{"id":1224,"date":"2019-04-17T09:00:28","date_gmt":"2019-04-17T06:00:28","guid":{"rendered":"https:\/\/teolupus.com\/?p=1224"},"modified":"2023-10-26T10:38:29","modified_gmt":"2023-10-26T07:38:29","slug":"control-activities-principle-10","status":"publish","type":"post","link":"https:\/\/teolupus.com\/en\/control-activities-principle-10\/","title":{"rendered":"Control Actions: Principle 10 &#8211; Selecting and Developing Control Actions"},"content":{"rendered":"\r\n<h2><b>Principle 10:\u00a0 Selecting and Developing Control Actions<\/b><\/h2>\r\n<p><span style=\"font-weight: 400;\">The organization selects and develops control actions to reduce risks to acceptable levels in achieving objectives.<\/span><\/p>\r\n<h2><b>Focus Points:<\/b><\/h2>\r\n<p><span style=\"font-weight: 400;\">Control actions serve as a mechanism that enables an organization to achieve its objectives and is an integral part of the organization&#8217;s processes to achieve those objectives.<\/span><\/p>\r\n<p><span style=\"font-weight: 400;\">The following focal points highlight essential features of this principle:<\/span><\/p>\r\n<ul>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Combined with Risk Assessment,\u00a0Control actions help ensure responses that address and reduce risks.<\/span><\/li>\r\n<\/ul>\r\n<p><span style=\"font-weight: 400;\">Control actions support all components of internal control but are precisely aligned with the Risk Assessment component. With risk assessment, management identifies and implements the measures necessary to implement specific responses to risks. Control actions are not required when an organization accepts or avoids a particular risk. However, there are situations where the organization decides to avoid a risk and develops control actions to avoid that risk. It serves as a focal point for selecting and developing prevention and control actions to reduce or share this risk. The nature and extent of the response to the risk and any associated control action will also depend, in part, on the level of risk mitigation desired by management that is acceptable to management.<\/span><\/p>\r\n<p><span style=\"font-weight: 400;\">When determining what measures to take to reduce risk, management considers all aspects of the organization&#8217;s internal control components and the relevant business processes, information technology, and locations where control actions are needed.<\/span><\/p>\r\n<ul>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Considers Organization-Specific Factors: It evaluates how the environment, complexity, nature, and scope of activities, as well as the unique characteristics of the organization, affect the selection and development of control actions.<\/span><\/li>\r\n<\/ul>\r\n<p><span style=\"font-weight: 400;\">Factors specific to the organization may affect the control actions required to operate internal control systems. For example:<\/span><\/p>\r\n<ul>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">An organization&#8217;s environment and complexity and the nature and scope of its activities influence, physically and logically, the organization&#8217;s control actions.<\/span><\/li>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The responses to risks and control actions adopted by highly regulated organizations are more complex than those of less regulated organizations.<\/span><\/li>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The scope and nature of risk responses and control actions of multinational organizations operating in various fields often require a more complex internal control structure than for an organization operating domestically whose activities are not as complex as those of multinational companies.<\/span><\/li>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The control actions of an organization with a sophisticated enterprise resource planning (ERP\/ERP) system will differ from those of an organization using an ordinary computerized accounting system.<\/span><\/li>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The control conditions of an organization whose activities are decentralized and emphasize local autonomy and innovation differ from those of organizations that carry out their activities with a fixed and overly centralized system.<\/span><\/li>\r\n<\/ul>\r\n<ul>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identifies Relevant Business Processes:\u00a0Management determines which business processes need control actions.<\/span><\/li>\r\n<\/ul>\r\n<p><span style=\"font-weight: 400;\">In order for organizations to achieve their goals, business processes are determined throughout the organization. These business processes may be similar in all businesses (such as purchasing, sales, and financing) or specific to a particular sector (such as damage compensation transactions or drilling activities). Each process transforms inputs into outputs through a series of operations or actions. Control actions that directly support measures to reduce the risks of processing (recording) business transactions in an organization&#8217;s business processes are often referred to as \u201capplication controls\u201d or \u201ctransaction controls.\u201d<\/span><\/p>\r\n<p><span style=\"font-weight: 400;\">A business process can consist of many objectives and sub-objectives, and all of these objectives have their own risks and responses to those risks. To bring together these risks in business processes in a more manageable way, the most common method is to group them according to information-processing purposes related to completeness, accuracy, and validity. Definitions regarding information processing purposes in the framework are as follows:<\/span><\/p>\r\n<ul>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Completeness \u2013 All transactions that occur are recorded.<\/span><\/li>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Accuracy\u00a0\u2013 Transactions are recorded in the correct account and in the correct amount and time at each step of the accounting process.<\/span><\/li>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Validity\u00a0\u2013 Recorded transactions represent economic events that actually occur and are executed according to predetermined procedures. For example, An example of validity in the context of operations would be sourcing the parts used to manufacture a car from an authorized supplier.<\/span><\/li>\r\n<\/ul>\r\n<ul>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Considers a Mix of Control Action Types:\u00a0Control actions include a range of diverse controls and may involve striking a balance between approaches taken to mitigate risks, considering both manual and automatic controls and preventive and detective controls.<\/span><\/li>\r\n<\/ul>\r\n<h3><b>Various process control actions can be selected and developed, including the following:<\/b><\/h3>\r\n<ul>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Authorizations and Approvals:<\/b><span style=\"font-weight: 400;\"> An authorization verifies that a transaction is valid. For example, a supervisor approves an expense report after reviewing whether the expense information is reasonable and in accordance with the organization&#8217;s policies. An example of an automatic approval would be comparing an invoice unit price to the corresponding purchase order unit price at a previously established tolerance level.<\/span><\/li>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Verifications:<\/b><span style=\"font-weight: 400;\"> Verifications compare two or more account items with each other or compare an account item with a policy. Verifications generally address the completeness, accuracy, and validity of processing business facts.<\/span><\/li>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Physical Controls: <\/b><span style=\"font-weight: 400;\">Equipment, inventories, securities, cash, and other assets are physically protected (restricted physical access), counted at regular intervals, and compared to the amounts seen in control records.<\/span><\/li>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Controls over Immutable Data: <\/b><span style=\"font-weight: 400;\">Immutable data, such as a price master file, is often used to support transaction processing in a business process.<\/span><\/li>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Reconciliations:<\/b><span style=\"font-weight: 400;\"> Reconciliation is the comparison of two or more data elements and taking action to reach a consensus regarding the data if a difference is detected. Reconciliations generally address the completeness and\/or accuracy of transactions subject to the process.<\/span><\/li>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Administrative Controls: <\/b><span style=\"font-weight: 400;\">Administrative controls evaluate whether other control actions (e.g., specific verifications, reconciliations, etc.) are performed both entirely and accurately and in accordance with policies and procedures. For example, a manager can review whether reconciliation transactions are carried out in accordance with policy.<\/span><\/li>\r\n<\/ul>\r\n<h2><span style=\"font-weight: 400;\">Control actions and technology affect each other in two ways:<\/span><\/h2>\r\n<ul>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Technology supports business processes\u00a0\u2013 When technology is incorporated into an organization&#8217;s business processes, such as robotic automation in a manufacturing facility, control actions are required to reduce the risk of the technology failing to continue operating as required to achieve the organization&#8217;s objectives.<\/span><\/li>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Technology Used to Automate Control Actions\u00a0\u2013 Control actions in an organization are either partially or fully automated through technology. For example, ERP Application.<\/span><\/li>\r\n<\/ul>\r\n<p><span style=\"font-weight: 400;\">Most business processes employ a mix of manual and automated controls, depending on the level of technology availability in the organization. Automated controls are more reliable, although the technology-general controls discussed later in this chapter vary depending on whether they are implemented and working. Because they are less affected by human decisions and errors and generally work more efficiently.<\/span><\/p>\r\n<ul>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Evaluate At What Levels Its Activities Are Executed:\u00a0Management evaluates control actions at various levels of the organization.<\/span><\/li>\r\n<\/ul>\r\n<p><span style=\"font-weight: 400;\">Organizations select and develop a mix of controls used at the transaction-processing level and control actions that operate more broadly and generally occur at higher levels of the organization. These broader control actions usually consist of operating performance or analytical reviews that involve comparing a number of different data, either operational or financial. Relationships are analyzed and investigated, and corrective action is taken as necessary if they do not comply with policy and expectations.\u00a0<\/span><\/p>\r\n<p><span style=\"font-weight: 400;\">Process controls and business performance reviews at different levels work together to provide a layered approach to the organization&#8217;s risks and are integrated into the control mix within the organization.<\/span><\/p>\r\n<p><span style=\"font-weight: 400;\">For example, an operating unit may have business performance reviews that include the percentage of purchase orders on the purchasing process and the percentage of returns relative to total purchase orders. By examining unexpected results and unusual trends, management can identify situations where key purchasing objectives may not have been achieved.<\/span><\/p>\r\n<ul>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Addresses Separation of Duties:\u00a0Management separates incompatible duties and develops alternative control actions where duties cannot be separated.<\/span><\/li>\r\n<\/ul>\r\n<p><span style=\"font-weight: 400;\">When selecting or developing control actions, management should consider whether tasks are divided or distributed among different individuals in order to reduce the risk of error or improper or fraudulent actions. Such assessment should include the legal environment, regulatory requirements, and stakeholders&#8217; expectations. Such separation of duties generally requires separating the responsibility for recording, authorizing, and approving transactions from the responsibility for managing the relevant asset.\u00a0<\/span><\/p>\r\n<p><span style=\"font-weight: 400;\">For example, A Manager who authorizes credit sales should not be responsible for maintaining accounts receivable records or processing cash (collection-disbursement) receipts. A system access request submitted by a salesperson to change product pricing files or commission rates should be denied.<\/span><\/p>\r\n<p><span style=\"font-weight: 400;\">Segregation of duties may indicate significant risks associated with management misconduct. Violating existing control actions by management is a frequently used method to commit fraud. Separation of duties is essential to mitigate the risk of fraud.<\/span><\/p>\r\n<p><span style=\"font-weight: 400;\">However, separation of duties may sometimes be inconvenient, cost-effective, or feasible. For example, small companies establish alternative control actions in such situations. In the example above, if the salesperson can change product-price files, a detective control action could be implemented by appointing personnel not affiliated with the sales unit to review whether this salesperson changed prices and, if so, under what circumstances.<\/span><\/p>\r\n<h2><b>Resources<\/b><\/h2>\r\n<ul>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dr. Davut Pehlivanl\u0131, Current Internal Audit Practices, Beta 2010<\/span><\/li>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Prof. Dr. Nejat Bozkurt, Accounting Audit, Alfa 1998<\/span><\/li>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Prof.Dr.Nejat Bozkurt, T\u00dcRMOB Independent Audit Training Lecture Notes, 2012<\/span><\/li>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dr.\u00d6zg\u00fcr \u00c7at\u0131kka\u015f, KGK, Marmara University. Corporate Governance Lecture Notes, 2013<\/span><\/li>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">\u0130SMMMO-Practical Information for Internal Audit in SMEs, 2013<\/span><\/li>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Turkish Internal Audit Institute, www.tide.org.tr<\/span><\/li>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Alp Buluch, Article, Internal Control, Hurses, 19 March 2013<\/span><\/li>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Turkish Commercial Code No. 6102<\/span><\/li>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">International Internal Auditing Standards, www.theiia.org<\/span><\/li>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Treadway Commission Supporting Institutions Committee, Internal Control-Integrated Framework, 2013<\/span><\/li>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public Financial Management and Control Law<\/span><\/li>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public Internal Control Standards<\/span><\/li>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public Internal Control Guide<\/span><\/li>\r\n<\/ul>\r\n<h2>\u00a0<\/h2>\r\n","protected":false},"excerpt":{"rendered":"<p>Principle 10:\u00a0 Selecting and Developing Control Actions The organization selects and develops control actions to reduce risks to acceptable levels in achieving objectives. Focus Points: Control actions serve as a&#8230;<\/p>\n","protected":false},"author":2,"featured_media":1444,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[845],"tags":[],"class_list":{"0":"post-1224","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-insights"},"_links":{"self":[{"href":"https:\/\/teolupus.com\/en\/wp-json\/wp\/v2\/posts\/1224","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teolupus.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teolupus.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teolupus.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/teolupus.com\/en\/wp-json\/wp\/v2\/comments?post=1224"}],"version-history":[{"count":0,"href":"https:\/\/teolupus.com\/en\/wp-json\/wp\/v2\/posts\/1224\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teolupus.com\/en\/wp-json\/wp\/v2\/media\/1444"}],"wp:attachment":[{"href":"https:\/\/teolupus.com\/en\/wp-json\/wp\/v2\/media?parent=1224"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teolupus.com\/en\/wp-json\/wp\/v2\/categories?post=1224"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teolupus.com\/en\/wp-json\/wp\/v2\/tags?post=1224"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}