Corporate Governor. Providing vision and advice for management, boards of directors and audit committees Winter 2015

Size: px
Start display at page:

Download "Corporate Governor. Providing vision and advice for management, boards of directors and audit committees Winter 2015"

Transcription

1 Corporate Governor Providing vision and advice for management, boards of directors and audit committees Winter 2015 COSO 2013 framework boosts fraud risk assessment and prevention Fraud is among the most distasteful fare on management s plate. Not only is it an enormous, unplanned drain on company resources the Association of Certified Fraud Examiners (ACFE) estimates that fraud costs the typical company 5% of revenue 1 it s spiritually crippling as well. Fraud by company outsiders, as damaging as it may be, simply testifies to human greed and malevolence. Fraud by co-workers and colleagues, often long-serving and trusted, is a gut-wrenching betrayal of faith. For companies that may not have formally documented processes and controls designed to address fraud risk systematically, adopting COSO 2013 can jump-start a broad and far-reaching program of necessary fraud risk prevention. Companies that have more fully developed FRA processes and procedures in place will see implementing COSO 2013 as an opportunity to re-evaluate and strengthen their fraud prevention effort. Daily stories of pilfered passwords and leaked s have placed cyberfraud at the top of management s agenda. This heightened concern coincides with the guidance in COSO s Internal Control Integrated Framework: Framework and Appendices (COSO 2013), effective Dec. 15, 2014, that requires companies to do a fraud risk assessment (FRA). Clearly, now is the time for companies to comprehensively reassess their approach to assessing and mitigating potential fraud risks. 2 1 ACFE: Report to the Nations on Occupational Fraud and Abuse 2014 Global Fraud Study. See for more information. 2 COSO released a new report, COSO in the Cyber Age, which provides direction on how the Internal Control-Integrated Framework and the Enterprise Risk Management-Integrated Framework can help organizations manage cyberrisks. Visit to download the report.

2 COSO guidance on fraud risk assessment Principle 8 The discussion of fraud in COSO 2013 centers on Principle 8 of the framework: The organization considers the potential for fraud in assessing risks to the achievement of objectives. For most companies, under 1992 COSO, fraud risk was viewed primarily in terms of satisfying SOX requirements, i.e., identifying and preventing fraud risk at the transaction level, says Michael Rose, partner, Business Advisory Services. But in COSO 2013, fraud risk becomes a specific component in the overall risk assessment: It addresses fraud at the organization or entity level, not just the transaction level. COSO requires a strong internal control foundation that addresses fraud much more broadly: company objectives, strategy, operations, and compliance, as well as reporting both external and internal, financial and nonfinancial. Principle 8 describes four specific areas of concern. 1. Fraudulent financial reporting: This area has long been at the heart of the mission of COSO; indeed, it is the purpose for which COSO was originally founded in Fraudulent nonfinancial reporting: The inclusion of fraudulent nonfinancial reporting is a significant change from 1992 COSO. COSO 2013 mentions sustainability reporting, health and safety reports and reports, on employment activity as examples of nonfinancial reporting. 3. Misappropriation of assets: Principle 8 states that illegal marketing, theft of assets, theft of intellectual property, late trading, and money laundering are among the activities that may relate to unauthorized acquisition, use and disposal of assets. 4. Illegal acts: These are violations of laws or governmental regulations that could have a material direct or indirect impact on the external financial reports. Examples include bribery, corruption and insider trading. 2 CorporateGovernor Winter 2015

3 Points of focus The first point of focus in Principle 8 summarizes the above four areas: Considers various types of fraud The assessment of fraud considers fraudulent reporting, possible loss of assets, and corruption resulting from the various ways that fraud and misconduct can occur. The three remaining points of focus largely mirror those of the fraud triangle as discussed in SAS The standard describes an assessment of fraud risks considering three specific aspects: 1. Incentives and pressures to commit fraud that exist in the control environment 2. Opportunities for unauthorized acquisition, use, or disposal of assets, altering of the entity s reporting records, or committing other inappropriate acts 3. Attitudes and rationalization, i.e., how management and other personnel might engage in or justify inappropriate actions Management override of controls Management override figures prominently in the text of Principle 8. It is an action taken to override an entity s controls for an illegitimate purpose, including personal gain or an enhanced presentation of an entity s financial condition or compliance status. Management override generally occurs in the largest or most significant fraud occurrences and is not easily detected. As COSO 2013 states, management override should not be confused with management intervention, i.e., action that departs from controls designed for legitimate purposes. The degree to which management can intervene is determined by the board and audit committee s assessment of the control environment. Building a successful fraud prevention function on the COSO foundation One extremely useful document for management in assessing and enhancing the company s fraud risk function is Managing the Business Risk of Fraud: A Practical Guide, produced by The Institute of Internal Auditors (IIA), AICPA and the ACFE. It offers a highly detailed guide including a sample fraud policy document, fraud prevention scorecard, and lists of fraud exposures and controls of how organizations of various sizes and types can establish their own fraud risk management programs. The following discussion draws significantly from that publication. Fraud risk governance The FRA should be seen as part of the company s effort for strong corporate governance. This commitment requires a tone at the top that facilitates corporate cultures embracing strong governance practices, including written policies that describe the expectations of the board and senior management regarding fraud risk. But even companies with committed senior leadership may have inadequate FRA programs. Most companies have some written policies to manage individual fraud components say, expense account procedures. We have also noted that many companies engage in some fraud management activities to assess, identify and control override risks. What most companies don t do is concisely summarize these documents and activities, so they can communicate and evaluate the completeness and sufficiency of their fraud management processes. 3 AICPA Statements on Auditing Standards No. 99. See for more information. 3 CorporateGovernor Winter 2015

4 Fraud risk assessment The fraud risk assessment should ordinarily be conducted as part of a broader assessment of company risk in an enterprise risk management program. But the fraud risk assessment itself may initially be conducted as part of that process or on a standalone basis. Regulatory and legal misconduct, such as Foreign Corrupt Practices Act violations, as well as reputation risk, should also be considered. Assess and identify inherent risk The FRA starts with a brainstorming session that seeks to uncover the potential fraud risks in the organization, without consideration of mitigating controls. The review takes place and is shaped by the company s operating environment, including industry practices, business culture, the state of the economy, applicable regulatory regimes, company business practices (e.g., heavy reliance on cash transactions), and business conditions. Each area of risk fraudulent reporting, possible loss of assets, and corruption should be examined. The FRA should include: Consideration of all types of fraud schemes and scenarios The incentives (such as through compensation programs), pressures (a CFO that needs to hit an earnings estimate) and opportunities (a senior manager with management override ability) to commit fraud Assess likelihood and significance of fraud risk The next step is to assess the relative likelihood and potential significance of identified fraud risks. This review should be based on interviews with staff, including business process owners; known fraud schemes; and historical information, both internal and external to the entity. In assessing fraud risk significance, companies should consider not only exposures to assets and the financial statements, but risk to an organization s operations, brand value and reputation, as well as criminal, civil and regulatory liability. Factors in fraudulent reporting Principle 8 lists various considerations organizations should make when identifying ways fraud in reporting can occur: Management bias for instance, in selecting accounting principles Degree of estimates and judgments in external reporting Fraud schemes and scenarios common to the industry sectors and markets in which the entity operates Geographic regions where the entity does business Incentives that may motivate fraudulent behavior Nature of technology and management s ability to manipulate information Unusual or complex transactions subject to significant management influence Vulnerability to management override and potential schemes to circumvent existing control activities The IT fraud risks specific to the organization Importantly, the FRA needs to consider the potential bypass of controls through management override, as well as areas where controls are weak or there is a lack of segregation of duties. 4 CorporateGovernor Winter 2015

5 Fraud prevention and detection Once the likelihood and significance of fraud risks are identified, design and implementation of mitigating controls follow. Fraud prevention requires both preventative and detective controls. Preventative controls include policies, procedures, training, and communication and certain computer-based application controls, while detective controls involve activities designed to identify specific examples of fraud or misconduct that is occurring or has occurred, such as reconciliations and other types of manual controls. However, these are interrelated concepts, as described below: If effective preventive controls are in place, working and well-known to potential fraud perpetrators, they serve as strong deterrents to those who might otherwise be tempted to commit fraud. Fear of getting caught due to a company s known commitment to punishment is always a strong deterrent. Effective preventive controls are, therefore, also strong deterrence controls. 4 Keep in mind that, in designing controls, segregation of duties in small companies can be difficult to achieve because of limited resources and personnel. Smaller firms need to work to assure that compensating controls (such as periodic budget to actual analysis at a precise-enough level to flag and investigate unusual activity) or other monitoring controls are in place to mitigate this occurrence. Fraud investigation and corrective action No system of internal control can eliminate fraud completely, so a program for how the company responds to identified fraud or potential illegal acts is essential. The investigation and response system should include a process for categorizing issues, communicating within the organization including the audit committee or those charged with governance (depending on the potential severity of the matter), conducting the investigation and fact-finding, and resolving or closing the investigation with a recommendation for prosecution. A tracking system for monitoring the status of fraud cases is a necessity. If the allegation involves senior management or affects the financial statements, there may be standards, regulations or laws that require parties like legal counsel, board, audit committee or external auditors to be notified. Conclusion COSO 2013 includes some key elements that management can leverage for companies starting or upgrading their FRA. Organizations that have adopted COSO 2013 can continue to build on that experience to prepare for the fraud challenges ahead. For companies that haven t yet implemented the framework, the direction it provides for improving FRA should motivate management to strive for adoption as soon as possible. Contacts Michael Rose Partner, Business Advisory Services T E michael.rose@us.gt.com Kevin Bennett Managing Director, Forensic and Valuation Services T E kevin.bennett@us.gt.com Priya Sarjoo Principal, Business Advisory Services T E priya.sarjoo@us.gt.com Brad Preber National Managing Partner, Forensic and Valuation Services T E brad.preber@us.gt.com Editor Evangeline Umali Hannum E evangeline.umalihannum@ us.gt.com 4 Managing the Business Risk of Fraud: A Practical Guide, p The Institute of Internal Auditors (IIA), AICPA and ACFE. See managing-business-risk.pdf for more information. 5 CorporateGovernor Winter 2015

6 About the newsletter CorporateGovernor is published by Grant Thornton LLP. The people in the independent firms of Grant Thornton International Ltd provide personalized attention and the highest-quality service to public and private clients in more than 100 countries. Grant Thornton LLP is the U.S. member firm of Grant Thornton International Ltd, one of the world s leading organizations of independent audit, tax and advisory firms. Grant Thornton International Ltd and its member firms are not a worldwide partnership, as each member firm is a separate and distinct legal entity. Content in this publication is not intended to answer specific questions or suggest suitability of action in a particular case. For additional information about the issues discussed, consult a Grant Thornton LLP client service partner or another qualified professional. Connect with us linkd.in/grantthorntonus Grant Thornton refers to Grant Thornton LLP, the U.S. member firm of Grant Thornton International Ltd (GTIL). GTIL and its member firms are not a worldwide partnership. All member firms are individual legal entities separate from GTIL. Services are delivered by the member firms. GTIL does not provide services to clients. GTIL and its member firms are not agents of, and do not obligate, one another and are not liable for one another s acts or omissions. Please visit grantthornton.com for details Grant Thornton LLP All rights reserved U.S. member firm of Grant Thornton International Ltd

Ramifications of the New COSO Framework & Recent PCAOB Actions

Ramifications of the New COSO Framework & Recent PCAOB Actions Ramifications of the New COSO Framework & Recent PCAOB Actions Panelists Moderator Bob Meyer, Senior Vice President of Finance & Corporate Controller, American Tower Joann Cangelosi, Partner, Grant Thornton

More information

Effective implementation of COSO s new anti-fraud guidance

Effective implementation of COSO s new anti-fraud guidance Effective implementation of COSO s new anti-fraud guidance In September 2016, the Committee of Sponsoring Organizations of the Treadway Commission (COSO) published a new Fraud Risk Management Guide (Anti-fraud

More information

MANAGING FRAUD RISK. Teresa D. Thamer, CPA, CFE Brenau University

MANAGING FRAUD RISK. Teresa D. Thamer, CPA, CFE Brenau University MANAGING FRAUD RISK Teresa D. Thamer, CPA, CFE Brenau University Overview I. Understanding what Fraud is and is not II. Identifying and assessing key fraud risk areas III. Developing a Comprehensive Fraud

More information

9. Internal control Internal control, as defined in accounting and auditing, is a process for assuring achievement of an organization's objectives in

9. Internal control Internal control, as defined in accounting and auditing, is a process for assuring achievement of an organization's objectives in 9. Internal control Internal control, as defined in accounting and auditing, is a process for assuring achievement of an organization's objectives in operational effectiveness and efficiency, reliable

More information

Anti-Fraud Programs and Control Policy

Anti-Fraud Programs and Control Policy Anti-Fraud Programs and Control Policy OVERVIEW This document provides an overview of the programs and controls Tahoe Resources Inc. ( Tahoe ) follows in order to evaluate fraud risk as it pertains to

More information

Fraud incident handling management. Meeting the challenges of fraud

Fraud incident handling management. Meeting the challenges of fraud Fraud incident handling management Meeting the challenges of fraud Recently, more companies are becoming more aware of the financial and reputational damage that fraud can cause to a company. Especially

More information

Managing Fraud Risk: New Professional Guidance

Managing Fraud Risk: New Professional Guidance Managing Fraud Risk: New Professional Guidance Mohammed Ahmed & Toby J.F. Bishop Deloitte Financial Advisory Services LLP September 10, 2007 Objectives Make you aware of the new guidance Show how you can

More information

Presented by Ed Williamson and Erica Bailey

Presented by Ed Williamson and Erica Bailey Presented by Ed Williamson and Erica Bailey Internal Controls & Fraud Detection Objectives Background on internal controls Review of organizational and functional level controls Fraud prevention and risk

More information

Agenda 11/26/13. Updated COSO Framework

Agenda 11/26/13. Updated COSO Framework Updated COSO Framework Danny M. Goldberg, Founder Agenda COSO Update Overview History/Background Changes Overview Five Control Objectives 17 Control Principles Case Study: Developing a Checklist for Your

More information

Fraud Risk Management

Fraud Risk Management Fraud Risk Management Introduction Bethmara Kessler, CFE, CISA Campbell Soup Company 2017 Association of Certified Fraud Examiners, Inc. CPE Information 2017 Association of Certified Fraud Examiners, Inc.

More information

COSO Updates and Expectations. IIA San Diego Chapter January 8, 2014

COSO Updates and Expectations. IIA San Diego Chapter January 8, 2014 COSO Updates and Expectations IIA San Diego Chapter January 8, 2014 Agenda Overview of 2013 Internal Control-Integrated Framework and Companion Guidance 2013 Framework General Enhancements by Component

More information

Fraud in focus March Fraud & Corruption in the Victorian Public Sector learnings and insight for 2017 and beyond

Fraud in focus March Fraud & Corruption in the Victorian Public Sector learnings and insight for 2017 and beyond Fraud in focus March 2017 Fraud & Corruption in the Victorian Public Sector learnings and insight for 2017 and beyond Introduction The Victorian Public Sector has a comprehensive integrity framework with

More information

McGraw-Hill/Irwin. Copyright 2013 by The McGraw-Hill Companies, Inc. All rights reserved.

McGraw-Hill/Irwin. Copyright 2013 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin Copyright 2013 by The McGraw-Hill Companies, Inc. All rights reserved. Chapter 04 Management Fraud and Audit Risk Learning Objectives 1. Define business risk and understand how management

More information

An Overview of the 2013 COSO Framework. August 2013

An Overview of the 2013 COSO Framework. August 2013 An Overview of the 2013 COSO Framework August 2013 Introduction Dean Geesler, KPMG Senior Manager Course Objectives Summarize the key changes from the 1992 Framework to the 2013 Framework including the

More information

In Control: Getting Familiar with the New COSO Guidelines. CSMFO Monterey, California February 18, 2015

In Control: Getting Familiar with the New COSO Guidelines. CSMFO Monterey, California February 18, 2015 In Control: Getting Familiar with the New COSO Guidelines CSMFO Monterey, California February 18, 2015 1 Background on COSO Part 1 2 Development of a comprehensive framework of internal control Internal

More information

Reducing fraud, bribery and corruption in your private business: 6 things you can do now

Reducing fraud, bribery and corruption in your private business: 6 things you can do now Reducing fraud, bribery and corruption in your private business: 6 things you can do now 1 With an increased focus on global commitments to mitigate fraud, bribery and corruption, there remains an ongoing

More information

STUDY UNIT TEN INTERNAL AUDIT RESPONSIBILITIES FOR FRAUD

STUDY UNIT TEN INTERNAL AUDIT RESPONSIBILITIES FOR FRAUD STUDY UNIT TEN INTERNAL AUDIT RESPONSIBILITIES FOR FRAUD 1 10.1 Fraud -- Nature, Prevention, and Detection..................................... 1 10.2 Fraud -- Indicators........................................................

More information

Heads Up. Control Integrated Framework. COSO Enhances Its Internal. In This Issue: Enhancements in the 2013 Framework

Heads Up. Control Integrated Framework. COSO Enhances Its Internal. In This Issue: Enhancements in the 2013 Framework June 10, 2013 Volume 20, Issue 17 Heads Up In This Issue: Enhancements in the 2013 Framework Effective Systems of Internal Control COSO Transition Guidance and Impact on Other COSO Documents Internal Control

More information

EY Center for Board Matters. Leading practices for audit committees

EY Center for Board Matters. Leading practices for audit committees EY Center for Board Matters for audit committees As an audit committee member, your role is increasingly complex and demanding. Regulators, standard-setters and investors are pressing for more transparency

More information

A Discussion About Internal Controls February 2016

A Discussion About Internal Controls February 2016 A Discussion About Internal Controls February 2016 What we will cover today 001 Introductions 002 Defining Internal Controls 003 COSO Internal Controls Integrated Framework 004 Approach to Designing Internal

More information

Fraud Prevention, Detection and Control. Elizabeth Coles, CPA Aldrich CPAs + Advisors LLP

Fraud Prevention, Detection and Control. Elizabeth Coles, CPA Aldrich CPAs + Advisors LLP Fraud Prevention, Detection and Control Elizabeth Coles, CPA Aldrich CPAs + Advisors LLP 1 Agenda Who and Why? Fraud Schemes and Risks Fraud Prevention what can you do? 3 Who Commits Fraud? Long time,

More information

FRAUD AWARENESS UPDATE

FRAUD AWARENESS UPDATE Tammy Michaud, CPA, Principal Sarah Belliveau, CPA, Senior Manager FRAUD AWARENESS UPDATE berrydunn.com CATEGORIES OF FRAUD Asset misappropriations (stealing) Theft or misuse of assets Corruption Inappropriate

More information

2/20/15. Trevor Stewart, CPA Director of Business Services Source documentation includes CCIA and FCMAT

2/20/15. Trevor Stewart, CPA Director of Business Services Source documentation includes CCIA and FCMAT 2/20/15 Trevor Stewart, CPA Director of Business Services Source documentation includes CCIA and FCMAT The Fraud Triangle factors that influence the commission of fraud The Fraud Tree occupational fraud

More information

IAASB Main Agenda (March 2005) Page Agenda Item 12-C

IAASB Main Agenda (March 2005) Page Agenda Item 12-C IAASB Main Agenda (March 2005) Page 2005 429 Agenda Item 12-C [ISA AND IAPS SPLIT] PROPOSED INTERNATIONAL AUDITING PRACTICE STATEMENT XXX THE APPLICATION OF INTERNATIONAL STANDARDS ON AUDITING IN AN AUDIT

More information

Understanding the Entity and Its Environment and Assessing the Risks of Material Misstatement

Understanding the Entity and Its Environment and Assessing the Risks of Material Misstatement Issued December 2007 International Standard on Auditing Understanding the Entity and Its Environment and Assessing the Risks of Material Misstatement The Malaysian Institute of Certified Public Accountants

More information

Present and functioning: Fine-tuning your ICFR using the COSO update

Present and functioning: Fine-tuning your ICFR using the COSO update Present and functioning: Fine-tuning your ICFR using the COSO update November 2014 With the COSO s 1992 Control Framework being superseded by the 2013 updated edition on December 15, 2014, now is the time

More information

Auditing Standards and Practices Council

Auditing Standards and Practices Council Auditing Standards and Practices Council PHILIPPINE STANDARD ON AUDITING 315 UNDERSTANDING THE ENTITY AND ITS ENVIRONMENT AND ASSESSING THE RISKS OF MATERIAL MISSTATEMENT PHILIPPINE STANDARD ON AUDITING

More information

Chapter 06. Audit Planning, Understanding the Client, Assessing Risks, and Responding. McGraw-Hill/Irwin

Chapter 06. Audit Planning, Understanding the Client, Assessing Risks, and Responding. McGraw-Hill/Irwin Chapter 06 Audit Planning, Understanding the Client, Assessing Risks, and Responding McGraw-Hill/Irwin Copyright 2012 by The McGraw-Hill Companies, Inc. All rights reserved. Obtaining Clients Submit a

More information

716 West Ave Austin, TX USA

716 West Ave Austin, TX USA FRAUD-RELATED INTERNAL CONTROLS GLOBAL Headquarters the gregor building 716 West Ave Austin, TX 78701-2727 USA Figure 2.1 COSO defines an internal control as a process, effected by an entity s board of

More information

38 Years of Excellent Client Service New COSO Model and How Internal Controls Help to Reduce Opportunity for Fraud

38 Years of Excellent Client Service New COSO Model and How Internal Controls Help to Reduce Opportunity for Fraud 38 Years of Excellent Client Service New COSO Model and How Internal Controls Help to Reduce Opportunity for Fraud Presented By William Blend, CPA, CFE Session Overview Review the new COSO model on internal

More information

Laurie Beets. PDG 27 th National College & University Bursars & SFS Conference

Laurie Beets. PDG 27 th National College & University Bursars & SFS Conference Foiling Fraudsters Laurie Beets Oklahoma State University Acknowledgements 2006 Fraud Examiners Manual, Association of Certified Fraud Examiners (ACFE) 2012 Report to the Nation on Occupational Fraud &

More information

AUDIT RISK ASSESSMENT AND RESPONSES TO ASSESSED RISK BY Geoffrey Byamugisha Partner, Ernst & Young. Lessons on Audit Risk. Responding to fraud risk

AUDIT RISK ASSESSMENT AND RESPONSES TO ASSESSED RISK BY Geoffrey Byamugisha Partner, Ernst & Young. Lessons on Audit Risk. Responding to fraud risk AUDIT RISK ASSESSMENT AND RESPONSES TO ASSESSED RISK BY Geoffrey Byamugisha Partner, Ernst & Young ICPAU Page 1 COURSE CONTENT Lessons on Audit Risk Identification of audit risk and audit risk assessment

More information

FRAUD SCHEMES. South Carolina HFMA Finance & Reimbursement Forum. November 13, 2012 WITH RELATED INTERNAL CONTROLS

FRAUD SCHEMES. South Carolina HFMA Finance & Reimbursement Forum. November 13, 2012 WITH RELATED INTERNAL CONTROLS FRAUD SCHEMES WITH RELATED INTERNAL CONTROLS South Carolina HFMA Finance & Reimbursement Forum November 13, 2012 2 Fraud Facts: Estimated loss of 5% of annual revenues to occupational fraud Financial statement

More information

Internal Controls for Deans, Directors and Chairs

Internal Controls for Deans, Directors and Chairs Internal Controls for Deans, Directors and Chairs Presented by: Laura Howat, CPA Controller/Director Financial Management Financial and Business Services Phone: 801-581-5077 Email: laura.howat@admin.utah.edu

More information

Eric Kinsherf, CPA MMAAA Conference June 12, 2018

Eric Kinsherf, CPA MMAAA Conference June 12, 2018 Eric Kinsherf, CPA MMAAA Conference June 12, 2018 Agenda Overview What is Fraud? How does Fraud happen? How to Detect and Prevent Fraud Summarize Objectives Gain better Understanding of Fraud Risk Illustrate

More information

Risk culture. Building great organisations and growing your foundation for success CAPABILITY STATEMENT 2016

Risk culture. Building great organisations and growing your foundation for success CAPABILITY STATEMENT 2016 Risk culture Building great organisations and growing your foundation for success CAPABILITY STATEMENT 2016 What the regulators are saying about risk culture 2 3 An effective risk culture guides and facilitates

More information

Protecting your private business from fraud

Protecting your private business from fraud Protecting your private business from fraud As a private business owner, you want to do everything possible to cost-effectively protect your company against fraud. It s very likely that, at some point,

More information

Consideration of Fraud in a Financial Statement Audit (Redrafted) *

Consideration of Fraud in a Financial Statement Audit (Redrafted) * STATEMENT ON AUDITING STANDARDS Consideration of Fraud in a Financial Statement Audit (Redrafted) * Statement on Auditing Standards (SAS) Consideration of Fraud in a Financial Statement Audit (Redrafted)

More information

AN AUDIT OF INTERNAL CONTROL THAT IS INTEGRATED WITH AN AUDIT OF FINANCIAL STATEMENTS: GUIDANCE FOR AUDITORS OF SMALLER PUBLIC COMPANIES

AN AUDIT OF INTERNAL CONTROL THAT IS INTEGRATED WITH AN AUDIT OF FINANCIAL STATEMENTS: GUIDANCE FOR AUDITORS OF SMALLER PUBLIC COMPANIES 1666 K Street, NW Washington, D.C. 20006 Telephone: (202) 207-9100 Facsimile: (202) 862-8430 www.pcaobus.org PRELIMINARY STAFF VIEWS AN AUDIT OF INTERNAL CONTROL THAT IS INTEGRATED WITH AN AUDIT OF FINANCIAL

More information

INTERNATIONAL STANDARD ON AUDITING 315 UNDERSTANDING THE ENTITY AND ITS ENVIRONMENT AND ASSESSING THE RISKS OF MATERIAL MISSTATEMENT CONTENTS

INTERNATIONAL STANDARD ON AUDITING 315 UNDERSTANDING THE ENTITY AND ITS ENVIRONMENT AND ASSESSING THE RISKS OF MATERIAL MISSTATEMENT CONTENTS INTERNATIONAL STANDARD ON AUDITING 315 UNDERSTANDING THE ENTITY AND ITS ENVIRONMENT AND ASSESSING THE RISKS OF MATERIAL MISSTATEMENT (Effective for audits of financial statements for periods beginning

More information

FRAUD RISK FACTORS CHECKLIST (Source: New AU Section 240, Appendix A)

FRAUD RISK FACTORS CHECKLIST (Source: New AU Section 240, Appendix A) Page 136 of 174 FRAUD RISK FACTORS CHECKLIST (Source: New AU Section 240, Appendix A) RECOGNIZING RISK FACTORS THAT SHOULD GET YOUR ATTENTION How to use the checklist: 1. Review this checklist towards

More information

Fraud Prevention and Detection Michael Schulstad, CPA/CFF/CGMA/FBI (ret)

Fraud Prevention and Detection Michael Schulstad, CPA/CFF/CGMA/FBI (ret) WEALTH ADVISORY OUTSOURCING AUDIT, TAX, AND CONSULTING Investment advisory services are offered through CliftonLarsonAllen Wealth Advisors, LLC, an SEC-registered investment advisor Fraud Prevention and

More information

Diving into the 2013 COSO Framework. Presented by: Ronald A. Conrad

Diving into the 2013 COSO Framework. Presented by: Ronald A. Conrad Diving into the 2013 COSO Framework Presented by: Ronald A. Conrad 2 Objectives Obtain an understanding of why the COSO Framework has been updated Understand how the framework has changed Identify the

More information

What Are Your Auditors Doing? Presented by Carrie Kennedy, Partner Travis Smith, Partner Moss Adams LLP

What Are Your Auditors Doing? Presented by Carrie Kennedy, Partner Travis Smith, Partner Moss Adams LLP What Are Your Auditors Doing? Presented by Carrie Kennedy, Partner Travis Smith, Partner Moss Adams LLP 1 MOSS ADAMS AT A GLANCE Full service national CPA firm providing assurance, tax, and consulting

More information

Navigating the PCAOB s and SEC s internal control expectations A discussion. June 2015

Navigating the PCAOB s and SEC s internal control expectations A discussion. June 2015 Navigating the PCAOB s and SEC s internal control expectations A discussion June 2015 Setting the scene ICFR guidance: PCAOB Auditing Standard No. 5 (May 2007) PCAOB staff views: An Audit of Internal Control

More information

Internal Financial Control (IFC)& Internal Financial Controls over Financial Reporting (IFCoFR)

Internal Financial Control (IFC)& Internal Financial Controls over Financial Reporting (IFCoFR) Internal Financial Control (IFC)& Internal Financial Controls over Financial Reporting (IFCoFR) Origin of IFC The first significant focus on internal control certification related to financial reporting

More information

9/17/2017. An Overview of COSO s New Framework and Implementation Guidance SPEAKER. Laura Harden, CPA History

9/17/2017. An Overview of COSO s New Framework and Implementation Guidance SPEAKER. Laura Harden, CPA History An Overview of COSO s New Framework and Implementation Guidance SPEAKER Laura Harden, CPA lharden@cbh.com History 2 1 About COSO Committee of Sponsoring Organizations Formed in 1985 to sponsor the National

More information

IIA ACFE Conference April 17, 2015

IIA ACFE Conference April 17, 2015 IIA ACFE Conference April 17, 2015 Summary of Presentation Forensic Audit / Internal Audit Forensic Audit Role Forensic Audit Methodology Pragmatic examples of how forensic audit can benefit the risk assessment

More information

201 Fraud Risk Assessment April 19, 2010 Monday 1:30 2:30 pm Paul M. Baran Mark P. Ruppert, CPA, CIA, CISA, CHFP. Round Up!

201 Fraud Risk Assessment April 19, 2010 Monday 1:30 2:30 pm Paul M. Baran Mark P. Ruppert, CPA, CIA, CISA, CHFP. Round Up! 201 Fraud Risk ment April 19, 2010 Monday 1:30 2:30 pm Paul M. Baran Mark P. Ruppert, CPA, CIA, CISA, CHFP Director, Internal Audit Director, Internal Audit Fraud Risk ment Round Up! Why? What is Fraud

More information

Fraud Risk in Difficult Economic Times - questions for directors to ask

Fraud Risk in Difficult Economic Times - questions for directors to ask Fraud Risk in Difficult Economic Times - questions for directors to ask Author: Mike Savage, CA Introduction In difficult economic times, the risk of fraud is heightened because of both an increased incidence

More information

Bribery in International Business Transactions. World Headquarters the gregor building 716 West Ave Austin, TX USA

Bribery in International Business Transactions. World Headquarters the gregor building 716 West Ave Austin, TX USA Bribery in International Business Transactions World Headquarters the gregor building 716 West Ave Austin, TX 78701-2727 USA IV. LIMITING LIABILITY: CORPORATE GOVERNANCE AND FRAUD PREVENTION STRATEGIES

More information

Modern Auditing: Assurance Services and the Integrity of Financial Reporting, 8 th Edition

Modern Auditing: Assurance Services and the Integrity of Financial Reporting, 8 th Edition Modern Auditing: Assurance Services and the Integrity of Financial Reporting, 8 th Edition William C. Boynton California Polytechnic State University at San Luis Obispo Raymond N. Johnson Portland State

More information

Community College Audit and Compliance Workshop. VAVRINEK, TRINE, DAY & CO., LLP April 15, 2014

Community College Audit and Compliance Workshop. VAVRINEK, TRINE, DAY & CO., LLP April 15, 2014 Community College Audit and Compliance Workshop VAVRINEK, TRINE, DAY & CO., LLP April 15, 2014 Audit Responsibilities Overview An annual financial statement and compliance audit of California Community

More information

STANDING ADVISORY GROUP MEETING

STANDING ADVISORY GROUP MEETING 1666 K Street, NW Washington, D.C. 20006 Telephone: (202) 207-9100 Facsimile: (202) 862-8430 www.pcaobus.org STANDING ADVISORY GROUP MEETING CONSIDERATION OF OUTREACH AND RESEARCH REGARDING THE AUDITOR'S

More information

Fraud in the Insurance Industry How it Can Impact Your Agency

Fraud in the Insurance Industry How it Can Impact Your Agency A MarshBerry Publication Volume XXIX, Issue 4 APRIL 2013 Authored by Molly McCarthy, Senior Consultant 440.392.6584 email: Molly.McCarthy@MarshBerry.com Fraud in the Insurance Industry How it Can Impact

More information

Conducting a Fraud Risk Assessment

Conducting a Fraud Risk Assessment Conducting a Fraud Risk Assessment Approach, Pitfalls and Recommendations IAAIA Istanbul October 10-13, 2010 Jean Pierre Garitte, CIA, CCSA, CISA, CFE, RFA May 2010 Introduction and Overview Why Conduct

More information

Mapping of Original ISA 315 to New ISA 315 s Standards and Application Material (AM) Agenda Item 2-C

Mapping of Original ISA 315 to New ISA 315 s Standards and Application Material (AM) Agenda Item 2-C Mapping of to 315 s and Application Material (AM) Agenda Item 2-C AM 1. The purpose of this International Standard on Auditing (ISA) is to establish standards and to provide guidance on obtaining an understanding

More information

Fraud Risk Management

Fraud Risk Management Fraud Risk Management Fraud Risk Management Overview 2017 Association of Certified Fraud Examiners, Inc. Discussion Questions 1. Does your organization follow a specific risk management model? If so, which

More information

2017 Private Company Audit Committee Outlook

2017 Private Company Audit Committee Outlook 2017 Private Company Audit Committee Outlook What s on your audit committee agenda? Private company audit committees have full agendas and finite resources, which can make keeping abreast of certain items

More information

Internal Control in Higher Education

Internal Control in Higher Education Internal Control in Higher Education Daniel Adams Office of Audit Services Audit Services Mission To provide assurance and advisory services that are independent, objective and risk-based in order to protect

More information

Fraud Awareness Jennifer Murtha Clara Ewing

Fraud Awareness Jennifer Murtha Clara Ewing Fraud Awareness Jennifer Murtha Clara Ewing The Monkey Business Illusion 2 Fraud Defined The term fraud is defined in Black's Law Dictionary (Sixth Edition, 1990) as: An intentional perversion of truth

More information

Module 1: Safeguarding District Resources: Roles & Responsibilities

Module 1: Safeguarding District Resources: Roles & Responsibilities Module 1: Safeguarding District Resources: Roles & Responsibilities Presenter: Jamie P. McPherson Leadership Development Manager New School Board Member Mandated Training Day Two: Fiscal Oversight Training

More information

My experiences with Employee Fraud

My experiences with Employee Fraud My experiences with Employee Fraud - Capt Percy Jokhi March 18, 2008 Introduction The present industry scenario is most prone to losses due to Fraud not only associated with external agencies, but more

More information

The Basics of Internal Controls & Segregation of Duties

The Basics of Internal Controls & Segregation of Duties The Basics of Internal Controls & Segregation of Duties Presented by: Kevin L. Pegish, CPA Senior Audit Manager Northwest Region klpegish@ohioauditor.gov Internal Controls, we will discuss the following:

More information

August 2010 Guidelines for Managing the Risk of Fraud in Government.

August 2010 Guidelines for Managing the Risk of Fraud in Government. August 2010 Guidelines for Managing the Risk of Fraud in Government www.bcauditor.com T a b l e o f C o n t e n t s The Five Principles Underpinning a Sound Fraud Risk Strategy 2 Principle 1: Understand

More information

Today s CFO: Changing the game plan for tomorrow

Today s CFO: Changing the game plan for tomorrow Risk Technology Today s CFO: Changing the game plan for tomorrow Investment Strategy As businesses evolve, the scope of the CFO s role is expanding. CFOs now have to balance competing demands on their

More information

By CPA Alfred Lagat Tullon Audit Consulting Ltd 11 th August 2015

By CPA Alfred Lagat Tullon Audit Consulting Ltd 11 th August 2015 By CPA Alfred Lagat Tullon Audit Consulting Ltd 11 th August 2015 Common deficiencies Steps you can take to avoid them Practical cases and implications So there is potentially an appetite for auditors

More information

5th Annual National Congress on Health Care Compliance. Internal Audits Role in Compliance (and Vice Versa)

5th Annual National Congress on Health Care Compliance. Internal Audits Role in Compliance (and Vice Versa) 5th Annual National Congress on Health Care Compliance Internal Audits Role in Compliance (and Vice Versa) Welcome To The New Humana James Rose, Corporate Director of Internal Audit February 7, 2002 Your

More information

AUDIT RESPONSIBILITIES AND OBJECTIVES

AUDIT RESPONSIBILITIES AND OBJECTIVES AUDIT RESPONSIBILITIES AND OBJECTIVES CHAPTER 6 Copyright 2017 Pearson Education, Ltd. 6-1 CHAPTER 1 LEARNING OBJECTIVES 6-1 Explain the objective of conducting an audit of financial statements and an

More information

Global Expectations for Addressing Fraud Risk and the Investigative Process

Global Expectations for Addressing Fraud Risk and the Investigative Process Global Expectations for Addressing Fraud Risk and the Investigative Process Waheed Alkahtani CFE, CISA, and CCEP-I Saudi Aramco Internal Auditing Special Audits Division Copyright 2014, Saudi Aramco. All

More information

APPENDIX A. Audit Findings Report. For the Year ended March 31, 2016

APPENDIX A. Audit Findings Report. For the Year ended March 31, 2016 APPENDIX A Audit Findings Report For the Year ended March 31, 2016 Annual General Meeting June 20, 2016 Muskoka Algonquin Healthcare Audit Findings Report For the year ended March 31, 2016 Chartered Professional

More information

International Standards for the Professional Practice of Internal Auditing (Standards)

International Standards for the Professional Practice of Internal Auditing (Standards) INTERNATIONAL STANDARDS FOR THE PROFESSIONAL PRACTICE OF INTERNAL AUDITING (STANDARDS) Attribute Standards 1000 Purpose, Authority, and Responsibility The purpose, authority, and responsibility of the

More information

STRENGTHENING INTERNAL CONTROLS. What We Will Cover Today

STRENGTHENING INTERNAL CONTROLS. What We Will Cover Today STRENGTHENING INTERNAL CONTROLS What We Will Cover Today 1. Background 2. Integrated framework of internal control 3. Five elements of internal controls 4. Practical examples 5. Additional resources 2

More information

Introductions. An Overview of the COSO 2013 Framework. Christian Peo Sharon Todd. An Overview of the 2013 COSO Framework.

Introductions. An Overview of the COSO 2013 Framework. Christian Peo Sharon Todd. An Overview of the 2013 COSO Framework. An Overview of the 2013 COSO Framework An Overview of the COSO 2013 Framework August 8, 2013 Introductions Christian Peo Sharon Todd Marc Wittenberg Module Name/SL/1 firms Course Objectives By the end

More information

13-A. Fraud Phase II Issues Paper

13-A. Fraud Phase II Issues Paper IAASB Main Agenda Page 2002 855 Agenda Item 13-A Convergence with US Fraud Standard 1. In March 2001, the IAPC approved revisions to ISA 240 The Auditor s Responsibility to Consider Fraud and Error in

More information

EFFICIENT USE OF AUDIT COMMITTEES

EFFICIENT USE OF AUDIT COMMITTEES AGENDA EFFICIENT USE OF AUDIT COMMITTEES BRENT YOUNG, CPA JERRY GAITHER, CPA Best practices related to: Audit Committee Process Internal Audit Risk Management 2 AUDIT COMMITTEE PROCESS AND PROCEDURES Audit

More information

Standards for Internal Control in New York State Government 2016 Update

Standards for Internal Control in New York State Government 2016 Update Standards for Internal Control in New York State Government 2016 Update Presented to the New York State Internal Control Association John F. Buyce Audit Director April 28, 2016 1 Last Revised in 2007 A

More information

Minimizing fraud exposure with effective ERP segregation of duties controls

Minimizing fraud exposure with effective ERP segregation of duties controls Minimizing fraud exposure with effective ERP segregation of duties controls Prepared by: Luke Leaon, Manager, RSM US LLP luke.leaon@rsmus.com, +1 612 629 9072 Adam Harpool, Manager, RSM US LLP adam.harpool@rsmus.com,

More information

IAASB Main Agenda (July 2007) Page Agenda Item

IAASB Main Agenda (July 2007) Page Agenda Item IAASB Main Agenda (July 2007) Page 2007 1787 Agenda Item 5-C Proposed Disposition of the Present Tense and Other in the Proposed ISQC1 () I. Those That Have Been Elevated to a Requirement 8 Such communication

More information

VERSION #1 WRITE ON YOUR SCANTRON!!!

VERSION #1 WRITE ON YOUR SCANTRON!!! ECON 132A WINTER 2009 MIDTERM #2 Name: Date: ANSWER ALL MULTIPLE CHOICE QUESTIONS ON GREEN SCANTRON ANSWER QUESTIONS 29 & 30 IN THE SPACE PROVIDED ANSWER THE SIMULATION ASSIGNMENT IN YOUR BLUE-BOOK, PUT

More information

Internal Controls. They Are Everyone s Business. Valdosta State University Office of Internal Audits June 2016

Internal Controls. They Are Everyone s Business. Valdosta State University Office of Internal Audits June 2016 Internal Controls They Are Everyone s Business Valdosta State University Office of Internal Audits June 2016 1 Presentation Overview Understand Internal Controls Identify Control Weaknesses Fraud Best

More information

INTEGRATING FORENSIC INVESTIGATION TECHNIQUES INTO INTERNAL AUDITING

INTEGRATING FORENSIC INVESTIGATION TECHNIQUES INTO INTERNAL AUDITING INTEGRATING FORENSIC INVESTIGATION TECHNIQUES INTO INTERNAL AUDITING The internal auditors roles in combating fraud are becoming more profound within an organization. Internal auditors may assume a variety

More information

The EU raises the bar on data privacy:

The EU raises the bar on data privacy: The EU raises the bar on data privacy: AIM for an integrated response Organizations can view the EU s General Data Protection Regulation (GDPR) as either a problem or an opportunity. Grant Thornton sees

More information

Internal Audit s Role in Preventing, Deterring and Detecting Fraud Working as Part of a Fraud Management Team The Way Forward

Internal Audit s Role in Preventing, Deterring and Detecting Fraud Working as Part of a Fraud Management Team The Way Forward Internal Audit s Role in Preventing, Deterring and Detecting Fraud Working as Part of a Fraud Management Team The Way Forward Ottawa, ON 11/26/2015 Introduction and Objectives The main objectives of today

More information

IAASB Main Agenda (December 2008) Page Agenda Item

IAASB Main Agenda (December 2008) Page Agenda Item IAASB Main Agenda (December 2008) Page 2008 2669 Agenda Item 2-C PROPOSED INTERNATIONAL STANDARD ON AUDITING 265 COMMUNICATING DEFICIENCIES IN INTERNAL CONTROL (Effective for audits of financial statements

More information

HCCA AUDIT & COMPLIANCE COMMITTEE CONFERENCE

HCCA AUDIT & COMPLIANCE COMMITTEE CONFERENCE HCCA AUDIT & COMPLIANCE COMMITTEE CONFERENCE EXTERNAL AUDIT AND THE AUDIT COMMITTEE CHRIS IDEKER, CPA CHRISIDEKER@ALVAREZANDMARSAL.COM February 25 th, 2013 QUESTIONS TO BE ADDRESSED The involvement and

More information

INTERNATIONAL STANDARDS FOR THE PROFESSIONAL PRACTICE OF INTERNAL AUDITING (STANDARDS)

INTERNATIONAL STANDARDS FOR THE PROFESSIONAL PRACTICE OF INTERNAL AUDITING (STANDARDS) INTERNATIONAL STANDARDS FOR THE PROFESSIONAL PRACTICE OF INTERNAL AUDITING (STANDARDS) ATTRIBUTE STANDARDS 1000 Purpose, Authority and Responsibility The purpose, authority, and responsibility of the internal

More information

AUDITING. Auditing PAGE 1

AUDITING. Auditing PAGE 1 AUDITING Auditing 1. Professionalism The International Professional Practices Framework (IPPF) is the conceptual framework that organizes authoritative guidance promulgated by The Institute of Internal

More information

COSO 2013: Updated internal control framework

COSO 2013: Updated internal control framework COSO 2013: Updated internal control framework Athens, 10 October 2013 Background COSO's structure and mission COSO 1 is a joint initiative of five sponsoring organizations - American Accounting Association

More information

The most commonly applied model for designing and auditing internal

The most commonly applied model for designing and auditing internal Fair Value Accounting Fraud: New Global Risks and Detection Techniques By Gerard M. Zack Copyright 2009 by Gerard M. Zack Appendix C Internal Controls over Fair Value Accounting Applications The most commonly

More information

International Standards for the Professional Practice of Internal Auditing (Standards)

International Standards for the Professional Practice of Internal Auditing (Standards) Attribute Standards 1000 Purpose, Authority, and Responsibility The purpose, authority, and responsibility of the internal audit activity must be formally defined in an internal audit charter, consistent

More information

Risk Management Culture: The Linkage Between Ethics & Compliance and ERM September 14, 2009

Risk Management Culture: The Linkage Between Ethics & Compliance and ERM September 14, 2009 2009 Compliance and Ethics Institute Risk Management Culture: The Linkage Between Ethics & Compliance and ERM September 14, 2009 Table of contents Section 1 2 3 4 5 6 Learning objectives Why measure risk

More information

[RELEASE NOS ; ; FR-77; File No. S ]

[RELEASE NOS ; ; FR-77; File No. S ] SECURITIES AND EXCHANGE COMMISSION 17 CFR PART 241 [RELEASE NOS. 33-8810; 34-55929; FR-77; File No. S7-24-06] Commission Guidance Regarding Management s Report on Internal Control Over Financial Reporting

More information

Glossary. Chartered Institute of Internal Auditors. 26 July Add value. Adequate control. Assurance services. Board. Charter

Glossary. Chartered Institute of Internal Auditors. 26 July Add value. Adequate control. Assurance services. Board. Charter 26 July 2017 Glossary Chartered Institute of Internal Auditors This glossary explains the specific meanings of some terms that are used in the The International Standards. Add value The internal audit

More information

Accounting 408 Exam 2, Chapters 3, 4, 5, 6, E, F

Accounting 408 Exam 2, Chapters 3, 4, 5, 6, E, F Accounting 408 Exam 2, Chapters 3, 4, 5, 6, E, F Summer 2017 Name Row Multiple Choice Questions. (2 points each, 100 points total) Read each question carefully and indicate the one best answer to each

More information

Report on Inspection of K. R. Margetson Ltd. (Headquartered in Vancouver, Canada) Public Company Accounting Oversight Board

Report on Inspection of K. R. Margetson Ltd. (Headquartered in Vancouver, Canada) Public Company Accounting Oversight Board 1666 K Street, N.W. Washington, DC 20006 Telephone: (202) 207-9100 Facsimile: (202) 862-8433 www.pcaobus.org Report on 2016 (Headquartered in Vancouver, Canada) Issued by the Public Company Accounting

More information

Mr. Jim Sylph Technical Director International Auditing and Assurance Standards Board 545 Fifth Avenue, 14th Floor New York, NY 10017

Mr. Jim Sylph Technical Director International Auditing and Assurance Standards Board 545 Fifth Avenue, 14th Floor New York, NY 10017 William G. Bishop III, CIA President Tel: +1 407 937 1200 wbishop@theiia.org November 15, 2003 Mr. Jim Sylph Technical Director International Auditing and Assurance Standards Board 545 Fifth Avenue, 14th

More information

Fraud risk management in not for profit organisations

Fraud risk management in not for profit organisations Fraud risk management in not for profit organisations TJ Koekemoer Director Ernst & Young, Australia 1 May 2012 Agenda Introduction The fraud landscape Understanding fraud risks using the fraud triangle

More information

Who Owns Fraud Uniting Corporate Executives to Manage Your Anti-Fraud Program

Who Owns Fraud Uniting Corporate Executives to Manage Your Anti-Fraud Program Who Owns Fraud Uniting Corporate Executives to Manage Your Anti-Fraud Program Monday June 13, 2011 10:20 11:40 San Diego, California Who owns fraud why is it important? Many companies struggle to determine

More information

INTERNAL AUDIT PLAN AND CHARTER 2018/19

INTERNAL AUDIT PLAN AND CHARTER 2018/19 INTERNAL AUDIT PLAN AND CHARTER 208/9 PURPOSE OF REPORT. To present the proposed 208/9 audit plan and charter to the Audit Committee for consideration and approval..2 The Internal Audit Plan for 208/9

More information