Wednesday, 24 March 2021

Auditing Internal Controls

 

In response to the large corporate financial scandals like energy firm Enron Corp, telecommunications giant WorldCom and Tyco International, Sarbanes-Oxley Act (SOX) was introduced, in the USA, in year 2002.

Purpose of the Act was to improve accuracy of financial reporting by establishing formalized system of checks and balances and protect shareholders/ general public from fraudulent practices in the companies.

The SOX is mandatory and applies to all US-based public companies. These companies are required to maintain both good financial practices and data security standards. The Section 404 of the Act mandates rules on “management’s report on internal control over financial reporting”. The section requires all financial reports to include an Internal Control Report. The report provides assurance that the company’s financial data is accurate and adequate controls are in place to safeguard financial data.

To align with the requirements of the SOX, the PCAOB (U.S. Public Company Accounting Oversight Board) provided an updated standard AS 5, in May 2007.The Standard was about “Audit of Internal Controls over Financial Reporting integrated with Audit of Financial Statements”.

The SOX measures seek to govern financial operations and disclosures of the corporate entities. A major part of the SOX regulations is related to the information technology systems. SOX reporting involves IT departments as those departments are responsible for creating corporate records and maintaining archives.

To align with SOX regulations, companies are required to develop and implement comprehensive data security strategy. The strategy should be able to protect financial data prepared, used and stored during normal operations. IT departments must become familiar with the security, access, privilege and log management standards applicable to them.

The security teams use data classification to enforce and monitor corporate policies for data handling. Depending upon sensitivity and applicable regulations data may be encrypted, compressed or saved in a different file format. With the proper policies in place corporations can prevent unauthorized users from viewing regulated data. The security solutions have the ability to safeguard shared data.

Section 302 and 404 of the SOX prevent fraudulent agents (whether internal or external) from tampering with sensitive financial information.

Section 302: Corporate Responsibility for Financial Reports
Section 302 states that the CEO and CFO are directly responsible for documentation, accuracy and submission of all financial reports as well as the internal control structure,

to the SEC (Security Exchange Commission of U.S.A.).

The Commission requires, for each company filing periodic reports under section 13(a) or 15(d) of the Securities Exchange Act of 1934, that the principal executive officer or officers and the principal financial officer or officers, or persons performing similar functions, certify in each annual or quarterly report filed under either such section of such Act that — 

1. the signing officer has reviewed the report;

2. based on the officer’s knowledge, the report does not contain any untrue statement of a material fact or omit to state a material fact necessary in order to make the statements made, in light of the circumstances under which such statements were made, not misleading;

3. based on such officer’s knowledge, the financial statements, and other financial information included in the report, fairly present in all material respects the financial condition and results of operations of the issuer as of, and for, the periods presented in the report;

4. the signing officers–

a. are responsible for establishing and maintaining internal controls;

b. have designed such internal controls to ensure that material information relating to the issuer and its consolidated subsidiaries is made known to such officers by others within those entities, particularly during the period in which the periodic reports are being prepared;

c. have evaluated the effectiveness of the issuer’s internal controls as of a date within 90 days prior to the report; and

d. have presented in the report their conclusions about the effectiveness of their internal controls based on their evaluation as of that date;

5. the signing officers have disclosed to the issuer’s auditors and the audit committee of the board of directors or persons fulfilling the equivalent function–

a. all significant deficiencies in the design or operation of internal controls which could adversely affect the issuer’s ability to record, process, summarize, and report financial data and have identified for the issuer’s auditors any material weaknesses in internal controls; and

b. any fraud, whether or not material, that involves management or other employees who have a significant role in the issuer’s internal controls; and

6. the signing officers have indicated in the report whether or not there were significant changes in internal controls or in other factors that could significantly affect internal controls subsequent to the date of their evaluation, including any corrective actions with regard to significant deficiencies and material weaknesses.

Section 404: Internal Control Report
The section 404 requires all annual financial reports to include an Internal Control Report. The report states that management is responsible for an adequate internal control structure and includes an assessment by the management of the effectiveness of the control structure. Any shortcomings in these controls must be reported. In addition, registered external auditors must attest to the accuracy of the management assertion that internal accounting controls are in place, operational and effective.

(a) Rule: The rules prescribed by the Commission, require each annual report submitted under section 13(a) or 15(d) of the Securities Exchange Act of 1934, to contain an internal control report, which shall — 

i. state responsibility of the management for establishing and maintaining an adequate internal control structure and procedures for financial reporting; and

ii. contain an assessment, as of the end of the most recent fiscal year of the issuer, of the effectiveness of the internal control structure and procedures of the issuer for financial reporting.

(b) Internal Control Evaluation and Reporting: With respect to the internal control assessment required under subsection (a), each registered public accounting firm that prepares or issues the audit report for the issuer shall attest to, and report on, the assessment made by the management of the issuer.

An attestation under this subsection shall be made in accordance with the standards for attestation engagements issued or adopted by the Board.

SOX Documentation
While adopting rules to implement Section 404, the SEC expressly declined to prescribe scope of assessment or extent of testing and documentation required by the management. The scope and process of the assessment should be reasonable and assessment including testing should be supported by a reasonable level of evidences. Each company should use informed judgment in documenting and testing its controls to fit its operations, risks and procedures. Management should use their own experience and informed judgment in designing an assessment process that fits needs of that company. Management should not allow the goal and purpose of the internal control over financial reporting provisions which is “production of reliable financial statements”, to be overshadowed by the process.

The key business processes, material transactions and related controls are to be documented. Management should maintain sufficient documentation so that a person with reasonable knowledge can understand the process, how key controls are operating, who is performing controls, time and frequency of operating controls, evidence that the controls were performed and the reports used while applying those controls.

It’s important to establish a change management process which will ensure that the documentation is kept up-to-date as processes and controls change in a business.

The external auditor should agree on the documentation of controls.

SOX Audits
The SOX mandates companies to complete yearly audits and make the results available to stakeholders. Companies hire independent auditors to conduct SOX audit, which must be separate from any other audit, to prevent a conflict of interest.

For audit under section 404, a company must meet the following requirements:

  • Management accepts responsibility for effectiveness of the controls
  • Controls are suitably designed and implemented to achieve control objective i.e. reliability of financial reporting, using established criteria
  • Control objectives and related controls are documented
  • Management assesses effectiveness of internal control over financial reporting and reports on design & operating effectiveness of the control.

Auditors compare past financial statements with the current year and may interview personnel to verify if compliance controls are effective. The auditors check with the staff whether their duties match their job descriptions and that they have adequate training to access financial information in a secured manner.

SOX audit process involves the following steps:

1. Define Scope of audit using a Risk Assessment Approach
For performing risk assessment, a top-down approach is recommended. The auditor focuses on entity-level controls and works down to significant accounts, their disclosures and relevant assertions.

The purpose is to help auditor identify potential risks and sources, their impact on the business and whether internal controls will provide reasonable assurance that a material fraud/error will be prevented or detected.

2. Determine Risks related to Material Accounts & Processes
The auditor will:

  • Identify material items in the financial statements.
  • Determine locations having material account balances.
  • Review financial statements of those locations.
  • Verify details of the transactions in material account balances. Check how transactions occurred and how they were recorded. Auditor may also meet with the concerned persons such as process owners, financial controller etc.
  • Identify financial reporting risks for material accounts and the possible impact they may have on the account balances.

3. Identify SOX Controls
During materiality analysis auditor should identify & document SOX controls which can detect or prevent transactions from incorrect recording. Those are the key controls. The auditor should differentiate key controls from non-key controls and also identify manual and automated controls.

4. Test Key Controls
Testing key controls validates design and operating effectiveness of the controls in place. Controls testing involve inspection of documentation, evaluation, observation, inquiries with process owners, walkthrough the transaction and re-performance of the process etc.

5. Perform Fraud Risk Assessment
An effective system of internal controls is in place where internal controls reduce the opportunity to commit a fraud and also help with the assessment of possible frauds. Examples of effective internal controls are segregation of duties, reconciliation of bank accounts at regular intervals, investigation of employees’ expenses reimbursements etc.

6. Manage Documentation of Processes and Controls
Key operating processes and controls should be properly documented.

7. Assessing Deficiencies
During testing auditor may come across deficiency or gap in the sample selected. The deficiency/gap should be identified & corrected. The auditor should also review whether the deficiency/gap was due to design failure or operational failure of the control.

8. Deliver Management’s Report on Controls
A large amount of data and information is collected during testing of SOX controls.

The information gathered is useful for the management’s report on internal controls.

Auditing IT Systems
During SOX audit, review of internal controls related to IT assets such as computers, network, hardware and other electronic equipment that the financial data passes through, form a major part of the audit.

While auditing IT systems auditors review following internal controls:

i. Access: Access includes both physical controls such as doors, badges, locks on file cabinets and electronic controls like login policies, least privilege access and permission audits. Least privilege access model is an excellent example of access control which means each user only has the access necessary to do his/her job. The function of the user and not his/her identity, controls assignment of access rights.

Another good control is Permission audit. Permission audits are about review of permissions e.g. who has permissions to what, basis of getting that permission and whether the person is acting in a responsible manner. Auditors examine if current permissions are recorded & any changes to the permissions are verified and recorded.

ii. Security: Security controls ensure that the company has protection against data breaches.

iii. Data Backup: Maintaining off-site backups of all financial records is a SOX compliance requirement.

iv. Change Management: is having defined processes to add and maintain users, install new software and make any changes to database or applications which manage company’s financial information.

SOX compliance checklist
SOX compliance checklist is a tool for evaluation of compliance with SOX, reinforcing information technology & security controls and to uphold legal financial practices. A SOX compliance checklist includes the following steps:

1. To prevent data tamperinga system is in place which tracks user logins and detects suspicious login attempts into the systems used for financial data.

2. To record timelines for key activities company has systems which can apply timestamps to all financial & other related data. The data is encrypted if required and stored at a remote, secure location.

3. Establish verifiable controls to track data access i.e. a system that can receive data messages from virtually unlimited number of sources including files, FTP transfers and databases and tracks who accessed or modified the data.

4. To ensure that safeguards are operational systems are implemented which can issue & distribute daily reports to selected officials in the organization, confirming that the SOX control measures are working properly.

5. Report periodically on effectiveness of safeguards implement system which generates reports periodically, on data, including report of all messages, critical messages, alerts and uses a ticketing system that archives security incidents occurred and how they were addressed.

6. To detect Security Breaches security system is in use which can analyze data in real-time, identify signs of a security breach and generate meaningful alerts, automatically updating incident management system.

7. To disclose security breaches company has a system which is capable of detecting and logging security breaches and allow security staff to record their resolution of each incident.

8. To disclose security safeguards to the auditor systems should be in place which can provide role-based access to the auditor, allowing him/her to view data and reports without making any changes.

9. A system to disclose failure of security controls to the SOX auditor. The system should enable auditor to view reports having details of the security control failure incidents, the incidents resolved successfully and the ones which could not be resolved.

Protecting the whistleblower
SOX encourages disclosure of corporate frauds by protecting employees who report fraud and testify in court against their employers. Companies are not allowed to change the terms and conditions of their employment. They can’t reprimand, fire, or blacklist the employee. Whistleblowers can report any corporate retaliation against them. SOX makes it a crime for a person to knowingly retaliate against a whistleblower for disclosing truthful information to a law enforcement officer. It authorizes the Department of Justice to criminally charge those responsible for the retaliation.

Firms conducting SOX Audits
The SOX also regulates accounting firms which conduct SOX audits. The PCAOB has set standards for the audit reports. It requires all auditors of public companies to register with them. The PCAOB inspects, investigates, and enforces compliance of these firms. It prohibits accounting firms from doing business consulting with the companies they are auditing. They can still act as tax consultants but the lead audit partners must rotate off the account after five years.

Auditing Internal Controls

Thursday, 7 January 2021

Need of Internal Audit

 

The purpose of auditing internally is to supply insight into an organization’s culture, policies, procedures, and aids board and management oversight by verifying internal controls like operating effectiveness, risk mitigation controls, and compliances with relevant laws or regulations.

Reasons why there’s an importance of Auditing Internally
Internal auditing programs are critical for monitoring and assuring that each one of the business assets are properly secured and safeguarded from threats. it’s also important for verifying that business processes reflect documented policies and procedures.

Let’s take a glance at five reasons why internal auditing is critical and their purpose keep your organization compliant with the common frameworks and regulations.

1. Provides Objective Insight
You can’t audit your own work without having a selected conflict of interest.
Your auditor, or internal audit team, cannot have any operational responsibility to know this objective insight. In situations where smaller companies don’t have extra resources to devote to this , it’s acceptable to cross-train employees in several departments to be able to audit another department. By providing an independent and unbiased view, the inside audit function adds value to your organization.

2. Improves Efficiency of Operations
By objectively reviewing your organization’s policies and procedures, you’ll receive assurance that you simply simply do what your policies and procedures say you’re doing, which these processes are adequate in mitigating your unique risks.

By continuously monitoring and reviewing your processes, you’ll identify control recommendations to reinforce the efficiency and effectiveness of these processes. In turn, allowing your organization to be enthusiastic to processes, rather than people.

3. Evaluates Risks and Protects Assets
An internal audit program assists management and stakeholders by identifying and prioritizing risks through a scientific risk assessment. A risk assessment can help to identify any gaps within the environment and permit for a remediation plan to happen.

Your internal audit program will assist you to trace and document any changes that are made to your environment and confirm the mitigation of any found risks.

4. Assesses Controls
Internal auditing is beneficial because it improves the control environment of the organization by assessing efficiency and operating effectiveness. Are your controls fulfilling their purpose? Are they adequate in mitigating risk?

5. Internal Audits Ensure Compliance with Laws and Regulations
By regularly performing an indoor audit, you’ll ensure compliance with any and every one relevant laws and regulations. It also helps provide you with peace of mind that you simply are prepared for you next external audit. Gaining client trust and avoiding costly fines related to non-compliance makes internal auditing a crucial and worthwhile activity for your organization.

Need of Internal Audit

Monday, 28 December 2020

Inventory Audit in India


Inventory audit in India

Inventory audit or stock audit refers to physical verification of a corporation or institution’s inventory assets. There are several sorts of stock audits depending upon the aim and each stock audit would require a special approach. Every business institution a minimum of must perform a stock audit once during a year to update and assure that the physical stock and therefore the computed stock is correctly matched. A stock audit helps to correct discrepancies between the physical stock and therefore the book stock. The stock audit helps to trace the quantity of physical assets remaining and make necessary arrangements to order new stock. If the corporate is handling different suppliers and vendors, a stock audit will make the inventory management process easier.

Why Stock Audit?

  • Records accurate level of inventory and help to avoid shortage or overstocking of materials.
  • It helps to detect inventory losses caused thanks to wastage, damage or theft.
  • It disclose obsolete raw materials and incorrect orders supplied to customers.
  • Analyze the particular quantity of stock against that noted on the accounting records.
  • Avoid unnecessary investment on raw materials and may help to save lots of money.
  • Enable the business owners to know truth financial status of the company.
  • Helps to seek out out discrepancies within the packaging and warehouse procedures.

It is very essential to conduct inventory audits to take care of inventory accuracy, spot causes of shrinkage, and make sure that one always have the proper quantity of stock at the proper time. an honest understanding of stock flow also will help make sure the business runs smoothly.

Inventory audit checklist
 The inventory audits have three phases: planning, execution, and analysis. Inventory is one among the important areas for any business where chances of fraud are more as it’s a department where thefts and damages occur. Having effective controls, appropriate processes, proper checklist and regular stock audit is important for this function. Following is that the checklist for Inventory audit:

  • Evaluate which items to audit: Higher-risk inventory items should be assessed more frequently. it’s also referred to as ABC Analysis. High-value items are given the grouping of products A, mid-tier are B, and low values are C. ABC analysis also can help to manage a stockroom better and save time. you’ll sort inventory out by SKU (Stock keeping units) or Universal Product Code , then prioritize. Check Stock valuation process, components of cost of inventory, method of valuation.
  • Create an audit schedule: map an auditing schedule. Unfortunately, conducting a listing audit can disturb the regular business flow. we would like to settle on times that are least effective for the business, but also happen at an honest frequency to make sure those high-value items are going to be accounted for. The policies and procedures of shopping for and shipping items also can affect the schedule of your audit.
  • Physical verification of Inventory: It is that the process of counting each item of inventory. Firstly, we schedule this before time because it’ll likely be an inconvenience to normal business flow. Also, think about using technology, sort of a Universal Product Code scanner, to assist physically count each item and reconcile the counted inventory with ledger .
  • Collect the required documentation: Get out any important documents before time and confirm they’re easily accessible, but secure. Categorized inventory in High, Medium and Low value stock.
  • Conduct the inventory audit: There are different numbers of audit which will be essential, counting on the character of your business. Check Inventory lying with third parties, i.e. for paperwork , in third party warehouse.
  • Record the findings: Stock related MIS format and contents. the most purpose of an audit is to get gaps in compliance and appearance at opportunities to repair the deficit and improve operational processes.
  • Reconciling items investigation:If there are inconsistency between inventory counts as per company’s records and therefore the actual amounts on the warehouse shelves then find out why there are differences between these two amounts and make adjustments to the records to reflect this analysis. Inventory reconciliation is extremely important a part of cycle counting.

Inventory stop Process
 Cut off process is an important process in Inventory valuation. When inventory is physically counted and inwards (receipts) and outwards (issues) movement of inventory isn’t stopped, it’s going to cause many difficulties within the counts. this is often why near of the date of inventory counting day, stop the movement of stock. If during this era stock is moved for any reason, it’s likely to affect the inventory count. Auditor requires studying the stop process of management and ensuring it’s adequate.


Source: Inventory Audit in India

Tuesday, 15 December 2020

Internal controls and Audit of Fixed Assets

 

Fixed assets, in an organization represent the long-term tangible assets which are used,

-to produce and deliver its products or services, and

-to manage its operations.

They are assets held for the purpose of providing or producing goods or services and are not meant for sale in the normal course of business. Therefore, an asset can be classified as a fixed asset or otherwise, depending upon the use to which it is put or intended to be put.

In many capital-intensive industries such as manufacturing, power generation and healthcare, fixed assets represent the largest item on the balance sheet. Historically, fixed assets have received little audit scrutiny and, as a result, some major financial frauds have been perpetrated through significant misstatements of fixed asset balances in the financial statements of public companies.

When asked if fixed assets are represented accurately in year-end financial statements, most organizations will answer with “yes.” However, audits may yield a different answer. Although many organizations do not perform an inventory of current fixed assets and a corresponding reconciliation, these steps provide an essential internal control for the financial reporting of fixed assets.

Moreover, fixed assets need attention to ensure the organization’s records are accurate and its controls provide effective oversight of this area. As with other asset classes, best practices enhance proper accounting, valuations and financial reporting.

Internal Controls over Fixed Assets
Fixed-asset transactions typically represent the acquisition and disposal of assets and the allocation of related costs to reporting periods through depreciation expense. The internal controls over the acquisition of fixed assets include the following:

  • Issuance and approval of a purchase order
  • Receipt of assets and preparation of a receiving report
  • Receipt of an invoice from a vendor
  • Reconciliation of the vendor invoice to the related receiving report and purchase order
  • Authorization of the payment of the vendor invoice
  • Issuance of a check for payment of the vendor invoice
  • Posting of the entry in the equipment sub-ledger
  • Posting of the equipment sub-ledger activity to the related general ledger control accounts
  • Reconciliation of the general ledger control accounts

Audit of Fixed Assets
External Auditors of most manufacturing organizations usually scope in Property, Plant & Equipment (PPE) as a risk area during their annual audit due to its materiality. A combination of controls testing and substantive testing is usually adopted when obtaining audit assurance on PPE.

An auditor should review the system of internal controls relating to fixed assets, particularly the following:


Verification under audit
Verification of fixed assets consists of examination of related records and physical verification. The auditor should normally verify the records with reference to the documentary evidence and by evaluation of internal controls. Physical verification of fixed assets is primarily the responsibility of the management.

Verification of Records

  • The opening balances of the existing fixed assets should be verified from records such as the schedule of fixed assets, ledger or register balances.
  • Acquisition of new fixed assets and improvements in the existing ones should be verified with reference to supporting documents such as orders, invoices, receiving reports and title deeds.
  • Self-constructed fixed assets, improvements and capital work-in-progress should be verified with reference to the supporting documents such as contractors’ bills, work-order records and independent confirmation of the work performed.
  • The auditor should scrutinize expense accounts (e.g. Repairs and Renewals) to ascertain that new capital assets and improvements have not been included therein.
  • Where fixed assets have been written-off or fully depreciated in the year of acquisition/ construction, the auditor should examine whether these were recorded in the fixed assets register before being written-off or depreciated.
  • In respect of fixed assets retired, i.e., destroyed, scrapped or sold, the auditor should examine

(a) whether the retirements have been properly authorized and appropriate procedures for invitation of quotations have been followed wherever applicable;

(b) whether the assets and depreciation accounts have been properly adjusted;

© whether the sale proceeds, if any, have been fully accounted for; and

(d) whether the resulting gains or losses, if material, have been properly adjusted and disclosed in the Profit and Loss Account.

It is possible that certain assets which were destroyed, scrapped or sold during the year have not been recorded. The auditor may use the following procedures to ascertain such omissions:

  • Review work orders/physical verification reports to trace any indicated retirements.
  • Examine major additions to ascertain whether they represent additional facilities or replacement of old assets, which may have been retired.
  • Make enquiries of key management and supervisory personnel.
  • Obtain a certificate from a senior official and/or departmental managers that all assets scrapped, destroyed or sold have been recorded in the books.
  • The ownership of assets, like land and buildings should be verified by examining title deeds. In case, the title deeds are held by other persons, such as solicitors or bankers, confirmation should be obtained directly by the auditors through a request signed by the client.

Concluding Remarks
In order to help the auditors undertake quality audits and adhere to the audit compliance standards, ICAI has released guidelines advising auditors with regards to conditions that may arise due to COVID-19 pandemic, how they can carefully examine specific circumstances while undertaking audit and assess the risk accordingly. For auditors, it is majorly “remote” auditing, going through virtual data, but continuing to comply with the requirements of standards on auditing.

The COVID-19 outbreak may affect the useful life and residual life of fixed assets which requires management review. In case the expectations differ from previous estimates, then change in estimate should be accounted for in accordance with Ind AS 8, Accounting Policies, Changes in Accounting Estimates and Errors.

It is imperative to ensure that appropriate level of disclosures are done in the financial statements (which in most cases is a judgment call, depending on the facts and circumstances of each case) for the users of the financial statements to understand the impact of pandemic on the company as assessed by the management, Board of Directors and Audit committees.


Source: Internal controls and Audit of Fixed Assets

Friday, 4 December 2020

“Risks” As in Internal Audit

 


Risk-based internal audit is an internal methodology which is primarily focused on the inherent risks involved in the activities or system and provide assurance that risk is being managed by the management within the defined risk appetite level.

Risk is defined as ‘the possibility of an event occurring that will have an impact on the achievement of objectives”. In general, risk management is concerned with positive and negative aspects of risk. The risk can have an adverse impact (downside risk) or it can also have potential benefit (upside risk). It can be applied holistically, and also used on specific activities, from the strategic to the operational.

Types of Risks:
♦ Inherent risk
♦ Control risk
♦ Detection risk

Inherent risk: The risk that could not be protected or detected by the entity’s internal controls. This risk could happen as a result of the complexity of the client’s nature of business or transactions.

Control risk: This is the risk that potential material misstatements would not be detected or prevented by a client’s controls system.

Detection risk: This is the risk that the audit procedures used are not capable of detecting a material misstatement.

Risk Management Framework

Risk management framework (RMF) is structured process to define the strategy for eliminating or minimising the impact of risks, as well as the mechanisms to effectively monitor and evaluate the strategy, for an organisation.

Steps in a Risk Management Framework (RMF)

Step 1 Identification (Identify potential threats (Risks))
Step 2 Measurement (Analyze Risks)
Step 3 Mitigation (Define the strategy for eliminating/ minimising impact of risks)
Step 4 Reporting & Monitoring (Decide & apply mechanisms to effectively monitor
Step 5 Governance

Risk Management Frameworks

A number of Frameworks are in use: brief description of some of the commonly used frameworks, is given below.

A. COSO: The COSO framework is one of two widely accepted risk management standards organizations use to manage risks. COSO stands for The Committee of Sponsoring Organizations of the Treadway Commission (COSO). The initial mission of COSO was to study financial reporting and develop recommendations to prevent frauds. This framework is commonly used in the United States and around the world.

The original COSO framework was published in 1992 and later updated in 2013.

5 components of COSO are:

– control environment
– risk assessment
– information and communication
– monitoring activities, and
– existing control activities

17 principles of COSO framework’s effective internal control are:

Internal Control ComponentPrinciplesControl environment1. Demonstrate commitment to integrity and ethical values2. Ensure that board exercises oversight responsibility

3. Establish structures, reporting lines, authorities and responsibilities

4. Demonstrate commitment to a competent workforce

5. Hold people accountable

Risk assessment6.Specify appropriate objectives7. Identify and analyze risks

8. Evaluate fraud risks

9. Identify and analyze changes that could significantly affect internal controls

Control activities10. Select and develop control activities that mitigate risks11. Select and develop technology controls

12. Deploy control activities through policies and procedures

Information and communication13. Use relevant, quality information to support the internal control function14. Communicate internal control information internally

15. Communicate internal control information externally

Monitoring16. Perform ongoing or periodic evaluations of internal controls (or a combination of the two)17. Communicate internal control deficiencies

B. CoCo: The CoCo (Criteria of Control) framework was developed by the Canadian Institute of Chartered Accountants (CICA) in 1995. This model builds on COSO and is thought to be more concrete and user-friendly by some. This framework outlines 20 control criteria that management can use to manage company performance and improve its decision-making.

The CoCo framework outlines criteria for effective controls in the following four areas:

  • Purpose
  • Commitment
  • Capability
  • Monitoring and learning

C. COBIT: Stands for Control Objectives for Information and Related Technology. This framework is created by the ISACA (Information Systems Audit and Control Association) for IT governance and management. The COBIT control model guarantees integrity of the information system. It allows to control IT operations of the company so that risk can be minimized and work power enhanced in a disciplined manner. It allows managers to fill the gap between technical issues, control requirements, and business risks.

5. Principles of COBIT:

1. Meeting stakeholder needs
2. Covering the enterprise end to end
3. Applying a single integrated framework
4. Enabling a holistic approach
5. Separating governance from management

Main focus areas of the Cobit are:

  • Planning and Organizing
  • Delivery and Support
  • Acquiring and Implementation
  • Monitoring and Evaluating

Risks As in Internal Audit

Tuesday, 24 November 2020

Complete Guide on Internal Audit in India

 

Internal Audit in India is one of the major areas which aid the organization in enhancing business performance by identifying the growth areas with greater scope for improvement. The process of Internal audit helps in reviewing the existing systems and their effectiveness by benchmark the audit processes and procedures against the best industry practices to meet the global standards.

Internal audit evaluates and improves effectiveness of an organizations risk management, control, governance and accounting processes. Internal audit is performed to identify potential risk (such as misappropriation of assets, misuse of funds, frauds, manipulation of records) an organization may be prone to, managing those risk and reporting on such risk and their management as per statutory requirements.

Internal Audit Objectives:
Internal audit is performed to give assurance to top level management that the risk associated to business are identified and managed properly. It is conducted to provide assurance that management of an organization has an ability to manage risk effectively. It also ensures that governance and internal control processes are operating effectively.

5 Reasons Why Internal Audits are Important
Internal auditing programs are critical for monitoring and assuring that all of your business assets have been properly secured and safeguarded from threats. It is also important for verifying that your business processes reflect your documented policies and procedures.

Let’s take a look at five reasons why internal auditing is important and their purpose in keeping your organization compliant with the common frameworks and regulations.

  1. Provides objective insight
  2. Improves efficiency of operations
  3. Evaluates risks and protects assets
  4. Assesses organizational controls
  5. Ensures legal compliance

Basic Principals of an Internal Audit
For an internal audit function to be considered effective, the basic Principles should be achieved. Failure to achieve any of the Principles would imply that an internal audit activity was not as effective. The basic principles governing internal Audit are

  • Demonstrate uncompromised integrity and independence;
  • Display due professional care while performing Audit;
  • Demonstrate commitment to competence;
  • Maintain Confidentiality;
  • Assessment of Risk element and having adequate resources to address it;
  • Focusing on Systems and process i.e., Root Cause Analysis;
  • Participating in decision making, other than those subject to subsequent audit;
  • Adopting procedures to continuously improve the quality of internal audit process and audit reports;
  • Align strategically with the aims and goals of the enterprise;
  • Achieve efficiency and effectiveness in delivery;
  • Communicate effectively;
  • Provide reliable assurance to Those Charged with Governance (TCWG);
  • Be insightful, proactive, and future-focused.

What is an internal audit report?
An internal audit report is a document with the formal results of an audit. It is used by the internal auditor to show what was examined, highlighting positives, negatives and conclusions, so that the company’s management knows what is going well and what needs to be improved.

The report should be carefully prepared. Yet it is at this point that many internal auditors fail.

The text needs to be clear, objective and impartial in order to ensure that the audit’s results are useful and the organization can use them as a guide to set the direction of actions.

PK Chopra is one of the leading management consultants who have been assisting clients across industries with flexible and result oriented solutions that enhance the organization’s performance by improving efficiency in the business processes.

PK Chopra offers the internal audit services / process audit services in India to the companies. If you wish to know more in this regard, kindly contact us.

Thursday, 29 October 2020

TCS Under Income Tax - Provisions Applicable from 01.10.2020

 

Tax Collected at Source Under Income Tax — New Provisions Applicable from 01 October 2020

Introduction
Finance Act, 2020
introduced 3 new provision under Tax Collected at Source (“TCS”):

TCS on foreign remittance through LRS;

TCS on selling overseas tour packages; and

TCS on sales of any goods

TCS unlike TDS is required to be collected additionally along with consideration for certain transaction;

That is TCS is required to be collected by the payee;

Whereas, TDS is required to be deducted on certain payments made by the payer for certain transactions.

TCS ON FOREIGN REMITTANCE THROUGH LRS

The new provisions of tax collected at source are applicable w.e.f 01 October 2020

TCS ON SELLING OVERSEAS TOUR PACKAGES

TCS ON SALE OF ANY GOODS (1/3)

TCS ON SALE OF ANY GOODS(2/3)

TCS ON SALE OF ANY GOODS(3/3)
We have tried to address few practical aspects in implementation of the said provision by way of FAQs:

How to Collect Tax from the buyer? The seller needs to raise the invoice inclusive of the amount of TCS. However, liability of remittance does not arise until the time when amount is to be collectedHow to determine the applicability of these provision?The law does not make mandatory to comply continuously once the seller is obliged to follow, which means the applicability needs to be determined on a year to year basisWhether TCS applicable on sale of property?Sale of property is covered distinctively under the provision of section 194IA for value exceeding INR 50 LakhsWhether TCS should be refunded in case of sales returns?No, only primary sales value should be refunded as the amount of TCS would have been credited as prepaid taxes and will appear in Form 26AS of the buyer. However, if the amount has not been settled or net settlement is being made post adjustment of return then on such net consideration TCS should be collectedWhether the consideration will include the amount collected towards GST?The word consideration is not defined. In terms of section 145A irrespective of the treatment in books of accounts, the value of sales will be inclusive of GST

TCS PAYMENT AND RETURN

  • TCS collected needs to be paid within 7 days of the nextmonth.
  • Every tax collector shall submit quarterly TCS return i.e., Form 27EQ in respect of the tax collected by him in a particular
  • The due date of quarterly return is asunder

WAY FORWARD AND SCOPE LIMITATION

WAY FORWARDSCOPE LIMITATIONWe shall assist in determining the applicability of the above provision, depending on the nature of business and each business transaction;andWe have not considered the current revised rates as proposed by the government in view of the global pandemic COVID — 19;andThe amount on which the tax should be collected and the amount of remittance for each of the transaction.However, for the sake of the completion, the rates w.r.t sale of goods have been reduced to 0.075% for buyer having PAN/Aadhar, for current financial year only

Disclaimer
Please note that the above note is subject to government clarification or changes in law, we have merely discussed the applicability in the current scenario

Source: https://pkchopra.com/blog/index.php/tcs-under-income-tax-provisions-applicable-from-01-10-2020/