Control Environment
Name
ACCT 2002 - Managerial Accounting: Introduction to Financial Planning and Analysis
Walden University
2022
Control Environment
The control environment, as established by the organization's administration, sets the tone of an
institution and influences the control consciousness of its people. Leaders of each department,
area or activity establish a local control environment. This is the foundation for all other
components of internal control, providing discipline and structure. Control environment factors
include:
Integrity and ethical values;
The commitment to competence;
Leadership philosophy and operating style;
The way management assigns authority and responsibility, and organizes and develops its
people;
Policies and procedures.
(Strauss, 2003)
2.8.2 Risk Assessment
Every entity faces a variety of risks from external and internal sources that must be assessed. A
precondition to risk assessment is establishment of objectives, linked at different levels and
internally consistent. Risk assessment is the identification and analysis of relevant risks to
achievement of the objectives, forming a basis for determining how the risks should be managed.
Because economics, regulatory and operating conditions will continue to change, mechanisms
are needed to identify and deal with the special risks associated with change.
Objectives must be established before administrators can identify and take necessary steps to
manage risks. Operations objectives relate to effectiveness and efficiency of the operations,
including performance and financial goals and safeguarding resources against loss. Financial
reporting objectives pertain to the preparation of reliable published financial statements,
including prevention of fraudulent financial reporting. Compliance objectives pertain to laws and
regulations which establish minimum standards of behavior.
The process of identifying and analyzing risk is an ongoing process and is a critical component
of an effective internal control system. Attention must be focused on risks at all levels and
necessary actions must be taken to manage. Risks can pertain to internal and external factors.
After risks have been identified they must be evaluated.
Managing change requires a constant assessment of risk and the impact on internal controls.
Economic, industry and regulatory environments change and entities' activities evolve.
Mechanisms are needed to identify and react to changing conditions.
2.8.3 Control Activities
Control activities are the policies and procedures that help ensure management directives are
carried out. They help ensure that necessary actions are taken to address risks to achievement of
the entity's objectives. Control activities occur throughout the organization, at all levels, and in
all functions. They include a range of activities as diverse as approvals, authorizations,
verifications, reconciliations, reviews of operating performance, security of assets and
segregation of duties.
Control activities usually involve two elements: a policy establishing what should be done and
procedures to effect the policy. All policies must be implemented thoughtfully, conscientiously
and consistently.
2.8.4 Information and Communication
Pertinent information must be identified, captured and communicated in a form and time frame
that enables people to carry out their responsibilities. Effective communication must occur in a
broad sense, flowing down, across and up the organization. All personnel must receive a clear
message from top management that control responsibilities must be taken seriously. They must
understand their own role in the internal control system, as well as how individual activities
relate to the work of others. They must have a means of communicating significant information
upstream.
2.8.5 Monitoring
Internal control systems need to be monitored - a process that assesses the quality of the system's
performance over time. Ongoing monitoring occurs in the ordinary course of operations, and
includes regular management and supervisory activities, and other actions personnel take in
performing their duties that assess the quality of internal control system performance.
The scope and frequency of separate evaluations depend primarily on an assessment of risks and
the effectiveness of ongoing monitoring procedures. Internal control deficiencies should be
reported upstream, with serious matters reported immediately to top administration and
governing boards.
Internal control systems change over time. The way controls are applied may evolve. Once
effective procedures can become less effective due to the arrival of new personnel, varying
effectiveness of training and supervision, time and resources constraints, or additional pressures.
Furthermore, circumstances for which the internal control system was originally designed also
may change. Because of changing conditions, management needs to determine whether the
internal control system continues to be relevant and able to address new risks.
Components of the Control Activity
Internal controls rely on the principle of checks and balances in the workplace. The following
components focus on the control activity:
Personnel need to be competent and trustworthy, with clearly established lines of authority and
responsibility documented in written job descriptions and procedures manuals. Organizational
charts provide a visual presentation of lines of authority and periodic updates of job descriptions
ensures that employees are aware of the duties they are expected to perform.
Authorization Procedures need to include a thorough review of supporting information to verify
the propriety and validity of transactions. Approval authority is to be commensurate with the
nature and significance of the transactions and in compliance with University policy.
Segregation of duties reduces the likelihood of errors and irregularities. An individual is not to
have responsibility for more than one of the three transaction components: authorization,
custody, and record keeping. When the work of one employee is checked by another, and when
the responsibility for custody for assets is separate from the responsibility for maintaining the
records relating to those assets, there is appropriate segregation of duties. This helps detect errors
in a timely manner and deter improper activities; and at the same time, it should be devised to
prompt operational efficiency and allow for effective communications.
Physical Restrictions are the most important type of protective measures for safeguarding
University assets, processes and data.
Documentation and Record Retention is to provide reasonable assurance that all information and
transactions of value are accurately recorded and retained. Records are to be maintained and
controlled in accordance with the established retention period and properly disposed of in
accordance with established procedures (Strauss 2003).
REFERENCES
Arens, A., Best, P., Schailer, G., Fiedler, B.,Elder, R., & Beasley M.,(2007) Auditing and
Assurance Services in Australia, an Integrated Approach, 7th Edn., Pearson Education
Australia, Sydney
Altamuro, J., Beatty, A., 2007. Do internal control reforms improve earnings quality? Working
Paper, The Ohio State University.
Ashbaugh-Skaife, H., Collins, D., Kinney, W., 2007. The discovery and reporting of internal
control deficiencies prior to SOX-mandated audits. Journal of Accounting and
Economics 44, 166-192.
Ashbaugh-Skaife, H., Collins, D., Kinney, W., LaFond, R., 2008. The effect of SOX internal
control deficiencies and their remediation on accrual quality. The Accounting Review 83,
217-250.
Ball, R., 2004. Corporate governance and financial reporting at Daimler-Benz (DaimlerChrysler)
AG: From a “Stakeholder” toward a “Shareholder Value” Model. In: Leuz, C., Pfaff, D.,
Hopwood, A., (Eds.). The Economics and Politics of Accounting. London: Oxford
University Press, 103-145.
Campbell, Mary Campbell, and Gary W. Adams (2009) Adding Significant Value with Internal
Controls, New York State Society of CPAs
Wright R (2009) Internal Audit, Internal Control and Organizational Culture, Unpublished PhD
thesis.