SlideShare a Scribd company logo
1 of 20
Recent COSO Internal Control and
Risk Management Developments
IFAC and ISO Panel Discussion
September 24, 2013
David L. Landsittel
Former Chair - COSO
About COSO
• Formed in 1985 to sponsor a group to make
recommendations on Fraudulent Financial Reporting
• A joint initiative of five private sector organizations:
▫ American Accounting Association (AAA)
▫ American Institute of Certified Public Accountants
(AICPA)
▫ Financial Executives International (FEI)
▫ Institute of Management Accountants (IMA)
▫ The Institute of Internal Auditors (IIA)
Mission
COSO’s Mission is “To provide thought leadership
through the development of comprehensive frameworks
and guidance on enterprise risk management,
internal control and fraud deterrence designed to
improve organizational performance and governance
and to reduce the extent of fraud in organizations.”

COSO’s Fundamental Principle
Good risk management and internal control are
necessary for long term success of all organizations
COSO’s Three Areas of Focus
1. Internal Control
2. Enterprise Risk Management

3. Fraud Deterrence
Timeline

2010: Fraud Study II Fraudulent Financial
Reporting: 1998-2007

2004: Enterprise Risk
Management Framework

1987: Treadway
Commission Report

2009: Guidance on
Monitoring Internal
Control Systems

1996: Internal Control
Issues in Derivatives
1985
1990

1995

2000

1999: Fraud Study I Fraudulent Financial
Reporting: 1987-1997
1992: Internal Control –
Integrated Framework

2005

2006: Guidance
for Smaller
Businesses on
Internal Control
over Financial
Reporting

2010

2010-2013:
Recent ERM
thought
papers on
current issues
COSO Internal Control Framework
• First published in 1992
• Gained wide acceptance following

financial control failures of early 2000’s
• Most widely used framework in the US
• Also widely used around the world – translated into 7
languages
Why Update What Works?
ICIF Works
Well Today

COSO’s Internal Control–Integrated Framework (1992 Edition)

Enhancements

ICIF Will Work
Better
Tomorrow

Reflect changes in

to facilitate effective

business & operating

internal control

Update
Objectives

Articulate principles

environments

Clarifies Requirements

Updates Context

Expand operations and
reporting objectives

Broadens Application

COSO’s Internal Control–Integrated Framework (2013 Edition)
Project Plan & Timetable
Assess &
Survey
Stakeholders

2010

Design
& Build

2011

Public
Exposure
& Assess

2012

Finalize

2013
Project Participants
COSO
Board of Directors

PwC
Author and Project Leader

COSO Advisory Council

Stakeholder Input

•
•
•
•
•
•
•
•

•Survey of over 700 stakeholders and users of the
1992 Internal Control – Integrated Framework

AICPA
AAA
FEI
IIA
IMA
Public Accounting Firms
Regulatory observers
Others (IFAC, ISACA, others)

•Public Exposures of updated Framework draft and
supporting documents
•Webcasts, round tables, direct correspondence via
icif@us.pwc.com et al
Summary of Updates
…
What is not changing...

What is changing...

1. Definition of internal control

1. Updated to reflect the current
business environment

2. Five components of internal
control
3. The fundamental criteria used to
assess effectiveness of systems
of internal control
4. Use of judgment in designing
and implementing controls and
in evaluating the effectiveness of
systems of internal control

2. Formalized fundamental
concepts underlying the five
components as principles
3. Expanded financial reporting
objective to address internal and
external, financial and nonfinancial reporting objectives

4. Increased focus on operations
and compliance objectives based
on user input
11

Summary of Updates
A changing business environment...
Expectations for governance oversight
Globalization of markets and operations
Changes in business models
Demands and complexity of rules,
regulations and standards
Expectations for competencies and
accountabilities

Use and reliance on evolving technology
Expectations for preventing and detecting fraud

Drives updates to the Framework...
17 Principles of the Updated ICIF
Control Environment

Risk Assessment

Control Activities

Information &
Communication
Monitoring Activities

1.
2.
3.
4.
5.

Demonstrates commitment to integrity and ethical values
Exercises oversight responsibility
Establishes structure, authority and responsibility
Demonstrates commitment to competence
Enforces accountability

6.
7.
8.
9.

Specifies suitable objectives
Identifies and analyzes risk
Assesses fraud risk
Identifies and analyzes significant change

10. Selects and develops control activities
11. Selects and develops general controls over technology
12. Deploys through policies and procedures
13. Uses relevant information
14. Communicates internally
15. Communicates externally
16. Conducts ongoing and/or separate evaluations
17. Evaluates and communicates deficiencies
Update Articulates Principles of
Effective Internal Control
Control Environment

1. The organization demonstrates a commitment to
integrity and ethical values.
2. The board of directors demonstrates independence
from management and exercises oversight of the
development and performance of internal control.
3. Management establishes, with board oversight,
structures, reporting lines, and appropriate
authorities and responsibilities in the pursuit of
objectives.
4. The organization demonstrates a commitment to
attract, develop, and retain competent individuals
in alignment with objectives.
5. The organization holds individuals accountable for
their internal control responsibilities in the pursuit
of objectives.
Project Deliverables: Internal ControlIntegrated Framework
• Consists of three volumes:
▫ Executive Summary
▫ Framework and Appendices
▫ Illustrative Tools: Assessing
Effectiveness of a System of
Internal Control

• Sets out:

▫ Definition of internal control
▫ Categories of objectives
▫ Components of internal control
▫

and related principles and points
of focus
Requirements for Effectiveness
Project Deliverables: Internal Control over
External Financial Reporting: A Compendium
• Provides approaches and
Examples illustrating how
principles are applied in
preparing financial statements
for external purposes
• Is relevant for variety of
entities – public, private, notfor-profit, and government

• Is consistent with and does not
modify the updated Framework
The ERM Framework
• Published in 2004
• Based upon a framework
with similarities to the
COSO 92 framework
• Widely recognized, but
not as widely adopted as
COSO 92

• Implementation not as
robust as COSO 92
Some Current ERM Challenges
• Uneven support to adopt any formal risk management
process
• Less than robust ERM implementation
• Difficulty “getting started” with ERM implementation
• Difficulty aligning ERM with top management view
• Inadequate board oversight of risk management – and
regulatory pressure mounting for better oversight

• Immature development of risk appetite
• Failure to consider low likelihood but high impact risks –
overconfidence
18

COSO ERM Response
Our objective – to assist stakeholders in moving up
“maturity curve” of an effective ERM process

Publication of a series of thought papers
19

COSO ERM “Thought Papers”
•

Four Papers issued in 2009 surveying ERM practices – and particularly
practices and recommendations related to board of director oversight

•

Four Papers in 2011 and 2012 focusing on difficult ERM process
implementation issues:
▫ “Getting Started”
▫ Developing Key Risk Indicators
▫ Understanding and Communicating Risk Appetite
▫ Risk Assessment Practices

•

Two Papers in 2012-2013 dealing with applying ERM to current
Management issues:
▫ “Cloud” Computing Risks
▫ Sustainability Risks

•

A Behavioral Paper in 2012 dealing with Judgment Biases
Questions or Comments?
Thank You!
David Landsittel
www.coso.org

More Related Content

What's hot

Are You Ready? Implementing COSO's Updated Internal Controls Framework
Are You Ready? Implementing COSO's Updated Internal Controls FrameworkAre You Ready? Implementing COSO's Updated Internal Controls Framework
Are You Ready? Implementing COSO's Updated Internal Controls FrameworkBlackLine
 
Introduction to internal auditing
Introduction to internal auditingIntroduction to internal auditing
Introduction to internal auditingDavid Griffiths
 
Coso internal control integrated framework
Coso internal control   integrated frameworkCoso internal control   integrated framework
Coso internal control integrated frameworkIrfan Ahmed - ACA, CICA
 
Internal Audit COSO Framework
Internal Audit COSO FrameworkInternal Audit COSO Framework
Internal Audit COSO FrameworkJesús Gándara
 
Ppt on risk based internal audit
Ppt on risk based internal auditPpt on risk based internal audit
Ppt on risk based internal auditAmitaMistry2
 
Governance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management SolutionGovernance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management SolutionRishabh Software
 
Internal audit manual template
Internal audit manual templateInternal audit manual template
Internal audit manual templateCenapSerdarolu
 
Internal audits role in compliance
Internal audits role in complianceInternal audits role in compliance
Internal audits role in complianceSalih Islam
 
Risk Assessment For Internal Auditors
Risk Assessment For Internal AuditorsRisk Assessment For Internal Auditors
Risk Assessment For Internal Auditorsminkhollow
 
A Presentation on Risk Based Auditing
A Presentation on Risk Based AuditingA Presentation on Risk Based Auditing
A Presentation on Risk Based AuditingAmar Deep Ghimire
 
Governance, risk and compliance framework
Governance, risk and compliance frameworkGovernance, risk and compliance framework
Governance, risk and compliance frameworkCeyeap
 

What's hot (20)

Risk based internal auditing
 Risk based internal auditing Risk based internal auditing
Risk based internal auditing
 
Are You Ready? Implementing COSO's Updated Internal Controls Framework
Are You Ready? Implementing COSO's Updated Internal Controls FrameworkAre You Ready? Implementing COSO's Updated Internal Controls Framework
Are You Ready? Implementing COSO's Updated Internal Controls Framework
 
COSO ERM
COSO ERMCOSO ERM
COSO ERM
 
Introduction to internal auditing
Introduction to internal auditingIntroduction to internal auditing
Introduction to internal auditing
 
Coso internal control integrated framework
Coso internal control   integrated frameworkCoso internal control   integrated framework
Coso internal control integrated framework
 
Internal Audit COSO Framework
Internal Audit COSO FrameworkInternal Audit COSO Framework
Internal Audit COSO Framework
 
Internal Auditor Roles
Internal Auditor RolesInternal Auditor Roles
Internal Auditor Roles
 
Ppt on risk based internal audit
Ppt on risk based internal auditPpt on risk based internal audit
Ppt on risk based internal audit
 
Governance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management SolutionGovernance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management Solution
 
Internal audit manual template
Internal audit manual templateInternal audit manual template
Internal audit manual template
 
Audit Risk Assessment Chapter 9
Audit Risk Assessment Chapter 9Audit Risk Assessment Chapter 9
Audit Risk Assessment Chapter 9
 
The Internal Audit Framework
The Internal Audit FrameworkThe Internal Audit Framework
The Internal Audit Framework
 
COSO 2013 and The Auditor
COSO 2013 and The AuditorCOSO 2013 and The Auditor
COSO 2013 and The Auditor
 
COSO Internal Control - Integrated Framework
COSO Internal Control - Integrated FrameworkCOSO Internal Control - Integrated Framework
COSO Internal Control - Integrated Framework
 
Internal audits role in compliance
Internal audits role in complianceInternal audits role in compliance
Internal audits role in compliance
 
Internal Audit Reporting
Internal Audit ReportingInternal Audit Reporting
Internal Audit Reporting
 
Risk Assessment For Internal Auditors
Risk Assessment For Internal AuditorsRisk Assessment For Internal Auditors
Risk Assessment For Internal Auditors
 
A Presentation on Risk Based Auditing
A Presentation on Risk Based AuditingA Presentation on Risk Based Auditing
A Presentation on Risk Based Auditing
 
Governance, risk and compliance framework
Governance, risk and compliance frameworkGovernance, risk and compliance framework
Governance, risk and compliance framework
 
Internal audit ppt
Internal audit pptInternal audit ppt
Internal audit ppt
 

Viewers also liked

COSO Implementation: Getting Real, Getting It Right
COSO Implementation: Getting Real, Getting It RightCOSO Implementation: Getting Real, Getting It Right
COSO Implementation: Getting Real, Getting It RightBlackLine
 
ERM and Internal Auditing 2016 Tea Talk v2a
ERM and Internal Auditing 2016 Tea Talk v2aERM and Internal Auditing 2016 Tea Talk v2a
ERM and Internal Auditing 2016 Tea Talk v2aNusaibah Hamizan
 
Internal Control & Risk Management Framework
Internal Control & Risk Management FrameworkInternal Control & Risk Management Framework
Internal Control & Risk Management FrameworkTreasury Consulting LLP
 
Internal Control
Internal ControlInternal Control
Internal ControlSalih Islam
 
Enterprise risk management
Enterprise risk managementEnterprise risk management
Enterprise risk managementAndre Knipe
 
Risk management and internal control simplified powerpoint
Risk management and internal control simplified powerpointRisk management and internal control simplified powerpoint
Risk management and internal control simplified powerpointNoel Rupanga ACMA, CGMA
 
Sarbanes Oxleys Impact On The Coso Cube
Sarbanes Oxleys Impact On The Coso CubeSarbanes Oxleys Impact On The Coso Cube
Sarbanes Oxleys Impact On The Coso CubeDwayne Jorgensen
 
Applying an Effective Control Environment to Integrated Reporting Through COS...
Applying an Effective Control Environment to Integrated Reporting Through COS...Applying an Effective Control Environment to Integrated Reporting Through COS...
Applying an Effective Control Environment to Integrated Reporting Through COS...Workiva
 
Đánh giá lựa chọn dự án đầu tư kinh doanh
Đánh giá lựa chọn dự án đầu tư kinh doanhĐánh giá lựa chọn dự án đầu tư kinh doanh
Đánh giá lựa chọn dự án đầu tư kinh doanhSi Thinh Hoang
 

Viewers also liked (17)

COSO Implementation: Getting Real, Getting It Right
COSO Implementation: Getting Real, Getting It RightCOSO Implementation: Getting Real, Getting It Right
COSO Implementation: Getting Real, Getting It Right
 
ERM and Internal Auditing 2016 Tea Talk v2a
ERM and Internal Auditing 2016 Tea Talk v2aERM and Internal Auditing 2016 Tea Talk v2a
ERM and Internal Auditing 2016 Tea Talk v2a
 
Upgrading Risk Management and Internal Control in Your Organization
Upgrading Risk Management and Internal Control in Your OrganizationUpgrading Risk Management and Internal Control in Your Organization
Upgrading Risk Management and Internal Control in Your Organization
 
Internal Control & Risk Management Framework
Internal Control & Risk Management FrameworkInternal Control & Risk Management Framework
Internal Control & Risk Management Framework
 
What is Cobit
What is CobitWhat is Cobit
What is Cobit
 
Internal Control
Internal ControlInternal Control
Internal Control
 
Enterprise risk management
Enterprise risk managementEnterprise risk management
Enterprise risk management
 
Risk management and internal control simplified powerpoint
Risk management and internal control simplified powerpointRisk management and internal control simplified powerpoint
Risk management and internal control simplified powerpoint
 
CPA Canada Risk Oversight and Governance Board Role in Risk
CPA Canada Risk Oversight and Governance Board Role in RiskCPA Canada Risk Oversight and Governance Board Role in Risk
CPA Canada Risk Oversight and Governance Board Role in Risk
 
Sarbanes Oxleys Impact On The Coso Cube
Sarbanes Oxleys Impact On The Coso CubeSarbanes Oxleys Impact On The Coso Cube
Sarbanes Oxleys Impact On The Coso Cube
 
Pursuing Global Alignment of Risk Management Guidelines
Pursuing Global Alignment of Risk Management GuidelinesPursuing Global Alignment of Risk Management Guidelines
Pursuing Global Alignment of Risk Management Guidelines
 
Exploring Common Paths in Risk Management by Jan Mattingly
Exploring Common Paths in Risk Management by Jan MattinglyExploring Common Paths in Risk Management by Jan Mattingly
Exploring Common Paths in Risk Management by Jan Mattingly
 
Applying an Effective Control Environment to Integrated Reporting Through COS...
Applying an Effective Control Environment to Integrated Reporting Through COS...Applying an Effective Control Environment to Integrated Reporting Through COS...
Applying an Effective Control Environment to Integrated Reporting Through COS...
 
What is RIMS Doing?
What is RIMS Doing?What is RIMS Doing?
What is RIMS Doing?
 
RMIC - It's What We Do
RMIC - It's What We DoRMIC - It's What We Do
RMIC - It's What We Do
 
COSO Update DTF
COSO Update DTFCOSO Update DTF
COSO Update DTF
 
Đánh giá lựa chọn dự án đầu tư kinh doanh
Đánh giá lựa chọn dự án đầu tư kinh doanhĐánh giá lựa chọn dự án đầu tư kinh doanh
Đánh giá lựa chọn dự án đầu tư kinh doanh
 

Similar to Recent COSO Internal Control and Risk Management Developments

Introduction to COSO 2013 - Corporate Compliance Seminars
Introduction to COSO 2013 - Corporate Compliance SeminarsIntroduction to COSO 2013 - Corporate Compliance Seminars
Introduction to COSO 2013 - Corporate Compliance SeminarsCorporate Compliance Seminars
 
COSO_2013_Framework_on_Internal_Control.pdf
COSO_2013_Framework_on_Internal_Control.pdfCOSO_2013_Framework_on_Internal_Control.pdf
COSO_2013_Framework_on_Internal_Control.pdfAliehaDhea
 
COSO 2013: What you need to know
COSO 2013: What you need to knowCOSO 2013: What you need to know
COSO 2013: What you need to knowjennyhollingworth
 
dt_mt_SREP_Pub_Transformation
dt_mt_SREP_Pub_Transformationdt_mt_SREP_Pub_Transformation
dt_mt_SREP_Pub_TransformationMark Micallef
 
Auditing corporate governance guide
Auditing corporate governance guideAuditing corporate governance guide
Auditing corporate governance guideCenapSerdarolu
 
New trends in the revised iso 9001:2015
New trends in the revised iso 9001:2015New trends in the revised iso 9001:2015
New trends in the revised iso 9001:2015PMILebanonChapter
 
COSO Deep Dive - Using BlackLine to Manage Your COSO Framework
COSO Deep Dive - Using BlackLine to Manage Your COSO FrameworkCOSO Deep Dive - Using BlackLine to Manage Your COSO Framework
COSO Deep Dive - Using BlackLine to Manage Your COSO FrameworkBlackLine
 
Auditing corporate governance guide
Auditing corporate governance guideAuditing corporate governance guide
Auditing corporate governance guideAstalapulosListestos
 
UNCCInternalControls.pptx
UNCCInternalControls.pptxUNCCInternalControls.pptx
UNCCInternalControls.pptxAral20101
 
Internal Financial Controls
Internal Financial ControlsInternal Financial Controls
Internal Financial Controlstarunmallappa
 
El-Paso SOX TestingTraining- June 2007
El-Paso SOX TestingTraining- June 2007El-Paso SOX TestingTraining- June 2007
El-Paso SOX TestingTraining- June 2007Danial Khan
 
Top 5 Pitfalls to Avoid Implemeting COSO 2013
Top 5 Pitfalls to Avoid Implemeting COSO 2013Top 5 Pitfalls to Avoid Implemeting COSO 2013
Top 5 Pitfalls to Avoid Implemeting COSO 2013Aviva Spectrum™
 
Richardson_AIS3e_CH13_PowerPoint.pptx
Richardson_AIS3e_CH13_PowerPoint.pptxRichardson_AIS3e_CH13_PowerPoint.pptx
Richardson_AIS3e_CH13_PowerPoint.pptxMohamedElmahgoub2
 
Intro to management_and_auditing_of_info_systs
Intro to management_and_auditing_of_info_systsIntro to management_and_auditing_of_info_systs
Intro to management_and_auditing_of_info_systsjakodongo
 
Coso internal control frameword executive summary_2013
Coso internal control frameword executive summary_2013Coso internal control frameword executive summary_2013
Coso internal control frameword executive summary_2013SARVJEET KAUSHAL
 
990025 p executive-summary-final-may20
990025 p executive-summary-final-may20990025 p executive-summary-final-may20
990025 p executive-summary-final-may20Thoriq Rivaldi
 

Similar to Recent COSO Internal Control and Risk Management Developments (20)

Introduction to COSO 2013 - Corporate Compliance Seminars
Introduction to COSO 2013 - Corporate Compliance SeminarsIntroduction to COSO 2013 - Corporate Compliance Seminars
Introduction to COSO 2013 - Corporate Compliance Seminars
 
COSO_2013_Framework_on_Internal_Control.pdf
COSO_2013_Framework_on_Internal_Control.pdfCOSO_2013_Framework_on_Internal_Control.pdf
COSO_2013_Framework_on_Internal_Control.pdf
 
COSO Deck
COSO DeckCOSO Deck
COSO Deck
 
COSO.pptx
COSO.pptxCOSO.pptx
COSO.pptx
 
COSO 2013: What you need to know
COSO 2013: What you need to knowCOSO 2013: What you need to know
COSO 2013: What you need to know
 
dt_mt_SREP_Pub_Transformation
dt_mt_SREP_Pub_Transformationdt_mt_SREP_Pub_Transformation
dt_mt_SREP_Pub_Transformation
 
Auditing corporate governance guide
Auditing corporate governance guideAuditing corporate governance guide
Auditing corporate governance guide
 
New trends in the revised iso 9001:2015
New trends in the revised iso 9001:2015New trends in the revised iso 9001:2015
New trends in the revised iso 9001:2015
 
COSO Deep Dive - Using BlackLine to Manage Your COSO Framework
COSO Deep Dive - Using BlackLine to Manage Your COSO FrameworkCOSO Deep Dive - Using BlackLine to Manage Your COSO Framework
COSO Deep Dive - Using BlackLine to Manage Your COSO Framework
 
Auditing corporate governance guide
Auditing corporate governance guideAuditing corporate governance guide
Auditing corporate governance guide
 
UNCCInternalControls.pptx
UNCCInternalControls.pptxUNCCInternalControls.pptx
UNCCInternalControls.pptx
 
Internal Financial Controls
Internal Financial ControlsInternal Financial Controls
Internal Financial Controls
 
El-Paso SOX TestingTraining- June 2007
El-Paso SOX TestingTraining- June 2007El-Paso SOX TestingTraining- June 2007
El-Paso SOX TestingTraining- June 2007
 
Sppt chap004
Sppt chap004Sppt chap004
Sppt chap004
 
Top 5 Pitfalls to Avoid Implemeting COSO 2013
Top 5 Pitfalls to Avoid Implemeting COSO 2013Top 5 Pitfalls to Avoid Implemeting COSO 2013
Top 5 Pitfalls to Avoid Implemeting COSO 2013
 
Updated CVnew3
Updated CVnew3Updated CVnew3
Updated CVnew3
 
Richardson_AIS3e_CH13_PowerPoint.pptx
Richardson_AIS3e_CH13_PowerPoint.pptxRichardson_AIS3e_CH13_PowerPoint.pptx
Richardson_AIS3e_CH13_PowerPoint.pptx
 
Intro to management_and_auditing_of_info_systs
Intro to management_and_auditing_of_info_systsIntro to management_and_auditing_of_info_systs
Intro to management_and_auditing_of_info_systs
 
Coso internal control frameword executive summary_2013
Coso internal control frameword executive summary_2013Coso internal control frameword executive summary_2013
Coso internal control frameword executive summary_2013
 
990025 p executive-summary-final-may20
990025 p executive-summary-final-may20990025 p executive-summary-final-may20
990025 p executive-summary-final-may20
 

More from International Federation of Accountants

Otros pronunciamientos: Información financiera según la base contable de efec...
Otros pronunciamientos: Información financiera según la base contable de efec...Otros pronunciamientos: Información financiera según la base contable de efec...
Otros pronunciamientos: Información financiera según la base contable de efec...International Federation of Accountants
 
Presentación de los Estados Financieros Estados de situación financiera, rend...
Presentación de los Estados Financieros Estados de situación financiera, rend...Presentación de los Estados Financieros Estados de situación financiera, rend...
Presentación de los Estados Financieros Estados de situación financiera, rend...International Federation of Accountants
 

More from International Federation of Accountants (20)

Closing Remarks International Women's Day 2024
Closing Remarks International Women's Day 2024Closing Remarks International Women's Day 2024
Closing Remarks International Women's Day 2024
 
IFAC Principios revisados de Gobierno Corporativo del G20 y de la OCDE
IFAC Principios revisados de Gobierno Corporativo del G20 y de la OCDEIFAC Principios revisados de Gobierno Corporativo del G20 y de la OCDE
IFAC Principios revisados de Gobierno Corporativo del G20 y de la OCDE
 
IFAC Presentación IGEP sobre OCDE-G20, Febrero 2024
IFAC Presentación IGEP sobre OCDE-G20, Febrero 2024IFAC Presentación IGEP sobre OCDE-G20, Febrero 2024
IFAC Presentación IGEP sobre OCDE-G20, Febrero 2024
 
Preparing for High Quality Sustainability assurance Engagements
Preparing for High Quality Sustainability assurance EngagementsPreparing for High Quality Sustainability assurance Engagements
Preparing for High Quality Sustainability assurance Engagements
 
Otros pronunciamientos: Información financiera según la base contable de efec...
Otros pronunciamientos: Información financiera según la base contable de efec...Otros pronunciamientos: Información financiera según la base contable de efec...
Otros pronunciamientos: Información financiera según la base contable de efec...
 
Otros pronunciamientos: Guías de Prácticas Recomendadas
Otros pronunciamientos: Guías de Prácticas RecomendadasOtros pronunciamientos: Guías de Prácticas Recomendadas
Otros pronunciamientos: Guías de Prácticas Recomendadas
 
Otros pronunciamientos: Marco conceptual
Otros pronunciamientos: Marco conceptualOtros pronunciamientos: Marco conceptual
Otros pronunciamientos: Marco conceptual
 
Adopción por primera vez de las NICSP de base de devengo
Adopción por primera vez de las NICSP de base de devengoAdopción por primera vez de las NICSP de base de devengo
Adopción por primera vez de las NICSP de base de devengo
 
Moneda Extranjera
Moneda ExtranjeraMoneda Extranjera
Moneda Extranjera
 
Presentación de la información presupuestaria
Presentación de la información presupuestariaPresentación de la información presupuestaria
Presentación de la información presupuestaria
 
Revelaciones de partes relacionadas
Revelaciones de partes relacionadasRevelaciones de partes relacionadas
Revelaciones de partes relacionadas
 
Estado de Flujos de Efectivo
Estado de Flujos de EfectivoEstado de Flujos de Efectivo
Estado de Flujos de Efectivo
 
Presentación de los Estados Financieros Estados de situación financiera, rend...
Presentación de los Estados Financieros Estados de situación financiera, rend...Presentación de los Estados Financieros Estados de situación financiera, rend...
Presentación de los Estados Financieros Estados de situación financiera, rend...
 
Combinaciones del sector público
Combinaciones del sector públicoCombinaciones del sector público
Combinaciones del sector público
 
Consolidación
ConsolidaciónConsolidación
Consolidación
 
Instrumentos financieros – Revelaciones
Instrumentos financieros – RevelacionesInstrumentos financieros – Revelaciones
Instrumentos financieros – Revelaciones
 
Instrumentos financieros – Cobertura y derivados
Instrumentos financieros – Cobertura y derivadosInstrumentos financieros – Cobertura y derivados
Instrumentos financieros – Cobertura y derivados
 
Instrumentos financieros – Conceptos básicos
Instrumentos financieros –  Conceptos básicos Instrumentos financieros –  Conceptos básicos
Instrumentos financieros – Conceptos básicos
 
Instrumentos financieros – Revelaciones
Instrumentos financieros –  Revelaciones Instrumentos financieros –  Revelaciones
Instrumentos financieros – Revelaciones
 
Instrumentos financieros – Coberturas y derivados
Instrumentos financieros – Coberturas y derivadosInstrumentos financieros – Coberturas y derivados
Instrumentos financieros – Coberturas y derivados
 

Recently uploaded

Go for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptx
Go for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptxGo for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptx
Go for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptxRakhi Bazaar
 
Fordham -How effective decision-making is within the IT department - Analysis...
Fordham -How effective decision-making is within the IT department - Analysis...Fordham -How effective decision-making is within the IT department - Analysis...
Fordham -How effective decision-making is within the IT department - Analysis...Peter Ward
 
Traction part 2 - EOS Model JAX Bridges.
Traction part 2 - EOS Model JAX Bridges.Traction part 2 - EOS Model JAX Bridges.
Traction part 2 - EOS Model JAX Bridges.Anamaria Contreras
 
digital marketing , introduction of digital marketing
digital marketing , introduction of digital marketingdigital marketing , introduction of digital marketing
digital marketing , introduction of digital marketingrajputmeenakshi733
 
Church Building Grants To Assist With New Construction, Additions, And Restor...
Church Building Grants To Assist With New Construction, Additions, And Restor...Church Building Grants To Assist With New Construction, Additions, And Restor...
Church Building Grants To Assist With New Construction, Additions, And Restor...Americas Got Grants
 
How To Simplify Your Scheduling with AI Calendarfly The Hassle-Free Online Bo...
How To Simplify Your Scheduling with AI Calendarfly The Hassle-Free Online Bo...How To Simplify Your Scheduling with AI Calendarfly The Hassle-Free Online Bo...
How To Simplify Your Scheduling with AI Calendarfly The Hassle-Free Online Bo...SOFTTECHHUB
 
The McKinsey 7S Framework: A Holistic Approach to Harmonizing All Parts of th...
The McKinsey 7S Framework: A Holistic Approach to Harmonizing All Parts of th...The McKinsey 7S Framework: A Holistic Approach to Harmonizing All Parts of th...
The McKinsey 7S Framework: A Holistic Approach to Harmonizing All Parts of th...Operational Excellence Consulting
 
1911 Gold Corporate Presentation Apr 2024.pdf
1911 Gold Corporate Presentation Apr 2024.pdf1911 Gold Corporate Presentation Apr 2024.pdf
1911 Gold Corporate Presentation Apr 2024.pdfShaun Heinrichs
 
GUIDELINES ON USEFUL FORMS IN FREIGHT FORWARDING (F) Danny Diep Toh MBA.pdf
GUIDELINES ON USEFUL FORMS IN FREIGHT FORWARDING (F) Danny Diep Toh MBA.pdfGUIDELINES ON USEFUL FORMS IN FREIGHT FORWARDING (F) Danny Diep Toh MBA.pdf
GUIDELINES ON USEFUL FORMS IN FREIGHT FORWARDING (F) Danny Diep Toh MBA.pdfDanny Diep To
 
Intermediate Accounting, Volume 2, 13th Canadian Edition by Donald E. Kieso t...
Intermediate Accounting, Volume 2, 13th Canadian Edition by Donald E. Kieso t...Intermediate Accounting, Volume 2, 13th Canadian Edition by Donald E. Kieso t...
Intermediate Accounting, Volume 2, 13th Canadian Edition by Donald E. Kieso t...ssuserf63bd7
 
WSMM Media and Entertainment Feb_March_Final.pdf
WSMM Media and Entertainment Feb_March_Final.pdfWSMM Media and Entertainment Feb_March_Final.pdf
WSMM Media and Entertainment Feb_March_Final.pdfJamesConcepcion7
 
Jewish Resources in the Family Resource Centre
Jewish Resources in the Family Resource CentreJewish Resources in the Family Resource Centre
Jewish Resources in the Family Resource CentreNZSG
 
Environmental Impact Of Rotary Screw Compressors
Environmental Impact Of Rotary Screw CompressorsEnvironmental Impact Of Rotary Screw Compressors
Environmental Impact Of Rotary Screw Compressorselgieurope
 
Data Analytics Strategy Toolkit and Templates
Data Analytics Strategy Toolkit and TemplatesData Analytics Strategy Toolkit and Templates
Data Analytics Strategy Toolkit and TemplatesAurelien Domont, MBA
 
Cyber Security Training in Office Environment
Cyber Security Training in Office EnvironmentCyber Security Training in Office Environment
Cyber Security Training in Office Environmentelijahj01012
 
WSMM Technology February.March Newsletter_vF.pdf
WSMM Technology February.March Newsletter_vF.pdfWSMM Technology February.March Newsletter_vF.pdf
WSMM Technology February.March Newsletter_vF.pdfJamesConcepcion7
 
20220816-EthicsGrade_Scorecard-JP_Morgan_Chase-Q2-63_57.pdf
20220816-EthicsGrade_Scorecard-JP_Morgan_Chase-Q2-63_57.pdf20220816-EthicsGrade_Scorecard-JP_Morgan_Chase-Q2-63_57.pdf
20220816-EthicsGrade_Scorecard-JP_Morgan_Chase-Q2-63_57.pdfChris Skinner
 
Psychic Reading | Spiritual Guidance – Astro Ganesh Ji
Psychic Reading | Spiritual Guidance – Astro Ganesh JiPsychic Reading | Spiritual Guidance – Astro Ganesh Ji
Psychic Reading | Spiritual Guidance – Astro Ganesh Jiastral oracle
 
Pitch Deck Teardown: Xpanceo's $40M Seed deck
Pitch Deck Teardown: Xpanceo's $40M Seed deckPitch Deck Teardown: Xpanceo's $40M Seed deck
Pitch Deck Teardown: Xpanceo's $40M Seed deckHajeJanKamps
 

Recently uploaded (20)

Go for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptx
Go for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptxGo for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptx
Go for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptx
 
Fordham -How effective decision-making is within the IT department - Analysis...
Fordham -How effective decision-making is within the IT department - Analysis...Fordham -How effective decision-making is within the IT department - Analysis...
Fordham -How effective decision-making is within the IT department - Analysis...
 
Traction part 2 - EOS Model JAX Bridges.
Traction part 2 - EOS Model JAX Bridges.Traction part 2 - EOS Model JAX Bridges.
Traction part 2 - EOS Model JAX Bridges.
 
digital marketing , introduction of digital marketing
digital marketing , introduction of digital marketingdigital marketing , introduction of digital marketing
digital marketing , introduction of digital marketing
 
Church Building Grants To Assist With New Construction, Additions, And Restor...
Church Building Grants To Assist With New Construction, Additions, And Restor...Church Building Grants To Assist With New Construction, Additions, And Restor...
Church Building Grants To Assist With New Construction, Additions, And Restor...
 
The Bizz Quiz-E-Summit-E-Cell-IITPatna.pptx
The Bizz Quiz-E-Summit-E-Cell-IITPatna.pptxThe Bizz Quiz-E-Summit-E-Cell-IITPatna.pptx
The Bizz Quiz-E-Summit-E-Cell-IITPatna.pptx
 
How To Simplify Your Scheduling with AI Calendarfly The Hassle-Free Online Bo...
How To Simplify Your Scheduling with AI Calendarfly The Hassle-Free Online Bo...How To Simplify Your Scheduling with AI Calendarfly The Hassle-Free Online Bo...
How To Simplify Your Scheduling with AI Calendarfly The Hassle-Free Online Bo...
 
The McKinsey 7S Framework: A Holistic Approach to Harmonizing All Parts of th...
The McKinsey 7S Framework: A Holistic Approach to Harmonizing All Parts of th...The McKinsey 7S Framework: A Holistic Approach to Harmonizing All Parts of th...
The McKinsey 7S Framework: A Holistic Approach to Harmonizing All Parts of th...
 
1911 Gold Corporate Presentation Apr 2024.pdf
1911 Gold Corporate Presentation Apr 2024.pdf1911 Gold Corporate Presentation Apr 2024.pdf
1911 Gold Corporate Presentation Apr 2024.pdf
 
GUIDELINES ON USEFUL FORMS IN FREIGHT FORWARDING (F) Danny Diep Toh MBA.pdf
GUIDELINES ON USEFUL FORMS IN FREIGHT FORWARDING (F) Danny Diep Toh MBA.pdfGUIDELINES ON USEFUL FORMS IN FREIGHT FORWARDING (F) Danny Diep Toh MBA.pdf
GUIDELINES ON USEFUL FORMS IN FREIGHT FORWARDING (F) Danny Diep Toh MBA.pdf
 
Intermediate Accounting, Volume 2, 13th Canadian Edition by Donald E. Kieso t...
Intermediate Accounting, Volume 2, 13th Canadian Edition by Donald E. Kieso t...Intermediate Accounting, Volume 2, 13th Canadian Edition by Donald E. Kieso t...
Intermediate Accounting, Volume 2, 13th Canadian Edition by Donald E. Kieso t...
 
WSMM Media and Entertainment Feb_March_Final.pdf
WSMM Media and Entertainment Feb_March_Final.pdfWSMM Media and Entertainment Feb_March_Final.pdf
WSMM Media and Entertainment Feb_March_Final.pdf
 
Jewish Resources in the Family Resource Centre
Jewish Resources in the Family Resource CentreJewish Resources in the Family Resource Centre
Jewish Resources in the Family Resource Centre
 
Environmental Impact Of Rotary Screw Compressors
Environmental Impact Of Rotary Screw CompressorsEnvironmental Impact Of Rotary Screw Compressors
Environmental Impact Of Rotary Screw Compressors
 
Data Analytics Strategy Toolkit and Templates
Data Analytics Strategy Toolkit and TemplatesData Analytics Strategy Toolkit and Templates
Data Analytics Strategy Toolkit and Templates
 
Cyber Security Training in Office Environment
Cyber Security Training in Office EnvironmentCyber Security Training in Office Environment
Cyber Security Training in Office Environment
 
WSMM Technology February.March Newsletter_vF.pdf
WSMM Technology February.March Newsletter_vF.pdfWSMM Technology February.March Newsletter_vF.pdf
WSMM Technology February.March Newsletter_vF.pdf
 
20220816-EthicsGrade_Scorecard-JP_Morgan_Chase-Q2-63_57.pdf
20220816-EthicsGrade_Scorecard-JP_Morgan_Chase-Q2-63_57.pdf20220816-EthicsGrade_Scorecard-JP_Morgan_Chase-Q2-63_57.pdf
20220816-EthicsGrade_Scorecard-JP_Morgan_Chase-Q2-63_57.pdf
 
Psychic Reading | Spiritual Guidance – Astro Ganesh Ji
Psychic Reading | Spiritual Guidance – Astro Ganesh JiPsychic Reading | Spiritual Guidance – Astro Ganesh Ji
Psychic Reading | Spiritual Guidance – Astro Ganesh Ji
 
Pitch Deck Teardown: Xpanceo's $40M Seed deck
Pitch Deck Teardown: Xpanceo's $40M Seed deckPitch Deck Teardown: Xpanceo's $40M Seed deck
Pitch Deck Teardown: Xpanceo's $40M Seed deck
 

Recent COSO Internal Control and Risk Management Developments

  • 1. Recent COSO Internal Control and Risk Management Developments IFAC and ISO Panel Discussion September 24, 2013 David L. Landsittel Former Chair - COSO
  • 2. About COSO • Formed in 1985 to sponsor a group to make recommendations on Fraudulent Financial Reporting • A joint initiative of five private sector organizations: ▫ American Accounting Association (AAA) ▫ American Institute of Certified Public Accountants (AICPA) ▫ Financial Executives International (FEI) ▫ Institute of Management Accountants (IMA) ▫ The Institute of Internal Auditors (IIA)
  • 3. Mission COSO’s Mission is “To provide thought leadership through the development of comprehensive frameworks and guidance on enterprise risk management, internal control and fraud deterrence designed to improve organizational performance and governance and to reduce the extent of fraud in organizations.” COSO’s Fundamental Principle Good risk management and internal control are necessary for long term success of all organizations
  • 4. COSO’s Three Areas of Focus 1. Internal Control 2. Enterprise Risk Management 3. Fraud Deterrence
  • 5. Timeline 2010: Fraud Study II Fraudulent Financial Reporting: 1998-2007 2004: Enterprise Risk Management Framework 1987: Treadway Commission Report 2009: Guidance on Monitoring Internal Control Systems 1996: Internal Control Issues in Derivatives 1985 1990 1995 2000 1999: Fraud Study I Fraudulent Financial Reporting: 1987-1997 1992: Internal Control – Integrated Framework 2005 2006: Guidance for Smaller Businesses on Internal Control over Financial Reporting 2010 2010-2013: Recent ERM thought papers on current issues
  • 6. COSO Internal Control Framework • First published in 1992 • Gained wide acceptance following financial control failures of early 2000’s • Most widely used framework in the US • Also widely used around the world – translated into 7 languages
  • 7. Why Update What Works? ICIF Works Well Today COSO’s Internal Control–Integrated Framework (1992 Edition) Enhancements ICIF Will Work Better Tomorrow Reflect changes in to facilitate effective business & operating internal control Update Objectives Articulate principles environments Clarifies Requirements Updates Context Expand operations and reporting objectives Broadens Application COSO’s Internal Control–Integrated Framework (2013 Edition)
  • 8. Project Plan & Timetable Assess & Survey Stakeholders 2010 Design & Build 2011 Public Exposure & Assess 2012 Finalize 2013
  • 9. Project Participants COSO Board of Directors PwC Author and Project Leader COSO Advisory Council Stakeholder Input • • • • • • • • •Survey of over 700 stakeholders and users of the 1992 Internal Control – Integrated Framework AICPA AAA FEI IIA IMA Public Accounting Firms Regulatory observers Others (IFAC, ISACA, others) •Public Exposures of updated Framework draft and supporting documents •Webcasts, round tables, direct correspondence via icif@us.pwc.com et al
  • 10. Summary of Updates … What is not changing... What is changing... 1. Definition of internal control 1. Updated to reflect the current business environment 2. Five components of internal control 3. The fundamental criteria used to assess effectiveness of systems of internal control 4. Use of judgment in designing and implementing controls and in evaluating the effectiveness of systems of internal control 2. Formalized fundamental concepts underlying the five components as principles 3. Expanded financial reporting objective to address internal and external, financial and nonfinancial reporting objectives 4. Increased focus on operations and compliance objectives based on user input
  • 11. 11 Summary of Updates A changing business environment... Expectations for governance oversight Globalization of markets and operations Changes in business models Demands and complexity of rules, regulations and standards Expectations for competencies and accountabilities Use and reliance on evolving technology Expectations for preventing and detecting fraud Drives updates to the Framework...
  • 12. 17 Principles of the Updated ICIF Control Environment Risk Assessment Control Activities Information & Communication Monitoring Activities 1. 2. 3. 4. 5. Demonstrates commitment to integrity and ethical values Exercises oversight responsibility Establishes structure, authority and responsibility Demonstrates commitment to competence Enforces accountability 6. 7. 8. 9. Specifies suitable objectives Identifies and analyzes risk Assesses fraud risk Identifies and analyzes significant change 10. Selects and develops control activities 11. Selects and develops general controls over technology 12. Deploys through policies and procedures 13. Uses relevant information 14. Communicates internally 15. Communicates externally 16. Conducts ongoing and/or separate evaluations 17. Evaluates and communicates deficiencies
  • 13. Update Articulates Principles of Effective Internal Control Control Environment 1. The organization demonstrates a commitment to integrity and ethical values. 2. The board of directors demonstrates independence from management and exercises oversight of the development and performance of internal control. 3. Management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities in the pursuit of objectives. 4. The organization demonstrates a commitment to attract, develop, and retain competent individuals in alignment with objectives. 5. The organization holds individuals accountable for their internal control responsibilities in the pursuit of objectives.
  • 14. Project Deliverables: Internal ControlIntegrated Framework • Consists of three volumes: ▫ Executive Summary ▫ Framework and Appendices ▫ Illustrative Tools: Assessing Effectiveness of a System of Internal Control • Sets out: ▫ Definition of internal control ▫ Categories of objectives ▫ Components of internal control ▫ and related principles and points of focus Requirements for Effectiveness
  • 15. Project Deliverables: Internal Control over External Financial Reporting: A Compendium • Provides approaches and Examples illustrating how principles are applied in preparing financial statements for external purposes • Is relevant for variety of entities – public, private, notfor-profit, and government • Is consistent with and does not modify the updated Framework
  • 16. The ERM Framework • Published in 2004 • Based upon a framework with similarities to the COSO 92 framework • Widely recognized, but not as widely adopted as COSO 92 • Implementation not as robust as COSO 92
  • 17. Some Current ERM Challenges • Uneven support to adopt any formal risk management process • Less than robust ERM implementation • Difficulty “getting started” with ERM implementation • Difficulty aligning ERM with top management view • Inadequate board oversight of risk management – and regulatory pressure mounting for better oversight • Immature development of risk appetite • Failure to consider low likelihood but high impact risks – overconfidence
  • 18. 18 COSO ERM Response Our objective – to assist stakeholders in moving up “maturity curve” of an effective ERM process Publication of a series of thought papers
  • 19. 19 COSO ERM “Thought Papers” • Four Papers issued in 2009 surveying ERM practices – and particularly practices and recommendations related to board of director oversight • Four Papers in 2011 and 2012 focusing on difficult ERM process implementation issues: ▫ “Getting Started” ▫ Developing Key Risk Indicators ▫ Understanding and Communicating Risk Appetite ▫ Risk Assessment Practices • Two Papers in 2012-2013 dealing with applying ERM to current Management issues: ▫ “Cloud” Computing Risks ▫ Sustainability Risks • A Behavioral Paper in 2012 dealing with Judgment Biases
  • 20. Questions or Comments? Thank You! David Landsittel www.coso.org