COSO Model and COCO Model As Control Frameworks
COSO Model and COCO Model As Control Frameworks
COSO Model and COCO Model As Control Frameworks
MODEL AS CONTROL
FRAMEWORKS
METALANGUAGE
CONTROL FRAMEWORK
• Basis for control system and promote the right control environment.
ESSENTIAL KNOWLEDGE
ESSENTIAL KNOWLEDGE
Capability
People must be equipped with the resources and competence to understand
and discharge the requirements of the control model. This includes knowledge;
skills and tools; communication processes; information; co-ordination; and
control activities. Capability is about resourcing the control effort by ensuring
staffs have the right skills, experience and attitudes not only to perform well but
also to be able to assess risks and ensure controls make it easier to deal with
these risks.
ESSENTIAL KNOWLEDGE
Action
This stage entails performing the activity that is being controlled. Before
employees’ act, they will have a clear purpose, a commitment to meet their
targets and the ability to deal with problems and opportunities. Any action that
comes after these prerequisites has more chance of leading to a successful
outcome.
ESSENTIAL KNOWLEDGE
Monitoring and Learning
People must buy into and be part of the organization’s evolution. This includes
monitoring internal and external environments, monitoring performance, challenging
assumptions, reassessing information needs and information systems, follow-up
procedures, and assessing the effectiveness of control. Monitoring is a hard control in
that it fits in with inspection, checking, supervising and examining. Challenging
assumptions is an important soft control in that it means people can develop and excel.
Documentation of understanding internal control may be in the form of:
a. Narrative memoranda -written description of a particular phase of a system or a
system itself. Appropriate for uncomplicated systems and infrequent change in the
system.
b. Flowchart -consists of interrelated symbols that diagram the flow of transactions
and events through the system. Powerful tool to capture the complexity of a
system.
c. Questionnaire -series of questions designed to detect control deficiencies and
potential misstatements. Can result in an unreliable documentation since
respondents can give inaccurate responses and or false information.
OPEN FORUM
THANK
YOU…