SlideShare a Scribd company logo
Prepared by
Wa'el Bibi,CPA,CIA,CISA 1
Internal Control
Integrated Framework
COSO’s
An Overview..
Source: COSO’s Internal Control Integrated Framework
Bibi Consulting
www.bibiconsulting.com
Prepared by
Wa'el Bibi,CPA,CIA,CISA 2
What is COSO?
Who are the sponsors?
Prepared by
Wa'el Bibi,CPA,CIA,CISA 3
What Is Internal Control ?
“A process effected by an entity’s board of
directors,management and other
personnel,designed to provide reasonable
assurance regarding the achievements of
objectives in the following categories:
♦ Effectiveness & efficiency of operations.
♦ Reliability of financial reporting.
♦ Compliance with applicable laws and regulations.”
Prepared by
Wa'el Bibi,CPA,CIA,CISA 4
♦ Internal control is a process. It is a means
to an end, not an end in itself.
♦ Internal control is effected by people. It’s
not merely policy manuals and forms, but
people at every level of an organization.
♦ Internal control can be expected to
provide only reasonable assurance, not
absolute assurance, to an entity’s
management and board.
♦ Internal control is geared to the
achievement of objectives in one or more
separate but overlapping categories.
Prepared by
Wa'el Bibi,CPA,CIA,CISA 5
Components Of Internal Control
♦ Control Environment.
♦ Risk Assessment.
♦ Control Activities.
♦ Information & Communication.
♦ Monitoring.
Prepared by
Wa'el Bibi,CPA,CIA,CISA 6
Prepared by
Wa'el Bibi,CPA,CIA,CISA 7
Control Environment
♦ Sets the tone of the organization.
♦ The foundation for all other components.
♦ It includes the integrity,ethical values and competence of
the people.
♦ Reflects: management’s philosophy & operating style,the
way management assigns authority and responsibility and
organizes and develops its people, and the attention and
direction provided by the board of directors.
Prepared by
Wa'el Bibi,CPA,CIA,CISA 8
Risk Assessment
♦ Every entity faces internal &external risks.
♦ Every entity sets objectives.
♦ Risk assessment is the identification and
analysis of relevant risks to achievements of
the objectives.
Prepared by
Wa'el Bibi,CPA,CIA,CISA 9
Control Activities
♦ The policies and procedures that help ensure
management directives are carried out.
♦ They help ensure that necessary actions are taken
to address risks.
♦ Control activities occur throughout the entity at all
levels and in all functions.
♦ They include activities such as approvals ,
authorization,reconciliations and segregation of
duties.
Prepared by
Wa'el Bibi,CPA,CIA,CISA 10
Information & Communication
♦ Relevant information must be identified , captured
and communicated in a form & timeframe that
enables people to carry out their responsibilities.
♦ Information systems produce reports containing
operational,financial and compliance –related
information that make it possible to run and
control the business.
♦ Effective communication must occur in a broader
sense,flowing down,across and up the
organization.
Prepared by
Wa'el Bibi,CPA,CIA,CISA 11
Monitoring
♦ Internal control systems need to be monitored.
♦ Types of monitoring:
- ongoing during the course of operations.
- evaluation for which the scope and frequency will
depend primarily on an assessment of risks and the
effectiveness of ongoing monitoring procedures.
Prepared by
Wa'el Bibi,CPA,CIA,CISA 12
Responsibilities
Who is responsible for internal control ?
Everyone !
Board of Directors :Governance,guidance & oversight
Management : CEO is the owner
Internal Auditors: evaluate & monitor
Other personnel :information and communication
Prepared by
Wa'el Bibi,CPA,CIA,CISA 13
What Internal Control Can Do
♦ It can help achieve performance & profitability
targets.
♦ It can help prevent loss of resources.
♦ It can help ensure reliable financial reporting.
♦ It can help ensure compliance with laws.
It can help an entity get to where it wants to
go,and avoid pitfalls and surprises along the
way.
Prepared by
Wa'el Bibi,CPA,CIA,CISA 14
What Internal Control Cannot Do
♦ It cannot ensure success.
♦ It cannot ensure the reliability of financial
reporting.
♦ It cannot ensure compliance with laws and
regulations.
Internal controls ,no matter how well designed and
operated,can provide only reasonable assurance to
management regarding achievements of an
entity’s objectives.
Prepared by
Wa'el Bibi,CPA,CIA,CISA 15
Limitations of Internal Control
♦ Judgement.
♦ Breakdowns.
♦ Management override.
♦ Collusion.
♦ Costs Versus Benefits.
Prepared by
Wa'el Bibi,CPA,CIA,CISA 16
End of COSO Presentation
Prepared by
Wa'el Bibi,CPA,CIA,CISA 17
Types of Controls
♦ Preventive
♦ Detective
♦ Corrective
♦ Directive
Prepared by
Wa'el Bibi,CPA,CIA,CISA 18
Preventive Controls
♦ Are designed to discourage errors or irregularities
from occurring.
♦ They are more cost-effective than detective
controls.
♦ Examples:
- Segregation of duties
- Authorization
- Firewalls
- Passwords
Prepared by
Wa'el Bibi,CPA,CIA,CISA 19
Detective Controls
♦ Are designed to search for and identify errors after
they have occurred.
♦ They are more expensive than preventive controls
.
♦ Examples:
- Reconcilaitions
- Analysis
- Periodic Inventory
- Surveillance cameras
- Audit
Prepared by
Wa'el Bibi,CPA,CIA,CISA 20
Corrective Controls
♦ corrective controls are designed to restore a
system to an approved/last known good
state.
♦ Examples:
- Anti Virus software.
- Adjusting entries.
Prepared by
Wa'el Bibi,CPA,CIA,CISA 21
Directive Controls
♦ Are designed to provide direction from
management. (Actions taken to cause or
encourage a desirable event to occur).
♦ Examples:
- Job Description
- Training
- Policies and procedures.

More Related Content

PPT
Time management,planning and prioritization
PPTX
Performance Management an Introduction to KPI
PPTX
Emerging leaders powerpoint presentation
PPT
Time management
PPTX
Step by Step Beginner's Guide on Workday Integration
PDF
Planilha controle-dizimo-oferta
PDF
Coso internal control frameword executive summary_2013
PDF
Internal control and Control Self Assessment
Time management,planning and prioritization
Performance Management an Introduction to KPI
Emerging leaders powerpoint presentation
Time management
Step by Step Beginner's Guide on Workday Integration
Planilha controle-dizimo-oferta
Coso internal control frameword executive summary_2013
Internal control and Control Self Assessment

Viewers also liked (20)

PPSX
8 Access Control
PDF
How to Easily Discover and Create Great Visual Content for Facebook
DOC
5.Apostoł narodów
PPTX
Legal and ethical issues
PDF
The Power of Social Influence
PPTX
Unit 4, Lesson 4
PPTX
Scopri le Fondamenta del Web Design
PDF
Howtoよいデザイン
RTF
2.Judasz
PDF
Building Loyalty Like Gaga
PPTX
2011-12 IABC Europe & Middle East Annual General Meeting
DOC
8.Droga kościoła do samodzielności
PPTX
Inspiring Revolution
PPTX
Social definitions
PDF
Blog
PPT
Passie voor Oranje
PPT
Guatelli per Madrid MFI
PDF
Nepal district-flood- preparedness-guidelines
PPTX
Mass Ave Wine Shop Continued
PPTX
Indiana Unviversity School of Medicine Computer ID Brochure Page 1
8 Access Control
How to Easily Discover and Create Great Visual Content for Facebook
5.Apostoł narodów
Legal and ethical issues
The Power of Social Influence
Unit 4, Lesson 4
Scopri le Fondamenta del Web Design
Howtoよいデザイン
2.Judasz
Building Loyalty Like Gaga
2011-12 IABC Europe & Middle East Annual General Meeting
8.Droga kościoła do samodzielności
Inspiring Revolution
Social definitions
Blog
Passie voor Oranje
Guatelli per Madrid MFI
Nepal district-flood- preparedness-guidelines
Mass Ave Wine Shop Continued
Indiana Unviversity School of Medicine Computer ID Brochure Page 1
Ad

Similar to Coso s internal_control_presentation (20)

PDF
Internal control system
PDF
Internal control system
PDF
Coso 2013 icfr executive summary
PDF
Coso 2013 icfr executive summary
PDF
990025 p executive-summary-final-may20
PPTX
Sppt chap003
PPTX
INTERNAL CONTROL-PPT.pptx
PPTX
Recent COSO Internal Control and Risk Management Developments
PPTX
Week 4_Lecture_Internal Control_Student.pptx
PPTX
Information system control and audit
PPT
FIN-Internal_Controls_Primer_Presentation.ppt
PPT
FIN-Internal_Controls_Primer_Presentation.ppt
PPT
Finance Internal_Controls presentation ppt
PPT
FIN-Internal_Controls_Primer_Presentation.ppt
PPT
FIN-Internal_Controls_Primer_Presentation.ppt
PPTX
COSO Deck
PDF
COSO Implementation: Getting Real, Getting It Right
PDF
COSO_2013_Framework_on_Internal_Control.pdf
PPTX
Coso And Internal Audit
PDF
Understanding Risk Management Through COSO ERM.pdf
Internal control system
Internal control system
Coso 2013 icfr executive summary
Coso 2013 icfr executive summary
990025 p executive-summary-final-may20
Sppt chap003
INTERNAL CONTROL-PPT.pptx
Recent COSO Internal Control and Risk Management Developments
Week 4_Lecture_Internal Control_Student.pptx
Information system control and audit
FIN-Internal_Controls_Primer_Presentation.ppt
FIN-Internal_Controls_Primer_Presentation.ppt
Finance Internal_Controls presentation ppt
FIN-Internal_Controls_Primer_Presentation.ppt
FIN-Internal_Controls_Primer_Presentation.ppt
COSO Deck
COSO Implementation: Getting Real, Getting It Right
COSO_2013_Framework_on_Internal_Control.pdf
Coso And Internal Audit
Understanding Risk Management Through COSO ERM.pdf
Ad

Recently uploaded (20)

PDF
Digital Marketing & E-commerce Certificate Glossary.pdf.................
PPTX
Belch_12e_PPT_Ch18_Accessible_university.pptx
PDF
Solara Labs: Empowering Health through Innovative Nutraceutical Solutions
PPTX
2025 Product Deck V1.0.pptxCATALOGTCLCIA
PPT
Lecture 3344;;,,(,(((((((((((((((((((((((
PDF
Power and position in leadershipDOC-20250808-WA0011..pdf
PPTX
svnfcksanfskjcsnvvjknsnvsdscnsncxasxa saccacxsax
PDF
Deliverable file - Regulatory guideline analysis.pdf
DOCX
unit 1 COST ACCOUNTING AND COST SHEET
DOCX
Business Management - unit 1 and 2
PDF
Roadmap Map-digital Banking feature MB,IB,AB
PDF
Stem Cell Market Report | Trends, Growth & Forecast 2025-2034
PPTX
New Microsoft PowerPoint Presentation - Copy.pptx
PDF
IFRS Notes in your pocket for study all the time
PDF
Nidhal Samdaie CV - International Business Consultant
PDF
Outsourced Audit & Assurance in USA Why Globus Finanza is Your Trusted Choice
PPTX
CkgxkgxydkydyldylydlydyldlyddolydyoyyU2.pptx
PPTX
Probability Distribution, binomial distribution, poisson distribution
PDF
Cours de Système d'information about ERP.pdf
PDF
Unit 1 Cost Accounting - Cost sheet
Digital Marketing & E-commerce Certificate Glossary.pdf.................
Belch_12e_PPT_Ch18_Accessible_university.pptx
Solara Labs: Empowering Health through Innovative Nutraceutical Solutions
2025 Product Deck V1.0.pptxCATALOGTCLCIA
Lecture 3344;;,,(,(((((((((((((((((((((((
Power and position in leadershipDOC-20250808-WA0011..pdf
svnfcksanfskjcsnvvjknsnvsdscnsncxasxa saccacxsax
Deliverable file - Regulatory guideline analysis.pdf
unit 1 COST ACCOUNTING AND COST SHEET
Business Management - unit 1 and 2
Roadmap Map-digital Banking feature MB,IB,AB
Stem Cell Market Report | Trends, Growth & Forecast 2025-2034
New Microsoft PowerPoint Presentation - Copy.pptx
IFRS Notes in your pocket for study all the time
Nidhal Samdaie CV - International Business Consultant
Outsourced Audit & Assurance in USA Why Globus Finanza is Your Trusted Choice
CkgxkgxydkydyldylydlydyldlyddolydyoyyU2.pptx
Probability Distribution, binomial distribution, poisson distribution
Cours de Système d'information about ERP.pdf
Unit 1 Cost Accounting - Cost sheet

Coso s internal_control_presentation

  • 1. Prepared by Wa'el Bibi,CPA,CIA,CISA 1 Internal Control Integrated Framework COSO’s An Overview.. Source: COSO’s Internal Control Integrated Framework Bibi Consulting www.bibiconsulting.com
  • 2. Prepared by Wa'el Bibi,CPA,CIA,CISA 2 What is COSO? Who are the sponsors?
  • 3. Prepared by Wa'el Bibi,CPA,CIA,CISA 3 What Is Internal Control ? “A process effected by an entity’s board of directors,management and other personnel,designed to provide reasonable assurance regarding the achievements of objectives in the following categories: ♦ Effectiveness & efficiency of operations. ♦ Reliability of financial reporting. ♦ Compliance with applicable laws and regulations.”
  • 4. Prepared by Wa'el Bibi,CPA,CIA,CISA 4 ♦ Internal control is a process. It is a means to an end, not an end in itself. ♦ Internal control is effected by people. It’s not merely policy manuals and forms, but people at every level of an organization. ♦ Internal control can be expected to provide only reasonable assurance, not absolute assurance, to an entity’s management and board. ♦ Internal control is geared to the achievement of objectives in one or more separate but overlapping categories.
  • 5. Prepared by Wa'el Bibi,CPA,CIA,CISA 5 Components Of Internal Control ♦ Control Environment. ♦ Risk Assessment. ♦ Control Activities. ♦ Information & Communication. ♦ Monitoring.
  • 7. Prepared by Wa'el Bibi,CPA,CIA,CISA 7 Control Environment ♦ Sets the tone of the organization. ♦ The foundation for all other components. ♦ It includes the integrity,ethical values and competence of the people. ♦ Reflects: management’s philosophy & operating style,the way management assigns authority and responsibility and organizes and develops its people, and the attention and direction provided by the board of directors.
  • 8. Prepared by Wa'el Bibi,CPA,CIA,CISA 8 Risk Assessment ♦ Every entity faces internal &external risks. ♦ Every entity sets objectives. ♦ Risk assessment is the identification and analysis of relevant risks to achievements of the objectives.
  • 9. Prepared by Wa'el Bibi,CPA,CIA,CISA 9 Control Activities ♦ The policies and procedures that help ensure management directives are carried out. ♦ They help ensure that necessary actions are taken to address risks. ♦ Control activities occur throughout the entity at all levels and in all functions. ♦ They include activities such as approvals , authorization,reconciliations and segregation of duties.
  • 10. Prepared by Wa'el Bibi,CPA,CIA,CISA 10 Information & Communication ♦ Relevant information must be identified , captured and communicated in a form & timeframe that enables people to carry out their responsibilities. ♦ Information systems produce reports containing operational,financial and compliance –related information that make it possible to run and control the business. ♦ Effective communication must occur in a broader sense,flowing down,across and up the organization.
  • 11. Prepared by Wa'el Bibi,CPA,CIA,CISA 11 Monitoring ♦ Internal control systems need to be monitored. ♦ Types of monitoring: - ongoing during the course of operations. - evaluation for which the scope and frequency will depend primarily on an assessment of risks and the effectiveness of ongoing monitoring procedures.
  • 12. Prepared by Wa'el Bibi,CPA,CIA,CISA 12 Responsibilities Who is responsible for internal control ? Everyone ! Board of Directors :Governance,guidance & oversight Management : CEO is the owner Internal Auditors: evaluate & monitor Other personnel :information and communication
  • 13. Prepared by Wa'el Bibi,CPA,CIA,CISA 13 What Internal Control Can Do ♦ It can help achieve performance & profitability targets. ♦ It can help prevent loss of resources. ♦ It can help ensure reliable financial reporting. ♦ It can help ensure compliance with laws. It can help an entity get to where it wants to go,and avoid pitfalls and surprises along the way.
  • 14. Prepared by Wa'el Bibi,CPA,CIA,CISA 14 What Internal Control Cannot Do ♦ It cannot ensure success. ♦ It cannot ensure the reliability of financial reporting. ♦ It cannot ensure compliance with laws and regulations. Internal controls ,no matter how well designed and operated,can provide only reasonable assurance to management regarding achievements of an entity’s objectives.
  • 15. Prepared by Wa'el Bibi,CPA,CIA,CISA 15 Limitations of Internal Control ♦ Judgement. ♦ Breakdowns. ♦ Management override. ♦ Collusion. ♦ Costs Versus Benefits.
  • 16. Prepared by Wa'el Bibi,CPA,CIA,CISA 16 End of COSO Presentation
  • 17. Prepared by Wa'el Bibi,CPA,CIA,CISA 17 Types of Controls ♦ Preventive ♦ Detective ♦ Corrective ♦ Directive
  • 18. Prepared by Wa'el Bibi,CPA,CIA,CISA 18 Preventive Controls ♦ Are designed to discourage errors or irregularities from occurring. ♦ They are more cost-effective than detective controls. ♦ Examples: - Segregation of duties - Authorization - Firewalls - Passwords
  • 19. Prepared by Wa'el Bibi,CPA,CIA,CISA 19 Detective Controls ♦ Are designed to search for and identify errors after they have occurred. ♦ They are more expensive than preventive controls . ♦ Examples: - Reconcilaitions - Analysis - Periodic Inventory - Surveillance cameras - Audit
  • 20. Prepared by Wa'el Bibi,CPA,CIA,CISA 20 Corrective Controls ♦ corrective controls are designed to restore a system to an approved/last known good state. ♦ Examples: - Anti Virus software. - Adjusting entries.
  • 21. Prepared by Wa'el Bibi,CPA,CIA,CISA 21 Directive Controls ♦ Are designed to provide direction from management. (Actions taken to cause or encourage a desirable event to occur). ♦ Examples: - Job Description - Training - Policies and procedures.