Requirement for Segregation of Duty Considerations 2
Business and Systems Overview 2
Risk Assessment 3
Scope of Assessment 3
Test Plan 3
Appendix A – SOD Risk Analysis 3
Definition of Segregation of Duties
A fundamental element of internal control is the segregation of certain key duties. The basic idea underlying segregation of duties (SOD) is that no employee or group of employees should be in a position both to perpetrate and to conceal errors or fraud in the normal course of their duties. In general, the principal incompatible duties to be segregated are:
▪ Custody of assets, ▪ Authorization or approval of related transactions affecting those assets, and ▪ Recording or reporting of related transactions.
Traditional systems of internal control have relied on assigning certain responsibilities to different individuals, or segregating incompatible functions. Such segregation of duties is intended to prevent one person from having both access to assets and responsibility for maintaining the accountability of such assets.
Requirement for Segregation of Duty Considerations
The purpose of segregating responsibilities is to prevent occupational fraud in the form of asset misappropriation and intentional financial misstatement. If internal control is to be effective, there needs to be an adequate division of responsibilities among those who perform accounting procedures or control activities and those who handle assets. In general, the flow of transaction processing and related activities should be designed so that the work of one individual is either independent of, or serves as a check on, the work of another. Such arrangements reduce the risk of undetected error and limit opportunities to misappropriate assets or conceal intentional misstatements in the financial statements. Segregation of duties serves as a deterrent to fraud and concealment of error because of the need to recruit another individual's co-operation, via collusion, to conceal it.
While no internal control audit standard or accounting pronouncement prescribes specific segregation of duty requirements, maintaining a system of effective internal control does require appropriate separation of responsibilities. To determine the nature of segregation of duty controls required, we considered the following guidance:
▪ SEC Guidance Regarding Management’s Report on Internal Control Over Financial Reporting ▪ PCAOB Audit Standard 5 (AS5) ▪ ACFE Uniform Fraud Classification System
Pursuant to SEC guidance, management’s evaluation of the risk of misstatement should include consideration of the vulnerability of the entity to fraudulent activity, and whether any such exposure could result in a material misstatement of the financial statements. However, the extent of activities required for the evaluation of fraud risks should be commensurate with the size and complexity of a company’s operations and financial reporting environment.
The Corporate Audit Department considered the adequacy of segregation of duties in determining if the Company’s control activities are effective in achieving the objectives of internal control and based the nature of related audit procedures on an assessment of fraud risk.
Business and Systems Overview
[Over view of business and information systems]
Significant processes containing key duties affecting either custody of assets, authorization or approval of related transactions affecting those assets, and recording/reporting of related transactions are noted in the table below.
|Company |Significant process |Related Financial System |
| |
Patterns of Food Production and Distribution Lindsey Sessions, Geoffrey Anderson, Connie Amaya, Courtney Van Winkle ENV/100 July 28th, 2014 Lori Keller Patterns of Food Production and Distribution 120000 years ago agriculture and animal husbandry were new aspects in everyday life. It is the reason that the world is the way it is today. Back then almost everyone was a farmer of some kind. Nowadays there are less than a third of the numbers of farmers there were in the 1930's. That is because…
Risk Assessment and Mitigation Techniques The Risk Management activity executes the Project Risk Management approach in response to risk events during a project. In the case of Gene One the success of the Initial Public Offering (IPO) and the lack of experience among the team in launching an (IPO) are paramount. All risks and probabilities cannot be identified during the Planning Process. Management, control, and iteration are required. When changes occur, the cycle of identify-analyze-respond…
Learning Team Question.doc CJA 374 Week 3 DQs and Summary.doc CJA 374 Week 3 Learning Team Assignment Juvenile and Adult Courts A Comparative Analysis.doc CJA 374 Week 4 DQs and Summary.doc CJA 374 Week 4 Individual Assignment Risk Assesment Paper.doc CJA 374 Week 5 DQs.doc CJA 374 Week 5 Learning Team Assignment Future of the Juvenile Justice System Paper.doc CJA 374 Week 5 Learning Team Assignment Future of the Juvenile Justice System Presentation and Paper.pptx…
Crime Statistics Paper CJA 374 Week 2 Individual Assignment Crime Causation and Diversion Paper CJA 374 Week 3 Learning Team Assignment Juvenile and Adult Courts A Comparative Analysis CJA 374 Week 4 Individual Assignment Risk Assesment Paper CJA 374 Week 5 Learning Team Assignment Future of the Juvenile Justice System Presentation and Paper You will be able to choose electives that are wonderful for your career. The more subjects you are exposed to, the more…
Crime Statistics Paper CJA 374 Week 2 Individual Assignment Crime Causation and Diversion Paper CJA 374 Week 3 Learning Team Assignment Juvenile and Adult Courts A Comparative Analysis CJA 374 Week 4 Individual Assignment Risk Assesment Paper CJA 374 Week 5 Learning Team Assignment Future of the Juvenile Justice System Presentation and Paper You want to know what it takes to be ready for the college experience, and there are many things you should be doing in…
HELEN UNIT 11 /SHC34 PRINCIPLES FOR IMPLEMENTING DUTY OF CARE IN HEALTH, SOCIAL CARE OR CHILDRENS AND YOUNG PEOPLES SETTINGS TASK 1 TO LEARNING OUTCOME 1 ASSESMENT CRITERIA 1.1, 1.2, 1.1 To have a duty of care means to be accountable for the children and young people in your care by e.g. exercising authority, managing risks, working safely, safeguarding children and young people, monitoring own behaviour and conduct, maintaining confidentiality, storing personal information appropriately…
plan to up date me on any changes as well as the moving and handeling risk assesment. Care plans and risk assesments are agreed and signed by the service user prior to care. Upon satisfactory understanding. I proceed with washing my hqands, applying personal protective equiptment (gloves and apron) and prepared the environment, ensuring health and safety of the moving and hadeling risk assesment and environment risk assesment is followed as well as the care plan. As this call has the use of a hoist…
Overview PCL operated in a high-risk environment – selling collectibles and special edition plates. This means that we, auditor, will need to rely heavily on expert opinion in valuing inventory impairment. They are also planning to make an investment of $4,900,000 by acquiring shares of Guther Limited. Owners are thinking to turn public in the near future; IFRS might be required. Primary stakeholder is the Bank, RBC. Analysis – Investment The information given for the Investment issues is limited;…
1 Bathroom risk assessments DATE: 11/05/07 MAY Time checked4.34 Signiture: STAFF A Windows are shut Doors are locked Chemicals are stored correctley Floors are mopped Bins are changed Nappy changing area to be cleaned Any other possiable hazards to be noted down It's important as it will state what to check and what risks will need to be minimised daily willow park will have this around the entire Nursey to whatever will pose a risk to the child…
Week 3: Risk Mitigation Plans Victor Sabani ITT Technical Institute Week 3: Risk Mitigation Plans 1. It is important to prioritize the IT infrastructure into risks, threats, and vulnerabilities because; knowing what can go wrong and what caused it can better prepare the staff on incidents. 2. If the risk mitigation plan is constructed well, then it will identify the cost of doing business that is affected by an event. By having the money that could be lost by an event, helps the company decide…