© Copyright Hari Iyer. Page 1 of 3
Background
Control Self-Assessment (CSA) is a technique that was originally developed by Gulf Canada
in 1987. In March 2000, the European Commission approved a white paper on CSA. In the
United States when the Sarbanes-Oxley Act was implemented in 2007, section 404 of the Act
required the companies to perform a top down risk assessment which necessitated CSA. In
the United Kingdom in 2011 the Financial Services Authority (now Financial Conduct
Authority) recognised in its recommendations for the improvement of operational risk
management that the assessment of risks through a control self-assessment may be an
important means of identifying risks. Today, a wide range of entities including private sector
companies, voluntary sector (charities) and the public sector entities use CSA to assess the
effectiveness of their risk management and control processes.
The Institute of Internal Auditors run courses, seminars and offer Certification in Control Self-
Assessment (CCSA).
The Information Systems Audit and Control Association
(ISACA) created a framework called COBIT (Control
Objectives for Information and Related Technology). Control
Self-Assessment is contained within COBIT’s Control
Objective ME2.4.
What is Control Self-Assessment
CSA is a management technique that can be used to assure key stakeholders, both internal
and external, that a company’s internal controls system is reliable. CSA allows managers and
work teams directly involved in the business units, functions or processes to participate in
assessing the company's risk management and control processes. CSA can cover objectives,
risks, controls and processes.
CSA is a sustainable process whereby management validates the operating effectiveness of
its internal controls via testing. Each process owner and functional control owner within a
company performs effectiveness testing to verify that the key controls are operating effectively.
Control
Self-Assessment
© Copyright Hari Iyer. Page 2 of 3
Each process owner develops test scripts for each key control and engages their team to
perform the given tests throughout the year. This allows management to verify that these
controls are working effectively. A CSA program expands the role of operations management
from merely assessing the design of its internal controls to testing and validating the
effectiveness of its internal controls throughout the year.
Benefits of a CSA Program
An effective CSA program can deliver a number of benefits including:
 Creation of clear line of accountability for internal controls;
 Minimising the risk of fraud;
 Creation of an improved controls environment resulting in a lower risk profile for the
company ;
 Sustainability of management’s compliance program;
 Reduction in regulatory compliance costs
CSA Program
The first step in any CSA program is to document the company's control processes with the
aim of identifying suitable ways of measuring or testing each control. The actual testing of the
controls is performed by staff whose day-to-day role is within the area of the company that is
being evaluated as they have the greatest knowledge of how the processes operate. The
common techniques for performing the evaluations are:
 Internal Control Questionnaire (ICQ) or Customised Survey Questionnaires
 Interview Techniques
 Control model Workshops or Interactive Workshops
Some companies choose a combination of methodologies that suits their operations to
implement an effective CSA program. On completion of the assessment each control may be
rated based on the responses received to determine the probability of its failure and the impact
if a failure occurred. These ratings can be summarised to produce a risk matrix showing
potential areas of vulnerability.
In any CSA program, the key steps are to define the nature and extent of the company’s CSA
program, roll out the program, perform the first round of testing and review, and then
incorporate lessons learned before going through the process again.
© Copyright Hari Iyer. Page 3 of 3
Hadigy Limited is a private limited company incorporated in England with registered number 07010656. Hadigy is a Practice Assurance scheme member of
the Chartered Institute of Public Finance and Accountancy (CIPFA). Hadigy is a member of the Federation of Small Business. This publication has been prepared
for general guidance on matters of interest only, and does not constitute professional advice. You should not act upon the information contained in this publication
without obtaining specific professional advice. No representation or warranty (express or implied) is given as to the accuracy, validity or completeness of the
information contained in this publication, and, to the extent permitted by law, Hadigy Limited, its employees and agents do not accept or assume any liability,
responsibility or duty of care for any consequences of you or anyone else acting, or refraining to act, in reliance on the information contained in this publication
or for any decision based on it.
Your Trusted Business Partner
www.hadigy.com
For details please contact: info@hadigy.com
17 Clareville Street, South Kensington, London SW7 5AJ
Conclusion
Entities have different drivers for wanting to enhance internal controls environment e.g.
regulatory requirements, change in ownership, change in senior management, implementation
of a major ERP system or simply wanting stronger internal controls to improve efficiency.
Whatever the driver is, implementing a CSA program should be considered. By implementing
an effective CSA program, the entity can embed internal control accountability deep into the
company, ensure the sustainability of the internal controls compliance efforts, and ultimately
reduce the cost of overall compliance efforts. In other words, an effective CSA program will
drive a much improved internal control environment, giving assurance to all key stakeholders,
internal and external alike, that the company’s controls are operating effectively.
Author - Hari Iyer MBA, FCPA (Australia), CISA, Chartered FCSI
Hari is the founding partner of Hadigy Limited, a management consultancy firm in London.
Hari has over 25 years of financial and IT auditing experience gained partly with the Big 4
professional accountancy firms (EY, Deloitte & PwC) in the UK. This includes audit assurance
reviews, SAP project assurance, business process reviews, IT audits, financial audits,
business continuity management, and SAP governance, risk and compliance (GRC)
implementation & reviews.

More Related Content

PPTX
Control self assessment (csa)
PPS
Control Self Assessment
PPT
Internal Audit COSO Framework
PPT
Coso Monitoring - Templates
PPTX
internal control and control self assessment
PDF
Coso illustrative tool
PDF
Internal control and Control Self Assessment
PPTX
Internal Financial Controls
Control self assessment (csa)
Control Self Assessment
Internal Audit COSO Framework
Coso Monitoring - Templates
internal control and control self assessment
Coso illustrative tool
Internal control and Control Self Assessment
Internal Financial Controls

What's hot (20)

PDF
Risk based internal auditing
PDF
IT Control Objectives for SOX
PPTX
Internal Audit
PPTX
Internal financial control
PDF
Model i best practice evaluation worksheet for ia
PPTX
Practical approach to Risk Based Internal Audit
PPT
Internal Financial Controls (IFC) / Internal Control over Financial Reporting...
PPTX
Performance audit adding value
PPTX
The role of internal audit department
PDF
Enterprise Risk Management - Aligning Risk with Strategy and Performance
PPSX
Minicurso de Controles Internos
PPTX
Introduction to internal auditing
PDF
Risk Based Internal Audit and Sampling Techniques
PPTX
COSO 2013 and The Auditor
PPTX
CISA exam 100 practice question
PPTX
Integrating Risk Appetite With Strategy Feb 14 2011
PPTX
Risk based auditing
PPTX
Internal Audit Strategic Framework
PPTX
Introduction to Internal Controls and Control Self-Assessments (CSA)
Risk based internal auditing
IT Control Objectives for SOX
Internal Audit
Internal financial control
Model i best practice evaluation worksheet for ia
Practical approach to Risk Based Internal Audit
Internal Financial Controls (IFC) / Internal Control over Financial Reporting...
Performance audit adding value
The role of internal audit department
Enterprise Risk Management - Aligning Risk with Strategy and Performance
Minicurso de Controles Internos
Introduction to internal auditing
Risk Based Internal Audit and Sampling Techniques
COSO 2013 and The Auditor
CISA exam 100 practice question
Integrating Risk Appetite With Strategy Feb 14 2011
Risk based auditing
Internal Audit Strategic Framework
Introduction to Internal Controls and Control Self-Assessments (CSA)
Ad

Viewers also liked (17)

PDF
Professional opportunities in Internal Audit
DOCX
Internal Control Questionnaires (ICQs)
PDF
Internal Quality Audit Training 26 27 March 2013
PDF
Integrating Internal Controls
PPTX
Hanrick Curran Audit Training - Internal Controls - March 2013
PPT
Coso Erm(2)
PDF
Proposal risk based internal audit 2013
PDF
Effective Internal Controls (Annotated) by @EricPesik
PPTX
COSO ERM
PPT
Risk Based Audit Approach
PDF
An industrial approach to risk and control self-assessments
PDF
Internal Control Checklist for Multi Purpose Cooperative
PPTX
Internal Audit Methodology
PDF
Internal Control
PPTX
Self Assessment
PPTX
COSO Internal Control - Integrated Framework
Professional opportunities in Internal Audit
Internal Control Questionnaires (ICQs)
Internal Quality Audit Training 26 27 March 2013
Integrating Internal Controls
Hanrick Curran Audit Training - Internal Controls - March 2013
Coso Erm(2)
Proposal risk based internal audit 2013
Effective Internal Controls (Annotated) by @EricPesik
COSO ERM
Risk Based Audit Approach
An industrial approach to risk and control self-assessments
Internal Control Checklist for Multi Purpose Cooperative
Internal Audit Methodology
Internal Control
Self Assessment
COSO Internal Control - Integrated Framework
Ad

Similar to Control Self-Assessment article (20)

PPTX
Spire Brief - Risk Consulting
PPTX
How an Organization Can Elevate Compliance Standards
PDF
Tyco Internal Audit Case Study
PDF
20 Key Considerations for Implementing an Effective Corporate Compliance Program
PDF
How Audit Committees Can Help with Third-Party Risks
PPTX
AUDIT - AUDITING STRATEGIES.pptx
PDF
Solution Manual for Internal Auditing Assurance and Consulting Services 2nd E...
PDF
Solution Manual for Internal Auditing Assurance and Consulting Services 2nd E...
PPTX
Chapter 9 Managing and Controlling Ethics Programs
PDF
Iso 55000 white_paper_english
DOCX
POSITION OF INTERNAL AUDIT IN THE CORPORATE FRAMEWORK
PDF
Solution Manual for Internal Auditing Assurance and Consulting Services 2nd E...
PPTX
The importance of value for money and perfomance based audits
PPTX
Compliance Control: Assessing Your Program For Anti-Corruption Effectiveness
PDF
Regulatory Audit Readiness Checklist for 2025 Compliance
DOCX
Mcs report
PDF
Solution Manual for Internal Auditing Assurance and Consulting Services 2nd E...
PDF
Performance management-ppt-generosa-jessica-charie-b.
PPTX
Comprehensive Guide to Compliance Audit service.pptx
PDF
compliance tracking
Spire Brief - Risk Consulting
How an Organization Can Elevate Compliance Standards
Tyco Internal Audit Case Study
20 Key Considerations for Implementing an Effective Corporate Compliance Program
How Audit Committees Can Help with Third-Party Risks
AUDIT - AUDITING STRATEGIES.pptx
Solution Manual for Internal Auditing Assurance and Consulting Services 2nd E...
Solution Manual for Internal Auditing Assurance and Consulting Services 2nd E...
Chapter 9 Managing and Controlling Ethics Programs
Iso 55000 white_paper_english
POSITION OF INTERNAL AUDIT IN THE CORPORATE FRAMEWORK
Solution Manual for Internal Auditing Assurance and Consulting Services 2nd E...
The importance of value for money and perfomance based audits
Compliance Control: Assessing Your Program For Anti-Corruption Effectiveness
Regulatory Audit Readiness Checklist for 2025 Compliance
Mcs report
Solution Manual for Internal Auditing Assurance and Consulting Services 2nd E...
Performance management-ppt-generosa-jessica-charie-b.
Comprehensive Guide to Compliance Audit service.pptx
compliance tracking

Control Self-Assessment article

  • 1. © Copyright Hari Iyer. Page 1 of 3 Background Control Self-Assessment (CSA) is a technique that was originally developed by Gulf Canada in 1987. In March 2000, the European Commission approved a white paper on CSA. In the United States when the Sarbanes-Oxley Act was implemented in 2007, section 404 of the Act required the companies to perform a top down risk assessment which necessitated CSA. In the United Kingdom in 2011 the Financial Services Authority (now Financial Conduct Authority) recognised in its recommendations for the improvement of operational risk management that the assessment of risks through a control self-assessment may be an important means of identifying risks. Today, a wide range of entities including private sector companies, voluntary sector (charities) and the public sector entities use CSA to assess the effectiveness of their risk management and control processes. The Institute of Internal Auditors run courses, seminars and offer Certification in Control Self- Assessment (CCSA). The Information Systems Audit and Control Association (ISACA) created a framework called COBIT (Control Objectives for Information and Related Technology). Control Self-Assessment is contained within COBIT’s Control Objective ME2.4. What is Control Self-Assessment CSA is a management technique that can be used to assure key stakeholders, both internal and external, that a company’s internal controls system is reliable. CSA allows managers and work teams directly involved in the business units, functions or processes to participate in assessing the company's risk management and control processes. CSA can cover objectives, risks, controls and processes. CSA is a sustainable process whereby management validates the operating effectiveness of its internal controls via testing. Each process owner and functional control owner within a company performs effectiveness testing to verify that the key controls are operating effectively. Control Self-Assessment
  • 2. © Copyright Hari Iyer. Page 2 of 3 Each process owner develops test scripts for each key control and engages their team to perform the given tests throughout the year. This allows management to verify that these controls are working effectively. A CSA program expands the role of operations management from merely assessing the design of its internal controls to testing and validating the effectiveness of its internal controls throughout the year. Benefits of a CSA Program An effective CSA program can deliver a number of benefits including:  Creation of clear line of accountability for internal controls;  Minimising the risk of fraud;  Creation of an improved controls environment resulting in a lower risk profile for the company ;  Sustainability of management’s compliance program;  Reduction in regulatory compliance costs CSA Program The first step in any CSA program is to document the company's control processes with the aim of identifying suitable ways of measuring or testing each control. The actual testing of the controls is performed by staff whose day-to-day role is within the area of the company that is being evaluated as they have the greatest knowledge of how the processes operate. The common techniques for performing the evaluations are:  Internal Control Questionnaire (ICQ) or Customised Survey Questionnaires  Interview Techniques  Control model Workshops or Interactive Workshops Some companies choose a combination of methodologies that suits their operations to implement an effective CSA program. On completion of the assessment each control may be rated based on the responses received to determine the probability of its failure and the impact if a failure occurred. These ratings can be summarised to produce a risk matrix showing potential areas of vulnerability. In any CSA program, the key steps are to define the nature and extent of the company’s CSA program, roll out the program, perform the first round of testing and review, and then incorporate lessons learned before going through the process again.
  • 3. © Copyright Hari Iyer. Page 3 of 3 Hadigy Limited is a private limited company incorporated in England with registered number 07010656. Hadigy is a Practice Assurance scheme member of the Chartered Institute of Public Finance and Accountancy (CIPFA). Hadigy is a member of the Federation of Small Business. This publication has been prepared for general guidance on matters of interest only, and does not constitute professional advice. You should not act upon the information contained in this publication without obtaining specific professional advice. No representation or warranty (express or implied) is given as to the accuracy, validity or completeness of the information contained in this publication, and, to the extent permitted by law, Hadigy Limited, its employees and agents do not accept or assume any liability, responsibility or duty of care for any consequences of you or anyone else acting, or refraining to act, in reliance on the information contained in this publication or for any decision based on it. Your Trusted Business Partner www.hadigy.com For details please contact: info@hadigy.com 17 Clareville Street, South Kensington, London SW7 5AJ Conclusion Entities have different drivers for wanting to enhance internal controls environment e.g. regulatory requirements, change in ownership, change in senior management, implementation of a major ERP system or simply wanting stronger internal controls to improve efficiency. Whatever the driver is, implementing a CSA program should be considered. By implementing an effective CSA program, the entity can embed internal control accountability deep into the company, ensure the sustainability of the internal controls compliance efforts, and ultimately reduce the cost of overall compliance efforts. In other words, an effective CSA program will drive a much improved internal control environment, giving assurance to all key stakeholders, internal and external alike, that the company’s controls are operating effectively. Author - Hari Iyer MBA, FCPA (Australia), CISA, Chartered FCSI Hari is the founding partner of Hadigy Limited, a management consultancy firm in London. Hari has over 25 years of financial and IT auditing experience gained partly with the Big 4 professional accountancy firms (EY, Deloitte & PwC) in the UK. This includes audit assurance reviews, SAP project assurance, business process reviews, IT audits, financial audits, business continuity management, and SAP governance, risk and compliance (GRC) implementation & reviews.