Control self-assessment is a technique developed in 1987 that is used by a range of organisations including corporations, charities and government departments, to assess the effectiveness of their risk management and control processes.
A "control process" is a check or process performed to reduce or
eliminate the risk of error. Since its introduction the technique has been widely adopted in the United States, European Union and other countries. There are a number of ways a control self-assessment can be implemented but its key feature is that, in contrast to a traditional
audit
An audit is an "independent examination of financial information of any entity, whether profit oriented or not, irrespective of its size or legal form when such an examination is conducted with a view to express an opinion thereon." Auditing al ...
, the tests and checks are made by staff whose normal day-to-day responsibilities are within the business unit being assessed.
A self-assessment, by identifying the higher risk processes within the organisation, allows
internal auditor
An internal auditor is an auditor who is appointed by the Board of directors of the company in order to carry out the internal audit function. Generally, an employee of the company acts as an internal auditor, whereas some companies appoint an e ...
s to plan their work more effectively. A number of governmental organisations require the use of control self-assessment. In the
United States
The United States of America (USA), also known as the United States (U.S.) or America, is a country primarily located in North America. It is a federal republic of 50 U.S. state, states and a federal capital district, Washington, D.C. The 48 ...
it is a requirement of the
FFIEC that control self-assessments are performed on IT systems and operational processes on a regular basis. Benefits claimed for control self-assessment include creating a clear line of accountability for controls, reducing the risk of fraud and the creation of an organisation with a lower risk profile.
In certain circumstances control self-assessment is not always effective. For example, it can be difficult to implement in a decentralised environment, in organisations where there is high employee turnover, where the organisation goes through frequent change or where the senior management of the organisation does not foster a culture of open communication.
Development and worldwide adoption
Control self-assessment was developed by Gulf Canada in 1987 when the company's General Auditor, Bruce McCuaig was dissatisfied with the standard auditing techniques in use following the impact of the Watergate
The Watergate scandal was a major political scandal in the United States involving the administration of President Richard Nixon. The scandal began in 1972 and ultimately led to Nixon's resignation in 1974, in August of that year. It revol ...
affair on the parent company, Gulf Oil Corporation. The decision to fully implement control self-assessment at Gulf Canada was driven by a number of factors. These included the presence of a consent decree
A consent decree is an agreement or settlement that resolves a dispute between two parties without admission of guilt (in a criminal case) or liability (in a civil case). Most often it is such a type of settlement in the United States. The ...
requiring the company to report on its internal controls and the difficulties it was facing in estimating its oil and gas reserves using more traditional audit measures.
Over the next ten years Gulf Canada developed a framework to support the analysis and evaluation of control processes by operational staff. This included anonymous voting to ensure there was no impediment to staff expressing their views. The approach was first published in ''Internal Auditor
An internal auditor is an auditor who is appointed by the Board of directors of the company in order to carry out the internal audit function. Generally, an employee of the company acts as an internal auditor, whereas some companies appoint an e ...
'' in December 1990. Gulf Canada discontinued this facilitated meeting approach in 1997 although it continued with control self-assessment using different techniques.[
Following Gulf Canada's introduction of control self-assessment many private sector organisations implemented similar techniques. In the United States several states made reviews based on control self-assessment practices mandatory as did the ]Federal Deposit Insurance Corporation
The Federal Deposit Insurance Corporation (FDIC) is a State-owned enterprises of the United States, United States government corporation supplying deposit insurance to depositors in American commercial banks and savings banks. The FDIC was cr ...
and the Canadian Deposit Insurance Corporation.[
Initially external auditors ignored the benefits of control self-assessment even though it was effective at providing audit evidence around the "soft" areas (such as staff morale) that are critical to the effectiveness of internal control systems.
After a number of financial scandals, notably the collapse of ]Robert Maxwell
Ian Robert Maxwell (born Ján Ludvík Hyman Binyamin Hoch; 10 June 1923 – 5 November 1991) was a Czechoslovakia, Czechoslovak-born British media proprietor, politician and fraudster.
After escaping the German occupation of Czechoslovakia, ...
's publishing empire, the United Kingdom government commissioned Adrian Cadbury to chair an investigation into corporate governance. The committee published its report ''The Financial Aspects of Corporate Governance'' in 1992. In section 4, Reporting and Controls, Cadbury made a number of recommendations that led to the increased adoption of control self-assessment in the UK. In particular section 4.5 of the Code of Practice contained within the report required that the directors of a company should report on the effectiveness of the company's system of internal control in each annual report
An annual report is a comprehensive report on a company's activities throughout the preceding year. Annual reports are intended to give shareholders and other interested people information about the company's activities and financial performance. ...
.
In March 2000 the European Commission
The European Commission (EC) is the primary Executive (government), executive arm of the European Union (EU). It operates as a cabinet government, with a number of European Commissioner, members of the Commission (directorial system, informall ...
approved a white paper on reform that led to a major change in the way the Commission was managed. These changes included recommendations for each department to establish an effective internal control system. To support the implementation of the internal controls the Directorate-General for Budget's Central Financial Service developed a control self-assessment process. This first control self-assessment identified several areas for improvement in internal control across the Commission most notably the need to implement a more systematic approach to risk management. The outcome of this first self-assessment was the implementation of the requirement for every Directorate General to perform a control and risk self-assessment annually.
In 2007 the United States implemented the Sarbanes-Oxley Act. In order to comply with section 404 of the Act the company had to perform a top down risk assessment which necessitated the production of an "internal control report" that affirmed "the responsibility of management for establishing and maintaining an adequate internal control structure and procedures for financial reporting." . This report has to include an evaluation of the effectiveness of the internal controls and procedures that are related to financial reporting. To meet this requirement organisations increasingly began to perform a control self-assessment using a recognised standard methodology. The organisation's external auditors, who are required to sign-off the internal control report, typically became more deeply involved in the control self-assessment process as it facilitated their later review of the internal control report.
In the United Kingdom
The United Kingdom of Great Britain and Northern Ireland, commonly known as the United Kingdom (UK) or Britain, is a country in Northwestern Europe, off the coast of European mainland, the continental mainland. It comprises England, Scotlan ...
in 2011 the Financial Services Authority
The Financial Services Authority (FSA) was a quasi-judicial body accountable for the regulation of the financial services industry in the United Kingdom between 2001 and 2013. It was founded as the Securities and Investments Board (SIB) in 1985 ...
recognised in its recommendations for the improvement of operational risk management that the assessment of risks through a control self-assessment may be an important means of identifying risks. It also noted that for the assessment to be fully effective it had to be fully integrated into the financial organisation's risk-management process.
Performing the control self-assessment
The first step in control self-assessment is to document the organisation's control processes with the aim of identifying suitable ways of measuring or testing each control. The actual testing of the controls is performed by staff whose day-to-day role is within the area of the organisation that is being examined as they have the greatest knowledge of how the processes operate. The two common techniques for performing the evaluations are:
* Workshops, that may be but do not have to be independently facilitated, involving some or all staff from the business unit being tested;
* Surveys or questionnaires completed independently by the staff.
Both approaches are the opposite of formal audits where the auditor
An auditor is a person or a firm appointed by a company to execute an audit.Practical Auditing, Kul Narsingh Shrestha, 2012, Nabin Prakashan, Nepal To act as an auditor, a person should be certified by the regulatory authority of accounting an ...
s, not the business unit staff, will perform the assessment.[
On completion of the assessment each control may be rated based on the responses received to determine the probability of its failure and the impact if a failure occurred. These ratings can be mapped to produce a ]heatmap
A heat map (or heatmap) is a 2-dimensional data visualization technique that represents the magnitude of individual values within a dataset as a color. The variation in color may be by hue or brightness, intensity.
In some applications such as cr ...
showing potential areas of vulnerability.
Methodologies
Six basic methodologies for control self-assessment have been defined:
*Internal Control Questionnaire (ICQ) self-audit
*Customised questionnaires
*Control guides
*Interview techniques
*Control model workshops
*Interactive workshops
The National Institute of Standards and Technology
The National Institute of Standards and Technology (NIST) is an agency of the United States Department of Commerce whose mission is to promote American innovation and industrial competitiveness. NIST's activities are organized into Outline of p ...
control self-assessment methodology is based on customised questionnaires. It is an IT focused methodology suitable for assessing system based controls. It provides a cost-effective technique to determine the status of information security controls, identify any weaknesses and, where necessary, define an improvement plan. The methodology uses a questionnaire that contains specific control objectives and techniques against a system or group of systems can be tested and measured. The methodology was designed for United States federal agencies but can also be valuable for private sector organisations.[
The ]COBIT
COBIT (Control Objectives for Information and Related Technologies) is a framework created by ISACA for information technology (IT) management and IT governance.
The framework is business focused and defines a set of generic processes for the ...
methodology can be used for control self-assessment; like the NIST methodology it was designed for IT focused assessments. COBIT's Process Description component provides a reference model of an organisation's processes and their ownership. Its Control Objectives component provides a set of requirements considered necessary for effective control of each IT process with the organisation. Assessment and evaluation of these components using the Management Guidelines component provides an assessment mechanism that generates a maturity model indicating if the organisation is meeting its control objectives.[
The Institute of Internal Auditors based its control self-assessment methodology on the ]Total Quality Management
Total quality management (TQM) is an organization-wide effort to "install and make a permanent climate where employees continuously improve their ability to provide on-demand products and services that customers will find of particular value." ...
approaches of the 1990s as well as the COSO's framework. The methodology became part of the ''International Standards for Professional Practice of Internal Auditing'' and was adopted by a large number of major organisations.
A number of other methodologies to standardise the control self-assessment have been published. The Institute of Internal Auditors offers a certification in control self-assessment practice.
Software tools
A number of software packages are available to support the control self-assessment process. These are typically modified versions of software developed originally for internal use by audit and accountancy firms such as Deloitte
Deloitte is a multinational professional services network based in London, United Kingdom. It is the largest professional services network in the world by revenue and number of employees, and is one of the Big Four accounting firms, along wi ...
or by niche vendors specialising in business or financial management tools.
Benefits
Control self-assessment creates a clear line of accountability for controls, reduces the risk of fraud
In law, fraud is intent (law), intentional deception to deprive a victim of a legal right or to gain from a victim unlawfully or unfairly. Fraud can violate Civil law (common law), civil law (e.g., a fraud victim may sue the fraud perpetrato ...
(by examining data that may flag unusual patterns of transactions) and results in an organisation with a lower risk profile.
A number of other soft benefits have been claimed for organisations performing control self-assessment. These include a better understanding of business operations (by both management and operational staff); stronger awareness of risk practices; a reinforced corporate governance
Corporate governance refers to the mechanisms, processes, practices, and relations by which corporations are controlled and operated by their boards of directors, managers, shareholders, and stakeholders.
Definitions
"Corporate governance" may ...
regime and internal audit efficiency improvements.
Criticism
Some researchers have criticised control self-assessment as a flawed approach as the way risk is defined and measured is unsophisticated. In particular, control self-assessment may understate risk by not identifying extreme downside risk. An extreme downside risk is a highly improbable event that would have catastrophic consequences if it occurred. These risks should have a high overall risk score (generally calculated as a product of the probability of a risk occurring and the impact if it does occur on a scale of 1 to 5). Individuals performing the control self-assessment are consequently unable to significantly differentiate between risks leading to extreme low probability risks either being excluded from the analysis or grouped together with other more probable (but still unlikely) risks that have a less severe impact.
The continual focus on risk elimination that a control self-assessment can lead to has also been criticised. The process of continual evaluation of risks and making plans to mitigate and eliminate them may lead to an unbalanced corporate culture where risks are eliminated ignoring the risk-return ratio of different business choices.[
]
See also
*Internal audit
Internal auditing is an independent, objective assurance and consulting activity designed to add value and improve an organization's operations. It helps an organization accomplish its objectives by bringing a systematic, disciplined approach t ...
*Internal control
Internal control, as defined by accounting and auditing, is a process for assuring of an organization's objectives in operational effectiveness and efficiency, reliable financial reporting, and compliance with laws, regulations and policies. A broa ...
External links
Control self-assessment tool
used by the Federal Transit Administration
The Federal Transit Administration (FTA) is an agency within the United States Department of Transportation (DOT) that provides financial and technical assistance to local public transportation systems. The FTA is one of ten modal administration ...
References
{{DEFAULTSORT:Control self-assessment
Auditing
Risk management
Corporate governance
Internal audit