顯示具有 Internal 標籤的文章。 顯示所有文章
顯示具有 Internal 標籤的文章。 顯示所有文章

2011年7月7日 星期四

Internal quality systems audits: A desk reference addressing objectives, procedures and methods of accomplishment

This digital document is an article from Management Accounting Quarterly, published by Institute of Management Accountants on September 22, 2009. The length of the article is 5342 words. The page length shown above is based on a typical 300-word page. The article is delivered in HTML format and is available immediately after purchase. You can view it with any web browser.

From the author: THE BALANCED SCORECARD (BSC) HAS BECOME A STANDARD MANAGEMENT TOOL FOR ALL TYPES OF PROFIT AND NONPROFIT ORGANIZATIONS, AND MANY REPORT SUCCESS WITH THE APPROACH. FEW PUBLISHED STUDIES, HOWEVER, HAVE EXAMINED HOW THE EMPLOYEES AFFECTED VIEW IT. TO ADD THIS DIMENSION TO THE ASSESSMENT OF THIS TOOL, WE HAVE CONDUCTED A SURVEY THAT FOCUSES ON EMPLOYEE REACTIONS TO BSC UTILIZATION. OVERALL, THE RESULTS OF THIS SURVEY SUGGEST CONSIDERABLE ROOM FOR IMPROVEMENT IN SCORECARD IMPLEMENTATION, PARTICULARLY WITH REGARD TO INDUCING EMPLOYEE BUY-IN AND DEVELOPING THE CULTURE NECESSARY FOR SUCCESS.

Citation Details
Title: Are employees buying the balanced scorecard?
Author: Clement C. Chen
Publication: Management Accounting Quarterly (Magazine/Journal)
Date: September 22, 2009
Publisher: Institute of Management Accountants
Volume: 11 Issue: 1 Page: 36

Distributed by Gale, a part of Cengage Learning

Price:


Click here to buy from Amazon

2011年5月31日 星期二

Internal Revenue Service Audits


Pick your favorite scary movie. It could be the first Alien or something else. No matter how scary they were, nothing is scarier than an audit by the Internal Revenue Service.

If a person has a nightmare about finances, chances are that it is about Internal Revenue Service audits. However, if you are paying your taxes regularly and are honest about your filings there is no reason why you should be afraid of an audit. The Internal Revenue Service picks people with the help of a computer software program that zeros in on individuals that could have erred in filing their returns.

Normally, people who show deductions too high in relation to their income or tax items as erroneous are more likely to face a tax audit. Even so, only 1.5 to 2 percent of all tax filers are audited every year. The reason for the relatively low rate is the Internal Revenue Service simply does not have the staff to do the work. Think about it. There are hundreds of millions of tax returns filed each year!

One area the Internal Revenue Service does get riled up about is abusive business loss claims. The Internal Revenue Service looks for people who show losses in business over the years. If you are claiming business losses each year, it begs the question as to how you are staying in business. People that fudge in this area are really asking for trouble.

Moreover, if you have these things on you tax forms you may attract a tax audit:

1. Unreported taxable income is definitely going to attract audit. For example, interest earned.

2. You have complicated business expenses

3. You have rental expenses.

4. You have been audited earlier and proven guilty.

5, If you are a partner or shareholder in an audited firm.

6. You claim to donate heavily to charities.

7. Self-employed people have the greatest chance to claim erroneous deductions; hence, they are more likely to be audited.

8. Deductions under home office are also open for scrutiny more often.

9. If the mileage claimed is large enough to cause doubt.

10. If you have not filed alimony under taxable income.

11. Some informant has tipped the Internal Revenue Service off about you, to wit, a former spouse.

The good news is most Internal Revenue Service audits fall under the category of correspondence audits. In fact, I was audited last year. The Internal Revenue Service sent me a letter indicating I had not claimed dividends of $60 from a stock and owed a small amount in tax. I checked and found out something interesting. I apparently owned a stock and didn't know it. Turned out I had received shares in a merger, but had moved and never received them. I paid the tax and was done with it. By the way, I really do own such a poor performing stock.

To avoid Internal Revenue Service audits, you need to be able to substantiate your claims. If you are claiming something that is out of the ordinary, make sure you have receipts, paperwork and so on to support it. A good accountant helps as well.








Richard A. Chapo is with BusinessTaxRecovery.com - providing information on taxes.


2011年5月26日 星期四

How to Develop an Internal OHS Audit Schedule


An internal OHS audit program is used by an organisation to evaluate the effectiveness of the procedures and processes used to meet OHS legislative and other statutory administrative requirements.

An internal OHS audit schedule is a considered approach by an organisation to identify the extent and methods by which to conduct OHS related audit verification activity. The internal audit is also global best practice in OHS management systems.

It's also a vital internal quality check on OHS systems and operations. The internal OHS audit is a particularly useful management tool for ensuring that the OHS management is being conducted efficiently and properly at all levels.

A senior manager should actively participate in the internal audit to ensure currency of management information and proper critical organisation-wide scrutiny of administrative and operational functions.

Internal audit scope

The organisation will need to identify the types of internal audit activity to be conducted.

These can include one or more of the following audit activity types:

OHS management system (OHSMS) audit - system level
Procedural compliance audit - operational level
OHS legislative compliance audit - analysing compliance capability
Incident management
Reporting systems
Records management and documentation

A determination of audit types will be based on requirements defined within the OHS management system. Factors relevant to the audits may involve the level of maturity of the OHSMS, policy initiatives and implementation, and similar issues. The knowledge and understanding of key stakeholders within the organisation and Further organisational factors (e.g. number of sites, geographical locations, State, national or international application) may also apply.

Schedule considerations

Having identified the types of internal audit activity to be conducted, the organisation will need to consider the most suitable audit delivery options and scheduling. Best practice is a standardised, thorough and transparent methodology which provides clearly defined outcomes to compliment an organisation's business goals and objectives.

These considerations will include one or more of the following points:

Mandatory audit requirements (e.g. Defined by statutory authority) - These very useful audit areas may include self insurers annual requirements for audit activity to be conducted for inclusion in reporting requirements. The internal audit in these cases can also act as "radar" for management, ensuring compliance issues are under proper scrutiny.
Size of organisation and geographical locations - Consideration should be given to the different types of activities (and risk potential) within an organisation, similarity of activities at different locations to evaluate uniformity of application, geographical locations that may impact on audit schedule delivery. This approach additionally allows for targeting of areas related directly to policy implementation.
Identified high risk potential subject areas - These areas naturally have high priority in an OHSMS. Any high risk areas identified as a result of statistical analysis or management review require audit verification to assist in implementing strategic management.
Changes in legislation or organisational structure - Changes in legislation or organisational structure that may impact on the capacity to implement OHS requirements. (Note: Legislative changes usually include a time frame for compliance, and may involve significant modifications to the OHSMS. It's strongly advised that all compliance issues are included in the audit to ensure management has adequate information regarding these matters.)
Resource base from which the organisation can allocate qualified and competent auditors to conduct the audit verification activity type - Requirements of the provision of internal or external resources depending on scope of activity to meet audit needs. The resource base must be able to deliver the necessary standard of auditing to ensure OHSMS efficiency and compliance.
Organisational planning and development cycles - Planning of audits to align provision of audit reports with review cycles. This planning is a particularly useful management tool which can ensure proper control and timeliness of operational data. The forward planning also ensures well integrated OHSMS reporting.
Prioritised activities (e.g. Based on risk evaluation or business need) which will impact on implementation of OHS requirements.

Internal Audit schedule detail

The internal audit schedule should be owned by a person who has authority to manage and review the implementation of the schedule. Senior management should have direct oversight of the process, to allow checks on audit functions and efficiency.

The internal audit schedule will provide, as a minimum the following information:

The type of audit to be conducted
The expected timeframe in which the audit is to be conducted
The lead auditor responsible for the audit activity
Location of the audit
Timeframe for final report

Common Problems

One major issue in relation to developing internal audit schedules is that they either do not meet organisational needs and/or merely aim to achieve a level of conformance with statutory body requirements of regulators.

This is quite inadequate, and may expose organisations to serious liabilities. To ensure a fully functional OHSMS which is capable of dealing with all OHS issues and meets the standards of both statutes and major legal claims, the organisation must ensure that the internal audit is conducted on a holistic, best practice, basis in which all areas of liability, risk management and OHS are properly audited. The OHSMS must achieve full coverage of all potential liabilities.

Conversely, the needs of internal audits may exceed the capacity of the organisation to meet the requirements defined therein. The organisation may lack the expertise required to deal with some areas of risk management. Any internal audit carried out on this basis will inevitably be inadequate, and can create a risk of serious deficiencies in the OHSMS.

Another key problem is to ensure that audit competency (either internal or external) is at a level to achieve a suitable outcome as defined within the internal audit schedule, e.g. There are serious risks in using auditors to conduct compliance audits without the necessary understanding in relation to legislative application of requirements.

It is absolutely essential that any audit of an OHSMS is conducted by auditors having:

The correct level of audit experience
Comprehensive experience in statutory compliance, including both self insurance regulatory requirements and any other relevant statutory issues
A strong knowledge base and resources, including relevant industry knowledge where applicable
Proper accreditation for the audit operations required

The safest approach to these issues is to obtain professional guidance. The best OHSMS consultants can meet all these criteria and can also provide ongoing support and services as required.








Lane Safety Systems offers safety consulting, risk management, compliance management and safety management systems for self-insured businesses across Australia. For more information, visit Self Insurance


2011年5月21日 星期六

Internal Audit - The ISO 9001 Standard Requirements For Internal Audits and the Audits Program


"What a headache" - that's surely what every employee think to himself when they receive the massage of an internal audit approaching. There is a reason why. They know that someone is coming to poke their deeds... The internal audit chapter is included under chapter 8.2 - Monitoring and measurement. So it is clear that the purpose of the internal audit is to perform Monitoring and measurement within the organization. Internal audits, sometimes called first-party, are conducted by, or on behalf of, the organization itself for internal purposes and can form the basis for an organization's self-declaration of conformity. The organization is required to conduct the audits within scheduled time frames to ensure that the quality management system is:


Maintained according to the ISO 9001 Standard requirements
Maintained according to the organization's requirements and audit's criteria

What are an audit's criteria? Set of policies, procedures or requirements used as a reference.

We believe that in the end of the day the internal audit is actually an internal inspection that the organization conducts upon itself. Within the organization structure, it is hard for the top management to view of what is going on down the organization. It's not enough to step down to the manufacture halls, logistic centers or service centers and view the employees or the goods on the shelves. It is necessary to sample processes and to examine whether they hold against pre defined criteria. Only high resolution sampling can provide with the real organization's status. What are the criterions? The ISO 9001 standard requirements, working procedures, quality plans, quality objectives - the characteristics of the quality management system.

Since the internal audit topic is very serious and wide, we would not include it all in one article. In this article we will focus with the ISO 9001 Standard requirements for maintaining internal audit system with reference to the ISO 19011 Standard - a guide line Standard for auditing quality or environmental systems. The Standard was published in 2002 and besides outlining guideline for conducting audits, it also refer to the auditor's skills and activities. Unfortunately, the ISO 9001 Standard sets requirements but it does not guide us how to conduct an effective audit - one that would not only apply the requirements but would also assist the organization. We would deal with that in another article (we just can't give you all the secrets in one article. Sorry. Company's policy).

The ISO 9001 requirements for internal audit interanl audit procedure

The ISO 9001 Standard requires that you maintain a documented procedure describing the method for conducting an internal audit process. This is not a recommendation but a requirement. The documented procedure must define:


Who must conduct the audit - who is responsible for executing the internal audit process.
What organizational units are under the scope - departments, specific processes, activities, sites, function, etc.
Describing the process itself - who meets with whom and where and what should everybody bring with them.
The supervision after the internal audit plan (don't get excited, we will go into details soon). Where the audit's evidence are documented.

It is possible to add as annex the audit's plan and all sort of forms and documentation regarding to the process.

The auditor

The auditor must be objective related to the organizational unit he is auditing. This is a hard thing to achieve, when the quality manager is the auditor. Then he is part of the organization. He will always conduct an audit to his colleagues (the ones he sits and eats lunch with, drinks coffee or smokes a cigarette). Besides that, the auditor must be skilled for conducting an audit and document the situation correctly. Remember, an audit is an emotional event where the employees are examined about the quality of their performance. The audit's approach is highly important for the audit's progressing. Beside his personal approach, the audit must have a minimum acquaintance with the field, in order to evaluate the processes and their quality beyond the working procedures (the documented criteria). That kind of knowledge can give him the ability and the consideration to evaluate the situation while he identifies any nonconformities or faults. Within the ISO 19011 Standard there is a specification for the auditor's qualities required:


Ethics - credibility, integrity and honesty.
Open minded - willing to listen, learn and accept new ideas.
Diplomatic - polite with high manners to his colleagues - after all he is working with people and he is the representative of the top management.
Observer - owns the ability to recognize what he sees and understand without interrogating.
Perspective - owns the ability to evaluate situations beyond appearance and with a wide systematic view of things - has the ability to understand the organizational consequences of his evidence.
Versatile - owns the ability to mobilize from one situation to another without losing direction.
Persistence - must be persistence with his objectives and to not stray away.
Decisive - ready to make decision
Independent - must have his own opinion of things and to not be influenced by the environment.

We also recommend an infinitive patience. During the audits people would try everything (but everything) to divert the auditor from the subject, from all sorts of reasons: they want to conceal their activities, they are afraid or just don't like when other people look through their draws. The auditor must remain patient and always wait until his question is answered. Mostly the audit clients answer completely other answers. Sometime things get out of hand and go into arguments and disputes. The auditor must remain cool, patient - we are use to say "business as usual" - the audit must make it clear; the audit is not for any arguments but a decision made by the top management. The auditor has one objective - to present with the top management the real status of the organization. He must not be concerned about time schedules as well. This is merely a tool and not the objective.

The audit's program

The organization must maintain a documented program for conducting the audits. The program must be documented according to the ISO 9001 requirement. This is not a recommendation but a requirement! The purpose of this program is to ensure that the audits are conducted as planned. So, first, you need a program. The ISO 9001 Standard requires performing the audits within scheduled and fixed time frames. This requirement ensures that employees would know that the audit is a part of the quality management system and not a momentarily capricious decision made by the top management. It is recommended to publish the audit schedules. And for "surprise" audits - you need to define the time frames, just don't publish them. The audits program must cover:


Quality plans for the products - For any requirement for product realization, you must evaluate if it is performed as planned. The best way is to sample. Pick the product, review its quality plan, and check whether the product was realized according to the plan. Document the results then.
The ISO 9001 Standard requirements -Including the documentation requirements (customer complaints, purchasing information, CAPA, training, etc). The examination must be conducted throughout the entire organizational units which related to product realization or are under the quality managment scope. Any unit must be examined at least once a year.
Processes and procedures - the audit must evaluate whether the processes that are related to the product realization are performed as required. It could be a correlated with quality plans. But generally an audit must sample processes and evaluate its performance.
Quality objectives - the audit must examine whether the organization is achieving his quality objectives. He evaluates the objectives - whether they are related to the product and evaluates the results. Where he revealed that the objectives are not fulfilled - he must be presented with reasons and measures.

It's not easy being an auditor. It also not so easy to maintain all of the above without some help.

Audit's evidences and findings

At the end of the audit the auditor must deliver a specific report about the audits evidences and findings. The report must specify:


Who were the participants - it is recommended to document who participated during the audit. The purpose is when top management would like to conduct its inquiry - they would know to whom they must approach.
The auditee - the organization or unit that were audited.
General detail to shed light upon the auditee: how many workers, special projects, special recent events - information that would support the evidences.
Reference to prior audits and prior findings - the auditor must verify that all nonconformities that were revealed during the last audit are eliminated the treatment was documented and most important, they are not repeated.
The audits findings according to the evidences - that mean what the auditor discovered and how is it referred to the criteria: good, requires improvement action or requires corrective action (we would not deal in this article with classification of findings). Actually this is the most important part of the report. It specifies what the auditor saw, and how it was. The auditor must document the evidences as accurate as possible.
Recommendations - for every finding the audit may pay his recommendation.

A sum of all nonconformities discovered during the audit - the purpose for that is: To gather all the nonconformities for the top management for review To trace the corrective action for the next audit This sum will become a corrective action report - but that is a whole different topic. Bear in mind - this report is designated for the top management and the function that is responsible for the auditee. That report is a tool for him to understand the status. Therefore it is recommended that the report would in a format that is easy for him to understand.

Summary


The purpose of the audit is to ensure that the quality management system is as required by the ISO 9001 Standard and appropriately maintained.
You are required to maintain a documented procedure specifying the process of the internal audit.
The auditor bears a lot of responsibility. Therefore he must be perspective to the environment that he is auditing, must own the skills for evaluating and examining, with a wide view of things.
The auditor must be polite with high manners, be patient and persistent. The audit is not an easy task to perform. The organization must maintain an audit program. The purpose of the program is to ensure that the audits are conducted as planned.
At the end of the audit the auditor must deliver a specified report about the audit. This report is designated to the function that is responsible for the auditee.








The author is Itay Abuhav who is external consultant who decided to establish a quality management knowledge center providing articles, news with added values, offering solutions, help and tips regarding to all quality management systems and the ISO 9001 standard. please visit us at http://www.9001quality.com


2011年3月20日 星期日

A new era For internal auditors

??? 'Translate' ???????????????????? XML ????????????????? (8192)???? XML ?????? XmlDictionaryReaderQuotas ?????? MaxStringContentLength ??,????????? ? 1,?? 8757?
??? 'Translate' ???????????????????? XML ????????????????? (8192)???? XML ?????? XmlDictionaryReaderQuotas ?????? MaxStringContentLength ??,????????? ? 2,?? 9042?

The core of every internal control system is the integrity of its people, processes, and technologies. There is little debate that the U.S. financial crisis, caused by concurrent system failures, has had a global economic and political impact. In the wake of today's corporate scandals, bankruptcies, media-frenzied bailouts, and the financial market meltdown, light is once again being shed on the criticality of system risk and control over processes and technologies. However, more scrutiny is starting to be placed on the people who are responsible for governing and managing these systems. Because people are the most vital part of any system environment, it is imperative to have the right people - especially qualified internal auditors - in the right positions performing the right activities.

INTERNAL AUDITING AS THE CORPORATE CONSCIENCE

"Risk Governance is about three things: understanding the limits of acceptable risk, providing confidence and guidance to management, and anticipating events to set yourself up for success,"said Admiral William J. Fallon (United States Navy, Retired), co-chair of the Blue Ribbon Commission on Risk Governance, in a Commission report, Balancing Risk and Reward. In today's economic climate, the concept of governance and risk management must evolve from mere written principles into robust practices within board and management processes. The IIA's International Standards for the Professional Practice of Internal Auditing (Standards) defines the role of internal auditing in governance in Standard 2110 - Governance: "The internal audit activity must assess and make appropriate recommendations for improving the governance process in its accomplishment of the following objectives:

- Promoting appropriate ethics and values within the organization.

- Ensuring effective organizational performance management and accountability.

- Communicating risk and control information to appropriate areas of the organization.

- Coordinating the activities of and communicating information among the board, external and internal auditors, and management.

With respect to ethics, the internal audit function is generally expected to serve as the corporate conscience. Therefore, the posture of the internal audit function must be such that it can influence the corporate "brain," which encompasses members of the board and management who are the keepers of the organization (i.e., "body") and trusted guardians of its well-being. As the corporate conscience, internal auditing must be prepared to have open, candid, and constructive dialogues with their boards and management to not only comply with the Standards, but also to balance the scale between the organization's financial and ethical performance.

One of the more sensitive challenges internal audit executives are confronting is how to bring transparency to the board and management's personal values, which are an essential part in establishing the integrity and core values of an enterprise. While the public sector continues to bring board and management transparency to the forefront of the reform agenda, there will likely be more focus on personal transparency among board members and management. The internal audit activity should recognize and consider this "inner" transparency when assessing governance structures and processes, and promoting appropriate ethics and values within the organization.

PREPARING FOR THE CHALLENGE

Internal auditors have an important role and must be educated and trained to effectively carry out their responsibilities. An educated and skilled auditor should be able to filter out the noise and sift down to what information is relevant, reliable, and sufficient to support the reasoning for timely decisions and actions. The new generation of internal audit professionals must strive to become as wise as the board, as savvy as management, as intelligent as the lawyers, as diligent as the accountants, and as precise as the statisticians. Most notably, internal auditors must exercise fair and ethical judgment.

Historically, there have not been regulatory requirements for internal auditing standards or certification requirements for its professionals. At this time, it is unlikely that a regulatory rule would enforce definitive quality or certification standards; however, it is critical that education and training programs are implemented to improve the effectiveness of the internal audit function. These programs will improve the capabilities of the company's internal watchdogs to help identify and respond to risks that threaten the health and vitality of the organization and its economic ecosystem.

Although there are a variety of audit-related certifications available, some are more notable than others. For example, The IIA's Certified Internal Auditor (CIA) designation, which has been earned by approximately 80,000 internal auditors worldwide, is The Institute's flagship certification and the standard by which individuals demonstrate their overall competence and professionalism in internal auditing. While other certifications touch on specific areas of specialization, the CIA certification covers the broader range of knowledge that internal auditors need to know. "Becoming a CIA enhances your overall skills in internal auditing, establishes your credentials, and demonstrates your commitment to the internal audit profession," says Angie Woodward, CIA, CCSA, CGAP, CFSA, IIA director of certification. "Even for individuals who are not planning to stay in internal auditing long term, earning the CIA can still add value to their careers by preparing them to meet a variety of management challenges."

In addition to the CIA, The IIA offers three specialized certifications:

Certified Government Auditing Professional (CGAP). This designation demonstrates an individual's knowledge of the unique features of public-sector auditing - fund accounting, grants, legislative oversight, and confidentiality rights. The program's broad scope emphasizes the auditor's role in strengthening accountability to the public and improving government services.

Certified Financial Services Auditor (CFSA). The CFSA measures an individual's knowledge of, and proficiency in, audit principles and practices within the banking, insurance, and securities financial services industries.

Certification in Control Self-Assessment (CCSA). This certification is designed for practitioners of control self-assessment (CSA). Gaining the required knowledge of areas such as risk and control models - often considered the realm of auditors only - exposes CSA practitioners to concepts that are vital in effectively using CSA to help clients achieve their objectives.

Other specialized certification programs also are available to internal auditors. The Association of Certified Fraud Examiners' (ACFEs') Certified Fraud Examiner (CFE) credential denotes proven expertise in fraud prevention, detection, and deterrence. According to ACFE, CFEs have a unique set of skills that combine knowledge of complex financial transactions with an understanding of methods, law, and how to resolve allegations of fraud. Fraud examiners also are trained to understand not only how fraud occurs, but also why it occurs. Approximately 20,000 anti-fraud professionals have obtained their CFE credential. The Information Systems Audit and Control Association (ISACA) offers the Certified Information Systems Auditor (CISA) certification, which is a globally recognized achievement for those who control, monitor, and assess an organization's IT and business systems. More than 70,000 professionals have earned the CISA since its inception in 1978.

Although internal audit certification currently is not mandatory, audit-related acronyms are starting to find their way into the boardroom to help directors and management set standards to measure the competency and qualifications of those professionals responsible for safeguarding the corporate conscience.

LOOKING TO THE FUTURE

While we continue to endure the challenges of these tough economic times, it is important to recognize that government regulation will cause various degrees of change to governance and internal control systems. Those organizations that recognize this will not only be prepared to respond to these changes, but also will be better positioned to sustain focus on strategic operations that create value for stakeholders. As companies embrace this ideology, we will continue to see the trend of increased audit-related certification as a means for organizations to evaluate and measure internal control excellence and maintain a healthy existence.








Michael Brozzetti, CIA, CISA, CGEIT, is president of Boundless LLC, a Philadelphia-based firm specializing in applying audit, compliance, and forensic methods to enhance the overall health and well-being of organizations. He is a member of the IIA-Philadelphia chapter and serves as an adjunct professor with Villanova University where he instructs an internal audit review course.

MICHAEL BROZZETTI, CIA, CISA, CGEIT
PRESIDENT
BOUNDLESS LLC
http://www.boundlessllc.com