Day 7 of One Month to a Better Board

Day 7 of One Month to a Better Board

The basic framework for internal controls is derived from the COSO Model developed by the Committee of Sponsoring Organizations of the Treadway Commission in 1992 (COSO). This model has become the standard for an internal control framework and provides a structure to ensure companies address the key elements that should result in an effective system of internal controls. Using the COSO Model, as modified in 2013, provides a very supportable approach when regulators challenge whether a company has effective internal controls. The COSO Model defines internal controls in a pyramid, from bottom to top, as follows: (a) Control environment, (b) Risk assessment, (c) Control activities, (d) Information and communication, and (e) Monitoring. Which internal controls does a company need to institute? Each company defines its internal controls to fit its business by determining what the Company wishes to protect and what type of control environment does it want to have in place. This means that they can be less formal in smaller companies but still effective if the focus is on the right risks. For anti-corruption risks, the most common control needs have been identified as follows: (i) Dealings with third parties; (ii) Gifts and entertainment, and (iii) Charitable donations. Yet even within those categories, a wide range of risks exists, depending on a company’s business practices. A Top Down ‘Check-the-box’ generic set of policies will not likely result in effective controls. The process to determine which internal controls are needed will be of some familiarity to the compliance professional. It all starts with a risk assessment to establish the corporate policies which are applicable, tailored to the company, and sufficiently specific. The risk assessment will also help to identify the types of transactions across the company which should be addressed (gifts and entertainment, maintenance of bank accounts and movement of cash, dealings with third parties, etc.). The next step is to prepare a set of documents which define the control objectives to be in place for each type of transaction – example: Controls will be in place to ensure no vendor has been added to the vendor master file until complete due diligence has been completed and the vendor has been approved in accordance with Corporate policies. Thereafter, you need to document how the controls will be performed and how they will be evidenced and then incorporate the control procedures into applicable work instructions and job descriptions. Each business location, determine the specific controls needed to accomplish each control objective. In many companies, a disparity of operating practices and accounting systems will result in different controls being needed. While this assignment may seem overwhelming it can be done in reasonable stages, pursuant to a specific implementation plan - it does not have to be done all at once for the entire company. Internal controls for a Board or Board Compliance Committee should be broken down into five concepts: Risk Assessment – A Board should assess the compliance risks associated with its business. Corporate Compliance Policy and Code of Conduct – A Board should have an overall governance document which will inform the company, its employees, stakeholders and third parties of the conduct the company expects from an employee. If the company is global/multi-national, this document should be translated into the relevant languages as appropriate. Implementing Procedures – A Board should determine if the company has a written set of procedures in place that instructs employees on the details of how to comply with the company’s compliance policy. Training – There are two levels of Board training. The first should be that the Board has a general understanding of what the FCPA is and it should also understand its role in an effective compliance program. Monitor Compliance – A Board should independently test, assess and audit to determine if its compliance policies and procedures are a ‘living and breathing program’ and not just a paper tiger. Three Key Takeaways Has your company implemented COSO 2013? What was the Board’s involvement? What is your documentation? Learn more about your ad choices. Visit megaphone.fm/adchoices

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(1622)

9/11 Twenty-Five Years Later: Part 2: Juan Zarate - The Treasury Department Responds

9/11 Twenty-Five Years Later: Part 2: Juan Zarate - The Treasury Department Responds

Ed. Note-Five years ago, I looked back on 9/11 in a 20 year retrospective. This week is the 25th anniversary of that event. I am rerunning this award winning podcast so that we never forget. On the ...

7 Sep 18min

9/11 Twenty-Five Years Later: Part 1: Gabe Hidalgo - Needing to Make a Difference

9/11 Twenty-Five Years Later: Part 1: Gabe Hidalgo - Needing to Make a Difference

Ed. Note-Five years ago, I looked back on 9/11 in a 20 year retrospective. This week is the 25th anniversary of that event. I am rerunning this award winning podcast so that we never forget. On the ...

6 Sep 20min

Mara Senn on AI-Native, Human-in-the-Loop Investigations for Compliance

Mara Senn on AI-Native, Human-in-the-Loop Investigations for Compliance

In this episode, Tom Fox welcomes Mara Senn, founder and CEO of Ethakos, about her path from big law and a decade as a partner at Arnold & Porter to anti-corruption work at the Kleptocracy Initiative,...

31 Aug 31min

Charisma Doesn’t Scale, Controls Do: Compliance Lessons from Ted Lasso

Charisma Doesn’t Scale, Controls Do: Compliance Lessons from Ted Lasso

In this episode, I take things in a very different direction. Last week I did a 5-part blog post series on leadership lessons from the hit TV show Ted Lasso. I took those 5 blog posts and fed them int...

24 Aug 24min

Data Analytics in Compliance: Lessons from Scoular

Data Analytics in Compliance: Lessons from Scoular

In this episode, Tom Fox welcomes back Vince Walden, CEO of konaAI, which is the sponsor of this podcast series. Vince is well known for his leadership in data analytics, machine learning, and AI, and...

17 Aug 29min

The Berko Verdict with Mike Volkov

The Berko Verdict with Mike Volkov

In this episode, Tom Fox welcomes back his good friend and colleague Mike Volkov and takes a deep dive into the Asante Berko FCPA guilty verdict. They question why Berko went to trial given the stren...

10 Aug 33min

Matt Ellis Wrap-Up from Cartels, FTO Risk, and Corporate Compliance Conference

Matt Ellis Wrap-Up from Cartels, FTO Risk, and Corporate Compliance Conference

In this episode, Tom Fox welcomes back Matt Ellis of Miller & Chevalier to recap ACI’s inaugural two-day Cartel Conference in Washington, DC, highlighting an unusually collaborative, high-energy atmos...

3 Aug 36min

The Business Case for Going Back into Venezuela with Loren Steffy

The Business Case for Going Back into Venezuela with Loren Steffy

Welcome to the award-winning FCPA Compliance Report, the longest-running podcast in compliance. In this episode, Tom welcomes back former Houston Chronicle business columnist Loren Steffy to discuss t...

27 Juli 19min

Populärt inom Business & ekonomi

framgangspodden
rss-jossan-nina
varvet
rss-borsens-finest
24fragor
svd-tech-brief
avanzapodden
badfluence
uppgang-och-fall
lastbilspodden
rss-inga-dumma-fragor-om-pengar
bathina-en-podcast
rikatillsammans-om-privatekonomi-rikedom-i-livet
fill-or-kill
kapitalet-en-podd-om-ekonomi
rss-veckans-trade
rss-dagen-med-di
rss-kort-lang-analyspodden-fran-di
bilar-med-sladd
tabberaset