Heightened Threat Levels
I am member of an internet community, and one of our group in the USA sent a message yesterday; in which she expressed her worries regarding the heightened risk of terrorist attacks.
I offered her and the group my opinion, which I have posted below.
"Take heart, speaking as a Brit whose country endured five years of Nazi bombing and thirty odd years of the ocassional IRA bomb we have learnt one or two things.
1 Heightened anxiety, so long as it does not become uncontrolled panic, improves vigilance. The price of freedom is eternal vigilance.
2 FDR was correct when he said, albeit in response to different issues, "we have nothing to fear but fear itself".
3 Act on fact, not rumour.
4 Stiff upper lip, I know it is a trite and hackneyed expression. However, when the chips are down; believe me it is an effective weapon against those that seek to disrupt your lives and cause fear.
Resolution, determination and focus are the qualities that people need to "dig deep" for during periods of increased international upheaval."
In Your Face
In Your Face
Thought provoking opinions on topical issues.
Friday, March 21, 2003
Monday, February 10, 2003
Pro Forma Guideline on Internet Usage
Introduction
There has been some discussion as to the time spent by employees surfing the net, during working time. The management of some companies are beginning to feel concerned that this is proving to be a time wasting temptation to some members of staff. These companies, in response to this perceived threat, seek to limit employees access to the internet.
I myself have had personal experience of an organisation where those members of staff who wished to have access to the internet, and email facilities, had to complete a form; stating why they needed it. This form would then be assessed by a committee, if you were lucky you may have the connection up within six weeks!
This is of course totally absurd. We live in the 21st century, the internet has become part of our lives; whether the “ostriches of 19th century management” like it or not. Specifically, it isn’t going to go away!
It is my view that knowledge of both the contents, and techniques, of the internet enhance the individual’s skill set; and hence benefit the company he/she is employed by. I do recognise that, at times, the systems offered to employees can be abused. However, if you treat people as adults; explaining where the boundaries of reasonable/unreasonable usage lie, they will in general act responsibly.
Therefore I have put together a simple, non prescriptive, pro forma guideline that companies could incorporate into their codes of conduct (to read my article Codes of Conduct click here).
Guideline
This guideline is intended to form part of a company’s code of conduct. As such breaches of this guideline would constitute a breach of the code, and shall constitute a notifiable event; requiring registration and action (as deemed appropriate) by the management responsible for implementation of the code.
The company expects that staff will use the internet, email and telephone facilities in a responsible manner. The use of these facilities is encouraged, where the use is for business purposes and supports the goals and objectives of the company.
However, the company expects the following general principles to be adhered to :
The above systems are company assets; and as such should be used for business purposes. However, personal use of the internet may take place during non work time so long as it does not interfere with an employee’s performance and does not contravene the other rules laid out below.
It is in the interests of the company, and its employees, that individual members of staff are fully conversant with technological innovations such as the internet.
A cost conscious approach should be adopted by users when determining which facility to use, and when to use it, eg email is less expensive than a phone call.
The use of the facilities to access/distribute sexual, offensive, illegal, religious or political material is strictly prohibited.
Employees shall not allow others (including family members) to use the facilities.
Employees shall abide by the principle of privacy with regard to other individuals’ facilities, eg unless the owner has given permission, colleagues’ email boxes shall not be read.
The nature of the internet is such that it accessible to all (including “quacks”). Therefore, information retrieved from the internet, intended to be used for decision making purposes, should be validated for authenticity before being used.
It is a violation of company policy for any employee, including system administrator (other than for system maintenance) to access information of the system without the employee’s knowledge. However, access without the employee’s knowledge may occur where permission has been granted by senior management when they have taken legal advice.
The company retains the right to access and disclose information in these systems in order to protect its interests, or when required to by law. Accordingly, employees should not have any expectation of privacy regarding the use of these systems and information stored therein.
Employees who inadvertently access information or messages that are in breach of the above should notify their senior line manager.
There has been some discussion as to the time spent by employees surfing the net, during working time. The management of some companies are beginning to feel concerned that this is proving to be a time wasting temptation to some members of staff. These companies, in response to this perceived threat, seek to limit employees access to the internet.
I myself have had personal experience of an organisation where those members of staff who wished to have access to the internet, and email facilities, had to complete a form; stating why they needed it. This form would then be assessed by a committee, if you were lucky you may have the connection up within six weeks!
This is of course totally absurd. We live in the 21st century, the internet has become part of our lives; whether the “ostriches of 19th century management” like it or not. Specifically, it isn’t going to go away!
It is my view that knowledge of both the contents, and techniques, of the internet enhance the individual’s skill set; and hence benefit the company he/she is employed by. I do recognise that, at times, the systems offered to employees can be abused. However, if you treat people as adults; explaining where the boundaries of reasonable/unreasonable usage lie, they will in general act responsibly.
Therefore I have put together a simple, non prescriptive, pro forma guideline that companies could incorporate into their codes of conduct (to read my article Codes of Conduct click here).
Guideline
This guideline is intended to form part of a company’s code of conduct. As such breaches of this guideline would constitute a breach of the code, and shall constitute a notifiable event; requiring registration and action (as deemed appropriate) by the management responsible for implementation of the code.
The company expects that staff will use the internet, email and telephone facilities in a responsible manner. The use of these facilities is encouraged, where the use is for business purposes and supports the goals and objectives of the company.
However, the company expects the following general principles to be adhered to :
The above systems are company assets; and as such should be used for business purposes. However, personal use of the internet may take place during non work time so long as it does not interfere with an employee’s performance and does not contravene the other rules laid out below.
It is in the interests of the company, and its employees, that individual members of staff are fully conversant with technological innovations such as the internet.
A cost conscious approach should be adopted by users when determining which facility to use, and when to use it, eg email is less expensive than a phone call.
The use of the facilities to access/distribute sexual, offensive, illegal, religious or political material is strictly prohibited.
Employees shall not allow others (including family members) to use the facilities.
Employees shall abide by the principle of privacy with regard to other individuals’ facilities, eg unless the owner has given permission, colleagues’ email boxes shall not be read.
The nature of the internet is such that it accessible to all (including “quacks”). Therefore, information retrieved from the internet, intended to be used for decision making purposes, should be validated for authenticity before being used.
It is a violation of company policy for any employee, including system administrator (other than for system maintenance) to access information of the system without the employee’s knowledge. However, access without the employee’s knowledge may occur where permission has been granted by senior management when they have taken legal advice.
The company retains the right to access and disclose information in these systems in order to protect its interests, or when required to by law. Accordingly, employees should not have any expectation of privacy regarding the use of these systems and information stored therein.
Employees who inadvertently access information or messages that are in breach of the above should notify their senior line manager.
Tuesday, February 04, 2003
Wednesday, January 15, 2003
Risk Management
Introduction
There are those in the world who would have you believe you can live your life, and operate your business, without risk. Palpable nonsense in my opinion; risk is an implicit part of life. The issue is how we handle it.
I present below a high level overview of the key components to an effective risk management system.
I will begin with a couple of simple definitions:
Profit is the reward for risk.
Risk is an event/occurrence that hinders the achievement of the business objectives.
Companies exist to make profits, and as such will always be exposed to risk.
Companies are exposed each day to many changes (organisational, commercial, political, technological, etc.). The speed of those changes is reducing reaction time, and increasing the types and complexity of risks. Within such an environment risk assessment is essential for an effective and efficient management process. Risk assessment helps management to focus on the issues that really matter.
The Risk Assessment
Risk assessments should be primarily a management exercise. The fact that a company is constantly facing changing risks, requires that management makes use of a proactive approach to assess those risks; as well as developing an effective, and efficient, process to reduce risks to an acceptable level. This proactive approach should address the following areas:
Determine the risk appetite of the company - This is the responsibility of the Board, who must set the risk parameters (high, medium or low) that they are prepared for the company to operate within.
Clear risk identification - Managers should analyse the company’s external environment, and internal processes, in order to ensure that all potential business risks and their sources are identified. The question management should be constantly asking itself is “what could go wrong?”.
Risk assessment - Management should categorise risks on the basis of their significance (magnitude of the loss or missed opportunity), and the probability of occurrence (eg likelihood of the risk event occurring say within the next two years). When making the assessment management should take into account factors such as the size/value of transaction streams, and the financial impact on the organisation of the risk.
Definition of critical areas - Critical areas are those areas which are of major importance for the specific business eg sales, R&D, production; coupled with the outcome of the risk assessment. Namely a high magnitude risk in the sales department, coupled with a high probability of occurrence, would mean that the sales area would be deemed a critical area. Having identified the critical areas the management now have a risk map of their organisation.
Control of the (critical) areas - Management should review the adequacy of controls by means of a self assessment control checklist. Controls, eg hedging of foreign currency transactions, being the means by which the organisation achieves its objectives. Where control gaps are identified, necessary steps (corrective actions) should be taken to implement compensating controls that reduce the residual risks to acceptable levels. Care should be taken when implementing compensating controls; as excess controls waste scarce resources. However, it may be the case that controls will not mitigate the risk to an acceptable level; in which case alternative measures such as insurance, outsourcing or closing the activity should be considered.
Continuous self assessment of the process - Management should review the entire process on a regular basis, to make sure that the model applied to identify risks and the business controls in place are adequate. Where necessary, management should take corrective actions in order to guarantee the quality of the entire process.
The Role of Internal Audit
I am a great believer in the maxim “what gets measured gets done”. Internal audit has a vital role to play in reviewing, and giving an opinion on, the effectiveness of the risk management process. Specifically, it should:
Verify if a business risk assessment process is in place and up to date
Verify the quality of the business risk assessment process in place
Verify the quality of business controls and control self assessment
Stimulate corrective actions
Track the trend of improvement and deterioration
Conclusion
Risk management is not a one off exercise, but part of an ongoing process. As circumstances change so do the risks faced by organisations; it is essential that management keep there risk map “up to speed”.
There are those in the world who would have you believe you can live your life, and operate your business, without risk. Palpable nonsense in my opinion; risk is an implicit part of life. The issue is how we handle it.
I present below a high level overview of the key components to an effective risk management system.
I will begin with a couple of simple definitions:
Profit is the reward for risk.
Risk is an event/occurrence that hinders the achievement of the business objectives.
Companies exist to make profits, and as such will always be exposed to risk.
Companies are exposed each day to many changes (organisational, commercial, political, technological, etc.). The speed of those changes is reducing reaction time, and increasing the types and complexity of risks. Within such an environment risk assessment is essential for an effective and efficient management process. Risk assessment helps management to focus on the issues that really matter.
The Risk Assessment
Risk assessments should be primarily a management exercise. The fact that a company is constantly facing changing risks, requires that management makes use of a proactive approach to assess those risks; as well as developing an effective, and efficient, process to reduce risks to an acceptable level. This proactive approach should address the following areas:
Determine the risk appetite of the company - This is the responsibility of the Board, who must set the risk parameters (high, medium or low) that they are prepared for the company to operate within.
Clear risk identification - Managers should analyse the company’s external environment, and internal processes, in order to ensure that all potential business risks and their sources are identified. The question management should be constantly asking itself is “what could go wrong?”.
Risk assessment - Management should categorise risks on the basis of their significance (magnitude of the loss or missed opportunity), and the probability of occurrence (eg likelihood of the risk event occurring say within the next two years). When making the assessment management should take into account factors such as the size/value of transaction streams, and the financial impact on the organisation of the risk.
Definition of critical areas - Critical areas are those areas which are of major importance for the specific business eg sales, R&D, production; coupled with the outcome of the risk assessment. Namely a high magnitude risk in the sales department, coupled with a high probability of occurrence, would mean that the sales area would be deemed a critical area. Having identified the critical areas the management now have a risk map of their organisation.
Control of the (critical) areas - Management should review the adequacy of controls by means of a self assessment control checklist. Controls, eg hedging of foreign currency transactions, being the means by which the organisation achieves its objectives. Where control gaps are identified, necessary steps (corrective actions) should be taken to implement compensating controls that reduce the residual risks to acceptable levels. Care should be taken when implementing compensating controls; as excess controls waste scarce resources. However, it may be the case that controls will not mitigate the risk to an acceptable level; in which case alternative measures such as insurance, outsourcing or closing the activity should be considered.
Continuous self assessment of the process - Management should review the entire process on a regular basis, to make sure that the model applied to identify risks and the business controls in place are adequate. Where necessary, management should take corrective actions in order to guarantee the quality of the entire process.
The Role of Internal Audit
I am a great believer in the maxim “what gets measured gets done”. Internal audit has a vital role to play in reviewing, and giving an opinion on, the effectiveness of the risk management process. Specifically, it should:
Verify if a business risk assessment process is in place and up to date
Verify the quality of the business risk assessment process in place
Verify the quality of business controls and control self assessment
Stimulate corrective actions
Track the trend of improvement and deterioration
Conclusion
Risk management is not a one off exercise, but part of an ongoing process. As circumstances change so do the risks faced by organisations; it is essential that management keep there risk map “up to speed”.
Tuesday, January 14, 2003
Contingency Planning
Given the current world-wide tensions, and risks of terrorist attacks, I feel that it is appropriate to address the issue of contingency (disaster) planning.
This is one area often overlooked by organisations. However, it is an area which they can ill afford to neglect. A major disaster such as a fire, bomb attack or flood can threaten the ongoing activities and profitability of the organisation; either directly by destroying or incapacitating an office or factory, or by disrupting the activities of key suppliers of eg IT, telecom or raw materials.
Adequate contingency planning should ensure that the organisation can continue to function and be able to process orders and transactions etc, in the event of a disaster outside of its control; eg a fire destroying the mainframe or a bomb destroying a key piece of infrastructure.
Key features of effective contingency planning include the following:
Ensure that members of the organisation know what procedures to follow in the event of a disaster, ie there should be a written contingency plan, copies of which are distributed to all members of personnel.
There should be of a list of off site telephone numbers from where to obtain instructions as to what to do.
There should be a team of managers assigned the task of managing the disaster.
Accommodation should be available, eg spare offices or a hotel off site, where telephones and computer cables etc can be installed in a relatively short period of time.
Spare capacity on an off site computer should be available; either using the mainframe of another unit within the same organisation, or a third party machine on which the right to access is purchased by an annual fee.
There should, at least once a year, be a practice disaster to ensure that the plans do operate as expected. The results of the dry runs should be analysed and any improvements arising from them be implemented, and communicated, to the employees as soon as possible.
I have put together a “high level” checklist below which provides a good starting point for organisations wishing to review the effectiveness of their contingency planning. Areas which are found wanting should be addressed.
1. Have all assets that are essential to the continuation of the business been identified; eg staff, equipment, intellectual property, materials and telecommunications?
2. Have the potential costs and impact of not having a business continuity plan been identified eg lost business, legal implications, credibility?
3. Is there a disaster team (membership to include HRM, building facility manager, building security manager, communication manager, key user management representatives)?
4. Is there a list of personnel authorised to declare a disaster?
5. Are there procedures in place to mobilise the disaster team?
6. Does each member of the team have primary and secondary contact numbers?
7. Does each member of the team know his/her duties?
8. What are the notification procedures for communicating to members of staff during a disaster?
9. Does every member of staff have procedural documentation for what to do in a disaster?
10. Is there a list of contact numbers for members of staff to use in the event of disaster?
11. Is there an alternative site to use in the event of non accessibility to normal site caused through eg fire, power failure etc?
12. Does this alternative site have adequate facilities for IT, telecommunications etc?
13. Do personnel have maps/directions to the alternative site?
14. Is there insurance cover for both loss of income and costs of business resumption?
15. Is there suitable power back up, eg on site generator, in the event of a power failure?
16. Are all IT back up procedures re software and hardware adequate in the event of fire, power failure etc? Bear in mind power failure may occur, when no one is on site to shut down the systems.
17. Are all key back up documents, tapes, discs etc stored offsite in fireproof waterproof containers?
18. Is there a procedure, and person responsible, for communicating to the press etc during the disaster?
19. In the event that the normal business site cannot be used during the disaster is there adequate security to prevent unauthorised access?
20. Have compliance certificates been obtained from third parties eg banks, utilities, landlords, warehouses and suppliers?
21. Are there documented procures that detail how to obtain emergency funds in the event of disaster, eg collapse of the local banking system?
Do you know what to do in the event of a disaster? Should you work for an organisation where there are gaps in the contingency plans, then draw their attention to this checklist.
This is one area often overlooked by organisations. However, it is an area which they can ill afford to neglect. A major disaster such as a fire, bomb attack or flood can threaten the ongoing activities and profitability of the organisation; either directly by destroying or incapacitating an office or factory, or by disrupting the activities of key suppliers of eg IT, telecom or raw materials.
Adequate contingency planning should ensure that the organisation can continue to function and be able to process orders and transactions etc, in the event of a disaster outside of its control; eg a fire destroying the mainframe or a bomb destroying a key piece of infrastructure.
Key features of effective contingency planning include the following:
Ensure that members of the organisation know what procedures to follow in the event of a disaster, ie there should be a written contingency plan, copies of which are distributed to all members of personnel.
There should be of a list of off site telephone numbers from where to obtain instructions as to what to do.
There should be a team of managers assigned the task of managing the disaster.
Accommodation should be available, eg spare offices or a hotel off site, where telephones and computer cables etc can be installed in a relatively short period of time.
Spare capacity on an off site computer should be available; either using the mainframe of another unit within the same organisation, or a third party machine on which the right to access is purchased by an annual fee.
There should, at least once a year, be a practice disaster to ensure that the plans do operate as expected. The results of the dry runs should be analysed and any improvements arising from them be implemented, and communicated, to the employees as soon as possible.
I have put together a “high level” checklist below which provides a good starting point for organisations wishing to review the effectiveness of their contingency planning. Areas which are found wanting should be addressed.
1. Have all assets that are essential to the continuation of the business been identified; eg staff, equipment, intellectual property, materials and telecommunications?
2. Have the potential costs and impact of not having a business continuity plan been identified eg lost business, legal implications, credibility?
3. Is there a disaster team (membership to include HRM, building facility manager, building security manager, communication manager, key user management representatives)?
4. Is there a list of personnel authorised to declare a disaster?
5. Are there procedures in place to mobilise the disaster team?
6. Does each member of the team have primary and secondary contact numbers?
7. Does each member of the team know his/her duties?
8. What are the notification procedures for communicating to members of staff during a disaster?
9. Does every member of staff have procedural documentation for what to do in a disaster?
10. Is there a list of contact numbers for members of staff to use in the event of disaster?
11. Is there an alternative site to use in the event of non accessibility to normal site caused through eg fire, power failure etc?
12. Does this alternative site have adequate facilities for IT, telecommunications etc?
13. Do personnel have maps/directions to the alternative site?
14. Is there insurance cover for both loss of income and costs of business resumption?
15. Is there suitable power back up, eg on site generator, in the event of a power failure?
16. Are all IT back up procedures re software and hardware adequate in the event of fire, power failure etc? Bear in mind power failure may occur, when no one is on site to shut down the systems.
17. Are all key back up documents, tapes, discs etc stored offsite in fireproof waterproof containers?
18. Is there a procedure, and person responsible, for communicating to the press etc during the disaster?
19. In the event that the normal business site cannot be used during the disaster is there adequate security to prevent unauthorised access?
20. Have compliance certificates been obtained from third parties eg banks, utilities, landlords, warehouses and suppliers?
21. Are there documented procures that detail how to obtain emergency funds in the event of disaster, eg collapse of the local banking system?
Do you know what to do in the event of a disaster? Should you work for an organisation where there are gaps in the contingency plans, then draw their attention to this checklist.
Monday, January 06, 2003
Attributes of a World Class Internal Audit Department
In my roles as Head of Internal Audit and International Forensic Co-ordinator, in both Philips and De Beers, I have had many years of experience setting up and running audit departments. Based on this experience I have put together my personal “top ten” list of attributes that make up a world class internal audit department.
1. Independent – an internal audit department that is not independent, or seen to be independent, is no use to man nor beast. Independence is functionally achieved through establishing a clear, direct reporting line to the audit committee (which itself should be comprised of independent non executive directors). Additionally, independence is maintained by ensuring that reports are fair and objective (not bending to the wills of dominant CEO’s) by senior review within the department; and ensuring that audit assignments are rotated so that members of the department do not become too close to the operational management of specific business units.
2. Approachable – contrary to popular belief the internal audit department is not the Gestapo. The department should report on business operations, risks and controls in an independent, fair and objective manner. Additionally, it should be the source of best practice advice; management should feel that they can raise an issue with the members of the department and obtain constructive, informed advice on that issue.
3. Communicative – the primary role of the department is to report on the adequacy of the business controls and effectiveness of the risk management process. Therefore by definition the reports need to be clear, concise and relevant. In order to garner information for the preparation of the report auditors need to interview people at various levels within the organisation. Additionally, where a situation arises that requires the attention of the Board this should be communicated in an effective and prompt manner. Members of the department therefore need high level communication skills, both written, oral and “soft”.
4. Deadline orientated– businesses are deadline orientated and so, by definition, should be the internal audit department. Reports need to be issued on a timely basis; a report that takes six months to clear is of no use, as the events on which it has been based have moved on. At the commencement of a review the deadline for publication of the report (after clearing the draft for errors with management) should be clearly stated, and accepted by auditor and “client”.
5. Appropriate mix of skill sets– internal audit departments should be staffed by people with skill sets, and experience, appropriate to the business. This would include people with IT, management, commercial and technical experience. Additionally, the department should have an appropriate cross section of career auditors and fast track trainees (who stay no more than two years in the department before moving on to line management).
6. Technically up to date – the members of the department should be up to date with technical and other issues relevant to the business, eg corporate governance. This can be maintained by internal/external training courses, and regular meetings with other bodies such as the external auditors.
7. High ethical principles– should the members of the audit department be regarded (rightly or wrongly) by other members of the organisation as being anything other than beyond reproach, then their ability to carry out their role effectively has been nullified. To ensure that ethical standards are maintained the company’s code of conduct should be strictly adhered to, and the acceptance of gifts from management/staff within the organisation being audited forbidden.
8. Flexibility – members of the department must be prepared to travel, and work in a variety of situations; such as international assignments, frauds, special management requests and due diligences.
9. Audit charter– this is an essential requirement as this document enshrines the mission, independence, reporting lines, right of access to documents/people and modus operandi of the department. The charter must be signed by the senior members of the board, to show their commitment to an independent function, and distributed to all senior management.
10. Commercially literate– members of the internal audit department must be commercially literate; understanding the general nature of business eg, marketing, logistics, cash flow etc. Additionally, they should have a specific understanding of the nature of the business which they are reviewing eg; risks, competition, results, market, suppliers, business plan etc. This will ensure that the review will be tailored to the needs of the organisation.
It goes without saying that the audit department should possess the basic operational attributes such as budgeting, planning and recording its work.
1. Independent – an internal audit department that is not independent, or seen to be independent, is no use to man nor beast. Independence is functionally achieved through establishing a clear, direct reporting line to the audit committee (which itself should be comprised of independent non executive directors). Additionally, independence is maintained by ensuring that reports are fair and objective (not bending to the wills of dominant CEO’s) by senior review within the department; and ensuring that audit assignments are rotated so that members of the department do not become too close to the operational management of specific business units.
2. Approachable – contrary to popular belief the internal audit department is not the Gestapo. The department should report on business operations, risks and controls in an independent, fair and objective manner. Additionally, it should be the source of best practice advice; management should feel that they can raise an issue with the members of the department and obtain constructive, informed advice on that issue.
3. Communicative – the primary role of the department is to report on the adequacy of the business controls and effectiveness of the risk management process. Therefore by definition the reports need to be clear, concise and relevant. In order to garner information for the preparation of the report auditors need to interview people at various levels within the organisation. Additionally, where a situation arises that requires the attention of the Board this should be communicated in an effective and prompt manner. Members of the department therefore need high level communication skills, both written, oral and “soft”.
4. Deadline orientated– businesses are deadline orientated and so, by definition, should be the internal audit department. Reports need to be issued on a timely basis; a report that takes six months to clear is of no use, as the events on which it has been based have moved on. At the commencement of a review the deadline for publication of the report (after clearing the draft for errors with management) should be clearly stated, and accepted by auditor and “client”.
5. Appropriate mix of skill sets– internal audit departments should be staffed by people with skill sets, and experience, appropriate to the business. This would include people with IT, management, commercial and technical experience. Additionally, the department should have an appropriate cross section of career auditors and fast track trainees (who stay no more than two years in the department before moving on to line management).
6. Technically up to date – the members of the department should be up to date with technical and other issues relevant to the business, eg corporate governance. This can be maintained by internal/external training courses, and regular meetings with other bodies such as the external auditors.
7. High ethical principles– should the members of the audit department be regarded (rightly or wrongly) by other members of the organisation as being anything other than beyond reproach, then their ability to carry out their role effectively has been nullified. To ensure that ethical standards are maintained the company’s code of conduct should be strictly adhered to, and the acceptance of gifts from management/staff within the organisation being audited forbidden.
8. Flexibility – members of the department must be prepared to travel, and work in a variety of situations; such as international assignments, frauds, special management requests and due diligences.
9. Audit charter– this is an essential requirement as this document enshrines the mission, independence, reporting lines, right of access to documents/people and modus operandi of the department. The charter must be signed by the senior members of the board, to show their commitment to an independent function, and distributed to all senior management.
10. Commercially literate– members of the internal audit department must be commercially literate; understanding the general nature of business eg, marketing, logistics, cash flow etc. Additionally, they should have a specific understanding of the nature of the business which they are reviewing eg; risks, competition, results, market, suppliers, business plan etc. This will ensure that the review will be tailored to the needs of the organisation.
It goes without saying that the audit department should possess the basic operational attributes such as budgeting, planning and recording its work.
Friday, December 20, 2002
The Added Value of Internal Audit, a Brief Overview
There is a joke which sums up some peoples’ attitudes to internal audit; it goes as follows:
“There is a pint glass, it contains half a pint of milk.
The optimistic manager says that the glass is half full.
The pessimistic manager says that the glass is half empty.
The internal auditor says that the milk is sour.”
Well I suppose, having run international internal audit departments in Philips and De Beers, I could be accused of being prejudiced. However, I firmly believe that a well run, independent and pro active internal audit department can add significant value to an organisation and its connected parties (such as shareholders).
I would point out that had the internal audit departments in both Enron and WorldCom operated in a professional and independent manner; then the gross mismanagement and corruption in these two companies would, in my opinion, not have occurred.
So how can an internal audit department add value? I will start with the basic, textbook, definition of the role of internal audit.
Internal audit provides independent objective assurance to the Board as to the adequacy of the business controls, and the effectiveness of the risk management and risk identification process.
In other words, the internal audit department should tell the Board when the company is being poorly managed, where risks are not being identified or mitigated and when the business objectives are not likely to be met.
In addition to this very wide ranging remit, a well run internal audit department adds value in the following ways:
It acts as a training ground for future line managers, by exposing fast track members of the department to a variety of situations, activities and functions within the organisation.
It provides a “one stop shop” for best practice advice.
It provides an independent, objective opinion as to the quality of the business controls.
It stimulates risk awareness throughout the organisation.
It is a source of qualified, experienced talent that can aid management in business improvement programmes.
It provides specialist professional independent opinions on a variety of situations; such as due diligence exercises.
It reports on fraudulent activity within the organisation, with a view to understanding how it happened and how to prevent it occurring again.
It ensures that the company wide initiatives, such as a code of conduct, are being adhered to.
I will expand on the subjects of business controls, risks (click here for risk article) and what constitutes a well run audit department (click here for the latter) in forthcoming articles.
“There is a pint glass, it contains half a pint of milk.
The optimistic manager says that the glass is half full.
The pessimistic manager says that the glass is half empty.
The internal auditor says that the milk is sour.”
Well I suppose, having run international internal audit departments in Philips and De Beers, I could be accused of being prejudiced. However, I firmly believe that a well run, independent and pro active internal audit department can add significant value to an organisation and its connected parties (such as shareholders).
I would point out that had the internal audit departments in both Enron and WorldCom operated in a professional and independent manner; then the gross mismanagement and corruption in these two companies would, in my opinion, not have occurred.
So how can an internal audit department add value? I will start with the basic, textbook, definition of the role of internal audit.
Internal audit provides independent objective assurance to the Board as to the adequacy of the business controls, and the effectiveness of the risk management and risk identification process.
In other words, the internal audit department should tell the Board when the company is being poorly managed, where risks are not being identified or mitigated and when the business objectives are not likely to be met.
In addition to this very wide ranging remit, a well run internal audit department adds value in the following ways:
It acts as a training ground for future line managers, by exposing fast track members of the department to a variety of situations, activities and functions within the organisation.
It provides a “one stop shop” for best practice advice.
It provides an independent, objective opinion as to the quality of the business controls.
It stimulates risk awareness throughout the organisation.
It is a source of qualified, experienced talent that can aid management in business improvement programmes.
It provides specialist professional independent opinions on a variety of situations; such as due diligence exercises.
It reports on fraudulent activity within the organisation, with a view to understanding how it happened and how to prevent it occurring again.
It ensures that the company wide initiatives, such as a code of conduct, are being adhered to.
I will expand on the subjects of business controls, risks (click here for risk article) and what constitutes a well run audit department (click here for the latter) in forthcoming articles.
Wednesday, December 18, 2002
Characteristics of a Well Managed Organisation
My experiences whilst working with KPMG, Philips and De Beers have given me a detailed understanding as to what constitutes a well managed organisation. I have put together my personal “top ten” list of the characteristics of a well managed organisation.
1. The organisation has a mission statement which is clearly communicated, and understood, by all members of the organisation. This will form the basis of the bsuiness plan.
2. The organisational structure is clearly defined, understood and appropriate for the activities carried out. Specifically, with regard to human reporting lines, there should be no dual/dotted reporting lines; these clutter up the clarity of the decision making process and cause conflict within the organisation. With regard to the actual organisational structure, this should be as “clean” and transparent as possible; complex off balance sheet arrangements at best confuse, and worst are deliberate attempts to obfuscate reality from interested parties (such as the Internal Revenue Service). In respect of the latter, I draw your attention to Enron.
3. The management of the organisation should clearly delegate responsibility for activities to those most appropriately qualified to perform them.
4. Targets and key performance indicators should be appropriate to the organisation’s mission, and be clearly communicated and understood. They should be stretching, but achievable; above all they should be measurable.
5. Management information must be timely, accurate, relevant and reliable. What gets measured gets done!
6. Management should take appropriate, timely, corrective actions in the event that targets are not being achieved.
7. There must be appropriate segregation of duties to ensure that one person’s ego does not take the organisation down the path to oblivion; specifically the roles of President, CEO and CFO must be separated.
8. There should be an independent supervisory board of appropriately qualified independent non executive directors. In my view, it is not merely enough for these non executives to posses titles and a string of directorships. They must be able to demonstrate that they deserve to hold office, and be proactive and “muscular” in their role; the non executives of, for example, Marconi and Cable and Wireless singularly failed in their roles.
9. There should be an independent, well qualified, proactive internal audit department which reports to an independent audit committee.
10. The organisation should have a code of conduct which is in the public arena and which is seen to be, and used as, a living document. See my article on Codes of Conduct (click here to read it) for more details.
Now, take a look at the organisation that you are dealing with/working for; does it posses all of the above? If not; then you should consider moving on, and dealing with/working for another better run organisation.
1. The organisation has a mission statement which is clearly communicated, and understood, by all members of the organisation. This will form the basis of the bsuiness plan.
2. The organisational structure is clearly defined, understood and appropriate for the activities carried out. Specifically, with regard to human reporting lines, there should be no dual/dotted reporting lines; these clutter up the clarity of the decision making process and cause conflict within the organisation. With regard to the actual organisational structure, this should be as “clean” and transparent as possible; complex off balance sheet arrangements at best confuse, and worst are deliberate attempts to obfuscate reality from interested parties (such as the Internal Revenue Service). In respect of the latter, I draw your attention to Enron.
3. The management of the organisation should clearly delegate responsibility for activities to those most appropriately qualified to perform them.
4. Targets and key performance indicators should be appropriate to the organisation’s mission, and be clearly communicated and understood. They should be stretching, but achievable; above all they should be measurable.
5. Management information must be timely, accurate, relevant and reliable. What gets measured gets done!
6. Management should take appropriate, timely, corrective actions in the event that targets are not being achieved.
7. There must be appropriate segregation of duties to ensure that one person’s ego does not take the organisation down the path to oblivion; specifically the roles of President, CEO and CFO must be separated.
8. There should be an independent supervisory board of appropriately qualified independent non executive directors. In my view, it is not merely enough for these non executives to posses titles and a string of directorships. They must be able to demonstrate that they deserve to hold office, and be proactive and “muscular” in their role; the non executives of, for example, Marconi and Cable and Wireless singularly failed in their roles.
9. There should be an independent, well qualified, proactive internal audit department which reports to an independent audit committee.
10. The organisation should have a code of conduct which is in the public arena and which is seen to be, and used as, a living document. See my article on Codes of Conduct (click here to read it) for more details.
Now, take a look at the organisation that you are dealing with/working for; does it posses all of the above? If not; then you should consider moving on, and dealing with/working for another better run organisation.
Tuesday, December 17, 2002
Ten Types of Fraud
In my roles as Head of Internal Audit and International Forensic Co-ordinator, in both Philips and De Beers, I have had many years of experience investigating frauds. Based on this experience I have put together my personal “top ten” list of common types of fraud. I recommend that you also read Ten Reasons Frauds Occur (click here to read it).
1. Falsification of expense claims – an old favourite with both senior and junior staff. Common “ruses” include; inflating mileage claims, entertaining friends and relatives at the company’s expense and claiming for expenses never incurred by stating that “the receipt must have been mislaid”.
2. Stealing money from the company bank account – the perpetrator having got away with this once, will usually try it again and again; until it is discovered. I personally reviewed a case where the perpetrator had been routinely helping himself to company cash for some twenty years.
3. Manipulating sales figures so as to reach target and achieve bonus – a simple version of this involves booking sales in one month (usually a quarter end) then crediting them back the next. Naturally unless the perpetrator keeps this “teeming and lading” up, the overstatement in one month will be shown as a shortfall in the next. Another, well worn, version of this involves booking orders as sales.
4. Falsifying supplier invoices – this is a little more daring, one case I have on record involved a senior manager who had some substantial renovation work carried out on his house. He then arranged for the invoices from the contractor to be sent to the company, posing as costs for work carried out on company premises.
5. Theft of stock – a time honoured way to make a “fast buck”. The perpetrator will over a period of time abscond with a number of items from the warehouse, and resell these to friends, family and members of the public. So long as the stock losses are within tolerance, then it is possible for this “scam” to remain undetected for a significant period of time.
6. Transactions that are not “arms length” – when a well run company asks for tenders for a service contract with a third party they usually obtain at least three closed quotes. The best value quote should then be selected. When the system does not run effectively, there is an opportunity for friends and relatives of the purchasing department to send in quotes that are accepted; bypassing the quotes from reputable suppliers. “Arms length” also applies to sales transactions where the purchaser bribes the salesman in return for a favourable contract.
7. Tax evasion – fraud on the corporate level. Excessively complex organisational structures are created, designed to obfuscate the revenue streams; and so hide reality from third parties, such as the Internal Revenue Service. Enron, with its complex off balance sheet structure and transactions, is a textbook example of this.
8. Fictitious invoicing – where there are poor accounting controls and insufficient segregation of duties in the F&A department the fraudster, if suitably positioned, can arrange for invoices (for services never delivered) from connected parties to be passed for payment.
9. Acquisition of company property at less than market value – this requires the collusion of at least two people (usually quite senior). Company property, such as fixed assets, offered for sale is “sold” to one of the individuals at a bargain price approved by the other. The property is then resold at market value, and the profit split.
10. Theft of raw materials – manufacturers should measure the quantities and costs of the raw materials used in the manufacturing process. Some processes use expensive materials, such as gold. When the measurement system has been compromised, or management do not investigate adverse yield variances, the fraudster has the opportunity to steal the raw material and sell it to third parties.
As I have noted this is my personal top ten, believe me there are many other types of frauds that have been, and are being, perpetrated.
1. Falsification of expense claims – an old favourite with both senior and junior staff. Common “ruses” include; inflating mileage claims, entertaining friends and relatives at the company’s expense and claiming for expenses never incurred by stating that “the receipt must have been mislaid”.
2. Stealing money from the company bank account – the perpetrator having got away with this once, will usually try it again and again; until it is discovered. I personally reviewed a case where the perpetrator had been routinely helping himself to company cash for some twenty years.
3. Manipulating sales figures so as to reach target and achieve bonus – a simple version of this involves booking sales in one month (usually a quarter end) then crediting them back the next. Naturally unless the perpetrator keeps this “teeming and lading” up, the overstatement in one month will be shown as a shortfall in the next. Another, well worn, version of this involves booking orders as sales.
4. Falsifying supplier invoices – this is a little more daring, one case I have on record involved a senior manager who had some substantial renovation work carried out on his house. He then arranged for the invoices from the contractor to be sent to the company, posing as costs for work carried out on company premises.
5. Theft of stock – a time honoured way to make a “fast buck”. The perpetrator will over a period of time abscond with a number of items from the warehouse, and resell these to friends, family and members of the public. So long as the stock losses are within tolerance, then it is possible for this “scam” to remain undetected for a significant period of time.
6. Transactions that are not “arms length” – when a well run company asks for tenders for a service contract with a third party they usually obtain at least three closed quotes. The best value quote should then be selected. When the system does not run effectively, there is an opportunity for friends and relatives of the purchasing department to send in quotes that are accepted; bypassing the quotes from reputable suppliers. “Arms length” also applies to sales transactions where the purchaser bribes the salesman in return for a favourable contract.
7. Tax evasion – fraud on the corporate level. Excessively complex organisational structures are created, designed to obfuscate the revenue streams; and so hide reality from third parties, such as the Internal Revenue Service. Enron, with its complex off balance sheet structure and transactions, is a textbook example of this.
8. Fictitious invoicing – where there are poor accounting controls and insufficient segregation of duties in the F&A department the fraudster, if suitably positioned, can arrange for invoices (for services never delivered) from connected parties to be passed for payment.
9. Acquisition of company property at less than market value – this requires the collusion of at least two people (usually quite senior). Company property, such as fixed assets, offered for sale is “sold” to one of the individuals at a bargain price approved by the other. The property is then resold at market value, and the profit split.
10. Theft of raw materials – manufacturers should measure the quantities and costs of the raw materials used in the manufacturing process. Some processes use expensive materials, such as gold. When the measurement system has been compromised, or management do not investigate adverse yield variances, the fraudster has the opportunity to steal the raw material and sell it to third parties.
As I have noted this is my personal top ten, believe me there are many other types of frauds that have been, and are being, perpetrated.
Monday, December 16, 2002
Ten Reasons Frauds Occur
In my roles as Head of Internal Audit and International Forensic Co-ordinator, in both Philips and De Beers, I have had many years of experience investigating frauds. Based on this experience I have put together my personal “top ten” list of reasons why frauds occur.
1. Greed - good old fashioned human nature intervenes when an individual, or group of individuals, sees a chance to make “a fast buck”. A good example being those cases where people “adjust” their expense claims upwards.
2. Lack of transparency - complex financial transactions that are difficult to understand are an ideal method to hide a fraud. The Barings fraud was perpetrated by use of an accounting “dump account” that no one understood.
3. Poor management information – where a company’s management information system does not produce results that are timely, accurate, sufficiently detailed and relevant; the warning signals of a fraud, such as ongoing theft from the bank account, can be obscured.
4. Excessively generous performance bonus payments – the more generous the bonus, when coupled to a demanding target; the more temptation there is to manipulate results, such as year end sales figures, to reach that target.
5. Non independent internal audit department – where an organisation’s internal audit department is not independent, eg the where it does not report to a truly independent audit committee but to the Finance Director, the more likely that when there are signals that a fraud is occurring the more likely they will be ignored. It is indeed interesting to note that Cynthia Cooper (Head of Internal Audit at WorldCom) had to bypass her boss (the CFO) and go directly to the audit committee to report the discovery of the capital expenditure fraud.
6. Lack of clear moral direction from senior management – leadership comes from the top. Where the senior management indulge themselves in “semi corrupt” behaviour, eg adjusting their expense claims upwards, others will follow adopting the well worn mantra “everyone’s at it”.
7. Excessively complex organisational structure - designed to obfuscate the revenue streams; and so hide reality from third parties, such as the Internal Revenue Service. Enron, with its complex off balance sheet structure and transactions, is a textbook example of this.
8. Poor accounting controls– where the accounting controls, such as a monthly reconciliation of the bank account, are lapse the signals that a fraud has occurred will be missed.
9. Arrogance – some people believe that they are better than “the system”, and that they can get away anything. The late Robert Maxwell (of the Mirror Group) plundered his company pension scheme, arrogantly assuming that since he was chairman of the company he could get away with it; he almost did!
10. Complacency – I have met many a manager who has an almost childlike faith, based in part on the “old boy” network, in the probity of their colleagues; believing that fraud “is not the sort of thing that could happen here”. Others will, and do, take advantage of that trust.
My simple advice is, if you think that a fraud may be happening then fear the worst; because it probably is.
1. Greed - good old fashioned human nature intervenes when an individual, or group of individuals, sees a chance to make “a fast buck”. A good example being those cases where people “adjust” their expense claims upwards.
2. Lack of transparency - complex financial transactions that are difficult to understand are an ideal method to hide a fraud. The Barings fraud was perpetrated by use of an accounting “dump account” that no one understood.
3. Poor management information – where a company’s management information system does not produce results that are timely, accurate, sufficiently detailed and relevant; the warning signals of a fraud, such as ongoing theft from the bank account, can be obscured.
4. Excessively generous performance bonus payments – the more generous the bonus, when coupled to a demanding target; the more temptation there is to manipulate results, such as year end sales figures, to reach that target.
5. Non independent internal audit department – where an organisation’s internal audit department is not independent, eg the where it does not report to a truly independent audit committee but to the Finance Director, the more likely that when there are signals that a fraud is occurring the more likely they will be ignored. It is indeed interesting to note that Cynthia Cooper (Head of Internal Audit at WorldCom) had to bypass her boss (the CFO) and go directly to the audit committee to report the discovery of the capital expenditure fraud.
6. Lack of clear moral direction from senior management – leadership comes from the top. Where the senior management indulge themselves in “semi corrupt” behaviour, eg adjusting their expense claims upwards, others will follow adopting the well worn mantra “everyone’s at it”.
7. Excessively complex organisational structure - designed to obfuscate the revenue streams; and so hide reality from third parties, such as the Internal Revenue Service. Enron, with its complex off balance sheet structure and transactions, is a textbook example of this.
8. Poor accounting controls– where the accounting controls, such as a monthly reconciliation of the bank account, are lapse the signals that a fraud has occurred will be missed.
9. Arrogance – some people believe that they are better than “the system”, and that they can get away anything. The late Robert Maxwell (of the Mirror Group) plundered his company pension scheme, arrogantly assuming that since he was chairman of the company he could get away with it; he almost did!
10. Complacency – I have met many a manager who has an almost childlike faith, based in part on the “old boy” network, in the probity of their colleagues; believing that fraud “is not the sort of thing that could happen here”. Others will, and do, take advantage of that trust.
My simple advice is, if you think that a fraud may be happening then fear the worst; because it probably is.
Sunday, December 15, 2002
An Open Letter to the Non Executive Directors of Cable and Wireless
Lady and Gentlemen,
You will, I believe, soon be searching for alternative employment; as it is my belief that you will shortly be dismissed for having stood by as £22bn of your company’s cash was wasted on worthless investments.
May I suggest that, before placing your names forward for other prestigious positions, you do yourselves and others a favour; by reading, learning and inwardly digesting my article In Place of Strife (click here to read it).
There is one saving grace in this sorry saga, by presiding over the destruction in value of C&W from £36bn to £1bn you have provided a textbook example of how Non Executive Directors should not “direct”.
I trust and assume that Derek Higgs will take this into account when he presents his review on corporate governance.
Kind regards,
Ken Frost
Lady and Gentlemen,
You will, I believe, soon be searching for alternative employment; as it is my belief that you will shortly be dismissed for having stood by as £22bn of your company’s cash was wasted on worthless investments.
May I suggest that, before placing your names forward for other prestigious positions, you do yourselves and others a favour; by reading, learning and inwardly digesting my article In Place of Strife (click here to read it).
There is one saving grace in this sorry saga, by presiding over the destruction in value of C&W from £36bn to £1bn you have provided a textbook example of how Non Executive Directors should not “direct”.
I trust and assume that Derek Higgs will take this into account when he presents his review on corporate governance.
Kind regards,
Ken Frost
Wednesday, December 04, 2002
An Idiot's Guide To Assessing Organisational Performance
The lamentable failures with the world of commerce over the past few years, eg Enron, Marconi and WorldCom, lead me to conclude that effective corporate governance is merely a phrase to be trotted out to the media; rather than, as it should be, a way of life in some organisations. Additionally, the fundamentals of what constitutes good corporate governance and effective management appear to have been overlooked by individuals (such as investors and analysts) and organisations (such auditors); when they are reviewing an organisation’s performance.
Therefore, based on many years of practical experience around the world, in the spirit of sharing best practice (teaching my grandmother to suck eggs maybe?); I have put together a basic checklist of questions that one should ask, and receive a satisfactory response to, when making a judgement as to the effectiveness of an organisation’s management. This is not designed to be a fully comprehensive, “covers all situations”, questionnaire.
However, the list should cover the key areas relevant to most organisations; be they companies, charities, political/military/scientific/educational bodies. The checklist should be tailored to fit the specific circumstances; naturally, depending on the answers received, more probing questions can/should be asked.
In my opinion, this checklist would be of benefit to a variety of individuals and organisations including, but not limited to:
Individual investors
Analysts
Internal/external audit
Non Governmental Organisations
Politicians
Audit Committees
Employees
In fact any stakeholder or interested party.
I have divided it into a number of sections, for ease of use.
Finger on the Pulse
1 What are the objectives of the organisation?
2 Are these objectives translated into realistic, achievable plans with timeframes and measurable milestones?
3 Are the objectives and plans communicated and understood by all?
4 What are the risks and opportunities that will affect the business objectives?
5 What is Management doing to address both the risks and opportunities?
6 Are there/have there been any major EDP changes planned? If so what are they, and what is the expected cost, benefit, timeframe for installation and payback period?
7 Have there been any frauds?
8 Details of any litigation being taken out either by or against the organisation?
9 Obtain the latest organisation chart, both senior personnel and organisational. Are there clear reporting lines?
10 Have there been any major investments/disinvestments previously or planned?
11 Ensure that there is an audit committee, and that it is independent of the Board.
12 Does the internal audit function report to the audit committee? If not, why not?
13 Review third party and (where applicable) internal audit reports.
Management Information
1 Review the latest results and compare to budget. Ensure that management receive regular (at least monthly) summaries of results (what gets measured gets done!).
2 Are the relevant key performance indicators on target eg RONA, Debtor days (DSO), cash flow?
4 Can management explain clearly, any material deviance from budget?
5 Are there adequate corrective actions in place to arrest negative deviations from budget?
6 Discuss the results with the appropriate Manager.
Have regard to, for example :
- Products with low sales against budget.
- Negative margins
Ensure that explanations for any of the above are adequate and that there are suitable corrective action plans in place to address these issues. Where the explanation seems confusing, be on your guard; either the manager doesn’t understand it or it is deliberate obfuscation.
7 Are there any areas where costs are significantly above budget? Why?
8 What are the corrective action plans to address these?
9 Review the debtor and creditor days figures. If these are high, what is Management doing to improve the situation?
10 Review the levels of stocks and enquire into reasons for levels that are higher than budget.
11 Obtain the latest forecast for the year and enquire into any significant variances between that and the budget. Also review the adequacy of the corrective actions.
Risk Management
1 Have management performed a risk assessment? If not why not?
2 Did the risk assessment highlight control gaps? If so, is there a corrective action plan?
3 Where there is a log of corrective actions :
- Do the corrective actions have a deadline and person responsible for completing the action?
- Are the deadlines being met? If not why not?
5 Is there a team responsible for monitoring progress of the action plan? If not why not? Is the process alive?
Financial Controls
1 Review the balance sheet for unusual dump accounts and other unusual items.
2 Select a sample of accounts eg accruals, provisions etc and ensure that they are adequately supported by documentary evidence/working papers.
3 Ensure that main sub ledgers are reconciled to the General Ledger.
4 Check a sample of debtors to ensure that credit limits are not exceeded.
5 Review adequacy/necessity for any provisions held.
6 Is there adequate data relating to currency exposure? How does the unit manage its exposure?
7 Are the main accounting functions/duties adequately segregated?
8 Does the CFO regularly monitor/review the controls and General Ledger? Is this evidenced, eg by use of a checklist?
9 Does the General Ledger agree to the monthly information submitted to the head office for consolidation?
11 Ensure that there are written procedures with regard to expense claims. Select a sample of expense claims and ensure that they follow the rules, are properly authorised and supported by documentary evidence, eg invoices. Ensure that there is no self authorisation of either expense claims or travel requisitions.
Code of Conduct
1 Does the organisation have a code of conduct? If so, has it been distributed to all members of staff?
2 Do all new employment contracts contain a reference to compliance?
3 Have there been any occasions of non compliance? Details please.
4 Have the non compliance occasions been reported to a Compliance Officer? What action has been taken?
Therefore, based on many years of practical experience around the world, in the spirit of sharing best practice (teaching my grandmother to suck eggs maybe?); I have put together a basic checklist of questions that one should ask, and receive a satisfactory response to, when making a judgement as to the effectiveness of an organisation’s management. This is not designed to be a fully comprehensive, “covers all situations”, questionnaire.
However, the list should cover the key areas relevant to most organisations; be they companies, charities, political/military/scientific/educational bodies. The checklist should be tailored to fit the specific circumstances; naturally, depending on the answers received, more probing questions can/should be asked.
In my opinion, this checklist would be of benefit to a variety of individuals and organisations including, but not limited to:
Individual investors
Analysts
Internal/external audit
Non Governmental Organisations
Politicians
Audit Committees
Employees
In fact any stakeholder or interested party.
I have divided it into a number of sections, for ease of use.
Finger on the Pulse
1 What are the objectives of the organisation?
2 Are these objectives translated into realistic, achievable plans with timeframes and measurable milestones?
3 Are the objectives and plans communicated and understood by all?
4 What are the risks and opportunities that will affect the business objectives?
5 What is Management doing to address both the risks and opportunities?
6 Are there/have there been any major EDP changes planned? If so what are they, and what is the expected cost, benefit, timeframe for installation and payback period?
7 Have there been any frauds?
8 Details of any litigation being taken out either by or against the organisation?
9 Obtain the latest organisation chart, both senior personnel and organisational. Are there clear reporting lines?
10 Have there been any major investments/disinvestments previously or planned?
11 Ensure that there is an audit committee, and that it is independent of the Board.
12 Does the internal audit function report to the audit committee? If not, why not?
13 Review third party and (where applicable) internal audit reports.
Management Information
1 Review the latest results and compare to budget. Ensure that management receive regular (at least monthly) summaries of results (what gets measured gets done!).
2 Are the relevant key performance indicators on target eg RONA, Debtor days (DSO), cash flow?
4 Can management explain clearly, any material deviance from budget?
5 Are there adequate corrective actions in place to arrest negative deviations from budget?
6 Discuss the results with the appropriate Manager.
Have regard to, for example :
- Products with low sales against budget.
- Negative margins
Ensure that explanations for any of the above are adequate and that there are suitable corrective action plans in place to address these issues. Where the explanation seems confusing, be on your guard; either the manager doesn’t understand it or it is deliberate obfuscation.
7 Are there any areas where costs are significantly above budget? Why?
8 What are the corrective action plans to address these?
9 Review the debtor and creditor days figures. If these are high, what is Management doing to improve the situation?
10 Review the levels of stocks and enquire into reasons for levels that are higher than budget.
11 Obtain the latest forecast for the year and enquire into any significant variances between that and the budget. Also review the adequacy of the corrective actions.
Risk Management
1 Have management performed a risk assessment? If not why not?
2 Did the risk assessment highlight control gaps? If so, is there a corrective action plan?
3 Where there is a log of corrective actions :
- Do the corrective actions have a deadline and person responsible for completing the action?
- Are the deadlines being met? If not why not?
5 Is there a team responsible for monitoring progress of the action plan? If not why not? Is the process alive?
Financial Controls
1 Review the balance sheet for unusual dump accounts and other unusual items.
2 Select a sample of accounts eg accruals, provisions etc and ensure that they are adequately supported by documentary evidence/working papers.
3 Ensure that main sub ledgers are reconciled to the General Ledger.
4 Check a sample of debtors to ensure that credit limits are not exceeded.
5 Review adequacy/necessity for any provisions held.
6 Is there adequate data relating to currency exposure? How does the unit manage its exposure?
7 Are the main accounting functions/duties adequately segregated?
8 Does the CFO regularly monitor/review the controls and General Ledger? Is this evidenced, eg by use of a checklist?
9 Does the General Ledger agree to the monthly information submitted to the head office for consolidation?
11 Ensure that there are written procedures with regard to expense claims. Select a sample of expense claims and ensure that they follow the rules, are properly authorised and supported by documentary evidence, eg invoices. Ensure that there is no self authorisation of either expense claims or travel requisitions.
Code of Conduct
1 Does the organisation have a code of conduct? If so, has it been distributed to all members of staff?
2 Do all new employment contracts contain a reference to compliance?
3 Have there been any occasions of non compliance? Details please.
4 Have the non compliance occasions been reported to a Compliance Officer? What action has been taken?
Subscribe to:
Posts (Atom)