WHY (ICFR) INTERNAL CONTROL OVER FINANCIAL REPORTING IS IMPORTANT
Recently?Credit Suisse Group, still reeling from significant losses tied to the 2021 collapses of Archegos Capital Management and Greensill Capital, disclosed in its annual report its internal control over financial reporting (ICFR) was “not effective” for the fiscal year ending December 2022. “Management did not design and maintain an effective risk assessment process to identify and analyse the risk of material misstatements in its financial statements,” Credit Suisse said in its report.
WHAT IS INTERNAL CONTROL OVER FINANCIAL REPORTING (ICFR)?
?According to the?Financial Accounting Standards Board (FASB)?in the United States, internal control over financial reporting (ICFR) is defined as,
“A process designed to provide reasonable assurance regarding the reliability of financial reporting and the preparation of financial statements for external purposes in accordance with generally accepted accounting principles (GAAP).”
ICFR encompasses the policies and procedures that a company puts in place to ensure that:
BACKGROUND
The Internal Control and financial reporting disciplines have evolved significantly over past two decades due to various international business incidents including the in 2002 (Enron collapse), 2008 (global financial crisis), and 2016 (oil price slump) amongst other events. This has resulted in major regulatory reforms that aim to govern the internal control environment, especially focused towards the financial reporting.
Strong internal control over financial reporting (ICFR) has been a priority for corporate governance and regulatory compliance ever since the Sarbanes-Oxley Act first underlined the importance of ICFR nearly 20 years ago in 2002.
?INTERNATIONAL REGULATORY REGIME ON ICFR
International Regulatory Regime on ICFR to achieve resilience Internal Control are often an area of focus for investors, creditors, shareholders, and Board members, among other stakeholders, when ensuring that the organization provides accurate financial reporting which shows its state of operations in today’s constantly changing business environment.
Many international and regional regulators have since implemented various laws, regulations, and guidelines in relation to ICFR, a few of which are listed below:
REGIONAL REGULATORY REGIME ON ICFR IN THE UAE
?
?
?INTERNAL CONTROL FRAMEWORK FOR ICFR IMPLEMENTATION
Management is responsible for maintaining a system of internal control over financial reporting (ICFR) that provides reasonable assurance regarding the reliability of financial reporting and the preparation of financial statements in accordance with the applicable accounting principles framework.
In the UAE management of insurance companies and Abu Dhabi government owned companies and departments in the UAE are required to obtain an independent auditor’s opinion of the effectiveness of internal controls over financial reporting. In supporting its assessment, management is responsible for maintaining evidential matter, including documentation.
?The regulators in UAE have not specifically mentioned any particular framework to be followed for the ICFR implementation. However, as per the leading best practices, internal control framework based on COSO is adopted by the companies to comply with the regulatory requirements in terms of Internal Controls Over Financial Reporting (ICFR).?QFMA and ADAA entities have widely accepted the Committee on Sponsoring Organizations framework (COSO) for internal controls.
?ICFR AND COMMITTEE OF SPONSORING ORGANIZATIONS OF THE TREADWAY COMMISSION (COSO)
?“ICFR is one element of the broader concept of internal control.”
?ICFR is one element of the broader concept of internal control. Released in 1992 and updated in 2013. The Committee of Sponsoring Organizations of the Treadway Commission (COSO) defines internal control over financial reporting (ICFR) as
“A process designed to provide reasonable assurance regarding the reliability of financial reporting and the preparation of financial statements for external purposes in accordance with generally accepted accounting principles (GAAP).”
The COSO framework defines internal control as a process designed to provide reasonable assurance that the following objectives are achieved:
ICFR specifically refers to the internal control processes that are designed to achieve the objective of reliable financial reporting. It includes the policies and procedures implemented by management to ensure that financial information is accurate, complete, and timely, and that financial transactions are properly recorded, classified, and summarized.
ICFR also involves the assessment of risks associated with financial reporting, the monitoring of internal control effectiveness, and the communication of control deficiencies to management and those charged with governance.
领英推荐
KEY COMPONENTS OF ICFR
THE COSO FRAMEWORK’S FIVE INTEGRATED COMPONENTS OF INTERNAL CONTROL
The Committee on Sponsoring Organizations (COSO) has laid out an integrated framework for robust internal controls. The COSO framework consists of five components, Internal Controls Deficiencies can be evaluated with these components.
Some indicators of a positive control environment include.
The following concepts are helpful to understanding control activities:
?“The design, implementation, and evaluation of controls need to be tailored to the reporting risks of the company.”
?“Effective ICFR provides reasonable assurance that corporate records are not intentionally or unintentionally misstated.”
?
ICFR ROLES AND RESPONSIBILITIES
The roles and responsibilities related to ICFR can vary depending on the size, complexity, and nature of the organization, but here are some common ones:
“It is important that competent, well-trained individuals are involved in the?Design and oversight of ICFR.”
Overall, an effective ICFR is essential for maintaining the integrity of an organization’s financial reporting process and ensuring that stakeholders can rely on its financial statements. The roles and responsibilities outlined above are critical for achieving this goal.
INTERNAL CONTROL OVER FINANCIAL REPORTING DEFICIENCIES?
When deficiencies in the design or operation of a control are found, management needs to assess how serious the impact may be on the integrity of the company’s financial reporting processes.
More serious deficiencies are classified as either significant deficiencies or material weaknesses.
The determination as to whether a deficiency in ICFR represents a material weakness depends on
KEY TAKEAWAY
The design, implementation, and evaluation of controls need to be tailored to the reporting risks of the company. These risks may be influenced by the size of the company. Designing and maintaining effective ICFR becomes more challenging as the size of a business and the scope of its activities increase. At the same time, smaller companies may face challenges as a result of limitations in qualified resources.
Benefits of internal financial controls are beyond the compliance, ICFR will facilitate in
?“Connect internal controls to strong processes.”
Chief Financial Officer at NBP Fund Management Limited
1 年A well articulated write up on ICFR full of valuable insights on key and relevant aspects