The New COSO:Internal Control - Integrated FrameworkSeptember 17, 2014WebinarPresented in association with

Presented by:Stephen W. Blann, CPA, CGFM, CGMADirector of Governmental Audit QualityRehmann

Session Outline Defining internal controlObjectives, components, and principlesLimitations on internal controlDeficiencies in internal controlInternal control over complianceConsiderations for smaller entities

Overview of Internal Control Internal Control—Integrated Framework– COSO Report (1992 & 2013)– Committee of Sponsoring Organizations (AICPA,AAA, IIA, IMA, FEI)– Codified in Auditing Standards by AICPA, GAO,OMB, and PCAOB (SOX)

Defining Internal Control Internal control is a process, effected by anentity's board of directors, management, andother personnel, designed to providereasonable assurance regarding theachievement of objectives relating tooperations, reporting, and compliance

Defining Internal Control Internal control is:– Geared to the achievement of objectives in one ormore separate but overlapping categories: Operations Reporting Compliance

Defining Internal Control Internal control is:– A process consisting of ongoing tasks andactivities—a means to an end, not an end in itself

Defining Internal Control Internal control is:– Effected by people—not merely about policy andprocedure manuals, systems, and forms, butabout people and the actions they take at everylevel of an organization to effect internal control

Defining Internal Control Internal control is:– Able to provide reasonable assurance—but notabsolute assurance, to an entity's seniormanagement and board of directors

Defining Internal Control Internal control is:– Adaptable to the entity structure—flexible inapplication for the entire entity or for a particularsubsidiary, division, operating unit, or businessprocess

Objectives, Components, & Principles Objectives:– Operations, reporting, compliance Components:– Control environment, risk assessment, controlactivities, information/communication, monitoring Principles:– 17 concepts applicable to the 5 components

Objectives, Components, & Principles Each principle andcomponent isapplicable to eachobjective at each levelof an organization

Objectives Operations objectives:– Achievement of the entity's basic mission andvision (effectiveness)– Safeguarding of assets (preservation andefficiency)

Objectives Reporting objectives:– External vs. internal– Financial vs. non-financial

Objectives Compliance objectives:– Laws and regulations– Provisions of grant agreements

Components and PrinciplesControl Environment The set of standards, processes, andstructures that provide the basis for carryingout internal control across the organization

Components and PrinciplesControl Environment Principle 1: Demonstrates Commitment toIntegrity and Ethical ValuesThe organization demonstrates a commitmentto integrity and ethical values.Sets the Tone at the TopEstablishes Standards of ConductEvaluates Adherence to Standards of ConductAddresses Deviations in a Timely Manner

Components and PrinciplesControl Environment Principle 2: Exercises Oversight ResponsibilityThe board of directors demonstratesindependence from management andexercises oversight of the development andperformance of internal control.Establishes Oversight ResponsibilitiesApplies Relevant ExpertiseOperates IndependentlyProvides Oversight for the System of Internal Control

Components and PrinciplesControl Environment Principle 3: Establishes Structure, Authority,and ResponsibilityManagement establishes, with boardoversight, structures, reporting lines, andappropriate authorities and responsibilities inthe pursuit of objectives.– Considers All Structures of the Entity– Establishes Reporting Lines– Defines, Assigns, and Limits Authorities and Responsibilities

Components and PrinciplesControl Environment Principle 4: Demonstrates Commitment toCompetenceThe organization demonstrates a commitmentto attract, develop, and retain competentindividuals in alignment with objectives.Establishes Policies and PracticesEvaluates Competence and Addresses ShortcomingsAttracts, Develops, and Retains IndividualsPlans and Prepares for Succession

Components and PrinciplesControl Environment Principle 5: Enforces AccountabilityThe organization holds individuals accountablefor their internal control responsibilities in thepursuit of objectives.– Enforces Accountability– Establishes Performance Measures, Incentives, and Rewards– Evaluates Measures, Incentives, and Rewards for OngoingRelevance– Considers Excessive Pressures– Evaluates Performance and Rewards or Disciplines Individuals

Components and PrinciplesRisk Assessment A dynamic and iterative process for identifyingand assessing the possibility that an event willoccur and adversely affect the achievement ofobjectives

Components and PrinciplesRisk Assessment Principle 6: Specifies Suitable ObjectivesThe organization specifies objectives withsufficient clarity to enable the identificationand assessment of risks relating to objectives.Reflects Management's ChoicesConsiders Tolerances for RiskIncludes Operations and Financial Performance GoalsForms a Basis for Committing of ResourcesComplies with reporting/compliance frameworks

Components and PrinciplesRisk Assessment Principle 7: Identifies and Analyzes RiskThe organization identifies risks to theachievement of its objectives across the entityand analyzes risks as a basis for determining howthe risks should be managed.Includes Entity, Subsidiary, Division, Operating Unit, & Functional LevelsAnalyzes Internal and External FactorsInvolves Appropriate Levels of ManagementEstimates Significance of Risks IdentifiedDetermines How to Respond to Risks

Components and PrinciplesRisk Assessment Principle 8: Assesses Fraud RiskThe organization considers the potential forfraud in assessing risks to the achievement ofobjectives.Considers Various Types of FraudAssesses Incentive and PressuresAssesses OpportunitiesAssesses Attitudes and Rationalizations

Components and PrinciplesRisk Assessment Principle 9: Identifies and Analyzes SignificantChangeThe organization identifies and assesseschanges that could significantly impact thesystem of internal control.– Assesses Changes in the External Environment– Assesses Changes in the Business Model– Assesses Changes in Leadership

Components and PrinciplesControl Activities The actions established through policies andprocedures that help ensure thatmanagement's directives to mitigate risks tothe achievement of objectives are carried out

Components and PrinciplesControl Activities Principle 10: Selects/Develops Control ActivitiesThe organization selects and develops controlactivities that contribute to the mitigation of risksto the achievement of objectives to acceptablelevels.Integrates with Risk AssessmentConsiders Entity-Specific FactorsDetermines Relevant Business ProcessesEvaluates a Mix of Control Activity TypesConsiders at What Level Activities Are AppliedAddresses Segregation of Duties

Components and PrinciplesControl Activities Principle 11: Selects and Develops GeneralControls over TechnologyThe organization selects and develops generalcontrol activities over technology to support theachievement of objectives.– Determines Dependency between the Use of Technology in BusinessProcesses and Technology General Controls– Establishes Relevant Technology Infrastructure Control Activities– Establishes Relevant Security Management Process Control Activities– Establishes Relevant Technology Acquisition, Development, andMaintenance Process Control Activities

Components and PrinciplesControl Activities Principle 12: Deploys Policies and ProceduresThe organization deploys control activitiesthrough policies that establish what isexpected and procedures that put policies intoaction.

Components and PrinciplesInformation and Communication The continual, iterative process of providing,sharing, and obtaining necessary informationto carry out internal control responsibilities tosupport the achievement of the entity'sobjectives

Components and PrinciplesInformation and Communication Principle 13: Uses Relevant InformationThe organization obtains or generates anduses relevant, quality information to supportthe functioning of internal control.Identifies Information RequirementsCaptures Internal and External Sources of DataProcesses Relevant Data into InformationMaintains Quality throughout ProcessingConsiders Costs and Benefits

Components and PrinciplesInformation and Communication Principle 14: Communicates InternallyThe organization internally communicatesinformation, including objectives andresponsibilities for internal control, necessaryto support the functioning of internal control.Communicates Internal Control InformationCommunicates with the Board of DirectorsProvides Separate Communication LinesSelects Relevant Method of Communication

Components and PrinciplesInformation and Communication Principle 15: Communicates ExternallyThe organization communicates with externalparties regarding matters affecting thefunctioning of internal control.Communicates to External PartiesEnables Inbound CommunicationsCommunicates with the Board of DirectorsProvides Separate Communication LinesSelects Relevant Method of Communication

Components and PrinciplesMonitoring Activities Ongoing evaluations, separate evaluations, orsome combination of the two are used toascertain whether each of the fivecomponents of internal control, includingcontrols to effect the principles within eachcomponent, is present and functioning

Components and PrinciplesMonitoring Activities Principle 16: Conducts Ongoing / Separate EvaluationsThe organization selects, develops, and performsongoing and/or separate evaluations to ascertainwhether the components of internal control are presentand functioning.Considers a Mix of Ongoing and Separate EvaluationsConsiders Rate of ChangeEstablishes Baseline UnderstandingUses Knowledgeable PersonnelIntegrates with Business ProcessesAdjusts Scope and FrequencyObjectively Evaluates

Components and PrinciplesMonitoring Activities Principle 17: Evaluates and CommunicatesDeficienciesThe organization evaluates and communicatesinternal control deficiencies in a timely manner tothose parties responsible for taking correctiveaction, including senior management and theboard of directors, as appropriate.– Assesses Results– Communicates Deficiencies– Monitors Corrective Actions

Limitations of Internal Control Internal control, no matter how well designed,implemented and conducted, can provide onlyreasonable assurance to management and theboard of directors of the achievement of anentity's objectives.

Limitations of Internal Control JudgmentExternal eventsBreakdownsManagement overrideCollusion

Deficiencies in Internal Control Internal control deficiency– a shortcoming in a component or components andrelevant principle(s) that reduces the likelihood ofan entity achieving its objectives Major deficiency– an internal control deficiency or combination ofdeficiencies that severely reduces the likelihoodthat the entity can achieve its objectives

Deficiencies in Internal Control Assessing severityInternal Control DeficienciesMajor Deficiencies

Deficiencies in Internal Control Responding to identified deficiencies– Consider the control environment– Assess risks– Establish/revise policies and procedures– Communicate changes– Monitor results

Internal Control over Compliance Differences and similarities with IC overfinancial reporting Existing and new requirements for grants Auditor involvement / testing

Internal Control over Compliance Existing grant requirements:– OMB Circulars A-102 Common Rule and A-110Administrative Requirements– Requires management to establish and maintaininternal controls designed to provide reasonableassurance of compliance with Federal laws,regulations and program compliancerequirements

Internal Control over Compliance New Uniform Grant Guidance (2 CFR 200):– Establish and maintain effective internal controlover the Federal award that provides reasonableassurance that the non-Federal entity is managingthe Federal award in compliance with Federalstatutes, regulations, and the terms andconditions of the Federal award– Follow COSO's Integrated Framework– Include written procedures

Internal Control over Compliance Auditor involvement / testing– Yellow Book engagements (material to financialstatements)– Single audit (material to major federal programs)– Other (Medicare, etc.)

Considerations for Smaller EntitiesCOSO – One Size Fits All? In 2006, COSO issued a tailored version of its1992 report, entitled Guidance for SmallerPublic Companies (now in Appendix C) Not specifically targeted at governments, buthelpful nonetheless Emphasizes the cost vs. benefit principle ofinternal control

Considerations for Smaller EntitiesCost vs. Benefit Entities always have limits on human andcapital resources and constraints on howmuch they can spend, and therefore they willoften consider the costs relative to thebenefits of alternative approaches inmanaging internal control options– Cost alone is not an acceptable reason to avoidimplementing internal control

Considerations for Smaller Entities"Small" vs. "Smaller" There is no "bright line" to define governments assmall, medium-size or large– Fewer types of services provided– Fewer personnel, many having a wider range of duties– Fewer levels of management, with wider spans ofcontrol– Less complex transaction processing systems andprotocols

Considerations for Smaller EntitiesChallenges for Smaller Governments Maintaining cost-effective internal control:– Managers that view internal control as a burden,rather than a benefit– Obtaining sufficient resources for adequatesegregation of duties– Management's ability to dominate activities andoverride internal control– Recruiting/retaining personnel with sufficientexperience and skill in financial reporting and/orcomputer information systems

Considerations for Smaller EntitiesChallenges for Smaller Governments Potential solutions:– Wide and direct control from the top– Effective governing bodies– Compensating for limited segregation of duties– Information technology– Monitoring activities

Considerations for Smaller EntitiesControl from the Top Smaller governments may have one or moremembers of senior management that have anin-depth understanding of virtually all of thegovernment's operations– Can enhance effectiveness of internal control– Enables leaders to know what to expect andfollow up on differences– Adds to risk of management override

Considerations for Smaller EntitiesEffective Governing Bodies Smaller governments have less complexstructures, and may have more involvedboards– Direct exposure to management– Careful review of monthly reporting, with followup questions– Extensive public transparency

Considerations for Smaller EntitiesCompensating for Limited SoD When it isn't practical to fully segregate allduties, introduce supervision and reviewEmployeeA– Two sets of eyes are better than oneEmployeeB

Considerations for Smaller EntitiesInformation Technology Smaller governments tend to rely on "off

Considerations for Smaller EntitiesInformation Technology Securing important spreadsheets fromaccidental or unauthorized changes 2014 Rehmann56

Considerations for Smaller EntitiesMonitoring Activities Monitoring is an important part of the COSOFramework.– Management of smaller governments regularlyperform such procedures, but have not alwaystaken sufficient “credit” for their contribution tointernal control effectiveness– Usually performed manually, but may rely ontechnology 2014 Rehmann57

Considerations for Smaller EntitiesControls vs. Processes It is easy to confuse the processes used tocreate transactions with the controls designedto prevent or detect errors in thosetransactions Smaller governments frequently use ITsystems to process financial transactions, butdesign manual controls to review the outputof those systems 2014 Rehmann58

Considerations for Smaller EntitiesAutomated vs. Manual Controls Generally Accepted Auditing Standards (GAAS)recognize the difference between automatedand manual controls (AU-C 315.A53)– Manual controls may be independent of IT or mayuse information produced by IT– Smaller governments may need to rely moreheavily on manual controls in the absence of acomprehensive set of IT controls 2014 Rehmann59

Considerations for Smaller EntitiesAchieving Further Efficiencies Controls should focus on financial reportingobjectives directly applicable to thegovernment’s activities and services:– Risk-based approach to internal control– Right-sizing documentation– Viewing internal control as an integrated process 2014 Rehmann60

Considerations for Smaller EntitiesFocusing on Risk Risk-based controls focus on quantitative andqualitative factors that potentially impact thereliability of financial reporting– Identify transactions or processes where somethingcould go wrong– Assess likelihood and significance– Design controls specifically tailored to those risks– Don’t rely on generic controls designed for “typical”governments without modification 2014 Rehmann61

Considerations for Smaller EntitiesRight-Sizing Documentationred·tape noun: excessive regulation or rigid conformity toformal rules that is considered redundant orbureaucratic and hinders or prevents action ordecision-making 2014 Rehmann62

Considerations for Smaller EntitiesRight-Sizing Documentation Smaller governments should determine thenature and extent of their documentation needs– Promote consistency– Provide evidence of control effectiveness– While smaller governments may not require as formaldocumentation, certain elements (such as riskassessment) cannot be performed entirely in theCFO’s head 2014 Rehmann63

Considerations for Smaller EntitiesViewing IC as an Integrated Process Remember theinterrelationship of the ormationandCommunication 2014 Rehmann– Management has flexibilityin choosing controls– Should adjust and improvecontrols over time– Effectiveness is measuredoverall, not by elementRiskAssessmentControlActivities64

Considerations for Smaller EntitiesFinal Thoughts Remember the objective of internal control Design controls that are consistent with thegovernment’s risk assessment and resources Mitigate deficiencies in internal control withas much supervision and review as possible– Management– Governing body– Others within the organization 2014 Rehmann65

Questions? 2014 Rehmann66

For more information.Stephen W. Blann, CPA, CGFM, CGMADirector of Governmental Audit .com/government 2014 Rehmann67

What is COSO? Internal Control-Integrated Framework In 1992, COSO published the original IC Framework, which allowed the management of an organization to: establish, monitor, evaluate, and report on internal control. PwC The original IC Framework