In January 2013, the updated version of the Committee of Sponsoring Organizations of the Treadway Commission (COSO) Integrated Internal Control Framework (Framework) went into effect (http://www.ic.coso.org). If you’re wondering what this model is, you probably work for a privately held corporation or a non-profit, or are very new to internal audit.
The Internal Control—Integrated Framework, a product of primary and secondary research, was originally published in 1992. However, in 2002 the Framework catapulted into the spotlight as a result of the Sarbanes-Oxley Act Section 404.
A lot has happened since the Framework was first published in 1992. There have been several natural disasters around the world, including tsunamis, earthquakes, blizzards, and hurricanes. Reliance on technology—particularly in the areas of Internet dependency, networking, mobile device proliferation and cloud computing—have increased the risk of data leakage and identity theft. There has been increased financial globalization and interdependency: consider the impact of auction rate security market failures and LIBOR rate rigging. Bernard Madoff and others have perpetrated significant frauds, increasing the need for fraud risk assessments and appropriate countermeasures. And of course, there’s been global impact from the Liquidity Crisis and the Eurozone Crisis, not to mention the effects of war and political unrest. It was time for a refresh, so that the Framework could continue to be contemporary and meaningful.
As part of the update, I think two noteworthy changes occurred that could (or should) affect your auditing methodology and organizational risk management practices:
The scope and definition of “reporting” as one of the dimensions of organizational goals
The articulation of principles associated with each of the components.
Let’s consider each of these changes and their implications for your organization.
NON-FINANCIAL REPORTING IS IMPORTANT, TOO
The original Framework defined internal control as “…a process, effected by an entity’s board of directors, management and other personnel, designed to provide reasonable assurance regarding the achievement of objectives in the following categories:
Effectiveness and efficiency of operations
Reliability of financial reporting
Compliance with applicable laws and regulations”
Following is the updated Framework definition:
“Internal control is a process, effected by an entity’s board of directors, management and other personnel, designed to provide reasonable assurance regarding the achievement of objectives relating to operations, reporting, and compliance.”
The emphasis I have added makes it easy to see that “financial” was dropped as the modifier, signaling that all reporting needs to be reliable. While this may seem to be an obvious point, in many organizations, financial reporting—specifically the reporting associated with financial statement preparation—is given attention and priority. The value and importance of non-financial or operational reporting is eclipsed, if not overlooked. Similarly, in many organizations, financial and financial reporting risks take priority over operational and compliance risk. And if it were a contest between compliance and operational risk, compliance would take priority because organizations want to avoid fines, penalties and sanctions.
The updated Framework recognizes that the reporting of non-financial data is as important as the reporting of financial data. Non-financial data is used to make key business decisions that affect an organization’s financial condition. For example, consider the manner in which your organization reports on the number of customer complaints, service calls, sales inquiries and potential prospects. Each of these activities is operational in nature and none directly affect the financial reporting process. Yet, if any of these were over- or under-reported, the organization could make erroneous decisions regarding expansion, consolidation or pricing. These decisions, in turn, would drive organizational behavior and ultimately affect financial performance.
For internal audit departments, consider the extent to which the operational component of your organization’s objectives and the associated risk are prioritized when you formulate your annual audit plan. To what extent are operational considerations and risks the focus of individual audits? Also consider to what extent your organization values controls over non-financial information security and reporting. To what extent is attention focused solely on financial reporting?
DEFINING ATTRIBUTES OF EFFECTIVENESS
In keeping with the adage, “what gets measured gets done,” the updated Framework describes 17 principles associated with the five components, which make it easier to evaluate organizational effectiveness. Audit departments and organizations that have been COSO-compliant have probably defined their own criteria and behavioral indicators. By articulating these principles, the updated Framework makes it easier for organizations—and the departments that comprise them—to achieve consistent implementation and assess their results.
Following is a summary of the principles by component:
|Information and Communication||
If you are already COSO-compliant, how do your organization’s current behavioral success indicators compare to the Framework’s principles? If you are considering the Framework’s adoption, the principles provide a clear starting point for your implementation efforts.
HOW IMPORTANT ARE THESE CHANGES?
The world has sustained a lot of change since 1992 and internal control practices need to keep pace. The Framework’s updates came at an opportune time and provide more prescriptive information, making it easier to achieve consistency in our internal control practices and evaluate their effectiveness.
The extent to which these changes matter depends on your organization’s structure and culture, and the degree to which your organization is COSO-compliant.
If you are in a non-publicly traded environment, the updates may provide you with a clearer roadmap to advance the risk management culture within your organization. If you are contemplating the Framework’s implementation, the addition of the 17 principles makes it easier to evaluate internal control effectiveness and determine the critical activities that comprise each internal control component.
If your organization is already COSO-compliant, these updates provide you with a basis for evaluating your audit methodology and may help you identify opportunities to enhance it.
About the author:
Ann M. Butera, MBA, CRP, is President of The Whole Person Project, Inc., an organizational development consulting and training firm, is a frequent conference speaker, and serves as audit committee chair for a financial services firm. She welcomes your reactions and questions, and can be reached at firstname.lastname@example.org or (516) 354-3551. Please visit www.wholepersonproject.com for more information on her consulting and training services.