Internal control and the Transformation of Entities

Internal control and the Transformation of Entities

Internal control and the Transformation of Entities

 

A recent survey of 1,950 members of ACCA, the Institute of Internal Auditors and the Institute of Management Accountants (Internal control and the Transformation of Entities | ACCA Global) has highlighted how internal controls have evolved since the development of COSO in response to the corporate challenges of the 1970s.

Of those surveyed 88% highlighted the importance of controls in minimising business risk with fraud as the most common risk cited. Notably the respondents were less focussed on legal and regulatory compliance as the core reason for control. However, only about half believed that controls were currently promoted efficiency – in fact a lack of cost effectiveness in compliance was the second highest challenge noted (after skills availability). This perception requires careful consideration if internal controls are to be view as valued contributors.

The research identified that contributors:

  • Strongly recognise and align with the IIA’s Three Lines Model demonstrating the interrelated governance roles off the board, management and the independent assurance functions in relation to effective internal controls over financial and non-financial risks within the organisation
  • Are most concerned about skills shortage as the required capabilities have evolved in response to expanding scope, emerging risks and demands for commitments and disclosures in areas such as sustainability
  • Highlight the need to incorporate internal control frameworks as early as possible in business transformation to underpin growth and sustainable value
  • Believe that continuous improvements and micro-developments to control frameworks are necessary to enable them to flex and change over time
  • Recognise the importance of automation, but with automated controls integrated with manual intervention and oversight.

The shift in internal controls is not only related to the nature of the risks and controls, but also moving from a more static view to one that focuses on real-time data flows that is agile.  There must be integrity of data, aligned with an appropriate risk culture that reacts quickly to changing business models.

80% of contributors agreed that the internal control framework must be extended to non-financial and ESG reporting. In relation to non-financial reporting the contributors suggested that there is a need to understand that:

  • Data is less robust and new methods of control must be developed
  • Sources of data are more varied
  • Controls must be embedded in the same way as optimised financial controls
  • Different forms of expertise are required aligning controls specialists with technical experts
  • Stakeholders will be broader and may need more support.

To embrace the required changes there will be a need to invest in the technology and data skills of those charged with internal control, alongside appropriate guidance that reflects current operating models. We believe these changes must be embedded within organisations. We must learn from experience of financial control development and apply this across all required areas. And we must consider carefully the skills requirements, investing in training across the lines of defence, to meet the emerging expectations for a UK control assessment regime.

AUTHOR.

CAROLYN CLARKE.

Share on
Related Posts