Audit & Advisory Services is committed to assisting all levels of management and staff in the achievement of UCSF's goals and objectives by striving to provide a positive impact on the efficiency and effectiveness of operations. To that end, the internal controls information provided below covers the basic concepts of internal controls and their application to UCSF, including: Show
Internal controls summary Internal controls summaryInternal control is a process, effected by an entity’s board of directors, management and other personnel, designed to provide reasonable assurance:
Internal controls are intended to prevent errors and irregularities, identify problems and ensure that corrective action is taken. In many cases, process owners within your department perform controls and interact with the control structure on a daily basis, sometimes without even realizing it because controls are built into operations. Control definition reflects certain fundamental concepts:
Internal controls are established to further strengthen:
Internal control structureThe internal control structure is derived from the way management runs an operation or function and is integrated with the management process. Although the components apply to the entire University, small and mid-size departments may implement them differently than large ones do. Together, they are designed to provide reasonable assurance that overall established objectives and goals are met. The internal control structure consists of five inter-related components:
Internal control typesDifferent risks and environments require different controls. The control types described below can be used in combination to mitigate risks to the organization. Preventive and detection controls
Hard vs. soft controls
Manual vs. automated controls
Key vs. secondary controls
To identify the correct control(s) to implement, you must know what risks are present. To know what risks are present, you need to understand what objectives are being sought. Therefore, Objectives → Risks→ Controls. Internal controls in my departmentControl activities within your department may include the following:
Remember, everyone in your department has responsibility for internal controls. Note: The above internal controls definition was developed by the Committee of Sponsoring Organizations of the Treadway Commission (COSO), which is recognized by UCSF Audit & Advisory Services. What are the policies procedures and activities that are part of a control framework designed to ensure that risks are contained within the established risk tolerance?Control processes are the policies, procedures, and activities that are part of a control framework, designed to ensure that risks are contained within the risk tolerances established by the risk management process.
What are the elements of the oversight component of governance?The elements of oversight are (1) the board's responsibilities to stakeholders, (2) the risk management activities of senior management and the board, and (3) internal and external assurance activities.
Who is ultimately responsible for determining the objectives for an internal audit engagement met?Who is ultimately responsible for determining that the objectives for an internal audit engagement have been met? a. The individual internal audit staff member.
Which of the following activities best describes the term operational audit?Which of the following best describes the operational audit? It concentrates on seeking aspects of operations in which waste could be reduced by the introduction of controls.
|