




版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
1、13.SOX Documentation and Requirement 4. A statement that the external auditor has issued an attestation report on managements assessment.13.SOX Documentation and Requirement 13.SOX Documentation and Requirement 6. Safeguarding - Assets are adequately safeguarded from misappropriation or use.7. Segre
2、gation of Duties - Authorization, custody, recording, and controlling are adequately segregated.13.SOX Documentation and Requirement 13.SOX Documentation and Requirement Control 1: VMM can only create / change the master vendor file based on approved forms and then the VMM double check the creation
3、/ change. Control 2: VMM runs SAP run vendor master change log and new vendor creation change log weekly, then deputy of VMM check the change log against the approved application form. PControl 1: Sales staff updates SAP based on the approved SAP Customer creation / change form with information of c
4、ustomers name, address, telephone no, fax no., proposed payment terms and order amount when opening a new customer account.Control 2: Sales staff runs SAP run customer master change log and new customer creation change log weekly, then deputy of sales staff checks the change log against the approved
5、 Customer creation / change form.PControl 1: The company follows the group policy and country policy. Control 2: Before engaging each hedging transaction, the accounting manager reviews and confirms whether the transaction is complied with the group policy - when PO is in place, it should be hedged.
6、 Then the FC approves the transaction in accordance with approved Group hedging policy. P13.SOX Documentation and Requirement Control 1: SAP required enter fields to remind VMM to fill all necessary information. Control 2: VMM runs SAP vendor master change log and new vendor creation change log week
7、ly, then deputy of VMM check the change log against the approved application form. P13.SOX Documentation and Requirement Key Controls Example (Purchasing & AP Process)Control 1 - All purchase orders are authorized by the purchase manager.Control 2 - All purchase orders are sequentially numbered
8、and entered into the SAP.Control 3 - Goods received are inspected and received in to the store, a Goods Received Note (GRN) is prepared and signed by the storekeeper and entered in the SAP.Control 4 - Invoices are received by the SSC, who check authorization of purchase, details of goods ordered, ma
9、terial received, details and pricing on the invoice before releasing payment (Three point matching).All these are important controls that must be documented and evaluated.This is a Key Control, which when tested will give you the comfort that all the 4 controls are operating effectively.Purchasing a
10、nd Accounts Payable Controls13.SOX Documentation and Requirement DeficienciesDesign DeficienciesOperating Deficiencies1.a control necessary to address a financial reporting risk is missing2.an existing control is not properly designed so that, even if the control operates as designed, the financial
11、reporting risk may not always be addressedFor an existing control, which is properly designed, while due to the responsible staff intentionally or unintentionally doesnt follow the designed control procedure during operating, the financial reporting risk may not be addressed13.SOX Documentation and
12、Requirement 13.SOX Documentation and Requirement Controls will be assessed twice; once for design effectiveness and once for operational effectiveness. If either assessment leads to the conclusion that the control is not working, an action plan must be developed.Documentcontrol Testcontrol Update de
13、ficiency log and developan action planEntity will continue to monitor control effectiveness Is control designed effectively?Is control operating effectively?YesYesNoNoTest of ControlRemediedAssessmenttechniquesExplanation“SOXProof”Re-performanceAscertain if the control iseffective by repeating the c
14、ontrolactivityYesExaminationAscertain if the control iseffective by inspecting evidence(records, documents, reports etc.)that the control activity has beenperformed properlyYesObservationAscertain if the control iseffective by watching it beingperformed by the relevantpersonnelNoInquiryAscertain if
15、the control iseffective by asking questions tothe relevant personnel.NoLevel ofcomfortRISKSCONTROLS KEY CONTROLS1234567ABCDENA.NA.ADEXProcess TemplateControl typeAssessmentinstructionExampleReconciliationand Cut-offcontrolTrace the reconcilingtotals to the source orsupporting document.Review the rec
16、oncilingitems forreasonableness.Bank reconciliation: Tracethe GL cash balance andthe bank statementbalance to the sourcedocument. Review thereconciling items for itemsmore than 3 months oldand for unusually largeamounts.Control typeAssessmentinstructionExampleCompliancewith policiesand proceduresand
17、 Educationand trainingThis is usuallycovered by interviewwith relevantpersonnel followed bya review of evidencethat the control wasperformed.Upon resignation orretirement, an employeeexit checklist iscompleted to ensure thatnecessary properties arereturned, access to thecompany is cancelled andpayro
18、ll is informedaccordingly. This can bereviewed by reviewing anemployee file forevidence of the checklist.Control typeAssessmentinstructionExampleVerification orvouching andArithmeticaccuracyThis is usually doneby re-performance ofthe control activity.That is, performexactly the samechecks done by th
19、econtrol executor.To test the 3 way matchof supplier invoice.Perform the 3 way matchfor the sample selected,ensuring the match forsupplier ID and name,description of goodspurchased, quantity andprice.Control typeAssessment instructionReview andAuthorisationThis is usually done by looking for evidenc
20、e ofreview or authorisationSegregation ofdutiesThis is usually done by interviewing the relevantmanager of the function, supported by observationof the actual activity. For segregation enforced bythe system, testing can be done by reviewing a listof user access generated from the system.Physical acc
21、esscontrolThis is usually done by interviewing the relevantmanager of the function, supported by observationof the actual activity.Control typeAssessment instructionIT configurationor programmedcontrolThis can usually be tested by a systemswalkthroughIT accesscontrolThis can usually be tested by rev
22、iewing a list ofusers access generated from the system.have been achieved.Note: If the sample size available is less than the targeted sample size, the sample should be 100% of the available population.13.SOX Documentation and Requirement 13.SOX Documentation and Requirement DocumentationA. Document
23、sub-processesB. DocumentRisks &ControlsD. Assess ControlsE.AssessRisks F. Report &sign-offG. Audit & final sign-offH. Filing to SEC and archiveAssessmentsReporting & sign-offExecutionC.ExecuteControlsA. Documentsub-processesB. DocumentRisks &ControlsC.ExecuteControlsD. Assess Con
24、trolsE.AssessRisks F. Report &sign-offG. Audit & final sign-offH. Filing to SEC and archiveThreshold inMillions ofU.S. DollarsMinimumAccountCoverage25.0 a5.0 60%2.0 60%2.0 60%0.5 60%aMinimum account coverage achieved through the selection of significant locations.LevelGroupSub-reporting Unit
25、LocationClass of TransactionsReporting UnitReporting UnitMinimum Account Coverage Balance3Sub-reporting Unit 1Account balance2.1 aSub-reporting Unit 2Account balance0.8 bSub-reporting Unit 3Account balance0.7 bSub-reporting Unit 4Account balance0.6Other Sub-reporting Units Account balanceless than 0
26、.6a. Significant Accounts identified by thresholdsb. Significant Accounts identified by minimum coverageRemote( or = 5%of Occurence)ThresholdSignificantAccountsInsignificantAccountsPossible SignificantAccountsConsider QualitativeFactorsMagnitude of AccountLikelihood of MisstatementFactorAssessment C
27、riteriaQuantitative Factor Size and composition of accountPrior year end actual results and current year end forecast in excess of established threshold or not in excess of established thresholdQualitative Factors Nature of account (for example, suspense accounts generally warrant greater attention)
28、Routine, Non-routine, or EstimationVolume of activity processedLow or HighA. Documentsub-processesB. DocumentRisks &ControlsC.ExecuteControlsD. Assess ControlsE.AssessRisks F. Report &sign-offG. Audit & final sign-offH. Filing to SEC and archiveA. Documentsub-processesB. DocumentRisks &a
29、mp;ControlsC.ExecuteControlsD. Assess ControlsE.AssessRisks F. Report &sign-offG. Audit & final sign-offH. Filing to SEC and archivelThe execution of control activities should be the part of the day to day business activities performed by the relevant personnel. lIn this step, we perform a g
30、ap analysis between the control activities in step B and C. Develop action plan to implement missing control activitiesA. Documentsub-processesB. DocumentRisks &ControlsC.ExecuteControlsD. Assess ControlsE.AssessRisks F. Report &sign-offG. Audit & final sign-offH. Filing to SEC and archi
31、velThe execution of the control activities needs to be reviewed on a regular basis to ensure that the control activities are effectivelThe assessment should be performed by someone independent of the execution of the controlExample: To continue from the previous example,Control assessor: AP managerA
32、ssessment instruction: Select 3 items for payment. Trace to supplier invoice, review for evidence of receipt of goods (goods received notes) or services (acknowledgement by recipient).Assessment frequency: QuarterlyA. Documentsub-processesB. DocumentRisks &ControlsC.ExecuteControlsD. Assess ControlsE.AssessRisks F. Report &sign-offG
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 2025年综合类-内科住院医师-卫生法规历年真题摘选带答案(5套单选100题合辑)
- 2025年综合类-内燃机械修理工考试-内燃机械修理工(高级)历年真题摘选带答案(5套单选100题合辑)
- 2025年综合类-内分泌专业知识-甲状腺疾病历年真题摘选带答案(5套单选100题合辑)
- 2025年综合类-公卫执业医师-消化系统历年真题摘选带答案(5卷单选100题合辑)
- 2025年综合类-儿科专业实践能力-新生儿及新生儿疾病历年真题摘选带答案(5卷单选100题合辑)
- 2025年综合类-人力资源管理师(二级)-基础知识综合练习历年真题摘选带答案(5套单选100题合辑)
- 2025年综合类-主管中药师-中药鉴定学-根及根茎类中药历年真题摘选带答案(5卷单选100题合辑)
- 2025年综合类-临床医学检验学主治医师-麻醉主治医师-临床麻醉学历年真题摘选带答案(5套单选100题合辑)
- 2025年综合类-中级面点工-中级面点工-初级面点工历年真题摘选带答案(5卷单选100题合辑)
- 2025年综合类-中级房地产经济-第五章房地产投资项目经济评价历年真题摘选带答案(5卷单选100题合辑)
- 放射状角膜切开术并发症的长期随访研究-全面剖析
- 内衣类目测试题及答案
- 2025优化企事业单位突发环境事件应急预案备案的指导意见
- Excel表格公式培训
- GB/T 45341-2025数字化转型管理参考架构
- 2025年山西省华远国际陆港集团有限公司招聘笔试参考题库含答案解析
- 2025年腾讯云从业者基础认证题库
- 塞尔维亚语教学与学习作业指导书
- 关于麻将馆的创业计划书
- 口腔消毒培训
- UG练习图纸大全-65张-绝对受用
评论
0/150
提交评论