ACC 491 Week 3, 4

profilere.bertyh.elpsfuben.t
ACC491Week4InternalControl.doc

Running head: Ethics on the Job 1

Internal Controls, COSO, and SOX Paper 3

Internal Controls, COSO, and SOX Paper

Internal Controls, COSO, and SOX paper

In this week’s learning concept, we discussed internal controls and the responsibility of management to uphold these procedures to ensure that companies are doing their utmost to alleviate misstatements and errors. In section 404(a) of the Sarbanes-Oxley Act, it requires that the management of all public companies provide a report on their internal control. In the report, they must include a statement verifying management’s responsibility to create and maintain proper policy and procedures for internal controls with financial reporting. They must also include an assessment stating the effectiveness of their internal control structure as of year-end. In addition, management must also identify what framework was used in the process of the evaluation of the company’s internal control.

The History of the Committee of Sponsoring Organizations

The COSO’s Internal Control -Integrated Framework was developed in 1992. It is one of the most commonly used internal control frameworks in the world and the COSO board has continued to keep the framework up to date with the ever-changing business environment in order for the framework to stay relevant. Since it was first created, there have been seven key changes to the framework. The framework now includes a principle approach where the seventeen broad principles are applied to all entities. It also now reflects the increased relevance of technology. Expands governance concepts to include discussions on audit, compensation and the nomination committees. The financial reporting on objectives now considers external reporting. The framework also now includes additional information on the relationship between fraud and internal control. Lastly, updates on the framework now consider the different types of business models and structures. Yet although there have been numerous changes to the framework, there have also been parts of the framework that remains unchanged. For instance, the definition of internal control, the categories of objectives, the reliability of the reporting, compliance in the laws and its regulations, and the five components of internal control.

The five components and 17 principles of the COSO Framework

In the COSO Framework, there are five components: Control environment, Risk assessment, Control activities, Information and communication, and Monitoring. The control environment component represents the top management’s views on the company’s internal control and the importance of the controls to management. Risk assessment is the process for management to analyze possible risks in the preparation of the financial statements. Control activities are the implementation of policies and procedures by management to meet financial reporting objectives. Information and communication are methods that serve to initiate, record, process, and report transactions with a level of accountability. Monitoring is the ongoing process of assessing internal controls for efficiency and to modify internal control when necessary.

There are five principles pertaining to the control environment component. The organization should demonstrate a level of integrity and ethical values. The board of directors must showcase a form of independence from management and oversee changes needed in the assessment of the performance with internal control. Both management and the board should create an organizational structure that defines the responsibility and authority and stress the importance of internal control to the employees. Commit to the practice of obtaining competent and trustworthy individuals that are aligned with the company’s objective. The organization should also hold each individual accountable for their responsibilities.

There are four principles under risk assessment. The organization should clarify the objectives in order to identify and assess the risks that relate to the objectives. Identify risk to achievements of objectives and analyze how to handle the risks properly. Firms must also consider potential fraud when assessing risk. Added to that, the organization must also assess any changes that could affect the internal control process.

There are three principles following control activities. The organization implements control activities that contribute to minimizing risks to achieve objectives to its acceptable level. The company also selects general control activities for technology to help achieve objectives. Policies are established as a part of control activities to determine what is expected and put in place procedures to put the policies in action.

There are three principles for information and communication. The organization should obtain relevant information to help support functions within the internal control. They should also communicate the necessary information to support the functions. And communicate with outside parties with matters that affect the company’s internal control.

The monitoring of activities has two principles. The firm should select, develop and perform a continuous evaluation to conclude whether the current internal controls are functioning properly. In addition, they must communicate all the deficiencies they find with their internal control to seek corrective action.

Importance of Management's Annual Report and Report of Independent Registered Public Accounting Firm

Management’s Annual Report on internal control over the financial reporting is important these reports allows an auditor to have an insight on the management responsibilities towards putting policies and procedures in place to showcase their integrity towards their financial reporting and to ensure that they are doing their due diligence in generating faithful reporting’s for their users. The report of independent registered public accounting firm is an important report because it is the auditor’s report regarding their conclusion of the audit. It also serves as a document to state that the auditor has performed the audit in accordance with the appropriate auditing standards.

References

Arens, A.A., Elder, R.J., & Beasley, M.S. (2014). Auditing & assurance services: An integrated approach (15th ed.). Retrieved from The University of Phoenix eBook Collection database.

Coso Internal Control - Integrated Framework Principles (2013). Retrieved from https://www.coso.org/Documents/COSO-ICIF-11x17-Cube-Graphic.pdf