INTERNAL AUDIT_ACCA_中華會計網校

2020-12-05 中華會計網校

DECISION TO HAVE AN INTERNAL AUDIT DEPARTMENT

At each stage of the process the board faces a number of decisions: setting the firm’s risk appetite, assessing risks, and then choosing which risks to accept, transfer, reduce or avoid. If a risk reduction response is adopted, the board must then design an appropriate set of controls, possibly including establishing an internal audit function. In most jurisdictions, especially where corporate governance is principles-based, IA departments are not required by statute or regulation, but are considered best practice. However, as soon as the task of reviewing the company’s internal control and risk management system reaches even a reasonably low level of complexity, the audit committee will find that they need to delegate this work. This is clearly a sensitive task, as it involves investigating and discovering how effective strategic and operational controls have been. It requires a skilled team of internal auditors, who can act independently and who will report back objectively to the audit committee. As you can imagine, it would be unusual for a company of any size (not just a listed company) to be able to dispense with the services of an IA department, which is why an explanation is required when there are no internal auditors.

 

One obvious issue to consider is what other factors apart from size would indicate that an IA department might be required. It is not hard to come up with some of the relevant factors by reflecting that a company needs a control when risk needs reducing. So factors giving rise to increased risk, such as complex or highly regulated transactions, might suggest the need for the IA control to be deployed. You would, therefore, expect banks to have IA departments since some of the transactions they handle are complex (accounting for financial instruments) and they operate in a regulated industry.

 

In some regulated industries it is mandatory to have an internal audit department, but even where this is not the case there may be close scrutiny of the company by the regulatory authority, which can apply significant sanctions such as the removal of operating licences. When a compliance failing (including timely reporting to the regulator) might mean that the company cannot operate at all, the case for an internal audit department becomes overwhelming. Companies in regulated industries may also need the information from internal audit to use in their reports and submissions to regulators and, so, reliable and accurate IA information is also needed to ensure the adequacy of this reporting.

 

The UK’s influential Turnbull report provides some other suggestions for the factors that ought to be considered when considering the establishment of an IA function. Some of them are things that might indicate risks. For example, one factor – number of employees – might indicate risks directly (a large volume of payroll transactions to process) but, more significantly, it indicates size and complexity, so perhaps widespread locations with complex reporting lines and less shared culture (of risk awareness, or of integrity). Specific problems with internal controls and an increase in unacceptable events are two other factors that might also be indicative of deeper issues within the organisation. As well as an immediate problem that needs investigating, both suggest failings in the board-implemented process of risk assessment and risk response, which – had it been done more effectively – might have implied the need for an IA department.

Arising out of uncertainty, risk is fundamental to change. Any significant changes faced by the business will therefore inevitably create risk, and the organisation should consider its need for internal audit. The changes highlighted in the Turnbull report are changes in key risks and changes in the internal organisational structure.

 

TABLE 1: THE TURNBULL CRITERIA TO ASSESS THE NEED FOR INTERNAL AUDIT

Scale, diversity and complexity of the company’s operations

Number of employees

Cost-benefit considerations

Changes in organisational structure

Changes in key risks

Problems with internal control systems

Increased number of unexplained or unacceptable events

 

REPORTING TO THE AUDIT COMMITTEE

Let’s return to the idea that the internal audit department is carrying out the delegated work of the audit committee. This is a fruitful area to explore because it explains some of the characteristics of effective (and ineffective) IA. The audit committee is made up of independent non-executive directors (NEDs). This isn’t the place to explore the concept of independence in detail, but independence is central to an effective IA department. The work of IA becomes meaningless if it is compromised by management influence. Achieving independence is difficult, and made more so because internal auditors are usually employees of the company.

 

The audit committee is one of the vital parts of the committee structure of sound corporate governance. Its role in overseeing IA is important because it is the audit committee that ensures that the IA function actually supports the strategic objectives of the company (and doesn’t act purely on its own initiative). In addition, though, it is likely that the audit committee – at the strategic level – will not only provide the IA function with the authority it needs to scrutinise the internal controls, but also to ensure that its work is actually supporting and providing the compliance needs of the company. It is part of ensuring the hierarchical congruence or consistency necessary in sound governance and strategic management.

 

Members of the IA function may encounter ethical threats (such as familiarity, self review, independence threats, and so on). An accountant working as an internal auditor, for example, may be unwilling to criticise the CFO if he believes the CFO has an influence on his future prospects with the company. Someone coming into IA from an operational position could also be exposed to a self-review threat. Even where external contractors are used to carry out the IA function, they are acting on behalf of management. To avoid this, and other ethical threats, internal audit work is one of the jobs expressly forbidden to external auditors under the terms of the Sarbanes–Oxley Act in the US, indicating just how valuable a characteristic independence is for all auditors (other codes have similar provisions).

 

There are some inherent limitations in what an IA department can achieve. Although corporate scandals sometimes arise from failings in operational level controls, there

are also examples where the problem is a failure of strategic level controls, either arising from management override of controls (as at Enron) or through poor strategic level decisions (as at some of the banks that required state support in the 2008 banking crisis). Even in companies where excellent procedures are put in place to assess operational level controls, it is hard to imagine how IA can fully monitor strategic controls. It would be very hard to design a corporate governance structure in which even the most independent IA department had a mechanism to do much more than check that procedures have been followed at board level. The board ultimately has to be responsible for the proper working of strategic level controls. This is also illustrative of the way IA fits in to overall corporate governance. The corporate governance big picture has to be addressed if IA is going to be effective. A domineering CEO cannot be countered by the existence of an IA department. Indeed, interference in the work of internal audit would indicate broader corporate governance problems.

 

DAY-TO-DAY INTERNAL AUDIT

In Paper F8 you will have studied the types of work carried out by internal auditors:

·           Value for money audits

·           Information technology audits

·           Best value audits

·           Financial audits

·           Operational audits

 

One of the key differences between internal and external audit is that the scope of internal audit work in an unregulated industry is determined by the company (specifically by the audit committee) while the scope of the external auditors』 work is determined by the fact that they are undertaking a statutory audit, a legal requirement. IA will mean something different in each organisation. In one company, the 『internal audit』 department might only carry out quality control checks, while in another it is a sophisticated team of specialists with different expertise that reflect the risks faced by that organization, including the regulatory requirements placed upon it.

 

Whether the IA department is carrying out a review of the process of designing systems, or a review of the operation of controls within those systems, will depend on the current concerns of the organisation. In an exam it would be wise to tailor the suggestions made for IA to the concerns hinted at in the scenario. For example, in a highly regulated business where compliance failures are a significant risk, monitoring compliance might be a key task assigned to IA. If safeguarding assets is a key concern you could discuss how IA might be involved in a review of the safeguarding of assets. You may have noted that the last two suggestions both relate to the Turnbull statements about a sound system of internal controls. Any of those could be related to the work of internal audit – for example, IA might need to review the implementation of corporate objectives.

 

Paper P1 also covers issues of sustainability, environmental and social responsibility. IA is a resource that could be deployed to monitor how effective a company’s corporate social responsibility (CSR) policies are. This could mean monitoring how well the policies have been implemented or it could mean IA monitoring how well CSR policies and wider corporate objectives are aligned with each other. Schemes like the European Union’s Eco-Management and Audit Scheme (EMAS) provide an example of an instance where specific monitoring of targets (by IA) is an externally imposed requirement on a company. ISO 14000, another environmental standard, also explicitly requires internal audits and reports to management.

 

To sum up, internal audit is the control of controls. It can feature in Paper P1 as a key part of the corporate governance framework of an organisation, and it can be viewed through the lens of risk management as a high level control in response to risk or by considering the detailed work required of IA. Finally, as a key component of the control system, it is important to maintain the integrity of internal audit and, from this perspective, issues of professional ethics and characteristics such as independence come into play.

 

Amanda Williams is a tutor and subject specialist at BPP Professional Education

See the original>>

相關焦點

  • acca F9考官文章2_ACCA_中華會計網校
    Feedback from internal examiners on candidate performance from successive exam sessions.Interim auditF2d) Going concern
  • acca 知識點:會計acca英文單詞(193)
    acca 知識點:會計acca英文單詞(193) ACCA在國內稱為"國際註冊會計師",考取acca證書可以在四大會計師事務所就職,也可以在各大投行、商行找到高薪工作。那麼,acca全英文考試需要如何準備呢?會計acca英語單詞有哪些?
  • 審計報告(中英對照)_會計實務_中華會計網校
    致XX公司股東(在XX註冊成立的股份有限公司)  本審計師(以下簡稱「我們」)已完成審核刊於第58頁至第108頁根據香港公認會計原則編制的財務報表。審核範圍包括以抽查方式查核與財務報表所載數額及披露事項有關的憑證,亦包括評估董事於編制該等財務報表時所作的重大估計及判斷、所釐定的會計政策是否適合貴公司的具體情況以及有否貫徹應用並充分披露該等會計政策。  我們於策劃及進行審核工作時,均以取得一切我們認為必須的數據及解釋,致使我們獲得充分的憑證,從而就該等財務報表是否存有重大的錯誤陳述,作合理的確定。
  • 中華會計網校名師徐經長解析《中級會計實務》三段式學習的特點
    主講《財務會計學》、《高級會計學》等課程。主要研究領域有會計理論與方法、國際會計協調、證券市場會計監管等。  彰顯大師級氣質與魅力,專業功底深厚,講解精闢透徹,高屋建瓴。善於啟迪思路,剖析背景,從源頭上講解準則制定的初衷。在讓學員茅塞頓開的同時,進一步感受會計學的精思妙想,從而激發起濃厚的學習興趣。
  • acca F9考官文章4_ACCA_中華會計網校
    Additionally, from June 2011 onwards, there is a section on Islamic finance (see the article in the 9 March issue of Student Accountant which covers Islamic finance in detail available at: www.accaglobal.com
  • 高頓教育:ACCA免試條件有哪些?ACCA對AICPA免試嗎?
    想要知道acca免考的相關信息,找小編就對了。今天給大家帶來的是acca免考條件以及免考的注意事項快來一看看吧!  一、ACCA免試條件有哪些?,下同)免試5門課程(AB-PM)會計學 – 輔修專業免試3門課程(AB-FA)法律專業免試1門課程 (LW)
  • 財務管理英語(二)_會計實務_中華會計網校
    capital investment 資本投資   operating expense 經營費用   payback period 回收期   discounted-payback rule 貼現回收期法則   discounted-cash-flow rate of return 貼現現金流量的收益率   internal
  • 中華會計網校為您解答:關於2020年高會無紙化考試的12個問題
    高級會計職稱考試方式採用無紙化考試方式,考試在計算機上進行。試題、答題要求和答題界面在計算機顯示屏上顯示,考生應使用計算機滑鼠和鍵盤在計算機答題界面上進行答題。  即將走上2020年高級會計職稱考場的考生,其中一部分人群是第一次報考,對於無紙化考試方式並不熟悉,難免有很多疑慮。網校特地整理了高級會計師無紙化考試12個問題,供大家參考。
  • 左右記帳_中華會計網校
    【課程名稱】:基於左右記帳法的會計學基礎(兼容借貸記帳法)  進入學習>> 【上課時間】:會計學基礎常識30分鐘,會計實務案例30分鐘。 【面向學員】:政府或企業的各級管理人士,對於會計界專業人士也同樣有參考價值,全國學員不限地域,可通過網絡學習。 【課程形式】:網絡視頻 【您的收益】:不需要有任何會計學背景,就可以根據記帳的規律,掌握會計學基礎及記帳操作方法!
  • 國內外基本會計準則比較_會計實務_中華會計網校
    概述  我國的會計準則分基本會計準則和具體會計準則。基本會計準則主要對會計核算的一般要求和會計核算的主要方面作出原則性的規定,為具體會計準則和會計制定的制定提供基本架構。具體會計準則則根據基本會計準則的要求,就經濟業務的會計處理及其程序作出具體規定。
  • 高等學校會計制度_財經法規-中華會計網校
    第一部分 總說明  一、為了適應我國社會主義市場經濟體制和高等學校各項事業發展的需要,規範高等學校會計核算,保證會計信息質量,根據《中華人民共和國會計法》和《事業單位會計準則(試行)》制定本制度。  二、本制度適用於各級人民政府舉辦的全日制普通高等學校、成人高等學校。
  • 淺談會計信息與股票價格_會計實務_中華會計網校
    【摘要】本文論述了有效市場假說,分析了會計披露對股票價格的影響,提出了我國提高會計信息與股票價格相關性的措施。  【關鍵詞】會計信息 股票價格 有效市場假說   國際會計準則中記載著會計信息所具有的四個著名的質量特徵:通懂性(Understandability),相關性(Relevance),可靠性(Reliability)和可比性(Comparability)。
  • 如何在中級會計職稱備考中鎖住時間
    2016年中級會計職稱考試時間是9月10日至12日,如今已是五月份的尾巴,各位中級會計職稱備考的人們,中華會計網校想要提醒大家的是
  • acca 知識點:acca英文單詞(53)
    acca 知識點:acca英文單詞(53) ACCA在國內稱為"國際註冊會計師",實際上是特許公認會計師公會(The Association Of Chartered Certified accountants)的縮寫,今天中公財經網小編給大家總結一些
  • acca 知識點:acca英文單詞(39)
    acca 知識點:acca英文單詞(39) ACCA在國內稱為"國際註冊會計師",實際上是特許公認會計師公會(The Association Of Chartered Certified accountants)的縮寫,今天中公財經網小編給大家總結一些ACCA 知識點
  • 中級會計職稱《經濟法》每日一練:經濟法的淵源
    中級會計職稱《經濟法》每日一練:經濟法的淵源 來源: 中華會計網校 編輯: 2010/10/22 08:39:06  字體:大 小
  • 高頓教育:2021年acca刷題一直錯怎麼辦?acca心態如何調整?
    2021年acca刷題一直錯怎麼辦?acca心態如何調整?ACCA刷題一直錯,不一定是自己的原因,這個時候你需要調整好自己的心態在繼續。  一、2021年acca刷題一直錯怎麼辦?  acca刷題一直錯,考試知識要點也記不住應該怎麼辦?
  • 中級會計職稱《財務管理》每日一練:上加法應用
    中級會計職稱《財務管理》每日一練:上加法應用 來源: 中華會計網校 編輯: 2010/11/03 08:45:45  字體:大 小