Day 3 Of One Month to More Effective Internal Controls

Day 3 Of One Month to More Effective Internal Controls

There are four significant controls that he would suggest the compliance practitioner implement initially. They are: (1) Delegation of Authority (DOA); (2) Maintenance of the vendor master file; (3) Contracts with third parties; and (4) Movement of cash / currency. Your DOA should reflect the impact of compliance risk including both transactions and geographic location so that a higher level of approval for matters involving third parties, for fund transfers and invoice payments to countries outside the US would be required inside your company. While it is quite often true that a DOA is prepared without much thought given to compliance risks, once a DOA is prepared it is not used again until it is time to update for personnel changes. Moreover, it is often not available, not kept current, and/or does not define authority in a way even the approvers could understand it. Therefore, it is incumbent that the DOA be integrated into a company’s accounts payable (AP) processing system in a manner that ensures all high-risk vendor invoices receive the proper visibility. To achieve this, you should identify the vendors within the vendor master file so payments are flagged for the appropriate approval BEFORE they are paid. Furthermore, if a DOA is properly prepared and enforced, it can be a powerful preventive tool for compliance. Consider the following example: A wire transfer between company bank accounts in the US might require approval by the Finance Manager at the initiating location and one officer. However, a wire transfer of the same amount to the company’s bank account in Nigeria, could require approval by the Finance Manager, a knowledgeable person in the compliance function, and one officer. In this situation, the DOA should specify who must give the final approval for engaging third parties. Finally, a DOA should address replenishment of petty cash funds in countries outside the US, as well as approval of expense reports for employees who work outside the US. The vendor master file, can be one of the most powerful PREVENTIVE control tools largely because payments to fictitious vendors are one of the most common occupational frauds. The vendor master file should be structured so that each vendor can be identified not only by risk level but also by the date on which the vetting was completed and the vendor received final approval. There should be electronic controls in place to block payments to any vendor for which vetting has not been approved. Next manual controls are needed over the submission, approval, and input of changes to the vendor master file. These controls include verification that all vendors have been approved before their information (and the vendor approval date) is input into the vendor master. Finally, manual controls are also needed when “one time” vendors are requested, when a vendor name and/or vendor payment information changes are submitted. Near and dear to my heart as a lawyer, contracts with third parties can be a very effective internal control which works to prevent nefarious conduct rather than simply as a detect control. I would caution that for contracts to provide effective internal controls, relevant terms of those contracts, including for instance the commission rate, reimbursement of business expenses, use of subagents, etc.,) should be made available to those who process and approve vendor invoices. If there are nonconforming service descriptions, commission rates, are present in a contract, the terms must be approved not only by the original approver but also by the person so delegated in the DOA. Unfortunately, contracts are not typically integrated into the internal control system. They are left off to the side on their own, usually gathering dust in the legal department file room. The Hewlett-Packard FCPA enforcement action was an excellent example of the lack of internal control over the disbursements of funds and movement of currency because you had the country manager delivering bags of cash to a Polish government official to obtain or retain business. All situations where funds can be sent outside the US, including such methods AP computer checks, manual checks, wire transfers, replenishment of petty cash, loans, advances; should all be reviewed from the compliance risk standpoint. This means you need to identify the ways in which a country manager or a sales manager, could cause funds to be transferred to their control and to conceal the true nature of the use of the funds within the accounting system. To prevent these types of activities internal controls, need to be in place. This means all wire transfers outside the US should have defined approvals in the DOA, and the persons who execute the wire transfers should be required to evidence agreement of the approvals to the DOA and wire transfer requests going out of the US should always require dual approvals. Lastly, wire transfer requests going outside the US should be required to include a description of proper business purpose. The bottom line is that internal controls are just good financial controls. The internal controls that detailed for third party representatives in the compliance context will help to detect fraud, which could well lead to bribery and corruption. Three Key Takeaways Remember the top four internal controls for an effective compliance program. Effective internal controls should do more than protect but also prevent internal program violations. Effective internal compliance controls are good financial controls. For more information on how to improve your internal controls management process, visit this month’s sponsor Workiva at workiva.com. Learn more about your ad choices. Visit megaphone.fm/adchoices

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(1622)

9/11 Twenty-Five Years Later: Part 2: Juan Zarate - The Treasury Department Responds

9/11 Twenty-Five Years Later: Part 2: Juan Zarate - The Treasury Department Responds

Ed. Note-Five years ago, I looked back on 9/11 in a 20 year retrospective. This week is the 25th anniversary of that event. I am rerunning this award winning podcast so that we never forget. On the ...

7 Sep 18min

9/11 Twenty-Five Years Later: Part 1: Gabe Hidalgo - Needing to Make a Difference

9/11 Twenty-Five Years Later: Part 1: Gabe Hidalgo - Needing to Make a Difference

Ed. Note-Five years ago, I looked back on 9/11 in a 20 year retrospective. This week is the 25th anniversary of that event. I am rerunning this award winning podcast so that we never forget. On the ...

6 Sep 20min

Mara Senn on AI-Native, Human-in-the-Loop Investigations for Compliance

Mara Senn on AI-Native, Human-in-the-Loop Investigations for Compliance

In this episode, Tom Fox welcomes Mara Senn, founder and CEO of Ethakos, about her path from big law and a decade as a partner at Arnold & Porter to anti-corruption work at the Kleptocracy Initiative,...

31 Aug 31min

Charisma Doesn’t Scale, Controls Do: Compliance Lessons from Ted Lasso

Charisma Doesn’t Scale, Controls Do: Compliance Lessons from Ted Lasso

In this episode, I take things in a very different direction. Last week I did a 5-part blog post series on leadership lessons from the hit TV show Ted Lasso. I took those 5 blog posts and fed them int...

24 Aug 24min

Data Analytics in Compliance: Lessons from Scoular

Data Analytics in Compliance: Lessons from Scoular

In this episode, Tom Fox welcomes back Vince Walden, CEO of konaAI, which is the sponsor of this podcast series. Vince is well known for his leadership in data analytics, machine learning, and AI, and...

17 Aug 29min

The Berko Verdict with Mike Volkov

The Berko Verdict with Mike Volkov

In this episode, Tom Fox welcomes back his good friend and colleague Mike Volkov and takes a deep dive into the Asante Berko FCPA guilty verdict. They question why Berko went to trial given the stren...

10 Aug 33min

Matt Ellis Wrap-Up from Cartels, FTO Risk, and Corporate Compliance Conference

Matt Ellis Wrap-Up from Cartels, FTO Risk, and Corporate Compliance Conference

In this episode, Tom Fox welcomes back Matt Ellis of Miller & Chevalier to recap ACI’s inaugural two-day Cartel Conference in Washington, DC, highlighting an unusually collaborative, high-energy atmos...

3 Aug 36min

The Business Case for Going Back into Venezuela with Loren Steffy

The Business Case for Going Back into Venezuela with Loren Steffy

Welcome to the award-winning FCPA Compliance Report, the longest-running podcast in compliance. In this episode, Tom welcomes back former Houston Chronicle business columnist Loren Steffy to discuss t...

27 Jul 19min

Populært innen Business og økonomi

stopp-verden
dine-penger-pengeradet
rss-penger-polser-og-politikk
e24-podden
rss-borsmorgen-okonominyhetene
rss-skravla-gar
finansredaksjonen
lydartikler-fra-aftenposten
rss-pa-konto
pengepodden-2
tid-er-penger-en-podcast-med-peter-warren
pengesnakk
stormkast-med-valebrokk-stordalen
lederpodden
morgenkaffen-med-finansavisen
livet-pa-veien-med-jan-erik-larssen
rss-orjasater
rss-markedspuls-2
okonomiamatorene
liberal-halvtime