300 likes | 1.07k Views
Risk Assessment and Internal Controls Anna Tomassacci Beth Ferracane Brendan McClune Objectives Complete a basic risk assessment. Set up a system of internal controls to mitigate the risks identified during the assessment.
E N D
Risk Assessment and Internal Controls Anna Tomassacci Beth FerracaneBrendan McClune
Objectives • Complete a basic risk assessment. • Set up a system of internal controls to mitigate the risks identified during the assessment. • Apply internal controls to potentially deter negative events (e.g., fraud, inappropriate procurements, improper payments, etc.). Office of Operations 2009 Fall Conference
Agenda • Internal Controls Overview • Group Exercises: • Global Risk Assessment for Procurement and Accounts Payable departments • Identify objectives and risks • Design control activities • Risk Assessment – Program Areas • Rank risks by impact and likelihood assuming there are no controls • Rank risks by impact and likelihood given existing controls • Attack and Defend Exercises Office of Operations 2009 Fall Conference
Internal Controls History • NYS Governmental Accountability, Audit & Internal Control Act of 1987 • Budget Bulletin 350 • Committee of Sponsoring Organizations of the Treadway Commission (COSO) Office of Operations 2009 Fall Conference
Internal Control The integration of the activities, plans, attitudes, policies, and efforts of the people of an organization working together to provide reasonable assurance that the organization will achieve its mission. Office of Operations 2009 Fall Conference
Basic Components • Control Environment • Risk Assessment • Control Activities • Information & Communication • Monitoring Office of Operations 2009 Fall Conference
Internal Controls Pyramid Monitoring Control Activities Risk Assessment Information & Communication Information& Communication ControlEnvironment Office of Operations 2009 Fall Conference
Control Environment Influences all of the decisions and activities of an organization, and on the control consciousness of its people The Tone at theTop The foundation for all the other components Office of Operations 2009 Fall Conference
Risk Assessment The possibility that an event will occur and adverselyaffect the achievement of objectives. To evaluate; to examine carefully; to determine or set the value of something. Office of Operations 2009 Fall Conference
Control Activities The tools – both manual and automated – that help prevent or reduce the risks that can stop an organization from meeting its objectives and goals. Office of Operations 2009 Fall Conference
Information & Communication The exchange of information between and among people and organizations. Office of Operations 2009 Fall Conference
Monitoring The ongoing review of the organization's daily activities and transactions to determine whether controls are effective in ensuring that operations work as intended. Office of Operations 2009 Fall Conference
The possibility that an event will occur and adverselyaffect the achievement of objectives. To evaluate; to examine carefully; to determine or set the value of something. Risk Assessment Office of Operations 2009 Fall Conference
Process • What are the objectives? • What could go wrong (the Risk)? • What’s the likelihood of it occurring? • What’s the impact if it happens? • Prioritize and respond accordingly. Office of Operations 2009 Fall Conference
Risk Assessment Assess each risk in terms of: • The likelihood of the negative event. • The significance or impact of the event. Office of Operations 2009 Fall Conference
Likelihood The probability that an unfavorable event would occur if there were: No internal controls. Existing internal controls. Impact A measure of the magnitude of the effect on an organization if the unfavorable event were to occur Risk Assessment Office of Operations 2009 Fall Conference
Ask the questions … • What obstacles could stand in the way of achieving your objective? • What can go wrong? • What is the worst thing that could happen? • What is the worst thing that has happened? Office of Operations 2009 Fall Conference
Ask the questions … • Are there new processes? Changed ones? • New goals or legislation? • Staffing changes? • What keeps you awake at night? Office of Operations 2009 Fall Conference
Evaluating Risk HIGH Area IV Most Concern Area II Minimal Concern LIKELIHOOD Judgment Required Area I Least Concern Area III Moderate Concern LOW LOW IMPACT HIGH Office of Operations 2009 Fall Conference
Helpful Hints • Change is the one constant. • A risk assessment is never “done.” • Communication and education can make all the difference. • The greatest risk is turning a blind eye to the possibility of risk. • Knowledge is power! Office of Operations 2009 Fall Conference
Managing Risk Three options: • Avoid the risk • Accept it • Prevent it Office of Operations 2009 Fall Conference
Managing Risk Avoid the risk: Whatever the risky activity is… Don’t do it! No additional controls are required Office of Operations 2009 Fall Conference
Managing Risk Accept the risk: Continue the way you’re going Maintain the Status Quo No changes, no new controls Office of Operations 2009 Fall Conference
Managing Risk Prevent or reduce the risk: Actively work to control the risk Change how you operate! Establish whatever controls are necessary to manage the risk Office of Operations 2009 Fall Conference
Control Activities The tools – both manual and automated – that help prevent or reduce the risks that can stop an organization from meeting its objectives and goals. Office of Operations 2009 Fall Conference
Control Activities Controls can be… • Directive:guide an organization toward desired outcome. • Preventive:deter the occurrence of an undesirable event. • Detective:identify undesirable events and alert management. Office of Operations 2009 Fall Conference
Commonly Used Control Activities • Documentation • Approval and Authorization • Verification • Supervision • Separation of Duties • Safeguarding Assets Office of Operations 2009 Fall Conference
Risk & Controls HIGH Area IV Most Concern Area II Minimal Concern LIKELIHOOD Judgment Required Area I Least Concern Area III Moderate Concern LOW LOW IMPACT HIGH Office of Operations 2009 Fall Conference
Control Activities Cost v. Benefit The cost of the controls shouldn’t be greater than the cost of the potential loss. Office of Operations 2009 Fall Conference
Questions Office of Operations 2009 Fall Conference