Internal Controls
Internal Controls
DiNapoli
State of New York
Office of the State Comptroller
Internal Controls
Steven J. Hancox
Deputy Comptroller
Division of Local Government and
School Accountability
Internal Controls
Introduction
Today, local governments are faced with providing needed services to citizens with limited
public resources. Local officials are entrusted with these limited public resources and are
responsible for complying with laws and regulations, meeting goals and objectives, safeguarding
assets, and issuing reports that inform the public of the results of government activities. A good
internal control system is necessary to assist local officials in meeting all their responsibilities.
In this session, we will focus on the following areas:
Page #
Background 1
What are Internal Controls? 1
Why are Internal Controls Important? 2
Who is Responsible for Internal Controls? 2
Key Components of Internal Control 3
Internal Control Examples 8
Top Ten Fraud Risk Indicators 10
Internal Control Checklist 10
Conclusions 11
Background
Internal controls have always been an important element of any local government’s financial and
operating structure. In the 1990’s, concerns about fraudulent financial reporting resulted in a
group being formed and a study on internal controls being produced. This group – the
Committee of Sponsoring Organizations (COSO) – developed a report that defined internal
control and identified five key components of internal control.
Internal Control, as defined in the COSO report, is “a process effected by the entity’s board of
directors, management, and other personnel, designed to provide reasonable assurance
regarding the achievement of objective in effectiveness and efficiency of operations, reliability
of financial reporting, and compliance with applicable laws and regulations.”
1
Internal Controls
* Protection of Assets
* Effectiveness and Efficiency of Operations
* Reliability of Financial Reporting
* Compliance with Applicable Laws and Regulations
Consequences of weak internal controls can be the waste or misuse of the local government’s
assets, inaccurate or incomplete information, and embezzlement and theft.
The Governing Board provides important oversight while the Chief Executive
Officer provides leadership and direction to the governance team
(management/leadership team).
2
Internal Controls
The Governing Board and the Chief Executive Officer are responsible for
establishing the presence of integrity, ethics, competence, and a positive control
environment.
The Governing Board is also responsible for establishing major operating policies
that form the foundation of the internal control system.
The Chief Executive Officer is responsible for establishing government-wide
regulations/procedures to ensure implementation of the major operating policies.
The governance team provides direction and oversight to senior administrators in
major functional areas such as general operations, departments, auxiliary
operations, and support services.
The Chief Fiscal Officers, Managers, Administrators, directors, and departments
execute the major government-wide control policies and procedures. They may
also design and implement control systems at detailed levels within their specific
units.
Managers and other supervisory personnel are responsible for executing control
policies and procedures at detailed levels within their specific units.
Each individual within a local government or unit is responsible for being
cognizant of proper internal control procedures associated with their specific job
responsibilities.
Claims auditors are responsible for auditing claims and internal auditors are
responsible for examining the adequacy & effectiveness of the local government’s
internal controls, and making recommendations where control improvements are
needed. Internal auditors contribute to the effectiveness of the controls, but they
are not responsible for establishing or maintaining them.
As you can see, every administrator, manager and staff member is responsible for assuring that
established internal controls are followed and applied.
We will now discuss each of these components and how they can be used in improving an
internal control system.
3
Internal Controls
Control Environment
This is also referred to as the “tone at the top.” It is the foundation for all other components of
internal control, providing discipline and structure. Factors include the integrity and ethical
values and competence of the unit’s people, management’s philosophy and operating style, the
way management assigns authority and responsibility, organizes and develops its people and the
attention and direction provided by the governing board.
Integrity and Ethical Values- Integrity and ethical behavior are essential elements of the
control environment. As the Treadway Commission 1 reported, “A strong ethical climate at all
levels is vital to the well being of the entity, all of its constituencies and the public at large.” The
key element in a favorable control environment is management’s attitude, as demonstrated
through its actions and example.
An example of unethical behavior by board members gives the green light to all employees of
the unit to follow their example. A couple of years ago a state commissioner was accused of
taking his state vehicle to Florida for vacation. What kind of example do you think that gave to
the employees of his department?
On a more familiar level, what would employees of your municipality think if the board
members’ travel or conference expenses bypassed the usual audit function of your municipality?
What kind of example would that give to the poor employee whose expense accounts were gone
over with a fine toothcomb?
Establish and maintain up-to-date job descriptions for all employees. These
descriptions should detail the responsibilities of each position as well as the
qualifications needed to fill the position. It is important that job descriptions be kept
up to date to reflect changes in responsibilities.
1
The Treadway Commission was created in 1985 to identify the causal factors of fraudulent financial reporting and
to make recommendations to reduce its incidence.
4
Internal Controls
Ensure that employees are properly trained. A combination of formal and on-the-
job training is essential to ensure that employees are properly prepared to perform
their duties. Moreover, training should be offered on an ongoing basis to reinforce
existing skills and to help employees adjust to changes in their job responsibilities
and work environment.
Periodically review and document performance. It is not enough to hire honest and
qualified individuals; management must also periodically review their performance
and document that review. When corrective action is needed that action should be
taken promptly and should be thoroughly documented. It is especially important
that management pay particular attention to the performance of employees during
their initial probation period of employment. Also, top management should
periodically review the performance evaluations to ensure that managers at all
levels are giving frank and objective evaluations of performance.
If a unit’s control environment is lacking, it is a good indication that severe problems exist in
some of its internal control processes. This does not say that severe problems exist in all its
internal control processes. The same holds true for all of the other COSO principals. It is merely
an indication not an absolute, because there is always the possibility that some other control
principle or authority has established the proper procedures or processes.
Managements Philosophy and Governing Style- This covers a wide range of characteristics. It
may include their approach to risk taking and monitoring risk and their attitude and actions
toward information processing, financial and operational reporting, and personnel.
Organization Structure- This is in reference to the departments and offices of the municipality.
Are they effective and conducive to controls and accountability?
Assigning Authority and Responsibility- What is the method of assigning authority and
responsibility? Does this method provide for the proper delegation of authority and
responsibility?
Role of the Governing Board- The elected board is responsible for establishing policies and
procedures that help ensure that the assets of the unit are protected.
5
Internal Controls
Risk Assessment
Risk assessment is one of the components and addresses the local government’s (not the
auditor’s) assessment of control risk. Risk Assessment is the local government’s identification
and analysis of relevant risks to achieving its objectives, forming a basis for determining how the
risks should be managed. This process identifies risk and analyzes its likelihood of occurrence
and its impact. This process will allow management to determine how much risk they are
willing to accept and to set priorities accordingly. Management may initiate plans, programs, or
actions to address specific risks, or it may decide to accept a risk because of cost (cost/benefit
analysis) or other considerations. The risk assessment is an ongoing process. Risks can arise or
change due to circumstances such as the following:
If the governing board alone is involved in assessing and monitoring risk, there is a good
possibility that many of the specific risks facing individual programs and activities will be
missed. Conversely, if a government’s risk assessment and monitoring is performed by lower
level managers, it is quite possible that more generalized risks may be completely overlooked.
6
Internal Controls
Accordingly, effective risk assessment and monitoring must include and involve managers at all
levels.
The basic concepts of the risk assessment process should be present in every entity, regardless of
size, but the risk assessment process is likely to be less formal and less structured in small and
mid-sized entities than in larger ones.
In a risk assessment process, the first step is to group naturally interrelated activities into
“control cycles.” After that, management should prioritize the examination of controls by
department, activity, or control cycles based upon the perceived degree of “vulnerability” by
considering the risk’s impact, and likelihood of occurrence. Once priorities have been
established, management should initiate the process of testing controls by documenting how
transactions and events are selected for evaluation. This documentation, which may take the
form of a narrative, memorandum or a flow chart, should clearly show who is responsible for
doing what. Management’s next step is to identify potential risks. Management then identifies
all of the related control policies and procedures designed to compensate for those potential
risks. The design of each compensating control should be evaluated to determine whether the
control would be effective if it is operating as designed, followed by testing to see if the control
has actually been implemented and is operational. If management discovers that controls are not
working properly, they should be amended, or steps should be taken to improve compliance.
Throughout this process, management needs to consider that the costs of the controls do not
exceed their benefit.
Control Activities
Control Activities are the policies established by the board and procedures developed by the
board, department heads, or others in order to be in conformance with these policies. Policies are
usually adopted in order to control the various risks identified in the unit’s risk assessment and in
some cases, in order to be in conformance with various laws, rules and regulations. Some of
these policies that I’m sure you are all familiar with are the Procurement Policy, the
Investment Policy and the infamous Standard Workday Policy for retirement reporting
purposes.
Once policies are adopted, the concerned departments or functions must develop procedures in
order to ensure that the policies are followed. These procedures must ensure that proper
separation of duties is observed. The procedure must also ensure that proper reporting and
reconciliations are adopted, proper authorizations are received, proper security of assets and
records is maintained, periodic verifications are performed, and analytical reviews are
performed.
7
Internal Controls
The information and communication component relates to the financial reporting process and, in
particular, the accounting system and underlying transactions. It consists of methods and records
established to identify, capture, and exchange information in a form and time frame that enables
people to carry out their responsibilities effectively, and to maintain accountability for the
related assets and liabilities. The information system should produce reports containing
operational, financial and compliance-related information that make it possible to run and
control the unit. Management should review the reports and use them in their decision-making
process. There is nothing worse than when you had the necessary information in order to make
the correct decision and did not utilize it.
Monitoring
Once the governing board, in conjunction with management, has assessed the risk potential of
the various processes within the municipality, a schedule of review should be planned and
outlined. This monitoring also applies to the various policies passed by the board. All major
policies should not be passed and then forgotten. Time has a way of changing the circumstances
and conditions from when the policy was first passed. On at least a yearly basis all policies
should be reviewed and a determination made as to whether they should be amended.
There are many more controls but these give you the general idea.
8
Internal Controls
There is no absolute control system for any transaction cycle including cash receipts, but there
are certain control procedures that are usually effective. For cash receipts they include:
Central Cash Receipts Function - Generally, the more central the cash receipts function is,
the better it can be from an internal control standpoint. It allows management to properly
segregate duties and provide good physical controls.
Individual Accountability – Each individual collecting cash should be individually
responsible for their accountability (i.e., have their own cash drawer and accountability
records). This ensures that, if there is a problem, the problem can be pinpointed.
Point of Sale Control - This means that the individual making the payment provides the
control (e.g., a cash register that has a visible amount rung up, a sign that says that you
should be sure to ask for a receipt).
Control of Forms - These could be press-numbered duplicate receipt forms, permit forms,
etc., that are controlled and reconciled by someone other than the person collecting cash.
Timely Recording and Deposit - Ideally, cash should be recorded by some method at the
same time it is received. This recording could be in a cash receipts book, on duplicate
receipts or by other methods. Deposits should be made daily or more often if necessary.
This control helps to prevent major loss by theft.
Segregation of Duties - The same person receiving cash should not be responsible for
recording receipts in detail customer accounts, enforcing of unpaid accounts or reconciling
control or bank accounts.
Periodic Reconciliations - This is the reconciliation of cash per books to cash in banks at
least once a month by someone independent of the cash collection or enforcement functions.
The key word here is "Independent.” The following tend to be effective internal controls for
cash disbursements:
Independent Central Receiving Function - Goods are received and receiving slips are
verified and signed before the goods go to the department that ordered them. This process
helps to make sure that goods are actually received prior to payment for them.
Independent Central Accounting Function – All the accounting functions are handled
through one central office, usually the business office.
Independent Central Pre-Audit Function- The review of claims for completeness,
authorization, itemization, legality, etc., prior to payment is a pre-audit function. This should
be defined and well-documented in order to be most effective. This is usually the
responsibility of the internal auditor if there is one.
Independent Check Signing and Mailing - The signing of authorized checks and mailing
them directly to the vendors. It also includes the control of blank checks and the control of
signature plates to protect against unauthorized use.
9
Internal Controls
Just to reemphasize how important internal controls are, the Ohio State Auditor reported the
following top ten risk indicators in school districts in Ohio:
In order to minimize the risk of fraud or abuse in your school district, the following checklist
will assist you:
10
Internal Controls
Conclusions
As a result of increasing pressure on local governments, well-planned and documented internal
control procedures are being recognized as becoming increasingly important in controlling local
government financial operations. Local government managers must recognize this increasing
importance and implement an improved control environment and additional or improved control
procedures where a well thought out cost/benefit analysis indicates they would be cost effective.
While the final decision on improved control procedures rests with the management of the local
government, management should keep in mind that there is always more than one way, and
almost always a cost effective way, to improve control procedures. Lastly, documentation of
existing control environment, accounting system, and control procedures generally has the effect
of improving controls and making them more effective.
11