




版權說明:本文檔由用戶提供并上傳,收益歸屬內容提供方,若內容存在侵權,請進行舉報或認領
文檔簡介
COSOCOSO2013PAGE10頁InternalControl–IntegratedExecutiveSummaryInternalcontrolhelpsentitiesachieveimportantobjectivesandsustainandimproveperformance.COSO’sInternalControl—IntegratedFramework(Framework)enablesorganizationstoeffectivelyandefficientlydevelopsystemsofinternalcontrolthatadapttochangingbusinessandoperatingenvironments,mitigateriskstoacceptablelevels,andsupportsounddecisionmakingandgovernanceoftheorganization.Designingandimplementinganeffectivesystemofinternalcontrolcanbechallenging;operatingthatsystemeffectivelyandefficientlyeverydaycanbedaunting.Newandrapidlychangingbusinessmodels,greateruseanddependenceontechnology,increasingregulatoryrequirementsandscrutiny,globalization,andotherchallengesdemandanysystemofinternalcontroltobeagileinadaptingtochangesinbusiness,operatingandregulatoryAneffectivesystemofinternalcontroldemandsmorethanrigorousadherencetopoliciesandprocedures:itrequirestheuseofjudgment.Managementandboardsofdirectors1usejudgmenttodeterminehowmuchcontrolisenough.Managementandotherpersonnelusejudgmenteverydaytoselect,develop,anddeploycontrolsacrosstheentity.Managementandinternalauditors,amongotherpersonnel,applyjudgmentastheymonitorandassesstheeffectivenessofthesystemofinternalcontrol.1TheFrameworkusestheterm“boardofdirectors,”whichencompassesthegoverningbody,includingboard,boardoftrustees,generalpartners,owner,orsupervisoryboard.TheFrameworkassistsmanagement,boardsofdirectors,externalstakeholders,andothersinteractingwiththeentityintheirrespectivedutiesregardinginternalcontrolwithoutbeingoverlyprescriptive.Itdoessobyprovidingbothunderstandingofwhatconstitutesasystemofinternalcontrolandinsightintowheninternalcontrolisbeingappliedeffectively.Formanagementandboardsofdirectors,theFrameworkAmeanstoapplyinternalcontroltoanytypeofentity,regardlessofindustryorlegalstructure,atthelevelsofentity,operatingunit,orfunctionAprinciples-basedapproachthatprovidesflexibilityandallowsforjudgmentindesigning,implementing,andconductinginternalcontrol—principlesthatcanbeappliedattheentity,operating,andfunctionallevelsRequirementsforaneffectivesystemofinternalcontrolbyconsideringhowcomponentsandprinciplesarepresentandfunctioningandhowcomponentsoperatetogetherAmeanstoidentifyandanalyzerisks,andtodevelopandmanageappropriateresponsestoriskswithinacceptablelevelsandwithagreaterfocusonanti-fraudmeasuresAnopportunitytoexpandtheapplicationofinternalcontrolbeyondfinancialreportingtootherformsofreporting,operations,andcomplianceAnopportunitytoeliminateineffective,redundant,orinefficientcontrolsthatprovideminimalvalueinreducingriskstotheachievementoftheentity’sobjectivesForexternalstakeholdersofanentityandothersthatinteractwiththeentity,applicationofthisFrameworkprovides:Greaterconfidenceintheboardofdirectors’oversightofinternalcontrolGreaterconfidenceregardingtheachievementofentityGreaterconfidenceintheorganization’sabilitytoidentify,analyze,andrespondtoriskandchangesinthebusinessandoperatingenvironmentsGreaterunderstandingoftherequirementofaneffectivesystemofinternalcontrolGreaterunderstandingthatthroughtheuseofjudgment,maybeabletoeliminateineffective,redundant,orinefficientInternalcontrolisnotaserialprocessbutadynamicandintegratedprocess.TheFrameworkappliestoallentities:large,mid-size,small,for-profitandnot-for-profit,andgovernmentbodies.However,eachorganizationmaychoosetoimplementinternalcontroldifferently.Forinstance,asmallerentity’ssystemofinternalcontrolmaybelessformalandlessstructured,yetstillhaveeffectiveinternalcontrol.TheremainderofthisExecutiveSummaryprovidesanoverviewofinternalcontrol,includingadefinition,categoriesofobjective,descriptionoftherequisitecomponentsandassociatedprinciples,andrequirementofaneffectivesystemofinternalcontrol.Italsoincludesadiscussionoflimitations—thereasonswhynosystemofinternalcontrolcanbeperfect.Finally,itoffersconsiderationsonhowvariouspartiesmayusethe本文也將討論內部控制的局限性——為什么沒有一個內部控制體系是完美的。DefiningInternalInternalcontrolisdefinedasInternalcontrolisaprocess,effectedbyanentity’sboardofdirectors,management,andotherpersonnel,designedtoprovidereasonableassuranceregardingtheachievementofobjectivesrelatingtooperations,reporting,andcompliance.Thisdefinitionreflectscertainfundamentalconcepts.InternalcontrolGearedtotheachievementofobjectivesinoneormorecategories—operations,reporting,andcomplianceAprocessconsistingofongoingtasksandactivities—ameanstoanend,notanendinitselfEffectedbypeople—notmerelyaboutpolicyandproceduremanuals,systems,andforms,butaboutpeopleandtheactionstheytakeateverylevelofanorganizationtoaffectinternalcontrolAbletoprovidereasonableassurance—butnotabsoluteassurance,toentity’sseniormanagementandboardofAdaptabletotheentitystructure—flexibleinapplicationfortheentityorforaparticularsubsidiary,division,operatingunit,orbusinessThisdefinitionisintentionallybroad.Itcapturesimportantconceptsthatarefundamentaltohoworganizationsdesign,implement,andconductinternalcontrol,providingabasisforapplicationacrossorganizationsthatoperateindifferententitystructures,industries,andgeographicregions.TheFrameworkprovidesforthreecategoriesofobjectives,whichalloworganizationstofocusondifferingaspectsofinternalcontrol:OperationsObjectives—Thesepertaintoeffectivenessandefficiencyofentity’soperations,includingoperationalandfinancialperformancegoals,andsafeguardingassetsagainstloss.ReportingObjectives—Thesepertaintointernalandexternalfinancialnon-financialreportingandmayencompassreliability,timeliness,transpar-ency,orothertermsassetforthbyregulators,recognizedstandardsetters,ortheentity’spolicies.ComplianceObjectives—ThesepertaintoadherencetolawsandtowhichtheentityisComponentsofInternalInternalcontrolconsistsoffiveintegratedControlThecontrolenvironmentisthesetofstandards,processes,andstructuresthatprovidethebasisforcarryingoutinternalcontrolacrosstheorganization.Theboardofdirectorsandseniormanagementestablishthetoneatthetopregardingtheimportanceofinternalcontrolincludingexpectedstandardsofconduct.Managementreinforcesexpectationsatthevariouslevelsoftheorganization.Thecontrolenvironmentcomprisestheintegrityandethicalvaluesoftheorganization;theparametersenablingtheboardofdirectorstocarryoutitsgovernanceoversightresponsibilities;theorganizationalstruc-tureandassignmentofauthorityandresponsibility;theprocessforattracting,developing,andretainingcompetentindividuals;andtherigoraroundperformancemeasures,incentives,andrewardstodriveaccountabilityforperformance.Theresultingcontrolenvironmenthasapervasiveimpactontheoverallsystemofinternalcontrol.topEveryentityfacesavarietyofrisksfromexternalandinternalsources.Riskisdefinedasthepossibilitythataneventwilloccurandadverselyaffecttheachievementofobjectives.Riskassessmentinvolvesadynamicanditerativeprocessforidentifyingandassessingriskstotheachievementofobjectives.Riskstotheachievementoftheseobjectivesfromacrosstheentityareconsideredrelativetoestablishedrisktolerances.Thus,riskassessmentformsthebasisfordetermininghowriskswillbemanaged.Apreconditiontoriskassessmentistheestablishmentofobjectives,linkedatdifferentlevelsoftheentity.Managementspecifiesobjectiveswithincategoriesrelatingtooperations,reporting,andcompliancewithsufficientclaritytobeabletoidentifyandanalyzeriskstothoseobjectives.Managementalsoconsidersthesuitabilityoftheobjectivesfortheentity.Riskassessmentalsorequiresmanagementtoconsidertheimpactofpossiblechangesintheexternalenvironmentandwithinitsownbusinessmodelthatmayrenderinternalcontrolineffective.Controlactivitiesaretheactionsestablishedthroughpoliciesandproceduresthathelpensurethatmanagement’sdirectivestomitigateriskstotheachievementofobjectivesarecarriedout.Controlactivitiesareperformedatalllevelsoftheentity,atvariousstageswithinbusinessprocesses,andoverthetechnologyenvironment.Theymaybepreventiveordetectiveinnatureandmayencompassarangeofmanualandautomatedactivitiessuchasauthorizationsandapprovals,verifications,reconciliations,andbusinessperformancereviews.Segregationofdutiesistypicallybuiltintotheselectionanddevelopmentofcontrolactivities.Wheresegregationofdutiesisnotpractical,managementselectsanddevelopsalternativecontrolInformationandInformationisnecessaryfortheentitytocarryoutinternalcontrolresponsibilitiestosupporttheachievementofitsobjectives.Managementobtainsorgeneratesandusesrelevantandqualityinformationfrombothinternalandexternalsourcestosupportthefunctioningofothercomponentsofinternalcontrol.Communicationisthecontinual,iterativeprocessofproviding,sharing,andobtainingnecessaryinformation.Internalcommunicationisthemeansbywhichinformationisdisseminatedthroughouttheorganization,flowingup,down,andacrosstheentity.Itenablespersonneltoreceiveaclearmessagefromseniormanagementthatcontrolresponsibilitiesmustbetakenseriously.Externalcommunicationistwofold:itenablesinboundcommunicationofrelevantexternalinformation,anditprovidesinformationtoexternalpartiesinresponsetorequirementsandexpectations.Ongoingevaluations,separateevaluations,orsomecombinationofthetwoareusedtoascertainwhethereachofthefivecomponentsofinternalcontrol,includingcontrolstoeffecttheprincipleswithineachcomponent,ispresentandfunctioning.Ongoingevaluations,builtintobusinessprocessesatdifferentlevelsoftheentity,providetimelyinformation.Separateevaluations,conductedperiodically,willvaryinscopeandfrequencydependingonassessmentofrisks,effectivenessofongoingevaluations,andothermanagementconsiderations.Findingsareevaluatedagainstcriteriaestablishedbyregulators,recognizedstandard-settingbodiesormanagementandtheboardofdirectors,anddeficienciesarecommunicatedtomanagementandtheboardofdirectorsasappropriate.RelationshipofObjectivesandAdirectrelationshipexistsbetweenobjectives,whicharewhatanentitystrivestoachieve,components,whichrepresentwhatisrequiredtoachievetheobjectives,andtheorganizationalstructureoftheentity(theoperatingunits,legalentities,andother).Therelationshipcanbedepictedintheformofacube. compliance—arerepresentedbythecolumns.ThefivecomponentsarerepresentedbytheAnentity’sorganizationalstructureisrepresentedbythethirdComponentsandTheFrameworksetsoutseventeenprinciplesrepresentingthefundamentalconceptsassociatedwitheachcomponent.Becausetheseprinciplesaredrawndirectlyfromthecomponents,anentitycanachieveeffectiveinternalcontrolbyapplyingallprinciples.Allprinciplesapplytooperations,reporting,andcomplianceobjectives.Theprinciplessupportingthecomponentsofinternalcontrolarelistedbelow.ControlEnvironmentTheorganizationdemonstratesacommitmenttointegrityandethicalTheboardofdirectorsdemonstratesindependencefrommanagementandexercisesoversightofthedevelopmentandperformanceofinternalManagementestablishes,withboardoversight,structures,reportinglines,andappropriateauthoritiesandresponsibilitiesinthepursuitofTheorganizationdemonstratesacommitmenttoattract,develop,andretaincompetentindividualsinalignmentwithobjectives.Theorganizationholdsindividualsaccountablefortheirinternalcontrolresponsibilitiesinthepursuitofobjectives.RiskAssessmentTheorganizationspecifiesobjectiveswithsufficientclaritytoenabletheidentificationandassessmentofrisksrelatingtoobjectives.Theorganizationidentifiesriskstotheachievementofitsobjectivesacrosstheentityandanalyzesrisksasabasisfordetermininghowtherisksshouldbemanaged.Theorganizationconsidersthepotentialforfraudinassessingriskstotheachievementofobjectives.Theorganizationidentifiesandassesseschangesthatcouldsignificantlyimpactthesystemofinternalcontrol.TheorganizationselectsanddevelopscontrolactivitiesthatcontributetothemitigationofriskstotheachievementofobjectivestoacceptableTheorganizationselectsanddevelopsgeneralcontrolactivitiesovertechnologytosupporttheachievementofobjectives.Theorganizationdeployscontrolactivitiesthroughpoliciesthatestablishwhatisexpectedandproceduresthatputpoliciesintoaction.Theorganizationobtainsorgeneratesandusesrelevant,qualityinformationtosupportthefunctioningofinternalcontrol.Theorganizationinternallycommunicatesinformation,includingobjectivesandresponsibilitiesforinternalcontrol,necessarytosupportthefunctioningofinternalcontrol.Theorganizationcommunicateswithexternalpartiesregardingmattersaffectingthefunctioningofinternalcontrol.Theorganizationselects,develops,andperformsongoingand/orseparateevaluationstoascertainwhetherthecomponentsofinternalcontrolarepresentandfunctioning.Theorganizationevaluatesandcommunicatesinternalcontroldeficienciesinatimelymannertothosepartiesresponsiblefortakingcorrectiveaction,includingseniormanagementandtheboardofdirectors,asappropriate.EffectiveInternalTheFrameworksetsforththerequirementsforaneffectivesystemofinternalcontrol.Aneffectivesystemprovidesreasonableassuranceregardingachievementofanentity’sobjectives.Aneffectivesystemofinternalcontrolreduces,toanacceptablelevel,theriskofnotachievinganentityobjectiveandmayrelatetoone,two,orallthreecategoriesofobjectives.Itrequiresthat:Eachofthefivecomponentsandrelevantprinciplesispresentand“Present”referstothedeterminationthatthecomponentsrelevantprinciplesexistinthedesignandimplementationofthesystemofinternalcontroltoachievespecifiedobjectives.“Functioning”referstothedeterminationthatthecomponentsandrelevantprinciplescontinuetoexistintheoperationsandconductofthesystemofinternalcontroltoachievespecifiedobjectives.Thefivecomponentsoperatetogetherinanintegrated“Operatingtogether”referstothedeterminationthatallfivecomponentscollectivelyreduce,toanacceptablelevel,theriskofnotachievinganobjective.Componentsshouldnotbeconsidereddiscretely;instead,theyoperatetogetherasanintegratedsystem.Componentsareinterdependentwithamultitudeofinterrelationshipsandlinkagesamongthem,particularlythemannerinwhichprinciplesinteractwithinandacrosscomponents.Whenamajordeficiencyexistswithrespecttothepresencefunctioningofacomponentorrelevantprinciple,orwithrespecttothecomponentsoperatingtogetherinanintegratedmanner,theorganizationcannotconcludethatithasmettherequirementsforaneffectivesystemofinternalcontrol.Whenasystemofinternalcontrolisdeterminedtobeeffective,seniormanagementandtheboardofdirectorshavereasonableassurance,relativetotheapplicationwithintheentitystructure,thattheAchieveseffectiveandefficientoperationswhenexternaleventsareconsideredunlikelytohaveasignificantimpactontheachievementofobjectivesorwheretheorganizationcanreasonablypredictthenatureandtimingofexternaleventsandmitigatetheimpacttoanacceptableUnderstandstheextenttowhichoperationsaremanagedeffectivelyandefficientlywhenexternaleventsmayhaveasignificantimpactontheachievementofobjectivesorwheretheorganizationcanreasonablypred
溫馨提示
- 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請下載最新的WinRAR軟件解壓。
- 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請聯系上傳者。文件的所有權益歸上傳用戶所有。
- 3. 本站RAR壓縮包中若帶圖紙,網頁內容里面會有圖紙預覽,若沒有圖紙預覽就沒有圖紙。
- 4. 未經權益所有人同意不得將文件中的內容挪作商業或盈利用途。
- 5. 人人文庫網僅提供信息存儲空間,僅對用戶上傳內容的表現方式做保護處理,對用戶上傳分享的文檔內容本身不做任何修改或編輯,并不能對任何下載內容負責。
- 6. 下載文件中如有侵權或不適當內容,請與我們聯系,我們立即糾正。
- 7. 本站不保證下載資源的準確性、安全性和完整性, 同時也不承擔用戶因使用這些下載資源對自己和他人造成任何形式的傷害或損失。
最新文檔
- 家具工廠衛生管理制度
- 家居公司獎罰管理制度
- 醫院資料復印管理制度
- 商品經營人員管理制度
- 醫院陪護業務管理制度
- 嵌入式開發面臨的挑戰試題及答案
- 國企企業年金管理制度
- 完善教師崗位管理制度
- 停車場地安全管理制度
- 數據庫版本控制與管理策略試題及答案
- 浙江百順服裝有限公司年產100萬套服裝及135萬套床上用品生產線項目環境影響報告
- AI 技術在高中歷史教學中的應用實例2
- 交通大數據的應用試題及答案
- 2024年中石油招聘考試真題
- 企業環保與健康安全管理體系的構建與實施
- 《抽水蓄能電站樞紐布置格局比選專題報告編制規程 》征求意見稿
- 廣東省深圳市2025年高三年級第二次調研考試數學試題(含答案)
- 山東省山東名??荚嚶撁?025年高三4月高考模擬考試物理試卷+答案
- 供應商維保管理制度
- 行政事業單位內部控制信息系統建設實施方案
- 山東棗莊科技職業學院棗莊工程技師學院招聘考試真題2024
評論
0/150
提交評論