SlideShare a Scribd company logo
1 of 30
COSO 2013 Internal Control-Integrated Framework,
Efficiently Transition Using policyIQ
March 6, 2014
Objectives
By the end of the session, you will
 Be aware of key changes in updated COSO Framework
 Have more information about how to plan your
transition project
 Understand what policyIQ is and how to navigate
 See that you can easily configure policyIQ to capture
COSO Principles
 Recognize how you can use reports for analysis and
final reporting
2
COSO Updates Framework, May 14, 2013
The New Framework
3
Internal Control –
Integrated Framework
Framework and Appendices
The New Framework
 Expands the financial reporting category of objectives to
include other forms of reporting (internal and non-
financial)
 Explicitly formalizes principles introduced in original
framework
 Provides approaches and examples illustrating how
principles are applied in financials
 Supersedes 1992 Framework on December 15, 2014
4
2013 COSO Framework
5
The updated framework formalizes 17 principles
that were introduced and embedded in the original
framework. Companies choosing to follow the COSO
Framework will need to demonstrate that all 17
Principles are present and functioning in their
Internal Control Framework.
10. Selects and develops control activities
11. Selects and develops general controls over technology
12. Deploys through policies and procedures
Control
Activities
1. Demonstrates commitment to integrity and ethical values
2. Exercises oversight responsibility
3. Establishes structure, authority and responsibility
4. Demonstrates commitment to competence
5. Enforces accountability
Control
Environment
6. Specifies suitable objectives
7. Identifies and analyzes risk
8. Assesses fraud risk
9. Identifies and analyzes significant change
Risk
Assessment
13. Uses relevant information
14. Communicates internally
15. Communicates externally
Information &
Communication
16. Conducts ongoing and/or separate evaluations
17. Evaluates and communicates deficiencies
Monitoring
Activities
2013 COSO Framework
6
Transition Strategy
7
 Project ownership
 it is important that someone takes responsibility for dates and deliverables
 Project communication
 include all parties touched by the change in communications
 Resource constraints
 assess the time and people that you have, reach out to RGP or others for support
 Coordination with external auditors
 touch base with auditors early and often to ensure that you are on the same page
 Top down versus bottom up
 RGP recommends doing both
Project Approach and TimelineActivities
Phase 1 - Plan
• Establish project
ownership /
management
• Develop detailed
approach and timeline
• Identify resources and
assign responsibility
• Communicate plan and
train
• Consult with auditors
P4
1/1/2014 – 3/31/2014
Q1 – Year-end close,
financial audits,
Year-end write-up
4/1/2014 – 6/30/2014
Q2 Testing for 1st half of
the year
7/1/2014 – 9/30/2014
Q3 – Testing 2nd
part of the year
10/1/2014 – 12/31/2014
Q4 – Year-end & Remediation
Testing
3/31/2014 6/30/2014 9/30/2014 12/31/2014Today
P3P2P1
Phase 2 - Map
• Update risk assessment
• Start mapping from top
down
• Link principles to
controls
• Consider points of
focus
• Coordinate with other
service providers
Phase 3 - Assess
• Identify deficiencies
• Evaluate deficiencies
• Determine controls
requiring remediation
• Consider eliminating
orphan controls
Phase 4 - Implement
• Design new controls
• Train control owners
• Schedule testing
8
Introduction policyIQ
9
Web-based Governance, Risk & Compliance
Customizable and flexible
A workflow, oversight, management
reporting tool
Secure (certifications, SSL, Username/PW)
10
Introduction policyIQ
Contract
Procedure
Policy
Test
Control
Risk Fields:
 Text
 Dropdown
 Multi-Select
 Date
 Number
 Currency
Restrict:
 Creators
 Approvers
Page
Procedure
Template
name
date
text
11
Introduction policyIQ
Create Pages for your Risks,
COSO Principles, Narratives,
Controls, and so on from
Templates that drive consistency
and sound information
governance practices
Contract
Procedure
Policy
Test
Control
Risk
Page
upload &
attach
Folder
Page
Page
Folder
Folder
12
Introduction policyIQ
Take advantage of the
database and easy-to-use
interface to eliminate issues
with multiple versions, to
manage workpapers and
supporting documentation and
to relate content appropriately
for powerful reporting
capabilities.
Introduction to policyIQ
13
Introduction to policyIQ
14
Remember SOX in Year 1 or 2 and manually managing Risk/Control matrices in Excel?
Introduction to policyIQ
15
Remember SOX in Year 1 or 2 and manually managing Risk/Control matrices in Excel?
You might be comforted knowing that policyIQ plays well with Excel—as in this example
above of a matrix (Detail Link Report) exported to Excel.
Introduction to policyIQ
16
Remember that
the root object
in policyIQ is
a page…
…with the
ability to link
pages to one
another.
Pages are
created from
Templates with
the fields that
you want.
You can define who should have read,
write and approve access to all content
and can index Pages into one or multiple
Folders.
Introduction to policyIQ
17
Getting around is very easy—using familiar actions to drill down
into Folders, select items in the table on the right and choose the
appropriate action from the toolbar above. We do these things
everyday while working with documents on our hard drive or in
shared network folders.
Introduction to policyIQ
18
To configure (retrofit) policyIQ for the new COSO
framework, we recommend adding a Folder structure
called “COSO” to which you can add subfolders for each
of the COSO Components. This is where you will file or
index your pages for each of your COSO Principles.
Introduction to policyIQ
19
To create those Principle Pages, you must first create a Page Template. Similar to the navigation
elsewhere in policyIQ, drill down into the appropriate Page Template Category and then choose
the appropriate action (Add Template for Pages) from the toolbar. Follow similar navigation to
highlight the Principle template on the left and add one Short Text field to capture the more
detailed description of each Principle.
Introduction to policyIQ
20
Populating policyIQ with your Principles, Points of Focus (and Risks, Controls, Tests, etc.
if you are new to policyIQ) is as simple as arranging the information in Excel for Import.
Introduction to policyIQ
21
The result of the import is:
your pages have been
created, appropriate security
rights have been assigned,
pages are indexed into the
appropriate folders and you
can even link pages to one
another.
Using policyIQ for Analysis and Reporting
22
Mapping Process – Top-down Approach
23
Without policyIQ, you could use COSO’s Illustrative Tools to help you manage your top-down
methodology of mapping your Principles to Points of Focus and then to relevant Controls.
Mapping Process – Top-down Approach
24
With policyIQ, you could use the tool and linking capability to manage your top-down
methodology of mapping your Principles to Points of Focus and then to relevant Controls.
You could also use
policyIQ to review all
of your controls and
map them to relevant
Principles or Points
of Focus. This process
will set the stage for
using policyIQ to
thoroughly (and
quickly) review and
rationalize the
reduction of controls
and, therefore, testing
(and related costs).
Mapping Process – Bottom-up Approach
25
policyIQ Reports – To Identify Gaps
26
With a simple report, it is
apparent when gaps exist.
policyIQ Reports – Control Rationalization
27
Reports also allow
you to easily see
where some Principles
might be more than
adequately controlled
and when it makes
sense to remove
Controls from the SOX
framework (noting
they are “out of
scope” for SOX).
policyIQ Reports – To Summarize
28
Focus only on necessary information in Results
You may also use policyIQ Reports to
summarize information—selecting only the
pertinent information—to share with the Audit
Committee, External Auditors, and so on.
 Start the transition process as soon as possible
 Use the opportunity to streamline key controls and
reduce costs
 Leverage technology to promote effectiveness and
efficiency
 Mapping process
 Control Rationalization – Gaps and Redundancies
 Reporting to the Audit Committee and External Auditors
Summary
29
Contact Information
LESTER SUSSMAN
Senior Practice Director, GRC
Lester.Sussman@rgp.com
STEPHENIE BUEHRLE
Product Director, policyIQ
Stephenie.Buehrle@rgp.com
POLICYIQ INFORMATION
Information@policyIQ.com
30
Reach out to us with
any questions about
the framework,
methodology for
transitioning, project
management, project
support or policyIQ!

More Related Content

What's hot

Introduction to COSO 2013 - Corporate Compliance Seminars
Introduction to COSO 2013 - Corporate Compliance SeminarsIntroduction to COSO 2013 - Corporate Compliance Seminars
Introduction to COSO 2013 - Corporate Compliance SeminarsCorporate Compliance Seminars
 
Internal Audit COSO Framework
Internal Audit COSO FrameworkInternal Audit COSO Framework
Internal Audit COSO FrameworkJesús Gándara
 
Coso And Internal Audit
Coso And Internal AuditCoso And Internal Audit
Coso And Internal Auditijazurrehman
 
Coso internal control integrated framework
Coso internal control   integrated frameworkCoso internal control   integrated framework
Coso internal control integrated frameworkIrfan Ahmed - ACA, CICA
 
POSITION OF INTERNAL AUDIT IN THE CORPORATE FRAMEWORK
POSITION OF INTERNAL AUDIT IN THE CORPORATE FRAMEWORKPOSITION OF INTERNAL AUDIT IN THE CORPORATE FRAMEWORK
POSITION OF INTERNAL AUDIT IN THE CORPORATE FRAMEWORKHaresh Lalwani
 
Internal control and Control Self Assessment
Internal control and Control Self AssessmentInternal control and Control Self Assessment
Internal control and Control Self AssessmentManoj Agarwal
 
Leveraging Effective Risk Management and Internal Control for Your Organization
Leveraging Effective Risk Management and Internal Control for Your OrganizationLeveraging Effective Risk Management and Internal Control for Your Organization
Leveraging Effective Risk Management and Internal Control for Your OrganizationInternational Federation of Accountants
 
internal control and control self assessment
internal control and control self assessmentinternal control and control self assessment
internal control and control self assessmentManoj Agarwal
 
COSO 2013: What you need to know
COSO 2013: What you need to knowCOSO 2013: What you need to know
COSO 2013: What you need to knowjennyhollingworth
 
COSO Deep Dive - Using BlackLine to Manage Your COSO Framework
COSO Deep Dive - Using BlackLine to Manage Your COSO FrameworkCOSO Deep Dive - Using BlackLine to Manage Your COSO Framework
COSO Deep Dive - Using BlackLine to Manage Your COSO FrameworkBlackLine
 
COSO Framework Model
COSO Framework ModelCOSO Framework Model
COSO Framework ModelTownofAddison
 
Approach note on internal audit [compatibility mode]
Approach note on internal audit [compatibility mode]Approach note on internal audit [compatibility mode]
Approach note on internal audit [compatibility mode]Deep Kumar Mendiratta
 

What's hot (20)

Introduction to COSO 2013 - Corporate Compliance Seminars
Introduction to COSO 2013 - Corporate Compliance SeminarsIntroduction to COSO 2013 - Corporate Compliance Seminars
Introduction to COSO 2013 - Corporate Compliance Seminars
 
Internal Audit COSO Framework
Internal Audit COSO FrameworkInternal Audit COSO Framework
Internal Audit COSO Framework
 
Coso And Internal Audit
Coso And Internal AuditCoso And Internal Audit
Coso And Internal Audit
 
Coso internal control integrated framework
Coso internal control   integrated frameworkCoso internal control   integrated framework
Coso internal control integrated framework
 
Best Practices: Change Management
Best Practices: Change ManagementBest Practices: Change Management
Best Practices: Change Management
 
SOX 2016 - PART I - COSO 2013
SOX 2016 - PART I - COSO 2013SOX 2016 - PART I - COSO 2013
SOX 2016 - PART I - COSO 2013
 
COSO Deck
COSO DeckCOSO Deck
COSO Deck
 
Coso illustrative tool
Coso illustrative toolCoso illustrative tool
Coso illustrative tool
 
COSO Internal Control - Integrated Framework
COSO Internal Control - Integrated FrameworkCOSO Internal Control - Integrated Framework
COSO Internal Control - Integrated Framework
 
POSITION OF INTERNAL AUDIT IN THE CORPORATE FRAMEWORK
POSITION OF INTERNAL AUDIT IN THE CORPORATE FRAMEWORKPOSITION OF INTERNAL AUDIT IN THE CORPORATE FRAMEWORK
POSITION OF INTERNAL AUDIT IN THE CORPORATE FRAMEWORK
 
Internal control and Control Self Assessment
Internal control and Control Self AssessmentInternal control and Control Self Assessment
Internal control and Control Self Assessment
 
Leveraging Effective Risk Management and Internal Control for Your Organization
Leveraging Effective Risk Management and Internal Control for Your OrganizationLeveraging Effective Risk Management and Internal Control for Your Organization
Leveraging Effective Risk Management and Internal Control for Your Organization
 
internal control and control self assessment
internal control and control self assessmentinternal control and control self assessment
internal control and control self assessment
 
COSO 2013: What you need to know
COSO 2013: What you need to knowCOSO 2013: What you need to know
COSO 2013: What you need to know
 
Model i best practice evaluation worksheet for ia
Model i best practice evaluation worksheet for iaModel i best practice evaluation worksheet for ia
Model i best practice evaluation worksheet for ia
 
COSO Deep Dive - Using BlackLine to Manage Your COSO Framework
COSO Deep Dive - Using BlackLine to Manage Your COSO FrameworkCOSO Deep Dive - Using BlackLine to Manage Your COSO Framework
COSO Deep Dive - Using BlackLine to Manage Your COSO Framework
 
COSO Framework Model
COSO Framework ModelCOSO Framework Model
COSO Framework Model
 
Audit rizkie hafizzah
Audit rizkie hafizzahAudit rizkie hafizzah
Audit rizkie hafizzah
 
Upgrading Risk Management and Internal Control in Your Organization
Upgrading Risk Management and Internal Control in Your OrganizationUpgrading Risk Management and Internal Control in Your Organization
Upgrading Risk Management and Internal Control in Your Organization
 
Approach note on internal audit [compatibility mode]
Approach note on internal audit [compatibility mode]Approach note on internal audit [compatibility mode]
Approach note on internal audit [compatibility mode]
 

Viewers also liked (8)

Penjelasan COSO & COBIT
Penjelasan COSO & COBITPenjelasan COSO & COBIT
Penjelasan COSO & COBIT
 
Coso guidance on_monitoring_intro_online1_002
Coso guidance on_monitoring_intro_online1_002Coso guidance on_monitoring_intro_online1_002
Coso guidance on_monitoring_intro_online1_002
 
COSO: Internal Control Integrated Framework
COSO: Internal Control Integrated FrameworkCOSO: Internal Control Integrated Framework
COSO: Internal Control Integrated Framework
 
Cobit dan coso
Cobit dan cosoCobit dan coso
Cobit dan coso
 
Recent COSO Internal Control and Risk Management Developments
Recent COSO Internal Control and Risk Management DevelopmentsRecent COSO Internal Control and Risk Management Developments
Recent COSO Internal Control and Risk Management Developments
 
Implementasi ERM dan Internal Control-
Implementasi ERM dan Internal Control-Implementasi ERM dan Internal Control-
Implementasi ERM dan Internal Control-
 
COSO ERM
COSO ERMCOSO ERM
COSO ERM
 
6. audit techniques
6. audit techniques6. audit techniques
6. audit techniques
 

Similar to policyIQ for COSO 2013 Internal Control - Integrated Framework

Module-7-Program-Monitoring-and-Evaluation.pptx
Module-7-Program-Monitoring-and-Evaluation.pptxModule-7-Program-Monitoring-and-Evaluation.pptx
Module-7-Program-Monitoring-and-Evaluation.pptxmusicearphone
 
Project Scope Management in IT Project and Software Project
Project Scope Management in IT Project and Software ProjectProject Scope Management in IT Project and Software Project
Project Scope Management in IT Project and Software ProjectHengSovannarith
 
Asset Finance Systems: Project Initiation "101"
Asset Finance Systems: Project Initiation "101"Asset Finance Systems: Project Initiation "101"
Asset Finance Systems: Project Initiation "101"David Pedreno
 
Asset Finance Systems: Project Initiation "101"
Asset Finance Systems: Project Initiation "101"Asset Finance Systems: Project Initiation "101"
Asset Finance Systems: Project Initiation "101"David Pedreno
 
Project planning
Project planningProject planning
Project planningShaikh Zain
 
Sue Hooton - Planning a quality improvement project & driver diagrams.
Sue Hooton - Planning a quality improvement project & driver diagrams.Sue Hooton - Planning a quality improvement project & driver diagrams.
Sue Hooton - Planning a quality improvement project & driver diagrams.Innovation Agency
 
BSBMGT517 Manage operational planPart C– Project Managing an op.docx
BSBMGT517 Manage operational planPart C– Project Managing an op.docxBSBMGT517 Manage operational planPart C– Project Managing an op.docx
BSBMGT517 Manage operational planPart C– Project Managing an op.docxAASTHA76
 
Result Base Project Management
Result Base Project ManagementResult Base Project Management
Result Base Project ManagementArifur Rahman
 
Project Management Methodology_rFmAt0BhU0dwihA.pdf
Project Management Methodology_rFmAt0BhU0dwihA.pdfProject Management Methodology_rFmAt0BhU0dwihA.pdf
Project Management Methodology_rFmAt0BhU0dwihA.pdfFaisalAziz831398
 
ContentsPart 1 Build a Methodology4Abstract4Introductio
ContentsPart 1 Build a Methodology4Abstract4IntroductioContentsPart 1 Build a Methodology4Abstract4Introductio
ContentsPart 1 Build a Methodology4Abstract4IntroductioAlleneMcclendon878
 
eCIO PPT Plan of Action for a Systems Integrations (SAP) Project
eCIO PPT Plan of Action for a Systems Integrations (SAP) ProjecteCIO PPT Plan of Action for a Systems Integrations (SAP) Project
eCIO PPT Plan of Action for a Systems Integrations (SAP) ProjectDavid Niles
 
MODULE II - M.ARCH.pptx
MODULE II - M.ARCH.pptxMODULE II - M.ARCH.pptx
MODULE II - M.ARCH.pptxMdAliMujawar1
 
COBIT 5 IT Governance Model: an Introduction
COBIT 5 IT Governance Model: an IntroductionCOBIT 5 IT Governance Model: an Introduction
COBIT 5 IT Governance Model: an Introductionaqel aqel
 
Project / Program / Portfolio Management and Processes Groups
Project / Program / Portfolio Management and Processes GroupsProject / Program / Portfolio Management and Processes Groups
Project / Program / Portfolio Management and Processes GroupsAhmed Alageed
 
MBA 705 Milestone Two Guidelines and Rubric Overview.docx
MBA 705 Milestone Two Guidelines and Rubric  Overview.docxMBA 705 Milestone Two Guidelines and Rubric  Overview.docx
MBA 705 Milestone Two Guidelines and Rubric Overview.docxwkyra78
 
Ahcs best practice_white_paper_1.5 (1)
Ahcs best practice_white_paper_1.5 (1)Ahcs best practice_white_paper_1.5 (1)
Ahcs best practice_white_paper_1.5 (1)HamadaAsmrAladham1
 

Similar to policyIQ for COSO 2013 Internal Control - Integrated Framework (20)

Module-7-Program-Monitoring-and-Evaluation.pptx
Module-7-Program-Monitoring-and-Evaluation.pptxModule-7-Program-Monitoring-and-Evaluation.pptx
Module-7-Program-Monitoring-and-Evaluation.pptx
 
project planning
project planningproject planning
project planning
 
Project Scope Management in IT Project and Software Project
Project Scope Management in IT Project and Software ProjectProject Scope Management in IT Project and Software Project
Project Scope Management in IT Project and Software Project
 
Asset Finance Systems: Project Initiation "101"
Asset Finance Systems: Project Initiation "101"Asset Finance Systems: Project Initiation "101"
Asset Finance Systems: Project Initiation "101"
 
Asset Finance Systems: Project Initiation "101"
Asset Finance Systems: Project Initiation "101"Asset Finance Systems: Project Initiation "101"
Asset Finance Systems: Project Initiation "101"
 
Project planning
Project planningProject planning
Project planning
 
Sue Hooton - Planning a quality improvement project & driver diagrams.
Sue Hooton - Planning a quality improvement project & driver diagrams.Sue Hooton - Planning a quality improvement project & driver diagrams.
Sue Hooton - Planning a quality improvement project & driver diagrams.
 
BSBMGT517 Manage operational planPart C– Project Managing an op.docx
BSBMGT517 Manage operational planPart C– Project Managing an op.docxBSBMGT517 Manage operational planPart C– Project Managing an op.docx
BSBMGT517 Manage operational planPart C– Project Managing an op.docx
 
Result Base Project Management
Result Base Project ManagementResult Base Project Management
Result Base Project Management
 
Project Management Methodology_rFmAt0BhU0dwihA.pdf
Project Management Methodology_rFmAt0BhU0dwihA.pdfProject Management Methodology_rFmAt0BhU0dwihA.pdf
Project Management Methodology_rFmAt0BhU0dwihA.pdf
 
ContentsPart 1 Build a Methodology4Abstract4Introductio
ContentsPart 1 Build a Methodology4Abstract4IntroductioContentsPart 1 Build a Methodology4Abstract4Introductio
ContentsPart 1 Build a Methodology4Abstract4Introductio
 
Logical framework analysis
Logical framework analysisLogical framework analysis
Logical framework analysis
 
Ch04
Ch04Ch04
Ch04
 
eCIO PPT Plan of Action for a Systems Integrations (SAP) Project
eCIO PPT Plan of Action for a Systems Integrations (SAP) ProjecteCIO PPT Plan of Action for a Systems Integrations (SAP) Project
eCIO PPT Plan of Action for a Systems Integrations (SAP) Project
 
MODULE II - M.ARCH.pptx
MODULE II - M.ARCH.pptxMODULE II - M.ARCH.pptx
MODULE II - M.ARCH.pptx
 
COBIT 5 IT Governance Model: an Introduction
COBIT 5 IT Governance Model: an IntroductionCOBIT 5 IT Governance Model: an Introduction
COBIT 5 IT Governance Model: an Introduction
 
Project / Program / Portfolio Management and Processes Groups
Project / Program / Portfolio Management and Processes GroupsProject / Program / Portfolio Management and Processes Groups
Project / Program / Portfolio Management and Processes Groups
 
sample456.pptx
sample456.pptxsample456.pptx
sample456.pptx
 
MBA 705 Milestone Two Guidelines and Rubric Overview.docx
MBA 705 Milestone Two Guidelines and Rubric  Overview.docxMBA 705 Milestone Two Guidelines and Rubric  Overview.docx
MBA 705 Milestone Two Guidelines and Rubric Overview.docx
 
Ahcs best practice_white_paper_1.5 (1)
Ahcs best practice_white_paper_1.5 (1)Ahcs best practice_white_paper_1.5 (1)
Ahcs best practice_white_paper_1.5 (1)
 

Recently uploaded

Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...Roland Driesen
 
7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...Paul Menig
 
Monthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxMonthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxAndy Lambert
 
KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...
KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...
KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...Any kyc Account
 
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...lizamodels9
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageMatteo Carbone
 
Event mailer assignment progress report .pdf
Event mailer assignment progress report .pdfEvent mailer assignment progress report .pdf
Event mailer assignment progress report .pdftbatkhuu1
 
HONOR Veterans Event Keynote by Michael Hawkins
HONOR Veterans Event Keynote by Michael HawkinsHONOR Veterans Event Keynote by Michael Hawkins
HONOR Veterans Event Keynote by Michael HawkinsMichael W. Hawkins
 
Understanding the Pakistan Budgeting Process: Basics and Key Insights
Understanding the Pakistan Budgeting Process: Basics and Key InsightsUnderstanding the Pakistan Budgeting Process: Basics and Key Insights
Understanding the Pakistan Budgeting Process: Basics and Key Insightsseri bangash
 
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876dlhescort
 
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...anilsa9823
 
Monte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSMMonte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSMRavindra Nath Shukla
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Neil Kimberley
 
Unlocking the Secrets of Affiliate Marketing.pdf
Unlocking the Secrets of Affiliate Marketing.pdfUnlocking the Secrets of Affiliate Marketing.pdf
Unlocking the Secrets of Affiliate Marketing.pdfOnline Income Engine
 
Best Basmati Rice Manufacturers in India
Best Basmati Rice Manufacturers in IndiaBest Basmati Rice Manufacturers in India
Best Basmati Rice Manufacturers in IndiaShree Krishna Exports
 
Grateful 7 speech thanking everyone that has helped.pdf
Grateful 7 speech thanking everyone that has helped.pdfGrateful 7 speech thanking everyone that has helped.pdf
Grateful 7 speech thanking everyone that has helped.pdfPaul Menig
 
Call Girls In Holiday Inn Express Gurugram➥99902@11544 ( Best price)100% Genu...
Call Girls In Holiday Inn Express Gurugram➥99902@11544 ( Best price)100% Genu...Call Girls In Holiday Inn Express Gurugram➥99902@11544 ( Best price)100% Genu...
Call Girls In Holiday Inn Express Gurugram➥99902@11544 ( Best price)100% Genu...lizamodels9
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMANIlamathiKannappan
 
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...Lviv Startup Club
 

Recently uploaded (20)

Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...
 
7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...
 
Monthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxMonthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptx
 
KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...
KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...
KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...
 
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usage
 
Event mailer assignment progress report .pdf
Event mailer assignment progress report .pdfEvent mailer assignment progress report .pdf
Event mailer assignment progress report .pdf
 
HONOR Veterans Event Keynote by Michael Hawkins
HONOR Veterans Event Keynote by Michael HawkinsHONOR Veterans Event Keynote by Michael Hawkins
HONOR Veterans Event Keynote by Michael Hawkins
 
Understanding the Pakistan Budgeting Process: Basics and Key Insights
Understanding the Pakistan Budgeting Process: Basics and Key InsightsUnderstanding the Pakistan Budgeting Process: Basics and Key Insights
Understanding the Pakistan Budgeting Process: Basics and Key Insights
 
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
 
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
 
Monte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSMMonte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSM
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023
 
Unlocking the Secrets of Affiliate Marketing.pdf
Unlocking the Secrets of Affiliate Marketing.pdfUnlocking the Secrets of Affiliate Marketing.pdf
Unlocking the Secrets of Affiliate Marketing.pdf
 
Best Basmati Rice Manufacturers in India
Best Basmati Rice Manufacturers in IndiaBest Basmati Rice Manufacturers in India
Best Basmati Rice Manufacturers in India
 
Grateful 7 speech thanking everyone that has helped.pdf
Grateful 7 speech thanking everyone that has helped.pdfGrateful 7 speech thanking everyone that has helped.pdf
Grateful 7 speech thanking everyone that has helped.pdf
 
Call Girls In Holiday Inn Express Gurugram➥99902@11544 ( Best price)100% Genu...
Call Girls In Holiday Inn Express Gurugram➥99902@11544 ( Best price)100% Genu...Call Girls In Holiday Inn Express Gurugram➥99902@11544 ( Best price)100% Genu...
Call Girls In Holiday Inn Express Gurugram➥99902@11544 ( Best price)100% Genu...
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMAN
 
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
 

policyIQ for COSO 2013 Internal Control - Integrated Framework

  • 1. COSO 2013 Internal Control-Integrated Framework, Efficiently Transition Using policyIQ March 6, 2014
  • 2. Objectives By the end of the session, you will  Be aware of key changes in updated COSO Framework  Have more information about how to plan your transition project  Understand what policyIQ is and how to navigate  See that you can easily configure policyIQ to capture COSO Principles  Recognize how you can use reports for analysis and final reporting 2
  • 3. COSO Updates Framework, May 14, 2013 The New Framework 3 Internal Control – Integrated Framework Framework and Appendices
  • 4. The New Framework  Expands the financial reporting category of objectives to include other forms of reporting (internal and non- financial)  Explicitly formalizes principles introduced in original framework  Provides approaches and examples illustrating how principles are applied in financials  Supersedes 1992 Framework on December 15, 2014 4
  • 5. 2013 COSO Framework 5 The updated framework formalizes 17 principles that were introduced and embedded in the original framework. Companies choosing to follow the COSO Framework will need to demonstrate that all 17 Principles are present and functioning in their Internal Control Framework.
  • 6. 10. Selects and develops control activities 11. Selects and develops general controls over technology 12. Deploys through policies and procedures Control Activities 1. Demonstrates commitment to integrity and ethical values 2. Exercises oversight responsibility 3. Establishes structure, authority and responsibility 4. Demonstrates commitment to competence 5. Enforces accountability Control Environment 6. Specifies suitable objectives 7. Identifies and analyzes risk 8. Assesses fraud risk 9. Identifies and analyzes significant change Risk Assessment 13. Uses relevant information 14. Communicates internally 15. Communicates externally Information & Communication 16. Conducts ongoing and/or separate evaluations 17. Evaluates and communicates deficiencies Monitoring Activities 2013 COSO Framework 6
  • 7. Transition Strategy 7  Project ownership  it is important that someone takes responsibility for dates and deliverables  Project communication  include all parties touched by the change in communications  Resource constraints  assess the time and people that you have, reach out to RGP or others for support  Coordination with external auditors  touch base with auditors early and often to ensure that you are on the same page  Top down versus bottom up  RGP recommends doing both
  • 8. Project Approach and TimelineActivities Phase 1 - Plan • Establish project ownership / management • Develop detailed approach and timeline • Identify resources and assign responsibility • Communicate plan and train • Consult with auditors P4 1/1/2014 – 3/31/2014 Q1 – Year-end close, financial audits, Year-end write-up 4/1/2014 – 6/30/2014 Q2 Testing for 1st half of the year 7/1/2014 – 9/30/2014 Q3 – Testing 2nd part of the year 10/1/2014 – 12/31/2014 Q4 – Year-end & Remediation Testing 3/31/2014 6/30/2014 9/30/2014 12/31/2014Today P3P2P1 Phase 2 - Map • Update risk assessment • Start mapping from top down • Link principles to controls • Consider points of focus • Coordinate with other service providers Phase 3 - Assess • Identify deficiencies • Evaluate deficiencies • Determine controls requiring remediation • Consider eliminating orphan controls Phase 4 - Implement • Design new controls • Train control owners • Schedule testing 8
  • 10. Web-based Governance, Risk & Compliance Customizable and flexible A workflow, oversight, management reporting tool Secure (certifications, SSL, Username/PW) 10 Introduction policyIQ
  • 11. Contract Procedure Policy Test Control Risk Fields:  Text  Dropdown  Multi-Select  Date  Number  Currency Restrict:  Creators  Approvers Page Procedure Template name date text 11 Introduction policyIQ Create Pages for your Risks, COSO Principles, Narratives, Controls, and so on from Templates that drive consistency and sound information governance practices
  • 12. Contract Procedure Policy Test Control Risk Page upload & attach Folder Page Page Folder Folder 12 Introduction policyIQ Take advantage of the database and easy-to-use interface to eliminate issues with multiple versions, to manage workpapers and supporting documentation and to relate content appropriately for powerful reporting capabilities.
  • 14. Introduction to policyIQ 14 Remember SOX in Year 1 or 2 and manually managing Risk/Control matrices in Excel?
  • 15. Introduction to policyIQ 15 Remember SOX in Year 1 or 2 and manually managing Risk/Control matrices in Excel? You might be comforted knowing that policyIQ plays well with Excel—as in this example above of a matrix (Detail Link Report) exported to Excel.
  • 16. Introduction to policyIQ 16 Remember that the root object in policyIQ is a page… …with the ability to link pages to one another. Pages are created from Templates with the fields that you want. You can define who should have read, write and approve access to all content and can index Pages into one or multiple Folders.
  • 17. Introduction to policyIQ 17 Getting around is very easy—using familiar actions to drill down into Folders, select items in the table on the right and choose the appropriate action from the toolbar above. We do these things everyday while working with documents on our hard drive or in shared network folders.
  • 18. Introduction to policyIQ 18 To configure (retrofit) policyIQ for the new COSO framework, we recommend adding a Folder structure called “COSO” to which you can add subfolders for each of the COSO Components. This is where you will file or index your pages for each of your COSO Principles.
  • 19. Introduction to policyIQ 19 To create those Principle Pages, you must first create a Page Template. Similar to the navigation elsewhere in policyIQ, drill down into the appropriate Page Template Category and then choose the appropriate action (Add Template for Pages) from the toolbar. Follow similar navigation to highlight the Principle template on the left and add one Short Text field to capture the more detailed description of each Principle.
  • 20. Introduction to policyIQ 20 Populating policyIQ with your Principles, Points of Focus (and Risks, Controls, Tests, etc. if you are new to policyIQ) is as simple as arranging the information in Excel for Import.
  • 21. Introduction to policyIQ 21 The result of the import is: your pages have been created, appropriate security rights have been assigned, pages are indexed into the appropriate folders and you can even link pages to one another.
  • 22. Using policyIQ for Analysis and Reporting 22
  • 23. Mapping Process – Top-down Approach 23 Without policyIQ, you could use COSO’s Illustrative Tools to help you manage your top-down methodology of mapping your Principles to Points of Focus and then to relevant Controls.
  • 24. Mapping Process – Top-down Approach 24 With policyIQ, you could use the tool and linking capability to manage your top-down methodology of mapping your Principles to Points of Focus and then to relevant Controls.
  • 25. You could also use policyIQ to review all of your controls and map them to relevant Principles or Points of Focus. This process will set the stage for using policyIQ to thoroughly (and quickly) review and rationalize the reduction of controls and, therefore, testing (and related costs). Mapping Process – Bottom-up Approach 25
  • 26. policyIQ Reports – To Identify Gaps 26 With a simple report, it is apparent when gaps exist.
  • 27. policyIQ Reports – Control Rationalization 27 Reports also allow you to easily see where some Principles might be more than adequately controlled and when it makes sense to remove Controls from the SOX framework (noting they are “out of scope” for SOX).
  • 28. policyIQ Reports – To Summarize 28 Focus only on necessary information in Results You may also use policyIQ Reports to summarize information—selecting only the pertinent information—to share with the Audit Committee, External Auditors, and so on.
  • 29.  Start the transition process as soon as possible  Use the opportunity to streamline key controls and reduce costs  Leverage technology to promote effectiveness and efficiency  Mapping process  Control Rationalization – Gaps and Redundancies  Reporting to the Audit Committee and External Auditors Summary 29
  • 30. Contact Information LESTER SUSSMAN Senior Practice Director, GRC Lester.Sussman@rgp.com STEPHENIE BUEHRLE Product Director, policyIQ Stephenie.Buehrle@rgp.com POLICYIQ INFORMATION Information@policyIQ.com 30 Reach out to us with any questions about the framework, methodology for transitioning, project management, project support or policyIQ!