readiness. Sarbanes-Oxley Compliance & Other Considerations. Presented by:

IPO Readiness. Sarbanes-Oxley Compliance & Other Considerations. Presented by: IPO Readiness Sarbanes-Oxley Compliance & Other Considerations Presented by: IPO Readiness Enhanced Financial / Legal compliance SEC / Stock Exchange Compliance Entity Structure / Registration Filing Requirements

More information

Protecting Fixed Assets: Internal Controls for Non Profits

Protecting Fixed Assets: Internal Controls for Non Profits Protecting Fixed Assets: Internal Controls for Non Profits 25 September 2012 Community Sector Council Newfoundland and Labrador (CSC) Darlene Scott, Senior Program Associate darlenescott@cscnl.ca www.communitysector.nl.ca

More information

Risk Management. Body of Knowledge Review Based on the 2014 ACMPE Exam Blueprint

Risk Management. Body of Knowledge Review Based on the 2014 ACMPE Exam Blueprint Body of Knowledge Review Based on the 2014 ACMPE Exam Blueprint Risk Management Under HIPAA regulations, what is the definition of a healthcare provider? 1 Risk Management A person or organization that

More information

POLICY. Number: Title: Internal Control Responsible Office: USF System Audit I. PURPOSE AND INTENT

POLICY. Number: Title: Internal Control Responsible Office: USF System Audit I. PURPOSE AND INTENT 1 2 3 USF System USF USFSP USFSM POLICY 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 Number: 0-023 Title: Internal Control Responsible Office:

More information

INTERNAL CONTROLS 101

INTERNAL CONTROLS 101 INTERNAL CONTROLS 101 Presented by: Christopher White, CPA Kristina Hoyng, CPA Northwest Region Overview of Topic Internal Controls - The Basics Components of Internal Controls Benefits of Internal Controls

More information

audit typology 115 audit universe 101 data and information pool 103 definition 101 structure and content 101

audit typology 115 audit universe 101 data and information pool 103 definition 101 structure and content 101 F Subject Index A ABAP 411 ABAP report for IT audit 412 ABAP workbench 417 accruals 319 for contingent losses 323 for legal and consulting costs 324 accrued liabilities audit 318 accruals for contingent

More information

Private Client Services Are your internal controls supporting your business strategy?*

Private Client Services Are your internal controls supporting your business strategy?* Private Client Services Are your internal controls supporting your business strategy?* Featured Article Series Issue 1 March 2008 *connectedthinking pwc We know you want more than just another consultant

More information

Single Audit Update: Internal Control over Compliance and the GAO s Green Book. MSBO s 80 th Annual Conference April 19, 2018

Single Audit Update: Internal Control over Compliance and the GAO s Green Book. MSBO s 80 th Annual Conference April 19, 2018 Single Audit Update: Internal Control over Compliance and the GAO s Green Book MSBO s 80 th Annual Conference April 19, 2018 Presented by: Stephen W. Blann, CPA, CGFM, CGMA Director of Governmental Audit

More information

A Discussion About Internal Controls February 2016

A Discussion About Internal Controls February 2016 A Discussion About Internal Controls February 2016 What we will cover today 001 Introductions 002 Defining Internal Controls 003 COSO Internal Controls Integrated Framework 004 Approach to Designing Internal

More information

1. Corporate management (including the CEO) must certify monthly and annually their organization s internal controls over financial reporting.

1. Corporate management (including the CEO) must certify monthly and annually their organization s internal controls over financial reporting. Chapter 1 Auditing and Internal Control TRUE/FALSE 1. Corporate management (including the CEO) must certify monthly and annually their organization s internal controls over financial reporting. F 2. Both

More information

Internal Controls for Deans, Directors and Chairs

Internal Controls for Deans, Directors and Chairs Internal Controls for Deans, Directors and Chairs Presented by: Laura Howat, CPA Controller/Director Financial Management Financial and Business Services Phone: 801-581-5077 Email: laura.howat@admin.utah.edu

More information

In Control: Getting Familiar with the New COSO Guidelines. CSMFO Monterey, California February 18, 2015

In Control: Getting Familiar with the New COSO Guidelines. CSMFO Monterey, California February 18, 2015 In Control: Getting Familiar with the New COSO Guidelines CSMFO Monterey, California February 18, 2015 1 Background on COSO Part 1 2 Development of a comprehensive framework of internal control Internal

More information

Diocese of Covington Policies & Procedures Manual Section: Compliance Accounting Policy: Internal Control & Segregation of Duties

Diocese of Covington Policies & Procedures Manual Section: Compliance Accounting Policy: Internal Control & Segregation of Duties Internal Control refers to the policies and procedures established to provide reasonable assurance that parish assets are safeguarded, that accountability is achieved, and that errors in financial records

More information

Common Questions on Segregation of Duties

Common Questions on Segregation of Duties Common Questions on Segregation of Duties Why should duties be segregated? What duties should be segregated? How can management determine if duties are properly segregated? What if management has inadequate

More information

The University of Texas MD Anderson Cancer Center Internal Audit Annual Report for FY 2017

The University of Texas MD Anderson Cancer Center Internal Audit Annual Report for FY 2017 Purpose of the Annual Report The purpose of the internal audit annual report is to provide information on the assurance services, consulting services, and other activities of the internal audit function.

More information

Internal Audit How the Internal Audit Function Facilitates Internal Controls. Office of the City Auditor City of Tallahassee

Internal Audit How the Internal Audit Function Facilitates Internal Controls. Office of the City Auditor City of Tallahassee Internal Audit How the Internal Audit Function Facilitates Internal Controls Office of the City Auditor City of Tallahassee 1 Internal Audits and Internal Controls Session Purpose: How does an internal

More information

Navigating the PCAOB s and SEC s internal control expectations A discussion. June 2015

Navigating the PCAOB s and SEC s internal control expectations A discussion. June 2015 Navigating the PCAOB s and SEC s internal control expectations A discussion June 2015 Setting the scene ICFR guidance: PCAOB Auditing Standard No. 5 (May 2007) PCAOB staff views: An Audit of Internal Control

More information

Guide to Internal Controls

Guide to Internal Controls Guide to Internal Controls Table of Contents Introduction to Internal Controls...3 Roles...4 Components....5 Control Environment...5 Risk assessment...6 Control Activities...7 Information & Communication...9

More information

A-9: Audit Committee Effectiveness

A-9: Audit Committee Effectiveness A-9: Audit Committee Effectiveness Renée W. Jaenicke, CPA, CIA Renown Health 2011 AHIA Annual Conference www.ahia.org Renown Health and Internal Audit Our Journey Sources and Presentations Please ask questions

More information

Internal Control in Higher Education

Internal Control in Higher Education Internal Control in Higher Education Daniel Adams Office of Audit Services Audit Services Mission To provide assurance and advisory services that are independent, objective and risk-based in order to protect

More information

Common Questions on Segregation of Duties

Common Questions on Segregation of Duties Common Questions on Segregation of Duties Why should duties be segregated? What duties should be segregated? How can management determine if duties are properly segregated? What if management has inadequate

More information

The Internal Control Framework

The Internal Control Framework The Internal Control Framework CA. Rajkumar S Adukia B.Com(Hons.) FCA, ACS,MBA, AICWA, LLB,Dip In IFRS(UK) rajkumarfca@gmail.com www.caaa.in 9820061049/9323061049 To receive regular updates kindly send

More information

Quality Assessments what you need to know

Quality Assessments what you need to know Quality Assessments what you need to know Patty Miller, Partner Deloitte & Touche LLP Cavell Alexander, VP-Internal Audit Intermountain Healthcare Overview of requirements Scope of assessment Approaches

More information

Understanding Internal Controls Office of Internal Audit

Understanding Internal Controls Office of Internal Audit Understanding Internal Controls Office of Internal Audit July 2015 Objectives for this manual Provide guidance to help management understand their responsibility to ensure that internal controls are established,

More information

Practices in Enterprise Risk Management

Practices in Enterprise Risk Management Practices in Enterprise Risk Management John Foulley Risk Management Practices Head SAS Institute Asia Pacific What is ERM? Enterprise risk management is a process, effected by an entity s board of directors,

More information

Internal controls over Financial Reporting Key concepts. Presentation by Jayesh Gandhi at WIRC

Internal controls over Financial Reporting Key concepts. Presentation by Jayesh Gandhi at WIRC Internal controls over Financial Reporting Key concepts Presentation by Jayesh Gandhi at WIRC Page 1 ICFR Key Concepts WIRC 28 May 2016 Agenda Scope and requirements Overview of internal controls as per

More information

Road to Self Governance

Road to Self Governance Road to Self Governance Transform internal controls; sustain business performance 8 January 2015 Contents 1. Setting the Context 2. What needs to be done 3. Perspectives on IFC coverage 4. Leveraging IFC

More information

AUDITING. Auditing PAGE 1

AUDITING. Auditing PAGE 1 AUDITING Auditing 1. Professionalism The International Professional Practices Framework (IPPF) is the conceptual framework that organizes authoritative guidance promulgated by The Institute of Internal

More information

CHAPTER 5 INFORMATION TECHNOLOGY SERVICES CONTROLS

CHAPTER 5 INFORMATION TECHNOLOGY SERVICES CONTROLS 5-1 CHAPTER 5 INFORMATION TECHNOLOGY SERVICES CONTROLS INTRODUCTION In accordance with Statements on Auditing Standards Numbers 78 and 94, issued by the American Institute of Certified Public Accountants

More information

Sarbanes-Oxley Act of 2002 Can private businesses benefit from it?

Sarbanes-Oxley Act of 2002 Can private businesses benefit from it? Sarbanes-Oxley Act of 2002 Can private businesses benefit from it? As used in this document, Deloitte means Deloitte Tax LLP, which provides tax services; Deloitte & Touche LLP, which provides assurance

More information

Internal Auditing 101 with Panel Discussion. VGFOA Virginia Beach May 2013

Internal Auditing 101 with Panel Discussion. VGFOA Virginia Beach May 2013 Internal Auditing 101 with Panel Discussion VGFOA Virginia Beach May 2013 Introduction of Our Panel Mike Garber Partner, PBMares Jon Munch Financial Services Division Chief - Fauquier County Government

More information

COSO Updates and Expectations. IIA San Diego Chapter January 8, 2014

COSO Updates and Expectations. IIA San Diego Chapter January 8, 2014 COSO Updates and Expectations IIA San Diego Chapter January 8, 2014 Agenda Overview of 2013 Internal Control-Integrated Framework and Companion Guidance 2013 Framework General Enhancements by Component

More information

Strengthening Business Practices:

Strengthening Business Practices: Strengthening Business Practices: The Language of Our Control Environment Debbie Rico Internal Controls We are Like a Business Good control is good business Good control is everyone s business You play

More information

Success in Joint Ventures: Sustained Compliance and Audit Oversight

Success in Joint Ventures: Sustained Compliance and Audit Oversight Success in Joint Ventures: Sustained Compliance and Audit Oversight Gene DeLaddy, CIA Senior Vice President, Chief Compliance & Privacy Officer, Chief Audit Executive Dave Pyland, CPA Director, Internal

More information

WHITE PAPER INTERNAL CONTROL WITH ADRA

WHITE PAPER INTERNAL CONTROL WITH ADRA WHITE PAPER INTERNAL CONTROL WITH ADRA About this document The purpose of this document is to discuss internal control and how Adra products supports ERM (Enterprise Risk Management), internal control

More information

INTERNAL CONTROLS ON OUR CAMPUS. Kara Kearney-Saylor Director of Internal Audit, UB

INTERNAL CONTROLS ON OUR CAMPUS. Kara Kearney-Saylor Director of Internal Audit, UB INTERNAL CONTROLS ON OUR CAMPUS Kara Kearney-Saylor Director of Internal Audit, UB 1 Select headlines over the past 12 months.. Dennis Black under investigation for UB spending Former UB VP Dennis Black

More information

20 Years in the Making. Meet the New ICIF: Revisions to COSO s Internal Control Integrated Framework. Dr. Sandra Richtermeyer COSO Board Member

20 Years in the Making. Meet the New ICIF: Revisions to COSO s Internal Control Integrated Framework. Dr. Sandra Richtermeyer COSO Board Member Meet the New ICIF: Revisions to COSO s Internal Control Integrated Framework Dr. Sandra Richtermeyer COSO Board Member Associate Dean and Professor of Accountancy Xavier University Cincinnati Ohio USA

More information

[RELEASE NOS ; ; FR-77; File No. S ]

[RELEASE NOS ; ; FR-77; File No. S ] SECURITIES AND EXCHANGE COMMISSION 17 CFR PART 241 [RELEASE NOS. 33-8810; 34-55929; FR-77; File No. S7-24-06] Commission Guidance Regarding Management s Report on Internal Control Over Financial Reporting

More information

OPERATIONAL RISK EXAMINATION TECHNIQUES

OPERATIONAL RISK EXAMINATION TECHNIQUES OPERATIONAL RISK EXAMINATION TECHNIQUES 1 OVERVIEW Examination Planning Oversight Policies, Procedures, and Limits Measurement, Monitoring, and MIS Internal Controls and Audit 2 Risk Assessment: Develop

More information

POSITION DESCRIPTIONS

POSITION DESCRIPTIONS Chief Executive Officer Responsible for planning, directing, coordinating and controlling the overall operations of the organization and subsidiaries. Directs short and long-range functions including development

More information

Business Benefits by Aligning IT best practices

Business Benefits by Aligning IT best practices Business Benefits by Aligning IT best practices Executive Summary Since the Sarbanes-Oxley Act (Sarbanes-Oxley or SOX) was signed into law in 2002, many companies have adopted some IT practices to comply

More information

APPENDIX 2 COMMUNITY DEVELOPMENT COMMISSION FINANCIAL CHECKLIST REQUIRED FOR ALL APPLICANTS (A SITE VISIT MAY BE CONDUCTED LATER)

APPENDIX 2 COMMUNITY DEVELOPMENT COMMISSION FINANCIAL CHECKLIST REQUIRED FOR ALL APPLICANTS (A SITE VISIT MAY BE CONDUCTED LATER) REQUIRED FOR ALL APPLICANTS (A SITE VISIT MAY BE CONDUCTED LATER) AGENCY NAME: AGENCY ADDRESS AGENCY PHONE: DATE PREPARED: PREPARED BY: TITLE: EMAIL: AGENCY GENERAL INFORMATION EXECUTIVE DIRECTOR /CITY

More information

Analyzing and improving operational processes

Analyzing and improving operational processes Analyzing and improving operational processes 178 Overview Overview of Internal Audit Review of 2017 Protiviti Survey Health Care Internal Audit Use of Data Analytics Internal Audit Transformation Questions

More information

SEGREGATION OF DUTIES for SAP

SEGREGATION OF DUTIES for SAP SEGREGATION OF DUTIES for SAP SEGREGATION-OF-DUTIES In todays modern, technology driven world, segregation-of-duties (SoD) is enforced through business applications and ERP s, but highlighting breakdowns

More information

Internal Controls and Fraud Risks

Internal Controls and Fraud Risks Internal Controls and Fraud Risks Chris Alger, Director of Financial Operations 10/26/2018 Agenda Introduction Internal Control Framework Components of Fraud What s Next? What are Internal Controls? The

More information

After completing this Session, you should be able to answer the following questions:

After completing this Session, you should be able to answer the following questions: About this Course Welcome to CMA Auditing Course, Part II. Below, you will find a short summary of the modules. Upon registration, further introductory resources will tell you: How the course is organized

More information

PART 1: REVENUE INTEGRITY PROGRAM DESIGN, PROCESS AND IMPLEMENTATION CAROLINE RADER ZNANIEC OWNER/FOUNDER LUNA HEALTHCARE ADVISORS

PART 1: REVENUE INTEGRITY PROGRAM DESIGN, PROCESS AND IMPLEMENTATION CAROLINE RADER ZNANIEC OWNER/FOUNDER LUNA HEALTHCARE ADVISORS 1 PART 1: REVENUE INTEGRITY PROGRAM DESIGN, PROCESS AND IMPLEMENTATION CAROLINE RADER ZNANIEC OWNER/FOUNDER LUNA HEALTHCARE ADVISORS AHIA 33 rd Annual Conference September 21-24, 2014 Austin, Texas www.ahia.org

More information

Office of the City Manager

Office of the City Manager Office of the City Manager TO: FROM: Finance/Audit Committee Ruthe Holden, Internal Audit Manager SUBJECT: Final Fraud Risk Assessment Report-Phase 1 Recommendation This report is for information only.

More information

FRAUD AWARENESS UPDATE

FRAUD AWARENESS UPDATE Tammy Michaud, CPA, Principal Sarah Belliveau, CPA, Senior Manager FRAUD AWARENESS UPDATE berrydunn.com CATEGORIES OF FRAUD Asset misappropriations (stealing) Theft or misuse of assets Corruption Inappropriate

More information

BOARD OF REGENTS AUDIT/COMPLIANCE AND INVESTMENT COMMITTEE 3 STATE OF IOWA OCTOBER 24-25, 2012 INTERNAL AUDIT REPORTS ISSUED

BOARD OF REGENTS AUDIT/COMPLIANCE AND INVESTMENT COMMITTEE 3 STATE OF IOWA OCTOBER 24-25, 2012 INTERNAL AUDIT REPORTS ISSUED STATE OF IOWA OCTOBER 24-25, 2012 INTERNAL AUDIT REPORTS ISSUED Action Requested: Receive the original and follow-up internal audit reports. Contact: Todd Stewart Executive Summary: Completed institutional

More information

3/17/2016. Unleashing the Power of Data Analytics Presented to: 2016 Compliance Institute. Today s Agenda. What Makes CHAN Healthcare Unique

3/17/2016. Unleashing the Power of Data Analytics Presented to: 2016 Compliance Institute. Today s Agenda. What Makes CHAN Healthcare Unique Unleashing the Power of Data Analytics Presented to: 2016 Compliance Institute 2016 CHAN Healthcare 1 Today s Agenda What Makes CHAN Unique Adding Value through Data Analytics Using Data Analytics in the

More information

We will be pleased to discuss the attached comments with you and, if desired, to assist you in implementing any of the suggestions.

We will be pleased to discuss the attached comments with you and, if desired, to assist you in implementing any of the suggestions. Deloitte & Touche LLP 361 South Marine Corps Drive Tamuning, GU 96913 USA Tel: +1 (671) 646-3884 Fax: +1 (671) 649-4265 www.deloitte.com May 5, 2017 Dr. Theresa Koroivulaono President College of the Marshall

More information

GATU Webinar Part 1 March 2017 Presented by Carol Kraus, CPA

GATU Webinar Part 1 March 2017 Presented by Carol Kraus, CPA GATU Webinar Part 1 March 2017 Presented by Carol Kraus, CPA Definition of Internal Controls COSO Internal Control Framework Internal Controls (2 CFR 200.303) Grantee responsibilities Awarding state agency

More information

GFMIS. MIS MIS - BW SEM Operating System SAP R/3 (GFMIS) FI CO. e-payroll, e-pension AFMIS. ก ก (e-catalog,e-shopping list

GFMIS. MIS MIS - BW SEM Operating System SAP R/3 (GFMIS) FI CO. e-payroll, e-pension AFMIS. ก ก (e-catalog,e-shopping list ก GFMIS: ก. 1 GFMIS MIS ( ) MIS - BW SEM Operating System SAP R/3 (GFMIS) FM PO HR ก FI ก ก RP AP ก CM FA GL ก CO BIS. DPIS ก. e-procurement ก ก (e-catalog,e-shopping list e-auction) e-payroll, e-pension

More information

Alyssa G. Martin, CPA Brandon Tanous, CIA, Using the COSO CFE, CGAP, CRMA Framework to Develop a Strong and Preventive Control Environment

Alyssa G. Martin, CPA Brandon Tanous, CIA, Using the COSO CFE, CGAP, CRMA Framework to Develop a Strong and Preventive Control Environment Speakers Using the COSO Framework to Develop a Strong and Preventive Control Environment Weaver Public Sector CPE Event Alyssa G. Martin, CPA Dallas Executive Partner, Advisory Services 25+ years of public

More information

ADMINISTRATIVE RESPONSIBILITIES FOR UNIVERSITY AND COLLEGE ADMINISTRATORS, DEPARTMENT HEADS, AND DIRECTORS

ADMINISTRATIVE RESPONSIBILITIES FOR UNIVERSITY AND COLLEGE ADMINISTRATORS, DEPARTMENT HEADS, AND DIRECTORS ADMINISTRATIVE RESPONSIBILITIES FOR UNIVERSITY AND COLLEGE ADMINISTRATORS, DEPARTMENT HEADS, AND DIRECTORS Internal Controls & Your Role 1) Internal Accounting Controls - procedures that ensure compliance

More information

CHAPTER 2 THEORETICAL FOUNDATIONS. organization which responsible to record and employs physical resources and other

CHAPTER 2 THEORETICAL FOUNDATIONS. organization which responsible to record and employs physical resources and other CHAPTER 2 THEORETICAL FOUNDATIONS 2.1 Accounting Information System (AIS) Accounting information system can be defined as an integrated system within an organization which responsible to record and employs

More information

SAMPLE BEC SuperfastCPA Review Notes

SAMPLE BEC SuperfastCPA Review Notes BEC 2018 SuperfastCPA Review Notes Table of Contents Corporate Governance 1 Internal Control Frameworks 1 Enterprise Risk Management Frameworks 6 Other Regulatory Frameworks and Provisions 10 Economic

More information

INTERNAL CONTROL HANDBOOK

INTERNAL CONTROL HANDBOOK INTERNAL CONTROL HANDBOOK INTERNAL CONTROL HANDBOOK ILLINOIS STATE BOARD OF EDUCATION SCHOOL BUSINESS SERVICES DIVISION Revised July, 2017 Most Content remains the same as published in 1993 Prepared by

More information

Assistance Options to New Applicants and Sponsors in connection with Internal Controls over Financial Reporting

Assistance Options to New Applicants and Sponsors in connection with Internal Controls over Financial Reporting Technical Bulletin - AATB 1 Issued March 2008 Technical Bulletin Assistance Options to New Applicants and Sponsors in connection with Internal Controls over Financial Reporting This Technical Bulletin

More information

Risk management. Risk management system

Risk management. Risk management system Report on the main characteristics of the internal control and risk management system with respect to the accounting process according to Sec. 289 para. 4 of the German Commercial Code As an enterprise

More information

EY Center for Board Matters. Leading practices for audit committees

EY Center for Board Matters. Leading practices for audit committees EY Center for Board Matters for audit committees As an audit committee member, your role is increasingly complex and demanding. Regulators, standard-setters and investors are pressing for more transparency

More information

Company LOGO C B T. An Educational Computer Based Training Program

Company LOGO C B T. An Educational Computer Based Training Program C B T An Educational Computer Based Training Program The University of Texas at Dallas Compliance Training Effectively Controlling Risks Company Effectively Controlling Risks What is the purpose of this

More information

Financial Controls Checklist

Financial Controls Checklist Financial Controls Checklist Board of Health: Board of Health for the Leeds, Grenville & Lanark District Health Unit Period ended: Dec. 31/17 Objective: The objective of the Financial Controls Checklist

More information

Defining Payroll Process

Defining Payroll Process Defining Payroll Process Personal Services = Big Bucks Expenditure includes Adjusted gross pay Employer s share of benefits Payroll department Pays employees Strong internal controls needed 42 Payroll

More information

Financial Statement Close Process

Financial Statement Close Process Financial Statement Close Process Process Control Objective Risk Control Considerations Segregation of Duties Accounting functions are properly segregated. Unauthorized and inaccurate transactions may

More information

Auditing Standards and Practices Council

Auditing Standards and Practices Council Auditing Standards and Practices Council PHILIPPINE STANDARD ON AUDITING 315 UNDERSTANDING THE ENTITY AND ITS ENVIRONMENT AND ASSESSING THE RISKS OF MATERIAL MISSTATEMENT PHILIPPINE STANDARD ON AUDITING

More information