<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-8132537442296217309</id><updated>2011-10-31T18:58:04.847-07:00</updated><category term='Government Auditing And Internal Audit'/><category term='Sixth Generation Governance'/><category term='Internal Audit'/><category term='Fraud and Investigation'/><title type='text'>governance</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://bestgovernance.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8132537442296217309/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://bestgovernance.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Nischal R Siwakoti</name><uri>http://www.blogger.com/profile/03370311086374566522</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://2.bp.blogspot.com/_Ihf6skjb1AQ/SdL77hWbE7I/AAAAAAAAAA8/JwiRdCmwPxs/S220/PP+Photo.JPg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>12</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8132537442296217309.post-1837152791905484025</id><published>2009-06-11T10:49:00.000-07:00</published><updated>2009-06-11T10:53:29.766-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Internal Audit'/><title type='text'>Segregation of Duties</title><content type='html'>&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 11"&gt;&lt;meta name="Originator" content="Microsoft Word 11"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5CADMINI%7E1%5CLOCALS%7E1%5CTemp%5Cmsohtml1%5C01%5Cclip_filelist.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;  &lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" latentstylecount="156"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face 	{font-family:Wingdings; 	panose-1:5 0 0 0 0 0 0 0 0 0; 	mso-font-charset:2; 	mso-generic-font-family:auto; 	mso-font-pitch:variable; 	mso-font-signature:0 268435456 0 0 -2147483648 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;}  /* List Definitions */  @list l0 	{mso-list-id:414472439; 	mso-list-type:hybrid; 	mso-list-template-ids:2067151876 67698689 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;} @list l0:level1 	{mso-level-number-format:bullet; 	mso-level-text:; 	mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in; 	font-family:Symbol;} @list l1 	{mso-list-id:1850026440; 	mso-list-type:hybrid; 	mso-list-template-ids:182098700 67698689 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;} @list l1:level1 	{mso-level-number-format:bullet; 	mso-level-text:; 	mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in; 	font-family:Symbol;} ol 	{margin-bottom:0in;} ul 	{margin-bottom:0in;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;} &lt;/style&gt; &lt;![endif]--&gt;&lt;o:p&gt;&lt;/o:p&gt;  &lt;p class="MsoNormal"&gt;Segregation of duties is critical to effective internal control because it reduces the risk of mistakes and inappropriate actions. It helps fight fraud by discouraging collusion and enhancing internal check. Segregation of duties is an Internal Control Concept in which individuals do not have responsibility for incompatible activities. In general, the following functions should be separated among employees:&lt;/p&gt;  &lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal" style=""&gt;Approval&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;Accounting/reconciling&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;Asset      custody&lt;/li&gt;&lt;/ul&gt;  &lt;p class="MsoNormal"&gt;In other words one person should normally not participate in one or more than one function.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Transaction involve the following stages to complete &lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Initiate&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Authorize&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Record&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Process&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Reconcile&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Handle Assets&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Report&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Segregation of duties is critical to effective internal control; it reduces the risk of both erroneous and inappropriate actions. In general, the approval function, the accounting/reconciling function, and the asset custody function should be separated among employees. When these functions cannot be separated, due to small department size, a detailed supervisory review of related activities is required as a compensating control activity. Segregation of duties is a deterrent to fraud because it requires collusion with another person to perpetrate a fraudulent act.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Specific examples of segregation of duties are as follows:&lt;/p&gt;  &lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal" style=""&gt;The      person who requisitions the purchase of goods or services should not be      the person who approves the purchase.&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;The      person who approves the purchase of goods or services should not be the      person who reconciles the monthly financial reports&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;The      person who approves the purchase of goods or services should not be able      to obtain custody of checks.&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;The      person who maintains and reconciles the accounting records should not be      able to obtain custody of checks.&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;The      person who opens the mail and prepares a listing of checks received should      not be the person who makes the deposit.&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;The      person who opens the mail and prepares a listing of checks received should      not be the person who maintains the accounts receivable records.&lt;/li&gt;&lt;/ul&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in;"&gt;Segregation of duties becomes more important when the size of the organization grows considerably. In small organization it is possible to review most of the transaction by the owner or the top level management of the organization and may see little importance of segregation of duties. As the size of the organization grows, the importance of segregation of duties becomes more and more important. SOD has been observed as the bigger risk especially in the organization whose size is growing fast. It is mainly because SOD is balanced by deep review of top level management for all the critical transaction but when the size of the organization becomes larger it is virtually impossible to offer that level of deep review for those transactions. In such situation the management needs to review the roles of an employee seriously and attempt to minimize this risk. If management overlooks this matter sooner or later the management will have to encounter fraud related problem. &lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8132537442296217309-1837152791905484025?l=bestgovernance.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bestgovernance.blogspot.com/feeds/1837152791905484025/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://bestgovernance.blogspot.com/2009/06/segregation-of-duties.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8132537442296217309/posts/default/1837152791905484025'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8132537442296217309/posts/default/1837152791905484025'/><link rel='alternate' type='text/html' href='http://bestgovernance.blogspot.com/2009/06/segregation-of-duties.html' title='Segregation of Duties'/><author><name>Nischal R Siwakoti</name><uri>http://www.blogger.com/profile/03370311086374566522</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://2.bp.blogspot.com/_Ihf6skjb1AQ/SdL77hWbE7I/AAAAAAAAAA8/JwiRdCmwPxs/S220/PP+Photo.JPg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8132537442296217309.post-6819339388388854965</id><published>2009-06-09T21:57:00.000-07:00</published><updated>2009-06-09T22:01:49.244-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Internal Audit'/><title type='text'>Roles and responsibilities in internal control</title><content type='html'>&lt;div&gt;According to the COSO Framework, everyone in an organization has responsibility for internal control to some extent. Virtually all employees produce information used in the internal control system or take other actions needed to effect control. Also, all personnel should be responsible for communicating upward problems in operations, noncompliance with the code of conduct, or other policy violations or illegal actions. Each major entity in corporate governance has a particular role to play:&lt;br /&gt;&lt;strong&gt;Chief executive officer (CEO)&lt;/strong&gt;: The CEO has ultimate responsibility and ownership of the internal control system. The individual in this role sets the tone at the top that affects the integrity and ethics and other factors that create the positive control environment needed for the internal control system to thrive. Aside from setting the tone at the top, much of the day-to-day operation of the control system is delegated to other senior managers in the company, under the leadership of the CEO.&lt;br /&gt;&lt;strong&gt;Chief financial officer (CFO):&lt;/strong&gt; Much of the internal control structure flows through the accounting and finance area of the organization under the leadership of the CFO. In particular, controls over financial reporting fall within the domain of the chief financial officer. The audit committee should use interactions with the CFO, and others, as a basis for their comfort level on the internal control over financial reporting.&lt;br /&gt;This is not intended to suggest that the CFO must provide the audit committee with a level of assurance regarding the system of internal control over financial reporting. Rather, through interactions with the CFO and others, the audit committee should get a gut feeling about the completeness, accuracy, validity, and maintenance of the system of internal control over financial reporting.&lt;br /&gt;&lt;strong&gt;Controller/director of accounting or finance:&lt;/strong&gt; Much of the basics of the control system come under the domain of this position. It is key that the controller understands the need for the internal control system, is committed to the system, and communicates the importance of the system to all people in the accounting organization. Further, the controller must demonstrate respect for the system though his or her actions.&lt;br /&gt;&lt;strong&gt;Internal audit:&lt;/strong&gt; A main role for the internal audit team is to evaluate the effectiveness of the internal control system and contribute to its ongoing effectiveness. With the internal audit team reporting directly to the audit committee of the board of directors and/or the most senior levels of management, it is often this function that plays a significant role in monitoring the internal control system. It is important to note that many not-for-profits are not large enough to employ an internal audit team. Each organization should assess the need for this team, and employ one as necessary.&lt;br /&gt;&lt;strong&gt;Board of director/audit committee:&lt;/strong&gt; A strong, active board is necessary. This is particularly important when the organization is controlled by an executive or management team with tight reins over the organization and the people within the organization. The board should recognize that its scope of oversight of the internal control system applies to all the three major areas of control: over operations, over compliance with laws and regulations, and over financial reporting. The audit committee is the board's first line of defense with respect to the system of internal control over financial reporting. All other personnel: The internal control system is only as effective as the employees throughout the organization that must comply with it. Employees throughout the organization should understand their role in internal control and the importance of supporting the system through their own actions and encouraging respect for the system by their colleagues throughout the organization.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8132537442296217309-6819339388388854965?l=bestgovernance.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bestgovernance.blogspot.com/feeds/6819339388388854965/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://bestgovernance.blogspot.com/2009/06/roles-and-responsibilities-in-internal.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8132537442296217309/posts/default/6819339388388854965'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8132537442296217309/posts/default/6819339388388854965'/><link rel='alternate' type='text/html' href='http://bestgovernance.blogspot.com/2009/06/roles-and-responsibilities-in-internal.html' title='Roles and responsibilities in internal control'/><author><name>Nischal R Siwakoti</name><uri>http://www.blogger.com/profile/03370311086374566522</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://2.bp.blogspot.com/_Ihf6skjb1AQ/SdL77hWbE7I/AAAAAAAAAA8/JwiRdCmwPxs/S220/PP+Photo.JPg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8132537442296217309.post-8078293056639349014</id><published>2009-06-09T08:08:00.000-07:00</published><updated>2009-06-09T08:18:25.943-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Internal Audit'/><title type='text'>Control Issues and Limitation</title><content type='html'>&lt;meta http-equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 11"&gt;&lt;meta name="Originator" content="Microsoft Word 11"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5CADMINI%7E1%5CLOCALS%7E1%5CTemp%5Cmsohtml1%5C01%5Cclip_filelist.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:WordDocument&gt;   &lt;w:View&gt;Normal&lt;/w:View&gt;   &lt;w:Zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:PunctuationKerning/&gt;   &lt;w:ValidateAgainstSchemas/&gt;   &lt;w:SaveIfXMLInvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:IgnoreMixedContent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:AlwaysShowPlaceholderText&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:Compatibility&gt;    &lt;w:BreakWrappedTables/&gt;    &lt;w:SnapToGridInCell/&gt;    &lt;w:WrapTextWithPunct/&gt;    &lt;w:UseAsianBreakRules/&gt;    &lt;w:DontGrowAutofit/&gt;   &lt;/w:Compatibility&gt;   &lt;w:BrowserLevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;  &lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:LatentStyles DefLockedState="false" LatentStyleCount="156"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;p class="MsoNormal"&gt;&lt;b style=""&gt;&lt;span style="font-family: Arial;"&gt;Cost of controls &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: Arial;"&gt;Costs of controls can include the price of physical safeguards, the value of additional hours of employee work incurred, your time, etc. The costs should be less than the benefits.&lt;span style=""&gt;  &lt;/span&gt;Employee supervision is where most owner-operated businesses get this comparison wrong, particularly by assuming too low a benefit to a control over a long-term and trusted employee. It is not uncommon for the been-there-forever, taken-for-granted, almost-a-member-of-the-family employee to take advantage of the paternal way in which he or she is treated to loot the company blind.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;meta http-equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 11"&gt;&lt;meta name="Originator" content="Microsoft Word 11"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5CADMINI%7E1%5CLOCALS%7E1%5CTemp%5Cmsohtml1%5C01%5Cclip_filelist.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:WordDocument&gt;   &lt;w:View&gt;Normal&lt;/w:View&gt;   &lt;w:Zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:PunctuationKerning/&gt;   &lt;w:ValidateAgainstSchemas/&gt;   &lt;w:SaveIfXMLInvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:IgnoreMixedContent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:AlwaysShowPlaceholderText&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:Compatibility&gt;    &lt;w:BreakWrappedTables/&gt;    &lt;w:SnapToGridInCell/&gt;    &lt;w:WrapTextWithPunct/&gt;    &lt;w:UseAsianBreakRules/&gt;    &lt;w:DontGrowAutofit/&gt;   &lt;/w:Compatibility&gt;   &lt;w:BrowserLevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;  &lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:LatentStyles DefLockedState="false" LatentStyleCount="156"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;b style=""&gt;&lt;span style="font-family: Arial;"&gt;Implementing controls &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: Arial;"&gt;Proper control design and selection are only the first steps. The most important factors in making them work are communication and organization. Simply putting the controls in place won't guarantee their effectiveness.   &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: Arial;"&gt;Make sure that your people are aware of and understand the controls; and then find ways to influence their behavior so that they agree to respect them. Organization issues involved include the chain of command structure, cost constraints, job descriptions, and the company’s formal and informal feedback loops.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;span style="font-size: 12pt; font-family: Arial;"&gt;Every control system needs to be flexible and change as the company evolves. No system of internal controls can completely protect against all risks of theft. Keep in mind that risk is a matter of possibilities and probabilities, and therefore must involve the analysis of both positive and negative outcomes. An analysis of internal controls needs to consider the key risks facing the company, the company’s objectives, and the existing controls and procedures.&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;meta http-equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 11"&gt;&lt;meta name="Originator" content="Microsoft Word 11"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5CADMINI%7E1%5CLOCALS%7E1%5CTemp%5Cmsohtml1%5C01%5Cclip_filelist.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:WordDocument&gt;   &lt;w:View&gt;Normal&lt;/w:View&gt;   &lt;w:Zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:PunctuationKerning/&gt;   &lt;w:ValidateAgainstSchemas/&gt;   &lt;w:SaveIfXMLInvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:IgnoreMixedContent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:AlwaysShowPlaceholderText&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:Compatibility&gt;    &lt;w:BreakWrappedTables/&gt;    &lt;w:SnapToGridInCell/&gt;    &lt;w:WrapTextWithPunct/&gt;    &lt;w:UseAsianBreakRules/&gt;    &lt;w:DontGrowAutofit/&gt;   &lt;/w:Compatibility&gt;   &lt;w:BrowserLevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;  &lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:LatentStyles DefLockedState="false" LatentStyleCount="156"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;b style=""&gt;&lt;span style="font-family: Arial;"&gt;Employee motivation Perceived equity&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family: Arial;"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;span style="font-size: 12pt; font-family: Arial;"&gt;Since it &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;isn&lt;/span&gt;’t always possible to eliminate the opportunities for theft, attention should also be paid to the rationalization used by wrongdoers. Most cases of employee theft or misbehavior involve issues of perceived equity. Employees who perceive that they are not being treated fairly are much more prone to steal from their employer. It is important to be perceived as being fair, but not weak. Make sure all of your employees know what is expected of them, and treat &lt;/span&gt;&lt;meta http-equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 11"&gt;&lt;meta name="Originator" content="Microsoft Word 11"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5CADMINI%7E1%5CLOCALS%7E1%5CTemp%5Cmsohtml1%5C01%5Cclip_filelist.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:WordDocument&gt;   &lt;w:View&gt;Normal&lt;/w:View&gt;   &lt;w:Zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:PunctuationKerning/&gt;   &lt;w:ValidateAgainstSchemas/&gt;   &lt;w:SaveIfXMLInvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:IgnoreMixedContent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:AlwaysShowPlaceholderText&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:Compatibility&gt;    &lt;w:BreakWrappedTables/&gt;    &lt;w:SnapToGridInCell/&gt;    &lt;w:WrapTextWithPunct/&gt;    &lt;w:UseAsianBreakRules/&gt;    &lt;w:DontGrowAutofit/&gt;   &lt;/w:Compatibility&gt;   &lt;w:BrowserLevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;  &lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:LatentStyles DefLockedState="false" LatentStyleCount="156"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;} &lt;/style&gt; &lt;![endif]--&gt;&lt;span style="font-size: 12pt; font-family: Arial;"&gt;everybody consistently. Avoid setting unreachable goals or creating other pressures to commit fraud, remove obstacles that block effective performance, and establish clear and consistent procedures with no exceptions.&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-size: 12pt; font-family: Arial;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;meta http-equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 11"&gt;&lt;meta name="Originator" content="Microsoft Word 11"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5CADMINI%7E1%5CLOCALS%7E1%5CTemp%5Cmsohtml1%5C01%5Cclip_filelist.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:WordDocument&gt;   &lt;w:View&gt;Normal&lt;/w:View&gt;   &lt;w:Zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:PunctuationKerning/&gt;   &lt;w:ValidateAgainstSchemas/&gt;   &lt;w:SaveIfXMLInvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:IgnoreMixedContent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:AlwaysShowPlaceholderText&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:Compatibility&gt;    &lt;w:BreakWrappedTables/&gt;    &lt;w:SnapToGridInCell/&gt;    &lt;w:WrapTextWithPunct/&gt;    &lt;w:UseAsianBreakRules/&gt;    &lt;w:DontGrowAutofit/&gt;   &lt;/w:Compatibility&gt;   &lt;w:BrowserLevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;  &lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:LatentStyles DefLockedState="false" LatentStyleCount="156"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;b style=""&gt;&lt;span style="font-family: Arial;"&gt;Limitations:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: Arial;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: Arial;"&gt;Internal control can provide reasonable, not absolute, assurance that the objectives of an organization will be met. The concept of reasonable assurance implies a high degree of assurance, constrained by the costs and benefits of establishing incremental control procedures.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: Arial;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: Arial;"&gt;Effective internal control implies the organization generates reliable financial reporting and substantially complies with the laws and regulations that apply to it. However, whether an organization achieves operational and strategic objectives may depend on factors outside the enterprise, such as competition or technological innovation. These factors are outside the scope of internal control; therefore, effective internal control provides only timely information or feedback on progress towards the achievement of operational and strategic objectives, but cannot guarantee their achievement.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family: Arial;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;span style="font-size: 12pt; font-family: Arial;"&gt;Internal control involves human action, which introduces the possibility of errors in processing or judgment. Internal control can also be overridden by collusion among employees (see separation of duties) or coercion by top management.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8132537442296217309-8078293056639349014?l=bestgovernance.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bestgovernance.blogspot.com/feeds/8078293056639349014/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://bestgovernance.blogspot.com/2009/06/control-issues-and-limitation.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8132537442296217309/posts/default/8078293056639349014'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8132537442296217309/posts/default/8078293056639349014'/><link rel='alternate' type='text/html' href='http://bestgovernance.blogspot.com/2009/06/control-issues-and-limitation.html' title='Control Issues and Limitation'/><author><name>Nischal R Siwakoti</name><uri>http://www.blogger.com/profile/03370311086374566522</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://2.bp.blogspot.com/_Ihf6skjb1AQ/SdL77hWbE7I/AAAAAAAAAA8/JwiRdCmwPxs/S220/PP+Photo.JPg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8132537442296217309.post-81871312311611017</id><published>2009-06-06T09:17:00.000-07:00</published><updated>2009-06-07T08:18:35.415-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Internal Audit'/><title type='text'>Preventive and Detective Controls</title><content type='html'>&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 11"&gt;&lt;meta name="Originator" content="Microsoft Word 11"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5CADMINI%7E1%5CLOCALS%7E1%5CTemp%5Cmsohtml1%5C01%5Cclip_filelist.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;  &lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" latentstylecount="156"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face 	{font-family:Wingdings; 	panose-1:5 0 0 0 0 0 0 0 0 0; 	mso-font-charset:2; 	mso-generic-font-family:auto; 	mso-font-pitch:variable; 	mso-font-signature:0 268435456 0 0 -2147483648 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;}  /* List Definitions */  @list l0 	{mso-list-id:1033963838; 	mso-list-type:hybrid; 	mso-list-template-ids:-1493246760 67698689 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;} @list l0:level1 	{mso-level-number-format:bullet; 	mso-level-text:; 	mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in; 	font-family:Symbol;} @list l1 	{mso-list-id:1854343295; 	mso-list-type:hybrid; 	mso-list-template-ids:1743533450 67698689 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;} @list l1:level1 	{mso-level-number-format:bullet; 	mso-level-text:; 	mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in; 	font-family:Symbol;} ol 	{margin-bottom:0in;} ul 	{margin-bottom:0in;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;p class="MsoNormal"&gt;&lt;font face="Arial"&gt;Controls can be either preventive or detective. The intent of these controls is different. Preventive controls attempt to deter or prevent undesirable events from occurring. They are proactive controls that help to prevent a loss. Examples of preventive controls are separation of duties, proper authorization, adequate documentation, and physical control over assets. Few Example of detective controls are given below:&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;  &lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal" style=""&gt;&lt;font face="Arial"&gt;Obtaining pre-approval      on actions or transactions before they can be processed &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;font face="Arial"&gt;Using document control      numbers to make sure all transactions are accounted for &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;font face="Arial"&gt;Matching and comparing      documents from different sources to ensure integrity &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;font face="Arial"&gt;Testing clerical      accuracy &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;font face="Arial"&gt;Locks on doors and      gates &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;font face="Arial"&gt;Physical controls over      cash, checks, signature plates, and&lt;font style=""&gt;       &lt;/font&gt;inventory &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;font face="Arial"&gt;Computer passwords,      access controls, and file locks, to prevent unauthorized electronic access      &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;font face="Arial"&gt;Computer backups for      both audit trails and disaster planning &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;font face="Arial"&gt;Batch totals on data      entry work &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;font face="Arial"&gt;Validating input data      against established parameters to ensure accurate keypunching. &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;font face="Arial"&gt;Segregation of duties,      well defined job descriptions and standards &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;font face="Arial"&gt;Job rotation, enforced      vacations, etc., to reduce chances of long-term embezzlement schemes &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;font face="Arial"&gt;Employee screening and      training programs &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;font face="Arial"&gt;Drug testing of      employees and applicants&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;p class="MsoNormal"&gt;&lt;font face="Arial"&gt;Preventive controls are subject to breakdown, with the biggest cause being individual circumvention. Sometimes it is malicious and sometimes it is well intentioned (we can get from one department to another easier if we prop the locked doors open, for example, or I can cut my data entry time by a third if I dummy my batch totals). In some companies physical controls are widely ignored – most major thefts of inventory happen in front of other employees who either assume that the thief is acting properly, or do not want to get involved.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;font face="Arial"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;font face="Arial"&gt;Detective controls, on the other hand, attempt to detect undesirable acts. They provide evidence that a loss has occurred but do not prevent a loss from occurring. Examples of detective controls are reviews, analyses, variance analyses, reconciliations, physical inventories, and audits. Some Examples are:&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;  &lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal" style=""&gt;&lt;font face="Arial"&gt;Enforcement of job      descriptions and standards to keep employees acting as expected &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;font face="Arial"&gt;Supervisory review and      sign-off of accounting work, expense reports, commission statements,      payroll data, etc. &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;font face="Arial"&gt;Cycle counts of      inventory &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;font face="Arial"&gt;Surprise cash counts &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;font face="Arial"&gt;Management review and      approval of account write-offs &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;font face="Arial"&gt;Review of monitoring      information and reports to ensure that controls are functioning as planned      &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;font face="Arial"&gt;Exception reporting      and resolution to highlight out-of-the-norm items &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;font face="Arial"&gt;internal audit &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;font face="Arial"&gt;Supervisory peer      review &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;p class="MsoNormal"&gt;&lt;font face="Arial"&gt;Comparison of actual results to budgeted or forecasted results &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;font face="Arial"&gt;Detective controls tend to be less expensive and more reliable than the preventive controls discussed earlier, because they can often be applied over a large number of transactions in a short time. &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;font face="Arial"&gt;  &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;font face="Arial"&gt;If detective controls review less than 100 percent of a certain activity, their review has to be somewhat random. If cash drawers are “surprise” counted by management Mondays, Wednesdays, and Fridays (60 percent of all work days), the counts are predictable and cash skimming will most likely occur during the other days of the week. Random counts would tend to deter skimming because they are unpredictable. &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;font face="Arial"&gt;  &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;font face="Arial"&gt;Since fraud perpetrators either ignore or compromise the preventive controls in place, it is imperative that management perform its supervisory and monitoring functions. Do not be afraid to manage – people generally want and need both direction and feedback in order to feel satisfied with their work. &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;font face="Arial"&gt;  &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;font face="Arial"&gt;Like preventive controls, detective controls are also subject to breakdown. To minimize the chance of both types of control breaking down, it is important to design the controls so that they do not get subverted – control the right thing and make the control easy to follow, implement, monitor, and reinforce. Implement the control properly, monitor and evaluate any feedback related to the control, and whenever possible, tie controls to incentive systems.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;font face="Arial"&gt;Both types of controls are essential to an effective internal control system. From a quality&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;font face="Arial"&gt;Point, preventive controls are essential because they are proactive and emphasize quality.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;font face="Arial"&gt;However, detective controls play a critical role providing evidence that the preventive controls are functioning and preventing losses.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;font face="Arial"&gt;Control activities include approvals, authorizations, verifications, reconciliations, reviews of performance, security of assets, segregation of duties, and controls over information systems.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8132537442296217309-81871312311611017?l=bestgovernance.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bestgovernance.blogspot.com/feeds/81871312311611017/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://bestgovernance.blogspot.com/2009/06/preventive-and-detective-controls.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8132537442296217309/posts/default/81871312311611017'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8132537442296217309/posts/default/81871312311611017'/><link rel='alternate' type='text/html' href='http://bestgovernance.blogspot.com/2009/06/preventive-and-detective-controls.html' title='Preventive and Detective Controls'/><author><name>Nischal R Siwakoti</name><uri>http://www.blogger.com/profile/03370311086374566522</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://2.bp.blogspot.com/_Ihf6skjb1AQ/SdL77hWbE7I/AAAAAAAAAA8/JwiRdCmwPxs/S220/PP+Photo.JPg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8132537442296217309.post-6299506302280934154</id><published>2009-06-05T10:38:00.000-07:00</published><updated>2009-06-06T08:49:05.154-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Internal Audit'/><title type='text'>Internal Control Objectives</title><content type='html'>&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 11"&gt;&lt;meta name="Originator" content="Microsoft Word 11"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5CADMINI%7E1%5CLOCALS%7E1%5CTemp%5Cmsohtml1%5C01%5Cclip_filelist.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;  &lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" latentstylecount="156"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;p class="MsoNormal"&gt;&lt;font face="Arial"&gt;Internal Control objectives are desired goals or conditions for a specific event cycle which, if achieved, minimize the potential that waste, loss, unauthorized use or misappropriation will occur.&lt;font style=""&gt;  &lt;/font&gt;They are conditions which we want the system of internal control to satisfy.&lt;font style=""&gt;  &lt;/font&gt;For a control objective to be effective, compliance with the control activities must be measurable and observable.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;font face="Arial"&gt;Control activities are the policies and procedures that help ensure management directives are carried out and these are designed in such a manner that it achieves the control objective. Effectiveness of control objective solely depends upon the effective design of control activities to address the need of control objective. &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;font face="Arial"&gt;The control objectives include authorization, completeness, accuracy, validity, physical safeguards and security, error handling and segregation of duties.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;font face="Arial"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b style=""&gt;&lt;font face="Arial"&gt;Authorization&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;font face="Arial"&gt;The objective is to ensure that all transactions are approved by responsible personnel in accordance with specific or general authority before the transaction is recorded.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b style=""&gt;&lt;font face="Arial"&gt;Completeness&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;font face="Arial"&gt;The objective is to ensure that no valid transactions have been omitted from the accounting records.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b style=""&gt;&lt;font face="Arial"&gt;Accuracy&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;font face="Arial"&gt;The objective is to ensure that all valid transactions are accurate, consistent with the originating transaction data and information is recorded in a timely manner.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b style=""&gt;&lt;font face="Arial"&gt;Validity&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;font face="Arial"&gt;The objective is to ensure that all recorded transactions fairly represent the economic events that actually occurred, are lawful in nature, and have been executed in accordance with management's general authorization.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b style=""&gt;&lt;font face="Arial"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b style=""&gt;&lt;font face="Arial"&gt;Physical Safeguards &amp;amp; Security&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;font face="Arial"&gt;The objective is to ensure that access to physical assets and information systems are controlled and properly restricted to authorized personnel.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b style=""&gt;&lt;font face="Arial"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b style=""&gt;&lt;font face="Arial"&gt;Error handling&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;font face="Arial"&gt;The objective is to ensure that errors detected at any stage of processing receive prompt corrective action and are reported to the appropriate level of management.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b style=""&gt;&lt;font face="Arial"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b style=""&gt;&lt;font face="Arial"&gt;Segregation of Duties&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;font face="Arial"&gt;The objective is to ensure that duties are assigned to individuals in a manner that ensures that no one individual can control both the recording function and the procedures relative to processing the transaction.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;font face="Arial"&gt;A well designed process with appropriate internal controls should meet most, if not all of these control objectives.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8132537442296217309-6299506302280934154?l=bestgovernance.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bestgovernance.blogspot.com/feeds/6299506302280934154/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://bestgovernance.blogspot.com/2009/06/internal-control-objectives.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8132537442296217309/posts/default/6299506302280934154'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8132537442296217309/posts/default/6299506302280934154'/><link rel='alternate' type='text/html' href='http://bestgovernance.blogspot.com/2009/06/internal-control-objectives.html' title='Internal Control Objectives'/><author><name>Nischal R Siwakoti</name><uri>http://www.blogger.com/profile/03370311086374566522</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://2.bp.blogspot.com/_Ihf6skjb1AQ/SdL77hWbE7I/AAAAAAAAAA8/JwiRdCmwPxs/S220/PP+Photo.JPg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8132537442296217309.post-6087239947959755550</id><published>2009-06-02T06:57:00.000-07:00</published><updated>2009-06-02T07:00:46.157-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Internal Audit'/><title type='text'>Component of Internal Control</title><content type='html'>Internal Control consists of five interrelated component. Internal control systems operate at different levels of effectiveness. Determining whether a particular internal control system is effective is a judgment resulting from an assessment of whether the five components - Control Environment, Risk Assessment, Control Activities, Information and Communication, and Monitoring - are present and functioning. Effective controls provide reasonable assurance regarding the accomplishment of established objectives.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Control environment:&lt;br /&gt;&lt;/strong&gt;It is an overall attitude of the management towards the existence and effectiveness of control.The control environment is the control consciousness of an organization. It is the atmosphere in which people conduct their activities and carry out their control responsibilities. An effective control environment is an environment where competent people understand their responsibilities, the limits to their authority, and are knowledgeable, mindful, and committed to doing what is right and doing it the right way. They are committed to following an organization's policies and procedures and its ethical and behavioral standards.&lt;br /&gt;The control environment encompasses technical competence and ethical commitment; it is an intangible factor that is essential to effective internal control.&lt;br /&gt;A governing board and management enhance an organization's control environment when they establish and effectively communicate written policies and procedures, a code of ethics, and standards of conduct. Moreover, a governing board and management enhance the control environment when they behave in an ethical manner-creating a positive "tone at the top"—and when they require that same standard of conduct from everyone in the organization.&lt;br /&gt;Leaders of each department, area or activity establish a local control environment. This is the foundation for all other components of internal control, providing discipline and structure. Control environment factors include:&lt;br /&gt;·        Integrity and ethical values;&lt;br /&gt;·        The commitment to competence;&lt;br /&gt;·        Leadership philosophy and operating style;&lt;br /&gt;·        The way management assigns authority and responsibility, and organizes and develops its people;&lt;br /&gt;·        Policies and procedures&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Risk Assessment:&lt;br /&gt;&lt;/strong&gt;Risk is an uncertainty associated with an event the outcome of which could adversely affect the attainment of organization objective. Every entity faces a variety of risks from external and internal sources that must be assessed. A precondition to risk assessment is establishment of objectives, linked at different levels and internally consistent. Risk assessment is the identification and analysis of relevant risks to achievement of the objectives, forming a basis for determining how the risks should be managed. Because economics, regulatory and operating conditions will continue to change, mechanisms are needed to identify and deal with the special risks associated with change.&lt;br /&gt;Objectives must be established before administrators can identify and take necessary steps to manage risks. Operations objectives relate to effectiveness and efficiency of the operations, including performance and financial goals and safeguarding resources against loss. Financial reporting objectives pertain to the preparation of reliable published financial statements, including prevention of fraudulent financial reporting. Compliance objectives pertain to laws and regulations which establish minimum standards of behavior. The process of identifying and analyzing risk is an ongoing process and is a critical component of an effective internal control system. Attention must be focused on risks at all levels and necessary actions must be taken to manage. Risks can pertain to internal and external factors. After risks have been identified they must be evaluated.&lt;br /&gt;Managing change requires a constant assessment of risk and the impact on internal controls. Economic, industry and regulatory environments change and entities' activities evolve. Mechanisms are needed to identify and react to changing conditions.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Control Activities&lt;br /&gt;&lt;/strong&gt;Control activities are actions, supported by policies and procedures that, when carried out properly and in a timely manner, manage or reduce risks. In other words Control activities are the policies and procedures that help to ensure management directives are carried out. They help in ensuring that necessary actions are taken to address risks to achievement of the entity's objectives. Control activities occur throughout the organization, at all levels, and in all functions. They include a range of activities as diverse as approvals, authorizations, verifications, reconciliations, reviews of operating performance, security of assets and segregation of duties.&lt;br /&gt;Who is Responsible? In the same way that managers are primarily responsible for identifying the financial and compliance risks for their operations, they also have line responsibility for designing, implementing and monitoring their internal control system.&lt;br /&gt;Control activities usually involve two elements: a policy establishing what should be done and designing procedures to implement the policy. All policies must be implemented thoughtfully, conscientiously and consistently.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Information and Communication&lt;/strong&gt;&lt;br /&gt;Pertinent information must be identified, captured and communicated in a form and time frame that enables people to carry out their responsibilities. Effective communication must occur in a broad sense, flowing down, across and up the organization. All personnel must receive a clear message from top management that control responsibilities must be taken seriously. They must understand their own role in the internal control system, as well as how individual activities relate to the work of others. They must have a means of communicating significant information upstream.&lt;br /&gt;Reliable and relevant information from both internal and external sources must be identified, captured, processed, and communicated to the people who need it--in a form and &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;timeframe&lt;/span&gt; that is useful. Information systems produce reports, containing operational, financial, and compliance-related information that makes it possible to run and control an organization.&lt;br /&gt;Information and communication systems can be formal or informal. Formal information and communication systems--which range from sophisticated computer technology to simple staff meetings-should provide input and feedback data relative to operations, financial reporting, and compliance objectives; such systems are vital to an organization's success.&lt;br /&gt;When assessing internal control over a significant activity (or process), the key questions to ask about information and communication are as follows:&lt;br /&gt;Does our department get the information it needs from internal and external sources in a form and &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;timeframe&lt;/span&gt; that is useful?&lt;br /&gt;Does our department get information that alerts it to internal or external risks (e.g. legislative, regulatory, and developments)?&lt;br /&gt;Does our department get information that measures its performance-information that tells the department whether it is achieving its operations, financial reporting, and compliance objectives?&lt;br /&gt;Does our department identifies, capture, process, and communicate the information that others need (e.g., information used by our customers or other departments)-in a form and &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;timeframe&lt;/span&gt; that is useful?&lt;br /&gt;Does our department provide information to others that alerts them to internal or external risks?&lt;br /&gt;Does our department communicate effectively--internally and externally?&lt;br /&gt;&lt;br /&gt;Information and communication are simple concepts. Nevertheless, communicating with people and getting information to people in a form and &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;timeframe&lt;/span&gt; that is useful to them is a constant challenge. When completing a Business Controls Worksheet for a significant activity (or process) in a department, evaluate the quality of related information and communication systems.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Monitoring&lt;br /&gt;&lt;/strong&gt;Monitoring is the assessment of internal control performance over time; it is accomplished by ongoing monitoring activities and by separate evaluations of internal control such as self-assessments, peer reviews, and internal audits. The purpose of monitoring is to determine whether internal control is adequately designed, properly executed, and effective. Internal control is adequately designed and properly executed if all five internal control components (Control Environment, Risk Assessment, Control Activities, Information and Communication, and Monitoring) are present and functioning as designed. Internal control is effective if management and interested stakeholders have reasonable assurance that:&lt;br /&gt;They understand the extent to which operations objectives are being achieved.&lt;br /&gt;Published financial statements are being prepared reliably.&lt;br /&gt;Applicable laws and regulations are being compiled.&lt;br /&gt;While internal control is a process, its effectiveness is an assessment of the condition of the process at one or more points in time. Just as control activities help to ensure that actions to manage risks are carried out, monitoring helps to ensure that control activities and other planned actions to effect internal control are carried out properly and in a timely manner and that the end result is effective internal control.&lt;br /&gt;Ongoing monitoring activities include various management and supervisory activities that evaluate and improve the design, execution, and effectiveness of internal control. Separate evaluations, on the other hand, such as self-assessments and internal audits, are periodic evaluations of internal control components resulting in a formal report on internal control. Department employees perform self-assessments; internal auditors who provide an independent appraisal of internal control perform internal audits. Management's role in the internal control system is critical to its effectiveness. Managers, like auditors, don't have to look at every single piece of information to determine that the controls are functioning and should focus their monitoring activities in high-risk areas. The use of spot checks of transactions or basic sampling techniques can provide a reasonable level of confidence that the controls are functioning as intended.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8132537442296217309-6087239947959755550?l=bestgovernance.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bestgovernance.blogspot.com/feeds/6087239947959755550/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://bestgovernance.blogspot.com/2009/06/component-of-internal-control.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8132537442296217309/posts/default/6087239947959755550'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8132537442296217309/posts/default/6087239947959755550'/><link rel='alternate' type='text/html' href='http://bestgovernance.blogspot.com/2009/06/component-of-internal-control.html' title='Component of Internal Control'/><author><name>Nischal R Siwakoti</name><uri>http://www.blogger.com/profile/03370311086374566522</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://2.bp.blogspot.com/_Ihf6skjb1AQ/SdL77hWbE7I/AAAAAAAAAA8/JwiRdCmwPxs/S220/PP+Photo.JPg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8132537442296217309.post-7061121428067120479</id><published>2009-06-02T06:52:00.000-07:00</published><updated>2009-06-02T06:56:07.209-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Internal Audit'/><title type='text'>Internal Control</title><content type='html'>&lt;ul&gt;&lt;li&gt;If company owners did all the work themselves, assuming they always acted in their own best interest, there would be virtually no loss from internal theft, unreliable financial reporting, non-compliance with applicable laws and regulations, or inefficient use of resources.&lt;br /&gt;As soon as you hire employees or outside contractors, you introduce those losses, or at least the risk of those losses. To control that risk, the owners then need to set goals and objectives for employees to strive for, define tasks, identify and quantify risks, establish policies, set boundaries, monitor progress, and take corrective action when needed.&lt;br /&gt;&lt;strong&gt;Control what?&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;Before designing a system of internal controls, it is important to understand what needs to be controlled. This involves identifying risks and the potential cost of each risk. Determine how often you expect each type of loss would likely occur, and what the cost per occurrence is likely to be. Multiply these two numbers together to get the total loss potential for each type of loss. Later you will compare loss potential with the cost of controls, in order to do a cost-benefit analysis and make sure controls don’t cost more than the potential losses they are designed to prevent.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Meaning:&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;The systems used by a company to minimize the risk of loss are known as internal controls. Internal control is the responsibility of both directors and managers of the company.&lt;br /&gt;&lt;br /&gt;Internal Control System is system of controls, both financial and non-financial, set up by the management of an organization to carry out the function of the company in an orderly and efficient manner. The system should ensure that management policies are adhered to, assets are safeguarded, and the records of the company's activities are both complete and accurate. In other words, internal control is defined as a process established by an organization's structure, work and authority flows, people and management information systems, designed to help the organization accomplish specific goals or objectives. It is a means by which an organization's resources are directed, monitored, and measured. It provides reasonable assurance of&lt;br /&gt;Effectiveness and efficiency of operations,&lt;br /&gt;reliability of financial reporting, safeguarding of assets,&lt;br /&gt;reliability and integrity of information assets and&lt;br /&gt;Compliance with policies, procedures, laws and regulations.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Internal control is a process; it is means to an end and not an end itself:&lt;br /&gt;&lt;/strong&gt;Internal control assists in achieving the organizational goal in more systematic and organized manner. Organisation aim to maintain good internal control to achieve its objective, off course maintaining the sound internal control system alone will not achieve its objective, it is one of the effort organization has to make in order to reach its goal.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Effective internal control helps an organization achieve its operations, financial Reporting and compliance objectives:&lt;br /&gt;&lt;/strong&gt;Effective internal control is a built-in part of the management process (i.e., plan, organize, direct, and control). Internal control keeps an organization on course toward its objectives and the achievement of its mission, and minimizes surprises along the way. Internal control promotes effectiveness and efficiency of operations, reduces the risk of asset loss, and helps to ensure compliance with laws and regulations. Internal control also ensures the reliability of financial reporting (i.e., all transactions are recorded and that all recorded transactions are real, properly valued, recorded on a timely basis, properly classified, correctly summarized and posted).&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;People at every level of an organization affect internal control:&lt;br /&gt;&lt;/strong&gt;Internal control is affected by people; it’s not merely policy, manual, and forms, but people at every level of the organization. In other words the traditional understanding of internal audit limited to policy, manual and forms no longer support achieving business objective in today’s complex and dynamic challenging work environment. In the present context every people of the organization is part for effective internal control.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Internal control can provide only reasonable assurance - not absolute assurance -regarding the achievement of an organization's objective:&lt;br /&gt;&lt;/strong&gt;Plenty of stakeholders and managers still believe that implementation of internal control gives them absolute assurance relating to effectiveness and efficiency of their operation to entity’s management and other stakeholders; this concept has to be clarified so that over reliance on internal control can be prevented. The stakeholders must be educated that the existence of internal control does not give absolute assurance to the business. The internal control merely gives reasonable assurance to the business. Off course Effective internal control helps an organization achieve its objectives; it does not ensure success. There are several reasons why internal control cannot provide absolute assurance that objectives will be achieved: cost/benefit realities, collusion among employees, and external events beyond an organization's control.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt; &lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8132537442296217309-7061121428067120479?l=bestgovernance.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bestgovernance.blogspot.com/feeds/7061121428067120479/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://bestgovernance.blogspot.com/2009/06/internal-control.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8132537442296217309/posts/default/7061121428067120479'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8132537442296217309/posts/default/7061121428067120479'/><link rel='alternate' type='text/html' href='http://bestgovernance.blogspot.com/2009/06/internal-control.html' title='Internal Control'/><author><name>Nischal R Siwakoti</name><uri>http://www.blogger.com/profile/03370311086374566522</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://2.bp.blogspot.com/_Ihf6skjb1AQ/SdL77hWbE7I/AAAAAAAAAA8/JwiRdCmwPxs/S220/PP+Photo.JPg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8132537442296217309.post-8157275642600704629</id><published>2009-04-29T04:47:00.000-07:00</published><updated>2009-04-29T19:13:14.979-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Internal Audit'/><title type='text'>Internal Audit-Defination</title><content type='html'>The globally accepted body the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;IIA&lt;/span&gt; defines Internal Audit as an  an independent, objective assurance and consulting activity designed to add value and improve an organization's operations. It helps an organization accomplish its objectives by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of risk management, control, and governance processes.&lt;br /&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;Investorwords&lt;/span&gt;, a business dictionary defines internal audit as an ongoing appraisal of the financial health of a company's operations by its own employees. Employees who carry out this function are called internal auditors. During an internal audit, internal auditors will evaluate and monitor a company's risk management, reporting, and control practices and make suggestions for improvement. Internal auditing covers not only an organization's finance function, but all the operations and systems in a firm. While internal auditors are typically accountants, this activity can also be carried out by other professionals who are well-versed with a company's functions and the relevant regulatory requirements.&lt;br /&gt;Moreover, internal auditing is an independent professional service, to serve not just management but the whole organisation and its &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_2"&gt;stakeholders&lt;/span&gt;. This means that the internal auditing customer base includes all stakeholders including employees, suppliers, customers, investors, external auditors etc.&lt;br /&gt;Internal audit is a progressive division within the Resources Directorate.  We provide independent assurance on the adequacy of risk management, control and governance to the Board of Directors.  We undertake this by carrying a programme of audits throughout the authority, and provide advice and assistance to managers at all levels on a range of audit related matters such as risk management, internal control, corporate governance and project / programme management.&lt;br /&gt;Careful analysis of the &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_3"&gt;definition&lt;/span&gt; of Internal Audit given by &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;IIA&lt;/span&gt; clearly shows two important functions of the Internal Audit mainly assurance and consulting.&lt;br /&gt;The assurance role of the internal audit function mainly require the auditors to give assurance to the stakeholders around adequacy and effective functioning of risk management, control and governance processes.&lt;br /&gt;The consulting roles of Internal Audit specially helps management through its technical knowledge and experience to improve the adequacy and effectiveness functioning of risk management, control and governance processes by partnering with management in designing effective system.&lt;br /&gt;Normally it is found that IA put consulting role more in small organisation or organisation where risk management, control and governance &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_5"&gt;roles&lt;/span&gt; are poor. Furthermore, if we observe the normal audit report we will found two part in the report the first part focus on assurance and recommendation part mainly focus on consulting role of internal audit.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8132537442296217309-8157275642600704629?l=bestgovernance.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bestgovernance.blogspot.com/feeds/8157275642600704629/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://bestgovernance.blogspot.com/2009/04/internal-audit-defination.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8132537442296217309/posts/default/8157275642600704629'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8132537442296217309/posts/default/8157275642600704629'/><link rel='alternate' type='text/html' href='http://bestgovernance.blogspot.com/2009/04/internal-audit-defination.html' title='Internal Audit-Defination'/><author><name>Nischal R Siwakoti</name><uri>http://www.blogger.com/profile/03370311086374566522</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://2.bp.blogspot.com/_Ihf6skjb1AQ/SdL77hWbE7I/AAAAAAAAAA8/JwiRdCmwPxs/S220/PP+Photo.JPg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8132537442296217309.post-2191986165885124476</id><published>2009-04-26T01:59:00.000-07:00</published><updated>2009-04-29T19:13:14.979-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Internal Audit'/><title type='text'>Internal Audit Profession-Brief History</title><content type='html'>Most of us have been doing Internal Auditing and providing wonderful support to achieve the organisational objectives. But it is very much possible that we do not know the history of evolution of the profession. In order to give a brief insight on the subject matter, research was done and following findings were observed.&lt;br /&gt;The practice of internal audit was first formally described in 1938, with the foundation of the Institute of Internal Auditors (IIA),with booming growth of business size and structure it was felt that many &lt;a title="Business" href="http://uncyclopedia.wikia.com/wiki/Business"&gt;businesses&lt;/a&gt; did not have appropriate controls in place to permit full achievement of their strategic objectives.&lt;br /&gt;Initially, the IIA comprised only three accountants and a secretary. Early work proved surprisingly successful in convincing the Executive Board of &lt;a title="IBM (not yet written)" href="http://uncyclopedia.wikia.com/index.php?title=IBM&amp;amp;action=edit&amp;amp;redlink=1"&gt;IBM&lt;/a&gt; that they should spend vast amounts of money having some complete stranger tell them they needed to sign and date all reports to confirm they had been reviewed. Initial fees were in the order of $700 (worth $12bn at today’s prices). These funds were shrewdly invested, by means of a blind trust, to yield an income equivalent to that of a small (well-controlled) country.&lt;br /&gt;In 1939, the Nazi Party were the first government to recognise the importance of having a well-controlled mechanism for running an evil, world-conquering regime. The IIA were contracted to undertake a series of efficiency reviews in the early weeks of &lt;a title="World War II" href="http://uncyclopedia.wikia.com/wiki/World_War_II"&gt;World War II&lt;/a&gt;.&lt;br /&gt;However, Heinrich Himmler failed to authorise a proper scope for the work, with the inevitable result that everything became subject to a series of "Value for Money" reviews. Even the Gestapo operated under the cloak of fear that, one day, a pleasant-but-determined auditor might demand to see a complete breakdown of the number of traitors who had been interrogated and, hence, reports on the number successfully converted to patriots.&lt;br /&gt;During the next six years, the IIA became the most feared body in the world, consuming resources and eventually crushing fascism into the ground by demanding to current authorised signatory lists relating to the &lt;a title="Holocaust" href="http://uncyclopedia.wikia.com/wiki/Holocaust"&gt;Holocaust&lt;/a&gt; and undertaking regular stock takes at the Eastern Front.&lt;br /&gt;Eventually, the ever-increasing need to comply with interim internal audit reports ensured that the war machine ground to a halt. The Allied Forces, apparently unconcerned with appropriate document retention strategies or enforcing segregation of duties amongst senior managers, swept across Europe and introduced democracy. They also introduced an interesting range of sexually transmitted diseases, but that's not important when freedom is at stake.&lt;br /&gt;With the final report on &lt;a title="World War II" href="http://uncyclopedia.wikia.com/wiki/World_War_II"&gt;World War II&lt;/a&gt;, a total of 6,395 management action points were raised to enhance controls in the remnants of &lt;a title="Germany" href="http://uncyclopedia.wikia.com/wiki/Germany"&gt;Germany&lt;/a&gt;. The resulting emergence of Europe as a global economic power has since been touted as the greatest success of internal audit in terms of adding value.&lt;br /&gt;During the dark years of the &lt;a title="1960s" href="http://uncyclopedia.wikia.com/wiki/1960s"&gt;1960s&lt;/a&gt; and &lt;a title="1970s" href="http://uncyclopedia.wikia.com/wiki/1970s"&gt;1970s&lt;/a&gt;, a number of rival organisations began to challenge the professional standards and objectivity of the IIA. These included such organisations like The Institute of Chartered &lt;a title="Accountant" href="http://uncyclopedia.wikia.com/wiki/Accountant"&gt;Accountants&lt;/a&gt; in England and Wales, EDP Auditors Association (now known as the Information Systems Audit and Mind Control Association); Auditing &lt;a title="Sadism" href="http://uncyclopedia.wikia.com/wiki/Sadism"&gt;Practices&lt;/a&gt; Board; The "Real" IIA (a radical splinter faction of the original IIA); and Audit Bureau of Circulation.&lt;br /&gt;To this day, regular street rumbles take place as the various bodies try to establish their supremacy above the others as the de facto providers of high quality, accessible and professional management assurance. Common weapons include slide rules, adding machines and cocktail sticks.&lt;br /&gt;After the world war II, different management philosophy were evolved as growth and expansion was continuously increasing making the business process more complex and fast changing. This made it increasingly difficult for organizations to maintain control and operational efficiency. The shift to a war economy further expanded organizations' responsibilities for scheduling, availability of materials and laborers, compliance with government regulations, and an increased emphasis on cost finding. The Internal Auditing profession evolved steadily with the progress of management science after World War II. It is conceptually similar in many ways to &lt;a title="Financial audit" href="http://en.wikipedia.org/wiki/Financial_audit"&gt;financial auditing&lt;/a&gt; by public accounting firms, quality assurance and banking compliance activities. Much of the theory underlying internal auditing is derived from management consulting and public accounting professions.&lt;br /&gt;Management found it impossible to visually observe all of the operating areas in their respective areas of responsibility or to have sufficient personal contact with individuals who directly or indirectly reported to them. In seeking ways to deal with these new problems, management appointed special staff people to review and report on what was happening and to probe for the why. These people came to be known as "internal auditors."&lt;br /&gt;The internal audit function varied greatly as to the number of people assigned to perform it and in the scope and nature of the work being done. In some organizations, internal auditors were used to check on routine financial and operational activities with a heavy emphasis on compliance, security, and detection of fraud. In others, internal auditors were given higher levels of status and were asked to analyze and appraise more substantive financial and operational activities.&lt;br /&gt;As the profession evolved, a number of internal auditors began pushing vigorously for greater understanding and recognition of their function, and began to develop contacts and relationships with professionals in other organizations in an attempt to share problems and to advance their common interests. With the implementation in the United States of the &lt;a title="Sarbanes-Oxley Act" href="http://en.wikipedia.org/wiki/Sarbanes-Oxley_Act"&gt;Sarbanes-Oxley Act&lt;/a&gt; of 2002, the profession's growth accelerated, as many internal auditors possess the skills required to help companies meet the requirements of the law.&lt;br /&gt;Sources: The IIA, WIKI and other online journals&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8132537442296217309-2191986165885124476?l=bestgovernance.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bestgovernance.blogspot.com/feeds/2191986165885124476/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://bestgovernance.blogspot.com/2009/04/internal-audit-profession-brief-history.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8132537442296217309/posts/default/2191986165885124476'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8132537442296217309/posts/default/2191986165885124476'/><link rel='alternate' type='text/html' href='http://bestgovernance.blogspot.com/2009/04/internal-audit-profession-brief-history.html' title='Internal Audit Profession-Brief History'/><author><name>Nischal R Siwakoti</name><uri>http://www.blogger.com/profile/03370311086374566522</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://2.bp.blogspot.com/_Ihf6skjb1AQ/SdL77hWbE7I/AAAAAAAAAA8/JwiRdCmwPxs/S220/PP+Photo.JPg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8132537442296217309.post-5192454054852432419</id><published>2009-04-25T06:19:00.000-07:00</published><updated>2009-04-25T06:24:31.904-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Fraud and Investigation'/><title type='text'>Fraud, Investigation &amp; Responsibility</title><content type='html'>Fraud is an intentional misrepresentation of fact in order to steal the assets of the organisation.&lt;br /&gt;Investigation is the process of inquiring into a matter through research, follow-up, study, or formal procedure of discovery.&lt;br /&gt; Fraud is very hot and ongoing topic in today's corporate world. Enron to Dotcom and now to Satyam, all we talk and think about dealing with fraud. We can see, fraud is universal in nature occurring every part of the world and in every nature of the organisation through every level.&lt;br /&gt;The application of SOX and stringent governance procedure still seems inadequate to prevent and deter the fraud. Research has shown that these laws are barely protecting the investors where evil intentions are prevailed at the top level of management. In the research of the major corporate failures, it was found despite all the governance procedure are functioning, fraud is happening at the different level of organisation.&lt;br /&gt;This has been raising a lot `of questions to the corporate world and doubt to the investors relying on the corporate governance.&lt;br /&gt;Since fraud seems inherent in the business, it is very important we give due importance to incorporate system compatible to the organisation to drive ethics and stringent control mechanism so that impact of the fraud to the organisation can be minimised.&lt;br /&gt;In some of the organisation misunderstanding were found to be prevailed with respect to the responsibility of the fraud. Top management feel that their responsibility towards fraud is discharged by the moment they appoint internal and external auditor. Research has shown that the the top management feel that the auditor are responsible for establishing fraud policy and investigation policy. Lack of understanding of this critical role by the top management has put the corporate world and governance more susceptible to fraud risk.&lt;br /&gt;In the today's context it is very important that the auditor educate top management about the responsibility of audit function with respect to fraud so that there is no ambiguity and hence more robust action to deter fraud can be initiated.&lt;br /&gt;As per the various pronouncement issued by the different professional bodies the primary role to prevent and deter fraud is of management. The auditors are responsible to ensure the audit review by applying professional skepticism in its audit process so that indicators of fraud can be identified.&lt;br /&gt;Further, it is the management who shall establish fraud policy in an organisation in order to prevent and detect fraud.The policy should clearly mentioned the procedure for whistle blowing to investigation process to uncover the fraudulent activities.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8132537442296217309-5192454054852432419?l=bestgovernance.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bestgovernance.blogspot.com/feeds/5192454054852432419/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://bestgovernance.blogspot.com/2009/04/fraud-investigation-responsibility.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8132537442296217309/posts/default/5192454054852432419'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8132537442296217309/posts/default/5192454054852432419'/><link rel='alternate' type='text/html' href='http://bestgovernance.blogspot.com/2009/04/fraud-investigation-responsibility.html' title='Fraud, Investigation &amp; Responsibility'/><author><name>Nischal R Siwakoti</name><uri>http://www.blogger.com/profile/03370311086374566522</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://2.bp.blogspot.com/_Ihf6skjb1AQ/SdL77hWbE7I/AAAAAAAAAA8/JwiRdCmwPxs/S220/PP+Photo.JPg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8132537442296217309.post-2762710390245661380</id><published>2009-04-01T13:27:00.000-07:00</published><updated>2009-04-29T19:13:47.598-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Sixth Generation Governance'/><title type='text'>Sixth Generation Governance</title><content type='html'>I really like people talking about governance and discussing the weakness and strength to develop an ideal governance system. Why people like to discuss governance? I think the main reason is people want to grow and develop. Every one who talks governance may not understand what governance is and how it is strengthened but one thing is sure that they know the out come of best governance is always development, better wealth and prosperity to the society.&lt;br /&gt;&lt;br /&gt;I always have one question in mind. Does the person occupying leadership role in an organization, state or globe understand what governance is? Probably yes or may be no.&lt;br /&gt;I guessed mixed answer considering the reality of the globe and the problems people are going through in these society. Some country are developed like USA and still facing the problem to serve its members to some extent hand to mouth and generate wealth/prosperity and some are very least developed like Somalia and their member too facing their own type of hand to mouth problem.&lt;br /&gt;&lt;br /&gt;If the governance can solve this problem why these country though at different education, wealth, and development stages are Facing almost same type of problem though at a different context? Does it mean that governance is not a solution? Or it means there is lack of governance in both the context. I believe most of the people will agree on the fact that there is no substitute of best governance to lead a society to wealth and prosperity.&lt;br /&gt;&lt;br /&gt;This means only the best governance can discipline the people and organize resources towards the betterment of the community. If so why do not we have best governance yet? If we see the human, it has come through thousands of years but why we failed to develop a best governance system that can lead the world towards prosperity?&lt;br /&gt;&lt;br /&gt;I thought about this matter and I found the main reason is the fast changing world. The world and its society changes so fast, every thing we built today becomes redundant the other day. We bought cloth for winter but nature changes gradually to summer making our external body protection system redundant. We readjust ourselves for the summer, it changes so fast that before we ready to govern one challenge the other challenge comes. This shows that we are subject to change and the governing system we build should also be such that it can automatically adjust the change. I believe this could be the major reason we are globally failing in the same way though we are at the different context.&lt;br /&gt;&lt;br /&gt;In order to build a strong and adoptive governing system the designer should really be brilliant and should have tracked all the past activities so that a reasonable prediction can be made to develop a system to protect fast changing environment. This will at least helps to protect the world from repeating the failure of governance at least from routine and expected changes.&lt;br /&gt;&lt;br /&gt;Time has really come we build up our next generation governance system which at least protect us from some expected and predictable threats. The next level will be the 6th generation governance system that not only protect from past behaviors but also from newly created challenges by doing analysis on threat through its highly active bio-digital intelligence and promptly reacting governing action protecting the society from evil eye and mall function. I believe this will become possible in today’s growing context as the globe is getting squeezed in to a palm. If we use the right technology with right attitude I do not think absolute governance can reach beyond our palm.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8132537442296217309-2762710390245661380?l=bestgovernance.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bestgovernance.blogspot.com/feeds/2762710390245661380/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://bestgovernance.blogspot.com/2009/04/sixth-generation-governance.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8132537442296217309/posts/default/2762710390245661380'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8132537442296217309/posts/default/2762710390245661380'/><link rel='alternate' type='text/html' href='http://bestgovernance.blogspot.com/2009/04/sixth-generation-governance.html' title='Sixth Generation Governance'/><author><name>Nischal R Siwakoti</name><uri>http://www.blogger.com/profile/03370311086374566522</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://2.bp.blogspot.com/_Ihf6skjb1AQ/SdL77hWbE7I/AAAAAAAAAA8/JwiRdCmwPxs/S220/PP+Photo.JPg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8132537442296217309.post-2975679924226387939</id><published>2009-03-31T21:00:00.000-07:00</published><updated>2009-04-29T19:14:20.125-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Government Auditing And Internal Audit'/><title type='text'>Government auditing &amp; use of Internal Audit Work</title><content type='html'>&lt;div align="center"&gt;&lt;span style="color:#ff0000;"&gt;Main Objective of Government Auditing&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;br /&gt;&lt;span style="color:#000099;"&gt;The primary role of the Government Auditor is to support the Parliament as parliamentary watch dog. &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;CAG&lt;/span&gt; support the parliament in meeting its constitutional responsibilities and helps to improve the performance and accountability of the central government for the benefit of the People &lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="color:#000099;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="color:#000099;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="color:#000099;"&gt;The &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;CAG&lt;/span&gt; support parliament by auditing government operations to determine whether public funds are spent efficiently and effectively &lt;/span&gt;&lt;/div&gt;&lt;span style="color:#000099;"&gt;&lt;div align="left"&gt;&lt;br /&gt;Reporting on How well the Government programs and policies are meeting their objectives.&lt;br /&gt;Analyzing government policy and outlining options to parliament through PAC for considerations &lt;/div&gt;&lt;div align="left"&gt;&lt;br /&gt;Advise parliament and head of executive agencies about ways to make government more efficient effective ethical, equitable and responsive.&lt;br /&gt;Our work leads to laws and acts that improve government operation, saving the government and taxpayers billions of rupees.&lt;br /&gt;&lt;/div&gt;&lt;/span&gt;&lt;div align="center"&gt;&lt;br /&gt;&lt;span style="color:#ff0000;"&gt;Objective of Internal Auditing&lt;/span&gt;&lt;/div&gt;&lt;span style="color:#ff0000;"&gt;&lt;/span&gt;&lt;div align="left"&gt;&lt;br /&gt;&lt;span style="color:#000099;"&gt;The institute of Internal Auditors has defined the Internal Auditing as an independent, objective, assurance and consulting activity designed to add value and improve an organization’s operations. It helps an organization accomplish its objectives by bringing a systematic, disciplined approach to evaluate and improve effectiveness of Risk Management, control, and governance process.”&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="center"&gt;&lt;br /&gt;&lt;span style="color:#ff0000;"&gt;Similarities of Role of Government auditing and Internal Auditing &lt;/span&gt;&lt;/div&gt;&lt;span style="color:#ff0000;"&gt;&lt;div align="center"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="color:#3333ff;"&gt;Both are independent function though there may be difference between level of independence each function is enjoying&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="color:#3333ff;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="color:#3333ff;"&gt;Both aim to improve an operations of government&lt;br /&gt;&lt;/div&gt;&lt;/span&gt;&lt;div align="left"&gt;&lt;span style="color:#3333ff;"&gt;Both aim to deliver a level of assurance to the work performed in the operations.&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="color:#3333ff;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="color:#3333ff;"&gt;Both assist the stake holders to make better decision and use taxpayer’s money more responsibly and effectively. &lt;/span&gt;&lt;/div&gt;&lt;span style="color:#3333ff;"&gt;&lt;/span&gt;&lt;div align="center"&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ff0000;"&gt;Why two different set of functions needed, though they are meeting all most all the same objective?&lt;br /&gt;&lt;/div&gt;&lt;/span&gt;&lt;div align="left"&gt;&lt;br /&gt;&lt;span style="color:#000099;"&gt;The question seems logical, but there is difference in the primary stakeholders it really serves to achieve the above objectives. The difference is not here for the universe of stake holders it serves, rather the primary (main) stakeholders it serves. &lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="color:#000099;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/span&gt;&lt;div align="left"&gt;&lt;span style="color:#000099;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="color:#000099;"&gt;The internal audit function reports primarily to the management of the government operations.&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="color:#000099;"&gt;However, the government auditor reports to the parliament.&lt;br /&gt;&lt;/div&gt;&lt;/span&gt;&lt;div align="left"&gt;&lt;span style="color:#000099;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="color:#000099;"&gt;So internal audit function can be taken as one of the control established by the government management to ensure they are meeting government objective as per the people’s mandate they obtained through the parliament. This gives them an opportunity to proactively improve their efficiency and effectiveness before it goes critical.&lt;br /&gt;&lt;/div&gt;&lt;/span&gt;&lt;div align="left"&gt;&lt;span style="color:#000099;"&gt;Internal Audit to discharge this responsibility reviews the adequacy of control put to ensure Risk Management, compliance, and proper governance. They conduct control assessment. This helps government management to self asses their performance and ensures the compliance of application of government fund as per the objective of mandate given to the government to apply those funds.&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="color:#000099;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="color:#000099;"&gt;Hence internal audit are more focused towards the adequacy of control and effectiveness of control but the government auditing consider this element as one of the critical factor to obtain assurance about the fair financial statement presentation, effective and efficient utilization of public funds.&lt;br /&gt;&lt;/div&gt;&lt;/span&gt;&lt;div align="left"&gt;&lt;span style="color:#000099;"&gt;External Audit work beyond the level then an internal audit does because their objective is to ensure that government funds are spent as per the mandate irrespective of the matter whether controls are there or not. &lt;/span&gt;&lt;/div&gt;&lt;span style="color:#000099;"&gt;&lt;div align="center"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="color:#ff0000;"&gt;What are the scopes a government audit has, to take advantage out of internal Auditing? &lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;br /&gt;&lt;span style="color:#000099;"&gt;The internal auditing does thorough risk assessment, control testing and they report the outcome to the management based on their review. This result can be of great use, if government auditor could gather enough evidence that they can rely on the Internal Audit work. It is very important to take due professional care to the internal audit work since their reliance to IA work does not release them from their professional responsibility to the parliament.&lt;br /&gt;&lt;/div&gt;&lt;/span&gt;&lt;div align="left"&gt;&lt;span style="color:#000099;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="color:#000099;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="color:#000099;"&gt;The recommendation of the IA to improve policy and procedure are of great help to the government auditors. Government auditor can apply their professional skepticism with respect to the appropriateness of those recommendations and give more pressure to management to implement those appropriate recommendations through the parliament. This helps to enhance the value IA added through the magic tools government auditors have in executing its jobs with the parliament.&lt;br /&gt;&lt;/div&gt;&lt;/span&gt;&lt;div align="left"&gt;&lt;span style="color:#000099;"&gt;External audit can also use the internal audit resources to execute external audit work which does not require high level of independence to execute and can be done under its own supervision.&lt;br /&gt;&lt;br /&gt;Internal audit tools could turn to be magic stick to the external auditors in order to execute follow-up and ensure effective implementation of their recommendation. This can be done by requiring IA to ensure its implementation and raise as follow up issues to the top level management on timely basis. This helps management to take action on those issues before it becomes critical. &lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="color:#000099;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="color:#000099;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="color:#000099;"&gt;The internal auditors continuously help management ensure effective control there by reducing the control risk this helps to reduce Audit Risk of the &lt;span id="SPELLING_ERROR_2" class="blsp-spelling-corrected"&gt;Government&lt;/span&gt; Auditor. &lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8132537442296217309-2975679924226387939?l=bestgovernance.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bestgovernance.blogspot.com/feeds/2975679924226387939/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://bestgovernance.blogspot.com/2009/03/awx.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8132537442296217309/posts/default/2975679924226387939'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8132537442296217309/posts/default/2975679924226387939'/><link rel='alternate' type='text/html' href='http://bestgovernance.blogspot.com/2009/03/awx.html' title='Government auditing &amp; use of Internal Audit Work'/><author><name>Nischal R Siwakoti</name><uri>http://www.blogger.com/profile/03370311086374566522</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://2.bp.blogspot.com/_Ihf6skjb1AQ/SdL77hWbE7I/AAAAAAAAAA8/JwiRdCmwPxs/S220/PP+Photo.JPg'/></author><thr:total>0</thr:total></entry></feed>
